Documentation Standards for URAC
A director of pharmacy named Elena had done everything right. Her specialty pharmacy used AI to accelerate prior authorizations, her pharmacists verified every clinical claim, her staff were genuinely competent, and her turnaround times were the envy of the region. Then the URAC accreditation review arrived, and the reviewer asked a question Elena had never been forced to answer cleanly: "Show me." Show me that this prior authorization was verified by a named human before it was submitted. Show me the record of what the AI produced and what your pharmacist changed. Show me that your staff were trained on these tools, on what, and when. Show me your governance policy for AI use and the decisions behind it. Elena knew, with complete certainty, that all of these things were true. Her pharmacy did verify, did train, did govern. But "I know it happened" is not the currency of an accreditation review. Evidence is. And as she went looking, she found that some of what she knew to be true lived only in her pharmacists' memories and in the transient state of a software system that did not retain what she now needed it to show. The earlier lessons in this chapter built the disciplines, catching hallucinations against the record, monitoring for bias across groups. This final lesson is about the form those disciplines have to take to satisfy URAC: audit-grade documentation, the kind of record that does not just describe good practice but proves it to a skeptical outside party. URAC stands for Utilization Review Accreditation Commission, and its Health Care AI Accreditation has a user track built specifically for organizations like Elena's that use AI rather than build it. This lesson is about what that track expects you to be able to show, and how to produce records that survive the moment someone says "show me."
Why URAC Changes the Documentation Question
An earlier lesson established the general principle that to an external evaluator, undocumented good practice is functionally indistinguishable from no practice, because they can only credit what can be shown. URAC accreditation is that principle made concrete and consequential. It is not a vague invitation to be responsible; it is a defined external party, on a scheduled visit, asking to see specific evidence that your AI use is competent and governed. That changes the documentation question from "should we keep records" to "will the records we keep survive the exact scrutiny the accreditation applies." The two are very different bars. A pharmacy can have informal notes that satisfy its own sense of diligence and still fail an accreditation review, because the review tests not whether you believe you practiced well but whether you can demonstrate it with records that a trained skeptic, who was not there, will accept as evidence.
The reason URAC carries this weight is that it functions as the buyer trigger for pharmacy AI. URAC launched the first national Health Care AI Accreditation, with separate tracks for AI developers and AI users, and the user track is the one a pharmacy lives under. It exists precisely so that organizations using AI can demonstrate competent, governed use to the payers, partners, and regulators who increasingly want that assurance before they will do business. This means the documentation standard is not an internal preference a pharmacy can set for itself; it is an external specification the pharmacy must meet, and the records have to be built to that specification rather than to whatever felt sufficient internally. Understanding URAC as a defined external evaluator with a defined evidentiary appetite is the shift that makes the rest of this lesson actionable, because it tells you the audience your documentation is really for: not yourself, not your staff, but the reviewer who will one day say "show me" and credit only what you can actually produce.
Accreditation does not test whether you believe you practiced well. It tests whether you can demonstrate it with records a trained skeptic, who was not there, will accept. Build the documentation to that bar, not to your own sense of diligence.
What Audit-Grade Actually Means
The phrase "audit-grade" is the heart of this lesson, and it has a precise meaning worth unpacking, because the gap between an ordinary record and an audit-grade one is exactly the gap that catches a well-run pharmacy off guard. An audit-grade record has several properties at once. It is contemporaneous: created at the time the work was done, not reconstructed afterward from memory, because a reconstruction is exactly what an auditor distrusts. It is attributable: it identifies the specific person who performed the action, so the human accountability the cardinal rule demands is visible in the record and not merely assumed. It is complete enough to reconstruct the event: someone reading it later can answer what the AI produced, what data it used, who reviewed it, what they changed, and what was decided, without having to interview the people involved. And it is tamper-evident or at least reliably retained: a record that could have been edited after the fact, or that the system silently overwrites, carries far less evidentiary weight than one preserved as it was made.
