Is your AI governed ? Get your maturity score and roadmap. Request Access to the AI Governance Advisor →

How to Build an AI Claim Register

Table of Contents

Summarize and analyze this article with
ChatGPT

Chat GPT

ChatGPT

Perplexity

 
ChatGPT

Grok

 
ChatGPT

Google AI

ChatGPT

Claude

 

The question

If a regulator asked tomorrow what your AI-enabled systems do, and asked you to prove it, what document would you hand over? Most organizations in regulated industries discover the answer is that no single document exists. A model inventory tells you what you are running. It does not tell you what you have said about what you are running, and the gap between those two is where enforcement now lives.
This guide explains how to build a claim register that closes that gap. It is general information about published regulatory and enforcement documents and is not legal advice.

Define a claim, narrowly, and go find them all

A claim is any statement about capability, performance, data handling, or consent that leaves the organization. That includes investor materials, product pages, data sheets, procurement and RFP responses, model cards, contract representations and warranties, marketing copy, and conference slides. Start where the exposure concentrates: anything shown to a customer, an investor, a counterparty, or an examiner. A sweep of the last twelve months of RFP responses is usually the fastest way to find claims nobody remembers making.

Give every claim five fields

Field What to record Why it matters
Claim text Verbatim, as it is published The exact words are what get tested
Where it appears A link or document identifier Locates the exposure and its audience
Who approved it The accountable approver Names ownership of the statement
The artifact The single artifact that evidences it The proof of the claim is true
Artifact date The date that artifact was produced If older than the approval, the claim is stale

Name the artifact, not the argument

“Validated by the data science team” is not an artifact. A test report with a dated test set, a stated population, a defined metric, and a named author is an artifact. The FDA denied a petition for a conditional partial exemption from 510(k) premarket notification for four categories of radiology software by letter dated 1 April 2026, and published that determination as a final order on 17 September 2026. Its reason was that the information presented does not demonstrate the case for reduced oversight. That is the standard to write into your register: demonstrate, with a document, or record the claim as unsupported.

Separate the evidence from the builder

For any system whose output informs a customer decision, a clinical decision, or a price, the evidence should be produced or reviewed by someone outside the team that built it. California’s Governor signed Senate Bill 813 and Assembly Bill 1405 on 9 September 2026, creating a designation route for independent verification organizations and a state registry for AI auditors. Neither binds a private party today, and the agency duties they create arrive later, so both take effect on 1 January 2027 with the operative registries and criteria following in 2028 and 2029. What they signal is that independence is becoming a defined term rather than a posture, and it is cheaper to organize for that now than to retrofit it.

Review the register on a fixed cycle, and on two triggers

Quarterly is a workable default. The two triggers that matter are a model change and a claim change. A retrained model with an unchanged data sheet is the most common way a register goes wrong, and a new marketing page written without reference to the register is the second.

What usually goes wrong

  • Scope drift into a model inventory. You get a long list of systems and no list of statements, and the actual question stays unanswered.
  • Treating it as a second-line compliance artifact. If marketing and sales never touch it, they never feed it. The register has to be a gate in the content-approval path or it is fiction within a quarter.
  • Forgetting the inverse claim. Teams check whether they overstate their own systems and forget that a vendor’s overstatement, once relied upon, becomes their exposure. Every vendor claim you repeat is now your claim.

Where PiTech fits

PiTech Solutions helps organizations in regulated industries build the evidence record behind their AI and automation programs: the claim sweep across investor, product, procurement, and contract material; the five-field register maintained as a gate in the content-approval path; the artifact standard that separates a document from an argument; and the independence design that keeps evidence credible. It pairs naturally with an AI inventory and a decision register, which answer the adjacent questions of what you run and what it decides. Delivery runs under CMMI Level 3 and ISO 27001, 9001, and 42001 certifications. See AI, GenAI and ML and Data Solutions. PiTech Solutions Inc. is headquartered in Durham, North Carolina (UEI GNLRY5LNNVH6, CAGE 530K4) and is distinct from similarly named companies.

The bottom line

A claim register is a small artifact that closes a large gap, and it can be stood up in weeks rather than quarters. Define a claim narrowly, give every claim five fields, name the artifact rather than the argument, separate evidence from the builder, and review on a cycle and on two triggers. Start with the claims that have already left the building.

Frequently Asked Questions (FAQs)

What is an AI claim register?

