2026 Addendum 3 — Controlled change, digital tools and evidence
COLABMO LEARNING · UPDATED 6 OCTOBER 2026
Controlled change, digital tools and evidence
This lesson develops practical applications of the change-planning and review themes in Addendum 1. The workflow and AI examples below are Colabmo recommendations. They are not claims that ISO 9001:2026 requires AI, a particular platform, a separate AI policy or a new certificate.

Look closely: A useful metaphor for controlled digital change: define which information and actions may pass through each boundary. For an AI pilot, identify permissions, human review, retained evidence and a way to stop or reverse the change.
Control Your Personal Data Stream by Elio Reichert, via UC Berkeley CLTC. CC BY 4.0. Unmodified image.
A change is complete when its result is demonstrated
A distributor replaces a manual receiving log with a CERP workflow. Installation and a training announcement do not establish whether the intended outcome was achieved. Before rollout, define the problem, affected processes, acceptance criteria, responsibilities, dependencies and a safe recovery route. After rollout, compare results with the intended outcome and decide whether to retain, modify or reverse the change.
| Stage | Questions for the process owner | Example evidence |
|---|---|---|
| Define | What customer or operational result should improve? What could become worse? | A pilot aims to reduce document retrieval from 15 minutes to 3 while preserving lot identity and approval history. |
| Prepare | Who needs access, competence, instructions or supplier coordination? | Role checks, approved data mapping, migration samples and a communication plan. |
| Verify before use | Do normal, exceptional and failure paths work? | Test a split lot, duplicate reference, revised certificate and unavailable network. Record expected and actual outcomes. |
| Release | Who accepts the remaining issues and authorizes operational use? | A dated release decision, unresolved-issue controls and fallback instructions. |
| Review | Did the change achieve the result? Are new risks visible? | A sample of completed receipts, retrieval timings, correction trends and a decision at the agreed review point. |
AI case: supplier certificates summarized automatically
An AI assistant extracts a part number, lot identifier and acceptance statement from a supplier certificate. A polished summary can still omit a qualification, confuse a revision, invent a field or associate the wrong attachment. Treat the generated result as an intermediate output until the intended use and controls justify reliance on it.
- Keep the original supplier record and its source link. A generated summary must not replace authentic evidence.
- Test representative and difficult cases: scans, handwritten annotations, multiple lots, contradictory text and missing fields.
- Define which facts require comparison with the original and who is competent to approve them.
- Prevent an unverified summary from authorizing acceptance or release. Route uncertainty to a person with the appropriate authority.
- Control access and the information sent to the tool under the organization’s approved arrangements.
- Record which tool or configuration produced the result when that is necessary to investigate or reproduce a decision.
- Recheck performance when the model, prompts, integration, document population or intended use changes.
Example acceptance criteria: in a defined pilot sample, every required lot identifier must match the authentic source; ambiguous records must be routed for review; no document lacking required evidence may be marked accepted automatically. These are example pilot criteria, not a universal ISO sampling rule. Select a method and sample that fit the consequence of an error.
Make documented information usable
Think beyond whether a file exists. Can the person doing the task find the authorized instruction? Is the applicable revision clear? Can completed evidence be retrieved and understood? Can changes be traced, and can records survive a system outage or staff change? Control needed information throughout its working life; adding a new logo or renumbering files does not answer these questions.
For an inspection instruction, test retrieval at the workstation. For a release record, trace the result back to the item, acceptance basis and authorizing person. For an external specification, identify the controlled source and edition. If the required record cannot be produced during the exercise, record the gap and investigate its extent rather than recreating evidence as though it existed earlier.
Bring changes into management review
For the CERP pilot, present results, unexpected effects, staff feedback and customer implications together. Include changes in relevant interested-party needs: for example, a customer now requires a different retrieval format. Ask leadership for decisions on resources, remaining issues and wider deployment. Assign owners and dates to decisions, then verify closure.
An internal audit can sample the complete path from a customer requirement through a changed workflow to released output. Use current agreed criteria and objective evidence. Distinguish a proven nonconformity from a suggestion, a disputed interpretation and a missing piece of information. Avoid declaring a failure against a draft clause or a preferred local template.
Exercise — design a controlled pilot
Choose one digital or procedural change. Write its intended result, three credible failure cases, acceptance criteria, release authority, fallback method and post-release review date. Have a colleague challenge whether your evidence would detect an incorrect result. Improve the plan before implementation.
Self-check
Question: The tool’s demonstration is accurate and its vendor says it is “ISO ready.” Can it automatically approve product release? Answer: That claim does not establish suitability for your process. Define and verify the intended use, applicable controls, authority and evidence before relying on its output.
There are no comments for now.