[{"data":1,"prerenderedAt":6089},["ShallowReactive",2],{"blog-list":3},[4,260,604,821,1062,1503,1681,1819,1926,2035,2122,2215,2380,2670,3084,3207,3560,3831,3947,4073,4288,4482,4619,4714,4837,4984,5100,5349,5442,5597,5713,5827,5943],{"id":5,"title":6,"author":7,"body":8,"category":241,"date":242,"description":243,"draft":244,"excerpt":245,"extension":246,"heroImage":245,"heroImageAlt":245,"meta":247,"navigation":248,"path":249,"seo":250,"slug":245,"stem":251,"tags":252,"__hash__":259},"blog\u002Fblog\u002Fcalibration-register-just-a-spreadsheet-validation.md","My Calibration Register Is Just a Spreadsheet. Does It Really Need Validation?","QikSolve",{"type":9,"value":10,"toc":231},"minimark",[11,15,18,21,26,29,51,65,69,72,98,101,105,108,139,143,146,178,182,185,199,207,211,224],[12,13,14],"p",{},"\"It's just a spreadsheet\" is one of the most common phrases heard when discussing calibration\nregisters in GMP facilities. Usually it is true, in the sense that the file does not calculate\nanything or make a GMP decision. It simply records what has already happened.",[12,16,17],{},"That does not mean the register is automatically outside the scope of validation thinking. It\nmeans the validation approach can be proportionate to what the spreadsheet actually does.",[12,19,20],{},"This article is a practical interpretation of a common register scenario. It is not a validation\nprotocol or a determination that any specific spreadsheet is compliant. Your organisation's own\nrisk assessment, quality system, and the applicable regulatory expectations remain the controlling\nreferences.",[22,23,25],"h2",{"id":24},"the-scenario","The scenario",[12,27,28],{},"A typical calibration register spreadsheet contains:",[30,31,32,36,39,42,45,48],"ul",{},[33,34,35],"li",{},"Equipment ID",[33,37,38],{},"Last calibration date",[33,40,41],{},"Next due date",[33,43,44],{},"Certificate reference",[33,46,47],{},"Equipment location",[33,49,50],{},"Comments",[12,52,53,54,59,60,64],{},"There are no GMP calculations. There is no decision-making logic. The spreadsheet is a structured\nlist, what we describe in our\n",[55,56,58],"a",{"href":57},"\u002Fblog\u002Fhidden-validation-cost-of-excel-registers-in-gmp","maturity model for GMP spreadsheets"," as a\n",[61,62,63],"strong",{},"register spreadsheet",", the first and lowest-risk level.",[22,66,68],{"id":67},"what-inspectors-tend-to-focus-on","What inspectors tend to focus on",[12,70,71],{},"Regardless of whether a register is a spreadsheet or a formal system, the underlying data\nintegrity expectations are the same. An inspector reviewing a calibration register is typically\ninterested in:",[30,73,74,80,86,92],{},[33,75,76,79],{},[61,77,78],{},"Data integrity."," Can the organisation show the record has not been altered inappropriately?",[33,81,82,85],{},[61,83,84],{},"Accuracy."," Do the dates and references in the register match the underlying certificates?",[33,87,88,91],{},[61,89,90],{},"Traceability."," Can a specific piece of equipment be traced to its calibration history and\nsupporting certificate?",[33,93,94,97],{},[61,95,96],{},"Evidence."," Is there something to show, beyond \"we've always done it this way,\" that the\nregister is maintained and reviewed?",[12,99,100],{},"None of these questions require the register to have been through a full software validation\nlifecycle. They do require the organisation to be able to answer them with more than an assumption.",[22,102,104],{"id":103},"common-risks-in-a-register-like-this","Common risks in a register like this",[12,106,107],{},"Even a simple register carries recognisable risks:",[30,109,110,116,122,133],{},[33,111,112,115],{},[61,113,114],{},"Manual transcription errors",", where a date or reference is typed incorrectly when copying from\na certificate.",[33,117,118,121],{},[61,119,120],{},"Missing calibration certificates",", where the register shows a date but the supporting document\ncannot be located.",[33,123,124,127,128,132],{},[61,125,126],{},"Formula corruption",", if a due-date calculation (",[129,130,131],"code",{},"= [Last calibration date] + 365",", for example)\nis accidentally overwritten in a cell.",[33,134,135,138],{},[61,136,137],{},"Poor version control",", with several copies of the register circulating across email or shared\ndrives, each slightly out of date.",[22,140,142],{"id":141},"what-validation-evidence-may-be-needed","What validation evidence may be needed",[12,144,145],{},"For a register at this level, a pragmatic, risk-based approach is usually more appropriate than a\nfull software validation lifecycle. Evidence that is commonly useful includes:",[30,147,148,154,160,166,172],{},[33,149,150,153],{},[61,151,152],{},"Intended use",": a short statement of what the register is used for, and what it is not used\nfor (for example, it does not calculate pass\u002Ffail status).",[33,155,156,159],{},[61,157,158],{},"Risk assessment",": an assessment of what could go wrong (missing certificate, wrong date,\noverwritten formula) and how likely and significant that is.",[33,161,162,165],{},[61,163,164],{},"Formula verification",": where any calculation exists (even a simple due-date formula), a check\nthat it produces the expected result.",[33,167,168,171],{},[61,169,170],{},"Change control",": a record of how the register's structure, formulas, or fields are changed and\nby whom.",[33,173,174,177],{},[61,175,176],{},"Validation report or summary",": a short document that ties the above together and states the\nregister is fit for its intended use.",[22,179,181],{"id":180},"when-excel-may-still-be-acceptable","When Excel may still be acceptable",[12,183,184],{},"Excel is not automatically the wrong tool for a register like this. Where the register:",[30,186,187,190,193,196],{},[33,188,189],{},"only records dates, references, and status information;",[33,191,192],{},"has no formulas that determine equipment fitness for use or product disposition;",[33,194,195],{},"has a small number of controlled editors; and",[33,197,198],{},"is backed by a defined review and certificate-filing process,",[12,200,201,202,206],{},"a lightweight, proportionate validation approach can often be justified without moving to a new\nplatform. The risk changes materially once the spreadsheet starts calculating anything the\norganisation relies on to make a GMP decision. That scenario is covered in\n",[55,203,205],{"href":204},"\u002Fblog\u002Fwhen-your-spreadsheet-starts-making-gmp-decisions","When Your Spreadsheet Starts Making GMP Decisions",".",[22,208,210],{"id":209},"a-proportionate-next-step","A proportionate next step",[12,212,213,214,218,219,223],{},"Not sure whether your calibration register requires formal validation, or what level of evidence is\nenough? A structured ",[55,215,217],{"href":216},"\u002Fvalidate-quality-register","Annex 11 spreadsheet assessment"," can classify the\nrisk and recommend whether the register should be retained with light-touch controls, remediated\nwith formal evidence, or migrated to a governed SharePoint register. See\n",[55,220,222],{"href":221},"\u002Fblog\u002Fannex-11-in-plain-english","Annex 11 in Plain English"," for the underlying computerised-systems\nquestions this assessment draws on.",[12,225,226,230],{},[55,227,229],{"href":228},"\u002Fcontact","Book a discovery call"," to talk through your calibration register and the evidence you\nmay already have.",{"title":232,"searchDepth":233,"depth":233,"links":234},"",2,[235,236,237,238,239,240],{"id":24,"depth":233,"text":25},{"id":67,"depth":233,"text":68},{"id":103,"depth":233,"text":104},{"id":141,"depth":233,"text":142},{"id":180,"depth":233,"text":181},{"id":209,"depth":233,"text":210},"Compliance","2026-09-14","A calibration register that only tracks equipment IDs, dates, and certificate references is a different risk to a spreadsheet that calculates pass or fail. A practical, risk-based look at what validation it may actually need.",false,null,"md",{},true,"\u002Fblog\u002Fcalibration-register-just-a-spreadsheet-validation",{"title":6,"description":243},"blog\u002Fcalibration-register-just-a-spreadsheet-validation",[253,254,255,256,257,258],"calibration","excel","annex-11","validation","gmp","spreadsheets","SNW155ZKlBQMEWngyY8AjmmyJweg5L5lX6B3QOqyMuo",{"id":261,"title":262,"author":7,"body":263,"category":241,"date":242,"description":596,"draft":244,"excerpt":245,"extension":246,"heroImage":245,"heroImageAlt":245,"meta":597,"navigation":248,"path":57,"seo":598,"slug":245,"stem":599,"tags":600,"__hash__":603},"blog\u002Fblog\u002Fhidden-validation-cost-of-excel-registers-in-gmp.md","The Hidden Validation Cost of Excel Registers in GMP Environments",{"type":9,"value":264,"toc":583},[265,268,271,274,283,286,290,293,296,299,304,307,311,314,318,321,324,328,331,360,363,367,370,470,478,482,485,505,508,512,515,534,550,554,557,578],[12,266,267],{},"Most GMP organisations still run on spreadsheets. Calibration registers, equipment logs, training\nmatrices, risk registers, and more than a few \"temporary\" trackers that quietly became permanent.\nExcel earns that trust because it is familiar, flexible, and appears to cost nothing to set up.",[12,269,270],{},"The cost only becomes visible later, and it rarely shows up in the IT budget. It shows up in the\nhours spent preparing for an inspection, defending a formula nobody remembers building, or proving\nthat a register nobody formally validated is still fit for purpose.",[12,272,273],{},"The useful question has quietly changed.",[275,276,277,280],"blockquote",{},[12,278,279],{},"It used to be: \"Can Excel do it?\"",[12,281,282],{},"It is now: \"Can we demonstrate control, accuracy, data integrity, and compliance?\"",[12,284,285],{},"This article sets out a practical, risk-based way to answer that question, and where a governed\nSharePoint pathway may reduce the ongoing burden. It is a practical interpretation, not a\nvalidation protocol or a determination that any specific spreadsheet is or is not compliant. The\napplicable regulatory expectations (including Annex 11 themes referenced by EU and TGA GMP\ninspectors, and the equivalent expectations FDA inspectors apply), the organisation's own risk\nassessment, and its quality system remain the controlling references.",[22,287,289],{"id":288},"not-every-spreadsheet-needs-the-same-validation-effort","Not every spreadsheet needs the same validation effort",[12,291,292],{},"A common mistake is treating every spreadsheet the same way: either \"it's just Excel, it's fine\"\nor \"every spreadsheet must go through full software validation.\" Neither position holds up well\nin practice.",[12,294,295],{},"Validation effort should scale with what the spreadsheet actually does and what happens if it is\nwrong. A simple calibration log that only records dates and certificate references carries a very\ndifferent risk profile to a spreadsheet that calculates pass\u002Ffail status against a specification\nlimit.",[12,297,298],{},"A useful way to see this is a three-level maturity model.",[300,301,303],"h3",{"id":302},"level-1-register-spreadsheet","Level 1: Register spreadsheet",[12,305,306],{},"Records information. IDs, dates, references, locations, comments. No calculations, no\ndecision-making logic. The spreadsheet is a structured list, not a system.",[300,308,310],{"id":309},"level-2-decision-support-spreadsheet","Level 2: Decision-support spreadsheet",[12,312,313],{},"Contains formulas that interpret data: pass\u002Ffail calculations, tolerance checks, status flags,\ntrend indicators. The spreadsheet now influences a GMP decision, even if a person still signs off\non the outcome.",[300,315,317],{"id":316},"level-3-quality-critical-spreadsheet","Level 3: Quality-critical spreadsheet",[12,319,320],{},"Drives GMP decisions directly, feeds other systems or reports, or replaces a controlled record.\nComplex formula chains, macros, or multiple dependent tabs are common at this level.",[12,322,323],{},"Validation effort increases sharply at each level, and it rarely increases in a straight line. A\nregister that takes a few hours to assess can sit next to a decision-support spreadsheet that needs\nformal requirements, risk assessment, and formula verification.",[22,325,327],{"id":326},"what-tends-to-drive-the-effort-up","What tends to drive the effort up",[12,329,330],{},"Regardless of which level a spreadsheet sits at, the same practical risks show up repeatedly:",[30,332,333,338,343,348,354],{},[33,334,335,337],{},[61,336,114],{}," between certificates, instruments, and the register.",[33,339,340,342],{},[61,341,126],{}," where a cell is overwritten, a range shifts, or a copy-paste breaks a\ncalculation without anyone noticing.",[33,344,345,347],{},[61,346,137],{},", with multiple copies in email, shared drives, and local desktops.",[33,349,350,353],{},[61,351,352],{},"Limited audit trails",", so it is difficult to show who changed what, and when.",[33,355,356,359],{},[61,357,358],{},"No record of intended use, risk assessment, or verification",", so there is little to point to\nwhen someone asks how the organisation knows the spreadsheet works.",[12,361,362],{},"None of these risks mean Excel is inherently non-compliant. They mean that as reliance on the\nspreadsheet grows, the organisation needs a clearer answer to the control questions an inspector is\nlikely to ask.",[22,364,366],{"id":365},"where-sharepoint-changes-the-equation","Where SharePoint changes the equation",[12,368,369],{},"Many organisations already hold a Microsoft 365 licence that includes SharePoint. That means a\nnumber of controls that have to be built manually around a spreadsheet already exist natively in a\nSharePoint list:",[371,372,373,389],"table",{},[374,375,376],"thead",{},[377,378,379,383,386],"tr",{},[380,381,382],"th",{},"Capability",[380,384,385],{},"Excel",[380,387,388],{},"SharePoint list",[390,391,392,404,415,426,437,448,459],"tbody",{},[377,393,394,398,401],{},[395,396,397],"td",{},"Version control",[395,399,400],{},"Manual, multiple copies",[395,402,403],{},"Native version history",[377,405,406,409,412],{},[395,407,408],{},"Audit trail",[395,410,411],{},"Limited or absent",[395,413,414],{},"Native change history",[377,416,417,420,423],{},[395,418,419],{},"Access control",[395,421,422],{},"Weak, often shared files",[395,424,425],{},"Native permissions",[377,427,428,431,434],{},[395,429,430],{},"Certificate attachment",[395,432,433],{},"Separate file location",[395,435,436],{},"Native, linked to the record",[377,438,439,442,445],{},[395,440,441],{},"Reminders",[395,443,444],{},"Manual",[395,446,447],{},"Automatable (for example, Power Automate)",[377,449,450,453,456],{},[395,451,452],{},"Review evidence",[395,454,455],{},"Manual compilation",[395,457,458],{},"Native views and reports",[377,460,461,464,467],{},[395,462,463],{},"Validation effort",[395,465,466],{},"Concentrated on formula logic and process control",[395,468,469],{},"Concentrated on configuration and process verification",[12,471,472,473,477],{},"This is not a claim that SharePoint requires zero validation, or that migrating is free. It is an\nobservation that the effort shifts: away from re-proving spreadsheet logic and manual process\ncontrol, and towards verifying that the list is configured, permissioned, and used as intended. Our\n",[55,474,476],{"href":475},"\u002Fblog\u002Fvalidating-a-sharepoint-quality-register","worked SharePoint quality-register validation example","\nsets out what that evidence can look like for a comparable register.",[22,479,481],{"id":480},"a-structured-way-to-decide","A structured way to decide",[12,483,484],{},"Rather than defaulting to \"replace everything\" or \"leave everything alone,\" a structured spreadsheet\nassessment can identify, register by register, whether it should be:",[30,486,487,493,499],{},[33,488,489,492],{},[61,490,491],{},"Retained",", with lightweight, proportionate controls;",[33,494,495,498],{},[61,496,497],{},"Remediated",", with formal requirements, risk assessment, and validation evidence; or",[33,500,501,504],{},[61,502,503],{},"Migrated",", to a governed SharePoint list where the ongoing burden is likely to be lower.",[12,506,507],{},"The right answer depends on what the spreadsheet does today, and what it is likely to be asked to\ndo next year.",[22,509,511],{"id":510},"where-this-pillar-leads","Where this pillar leads",[12,513,514],{},"This article introduces the maturity model. Three companion articles work through it in more\ndetail:",[30,516,517,522,527],{},[33,518,519,521],{},[55,520,6],{"href":249},"\nlooks at a Level 1 register spreadsheet.",[33,523,524,526],{},[55,525,205],{"href":204},"\nlooks at what changes once formulas start deciding pass\u002Ffail status.",[33,528,529,533],{},[55,530,532],{"href":531},"\u002Fblog\u002Fwhy-sharepoint-can-be-easier-to-validate-than-excel","The Spreadsheet Trap: Why SharePoint Can Be Easier to Validate Than Excel","\ncompares the ongoing validation burden of each platform using the same calibration example.",[12,535,536,537,541,542,546,547,549],{},"For broader context on quality registers generally (not only calibration), see\n",[55,538,540],{"href":539},"\u002Fblog\u002Fhidden-compliance-risk-excel-registers","The Hidden Compliance Risk in Your Excel Registers",",\n",[55,543,545],{"href":544},"\u002Fblog\u002Fbeyond-excel-gxp-quality-registers-sharepoint-lists","Beyond Excel: A Practical GxP Approach to Quality Registers Using SharePoint Lists",",\nand ",[55,548,222],{"href":221}," for the underlying computerised-systems\nthemes.",[22,551,553],{"id":552},"where-to-start","Where to start",[12,555,556],{},"Excel is not the problem. Lack of control is the problem. The goal is not to eliminate spreadsheets;\nit is to apply the right level of control based on risk, and to be able to demonstrate it.",[12,558,559,560,563,564,568,569,573,574,206],{},"If you are not sure which level your spreadsheets sit at, start with a\n",[55,561,562],{"href":216},"GMP spreadsheet assessment"," to get a risk classification and a\nrecommended next step for each register. Where migration is the right answer, our\n",[55,565,567],{"href":566},"\u002Fexcel-register-to-sharepoint","Excel-to-SharePoint assessment and implementation support"," can help\nplan the register, certificate, and workflow migration alongside the evidence you need to support\nit. For the wider platform context, see\n",[55,570,572],{"href":571},"\u002Fproduct\u002Fsharepoint-governance","SharePoint governance and configuration"," and\n",[55,575,577],{"href":576},"\u002Fproduct\u002Fquality-systems","practical GxP quality systems",[12,579,580,582],{},[55,581,229],{"href":228}," to talk through your spreadsheet register and the most\nproportionate next step.",{"title":232,"searchDepth":233,"depth":233,"links":584},[585,591,592,593,594,595],{"id":288,"depth":233,"text":289,"children":586},[587,589,590],{"id":302,"depth":588,"text":303},3,{"id":309,"depth":588,"text":310},{"id":316,"depth":588,"text":317},{"id":326,"depth":233,"text":327},{"id":365,"depth":233,"text":366},{"id":480,"depth":233,"text":481},{"id":510,"depth":233,"text":511},{"id":552,"depth":233,"text":553},"Excel looks like the cheapest option for GMP registers until you count the effort needed to demonstrate control, accuracy, and data integrity. A risk-based way to decide what a spreadsheet actually needs.",{},{"title":262,"description":596},"blog\u002Fhidden-validation-cost-of-excel-registers-in-gmp",[254,258,255,256,257,601,602],"sharepoint","quality-management","_44AeMIvhvByf7zGPbopQ2uRo8YNJWC4Dt9y4od52Z4",{"id":605,"title":205,"author":7,"body":606,"category":241,"date":242,"description":815,"draft":244,"excerpt":245,"extension":246,"heroImage":245,"heroImageAlt":245,"meta":816,"navigation":248,"path":204,"seo":817,"slug":245,"stem":818,"tags":819,"__hash__":820},"blog\u002Fblog\u002Fwhen-your-spreadsheet-starts-making-gmp-decisions.md",{"type":9,"value":607,"toc":807},[608,611,614,616,623,640,643,652,655,659,662,676,686,690,693,723,727,730,747,750,754,757,783,786,790,796,802],[12,609,610],{},"Most GMP spreadsheets start life as simple registers. Somewhere along the way, a formula gets\nadded to save someone the trouble of checking a result against a specification by hand. That\nformula is usually welcomed as a convenience. It rarely gets treated as the moment the spreadsheet\nchanged category.",[12,612,613],{},"This article is a practical interpretation of that scenario, not a validation protocol or a\ndetermination that any specific spreadsheet is compliant. Your organisation's own risk assessment\nand quality system remain the controlling references.",[22,615,25],{"id":24},[12,617,618,619,622],{},"Building on the ",[55,620,621],{"href":249},"calibration register example",",\nimagine the same spreadsheet now also contains:",[30,624,625,628,631,634,637],{},[33,626,627],{},"Calibration values",[33,629,630],{},"Specification limits",[33,632,633],{},"Pass\u002Ffail calculations",[33,635,636],{},"Equipment status calculations",[33,638,639],{},"Trending data",[12,641,642],{},"A typical formula looks like this:",[644,645,650],"pre",{"className":646,"code":648,"language":649,"meta":232},[647],"language-text","=IF(ABS(Result-Target)\u003C=Tolerance,\"PASS\",\"FAIL\")\n","text",[129,651,648],{"__ignoreMap":232},[12,653,654],{},"Simple to write, and easy to trust once it has \"always worked.