These properties are demanding precisely because ordinary good-faith record-keeping tends to violate them without anyone noticing. A pharmacist's general recollection that "we always verify" is not contemporaneous, attributable, or reconstructable; it is an assertion, and an accreditor cannot credit an assertion. A software log that records the final state but not who approved it fails attribution. A system that shows the current version of a document but not what the AI originally produced and what the human corrected fails reconstructability, which is often the most painful gap, because the entire point of the record is to show that the human caught and fixed what the AI got wrong, and a record that shows only the corrected end state has erased the very evidence of the verification it was meant to prove. Audit-grade documentation is what you get when you design the record deliberately to have these properties, rather than hoping that the documentation a system happens to produce as a byproduct will satisfy a reviewer who is specifically trained to probe for exactly these weaknesses.
The Records the User Track Expects to See
The URAC AI user track is concerned with whether a pharmacy uses AI competently and under governance, and that resolves into a recognizable set of records the pharmacy should be able to produce on request. The first is the verification record: evidence, per high-stakes AI-assisted clinical event, that the output was checked by an identifiable human against the authoritative source before it took effect. This is the documentary form of the cardinal rule and of the hallucination-catching workflow from earlier in this chapter; it is what proves the human decision point was real rather than a rubber stamp. The second is the audit trail: the reconstructable record of an AI-assisted event, what the AI produced, what data it drew on, who reviewed it, and what was decided, which is what lets someone answer "what actually happened here" months later when a question arises.
The third is governance documentation: the policies, roles, and decisions showing the pharmacy has deliberately decided how AI is used and overseen, including who is accountable, which uses are permitted, and how risks like bias are monitored. This is where the equity work of the previous lesson becomes audit-grade, the disaggregated monitoring, the disparities found, and the responses taken, recorded as evidence of a managed risk rather than an assumed virtue. The fourth is the competency record: evidence that the people using AI were trained on it, on what, and when, demonstrating that the workforce is prepared rather than merely assumed to be capable. Completing a structured, role-grounded AI program, like this one, and retaining the record of that completion, is exactly the kind of competency evidence the user track contemplates. Together these four record types, verification, audit trail, governance, and competency, are the spine of what a pharmacy must be able to show, and a pharmacy that can produce all four, contemporaneous and attributable, is one that walks into the review with evidence rather than assurances.
Proportionate Documentation Under Accreditation
A fear that surfaces immediately when pharmacists hear "audit-grade" is that the standard demands maximal documentation of everything, a paper trail so heavy it strangles the work it is meant to protect. That fear, left unaddressed, drives the worst outcome, which is documenting nothing for fear of the burden of documenting everything. The resolution is the same calibration principle that has run through the whole program: documentation should be proportionate to the stakes, and URAC's expectation is reasonable rather than absolute. A high-stakes clinical use, an AI-assisted prior authorization, an AI-supported order verification, warrants a thorough verification record and a full audit trail, because that is exactly the use whose soundness someone may later need to reconstruct and whose failure carries patient-safety and access consequences. A low-stakes operational use, an inventory forecast, warrants far lighter documentation, because the cost of an unprovable forecast is a recoverable business question, not a patient harm.
This calibration is what makes audit-grade documentation sustainable rather than crushing, and it is also what a thoughtful reviewer actually expects to see. An accreditor is not looking for a pharmacy that has buried itself in uniform paperwork; that pattern often signals a pharmacy that does not understand its own risk, spreading effort evenly instead of concentrating it where the stakes live. The reviewer is looking for evidence that the pharmacy has identified its high-stakes AI uses and documented them thoroughly, while treating low-stakes uses proportionately. The best-designed documentation programs achieve this by capturing much of the high-stakes evidence automatically as a byproduct of the workflow: the system logs what the AI produced, what the human reviewed and changed, and who approved it, so the heavy evidence accumulates without a heavy daily writing burden on the pharmacist. The pharmacist's job becomes less to write documentation than to work within systems designed to capture it, and to ensure the capture is happening for the uses that matter, which is a design problem the pharmacy solves once rather than a task the individual repeats endlessly.
Building the Record as the Work Happens
The single most important operational lesson about audit-grade documentation is that it cannot be reconstructed under pressure, it has to be built as the work is done, and Elena's predicament is the cautionary tale. When the reviewer says "show me," the records either already exist, contemporaneous and attributable, or they do not, and there is no honest way to manufacture a contemporaneous record after the fact, because the very property that gives it weight, that it was made at the time by the person who did the work, cannot be recreated later. A pharmacy that waits until an accreditation deadline to think about documentation discovers that the evidence it most needs, the record of who verified what and what the AI originally produced, has already evaporated into the past and the transient state of systems that did not retain it.
