0
Innovativer Roboter assistiert bei IT-Service-Management in moderner Büroumgebung.
KI-Wissen

Wie dokumentiert man KI-Entscheidungen rechtssicher im Unternehmen?

Documenting AI decisions in a legally compliant way means recording every automated decision-making process so that it is traceable, verifiable, and regulatory-compliant. The foundation for this is formed by the EU AI Act, the GDPR, and the ISO 42001 standard for AI management systems. This article answers the most important questions about the requirements, content, and processes involved in legally compliant AI documentation.

What legal requirements apply to AI documentation?

From 2026 onwards, three main legal frameworks apply to AI documentation within organisations: the EU AI Act, the GDPR, and the international standard ISO 42001. Companies that operate or offer high-risk AI systems are required to create technical documentation, demonstrate risk management measures, and ensure transparency towards authorities and affected individuals.

The EU AI Act classifies AI systems according to risk categories. For high-risk systems, Article 11 of the EU AI Act requires complete technical documentation. Additional requirements cover datasets (Art. 10), accuracy and robustness (Art. 15), and the obligation to cooperate with authorities (Art. 21). For AI systems with transparency risks — such as deepfake generators or emotion recognition systems — additional disclosure obligations apply under Art. 50 of the EU AI Act.

In parallel, the GDPR requires organisations to base every AI-supported processing of personal data on a clear legal basis and to comply with the six principles set out in Art. 5 GDPR: lawfulness, purpose limitation, data minimisation, accuracy, storage limitation, and integrity and confidentiality. Anyone using AI systems for automated decisions with a significant impact on individuals must also actively uphold data subject rights.

ISO 42001 complements these legal requirements as a recognised international standard for AI management systems. It provides a structured framework for defining AI policies, assigning responsibilities, and embedding continuous improvement.

What must legally compliant AI documentation contain?

Legally compliant AI documentation must contain at minimum a description of the AI system, the data used, the risk analysis, the decision logic, and clear responsibilities. For high-risk systems under the EU AI Act, technical specifications, test records, and evidence of conformity assessment are also required.

In detail, complete documentation should cover the following elements:

  • AI policy and objectives: A written AI policy aligned with the corporate strategy, reflecting the organisation’s risk appetite and taking legal and contractual requirements into account.
  • System description: The purpose, functionality, and scope of the AI system, including the algorithms and model architecture used.
  • Data documentation: The origin, quality, and processing principles of training data in compliance with GDPR principles.
  • Risk analysis: Identified risks, risk assessments, and protective measures taken, particularly for high-risk applications.
  • Responsibilities: Clearly named roles, such as an AI officer, with defined powers and areas of responsibility.
  • Change log: A traceable record of all modifications to the system, in line with the change management principle of ISO 42001.

According to ISO 42001, the AI policy must not only be documented but also communicated throughout the organisation and made accessible to relevant external groups. It should also be aligned with existing policies, such as the data protection policy, the information security policy, and the supplier policy.

How can AI decisions be explained in a traceable way?

AI decisions become traceable when an organisation documents both the input data and the decision logic and context, and explains them in plain language when required. Technically, this approach is called Explainable AI (XAI). Legally, it is mandatory for high-risk systems and automated individual decisions with significant consequences.

In practice, this means: for every AI-supported decision, it should be possible to trace which data points influenced the outcome and with what weighting. Particularly for decisions affecting individuals — such as in personnel selection, credit assessment, or medical diagnostics — human review must be possible and documented.

The EU Ethics Guidelines for Trustworthy AI emphasise the primacy of human agency and human oversight as a central principle. In concrete terms, this means: humans must be able to override AI decisions at any time, and this oversight mechanism must be recorded in writing. Transparency is not only a technical task but also a communicative one, since affected individuals have the right to understand the basis on which a decision was made.

Which processes and tools are suitable for day-to-day AI documentation?

For ongoing AI documentation in day-to-day business, structured documentation processes with clear responsibilities, standardised templates for AI policies and risk analyses, and digital tools for versioning and tracking changes are all well suited. What matters is not any single tool, but a consistent process.