\" But this formula is now making a\nGMP decision that a person previously made by comparing numbers manually.",[22,656,658],{"id":657},"the-spreadsheet-trap","The spreadsheet trap",[12,660,661],{},"Many organisations still describe a spreadsheet like this as \"just Excel.\" In practice, it now\ndetermines:",[30,663,664,667,670,673],{},[33,665,666],{},"Equipment status (in calibration or out of calibration)",[33,668,669],{},"Compliance status against specification",[33,671,672],{},"Whether an investigation should be triggered",[33,674,675],{},"Whether a batch, process, or piece of equipment is reviewed further",[12,677,678,679,681,682,685],{},"In our ",[55,680,58],{"href":57},",\nthis is a ",[61,683,684],{},"decision-support spreadsheet",": Level 2. It is no longer acting as a register. It is\nacting as a small GMP application, built without the requirements, risk assessment, or testing that\nwould normally accompany one.",[22,687,689],{"id":688},"why-validation-expectations-increase","Why validation expectations increase",[12,691,692],{},"Once a formula decides pass or fail, the questions an assessment needs to answer expand:",[30,694,695,701,706,711,717],{},[33,696,697,700],{},[61,698,699],{},"Requirements",": what is the formula supposed to do, and under what conditions?",[33,702,703,705],{},[61,704,158],{},": what happens if the formula is wrong, and how would the organisation notice?",[33,707,708,710],{},[61,709,164],{},": has the formula been checked against known, expected results?",[33,712,713,716],{},[61,714,715],{},"Boundary testing",": what happens at the edge of tolerance, with a blank cell, a negative\nnumber, or a rounding difference?",[33,718,719,722],{},[61,720,721],{},"Traceability",": can a specific pass\u002Ffail decision be traced back to the values and formula\nversion that produced it?",[22,724,726],{"id":725},"what-an-auditor-might-ask","What an auditor might ask",[12,728,729],{},"A reasonable inspector or auditor reviewing a spreadsheet like this may ask:",[30,731,732,735,738,741,744],{},[33,733,734],{},"How were these formulae verified?",[33,736,737],{},"How do you know the results are accurate?",[33,739,740],{},"How are the specification limits controlled, and who can change them?",[33,742,743],{},"What happens if someone edits the formula by mistake, and how would you know?",[33,745,746],{},"Can you show me the version history for this file?",[12,748,749],{},"These are fair questions. A spreadsheet performing a GMP calculation deserves the same scrutiny\nthat any other tool making that decision would receive.",[22,751,753],{"id":752},"the-hidden-cost","The hidden cost",[12,755,756],{},"The cost of this stage is rarely visible on a project plan. It shows up as ongoing effort:",[30,758,759,765,771,777],{},[33,760,761,764],{},[61,762,763],{},"Review effort",", checking that formulas have not silently changed.",[33,766,767,770],{},[61,768,769],{},"Periodic review",", re-confirming the spreadsheet still does what it was built to do.",[33,772,773,776],{},[61,774,775],{},"Retesting",", whenever a specification limit, tolerance, or formula structure changes.",[33,778,779,782],{},[61,780,781],{},"Change control burden",", tracking who changed what, and when, in a tool that was never designed\nfor that purpose.",[12,784,785],{},"This effort accumulates quietly, and it tends to be highest for the spreadsheets that are relied on\nmost.",[22,787,789],{"id":788},"a-more-proportionate-path","A more proportionate path",[12,791,792,793,795],{},"The goal is not to panic and rebuild every spreadsheet with a formula in it. It is to recognise\nthat a decision-support spreadsheet needs a different level of evidence than a register, and to\ndecide, deliberately, whether Excel remains the right platform for that decision once the ongoing\neffort is counted.\n",[55,794,532],{"href":531},"\ncompares that ongoing effort directly using the same calibration example.",[12,797,798,799,801],{},"If your spreadsheet can determine pass or fail status, it may require significantly more validation\nthan you expect. A ",[55,800,562],{"href":216}," can help classify the\nrisk and identify what evidence is genuinely needed.",[12,803,804,806],{},[55,805,229],{"href":228}," to discuss a spreadsheet that has started making GMP decisions.",{"title":232,"searchDepth":233,"depth":233,"links":808},[809,810,811,812,813,814],{"id":24,"depth":233,"text":25},{"id":657,"depth":233,"text":658},{"id":688,"depth":233,"text":689},{"id":725,"depth":233,"text":726},{"id":752,"depth":233,"text":753},{"id":788,"depth":233,"text":789},"Once a spreadsheet calculates pass or fail, status, or trend, it is no longer just a register. A practical look at what validation, evidence, and audit questions change once formulas start deciding GMP outcomes.",{},{"title":205,"description":815},"blog\u002Fwhen-your-spreadsheet-starts-making-gmp-decisions",[254,257,256,255,258,253],"15gi7XMsxt1rfzHMyfV9tzoSNTwcx39RqxXOoeG2Xeo",{"id":822,"title":532,"author":7,"body":823,"category":241,"date":242,"description":1056,"draft":244,"excerpt":245,"extension":246,"heroImage":245,"heroImageAlt":245,"meta":1057,"navigation":248,"path":531,"seo":1058,"slug":245,"stem":1059,"tags":1060,"__hash__":1061},"blog\u002Fblog\u002Fwhy-sharepoint-can-be-easier-to-validate-than-excel.md",{"type":9,"value":824,"toc":1048},[825,828,831,841,845,848,884,888,891,929,933,996,999,1003,1006,1009,1018,1022,1025,1029,1032,1043],[12,826,827],{},"Most organisations assume that moving a GMP register to SharePoint means taking on more validation\nwork, not less. It is an understandable assumption. SharePoint is a Microsoft 365 platform, and\nExcel is \"just a file.\"",[12,829,830],{},"In practice, the opposite is often true once a spreadsheet has grown beyond a simple register. A\ngoverned SharePoint list already provides several of the controls that would otherwise have to be\nbuilt, and re-verified, around a spreadsheet by hand.",[12,832,833,834,837,838,840],{},"This article compares the ongoing validation burden of each platform using the same calibration\nregister example from ",[55,835,836],{"href":249},"My Calibration Register Is Just a Spreadsheet","\nand ",[55,839,205],{"href":204},".\nIt is a practical interpretation, not a validation protocol or a determination that any specific\nsolution is compliant.",[22,842,844],{"id":843},"where-excels-validation-burden-tends-to-sit","Where Excel's validation burden tends to sit",[12,846,847],{},"As a register or decision-support spreadsheet matures, most of the ongoing validation effort\nconcentrates on:",[30,849,850,855,860,866,872,878],{},[33,851,852,854],{},[61,853,164],{},", re-checking that calculations still produce correct results after\nevery change.",[33,856,857,859],{},[61,858,397],{},", because a spreadsheet is easy to copy, and hard to keep a single\nauthoritative version of.",[33,861,862,865],{},[61,863,864],{},"Multiple versions",", circulating across email, shared drives, and local machines.",[33,867,868,871],{},[61,869,870],{},"Audit trail limitations",", since standard Excel files provide limited visibility into who\nchanged what, and when.",[33,873,874,877],{},[61,875,876],{},"Manual reminders",", for due dates, reviews, and expiring certificates.",[33,879,880,883],{},[61,881,882],{},"Manual reviews",", because there is no native workflow to confirm a review has happened.",[22,885,887],{"id":886},"what-sharepoint-provides-natively","What SharePoint provides natively",[12,889,890],{},"A SharePoint list, configured for the intended use, already includes:",[30,892,893,899,905,911,917,923],{},[33,894,895,898],{},[61,896,897],{},"Version history",", recording changes over time without extra tooling.",[33,900,901,904],{},[61,902,903],{},"Metadata",", structured fields instead of free-text cells that can be typed incorrectly.",[33,906,907,910],{},[61,908,909],{},"Permissions",", separating who can view a record from who can edit it.",[33,912,913,916],{},[61,914,915],{},"Auditability",", a native change history for list items.",[33,918,919,922],{},[61,920,921],{},"Document attachment",", so a certificate can be attached directly to its equipment record.",[33,924,925,928],{},[61,926,927],{},"Workflow automation",", for example, Power Automate reminders ahead of a due date.",[22,930,932],{"id":931},"the-calibration-register-example","The calibration register example",[371,934,935,945],{},[374,936,937],{},[377,938,939,941,943],{},[380,940],{},[380,942,385],{},[380,944,388],{},[390,946,947,958,968,977,987],{},[377,948,949,952,955],{},[395,950,951],{},"Register",[395,953,954],{},"Separate spreadsheet",[395,956,957],{},"Controlled list",[377,959,960,963,965],{},[395,961,962],{},"Certificate",[395,964,433],{},[395,966,967],{},"Attached to the record",[377,969,970,972,974],{},[395,971,441],{},[395,973,444],{},[395,975,976],{},"Automated",[377,978,979,982,984],{},[395,980,981],{},"Review",[395,983,455],{},[395,985,986],{},"Native views and history",[377,988,989,991,994],{},[395,990,397],{},[395,992,993],{},"Multiple copies",[395,995,403],{},[12,997,998],{},"The comparison is not \"SharePoint is better.\" It is that several of the controls a spreadsheet\nneeds built and maintained by hand are already present in a properly configured list.",[22,1000,1002],{"id":1001},"the-validation-comparison","The validation comparison",[12,1004,1005],{},"This does not mean SharePoint needs no validation. It means the assessment focuses on different\nthings.",[12,1007,1008],{},"Validating a spreadsheet that calculates pass\u002Ffail status typically means proving the formula\nlogic is correct, verified, and has not silently changed. Validating an equivalent SharePoint list\ntypically means confirming the configuration (fields, required values, permissions, and any\nautomation) matches what was intended, and that reports or views reflect the underlying data\ncorrectly.",[12,1010,1011,1012,1014,1015,1017],{},"In other words, the effort shifts from re-proving spreadsheet logic towards verifying configuration\nand process. Our\n",[55,1013,476],{"href":475},"\nsets out what that evidence pack can look like, and\n",[55,1016,545],{"href":544},"\nexplains the record-versus-register distinction that keeps the paper or controlled record\nauthoritative where that is the intended boundary.",[22,1019,1021],{"id":1020},"the-economic-case","The economic case",[12,1023,1024],{},"The more critical a spreadsheet becomes to a GMP decision, the stronger the case for moving it. A\nsimple register with no formulas may not need to move at all. A spreadsheet calculating pass\u002Ffail\nstatus, feeding trend reports, or triggering investigations is exactly the kind of tool where the\nongoing cost of maintaining, reviewing, and defending Excel logic can exceed the cost of a\none-time, proportionate migration.",[22,1026,1028],{"id":1027},"assess-before-you-migrate","Assess before you migrate",[12,1030,1031],{},"The question is not whether SharePoint needs validation. It is whether it is easier to validate,\nand cheaper to maintain, than the spreadsheet it would replace. That answer is different for every\nregister, which is why an assessment should come before a migration decision.",[12,1033,1034,1037,1038,1040,1041,206],{},[55,1035,1036],{"href":216},"Assess whether your spreadsheet should be retained, remediated, or migrated",",\nand where migration is the right answer, see our\n",[55,1039,567],{"href":566}," for what\nthat work can include. For the wider platform context, see\n",[55,1042,572],{"href":571},[12,1044,1045,1047],{},[55,1046,229],{"href":228}," to talk through a spreadsheet that may be more expensive to keep\nthan to migrate.",{"title":232,"searchDepth":233,"depth":233,"links":1049},[1050,1051,1052,1053,1054,1055],{"id":843,"depth":233,"text":844},{"id":886,"depth":233,"text":887},{"id":931,"depth":233,"text":932},{"id":1001,"depth":233,"text":1002},{"id":1020,"depth":233,"text":1021},{"id":1027,"depth":233,"text":1028},"Most organisations assume SharePoint requires more validation effort than Excel. In practice, many of the controls a spreadsheet needs built around it already exist natively in a governed SharePoint list.",{},{"title":532,"description":1056},"blog\u002Fwhy-sharepoint-can-be-easier-to-validate-than-excel",[601,254,256,255,257,253],"jdFsICt9KQa39Y5pnvSS9VvKMU0Or_5sxRqm_6bDnA8",{"id":1063,"title":540,"author":7,"body":1064,"category":241,"date":1495,"description":1496,"draft":244,"excerpt":245,"extension":246,"heroImage":245,"heroImageAlt":245,"meta":1497,"navigation":248,"path":539,"seo":1498,"slug":245,"stem":1499,"tags":1500,"__hash__":1502},"blog\u002Fblog\u002Fhidden-compliance-risk-excel-registers.md",{"type":9,"value":1065,"toc":1475},[1066,1069,1072,1075,1078,1083,1086,1090,1093,1096,1099,1122,1125,1129,1132,1136,1139,1142,1159,1162,1166,1169,1172,1175,1179,1182,1185,1190,1193,1198,1201,1205,1209,1212,1215,1226,1230,1233,1236,1246,1249,1252,1255,1266,1269,1273,1276,1279,1282,1287,1290,1295,1299,1302,1304,1325,1328,1330,1353,1356,1360,1363,1366,1380,1383,1386,1406,1409,1412,1416,1419,1424,1427,1432,1435,1439,1442,1445,1448,1451,1455,1458,1461,1472],[12,1067,1068],{},"Walk into almost any regulated organisation and you will find spreadsheets supporting critical\nbusiness processes.",[12,1070,1071],{},"Training records. Supplier registers. Equipment logs. Calibration schedules. Risk registers.\nChange controls.",[12,1073,1074],{},"Excel is often the tool that fills the gap between paper-based systems and expensive enterprise\nplatforms. The problem is that spreadsheets frequently evolve from a simple tracking tool into a\nbusiness-critical system without anyone noticing.",[12,1076,1077],{},"Everything works perfectly until an auditor asks a simple question:",[275,1079,1080],{},[12,1081,1082],{},"\"How do you know this register is fit for its intended use?\"",[12,1084,1085],{},"For many organisations, that is when the real risk becomes apparent.",[22,1087,1089],{"id":1088},"the-problem-isnt-excel","The problem isn't Excel",[12,1091,1092],{},"Let's be clear.",[12,1094,1095],{},"Excel itself is not inherently non-compliant. Many organisations use spreadsheets successfully for\nyears. The real issue is that critical registers often lack the governance controls required to\nshow control, accuracy and reliability.",[12,1097,1098],{},"Questions auditors commonly ask include:",[30,1100,1101,1104,1107,1110,1113,1116,1119],{},[33,1102,1103],{},"Who can modify this register?",[33,1105,1106],{},"How are changes reviewed and approved?",[33,1108,1109],{},"How do you know formulas have not been altered?",[33,1111,1112],{},"How is data backed up?",[33,1114,1115],{},"How is access controlled?",[33,1117,1118],{},"What testing was performed before the register was released?",[33,1120,1121],{},"How do you demonstrate ongoing control?",[12,1123,1124],{},"In many cases, organisations have never formally considered these questions. The spreadsheet simply\nevolved over time and became part of day-to-day operations.",[22,1126,1128],{"id":1127},"the-journey-from-spreadsheet-to-system","The journey from spreadsheet to system",[12,1130,1131],{},"A common pattern looks like this.",[300,1133,1135],{"id":1134},"stage-1-simple-spreadsheet","Stage 1: simple spreadsheet",[12,1137,1138],{},"A department creates an Excel file to solve a local problem.",[12,1140,1141],{},"Examples include:",[30,1143,1144,1147,1150,1153,1156],{},[33,1145,1146],{},"Supplier registers",[33,1148,1149],{},"Training matrices",[33,1151,1152],{},"Equipment lists",[33,1154,1155],{},"Risk logs",[33,1157,1158],{},"Audit schedules",[12,1160,1161],{},"Initially there are only a handful of users and minimal complexity.",[300,1163,1165],{"id":1164},"stage-2-business-reliance","Stage 2: business reliance",[12,1167,1168],{},"Over time the spreadsheet becomes the primary source of information.",[12,1170,1171],{},"More users access it. Additional columns are added. Formulas become more complex. Reports depend on\nthe data. Management decisions rely on the information stored within it.",[12,1173,1174],{},"At this point the spreadsheet is effectively operating as a business application.",[300,1176,1178],{"id":1177},"stage-3-audit-or-inspection","Stage 3: audit or inspection",[12,1180,1181],{},"An external auditor reviews the process.",[12,1183,1184],{},"The focus is no longer:",[275,1186,1187],{},[12,1188,1189],{},"\"Does the spreadsheet exist?\"",[12,1191,1192],{},"The focus becomes:",[275,1194,1195],{},[12,1196,1197],{},"\"How is it controlled?\"",[12,1199,1200],{},"This is often where organisations discover they have little objective evidence demonstrating the\nspreadsheet is reliable and fit for purpose.",[22,1202,1204],{"id":1203},"typical-audit-concerns","Typical audit concerns",[300,1206,1208],{"id":1207},"lack-of-access-control","Lack of access control",[12,1210,1211],{},"If multiple users can edit a file without defined permissions, it becomes difficult to demonstrate\naccountability.",[12,1213,1214],{},"Questions arise around:",[30,1216,1217,1220,1223],{},[33,1218,1219],{},"Accidental changes",[33,1221,1222],{},"Unauthorised modifications",[33,1224,1225],{},"Data integrity",[300,1227,1229],{"id":1228},"formula-risk","Formula risk",[12,1231,1232],{},"Complex spreadsheets frequently contain formulas that have evolved over several years.",[12,1234,1235],{},"Without formal review and testing, organisations may struggle to demonstrate:",[30,1237,1238,1241,1243],{},[33,1239,1240],{},"Formula accuracy",[33,1242,170],{},[33,1244,1245],{},"Impact assessment",[12,1247,1248],{},"A single incorrect formula can affect every report generated from the register.",[300,1250,352],{"id":1251},"limited-audit-trails",[12,1253,1254],{},"Many spreadsheets provide limited visibility regarding:",[30,1256,1257,1260,1263],{},[33,1258,1259],{},"Who changed what",[33,1261,1262],{},"When changes occurred",[33,1264,1265],{},"Why changes were made",[12,1267,1268],{},"This makes investigations and reviews significantly more difficult.",[300,1270,1272],{"id":1271},"lack-of-validation-evidence","Lack of validation evidence",[12,1274,1275],{},"One of the most common challenges is the absence of evidence that the spreadsheet was ever assessed,\ntested or approved.",[12,1277,1278],{},"Many organisations know the register works. Few can demonstrate it objectively.",[12,1280,1281],{},"There is an important difference between:",[275,1283,1284],{},[12,1285,1286],{},"\"We've always used it.