This is why the practical wisdom is to design the documentation into the workflow now, before any reviewer asks, so that the evidence is produced as a natural consequence of doing the work rather than as a frantic, partial reconstruction afterward. The advantages compound. Readiness is the obvious one: when the review comes, the records are already there. But there is a subtler benefit, which is that designing for audit-grade evidence tends to improve the practice itself, because a workflow built to capture who verified what, against which source, with the AI's original output preserved, is a workflow that makes verification harder to skip and easier to do consistently. The documentation requirement, properly designed in, becomes a forcing function for the underlying discipline, not merely a record of it. A pharmacy that builds the audit-grade record into its AI workflows from the start gets both the evidence and a stronger practice, and it never has to face Elena's moment of knowing something was true and being unable to prove it.
Walking Into the Review With Evidence
This lesson closes the quality, safety, and governance chapter, and with it the level, by tying the chapter's disciplines to the standard they ultimately answer to. The hallucination-catching workflow produces verification records. The bias and equity monitoring produces the disparate-performance findings and responses that governance documentation captures. The competency this program develops, retained as a completion record, is the competency evidence the user track expects. And the audit-grade standard is what shapes all of it into records that survive a skeptical review. The picture that emerges is coherent: a pharmacy does the right things with AI, catches the dangerous output, watches for the quiet disparity, keeps its people competent, and builds the contemporaneous, attributable, reconstructable record of all of it as the work happens, so that when an accreditor, a board, or a court says "show me," the answer is evidence rather than assurance.
The awareness to carry forward into the hands-on levels that follow is that competent, governed AI use and the documentation of it are not two separate jobs but one. The verification you do is also the verification record you build; the equity you monitor is also the governance evidence you retain; the discipline you practice is also the proof you can show. URAC's user track is, in the end, an external party asking to see exactly the evidence that a pharmacy practicing the disciplines of this chapter would naturally produce, if it builds the record as it works rather than reconstructing it under pressure. The pharmacy that internalizes this, that treats documentation not as the boring administrative tail of AI use but as the durable form of its good practice, is the one that is not only safe but demonstrably safe, governed not only in fact but in evidence, and ready for the review before the reviewer ever arrives. That readiness is the exit state of this level, and it is the foundation on which the strategic and enterprise work of the levels above is built, because everything those levels scale rests on a pharmacy's ability to show, and not merely assert, that its AI use is sound.
Key Takeaways
- URAC (Utilization Review Accreditation Commission) launched the first national Health Care AI Accreditation with separate developer and user tracks; a pharmacy lives under the user track, which asks it to demonstrate competent, governed AI use, and functions as the buyer trigger payers and partners increasingly want satisfied.
- Accreditation makes concrete the principle that undocumented good practice is indistinguishable from no practice: the review does not test whether you believe you practiced well, but whether you can demonstrate it with records a trained skeptic who was not present will accept.
- Audit-grade documentation has specific properties: contemporaneous (made at the time, not reconstructed), attributable (identifies the specific person), reconstructable (lets a later reader answer what the AI produced, what the human changed, and what was decided), and reliably retained or tamper-evident.
- The most painful gap is reconstructability: a system that shows only the corrected end state erases the evidence of the human verification, which was the entire point of the record, so the AI's original output and the human's changes must both be preserved.
- The user track expects four record types: verification records (proof an identifiable human checked the output against the source), audit trails (reconstructable event records), governance documentation (policies, roles, accountability, and bias monitoring, where the equity work becomes audit-grade), and competency records (who was trained, on what, when).
- Documentation should be proportionate to the stakes, thorough for high-stakes clinical uses like prior authorization and order verification, lighter for low-stakes operational uses like inventory forecasts; uniform maximal paperwork often signals a pharmacy that does not understand its own risk.
- Well-designed systems capture most high-stakes evidence automatically as a byproduct of the workflow (what the AI produced, what the human changed, who approved), so the pharmacist's job is to work within capture-designed systems rather than to write documentation by hand.
- Audit-grade records cannot be reconstructed under pressure; they must be built as the work happens, because a contemporaneous, attributable record cannot honestly be manufactured after the fact, and designing the documentation into the workflow early both ensures readiness and strengthens the underlying verification discipline.
Skill.re