Article · Company
TIC Council's Digitalization Framework: Where AI Fits (and Where It Doesn't)
TIC Council published its Quality Infrastructure Framework for the Digitalised World in February 2026, endorsing AI in conformity assessment while rejecting full automation of conformity decisions. Our position on what the framework gets right.
By Conformo Editorial Team · Published
Overview
On 16 February 2026, TIC Council — the global trade association for the independent third-party Testing, Inspection and Certification industry — published its membership view on digitalising assurance services, titled Quality Infrastructure Framework for the Digitalised World.
It is a more useful document than most industry association output on AI, for one reason: it draws a line. It endorses the adoption of AI, IoT systems and digital twins in conformity assessment, and it states that full automation of conformity decisions is unacceptable at the current state of the technology. Both halves matter, and the second half is the one worth building a company around.
We agree with the framework's central architecture. This post sets out where, and where we would go further.
What the framework says
The framework positions itself as a blueprint for a digitalised Quality Infrastructure. Its core move is to pair permission with constraint.
The permission. TIC organisations should have the freedom to adopt emerging technologies — artificial intelligence, IoT systems, digital twins, remote techniques and data analytics — in conformity assessment activities. The framework is explicit that these methods can improve visibility, accelerate detection of non-conformities, and enable more continuous assurance models than periodic assessment allows.
The constraint. That adoption must uphold four principles the framework treats as non-negotiable: independence, impartiality, technical competence and confidentiality, with transparency running alongside. In the words of TIC Council Director General Hanane Taidi, digital methods can strengthen conformity assessment "provided adoption upholds independence, impartiality, technical competence and confidentiality."
The framework conditions the benefits on three guardrails: validated methodologies, auditable records, and robust governance. Digital methods deliver continuous assurance only when supported by all three.
The Human-in-the-Loop requirement
The framework embeds an explicit Human-in-the-Loop framework, requiring human approval, input or supervision at defined decision points. It gives HITL two dimensions:
- Active monitoring and validation by qualified professionals — not nominal sign-off, but substantive engagement with the output.
- Clear responsibility allocation to identified persons for decisions and compliance outcomes.
The second dimension is the one that does real work, and it is frequently omitted from vendor descriptions of human oversight. A named person is accountable for the decision. Not a team, not a process, not a system — an identified individual whose competence is on record.
The gaps it identifies
The framework is candid about structural problems that neither vendors nor individual TIC organisations can solve alone:
- No accreditation schemes exist for hybrid digital-human assessment models. Accreditation frameworks were designed around human assessors performing defined activities. A model where a system performs analysis and a human validates it has no established accreditation route.
- Insufficient recognition and guidance for digitally collected or continuously validated evidence. The rules governing what counts as evidence, and how continuously-gathered data is treated relative to point-in-time observation, have not caught up.
These are the right gaps to name. They are also the reason a vendor cannot credibly tell a Certification Body that AI-assisted review is an accreditation-neutral change.
Where we agree, and why it shapes what we build
Full automation of conformity decisions is the correct line
We have held this position since we started, and not primarily for regulatory reasons.
The regulatory reason is real: a conformity decision under MDR Annex VII, Section 4.7 and 4.8 is an exercise of delegated public authority. The Notified Body's designation rests on the competence of identified personnel. There is no reading of the Regulations in which an algorithm holds that competence.
But the substantive reason is stronger. Technical documentation assessment is not a classification task. It is an exercise in judgement under incomplete information — deciding whether the evidence a manufacturer has assembled is sufficient to support a claim about safety and performance, in a context where sufficiency is genuinely contested and depends on the state of the art, the risk class, the intended purpose and the clinical context. Systems that are good at pattern recognition over documents are not thereby good at that judgement, and presenting them as if they were is how trust in the whole category gets destroyed.
The productive framing is narrower and more defensible: AI is applied to the retrieval and organisation problem, not the conclusion. Locating the evidence that responds to a given requirement across a several-thousand-page file, flagging where a requirement appears unaddressed, identifying that a referenced standard has been superseded, checking whether a claim in one document is supported by data in another — these are demanding tasks that consume the majority of assessment time, and none of them is the conformity decision.