\"",[12,1288,1289],{},"and",[275,1291,1292],{},[12,1293,1294],{},"\"We can demonstrate it performs as intended.\"",[22,1296,1298],{"id":1297},"why-more-organisations-are-moving-to-sharepoint-based-registers","Why more organisations are moving to SharePoint-based registers",[12,1300,1301],{},"Many organisations already own Microsoft 365. That means they already have access to capabilities\nthat can significantly improve governance when compared with standalone spreadsheets.",[12,1303,1141],{},[30,1305,1306,1309,1311,1313,1316,1319,1322],{},[33,1307,1308],{},"Controlled permissions",[33,1310,897],{},[33,1312,903],{},[33,1314,1315],{},"Structured data",[33,1317,1318],{},"Automated workflows",[33,1320,1321],{},"Centralised management",[33,1323,1324],{},"Reporting and dashboards",[12,1326,1327],{},"For many use cases, a governed SharePoint List provides a practical alternative to a complex\nspreadsheet.",[12,1329,1141],{},[30,1331,1332,1335,1338,1341,1344,1347,1350],{},[33,1333,1334],{},"Supplier Registers",[33,1336,1337],{},"Training Registers",[33,1339,1340],{},"CAPA Registers",[33,1342,1343],{},"Equipment Registers",[33,1345,1346],{},"Calibration Registers",[33,1348,1349],{},"Risk Registers",[33,1351,1352],{},"Change Control Registers",[12,1354,1355],{},"The objective is not necessarily to implement a full eQMS. The objective is to move from an\nuncontrolled spreadsheet to a governed digital process.",[22,1357,1359],{"id":1358},"the-missing-piece-validation-and-evidence","The missing piece: validation and evidence",[12,1361,1362],{},"Technology alone does not solve the compliance problem.",[12,1364,1365],{},"An organisation still needs to demonstrate that the solution is:",[30,1367,1368,1371,1374,1377],{},[33,1369,1370],{},"Appropriate for its intended use",[33,1372,1373],{},"Properly configured",[33,1375,1376],{},"Tested",[33,1378,1379],{},"Released under control",[12,1381,1382],{},"This is where many projects become expensive.",[12,1384,1385],{},"Traditionally, consultants spend considerable time producing:",[30,1387,1388,1391,1394,1397,1400,1403],{},[33,1389,1390],{},"Intended Use documents",[33,1392,1393],{},"Risk Assessments",[33,1395,1396],{},"Test Scripts",[33,1398,1399],{},"Traceability Matrices",[33,1401,1402],{},"Validation Reports",[33,1404,1405],{},"Evidence Packs",[12,1407,1408],{},"Much of this work is repetitive.",[12,1410,1411],{},"As organisations increasingly adopt automation and AI, there is an opportunity to generate much of\nthe required validation evidence far more efficiently while maintaining appropriate oversight and\napproval by process owners.",[22,1413,1415],{"id":1414},"a-better-question-to-ask","A better question to ask",[12,1417,1418],{},"Instead of asking:",[275,1420,1421],{},[12,1422,1423],{},"\"Do we need to validate Excel?\"",[12,1425,1426],{},"A more useful question may be:",[275,1428,1429],{},[12,1430,1431],{},"\"Is this business process controlled, governed and demonstrably fit for purpose?\"",[12,1433,1434],{},"If the answer is uncertain, it may be time to review whether a spreadsheet remains the best platform\nfor the task.",[22,1436,1438],{"id":1437},"conclusion","Conclusion",[12,1440,1441],{},"Excel is not the enemy.",[12,1443,1444],{},"Uncontrolled business processes are.",[12,1446,1447],{},"Many organisations continue to rely on spreadsheets because they are flexible, familiar and low cost.\nHowever, as those spreadsheets become business-critical, they frequently outgrow the controls needed\nto support compliance, audit readiness and operational excellence.",[12,1449,1450],{},"For organisations operating in regulated or quality-focused environments, the opportunity is not\nsimply to replace Excel. The opportunity is to modernise critical registers, improve governance and\ngenerate the evidence needed to demonstrate control with confidence.",[300,1452,1454],{"id":1453},"call-to-action","Call to action",[12,1456,1457],{},"Still relying on Excel for critical registers?",[12,1459,1460],{},"Assess whether your training, supplier, equipment, risk or quality registers would benefit from a\ngoverned digital approach. The first step is understanding where the compliance risks actually sit\nbefore an auditor does.",[12,1462,1463,1464,1467,1468,1471],{},"If you are reviewing how to modernise a quality register without creating unnecessary process\nburden, our ",[55,1465,1466],{"href":571},"SharePoint governance"," and ",[55,1469,1470],{"href":576},"quality systems","\npathways can help frame a proportionate next step.",[12,1473,1474],{},"For organisations balancing compliance, evidence and operational practicality, the right answer is\nnot always a new platform. It is often a better-controlled process with clearer ownership and more\nreliable oversight.",{"title":232,"searchDepth":233,"depth":233,"links":1476},[1477,1478,1483,1489,1490,1491,1492],{"id":1088,"depth":233,"text":1089},{"id":1127,"depth":233,"text":1128,"children":1479},[1480,1481,1482],{"id":1134,"depth":588,"text":1135},{"id":1164,"depth":588,"text":1165},{"id":1177,"depth":588,"text":1178},{"id":1203,"depth":233,"text":1204,"children":1484},[1485,1486,1487,1488],{"id":1207,"depth":588,"text":1208},{"id":1228,"depth":588,"text":1229},{"id":1251,"depth":588,"text":352},{"id":1271,"depth":588,"text":1272},{"id":1297,"depth":233,"text":1298},{"id":1358,"depth":233,"text":1359},{"id":1414,"depth":233,"text":1415},{"id":1437,"depth":233,"text":1438,"children":1493},[1494],{"id":1453,"depth":588,"text":1454},"2026-09-12","Many regulated organisations still rely on Excel for training, supplier, equipment and quality registers. Learn why spreadsheets become audit findings and how governed digital registers can reduce compliance risk.",{},{"title":540,"description":1496},"blog\u002Fhidden-compliance-risk-excel-registers",[254,258,1501,257,601,602],"audit-risk","6qq0JPGdY6at3hWUxgmGdBEyg1CL5pBrkwuVNhXOH_8",{"id":1504,"title":1505,"author":7,"body":1506,"category":1668,"date":1669,"description":1670,"draft":244,"excerpt":245,"extension":246,"heroImage":245,"heroImageAlt":245,"meta":1671,"navigation":248,"path":1672,"seo":1673,"slug":245,"stem":1674,"tags":1675,"__hash__":1680},"blog\u002Fblog\u002Fagent-design-is-a-systems-problem.md","Agent Design Is a Systems Problem, Not a Prompting Problem",{"type":9,"value":1507,"toc":1660},[1508,1511,1515,1518,1544,1548,1551,1565,1569,1572,1599,1602,1606,1609,1635,1639,1642,1646],[12,1509,1510],{},"Early generative AI thinking was linear and prompt-centric: craft better instructions, refine\nwording, treat the model as a black box that responds to cleverness. That mental model breaks down\nalmost completely once you move to agent-based systems. When agents enter the picture, individual\nprompt quality becomes a local optimisation concern. What determines real-world outcomes is the\narchitecture surrounding the model — how components interconnect, how state is managed, and how\nfailures are handled. This is not a refinement of the old model; it is a different paradigm.",[22,1512,1514],{"id":1513},"why-agents-are-systems-problems","Why agents are systems problems",[12,1516,1517],{},"An agent setup is not a single function call — it is a dynamic system with all the complexity that\nimplies:",[30,1519,1520,1526,1532,1538],{},[33,1521,1522,1525],{},[61,1523,1524],{},"Multiple components:"," LLMs, tools, memory stores, triggers, and external APIs operating in\nconcert, each with its own failure profile.",[33,1527,1528,1531],{},[61,1529,1530],{},"State over time:"," unlike stateless calls, agents accumulate context across steps. Where state\nlives, and how it is managed, determines system reliability.",[33,1533,1534,1537],{},[61,1535,1536],{},"Feedback loops:"," outputs feed back into subsequent inputs. Without deliberate loop design,\nagents drift, compound errors, or enter cycles.",[33,1539,1540,1543],{},[61,1541,1542],{},"Non-deterministic behaviour:"," probabilistic components mean identical inputs can yield\ndifferent outputs. The system must be resilient to that variance by design.",[22,1545,1547],{"id":1546},"the-questions-a-systems-architect-asks","The questions a systems architect asks",[12,1549,1550],{},"Once you accept agents are systems, the diagnostic questions change entirely from \"how do I get a\nbetter answer?\" to:",[30,1552,1553,1556,1559,1562],{},[33,1554,1555],{},"Where does state live, and how is it persisted, updated, or discarded at each point in the\nworkflow?",[33,1557,1558],{},"How does information flow? What data contract does each agent receive, and what can it act on?",[33,1560,1561],{},"What triggers actions? Ambiguous triggers introduce race conditions and unpredictable side\neffects.",[33,1563,1564],{},"What are the failure modes? Every component fails eventually — design recovery pathways before\nyou encounter them in production.",[22,1566,1568],{"id":1567},"a-four-layer-mental-model","A four-layer mental model",[12,1570,1571],{},"Context and harness engineering remain important, but they operate at lower layers than top-level\nsystem design — conflating them with architecture is where most agent projects go wrong.",[1573,1574,1575,1581,1587,1593],"ol",{},[33,1576,1577,1580],{},[61,1578,1579],{},"Systems thinking (foundation):"," define agents, roles, flows, feedback loops, state\ntransitions, and failure handling.",[33,1582,1583,1586],{},[61,1584,1585],{},"Harness \u002F orchestration:"," how agents are invoked, how tools are called, retry mechanisms,\nguardrails, and observability hooks.",[33,1588,1589,1592],{},[61,1590,1591],{},"Context engineering:"," what each agent sees — context boundaries, data contracts between\ncomponents, and which elements of state are exposed and when.",[33,1594,1595,1598],{},[61,1596,1597],{},"Prompting:"," local optimisation only — effective within a well-designed system, no substitute\nfor one.",[12,1600,1601],{},"Context engineering, done properly, moves from \"how do I write the perfect prompt?\" to \"what\ninformation is available at each node in the system?\" Harness engineering moves from \"how do I make\nthe model behave?\" to \"how do I orchestrate execution and control flow?\"",[22,1603,1605],{"id":1604},"what-happens-without-systems-thinking","What happens without systems thinking",[12,1607,1608],{},"The consequences of treating agent design as a prompting problem are predictable and compounding:",[30,1610,1611,1617,1623,1629],{},[33,1612,1613,1616],{},[61,1614,1615],{},"Agents loop"," — without termination conditions and state boundaries, agents re-enter completed\nflows, consuming tokens, time, and budget.",[33,1618,1619,1622],{},[61,1620,1621],{},"Context bloats"," — without deliberate context management, history and retrieved data accumulate\nunchecked, degrading performance and increasing latency.",[33,1624,1625,1628],{},[61,1626,1627],{},"Outputs drift"," — without feedback-loop controls, small early deviations compound into large\nones.",[33,1630,1631,1634],{},[61,1632,1633],{},"Failures compound silently"," — without observability, errors propagate undetected until the\nroot cause is several steps removed and hard to isolate.",[22,1636,1638],{"id":1637},"the-bottom-line","The bottom line",[12,1640,1641],{},"If you lean on prompts, you will see early gains, then plateau — prompts cannot compensate for\narchitectural weaknesses, only mask them temporarily, and technical debt accumulates invisibly\nuntil it fails visibly. Get the system right, and you get predictable behaviour from unpredictable\ncomponents: a resilient, observable, extensible system in which prompts become almost a replaceable\nimplementation detail rather than the load-bearing design decision.",[22,1643,1645],{"id":1644},"related-reading","Related reading",[30,1647,1648,1654],{},[33,1649,1650],{},[55,1651,1653],{"href":1652},"\u002Fblog\u002Fqxaios-compliance-centric-operating-model-for-ai-systems","QxAIOS: A Compliance-Centric Operating Model for AI Systems",[33,1655,1656],{},[55,1657,1659],{"href":1658},"\u002Fblog\u002Foperating-ai-agents-in-gxp-qa-practitioners-guide","Operating AI Agents in GxP: A QA Practitioner's Guide",{"title":232,"searchDepth":233,"depth":233,"links":1661},[1662,1663,1664,1665,1666,1667],{"id":1513,"depth":233,"text":1514},{"id":1546,"depth":233,"text":1547},{"id":1567,"depth":233,"text":1568},{"id":1604,"depth":233,"text":1605},{"id":1637,"depth":233,"text":1638},{"id":1644,"depth":233,"text":1645},"AI Governance","2026-09-10","The assumption that better prompts yield better outputs breaks down entirely when you move from single-shot generation to agent-based systems. The real lever is architecture.",{},"\u002Fblog\u002Fagent-design-is-a-systems-problem",{"title":1505,"description":1670},"blog\u002Fagent-design-is-a-systems-problem",[1676,1677,1678,1679],"agentic-ai","systems-thinking","ai-architecture","agent-design","vPuQ92ep4AVAWnn-xGgLBNvoEXiy5ypuAeX-0iRP9NY",{"id":1682,"title":1683,"author":7,"body":1684,"category":1668,"date":1669,"description":1807,"draft":244,"excerpt":245,"extension":246,"heroImage":245,"heroImageAlt":245,"meta":1808,"navigation":248,"path":1809,"seo":1810,"slug":245,"stem":1811,"tags":1812,"__hash__":1818},"blog\u002Fblog\u002Fai-agent-governance-scenarios-part-1-the-new-game-changer-agent.md","AI Agent Governance Scenarios, Part 1: The New \"Game Changer\" Agent",{"type":9,"value":1685,"toc":1794},[1686,1689,1691,1694,1711,1717,1721,1724,1728,1731,1735,1738,1742,1745,1749,1752,1756,1759,1763,1766,1770,1773,1777,1780,1782],[12,1687,1688],{},"This is the first in a five-part series of practical AI-governance scenarios for quality\nprofessionals working through what \"good\" looks like when an AI agent proposal lands on their desk.",[22,1690,25],{"id":24},[12,1692,1693],{},"The production team has developed a new AI agent that automatically reviews batch manufacturing\nrecords to identify potential GMP deviations. They want to deploy it within the next month and\nbelieve it will significantly improve productivity and reduce the review backlog. They tell QA:",[30,1695,1696,1699,1702,1705,1708],{},[33,1697,1698],{},"the agent was built using Microsoft Copilot Studio;",[33,1700,1701],{},"it reviews PDF exports of batch records;",[33,1703,1704],{},"it was tested on ten historical records and \"worked well\";",[33,1706,1707],{},"the prompts include reference SOPs to help guide the AI;",[33,1709,1710],{},"QA will still make the final decision, so they believe validation can be minimal.",[12,1712,1713,1714],{},"They ask QA to approve rollout. ",[61,1715,1716],{},"Before approving, what would you ask about inputs, governance,\nvalidation, human oversight, documentation, and risk management?",[22,1718,1720],{"id":1719},"issue-1-uncontrolled-sop-versions-provided-to-the-agent","Issue 1 — Uncontrolled SOP versions provided to the agent",[12,1722,1723],{},"If the prompt references a draft, superseded, or otherwise uncontrolled training document, the\nagent cannot determine document validity, and an incorrect SOP leads to incorrect reasoning.\nControlled document management has to remain inside the quality management system regardless of\nwhat generates the prompt.",[22,1725,1727],{"id":1726},"issue-2-batch-records-provided-as-pdf-exports","Issue 2 — Batch records provided as PDF exports",[12,1729,1730],{},"An exported PDF is not the system of record, and metadata can be lost in export. Ask whether the\nexports are complete, whether the export process is itself validated, and whether records can be\naltered after export — traceability requires knowing exactly what data was analysed.",[22,1732,1734],{"id":1733},"issue-3-insufficient-testing","Issue 3 — Insufficient testing",[12,1736,1737],{},"\"We tried it on ten records\" is not an evaluation method. Ask what the evaluation method was,\nwhether known deviations were deliberately included in the test set, and what the miss rate was.\nAI-assisted processes must be risk-assessed and justified, not validated by anecdote.",[22,1739,1741],{"id":1740},"issue-4-the-agent-summarises-compliance-issues","Issue 4 — The agent summarises compliance issues",[12,1743,1744],{},"Summarising compliance issues edges into interpreting GMP compliance and inferring regulatory\nconclusions. AI is well suited to pattern recognition, comparison, and anomaly detection; it is not\nappropriate for making compliance determinations. Scope has to be defined precisely enough to keep\nthe agent on the right side of that line.",[22,1746,1748],{"id":1747},"issue-5-production-built-the-agent","Issue 5 — Production built the agent",[12,1750,1751],{},"A tool developed by the operations team and brought to QA for approval after the fact inverts the\ncorrect order. Every agent needs an owner, defined responsibilities, and controlled deployment\nestablished before operational use — QA governance has to exist before use, not be retrofitted onto\nit.",[22,1753,1755],{"id":1754},"issue-6-sop-updates-could-break-the-agent","Issue 6 — SOP updates could break the agent",[12,1757,1758],{},"If prompt logic references SOP text directly, an SOP revision without a corresponding agent update\ncreates silent drift. Prompt logic tied to controlled documents must be subject to the same change\ncontrol as the documents themselves.",[22,1760,1762],{"id":1761},"issue-7-ambiguous-human-review","Issue 7 — Ambiguous human review",[12,1764,1765],{},"\"QA will still make the final decision\" is a common but vague reassurance. Verification needs to be\nexplicit, documented, and meaningful — humans reviewing the underlying reasoning, not just the\nsummary presented to them.",[22,1767,1769],{"id":1768},"issue-8-no-clear-definition-of-agent-scope","Issue 8 — No clear definition of agent scope",[12,1771,1772],{},"Is the agent checking calculations? Detecting missing data? Interpreting GMP compliance? Without an\nexplicit answer, the agent has no defined tasks, boundaries, or known limitations — and no governance\ncontrol can be properly assessed against an undefined scope.",[22,1774,1776],{"id":1775},"the-takeaway","The takeaway",[12,1778,1779],{},"None of these eight issues require deep AI expertise to identify — they require the same instinct a\nquality professional already applies to any new process: define scope, control inputs, verify\noutputs, and document the decision trail before granting operational trust.",[22,1781,1645],{"id":1644},[30,1783,1784,1790],{},[33,1785,1786],{},[55,1787,1789],{"href":1788},"\u002Fblog\u002Fai-agent-governance-scenarios-part-2-the-helpful-trend-analysis-agent","Part 2: The \"Helpful Trend Analysis\" Agent",[33,1791,1792],{},[55,1793,1659],{"href":1658},{"title":232,"searchDepth":233,"depth":233,"links":1795},[1796,1797,1798,1799,1800,1801,1802,1803,1804,1805,1806],{"id":24,"depth":233,"text":25},{"id":1719,"depth":233,"text":1720},{"id":1726,"depth":233,"text":1727},{"id":1733,"depth":233,"text":1734},{"id":1740,"depth":233,"text":1741},{"id":1747,"depth":233,"text":1748},{"id":1754,"depth":233,"text":1755},{"id":1761,"depth":233,"text":1762},{"id":1768,"depth":233,"text":1769},{"id":1775,"depth":233,"text":1776},{"id":1644,"depth":233,"text":1645},"The production team wants to deploy an AI agent that reviews batch manufacturing records within a month. What questions should QA ask before approving it for GxP