The question
If a regulator asked tomorrow what your AI-enabled systems do, and asked you to prove it, what document would you hand over? Most organizations in regulated industries discover the answer is that no single document exists. A model inventory tells you what you are running. It does not tell you what you have said about what you are running, and the gap between those two is where enforcement now lives.
This guide explains how to build a claim register that closes that gap. It is general information about published regulatory and enforcement documents and is not legal advice.
Define a claim, narrowly, and go find them all
A claim is any statement about capability, performance, data handling, or consent that leaves the organization. That includes investor materials, product pages, data sheets, procurement and RFP responses, model cards, contract representations and warranties, marketing copy, and conference slides. Start where the exposure concentrates: anything shown to a customer, an investor, a counterparty, or an examiner. A sweep of the last twelve months of RFP responses is usually the fastest way to find claims nobody remembers making.
Give every claim five fields
| Field |
What to record |
Why it matters |
| Claim text |
Verbatim, as it is published |
The exact words are what get tested |
| Where it appears |
A link or document identifier |
Locates the exposure and its audience |
| Who approved it |
The accountable approver |
Names ownership of the statement |
| The artifact |
The single artifact that evidences it |
The proof of the claim is true |
| Artifact date |
The date that artifact was produced |
If older than the approval, the claim is stale |
Name the artifact, not the argument
“Validated by the data science team” is not an artifact. A test report with a dated test set, a stated population, a defined metric, and a named author is an artifact. The FDA denied a petition for a conditional partial exemption from 510(k) premarket notification for four categories of radiology software by letter dated 1 April 2026, and published that determination as a final order on 17 September 2026. Its reason was that the information presented does not demonstrate the case for reduced oversight. That is the standard to write into your register: demonstrate, with a document, or record the claim as unsupported.
Separate the evidence from the builder
For any system whose output informs a customer decision, a clinical decision, or a price, the evidence should be produced or reviewed by someone outside the team that built it. California’s Governor signed Senate Bill 813 and Assembly Bill 1405 on 9 September 2026, creating a designation route for independent verification organizations and a state registry for AI auditors. Neither binds a private party today, and the agency duties they create arrive later, so both take effect on 1 January 2027 with the operative registries and criteria following in 2028 and 2029. What they signal is that independence is becoming a defined term rather than a posture, and it is cheaper to organize for that now than to retrofit it.
Review the register on a fixed cycle, and on two triggers
Quarterly is a workable default. The two triggers that matter are a model change and a claim change. A retrained model with an unchanged data sheet is the most common way a register goes wrong, and a new marketing page written without reference to the register is the second.
What usually goes wrong
- Scope drift into a model inventory. You get a long list of systems and no list of statements, and the actual question stays unanswered.
- Treating it as a second-line compliance artifact. If marketing and sales never touch it, they never feed it. The register has to be a gate in the content-approval path or it is fiction within a quarter.
- Forgetting the inverse claim. Teams check whether they overstate their own systems and forget that a vendor’s overstatement, once relied upon, becomes their exposure. Every vendor claim you repeat is now your claim.
Where PiTech fits
PiTech Solutions helps organizations in regulated industries build the evidence record behind their AI and automation programs: the claim sweep across investor, product, procurement, and contract material; the five-field register maintained as a gate in the content-approval path; the artifact standard that separates a document from an argument; and the independence design that keeps evidence credible. It pairs naturally with an AI inventory and a decision register, which answer the adjacent questions of what you run and what it decides. Delivery runs under CMMI Level 3 and ISO 27001, 9001, and 42001 certifications. See AI, GenAI and ML and Data Solutions. PiTech Solutions Inc. is headquartered in Durham, North Carolina (UEI GNLRY5LNNVH6, CAGE 530K4) and is distinct from similarly named companies.
The bottom line
A claim register is a small artifact that closes a large gap, and it can be stood up in weeks rather than quarters. Define a claim narrowly, give every claim five fields, name the artifact rather than the argument, separate evidence from the builder, and review on a cycle and on two triggers. Start with the claims that have already left the building.
Frequently Asked Questions (FAQs)