Establishing processes

A functioning documentation process begins with the appointment of an AI officer or a responsible team. This role covers maintaining and updating system documentation, coordinating risk analyses, and ensuring that all changes to the AI system are recorded. ISO 42001 recommends carrying out changes to the AI management system in a planned manner — that is, within the framework of structured change management.

Using templates and standards

Rather than developing documentation structures from scratch, it is worth drawing on proven templates. ISO 42001 provides concrete implementation guidance in its Annex A, for example on AI policy. In addition, publicly available sample policies can serve as a starting point and be adapted to your own organisational structure. The requirements of DIN EN 18286, which describes a quality management system specifically for EU AI Act regulatory purposes, also provide helpful orientation for providers of high-risk AI systems.

What happens if AI decisions are not adequately documented?

Missing or inadequate AI documentation can lead to fines, regulatory orders, and civil liability risks. For high-risk AI systems, the market surveillance authority can prohibit the operation of the system. Reputational damage is also a risk when a lack of transparency becomes public.

The EU AI Act provides for significant sanctions for violations of documentation obligations. Fines can be imposed on providers of high-risk systems that do not maintain their technical documentation properly. In parallel, the GDPR gives supervisory authorities the ability to initiate their own sanction proceedings where AI-related data processing is inadequately documented.

Beyond regulatory risks, practical problems arise: without complete documentation, it is impossible to provide exculpatory evidence in the event of damage. Anyone who cannot demonstrate how an AI system reached a decision will have no grounds to stand on when faced with lawsuits or complaints from affected individuals. Documentation is therefore not only an obligation but also a form of protection.

How do you prepare for AI audits and regulatory enquiries?

You prepare for AI audits and regulatory enquiries by ensuring that all relevant documents are current, complete, and retrievable at any time. This includes the technical system documentation, risk analyses, change logs, evidence of employee training, and the organisation’s AI policy. Anyone operating a structured AI management system in accordance with ISO 42001 is fundamentally well positioned for audits.

Specifically, organisations should take the following preparatory steps:

  1. Create a document register: Centrally record all AI-relevant documents, with version numbers and update dates.
  2. Define responsibilities clearly: Who answers which questions in an audit? Clear roles prevent information gaps.
  3. Conduct internal pre-checks: Regular internal audits that simulate the requirements of external reviews identify gaps before authorities do.
  4. Train employees: The EU AI Act makes ensuring AI competence mandatory under Art. 4. Training records therefore form part of audit documentation.
  5. Define a communication process: How and by whom are regulatory enquiries handled? A defined process prevents ad-hoc reactions under pressure.

Anyone aiming for an ISO 42001 audit or preparing for regulatory inspections benefits from integrating the standard’s requirements into their own processes at an early stage. The standard provides a recognised framework that serves not only for AIMS certification under ISO 42001, but also as evidence of good AI governance towards authorities.

How mITSM supports organisations with legally compliant AI documentation

As a specialised training provider with over 20 years of experience in IT management, we help organisations build the knowledge needed for legally compliant AI governance. Our offering is aimed at professionals and managers who want to understand and implement AI compliance, documentation obligations, and regulatory requirements on a sound basis.

Specifically, we offer:

  • AI Manager training: Comprehensive training courses on AI governance, the EU AI Act, GDPR compliance, and ISO 42001, equipping participants to build and operate AI management systems.
  • ISO 42001 preparation: Targeted training for introducing an AI management system in accordance with ISO 42001, including audit preparation and personal certifications via ICO-Cert as a recognised certification partner for AI topics.
  • Flexible formats: In-person training, online live courses, and in-house sessions at 11 locations across Germany, so that professional development fits into any working routine.
  • Certified trainers: All trainers are certified experts in their specialist fields who know their subject matter from practical experience and convey it in a hands-on way.

Ready to put AI documentation and compliance in your organisation on a solid footing? Discover our AI training courses and find the right format for your needs.

Dieser Inhalt wurde mithilfe von KI erstellt und kann Fehler enthalten.

+49 89 - 44 44 31 88 0 Chat starten
4.9
Basierend auf 126 Rezensionen