use?",{},"\u002Fblog\u002Fai-agent-governance-scenarios-part-1-the-new-game-changer-agent",{"title":1683,"description":1807},"blog\u002Fai-agent-governance-scenarios-part-1-the-new-game-changer-agent",[1813,1814,1815,1816,1817],"ai-agents","gxp","workshop-scenario","batch-record-review","governance","ttxHPldqmMRcY-xKKKYrxoCUgIvrYPVPHbjdas441LY",{"id":1820,"title":1821,"author":7,"body":1822,"category":1668,"date":1669,"description":1918,"draft":244,"excerpt":245,"extension":246,"heroImage":245,"heroImageAlt":245,"meta":1919,"navigation":248,"path":1788,"seo":1920,"slug":245,"stem":1921,"tags":1922,"__hash__":1925},"blog\u002Fblog\u002Fai-agent-governance-scenarios-part-2-the-helpful-trend-analysis-agent.md","AI Agent Governance Scenarios, Part 2: The \"Helpful Trend Analysis\" Agent",{"type":9,"value":1823,"toc":1912},[1824,1827,1829,1832,1835,1840,1844,1850,1856,1862,1868,1874,1880,1886,1890,1893,1895],[12,1825,1826],{},"This is the second in a five-part series of practical AI-governance scenarios for quality\nprofessionals.",[22,1828,25],{"id":24},[12,1830,1831],{},"Six months ago, a quality team implemented an AI agent to assist with deviation trend analysis\nacross deviation reports, CAPA investigations, environmental monitoring events, and batch record\ndeviations. Its original purpose was to highlight possible patterns for QA to investigate further,\nproducing a monthly trend summary for the quality management review meeting.",[12,1833,1834],{},"Over time, reliance has grown quietly: the trend report is now used directly in quality review\nmeetings; investigators reference it to support root-cause conclusions; a recent CAPA closure cited\nthe AI report as evidence that \"no recurring trend exists\"; and the report is now routinely attached\nto quality review documentation.",[12,1836,1837],{},[61,1838,1839],{},"Is this still appropriate use? What questions would you ask, what controls should be reviewed, and\nwhat risks may have emerged over time?",[22,1841,1843],{"id":1842},"the-subtle-issues-hidden-in-this-drift","The subtle issues hidden in this drift",[12,1845,1846,1849],{},[61,1847,1848],{},"The report is now used directly in quality review meetings."," Output originally intended as a\nsupplementary investigation tool is being treated as an authoritative source for critical decisions,\nbypassing the human oversight and critical evaluation GxP requires. The agent must remain a governed\nassistant, not an autonomous decision authority, and QA personnel need to independently evaluate\nevidence rather than accepting AI-generated conclusions.",[12,1851,1852,1855],{},[61,1853,1854],{},"CAPA closures cite the AI report as conclusive evidence."," Investigators citing \"no recurring\ntrend exists\" as a closure justification undermines the thoroughness of human investigation and\nrelies on the agent for a determination it was never designed to make. Its role was explicitly to\ndetect patterns, not to make compliance determinations — pattern identification is not the same\ncapability as a defensible compliance conclusion.",[12,1857,1858,1861],{},[61,1859,1860],{},"The agent's role expanded without formal review."," The organisation allowed scope to broaden\ngradually, with no formal assessment or documentation — an informal expansion that circumvents the\nQMS's own change control procedures. Any expansion of intended use requires a formal, documented\nreview, not accretion by habit.",[12,1863,1864,1867],{},[61,1865,1866],{},"Investigators increasingly rely on the trend summary."," There is a real risk that human reviewers\nare now confirming the agent's output rather than conducting independent evaluation, reducing human\nvigilance and risking oversight of details the agent may miss or misinterpret.",[12,1869,1870,1873],{},[61,1871,1872],{},"The report may not show which records were analysed."," Without visibility into which specific\ndeviation reports or CAPAs contributed to a trend, the integrity and auditability of the analysis is\ncompromised — QA needs to be able to trace conclusions back to the specific records analysed.",[12,1875,1876,1879],{},[61,1877,1878],{},"The agent aggregates multiple record types."," Combining deviation reports, CAPAs, and\ninvestigations for analysis is potentially efficient, but introduces risk of incomplete datasets,\ndraft records, or omitted relevant events feeding a flawed trend.",[12,1881,1882,1885],{},[61,1883,1884],{},"Six months, no reassessment."," Despite expanded usage over an extended period, there has been no\nstructured, formal review of the agent's continued suitability or its impact on the quality\nmanagement system — a significant governance gap in its own right.",[22,1887,1889],{"id":1888},"what-this-scenario-teaches","What this scenario teaches",[12,1891,1892],{},"AI risk often increases gradually, through small behavioural changes rather than a single design\nflaw. The agent itself may be technically unchanged, but its role in decision-making has evolved —\nthat is a classic GMP governance issue, and it is exactly the kind of drift that periodic review, not\na one-time validation, is designed to catch.",[22,1894,1645],{"id":1644},[30,1896,1897,1902,1908],{},[33,1898,1899],{},[55,1900,1901],{"href":1809},"Part 1: The New \"Game Changer\" Agent",[33,1903,1904],{},[55,1905,1907],{"href":1906},"\u002Fblog\u002Fai-agent-governance-scenarios-part-3-the-smart-sop-assistant","Part 3: The \"Smart SOP Assistant\"",[33,1909,1910],{},[55,1911,1659],{"href":1658},{"title":232,"searchDepth":233,"depth":233,"links":1913},[1914,1915,1916,1917],{"id":24,"depth":233,"text":25},{"id":1842,"depth":233,"text":1843},{"id":1888,"depth":233,"text":1889},{"id":1644,"depth":233,"text":1645},"Six months after deployment, a deviation trend-analysis agent is now cited as evidence in CAPA closures. Is that still appropriate use, and what changed without anyone noticing?",{},{"title":1821,"description":1918},"blog\u002Fai-agent-governance-scenarios-part-2-the-helpful-trend-analysis-agent",[1813,1814,1815,1923,1924],"capa","scope-creep","5oM6akrgLlZTx4kGNyKpuOHK8Q3Jcn9tGXJp0IwxwHY",{"id":1927,"title":1928,"author":7,"body":1929,"category":1668,"date":1669,"description":2027,"draft":244,"excerpt":245,"extension":246,"heroImage":245,"heroImageAlt":245,"meta":2028,"navigation":248,"path":1906,"seo":2029,"slug":245,"stem":2030,"tags":2031,"__hash__":2034},"blog\u002Fblog\u002Fai-agent-governance-scenarios-part-3-the-smart-sop-assistant.md","AI Agent Governance Scenarios, Part 3: The \"Smart SOP Assistant\"",{"type":9,"value":1930,"toc":2018},[1931,1934,1936,1943,1950,1954,1961,1965,1972,1976,1983,1987,1994,1998,2001,2004,2006],[12,1932,1933],{},"This is the third in a five-part series of practical AI-governance scenarios for quality\nprofessionals.",[22,1935,25],{"id":24},[12,1937,1938,1939],{},"An AI assistant, deployed across the company intranet, helps operators and supervisors find answers\nto procedural and GMP-related questions quickly, drawing on a library that includes approved SOPs,\nwork instructions, training materials, draft procedures, internal guidance notes, and historical\ninvestigation reports. Staff ask it questions with direct procedural and compliance consequences:\n",[1940,1941,1942],"em",{},"can I continue if this section of the batch record is incomplete? Does this step require QA\napproval? Is this deviation minor or major?",[12,1944,1945,1946,1949],{},"The tool is widely used precisely because it provides quick answers. ",[61,1947,1948],{},"Speed of adoption is not\nevidence of compliance fitness"," — a QA review has surfaced four distinct risk areas.",[22,1951,1953],{"id":1952},"issue-1-controlled-and-uncontrolled-documents-mixed","Issue 1 — Controlled and uncontrolled documents mixed",[12,1955,1956,1957,1960],{},"The knowledge library does not distinguish approved SOPs from draft procedures, training slides, or\nhistorical investigation reports containing superseded conclusions — and the AI presents an answer\nciting any of them with no visible difference. If the system retrieves and presents guidance from an\nuncontrolled document, any manufacturing decision made on that basis is non-compliant, regardless of\nintent. ",[61,1958,1959],{},"Applicable principle: controlled inputs"," — the AI must operate only on approved,\ncontrolled sources, with technical controls preventing draft or superseded content from entering the\nlibrary.",[22,1962,1964],{"id":1963},"issue-2-the-assistant-interprets-procedural-requirements","Issue 2 — The assistant interprets procedural requirements",[12,1966,1967,1968,1971],{},"Answering whether a deviation is minor or major, or whether a step requires QA approval, is\nprocedural interpretation, not information retrieval — it requires contextual judgement in light of\nreal-time manufacturing circumstances. The acceptable role for an assistant like this is to retrieve\nand display the relevant SOP section for the user to apply themselves; interpreting whether approval\nis needed or production may proceed belongs to qualified personnel. ",[61,1969,1970],{},"Applicable principle: define\nintended use and scope"," — procedural interpretation should be explicitly excluded, with the system\ndeclining or redirecting such queries.",[22,1973,1975],{"id":1974},"issue-3-operators-treat-the-assistant-as-procedural-authority","Issue 3 — Operators treat the assistant as procedural authority",[12,1977,1978,1979,1982],{},"Operators are routinely relying on the summarised answer rather than opening and reading the\ncontrolled SOP — understandable, since the AI answer is faster to consume, but the controlled SOP,\nnot the AI's interpretation of it, is the procedural authority. Errors or omissions in the summary\npropagate directly into manufacturing decisions, and version drift between the library and the live\ndocument-management system can go undetected if no one reads the source document. ",[61,1980,1981],{},"Applicable\nprinciple: human verification is mandatory"," — every response should display the source document\nand version, with a visible prompt to confirm understanding against the controlled document before\nacting.",[22,1984,1986],{"id":1985},"issue-4-knowledge-library-governance-is-unclear","Issue 4 — Knowledge library governance is unclear",[12,1988,1989,1990,1993],{},"There is no defined process for approving a document's inclusion, propagating SOP revisions to the\nknowledge base, or excluding draft and retired documents. ",[61,1991,1992],{},"Applicable principle: quality system\ngovernance"," — the knowledge library is, in effect, a controlled document repository, and needs a\nnamed owner, a documented change-control process for additions and removals, and a periodic audit\nschedule.",[22,1995,1997],{"id":1996},"what-has-to-happen-before-continued-use-is-approved","What has to happen before continued use is approved",[12,1999,2000],{},"Continued use should not be approved in its current form, though the tool could provide genuine\nvalue once the gaps are closed: suspend unrestricted access pending review; audit and restrict the\nknowledge library to confirmed-approved documents only; produce a formal scope statement excluding\nprocedural interpretation; establish named ownership and change control for the library; and\nformally validate the system while updating training to address AI over-reliance.",[12,2002,2003],{},"Each of these is a prerequisite for a regulated deployment of this kind of tool, not an optional\nenhancement layered on afterward.",[22,2005,1645],{"id":1644},[30,2007,2008,2012],{},[33,2009,2010],{},[55,2011,1789],{"href":1788},[33,2013,2014],{},[55,2015,2017],{"href":2016},"\u002Fblog\u002Fai-agent-governance-scenarios-part-4-the-efficiency-shortcut","Part 4: The \"Efficiency Shortcut\"",{"title":232,"searchDepth":233,"depth":233,"links":2019},[2020,2021,2022,2023,2024,2025,2026],{"id":24,"depth":233,"text":25},{"id":1952,"depth":233,"text":1953},{"id":1963,"depth":233,"text":1964},{"id":1974,"depth":233,"text":1975},{"id":1985,"depth":233,"text":1986},{"id":1996,"depth":233,"text":1997},{"id":1644,"depth":233,"text":1645},"An AI assistant that answers procedural questions quickly became popular across the site. Rapid adoption is not the same thing as compliance fitness.",{},{"title":1928,"description":2027},"blog\u002Fai-agent-governance-scenarios-part-3-the-smart-sop-assistant",[1813,1814,1815,2032,2033],"controlled-documents","sop","5HImK3jzJXMgT6rjhSxp7Utv_cR0XSoyOc2kvqBXLkA",{"id":2036,"title":2037,"author":7,"body":2038,"category":1668,"date":1669,"description":2114,"draft":244,"excerpt":245,"extension":246,"heroImage":245,"heroImageAlt":245,"meta":2115,"navigation":248,"path":2016,"seo":2116,"slug":245,"stem":2117,"tags":2118,"__hash__":2121},"blog\u002Fblog\u002Fai-agent-governance-scenarios-part-4-the-efficiency-shortcut.md","AI Agent Governance Scenarios, Part 4: The \"Efficiency Shortcut\"",{"type":9,"value":2039,"toc":2108},[2040,2043,2045,2048,2059,2063,2069,2075,2081,2087,2091,2094,2096],[12,2041,2042],{},"This is the fourth in a five-part series of practical AI-governance scenarios for quality\nprofessionals.",[22,2044,25],{"id":24},[12,2046,2047],{},"An organisation implemented an AI agent to assist QA reviewers with batch record review. The\nintended workflow was structured and sequential: the agent flags potential issues, the reviewer\nevaluates those flags, and the reviewer makes the final determination — the agent accelerates the\nreview; it does not replace it.",[12,2049,2050,2051,2054,2055,2058],{},"During a routine review meeting, quality leadership discovers that a number of reviewers have\nquietly changed how they use the agent. Instead of running the structured workflow, they ask a\nsingle direct question: ",[1940,2052,2053],{},"\"Are there any compliance concerns in this batch record?\""," The agent\nreturns a short, reassuring summary — ",[1940,2056,2057],{},"\"No major documentation issues detected\""," — and the reviewer\nproceeds with minimal further evaluation. This approach has become common practice. The system\nconfiguration has not changed. No procedure has been updated. No change control has been raised. Yet\nthe effective process has shifted fundamentally.",[22,2060,2062],{"id":2061},"is-this-acceptable-and-what-would-you-do-about-it","Is this acceptable, and what would you do about it?",[12,2064,2065,2068],{},[61,2066,2067],{},"Issue 1 — the defined review workflow is bypassed."," The agent was validated to support a\nstructured process; that structure defines the scope within which its outputs can be considered\nreliable. A general question invokes a surface-level interpretation rather than the systematic\ncheck the workflow was designed to run, and the reviewer has no visibility into what was actually\nevaluated. From a GMP perspective this is a process deviation, whether or not anyone documented it as\none — the gap between written procedure and actual practice being invisible to the quality system\nmakes it worse, not better.",[12,2070,2071,2074],{},[61,2072,2073],{},"Issue 2 — the agent is used as a decision shortcut."," When a reassuring summary is accepted with\nminimal further review, the agent has effectively become a decision authority rather than a review\nassistant — a fundamental inversion of the intended relationship. \"No major issues detected\" is not\na QA release decision; it is an output that requires human interpretation to be meaningful, and the\ndistinction between \"the AI found no issues\" and \"the record is acceptable\" is being collapsed.",[12,2076,2077,2080],{},[61,2078,2079],{},"Issue 3 — human verification is reduced."," GMP requires meaningful, independent verification, not\ncursory confirmation of what an agent has already reported. When a reviewer's evaluation is shaped\nprimarily by the agent's conclusion, the independence of that verification is compromised — and a\nreviewer expecting a clean record may apply less scrutiny than one approaching the record fresh, a\nwell-documented cognitive effect amplified by algorithmic authority.",[12,2082,2083,2086],{},[61,2084,2085],{},"Issue 4 — informal behaviour change without governance."," This is arguably the most significant\nissue: the written procedure describes the approved workflow, but actual practice has diverged, and\nthat gap is invisible without active oversight. Behavioural changes to how a tool is used constitute\nan effective process change, even without a formal update — governance has to extend beyond initial\nvalidation to include periodic review of interaction logs, competency checks, and clear escalation\npathways for identified workarounds.",[22,2088,2090],{"id":2089},"two-different-failure-modes","Two different failure modes",[12,2092,2093],{},"This scenario and the \"Game Changer Agent\" scenario illustrate two distinct failure types. A\ntechnology-governance failure is a change in how the system itself is controlled — visible, and\nusually caught by existing change control. A human behavioural-drift failure — this one — is a\nchange in how people interact with a system that has not technically changed at all: no alarm\ntriggers, no change control initiates, and the quality system may be entirely unaware anything has\nshifted. AI risk in GMP is primarily about governance and behaviour, not the model itself, and the\nmost significant risks often come from how people choose to use a tool rather than from what the\ntool does.",[22,2095,1645],{"id":1644},[30,2097,2098,2102],{},[33,2099,2100],{},[55,2101,1907],{"href":1906},[33,2103,2104],{},[55,2105,2107],{"href":2106},"\u002Fblog\u002Fai-agent-governance-scenarios-part-5-the-inspection-question","Part 5: The Inspection Question",{"title":232,"searchDepth":233,"depth":233,"links":2109},[2110,2111,2112,2113],{"id":24,"depth":233,"text":25},{"id":2061,"depth":233,"text":2062},{"id":2089,"depth":233,"text":2090},{"id":1644,"depth":233,"text":1645},"The system did not change and no change control was raised, but the way people actually used it drifted from a structured review workflow to a single question.",{},{"title":2037,"description":2114},"blog\u002Fai-agent-governance-scenarios-part-4-the-efficiency-shortcut",[1813,1814,1815,2119,2120],"human-oversight","behavioural-drift","JV2o4JfeDE1lfKM62xXRCfAbm80lvWSj4_d4Puq8ZNQ",{"id":2123,"title":2124,"author":7,"body":2125,"category":1668,"date":1669,"description":2207,"draft":244,"excerpt":245,"extension":246,"heroImage":245,"heroImageAlt":245,"meta":2208,"navigation":248,"path":2106,"seo":2209,"slug":245,"stem":2210,"tags":2211,"__hash__":2214},"blog\u002Fblog\u002Fai-agent-governance-scenarios-part-5-the-inspection-question.md","AI Agent Governance Scenarios, Part 5: The Inspection Question",{"type":9,"value":2126,"toc":2196},[2127,2130,2132,2135,2139,2142,2146,2149,2153,2156,2160,2163,2167,2170,2174,2177,2181,2184,2186],[12,2128,2129],{},"This is the final part of a five-part series of practical AI-governance scenarios for quality\nprofessionals.",[22,2131,25],{"id":24},[12,2133,2134],{},"An organisation has used an AI agent to assist QA reviewers with batch record review for six\nmonths, identifying missing entries, arithmetic inconsistencies, and potential documentation issues\nfor QA consideration. During a routine regulatory inspection, the auditor learns AI is used in the\nprocess and asks for a full explanation of how the system is governed.",[22,2136,2138],{"id":2137},"question-1-how-is-this-ai-system-used-within-your-quality-process","Question 1 — \"How is this AI system used within your quality process?\"",[12,2140,2141],{},"The first and most important move in any audit defence involving AI is to position the system\ncorrectly from the outset: the agent performs a structured scan of the batch record to highlight\npotential areas of concern, and presents findings in a review summary for QA consideration. It does\nnot make compliance decisions and does not determine whether a batch is releasable — every output is\nreviewed by a qualified reviewer, who performs the final assessment and takes full professional\naccountability. Regulators are not inherently opposed to AI in GMP; what they require is evidence\nthat it is properly governed and that human judgement remains at the centre of the decision.",[22,2143,2145],{"id":2144},"question-2-how-do-you-ensure-the-system-operates-within-an-appropriate-scope","Question 2 — \"How do you ensure the system operates within an appropriate scope?