Auditable records are the whole ballgame
The framework lists auditable records as one of three guardrails. We would put it first, because it is the guardrail that makes the other two verifiable.
Concretely, for any AI-assisted output in an assessment, a reviewer and a subsequent auditor should be able to establish:
- What source material produced this? Not "the technical file" — the specific document, version, page and passage.
- What requirement is it mapped to? The specific annex section, not a thematic category.
- What did the reviewer do with it? Accepted, rejected, modified, escalated — with the reviewer identified and the timestamp recorded.
- What would the file look like without it? Whether the assessment conclusion depends on the AI-assisted step, or whether the reviewer reached it independently.
If a system cannot answer all four, the record is not auditable, and the human-in-the-loop claim is not verifiable. This has a direct architectural consequence: a system that produces summaries without citations into the source cannot satisfy the framework's own requirement, regardless of how accurate its summaries are.
The responsibility-allocation dimension needs to be designed for
The framework's requirement that responsibility be allocated to identified persons has an uncomfortable implication for interface design, and it is worth stating plainly.
A reviewer who is shown a confident-looking machine-generated conclusion and asked to approve it is in a materially worse position to exercise independent judgement than a reviewer shown the underlying evidence and asked to reach a conclusion. Automation bias is well documented, and a system optimised for reviewer throughput will tend to produce exactly the first pattern.
If a named individual carries responsibility for the decision, the system has an obligation to put them in a position to actually exercise it. In practice that means presenting evidence before conclusions, making the source material one click away rather than buried, and not designing the accept path to be dramatically cheaper than the disagree path.
This is where we would go further than the framework does. It requires human validation at defined decision points. It does not address whether the system is designed such that validation is meaningful. That is a real gap, and it is not one that accreditation bodies are currently equipped to assess.
Where the framework leaves work undone
The accreditation gap needs schemes, not just acknowledgement. Naming the absence of accreditation routes for hybrid models is useful. It does not help a Certification Body preparing for an assessment next quarter. Until accreditation bodies publish guidance on how they will assess AI-assisted processes, individual organisations are making defensible-but-untested judgements, and vendors should say so rather than implying otherwise.
Validated methodology needs an operational definition. The framework requires validated methodologies. For a deterministic measurement method, validation has established meaning. For a system whose behaviour is probabilistic and whose performance varies by document type, language, and file quality, what constitutes validation — and what evidence of it a TIC organisation should demand from a vendor — is unresolved. This is the question we get asked most often, and the honest answer is that the industry has not converged on one.
Confidentiality has an infrastructure dimension the framework treats lightly. Technical documentation contains manufacturers' most sensitive design and clinical data. Where that data is processed, under whose jurisdiction, whether it is used for model training, and what contractual and technical guarantees exist are confidentiality questions in the framework's own terms. For European Notified Bodies the data sovereignty question is concrete and answerable, and it belongs in any evaluation. We treat it as a first-order requirement, not a deployment detail — see our buyer's checklist for evaluating AI-assisted certification software.
Our position, stated directly
The TIC Council framework draws the line in the right place. Independence, impartiality, technical competence and confidentiality are not principles that yield to efficiency arguments, and an industry whose product is trust cannot trade them for throughput.
What the framework correctly identifies is that the choice is not between adopting AI and preserving those principles. The assessment capacity problem in European conformity assessment is real and measurable, and refusing to address it has its own costs — for patients waiting on devices, for manufacturers in certification queues, and for the credibility of the regulatory system. Doing nothing is a decision with consequences too.
The resolution is to be precise about what is being automated. Retrieval, organisation, cross-referencing and gap identification: yes, with full traceability to source. Judgement about sufficiency of evidence, and the conformity decision itself: no, and not later either.
We have written elsewhere about what that separation looks like in practice — see human-in-the-loop AI for technical assessment and what certification leaders worry about when adopting AI. The TIC Council framework is a considerably better articulation of the industry's position than most, and organisations evaluating AI-assisted tooling should read it before they read any vendor's material, including ours.
Conformo builds AI-assisted review infrastructure for Notified Bodies, Certification Bodies and TIC organisations. Every finding is traceable to its source in the technical file, and every conformity decision remains with a qualified reviewer.