Glossary Updates12 new terms added to the glossaries · October 2, 2026, 22:44 CEST
AI TechDocKnowledge

Glossary · Document and evidence governance

Human review record

Also known as: Review record, Review and approval record, Sign-off record, Human sign-off record

German: Dokumenten- und Belegmanagement

In document and evidence governance, a human review record is the documented proof that a named, competent person examined a specific output — a document version, a translation, a code change, a model output — before it was accepted. It captures what was reviewed, against which criteria, what was changed or rejected, who decided and when. Where a law, a contract or a quality system requires human oversight or approval, this record is what makes the review verifiable after the fact; without it, a required review leaves no trace that it took place. Holding such records shows that a review happened; it does not by itself show that the reviewed product, system or documentation is compliant.

  • Compliance
  • Technical documentation
  • AI
  • Standards

In one sentence

A human review record is the evidence that a named, competent person checked a specific output against stated criteria before it was accepted.

Example

Before the release, the documentation lead signs a review record naming the manual version, the checklist used, the AI-drafted safety sections that were corrected and the date of approval.

How it applies

  • Minimum content: A usable review record identifies the reviewed object (title, ID, version or file hash), the criteria applied (checklist, standard, style guide, acceptance criteria, risk assessment), the reviewer as a named natural person with stated competence and authority, the findings, the changes or rejections that followed, the decision and the date. A record that says only "approved" proves attendance, not review.
  • Named persons, not shared accounts: Approvals booked to a generic workflow or service account cannot be traced to a competent human. Map review roles to identified persons and keep the evidence of their qualification separate but linkable.
  • AI-assisted work: Generated text, translations and code carry no evidence that anyone judged them. Where AI-assisted documentation is used, record which parts were machine-drafted, what the human checked and what was corrected, so the accountability stays with a person.
  • Oversight is not the same as logging: Under the EU AI Act, high-risk AI systems must technically allow automatic recording of events (logs) over the lifetime of the system (Article 12), and must be designed so that natural persons can effectively oversee them (Article 14). System logs show what the system did; they do not show that a person examined an output against criteria — that gap is what a human review record fills.
  • Two-person rules: Article 14 of the AI Act sets a stricter regime for certain remote biometric identification systems listed in Annex III, where a decision must be separately verified and confirmed by at least two natural persons with the necessary competence, training and authority. Any such rule is only auditable if each verification produces its own record.
  • Timing under the AI Act: As of 2026-09-29 the obligations for high-risk AI systems are reported to apply from 2 December 2027 for systems under Annex III and 2 August 2028 for systems under Annex I, following amendment of the application dates in Article 113; check the current consolidated text on EUR-Lex before planning, as these dates have already shifted once.
  • Quality systems: ISO 9001:2015 treats review and approval for suitability and adequacy as part of controlling documented information (clause 7.5.3). In practice the review record is the retained documented information that closes that loop for each version.
  • Machinery and product files: Reviews of instructions for use, warning messages, translations and residual risk statements should leave records that can be filed with, or referenced from, the Technical file, so that an assessor can see who released which version and on what basis.
  • Storage and retention: Keep the record immutable, linked to the exact version it approved, and retained at least as long as the reviewed document or product obligation. A review record that can be edited later is not evidence.
  • No compliance claim: Producing review records is a control, not a conformity statement. Naming a regulation or standard in the record template does not establish that the reviewed item meets it.

Human review record vs. audit trail

An Audit trail is a chronological, largely system-generated trace of events: who opened, changed, approved or deleted something, and when. A human review record is the artifact of judgment: the criteria, the findings and the reasoned decision of a competent person. An audit trail can show that an account clicked "approve" at 17:58; only the review record says what was checked, against what, and what was rejected. Mature setups keep both, and link them, so the trail evidences integrity and the record evidences substance.

External references