\"",[12,2147,2148],{},"A common weakness in AI governance is a failure to formally define what a system is, and is not,\npermitted to do. The system is permitted to identify missing fields, arithmetic issues, and\nformatting anomalies; it is explicitly prohibited from determining compliance conclusions or release\ndecisions, and that boundary is documented in the system's intended-use statement and reviewed as\npart of quality governance — not assumed or informally understood.",[22,2150,2152],{"id":2151},"question-3-what-controls-ensure-the-inputs-are-reliable-and-appropriate","Question 3 — \"What controls ensure the inputs are reliable and appropriate?\"",[12,2154,2155],{},"The system exclusively reviews controlled batch record exports generated as part of the review\nprocess — not drafts, working copies, or documents from outside the defined input boundary, and it\nhas no access to uncontrolled data. Controlling inputs is a fundamental GMP principle that applies\nequally to AI systems: if the inputs were uncontrolled, the findings could not be relied upon as a\nmeaningful review aid.",[22,2157,2159],{"id":2158},"question-4-are-reviewers-independently-assessing-outputs-not-simply-accepting-them","Question 4 — \"Are reviewers independently assessing outputs, not simply accepting them?\"",[12,2161,2162],{},"The AI summary is presented as a structured list of potential concerns, not a compliance finding or\nan authoritative assessment. QA reviewers are required to independently assess each flagged item —\nacceptance without independent verification is not permitted, and the reviewer's assessment,\nincluding any disagreement with the AI output, is formally recorded as part of the batch record\nreview documentation. That creates a clear audit trail demonstrating human judgement at every\nstage; the AI summary does not appear in the record as a compliance document, the reviewer's\nassessment does.",[22,2164,2166],{"id":2165},"question-5-how-are-changes-to-the-system-managed","Question 5 — \"How are changes to the system managed?\"",[12,2168,2169],{},"Any modification to configuration, prompts, or workflow integration is processed through the\norganisation's established change control procedure, with a documented impact assessment for any\nchange that could affect system behaviour. The AI system is not governed through a separate\nframework — it is a component of the quality workflow, subject to the same QMS controls as any\nother regulated process.",[22,2171,2173],{"id":2172},"question-6-how-do-you-monitor-ongoing-performance","Question 6 — \"How do you monitor ongoing performance?\"",[12,2175,2176],{},"The system is subject to periodic review as part of quality oversight, evaluating performance\nagainst expectations, incorporating reviewer feedback, and assessing discrepancies identified during\nuse — including whether the system continues to operate within its defined intended use, with any\nscope drift addressed through the change control and governance process before use continues.",[22,2178,2180],{"id":2179},"why-this-defence-holds-up","Why this defence holds up",[12,2182,2183],{},"Five elements make this a strong defence: clearly defined intended use with documented limitations;\nAI outputs never treated as compliance decisions; inputs restricted to controlled sources only;\nmandatory, documented human verification at every stage; and change control and periodic review\nhandled through existing QMS processes rather than a parallel framework. A strong audit defence for\nAI in GMP does not require explaining transformer architectures or training methodology — it\nrequires showing that the same disciplined governance thinking already applied to every other\nquality-critical process has been extended to AI. The language of the defence is the language of\nquality, not technology.",[22,2185,1645],{"id":1644},[30,2187,2188,2192],{},[33,2189,2190],{},[55,2191,2017],{"href":2016},[33,2193,2194],{},[55,2195,1659],{"href":1658},{"title":232,"searchDepth":233,"depth":233,"links":2197},[2198,2199,2200,2201,2202,2203,2204,2205,2206],{"id":24,"depth":233,"text":25},{"id":2137,"depth":233,"text":2138},{"id":2144,"depth":233,"text":2145},{"id":2151,"depth":233,"text":2152},{"id":2158,"depth":233,"text":2159},{"id":2165,"depth":233,"text":2166},{"id":2172,"depth":233,"text":2173},{"id":2179,"depth":233,"text":2180},{"id":1644,"depth":233,"text":1645},"A strong audit defence for AI-assisted batch record review does not require explaining the technology — only clear governance, defined scope, and human oversight.",{},{"title":2124,"description":2207},"blog\u002Fai-agent-governance-scenarios-part-5-the-inspection-question",[1813,1814,1815,2212,2213],"inspection-readiness","audit-defence","i3OfPwcR4qzwSj4UonZuuFItV_mCXKxAR60qqL9QPhU",{"id":2216,"title":2217,"author":7,"body":2218,"category":1668,"date":1669,"description":2369,"draft":244,"excerpt":245,"extension":246,"heroImage":245,"heroImageAlt":245,"meta":2370,"navigation":248,"path":2371,"seo":2372,"slug":245,"stem":2373,"tags":2374,"__hash__":2379},"blog\u002Fblog\u002Fai-governance-framework-ecs-botanics-case-study.md","AI Governance in a PIC\u002FS GMP Manufacturer: The ECS Botanics Approach",{"type":9,"value":2219,"toc":2361},[2220,2223,2226,2230,2233,2247,2250,2254,2257,2277,2281,2284,2321,2325,2328,2332,2338,2341,2343],[12,2221,2222],{},"ECS Botanics operates as a regulated, pharmaceutical-grade medicinal cannabis manufacturer, subject\nto PIC\u002FS GMP standards and Organic Drugs Commission (ODC) oversight. Like many regulated\nmanufacturers, the organisation faced a familiar problem: teams were already using consumer\ngenerative AI tools such as ChatGPT and Google Gemini for document drafting, data analysis, and\nprocess design, alongside an enterprise Microsoft 365 Copilot deployment that had no governing\nframework around it.",[12,2224,2225],{},"That gap between available capability and controlled use is what an AI governance framework needs\nto close.",[22,2227,2229],{"id":2228},"the-shadow-ai-risk","The shadow AI risk",[12,2231,2232],{},"Uncontrolled consumer AI use creates specific, identifiable risks in a GMP environment:",[30,2234,2235,2238,2241,2244],{},[33,2236,2237],{},"no enterprise data governance, audit trail, or change control on the tools being used;",[33,2239,2240],{},"outputs that are not version-tracked or linked to the decisions they informed;",[33,2242,2243],{},"no record of which tool, model version, or controlled instruction produced an output;",[33,2245,2246],{},"potential exposure of confidential product formulations, cultivation data, or manufacturing\nparameters to consumer services with no contractual data protection.",[12,2248,2249],{},"The mitigation is not to ban AI use — it is to make Microsoft 365 Copilot, already licensed and\nalready enterprise-governed, the sole approved tool for company data, with guardrails that\neliminate the risks shadow AI use creates.",[22,2251,2253],{"id":2252},"a-risk-based-use-category-model","A risk-based use-category model",[12,2255,2256],{},"The framework ECS Botanics adopted classifies AI use into three categories, each with different\ncontrols and approval authority:",[30,2258,2259,2265,2271],{},[33,2260,2261,2264],{},[61,2262,2263],{},"Category A — Corporate\u002Fnon-GMP:"," Copilot only, human review before external use, no\nconfidential or manufacturing data. Approval: team lead sign-off.",[33,2266,2267,2270],{},[61,2268,2269],{},"Category B — GMP-adjunct:"," Copilot only, human and qualified-person review before use in a\nGMP workflow, audit trail of tool\u002Fversion\u002Foutput\u002Fapprover, no direct output in batch records.\nApproval: qualified person or quality team.",[33,2272,2273,2276],{},[61,2274,2275],{},"Category C — GMP-critical:"," full ALCOA+ compliance, version-controlled Copilot instances,\nmandatory QP approval, immutable audit trail, electronic signature capability, formal change\ncontrol on any model or instruction change. Approval: QA Director and Regulatory Affairs.",[22,2278,2280],{"id":2279},"six-governance-principles","Six governance principles",[12,2282,2283],{},"The framework rests on principles that will be familiar to any mature quality system:",[1573,2285,2286,2292,2298,2303,2309,2315],{},[33,2287,2288,2291],{},[61,2289,2290],{},"Regulated use first"," — AI use in regulated decisions must support audit readiness,\ntraceability, and data integrity; convenience use is not permitted in GMP workflows.",[33,2293,2294,2297],{},[61,2295,2296],{},"Human oversight"," — qualified personnel review and approve AI-generated outputs before use.",[33,2299,2300,2302],{},[61,2301,915],{}," — every AI-supported regulatory decision creates an immutable audit trail\nlinking user, timestamp, model version, inputs, outputs, and approval.",[33,2304,2305,2308],{},[61,2306,2307],{},"Qualified tools"," — AI tools must be enterprise-managed, with data governance, change\nmanagement, and model governance controls.",[33,2310,2311,2314],{},[61,2312,2313],{},"Segregated use"," — corporate and non-GMP workflows carry lighter controls than GMP-critical\noperations.",[33,2316,2317,2320],{},[61,2318,2319],{},"Data classification discipline"," — public and internal data can go to Copilot freely;\nconfidential and GMP-critical data are restricted to Category B\u002FC workflows with explicit\napproval, and specific inputs (batch record numbers, patient names, cultivation parameters,\nformulation details) are never entered into an AI system directly.",[22,2322,2324],{"id":2323},"making-the-audit-trail-concrete","Making the audit trail concrete",[12,2326,2327],{},"A Category B or C interaction produces a structured record: timestamp, user, category, tool and\nmodel version, the controlled instruction version applied, an input summary, the output generated,\nthe approving qualified person, and a retention period aligned to the organisation's record-keeping\nrequirements. Records are never deleted or edited retroactively — a correction creates a\nsuperseding record with a documented reason.",[22,2329,2331],{"id":2330},"what-this-buys-an-inspector","What this buys an inspector",[12,2333,2334,2335],{},"When an ODC or GMP auditor asks how the organisation ensures data integrity in its AI processes,\nthe answer is a documented, risk-based framework with an audit trail, not an informal assurance.\nThe response an ECS Botanics QA lead can give reads simply: ",[1940,2336,2337],{},"\"We follow a risk-based approach. AI\nin administrative workflows is lighter-touch. AI in GMP workflows requires full ALCOA+ controls,\nqualified-person review, and an immutable audit trail. We do not use consumer AI tools for company\ndata.\"",[12,2339,2340],{},"That is the practical shape of AI governance in a GMP environment: not a parallel compliance\nregime, but the same risk-based, evidence-led discipline already applied to every other quality\nprocess, extended to a new category of tool.",[22,2342,1645],{"id":1644},[30,2344,2345,2351,2355],{},[33,2346,2347],{},[55,2348,2350],{"href":2349},"\u002Fblog\u002Fpharma-does-not-need-a-new-ai-governance-religion","Pharma Does Not Need a New AI Governance Religion",[33,2352,2353],{},[55,2354,1653],{"href":1652},[33,2356,2357],{},[55,2358,2360],{"href":2359},"\u002Fproduct\u002Fagentic-ai-governance","Governed AI pathway",{"title":232,"searchDepth":233,"depth":233,"links":2362},[2363,2364,2365,2366,2367,2368],{"id":2228,"depth":233,"text":2229},{"id":2252,"depth":233,"text":2253},{"id":2279,"depth":233,"text":2280},{"id":2323,"depth":233,"text":2324},{"id":2330,"depth":233,"text":2331},{"id":1644,"depth":233,"text":1645},"How a PIC\u002FS GMP-regulated cannabis manufacturer moved from uncontrolled consumer AI tools to a governed, auditable model built on Microsoft 365 Copilot.",{},"\u002Fblog\u002Fai-governance-framework-ecs-botanics-case-study",{"title":2217,"description":2369},"blog\u002Fai-governance-framework-ecs-botanics-case-study",[2375,257,2376,2377,2378],"ai-governance","m365-copilot","data-integrity","case-study","uud9eCqYFTBviHpMoNKm2zFEOhQMtW2FB97iaT3BE_k",{"id":2381,"title":222,"author":7,"body":2382,"category":241,"date":1669,"description":2663,"draft":244,"excerpt":245,"extension":246,"heroImage":245,"heroImageAlt":245,"meta":2664,"navigation":248,"path":221,"seo":2665,"slug":245,"stem":2666,"tags":2667,"__hash__":2669},"blog\u002Fblog\u002Fannex-11-in-plain-english.md",{"type":9,"value":2383,"toc":2644},[2384,2387,2390,2393,2397,2400,2403,2408,2412,2415,2418,2422,2425,2428,2432,2435,2438,2442,2445,2448,2456,2460,2463,2466,2470,2473,2476,2490,2497,2501,2504,2507,2511,2514,2517,2521,2524,2527,2531,2534,2537,2545,2549,2552,2555,2559,2562,2565,2571,2575,2578,2581,2585,2588,2591,2595,2598,2601,2605,2608,2625,2636,2639],[12,2385,2386],{},"When a GMP activity depends on a computerised system, the important question is not simply\nwhether the software works. It is whether the organisation can trust the data, the process, the\npeople, and the decisions that depend on it.",[12,2388,2389],{},"This is Annex 11 in plain English: a practical guide to the questions GMP companies should ask\nwhen they introduce, operate, change, integrate, or retire computerised systems.",[12,2391,2392],{},"This article is a practical interpretation of the Annex 11 themes. It is not legal advice, a\nvalidation protocol, or a determination that a particular system is compliant. The applicable\nregulatory text, intended use, risk assessment, and quality system remain the controlling\nreferences.",[22,2394,2396],{"id":2395},"the-central-idea-trust-in-gmp-decisions","The central idea: trust in GMP decisions",[12,2398,2399],{},"Annex 11 is about the reliability of GMP activities supported by computerised systems. A team\nshould be able to explain how the system is used, show that risks are controlled, demonstrate\nthat records are trustworthy, and recover when something goes wrong.",[12,2401,2402],{},"The practical test is simple:",[275,2404,2405],{},[12,2406,2407],{},"If a computerised system performs all or part of a task that was previously manual, what new\nrisks have been introduced, and how will the organisation know that control has been retained?",[22,2409,2411],{"id":2410},"_1-risk-management","1. Risk management",[12,2413,2414],{},"Not every system needs the same level of assessment, testing, or ongoing review. The effort\nshould reflect what could go wrong if the system fails, produces incorrect data, restricts the\nwrong person, or changes the way a GMP decision is made.",[12,2416,2417],{},"Start by identifying the process impact, critical records, decisions, interfaces, users, and\nfailure modes. Link the resulting controls and testing to the risk rather than treating every\nsystem as if it carried the same consequence.",[22,2419,2421],{"id":2420},"_2-people-and-responsibilities","2. People and responsibilities",[12,2423,2424],{},"Someone must own the system and the process it supports. Responsibility should be clear across\nthe process owner, system owner, IT or infrastructure team, and Quality.",[12,2426,2427],{},"The organisation should be able to answer who owns the business process, who operates the\nsystem, who manages the technical environment, who approves access, and who provides GMP\noversight. Shared responsibility is useful; assumed responsibility is not.",[22,2429,2431],{"id":2430},"_3-suppliers-matter","3. Suppliers matter",[12,2433,2434],{},"Using a supplier does not transfer accountability for the organisation's GMP use of the\nsystem. Supplier assessment should consider quality processes, security, change management,\nsupport, incident handling, and the evidence available for the intended use.",[12,2436,2437],{},"The practical question is not whether a vendor has validated the product in the abstract. It is\nwhether the organisation has justified reliance on the supplier and controlled its own use of\nthe service.",[22,2439,2441],{"id":2440},"_4-validation","4. Validation",[12,2443,2444],{},"Validation is evidence that the system is fit for its intended use. It is not a claim that every\npossible feature has been tested, and it is not something a vendor can complete on the customer's\nbehalf without understanding the customer's process.",[12,2446,2447],{},"A proportionate validation approach normally connects requirements, implementation, testing,\nresults, deviations, and a conclusion about fitness for use. The evidence should remain\nunderstandable when the system, team, or supplier changes.",[12,2449,2450,2451,2455],{},"The ",[55,2452,2454],{"href":2453},"\u002Fproduct\u002Fevaluating-gmp-ai-before-and-after-release","GMP AI evaluation guide"," explores the\nsame lifecycle discipline for AI-assisted use cases.",[22,2457,2459],{"id":2458},"_5-user-requirements","5. User requirements",[12,2461,2462],{},"User requirements should describe the problem the organisation needs to solve and the controls\nthe process requires. They become the basis for evaluating options, defining acceptance criteria,\nand showing that the implemented system meets the intended use.",[12,2464,2465],{},"Ask what the process needs the system to do, what information must be captured, which decisions\nmust be supported, and which controls must be visible. A feature list alone is not a user\nrequirement.",[22,2467,2469],{"id":2468},"_6-data-integrity","6. Data integrity",[12,2471,2472],{},"Data integrity asks whether people can trust the record throughout its lifecycle. Consider\nwhether data is attributable, legible, contemporaneous, original, accurate, complete, consistent,\nenduring, and available when needed.",[12,2474,2475],{},"The practical questions include:",[30,2477,2478,2481,2484,2487],{},[33,2479,2480],{},"Who created or changed the record?",[33,2482,2483],{},"Can the organisation tell what changed and why?",[33,2485,2486],{},"Are records protected from inappropriate alteration or deletion?",[33,2488,2489],{},"Can the information be retrieved and understood for the required retention period?",[12,2491,2450,2492,2496],{},[55,2493,2495],{"href":2494},"\u002Fproduct\u002Fevidence-and-traceability-for-gmp-ai","evidence and traceability guide for GMP AI","\napplies these questions to AI-assisted work as well.",[22,2498,2500],{"id":2499},"_7-interfaces-and-integrations","7. Interfaces and integrations",[12,2502,2503],{},"Whenever systems exchange information, the transfer becomes part of the controlled process. The\norganisation should know what data moves, where it goes, how errors are handled, and how it can\nshow that the receiving system received the correct information.",[12,2505,2506],{},"Examples may include an ERP to eQMS transfer, a LIMS to MES interface, SharePoint to Power\nAutomate, or an electronic balance to a spreadsheet. The technology changes, but the questions\nabout completeness, accuracy, reconciliation, and exception handling remain.",[22,2508,2510],{"id":2509},"_8-backups-and-storage","8. Backups and storage",[12,2512,2513],{},"A backup that has never been restored is an assumption, not evidence of recovery capability.",[12,2515,2516],{},"Document where data is stored, how often it is backed up, how long it is retained, who can access\nit, and how restoration is tested. Frequency and recovery objectives should reflect the process\nand the consequences of data loss.",[22,2518,2520],{"id":2519},"_9-audit-trails","9. Audit trails",[12,2522,2523],{},"When a GMP-relevant record changes, the organisation should be able to understand who changed it,\nwhen it changed, what changed, and why. Audit trails are part of the evidence that makes a record\ntrustworthy.",[12,2525,2526],{},"They should be reviewed in a way that is meaningful for the process, with findings assessed and\nescalated where the change could affect quality, data integrity, or a regulated decision.",[22,2528,2530],{"id":2529},"_10-change-control","10. Change control",[12,2532,2533],{},"Change itself is not the problem. Uncontrolled change is.",[12,2535,2536],{},"Assess changes to workflows, configuration, software versions, integrations, reports, permissions,\nand surrounding procedures for their potential effect on GMP functionality and validated state.