Proceedings of the
European Safety and Reliability Conference (ESREL2026)
14 – 19 June 2026, Braga, Portugal

Shippable document and market access for high-risk AI systems

Thor Myklebust

SESS, SINTEF Digital, Norway.

thor.myklebust@sintef.no

ABSTRACT

Shippable documents are lifecycle work products, referred to as "information items" in ISO/IEC/IEEE 15289:2019 and as "work products" in ISO 26262:2018, that are prepared to be accurate, complete, traceable, and ready for scrutiny by assessors and certification bodies. In safety-regulated domains, shippable documents typically comprise (1) the safety case or certification report and its supporting references, (2) procurement information for products and systems, and (3) certification documentation. Inspired by the agile concept of "shippable code," shippable documents operationalize regulatory compliance by providing review-ready, traceable evidence that can be continuously assessed against the requirements of the EU AI Act and applicable AI, safety, and cybersecurity standards. Shippable documents enhance regulatory compliance, reduce documentation-related errors, and streamline certification processes. Examples include safety plans, hazard logs, and work products mandated by standards such as ISO 26262, ISO/PAS 8800, ISO 21448 (SOTIF), and IEC 61508, as well as standardized reporting forms such as IEC Test Report Forms, Compliance Report Forms, and documentation structures defined in IEC 61508-1. Their inherent structured traceability ensures transparency among stakeholders by maintaining verifiable links between requirements, analyses, test evidence, and validation results. Continuous readiness for incremental review supports proactive compliance and reduces risks associated with late-stage documentation gaps. By applying agile practices such as Definition of Ready and Definition of Done, organizations can iteratively improve clarity, completeness, and validation throughout the lifecycle. This paper examines the implementation and benefits of shippable documents as dynamic compliance tools for AI systems, highlighting their integration with existing safety and cybersecurity practices and their role in sustaining innovation without compromising safety.

Keywords: Market access, Safety case references, AI, Documents, Work Products, Compliance.



Download PDF