Cognatum

Standards

Change control ends where your AI answer begins

Every regulated company controls changes to its documents. Almost none control what happens to the answers already built on the old version. An AI assistant turns that gap into a daily problem.

Cognatum Team · Sep 14, 2026 · 5 min read

Every regulated company has a change control process. A change is proposed, someone assesses its impact, a named person approves or rejects it, and the new version replaces the old one. The process is mature, it is audited, and it mostly works.

Served to one approved entry
AI assistants & agents
Proposal tools
Internal search & chat
Customer portals
Compliance & audit

Cognatum governs the entry

source · version · approver · permissions

It also ends too early. Change control governs the document. It says nothing about the answers, summaries and AI responses that were built on the previous version and are still in circulation.

What change control actually controls

The Association for Project Management defines change control as the process through which all requests to change an approved baseline are captured, evaluated, and then approved, rejected or deferred. See the definition. The emphasis sits on the baseline. Something is fixed, and changes to it are handled deliberately rather than casually.

Atlassian's version, written for IT service teams, runs through five steps: initiate a request, evaluate it, review and approve it, implement it, then monitor and close it. See the process. Close is where the process stops.

The document changes. The derived work does not.

Consider a pricing exception that applied to one client. It lived in a controlled document, approved in March, superseded in August. Change control did its job. The August version is current, the March version is archived, and the approval trail is clean.

In the months between, that March wording was quoted in a client email, pasted into an onboarding deck, summarized in a team wiki page, and indexed by an AI assistant. None of those copies were named in the change request. None of them were reviewed when the source moved. All of them are still answering questions.

An AI assistant makes the gap louder

A retrieval system does not know that a passage was superseded unless something tells it. It matches the question, finds the text, and writes a confident sentence around it. The March exception comes back as current policy, in fluent prose, with no hedging.

The failure is not that the model lied. It is that nothing connected the change in the source to the material derived from it. That link has never been part of change control, because until recently the derived material sat in people's heads and inboxes rather than in a system that answers at scale.

The question a reviewer actually asks

Reviewers rarely ask whether you have a change control process. They assume you do. The harder question is what happened to everything that relied on the old version. Which answers went out between the change and the correction, who received them, and how you know.

A clean document history does not answer that. It shows the document changed. It does not show what the change touched. That second trail is the one most organizations cannot produce, and an AI deployment makes it urgent, because the volume of derived answers rises sharply the moment an assistant is switched on.

The rule was written for documents first

This is not a new expectation, only a newly stretched one. EudraLex Volume 4, Annex 15 sets out change control alongside qualification and validation, requiring that changes be formally evaluated before they are made. Read Annex 15. ICH Q10 names change management as a core element of a pharmaceutical quality system. Read the guideline.

ISO 9001 makes control of documented information a requirement of the quality management system itself. See the standard. Each of these instruments assumes the controlled artifact is a document, and each of them predates the assistant that now reads it.

What the AI instruments ask for

The newer instruments come at it from the system side. The EU AI Act requires high risk systems to allow the automatic recording of events across the system's lifetime, in Article 12. Read Article 12. ISO/IEC 42001 extends management system discipline to artificial intelligence itself. See the standard.

NIST's Generative AI Profile treats information integrity as a risk category in its own right, separate from privacy and security. See the profile. MHRA's GxP guidance is older and blunter: records should be attributable, legible, contemporaneous, original and accurate. See the guidance.

What software can and cannot claim here

These instruments describe what an organization must be able to demonstrate. Software can align with them and produce the evidence that supports a demonstration. No product confers compliance or certification on the company running it, and a vendor who says otherwise is selling a sentence rather than a control.

Change control that reaches the answer

The fix is not a larger approval committee. It is extending the same discipline one step further, to the material that depends on the source.

  • A link between source and answer. Every approved entry records the document, system or conversation it was drawn from.
  • A version stamp. Not only which source, but which version of it the answer relied on at the moment the answer was given.
  • A signal when the source moves. Change the document and every entry that depends on it is flagged and routed back to a person.
  • A named approver on the re-check. The person decides what the change means. The system does not decide for them.
  • A record of the disagreement. Where two sources conflict, both are shown and the conflict is named rather than quietly resolved.

The signal matters more than it sounds. A knowledge base that rewrites an approved entry the moment its source changes has removed the one thing the approver was there to provide, which is a person standing behind the wording. Notification keeps that person in the loop. Silent correction removes them from it.

Change detection here is not only about files. If a table, a query or a data mart changes, anything tied to it can fall out of date, and the same signal should apply.

Where to start

Pick one controlled document that matters and trace it forward. Who quoted it, which deck repeated it, which assistant indexed it. The exercise usually takes an afternoon.

Then apply the fields above to that one chain before widening it. A small governed set is worth more to an AI assistant than a large uncontrolled one, because the assistant can say where the answer came from and who approved it.

The work left over

Change control already tells you when a document changed. The work left over is telling everything downstream, which is what the Cognatum Knowledge Loop is built around. Your company's knowledge isn't missing. It's unusable. Cognatum changes that.

Common questions

Questions this raises.

What is change control?

Change control is the formal process by which a proposed change to an approved baseline is captured, assessed for impact, and then approved, rejected or deferred by a named decision maker. It is standard practice in project management, IT service management and regulated quality systems. Its scope is the controlled item itself, usually a document, a specification or a system configuration.

What is the difference between change control and change management?

Change control is the narrower of the two. It governs whether a specific change to a controlled item is permitted and records the decision. Change management is broader and covers how an organization prepares people for a change and carries it through. A company can have excellent change control and still have no idea what its approved changes affected downstream.

Does change control cover AI-generated answers?

Usually not. A conventional change control record covers the source document and stops when the new version is released. It does not enumerate the emails, decks, wiki pages or retrieval indexes that quoted the previous version. Unless something explicitly links an answer back to the source and version it drew on, a superseded passage can keep surfacing long after the change was approved.

How do you know which version of a source an AI answer used?

Only if the system recorded it at the time. Retrieval logs tell you which documents were consulted; point-in-time provenance goes further and records the state of the knowledge when the answer was given. The EU AI Act's record-keeping expectations and NIST's treatment of information integrity both push in that direction, though neither prescribes a product.

Should a governed knowledge base update itself when a source changes?

It should tell you, not act for you. When a source moves, every entry that depends on it is flagged and routed to a named person to decide what the change means. Quietly rewriting approved wording removes the accountability the approval was there to create, and no knowledge base should be described as always current.

Knowledge governed. Intelligence everywhere.

See it on your own content, in your own environment.