\nThe change record should explain the impact assessment, testing, approval, implementation, and\nany required follow-up.",[12,2538,2539,2540,2544],{},"See ",[55,2541,2543],{"href":2542},"\u002Fproduct\u002Fcontrolled-change-for-gmp-ai-workflows","controlled change for GMP AI workflows"," for\nthe corresponding questions when models, prompts, retrieval, tools, or AI workflows change.",[22,2546,2548],{"id":2547},"_11-periodic-review","11. Periodic review",[12,2550,2551],{},"Validation is not a one-time declaration that remains sufficient forever. Periodic review asks\nwhether the organisation still has justified confidence in the system based on what has changed\nand what has been learned.",[12,2553,2554],{},"Review the process, risks, users, access, supplier, incidents, deviations, upgrades, interfaces,\nand performance evidence. The outcome should be a documented decision about continued use,\nremediation, requalification, or retirement.",[22,2556,2558],{"id":2557},"_12-security","12. Security",[12,2560,2561],{},"Access should be restricted according to role and need. The organisation should know who has\nprivileged access, who approves it, how access is reviewed, and how leavers or role changes are\nhandled.",[12,2563,2564],{},"Security protects more than confidentiality. In a GMP system, inappropriate access can affect\ndata integrity, records, approvals, audit trails, and the reliability of quality decisions.",[12,2566,2450,2567,2570],{},[55,2568,2569],{"href":571},"SharePoint governance pathway"," provides related guidance for\ncontrolled information, permissions, and process structure in Microsoft 365.",[22,2572,2574],{"id":2573},"_13-incident-management","13. Incident management",[12,2576,2577],{},"When a system or record fails, a quick fix is not the same as an investigation. The organisation\nshould understand what happened, why it happened, whether it could happen again, and whether the\nvalidation or control state needs to be updated.",[12,2579,2580],{},"Incidents, deviations, root causes, corrective actions, and follow-up evidence should connect in\na way that lets the organisation learn rather than repeatedly restore the same failure.",[22,2582,2584],{"id":2583},"_14-and-15-electronic-signatures-and-batch-release","14 and 15. Electronic signatures and batch release",[12,2586,2587],{},"An electronic signature needs to be attributable and meaningful. The record should make clear\nwho signed, when they signed, and what the signature represented, such as review, approval, or\nrelease.",[12,2589,2590],{},"Where a computerised system supports batch release or another critical quality decision, the\norganisation should be able to explain the decision path, the evidence considered, the authority\nof the signatory, and the controls that prevent ambiguity.",[22,2592,2594],{"id":2593},"_16-and-17-business-continuity-and-archiving","16 and 17. Business continuity and archiving",[12,2596,2597],{},"Ask what would happen if the system disappeared now. Could production, Quality, investigation,\nor batch release continue? Critical processes need documented fallback arrangements that are\nunderstood and tested.",[12,2599,2600],{},"Archiving is more than storing data. The organisation must be able to retrieve, read, understand,\nand trust the record at the end of the retention period, including the context needed to interpret\nit.",[22,2602,2604],{"id":2603},"the-questions-to-keep-asking","The questions to keep asking",[12,2606,2607],{},"Across all 17 themes, Annex 11 can be translated into a small set of operating questions:",[1573,2609,2610,2613,2616,2619,2622],{},[33,2611,2612],{},"Is the system fit for the intended GMP use?",[33,2614,2615],{},"Are risks understood and controlled in proportion to their impact?",[33,2617,2618],{},"Are responsibilities, permissions, and decisions attributable?",[33,2620,2621],{},"Are data, interfaces, audit trails, and changes trustworthy and traceable?",[33,2623,2624],{},"Can the organisation recover, investigate, learn, and demonstrate continued control?",[12,2626,2450,2627,2631,2632,2635],{},[55,2628,2630],{"href":2629},"\u002Fproduct\u002Fregulatory-compliance","Regulatory compliance pathway"," places these questions in\nthe wider context of practical quality practice. For AI-assisted work, the ",[55,2633,2634],{"href":2359},"Practical, Governed\nAI for GMP Quality Operations"," hub adds questions about output\nboundaries, human oversight, evaluation, evidence, and controlled change.",[12,2637,2638],{},"Annex 11 is therefore not only a software checklist. It is a way to test whether a computerised\nsystem supports quality work without weakening control, visibility, accountability, or trust.",[12,2640,2641,206],{},[55,2642,2643],{"href":228},"Discuss your quality-system pathway",{"title":232,"searchDepth":233,"depth":233,"links":2645},[2646,2647,2648,2649,2650,2651,2652,2653,2654,2655,2656,2657,2658,2659,2660,2661,2662],{"id":2395,"depth":233,"text":2396},{"id":2410,"depth":233,"text":2411},{"id":2420,"depth":233,"text":2421},{"id":2430,"depth":233,"text":2431},{"id":2440,"depth":233,"text":2441},{"id":2458,"depth":233,"text":2459},{"id":2468,"depth":233,"text":2469},{"id":2499,"depth":233,"text":2500},{"id":2509,"depth":233,"text":2510},{"id":2519,"depth":233,"text":2520},{"id":2529,"depth":233,"text":2530},{"id":2547,"depth":233,"text":2548},{"id":2557,"depth":233,"text":2558},{"id":2573,"depth":233,"text":2574},{"id":2583,"depth":233,"text":2584},{"id":2593,"depth":233,"text":2594},{"id":2603,"depth":233,"text":2604},"A practical guide to the questions GMP teams should ask about computerised systems, from risk and responsibilities to data integrity, change control, and recovery.",{},{"title":222,"description":2663},"blog\u002Fannex-11-in-plain-english",[255,257,2377,256,2668],"quality-systems","1asnTkwBTwI3Nt4IiNvphdiua_8S3RMm_3CvsOVM9Vk",{"id":2671,"title":545,"author":7,"body":2672,"category":241,"date":1669,"description":3078,"draft":244,"excerpt":245,"extension":246,"heroImage":245,"heroImageAlt":245,"meta":3079,"navigation":248,"path":544,"seo":3080,"slug":245,"stem":3081,"tags":3082,"__hash__":3083},"blog\u002Fblog\u002Fbeyond-excel-gxp-quality-registers-sharepoint-lists.md",{"type":9,"value":2673,"toc":3058},[2674,2677,2680,2683,2687,2690,2694,2697,2701,2704,2707,2711,2714,2737,2740,2744,2747,2809,2812,2815,2819,2822,2860,2863,2867,2870,2874,2877,2881,2884,2888,2891,2895,2898,2905,2909,2912,2941,2944,2948,2951,2954,2957,2961,2964,2984,2987,2997,3006,3010,3013,3036,3039,3043,3046,3049],[12,2675,2676],{},"Many life sciences organisations manage quality processes through approved paper forms and Excel\nregisters. Deviations, CAPAs, change controls, complaints, audit findings, and supplier issues may\nbe documented on controlled forms, while a spreadsheet tracks status and supports management\noversight.",[12,2678,2679],{},"There is nothing inherently wrong with a paper-based quality process or a spreadsheet register.\nThe challenge is that, as the organisation grows, multiple copies, manual reporting, overdue\nactions, and inconsistent classifications can make it harder to see what is happening and whether\nthe management information can be trusted.",[12,2681,2682],{},"SharePoint Lists can provide a practical next step. The important design decision is to improve\nvisibility and control without confusing a management register with the authoritative GMP record.",[22,2684,2686],{"id":2685},"the-critical-distinction-record-versus-register","The critical distinction: record versus register",[12,2688,2689],{},"Before selecting a technology, define the intended use.",[300,2691,2693],{"id":2692},"the-gmp-record","The GMP record",[12,2695,2696],{},"The approved deviation form, investigation documentation, authorised approvals, supporting\nevidence, and effectiveness checks may remain the official GMP record under the organisation's\nexisting document-control and records-management procedures.",[300,2698,2700],{"id":2699},"the-quality-register","The quality register",[12,2702,2703],{},"A register tracks management information such as the record number, date opened, process owner,\nstatus, due date, and closure date. It may also hold structured metadata for oversight and\ndecision support, including deviation type, root-cause category, risk classification, process\narea, product family, site, or CAPA classification.",[12,2705,2706],{},"A SharePoint List can support the register without replacing the controlled record. The intended\nuse, process impact, and relationship between the list and the record must be documented clearly.",[22,2708,2710],{"id":2709},"where-excel-registers-start-to-struggle","Where Excel registers start to struggle",[12,2712,2713],{},"As a register grows, familiar spreadsheet practices can create operational friction:",[30,2715,2716,2719,2722,2725,2728,2731,2734],{},[33,2717,2718],{},"multiple versions circulate across teams and email attachments;",[33,2720,2721],{},"concurrent editing can create conflicts or accidental overwrites;",[33,2723,2724],{},"formulas, column headings, and validation rules can change without sufficient visibility;",[33,2726,2727],{},"access is difficult to separate between people who need to view and people who need to edit;",[33,2729,2730],{},"status reporting and overdue-action reviews require manual effort;",[33,2732,2733],{},"inconsistent free-text classifications make trends difficult to interpret;",[33,2735,2736],{},"change history is difficult to maintain reliably without additional controls.",[12,2738,2739],{},"These issues do not automatically mean that the spreadsheet creates a direct GMP risk. They can,\nhowever, make quality oversight less reliable and make it harder to demonstrate how management\ninformation was created and maintained.",[22,2741,2743],{"id":2742},"how-a-sharepoint-list-can-support-a-paper-based-process","How a SharePoint List can support a paper-based process",[12,2745,2746],{},"Consider a deviation register with fields such as:",[371,2748,2749,2759],{},[374,2750,2751],{},[377,2752,2753,2756],{},[380,2754,2755],{},"Field",[380,2757,2758],{},"Example value",[390,2760,2761,2769,2777,2785,2793,2801],{},[377,2762,2763,2766],{},[395,2764,2765],{},"Deviation number",[395,2767,2768],{},"DEV-2026-001",[377,2770,2771,2774],{},[395,2772,2773],{},"Title",[395,2775,2776],{},"Temperature excursion",[377,2778,2779,2782],{},[395,2780,2781],{},"Process owner",[395,2783,2784],{},"Quality Manager",[377,2786,2787,2790],{},[395,2788,2789],{},"Status",[395,2791,2792],{},"Investigation open",[377,2794,2795,2798],{},[395,2796,2797],{},"Due date",[395,2799,2800],{},"30 August 2026",[377,2802,2803,2806],{},[395,2804,2805],{},"Closure date",[395,2807,2808],{},"Pending",[12,2810,2811],{},"The corresponding paper or controlled document file can continue to hold the completed deviation\nform, investigation narrative, root-cause analysis, authorised approvals, supporting documents,\nCAPA linkages, and effectiveness checks.",[12,2813,2814],{},"The list provides a central view of process status and structured metadata. It does not become the\nofficial GMP record merely because it is electronic, and it does not remove the need to control the\nunderlying record.",[22,2816,2818],{"id":2817},"the-value-is-quality-intelligence","The value is quality intelligence",[12,2820,2821],{},"When the register is designed and governed well, its structured data can support:",[30,2823,2824,2830,2836,2842,2848,2854],{},[33,2825,2826,2829],{},[61,2827,2828],{},"Trending:"," identify recurring deviation types, root causes, and process areas.",[33,2831,2832,2835],{},[61,2833,2834],{},"Management review:"," provide consistent information for periodic quality review and leadership\ndecisions.",[33,2837,2838,2841],{},[61,2839,2840],{},"Quality metrics:"," produce defined indicators without repeatedly rebuilding reports by hand.",[33,2843,2844,2847],{},[61,2845,2846],{},"Resource planning:"," understand workload, overdue actions, and investigation timelines.",[33,2849,2850,2853],{},[61,2851,2852],{},"Continuous improvement:"," prioritise CAPA activity and focus improvement on recurring issues.",[33,2855,2856,2859],{},[61,2857,2858],{},"Inspection preparation:"," maintain a clear picture of quality performance and its supporting\nevidence.",[12,2861,2862],{},"The value depends on data quality. A register that is complete but inconsistently classified can\ncreate noise rather than useful intelligence.",[22,2864,2866],{"id":2865},"the-compliance-questions-to-answer","The compliance questions to answer",[12,2868,2869],{},"A proportionate assessment should make the intended use and risk visible:",[300,2871,2873],{"id":2872},"is-the-list-making-a-gmp-decision","Is the list making a GMP decision?",[12,2875,2876],{},"If the list tracks status and metadata but does not release product or control manufacturing\nequipment, its direct process impact may differ from a system that executes a critical GMP action.\nIt may still support quality decisions through trending, reporting, and management review, so the\nmetadata must remain accurate and consistent.",[300,2878,2880],{"id":2879},"is-the-list-replacing-the-record","Is the list replacing the record?",[12,2882,2883],{},"If the approved paper or controlled document remains authoritative, the list should make that\nrelationship explicit. Links, identifiers, ownership, and reconciliation checks should help users\nmove between the register entry and its supporting record.",[300,2885,2887],{"id":2886},"is-the-metadata-trustworthy","Is the metadata trustworthy?",[12,2889,2890],{},"Incorrect root-cause categories, risk classifications, status values, or dates can mislead quality\noversight. The primary risk may be data quality and management decision-making rather than direct\nproduct impact, but that still warrants proportionate controls.",[300,2892,2894],{"id":2893},"is-the-validation-proportionate-to-intended-use","Is the validation proportionate to intended use?",[12,2896,2897],{},"The question is not simply whether SharePoint is validated. It is whether the configured list is\nfit for its intended use and whether the data it provides is accurate, consistent, and suitable to\nsupport the decisions for which it is used.",[12,2899,2450,2900,2904],{},[55,2901,2903],{"href":2902},"\u002Fproduct\u002Fongoing-control-beyond-validation","ongoing control beyond validation guide"," explains\nwhy assurance continues after initial implementation.",[22,2906,2908],{"id":2907},"proportionate-controls-for-a-quality-register","Proportionate controls for a quality register",[12,2910,2911],{},"Useful controls may include:",[30,2913,2914,2917,2920,2923,2926,2929,2932,2935,2938],{},[33,2915,2916],{},"defined permissions that restrict editing while preserving appropriate read access;",[33,2918,2919],{},"required fields and controlled picklists for important classifications;",[33,2921,2922],{},"agreed definitions for deviation types, root causes, risk levels, and statuses;",[33,2924,2925],{},"periodic reconciliation of register data to the underlying controlled records;",[33,2927,2928],{},"version history and review of significant changes;",[33,2930,2931],{},"named data ownership and scheduled quality review;",[33,2933,2934],{},"training on both list operation and correct data classification;",[33,2936,2937],{},"documented backup, retention, recovery, and access arrangements;",[33,2939,2940],{},"verification that views, reports, dashboards, filters, and calculations reflect source data.",[12,2942,2943],{},"The right control set depends on the intended use, process impact, system configuration, and\nquality-system requirements. These are design considerations, not a universal validation recipe.",[22,2945,2947],{"id":2946},"data-governance-is-the-foundation","Data governance is the foundation",[12,2949,2950],{},"Standardised classifications make trends meaningful. Controlled picklists reduce free-text\nvariation. Defined risk criteria reduce differences between individual judgements. A named data\nowner provides accountability for maintaining the register's integrity.",[12,2952,2953],{},"Periodic review should ask whether classifications remain consistent, whether entries align with\nthe underlying records, and whether the register still supports the decisions it was intended to\ninform.",[12,2955,2956],{},"Data governance is therefore a quality requirement, not merely an administrative preference.",[22,2958,2960],{"id":2959},"a-sensible-modernisation-path","A sensible modernisation path",[12,2962,2963],{},"Digital improvement does not need to replace the established quality process in one step.",[1573,2965,2966,2972,2978],{},[33,2967,2968,2971],{},[61,2969,2970],{},"Replace the tracking spreadsheet:"," move the register into a controlled SharePoint List while\nretaining approved forms and procedures.",[33,2973,2974,2977],{},[61,2975,2976],{},"Add reminders and notifications:"," help owners see due actions without manual chasing.",[33,2979,2980,2983],{},[61,2981,2982],{},"Enable management reporting:"," use defined views and dashboards for trends, workload, and\nperiodic review.",[12,2985,2986],{},"Each stage should be assessed for its effect on intended use, data integrity, permissions,\nvalidation evidence, and change control. Incremental improvement can preserve familiar processes\nwhile making visibility and oversight more reliable.",[12,2988,2989,2990,2993,2994,206],{},"Before deciding to modernise, assess ",[55,2991,2992],{"href":216},"whether an Excel quality register remains fit for purpose",".\nWhere a governed SharePoint path is appropriate, see ",[55,2995,2996],{"href":566},"Excel register assessment and SharePoint implementation support",[12,2998,2450,2999,3001,3002,3005],{},[55,3000,2569],{"href":571}," explores the wider questions\naround controlled information, permissions, and process structure in Microsoft 365. The\n",[55,3003,3004],{"href":576},"Practical GxP quality systems pathway"," connects these decisions to\nusable, controlled quality practice.",[22,3007,3009],{"id":3008},"what-good-validation-evidence-can-show","What good validation evidence can show",[12,3011,3012],{},"For a straightforward quality-register solution, evidence may include:",[30,3014,3015,3018,3021,3024,3027,3030,3033],{},[33,3016,3017],{},"an intended-use statement and functional risk assessment;",[33,3019,3020],{},"configuration records covering list design, fields, settings, views, and access controls;",[33,3022,3023],{},"verification that required fields and picklists are configured correctly;",[33,3025,3026],{},"tests showing that reports, dashboards, filters, and trend calculations reflect source data;",[33,3028,3029],{},"defined user roles and access reviews;",[33,3031,3032],{},"training records, including classification guidance;",[33,3034,3035],{},"decisions, deviations, and follow-up actions from implementation and periodic review.",[12,3037,3038],{},"The goal is not paperwork for its own sake. The goal is justified confidence that the configured\nregister is fit for purpose and that the quality information it supplies can be understood and\ntrusted.",[22,3040,3042],{"id":3041},"final-thought","Final thought",[12,3044,3045],{},"Moving beyond Excel does not require abandoning paper forms or redesigning every quality process.