An AI claim register is a single list, maintained like a risk register, that pairs every external statement your organization makes about what an automated system does with the dated artifact that evidences that statement and the person accountable for both. It captures claims about capability, performance, data handling, and consent wherever they appear, from investor materials and product pages to RFP responses, model cards, and contract warranties. Its purpose is to answer a question a model inventory cannot: not what AI you run, but what you have said about it, and whether you can prove each statement with a document rather than an assertion.
A model inventory answers what you are running; a claim register answers what you said about it. The two are complementary and neither replaces the other. Enforcement in 2026 has focused on the gap between the two: agencies test public statements about AI against the evidence behind them, and an organization can have a complete model inventory and still be unable to substantiate its marketing, investor, or procurement claims. Keeping the register at the claim level rather than the system level is essential, because one system routinely carries many claims with very different evidentiary support, and only a claim-level list surfaces the weak ones.
Any statement about capability, performance, data handling, or consent that leaves the organization. That includes investor materials, product pages, data sheets, procurement and RFP responses, model cards, contract representations and warranties, marketing copy, and conference slides. The test is whether the statement was shown to a customer, an investor, a counterparty, or an examiner, because those are the audiences whose reliance creates exposure. A practical starting point is a sweep of the last twelve months of RFP responses, which is usually the fastest way to surface specific, consequential claims that no one remembers making but that are now in a counterparty’s hands.
A document that demonstrates the claim, not an argument that asserts it. “Validated by the data science team” is an argument. A test report with a dated test set, a stated population, a defined metric, and a named author is an artifact. The standard is the one regulators apply: demonstrate, with a document, or record the claim as unsupported. The FDA’s 2026 denial of a petition for reduced radiology-software oversight rested on the finding that the information presented did not demonstrate the case. Writing that same demonstrate-it standard into your register forces each claim to be backed by a real, dated, attributable document or flagged honestly as unsupported.
When it goes stale. A statement that was accurate when made can become inaccurate as the system changes underneath it, and the most common failure is a retrained model paired with an unchanged data sheet. If the evidence artifact behind a claim is older than the claim’s last approval, the claim is stale, and stale is how a true statement quietly becomes a false one. This is why the register records artifact dates and why it is reviewed on two triggers, a model change and a claim change, in addition to a fixed cycle. Catching staleness is one of the main reasons the register exists.
Because for any system whose output informs a customer decision, a clinical decision, or a price, evidence produced only by the builders invites the criticism that it was not objectively tested. Having the evidence produced or reviewed by someone outside the building team makes it more credible to a regulator, a counterparty, or an auditor. This is also the direction of the law: California’s SB 813 and AB 1405, signed on 9 September 2026, create a designation route for independent verification organizations and a state registry for AI auditors, signaling that independence is becoming a defined term rather than a posture. Organizing for independence now is cheaper than retrofitting it later.
Once you rely on and repeat a vendor’s claim, it effectively becomes your claim, and the vendor’s overstatement becomes your exposure. Organizations tend to check whether they are overstating their own systems and forget the inverse claim: representations they carry forward from a vendor’s data sheet, model card, or sales material into their own product pages, RFP responses, or customer communications. The register should capture these repeated vendor claims and demand the same evidence standard for them as for internally generated claims. If a vendor cannot supply an artifact that demonstrates a claim you are repeating, that claim should be recorded as unsupported, exactly as an internal one would be.
Ownership must reach the functions that generate claims, not sit solely in second-line compliance. A register owned only by compliance, and never touched by marketing and sales, is not fed by the people who actually make claims and becomes fiction within a quarter. The most effective placement makes the register a gate in the content-approval path, so a new product page, RFP response, or investor statement cannot go out without a corresponding register entry and artifact. Compliance can steward the standard, but the claim-generating functions must maintain their entries. This shared ownership, with a hard gate in the approval workflow, is what keeps the register current and truthful.
It can be stood up in weeks rather than quarters, because it is a small artifact focused on statements rather than an exhaustive technical catalogue. The work is defining a claim narrowly, sweeping the highest-exposure material (customer-facing, investor, procurement, and contract documents) for the last twelve months, giving each claim its five fields, and applying the demonstrate-it artifact standard. Starting where exposure concentrates produces a usable register quickly, and the review cycle plus the two triggers keep it current thereafter. The alternative, reconstructing what you claimed and whether you can prove it during an actual inquiry, takes far longer and happens under pressure, which is exactly what the register avoids.
Yes. PiTech Solutions helps organizations in regulated industries build the evidence record behind their AI and automation programs: the claim sweep across investor, product, procurement, and contract material; the five-field register maintained as a gate in the content-approval path; the artifact standard that separates a document from an argument; and the independence design that keeps evidence credible. It pairs the claim register with an AI inventory and a decision register, which answer the adjacent questions of what you run and what it decides. Delivery runs under CMMI Level 3 and ISO 27001, 9001, and 42001 certifications. PiTech is positioned as a specialist partner for AI evidence and governance at a mid-market price.