\nIt requires a clear boundary between the authoritative record and the information used to manage\nthe process around it.",[12,3047,3048],{},"When intended use, data ownership, classifications, permissions, review, and validation are clear,\na SharePoint List can become a more reliable quality-register tool. It can improve visibility and\nsupport quality intelligence while preserving the controlled processes that already work.",[12,3050,3051,3052,3055,3056,206],{},"For broader regulated-AI and evidence questions, visit the ",[55,3053,3054],{"href":2359},"Practical, Governed AI for GMP Quality\nOperations"," hub. ",[55,3057,2643],{"href":228},{"title":232,"searchDepth":233,"depth":233,"links":3059},[3060,3064,3065,3066,3067,3073,3074,3075,3076,3077],{"id":2685,"depth":233,"text":2686,"children":3061},[3062,3063],{"id":2692,"depth":588,"text":2693},{"id":2699,"depth":588,"text":2700},{"id":2709,"depth":233,"text":2710},{"id":2742,"depth":233,"text":2743},{"id":2817,"depth":233,"text":2818},{"id":2865,"depth":233,"text":2866,"children":3068},[3069,3070,3071,3072],{"id":2872,"depth":588,"text":2873},{"id":2879,"depth":588,"text":2880},{"id":2886,"depth":588,"text":2887},{"id":2893,"depth":588,"text":2894},{"id":2907,"depth":233,"text":2908},{"id":2946,"depth":233,"text":2947},{"id":2959,"depth":233,"text":2960},{"id":3008,"depth":233,"text":3009},{"id":3041,"depth":233,"text":3042},"How GMP teams can use SharePoint Lists to improve quality-register visibility while preserving the authoritative record and applying proportionate controls.",{},{"title":545,"description":3078},"blog\u002Fbeyond-excel-gxp-quality-registers-sharepoint-lists",[257,1814,601,602,2377],"eBhZSLQqc3mRSK__yOUXJsiVTruJe99rwJRWGcyI6IQ",{"id":3085,"title":3086,"author":7,"body":3087,"category":241,"date":1669,"description":3197,"draft":244,"excerpt":245,"extension":246,"heroImage":245,"heroImageAlt":245,"meta":3198,"navigation":248,"path":3199,"seo":3200,"slug":245,"stem":3201,"tags":3202,"__hash__":3206},"blog\u002Fblog\u002Fcost-of-inaction-inq-product-documentation.md","The Cost of Inaction: What Manual Product Documentation Actually Costs",{"type":9,"value":3088,"toc":3189},[3089,3092,3096,3099,3104,3107,3111,3114,3117,3121,3128,3131,3135,3138,3164,3168,3175,3177],[12,3090,3091],{},"Most organisations evaluate documentation modernisation as a software-spend decision: does the\ntool cost more than doing nothing? That framing misses the real comparison. Every product\ndocumentation update already carries a hidden operational cost — coordination, routing, approval\nfollow-up, version-control checks, signature management, and audit-evidence preparation. That cost\ndoes not appear as a line item, but it recurs on every single update.",[22,3093,3095],{"id":3094},"the-real-comparison","The real comparison",[12,3097,3098],{},"The decision quality teams actually face is not \"new software cost versus no cost.\" It is:",[275,3100,3101],{},[12,3102,3103],{},"Visible, governed cost per completed update, versus continued hidden operational cost per update.",[12,3105,3106],{},"That distinction matters because the hidden cost does not go away if you decline to act — it is\nsimply absorbed, unbudgeted, by the people doing the coordination work.",[22,3108,3110],{"id":3109},"where-the-time-actually-goes","Where the time actually goes",[12,3112,3113],{},"A structured comparison of manual, administratively-heavy documentation workflows against a\ngoverned digital workflow shows the overhead concentrated in the same places every time:\nchasing signatures, confirming the correct version is in circulation, re-checking cross-references,\nand assembling audit evidence after the fact rather than capturing it as the record is created.",[12,3115,3116],{},"A governed digital workflow does not remove the need for human review and sign-off — it removes\nthe coordination overhead around that review, and it captures audit evidence as a by-product of the\nworkflow rather than as a separate task.",[22,3118,3120],{"id":3119},"why-outcome-based-pricing-changes-the-calculation","Why outcome-based pricing changes the calculation",[12,3122,3123,3124,3127],{},"A governed workflow model that charges per ",[61,3125,3126],{},"completed governed record"," rather than per seat\nchanges the economics in a useful way: draft creation, comments, and review participation are not\nbilled as separate commercial events. The cost only applies when a document update reaches final\napproved or effective status — which means the cost scales with genuine quality outcomes, not with\nhow many people happen to have access to the system.",[12,3129,3130],{},"For finance and quality leadership planning a budget, that produces a simple annual formula:\nexpected completed updates per year, multiplied by a fixed per-update rate, gives a governed cost\nceiling that can be compared directly against the current unbudgeted manual cost per update.",[22,3132,3134],{"id":3133},"what-a-governed-model-needs-to-demonstrate","What a governed model needs to demonstrate",[12,3136,3137],{},"Whatever the pricing model, the underlying claim — reduced administrative burden, improved audit\nreadiness, predictable economics — needs to hold up under scrutiny:",[30,3139,3140,3146,3152,3158],{},[33,3141,3142,3145],{},[61,3143,3144],{},"Predictable economics:"," cost tied to completed quality outcomes, not headcount.",[33,3147,3148,3151],{},[61,3149,3150],{},"Reduced admin burden:"," routing, approvals, and version control built into the workflow rather\nthan tracked manually.",[33,3153,3154,3157],{},[61,3155,3156],{},"Audit readiness:"," traceability captured at each step, not reconstructed after the fact.",[33,3159,3160,3163],{},[61,3161,3162],{},"Governed workflows:"," structured approvals and version control, not informal email chains.",[22,3165,3167],{"id":3166},"the-honest-caveat","The honest caveat",[12,3169,3170,3171,3174],{},"Cost-of-inaction framing is only useful if it is evidence-based. Any specific cost figures should be\ncalibrated to the organisation's own update volume and labour assumptions before they inform a\nbudget decision — a generic industry benchmark is a starting point for a conversation, not a\ncommitment. The claim that matters is structural: ",[61,3172,3173],{},"hidden cost does not disappear by not acting; it\njust stays hidden."," Making it visible is the first step toward deciding whether it is worth paying\nto remove.",[22,3176,1645],{"id":1644},[30,3178,3179,3183],{},[33,3180,3181],{},[55,3182,2630],{"href":2629},[33,3184,3185],{},[55,3186,3188],{"href":3187},"\u002Fblog\u002Fpractical-risk-based-computerised-system-validation","Practical Risk-Based Computerised System Validation",{"title":232,"searchDepth":233,"depth":233,"links":3190},[3191,3192,3193,3194,3195,3196],{"id":3094,"depth":233,"text":3095},{"id":3109,"depth":233,"text":3110},{"id":3119,"depth":233,"text":3120},{"id":3133,"depth":233,"text":3134},{"id":3166,"depth":233,"text":3167},{"id":1644,"depth":233,"text":1645},"Most organisations frame documentation modernisation as a software-spend decision. In practice it is a cost-of-inaction decision, and the hidden cost is recurring, not one-off.",{},"\u002Fblog\u002Fcost-of-inaction-inq-product-documentation",{"title":3086,"description":3197},"blog\u002Fcost-of-inaction-inq-product-documentation",[3203,3204,257,2668,3205],"document-control","cost-of-inaction","inq","xwp2psw6rjWxohs7sd77TZjtTpYQLIiaKq3WCTvfBcU",{"id":3208,"title":3209,"author":7,"body":3210,"category":241,"date":1669,"description":3552,"draft":244,"excerpt":245,"extension":246,"heroImage":245,"heroImageAlt":245,"meta":3553,"navigation":248,"path":3554,"seo":3555,"slug":245,"stem":3556,"tags":3557,"__hash__":3559},"blog\u002Fblog\u002Fdoes-draft-annex-11-prohibit-generative-ai.md","Does Draft Annex 11 Prohibit Generative AI?",{"type":9,"value":3211,"toc":3533},[3212,3215,3220,3227,3234,3237,3240,3244,3247,3250,3270,3273,3277,3280,3284,3287,3304,3307,3311,3314,3337,3340,3344,3347,3350,3373,3376,3384,3388,3391,3395,3398,3402,3405,3411,3415,3418,3422,3425,3429,3432,3439,3443,3446,3452,3456,3459,3482,3485,3489,3492,3509,3512,3518,3522,3525,3528],[12,3213,3214],{},"The question is increasingly appearing in quality and digital transformation discussions:",[275,3216,3217],{},[12,3218,3219],{},"Does the draft Annex 11 say that a GMP organisation cannot use generative AI?",[12,3221,3222,3223,3226],{},"The short answer is ",[61,3224,3225],{},"no blanket prohibition is identified in the draft text",". That does not mean every use of generative AI is acceptable, low risk, or automatically compliant. It means the regulatory question is more specific:",[275,3228,3229],{},[12,3230,3231],{},[61,3232,3233],{},"What is the organisation relying on the AI system to do?",[12,3235,3236],{},"That question leads to the matters that Annex 11 is concerned with: intended use, risk, data integrity, validation or verification, security, supplier oversight, controlled change, and accountable human review.",[12,3238,3239],{},"This article provides a practical reading for GMP teams. It is not legal advice, a validation protocol, or a customer-specific regulatory determination. The draft consultation text and the organisation's own quality-system context remain the controlling references.",[22,3241,3243],{"id":3242},"start-with-intended-use","Start with intended use",[12,3245,3246],{},"Generative AI can be used for very different purposes. A person may use M365 Copilot to improve grammar in a draft deviation report. Another team may use an AI system to summarise evidence, suggest a root cause, recommend a CAPA, or classify product impact. These uses may look similar from a technology perspective, but they do not have the same quality or data-integrity implications.",[12,3248,3249],{},"The first step is therefore to describe the intended use precisely:",[30,3251,3252,3255,3258,3261,3264,3267],{},[33,3253,3254],{},"What task is the AI assisting with?",[33,3256,3257],{},"What information does it receive?",[33,3259,3260],{},"What output does it produce?",[33,3262,3263],{},"Who reviews that output?",[33,3265,3266],{},"What decision or process step follows?",[33,3268,3269],{},"Can the output become part of a controlled record or approval?",[12,3271,3272],{},"A general statement such as \"we use Copilot for documentation\" is not enough to define the control boundary. The organisation needs to explain what the tool is allowed to do and what remains outside its role.",[22,3274,3276],{"id":3275},"support-function-or-gmp-decision-making","Support function or GMP decision-making?",[12,3278,3279],{},"A useful first distinction is between an AI support function and AI being relied on for GMP decision-making.",[300,3281,3283],{"id":3282},"ai-as-writing-support","AI as writing support",[12,3285,3286],{},"Examples may include:",[30,3288,3289,3292,3295,3298,3301],{},[33,3290,3291],{},"improving grammar and readability;",[33,3293,3294],{},"helping structure a draft;",[33,3296,3297],{},"suggesting consistent terminology;",[33,3299,3300],{},"identifying missing sections for an author to check;",[33,3302,3303],{},"helping a person prepare a document for review.",[12,3305,3306],{},"These uses can still create risks. AI-generated text may introduce an incorrect statement, change the meaning of an investigation, omit important context, or expose information to an unauthorised service. But the AI remains a support tool if the responsible author checks the output and remains accountable for the final document.",[300,3308,3310],{"id":3309},"ai-influencing-a-gmp-decision","AI influencing a GMP decision",[12,3312,3313],{},"Greater control is needed when an organisation relies on AI to:",[30,3315,3316,3319,3322,3325,3328,3331,3334],{},[33,3317,3318],{},"assess product impact;",[33,3320,3321],{},"determine or recommend a root cause;",[33,3323,3324],{},"classify a deviation;",[33,3326,3327],{},"recommend or assess CAPA effectiveness;",[33,3329,3330],{},"interpret evidence for a quality decision;",[33,3332,3333],{},"recommend batch disposition or release;",[33,3335,3336],{},"approve an investigation or other controlled action.",[12,3338,3339],{},"The issue is not simply whether the model is described as \"assistive\". The issue is what influence the output has on the process and whether a qualified person can understand, challenge, accept, reject, or escalate it.",[22,3341,3343],{"id":3342},"human-review-is-necessary-but-it-is-not-the-whole-answer","Human review is necessary, but it is not the whole answer",[12,3345,3346],{},"Human review is a central control for AI-assisted GMP work, but \"a human looked at it\" is not a complete governance model.",[12,3348,3349],{},"A meaningful review process should define:",[30,3351,3352,3355,3358,3361,3364,3367,3370],{},[33,3353,3354],{},"who is authorised to review the output;",[33,3356,3357],{},"what the reviewer is expected to check;",[33,3359,3360],{},"which source evidence must be considered;",[33,3362,3363],{},"what acceptance criteria apply;",[33,3365,3366],{},"how the reviewer records accept, reject, rework, or escalate;",[33,3368,3369],{},"how amendments and reasons are captured;",[33,3371,3372],{},"what happens when the output is uncertain, incomplete, or wrong.",[12,3374,3375],{},"The original AI output and the human disposition may need to remain understandable and retrievable, depending on the process impact and the applicable quality-system requirements. Oversight is a workflow, not merely a signature at the end of a document.",[12,3377,3378,3379,3383],{},"Our guide on ",[55,3380,3382],{"href":3381},"\u002Fproduct\u002Fhuman-oversight-for-gmp-ai-workflows","human oversight patterns for GMP AI workflows"," explores this distinction in more detail.",[22,3385,3387],{"id":3386},"what-controls-should-a-gmp-team-consider","What controls should a GMP team consider?",[12,3389,3390],{},"A proportionate assessment of a generative AI use case should consider at least the following areas.",[300,3392,3394],{"id":3393},"risk-and-process-impact","Risk and process impact",[12,3396,3397],{},"Assess the possible effect on product quality, patient safety, data integrity, and the decisions or records involved. Revisit the assessment when the intended use, data, workflow, or system changes.",[300,3399,3401],{"id":3400},"data-integrity-and-traceability","Data integrity and traceability",[12,3403,3404],{},"Consider whether the organisation can explain what information was provided, what the AI produced, what the reviewer changed, who made the decision, and which relevant versions or configurations were involved. The appropriate evidence chain depends on the use case and process impact.",[12,3406,2539,3407,3410],{},[55,3408,3409],{"href":2494},"evidence and traceability for GMP AI workflows"," for the practical questions this raises.",[300,3412,3414],{"id":3413},"security-and-information-handling","Security and information handling",[12,3416,3417],{},"The team should understand what information is sent to the service, how access is controlled, how prompts and outputs are handled, and whether the use is consistent with the organisation's data-governance requirements. These questions are especially important when prompts contain confidential product, patient, batch, investigation, or supplier information.",[300,3419,3421],{"id":3420},"supplier-and-service-oversight","Supplier and service oversight",[12,3423,3424],{},"Where a cloud or SaaS service is used in the workflow, the organisation remains responsible for assessing whether the service is suitable for the intended use and for retaining the evidence needed to support that assessment. Using a well-known supplier does not remove the need to understand the service boundary and relevant changes.",[300,3426,3428],{"id":3427},"validation-evaluation-and-verification","Validation, evaluation, and verification",[12,3430,3431],{},"The level of validation or verification should follow the intended use and risk. A narrowly bounded writing-support use may require a different evidence approach from an AI output that influences a quality decision or enters a controlled record. The organisation should define how it will evaluate the use before release and how it will monitor effectiveness after release.",[12,3433,3434,3435,3438],{},"Read ",[55,3436,3437],{"href":2453},"evaluating GMP AI before and after release"," for more on that lifecycle view.",[300,3440,3442],{"id":3441},"controlled-change","Controlled change",[12,3444,3445],{},"AI services, models, prompts, retrieval sources, configurations, permissions, and surrounding workflows can change. A GMP team needs a way to assess whether a change affects the approved intended use, the output, the review process, or the evidence chain.",[12,3447,2450,3448,3451],{},[55,3449,3450],{"href":2542},"controlled change guide for GMP AI workflows"," provides a starting point for that assessment.",[22,3453,3455],{"id":3454},"what-the-answer-does-not-mean","What the answer does not mean",[12,3457,3458],{},"Saying that the draft Annex 11 does not create a blanket prohibition does not mean:",[30,3460,3461,3464,3467,3470,3473,3476,3479],{},[33,3462,3463],{},"generative AI can be used without a defined purpose;",[33,3465,3466],{},"human review can be informal or bypassed;",[33,3468,3469],{},"an organisation can put confidential GMP information into any public AI service;",[33,3471,3472],{},"every AI-assisted document requires the same controls;",[33,3474,3475],{},"M365 Copilot or another vendor is automatically validated for the customer's use;",[33,3477,3478],{},"an AI system can make a regulated decision simply because a person remains nominally responsible;",[33,3480,3481],{},"the use is compliant without a documented assessment and appropriate evidence.",[12,3483,3484],{},"The technology may be available, but the operating boundary still needs to be designed and maintained.",[22,3486,3488],{"id":3487},"a-practical-starting-point","A practical starting point",[12,3490,3491],{},"For a proposed generative AI use case, a GMP team can begin with five questions:",[1573,3493,3494,3497,3500,3503,3506],{},[33,3495,3496],{},"What exactly is the AI allowed to do?",[33,3498,3499],{},"What must it never be relied on to do?",[33,3501,3502],{},"Where does its output go next?",[33,3504,3505],{},"Who must review and decide before the process progresses?",[33,3507,3508],{},"What evidence will show what happened and what changed?",[12,3510,3511],{},"If those questions cannot be answered clearly, the use case is not ready to move from interest to controlled adoption. Start by defining the process problem and the output boundary, then decide what governance and evaluation are proportionate.",[12,3513,2450,3514,3517],{},[55,3515,3516],{"href":2359},"Practical, Governed AI for GMP Quality Operations"," hub brings those questions together, including use-case selection, output boundaries, human oversight, evidence, evaluation, and controlled change.",[22,3519,3521],{"id":3520},"a-more-useful-question-than-can-we-use-ai","A more useful question than \"Can we use AI?\"",[12,3523,3524],{},"The most useful question is not whether generative AI is categorically allowed or forbidden. It is whether the organisation can define, control, review, evidence, and improve the particular use it is considering.",[12,3526,3527],{},"That is where a regulatory reading becomes an operating decision. Generative AI may support some GMP work, but its role should remain bounded by intended use, process impact, accountable human judgement, and evidence that can be understood when the organisation needs to explain what happened.",[12,3529,3530,206],{},[55,3531,3532],{"href":228},"Discuss your GMP AI pathway",{"title":232,"searchDepth":233,"depth":233,"links":3534},[3535,3536,3540,3541,3549,3550,3551],{"id":3242,"depth":233,"text":3243},{"id":3275,"depth":233,"text":3276,"children":3537},[3538,3539],{"id":3282,"depth":588,"text":3283},{"id":3309,"depth":588,"text":3310},{"id":3342,"depth":233,"text":3343},{"id":3386,"depth":233,"text":3387,"children":3542},[3543,3544,3545,3546,3547,3548],{"id":3393,"depth":588,"text":3394},{"id":3400,"depth":588,"text":3401},{"id":3413,"depth":588,"text":3414},{"id":3420,"depth":588,"text":3421},{"id":3427,"depth":588,"text":3428},{"id":3441,"depth":588,"text":3442},{"id":3454,"depth":233,"text":3455},{"id":3487,"depth":233,"text":3488},{"id":3520,"depth":233,"text":3521},"A practical reading of what the draft Annex 11 may mean for GMP teams considering generative AI, M365 Copilot, and AI-assisted documentation.",{},"\u002Fblog\u002Fdoes-draft-annex-11-prohibit-generative-ai",{"title":3209,"description":3552},"blog\u002Fdoes-draft-annex-11-prohibit-generative-ai",[255,3558,257,2375,2376],"generative-ai","ZSsAwqhY_dGFLV74oY0nXODtcIiE6cFsiwAQREp7YkI",{"id":3561,"title":3562,"author":7,"body":3563,"category":241,"date":1669,"description":3822,"draft":244,"excerpt":245,"extension":246,"heroImage":245,"heroImageAlt":245,"meta":3823,"navigation":248,"path":3824,"seo":3825,"slug":245,"stem":3826,"tags":3827,"__hash__":3830},"blog\u002Fblog\u002Ffrom-annex-22-to-agentic-ai-practical-language-for-regulated-ai.md","From Annex 22 to Agentic AI: A Practical Language for Regulated AI",{"type":9,"value":3564,"toc":3810},[3565,3568,3575,3578,3582,3585,3595,3599,3602,3606,3609,3612,3615,3619,3622,3625,3628,3632,3635,3638,3641,3645,3648,3698,3701,3705,3708,3711,3728,3731,3735,3738,3749,3752,3756,3761,3764,3798],[12,3566,3567],{},"The draft EU GMP Annex 22 consultation guideline has made one question more visible for\nregulated organisations: what kind of artificial intelligence is being used, and what does it\ndo in the process?",[12,3569,3570,3571,3574],{},"That question matters because the same word, ",[61,3572,3573],{},"AI",", can describe a model that predicts an\noutcome, a tool that drafts content, or a system that coordinates actions. Those uses do not\ncreate the same testing, review, evidence, or change-control questions.",[12,3576,3577],{},"This article proposes a practical language for discussing the difference. It is a planning\nmodel for regulated AI, not a regulatory determination, validation protocol, or legal advice.\nThe organisation's intended use, process impact, jurisdiction, and quality system remain the\ncontrolling context.",[22,3579,3581],{"id":3580},"what-the-draft-annex-22-says-about-scope","What the draft Annex 22 says about scope",[12,3583,3584],{},"The draft Annex 22 consultation guideline addresses certain AI use cases in GMP environments.\nIt distinguishes the AI and machine-learning applications within its scope from generative AI\nand large language models, and states that generative AI and LLMs should not be used in critical\nGMP applications. It also describes human responsibility for reviewing outputs in non-critical\nuses where those models are used.",[12,3586,3587,3588,3594],{},"Read the ",[55,3589,3593],{"href":3590,"rel":3591},"https:\u002F\u002Fhealth.ec.europa.eu\u002Fdocument\u002Fdownload\u002F5f38a92d-bb8e-4264-8898-ea076e926db6_en?filename=mp_vol4_chap4_annex22_consultation_guideline_en.pdf",[3592],"nofollow","draft EU GMP Annex 22 consultation guideline","\nfor the source text and its defined context. The draft is not a blanket answer to every future\nAI use case. A team still needs to describe the intended use and determine what the output does\nnext.",[22,3596,3598],{"id":3597},"a-useful-language-predict-generate-act","A useful language: predict, generate, act",[12,3600,3601],{},"Technology labels can obscure the practical control question. A simpler starting point is to\nclassify the role of the output in the process.",[300,3603,3605],{"id":3604},"predictive-ai-predicts-data","Predictive AI predicts data",[12,3607,3608],{},"Predictive AI produces classifications, measurements, probabilities, or predictions. Examples\nmay include defect detection, process anomaly detection, predictive maintenance, yield\nprediction, or process trend analysis.",[12,3610,3611],{},"The central question is usually whether the prediction performs as intended against suitable\ndata and acceptance criteria. Accuracy, precision, sensitivity, specificity, and false-positive\nor false-negative rates may be relevant, depending on the use case.",[12,3613,3614],{},"This does not make predictive AI automatically suitable for a GMP process. The data, intended\nuse, decision impact, review, and ongoing control still need to be assessed.",[300,3616,3618],{"id":3617},"generative-ai-generates-content","Generative AI generates content",[12,3620,3621],{},"Generative AI produces text, explanations, summaries, or other content. Examples may include\ndrafting a deviation summary, organising an investigation, suggesting an SOP structure, or\nexplaining a trend for a person to review.",[12,3623,3624],{},"There may not be one exact correct answer. Evaluation therefore asks whether the output is\naccurate, complete, grounded in the available evidence, consistent enough for the intended use,\nand acceptable to the accountable reviewer. The original context and the review disposition may\nalso need to remain understandable and retrievable.",[12,3626,3627],{},"Human review is not a substitute for defining the review. The team should specify who reviews\nthe output, what evidence they check, what acceptance criteria apply, and what happens when the\noutput is incomplete, uncertain, or wrong.",[300,3629,3631],{"id":3630},"agentic-ai-coordinates-actions","Agentic AI coordinates actions",[12,3633,3634],{},"Agentic AI uses content generation as part of a larger process involving planning,\norchestration, tool use, or action. An agent might retrieve records, search procedures, prepare\nfindings, identify missing information, recommend escalation, or create a task for a person to\nreview.",[12,3636,3637],{},"The important change is that the output is no longer only an answer. It can influence what\nhappens next. The governance question becomes whether the agent followed the intended workflow,\nused approved information, avoided prohibited actions, escalated when required, and obtained\nhuman approval at the correct point.",[12,3639,3640],{},"Agentic AI therefore combines two kinds of evaluation: generative-AI evaluation for the quality\nand grounding of content, and workflow or process testing for sequencing, permissions,\nexceptions, escalation, and evidence.",[22,3642,3644],{"id":3643},"why-the-testing-approach-changes","Why the testing approach changes",[12,3646,3647],{},"The question should move from \"Was the model answer correct?\" to \"Did the AI-assisted process\nbehave as intended for this use case?”",[371,3649,3650,3663],{},[374,3651,3652],{},[377,3653,3654,3657,3660],{},[380,3655,3656],{},"AI role",[380,3658,3659],{},"Primary output",[380,3661,3662],{},"Practical testing emphasis",[390,3664,3665,3676,3687],{},[377,3666,3667,3670,3673],{},[395,3668,3669],{},"Predictive AI",[395,3671,3672],{},"Prediction or classification",[395,3674,3675],{},"Performance against suitable data and acceptance criteria",[377,3677,3678,3681,3684],{},[395,3679,3680],{},"Generative AI",[395,3682,3683],{},"Content or explanation",[395,3685,3686],{},"Quality, grounding, completeness, consistency, and human review",[377,3688,3689,3692,3695],{},[395,3690,3691],{},"Agentic AI",[395,3693,3694],{},"Action or workflow progression",[395,3696,3697],{},"Process sequence, permissions, escalation, human approval, and traceability",[12,3699,3700],{},"This table is a planning aid, not a universal validation classification. A single solution may\ncontain more than one role, and the same model may require a different control response when its\noutput is used in a different process.",[22,3702,3704],{"id":3703},"start-with-process-impact","Start with process impact",[12,3706,3707],{},"The tool does not set the control boundary. Process impact does.",[12,3709,3710],{},"Ask five questions before selecting a governance response:",[1573,3712,3713,3716,3719,3722,3725],{},[33,3714,3715],{},"What is the AI allowed to do, and what must it never be relied on to do?",[33,3717,3718],{},"What information does it receive, and which sources are approved?",[33,3720,3721],{},"Where does its output go next: a draft, a workflow, a decision, an approval, a release, or a\ncontrolled record?",[33,3723,3724],{},"Who is accountable for reviewing, accepting, rejecting, reworking, or escalating the output?",[33,3726,3727],{},"What evidence will show what happened, which version or configuration was involved, and what\nchanged later?",[12,3729,3730],{},"These questions connect the AI use case to existing quality-system disciplines rather than\ncreating a parallel governance vocabulary.",[22,3732,3734],{"id":3733},"from-model-language-to-operating-language","From model language to operating language",[12,3736,3737],{},"For a quality team, the three roles can be understood through familiar work:",[30,3739,3740,3743,3746],{},[33,3741,3742],{},"A monitoring or statistical tool that identifies an emerging trend resembles predictive AI.",[33,3744,3745],{},"A quality professional using assistance to prepare a draft resembles generative AI.",[33,3747,3748],{},"A quality professional coordinating an investigation, assigning actions, and managing\nescalation resembles the process role of agentic AI.",[12,3750,3751],{},"The analogy is not a substitute for assessing the actual system. It helps people ask where\naccountability, review, evidence, and permission belong as AI moves from describing information\nto influencing action.",[22,3753,3755],{"id":3754},"continue-the-decision","Continue the decision",[12,3757,2450,3758,3760],{},[55,3759,3516],{"href":2359}," hub\nconnects this language to use-case selection, output boundaries, human oversight, evidence and\ntraceability, evaluation, controlled change, and scaling through existing quality systems.",[12,3762,3763],{},"Relevant next questions include:",[30,3765,3766,3772,3778,3783,3788,3793],{},[33,3767,3768],{},[55,3769,3771],{"href":3770},"\u002Fproduct\u002Fchoosing-ai-use-cases-for-gmp-quality-work","Choose AI use cases for GMP quality work",[33,3773,3774],{},[55,3775,3777],{"href":3776},"\u002Fproduct\u002Fdefining-gmp-boundary-for-ai-outputs","Define the GMP boundary for AI outputs",[33,3779,3780],{},[55,3781,3782],{"href":3381},"Design human oversight for GMP AI workflows",[33,3784,3785],{},[55,3786,3787],{"href":2453},"Evaluate GMP AI before and after release",[33,3789,3790],{},[55,3791,3792],{"href":2494},"Capture evidence and traceability for GMP AI",[33,3794,3795],{},[55,3796,3797],{"href":2542},"Control change in GMP AI workflows",[12,3799,3800,3801,3806,3807,206],{},"For platform and implementation depth, the hub refers visitors to the ",[55,3802,3805],{"href":3803,"rel":3804},"https:\u002F\u002Fqx.qiksolve.com",[3592],"QxAIOS solution",".\nFor a discussion of a defined use case and operating context, ",[55,3808,3809],{"href":228},"contact QikSolve",{"title":232,"searchDepth":233,"depth":233,"links":3811},[3812,3813,3818,3819,3820,3821],{"id":3580,"depth":233,"text":3581},{"id":3597,"depth":233,"text":3598,"children":3814},[3815,3816,3817],{"id":3604,"depth":588,"text":3605},{"id":3617,"depth":588,"text":3618},{"id":3630,"depth":588,"text":3631},{"id":3643,"depth":233,"text":3644},{"id":3703,"depth":233,"text":3704},{"id":3733,"depth":233,"text":3734},{"id":3754,"depth":233,"text":3755},"A practical language for distinguishing predictive, generative, and agentic AI, and matching testing and oversight to the role AI plays in regulated work.",{},"\u002Fblog\u002Ffrom-annex-22-to-agentic-ai-practical-language-for-regulated-ai",{"title":3562,"description":3822},"blog\u002Ffrom-annex-22-to-agentic-ai-practical-language-for-regulated-ai",[3828,3829,257,2375,1676],"annex-22","regulated-ai","522zHg88j_UsKxV5jTXZdONfrv9zolpDUxEz-X0ok9w",{"id":3832,"title":3833,"author":7,"body":3834,"category":1668,"date":1669,"description":3938,"draft":244,"excerpt":245,"extension":246,"heroImage":245,"heroImageAlt":245,"meta":3939,"navigation":248,"path":3940,"seo":3941,"slug":245,"stem":3942,"tags":3943,"__hash__":3946},"blog\u002Fblog\u002Finherent-bias-in-humans-and-llms.md","Inherent Bias in Humans and LLMs: How to Manage It Without Losing Trust",{"type":9,"value":3835,"toc":3930},[3836,3839,3843,3846,3849,3853,3873,3877,3880,3884,3904,3908,3911,3914,3916],[12,3837,3838],{},"A deviation is investigated, and the first plausible cause becomes the accepted cause. A risk\nregister is updated, but last month's event shapes the ratings more than the full trend. A\ncontrolled document is revised with AI assistance, and subtle wording drift changes how operators\ninterpret a critical step. None of this is a future risk — it is a current operating reality in any\nquality system that has started using AI-assisted tools.",[22,3840,3842],{"id":3841},"the-shared-bias-problem","The shared bias problem",[12,3844,3845],{},"Human bias and LLM bias arise from different mechanisms but produce similar effects. Human sources\ninclude familiarity and recency effects, role assumptions, and workload pressure. LLM sources\ninclude dominant training examples, overrepresented enterprise patterns, and missing local context.\nWhen both combine, decisions can drift while still appearing entirely reasonable — which is why\ngovernance cannot rely on intent alone. It needs evidence, thresholds, review controls, and\nlifecycle monitoring.",[12,3847,3848],{},"A concrete pattern in AI-assisted engineering illustrates the mechanism outside GxP: AI code\ngeneration tends to suggest enterprise-scale architecture patterns even when the actual context does\nnot justify them, and complexity accumulates faster under AI assistance because generation is quick\nand compounds across iterations. Teams can over-trust recommendations framed as \"best practice\"\nwithout checking context fit — the model is not selecting people, but it is steering decisions in a\nconsistent direction that may not suit the current phase. The same governance lesson applies\ndirectly to GxP workflows where judgement quality, traceability, and consistency are\nsafety-critical.",[22,3850,3852],{"id":3851},"three-critical-areas-in-gxp-workflows","Three critical areas in GxP workflows",[30,3854,3855,3861,3867],{},[33,3856,3857,3860],{},[61,3858,3859],{},"Quality risk assessment:"," recency and familiarity bias skew severity ratings; LLMs suggest\ngeneric industry templates over site-specific conditions. Governance response: define scoring\ncriteria before tool use, require explicit rationale for score changes, and apply second-line\nreview for high-risk ratings.",[33,3862,3863,3866],{},[61,3864,3865],{},"Technical writing and controlled documents:"," assumption bias omits tacit process knowledge;\nLLMs default to generic enterprise phrasing. Governance response: approved templates with\nevidence-linked sections, controlled terminology checks, and logged prompt context.",[33,3868,3869,3872],{},[61,3870,3871],{},"Root cause analysis and CAPA:"," confirmation bias anchors investigations prematurely; LLMs\nmirror historical patterns rather than current evidence. Governance response: require\nevidence-to-cause mapping, separate cause identification from action definition, and trigger\nindependent review for repeat deviations.",[22,3874,3876],{"id":3875},"where-human-and-agent-bias-overlap","Where human and agent bias overlap",[12,3878,3879],{},"Quality degradation rarely comes from a single source — it emerges where human judgement patterns\nand agent output patterns intersect without sufficient controls. In deviation triage, recency\nframing drives unequal human prioritisation while agent language patterns over-standardise from\nprior dominant cases, and reviewers can accept fluent categorisation without testing whether it is\nactually equivalent. In trend interpretation, human anchoring on historical norms combines with\nagent trend summaries that overfit baseline periods, so drift is normalised until a threshold breach\nforces late intervention. These are not separate bias types competing for ownership — they are\ninteracting biases inside one quality system, and control design has to test both pathways at the\nsame control point.",[22,3881,3883],{"id":3882},"a-three-phase-compliance-control-model","A three-phase compliance control model",[1573,3885,3886,3892,3898],{},[33,3887,3888,3891],{},[61,3889,3890],{},"Pre-use control design:"," define decision boundaries, accountable owners, risk metrics,\nevidence requirements, acceptance thresholds, prohibited data use, and escalation criteria before\ndeployment.",[33,3893,3894,3897],{},[61,3895,3896],{},"In-flight monitoring:"," track scoring drift, language drift, and investigation-pattern drift\nover time; set alert thresholds; log human overrides; record model, prompt, and policy changes\nfor traceability.",[33,3899,3900,3903],{},[61,3901,3902],{},"Post-hoc review:"," run scheduled drift and effectiveness analysis across risk, documentation,\nand CAPA outputs; distinguish model-driven from reviewer-driven effects; revalidate controls\nafter remediation.",[22,3905,3907],{"id":3906},"a-human-equivalent-governance-principle","A human-equivalent governance principle",[12,3909,3910],{},"Treat AI-assisted recommendations as if a person made them, then apply additional safeguards for\nscale and speed effects: the same accountability owner regardless of source, the same evidentiary\nstandard, the same challenge rights for any recommendation, and additional monitoring where\nautomation can propagate harm faster than human review can catch it. This keeps governance\nconsistent across technologies and avoids the common failure mode where digital recommendations\nreceive less scrutiny than human judgement.",[12,3912,3913],{},"Bias management is not a model-selection exercise. It is a system-design responsibility spanning\npolicy, process, tooling, and review behaviour — and in regulated, quality-sensitive settings, it\nis the practical shift from AI confidence to AI governance. Leadership needs to own that framework,\nnot delegate it to technical teams alone.",[22,3915,1645],{"id":1644},[30,3917,3918,3922,3926],{},[33,3919,3920],{},[55,3921,2350],{"href":2349},[33,3923,3924],{},[55,3925,1659],{"href":1658},[33,3927,3928],{},[55,3929,2360],{"href":2359},{"title":232,"searchDepth":233,"depth":233,"links":3931},[3932,3933,3934,3935,3936,3937],{"id":3841,"depth":233,"text":3842},{"id":3851,"depth":233,"text":3852},{"id":3875,"depth":233,"text":3876},{"id":3882,"depth":233,"text":3883},{"id":3906,"depth":233,"text":3907},{"id":1644,"depth":233,"text":1645},"Human bias and LLM bias differ in mechanism but combine in GxP workflows while decisions still appear reasonable. Governance has to rely on evidence, not intent.",{},"\u002Fblog\u002Finherent-bias-in-humans-and-llms",{"title":3833,"description":3938},"blog\u002Finherent-bias-in-humans-and-llms",[2375,3944,1814,3945,2377],"bias","quality-risk","YBmYfg15W7zRsfmIMvehquMd26-3MdTq0Uwja-vfaM8",{"id":3948,"title":3949,"author":7,"body":3950,"category":4060,"date":1669,"description":4061,"draft":244,"excerpt":245,"extension":246,"heroImage":245,"heroImageAlt":245,"meta":4062,"navigation":248,"path":4063,"seo":4064,"slug":245,"stem":4065,"tags":4066,"__hash__":4072},"blog\u002Fblog\u002Flevels-of-development-framework-for-regulated-facility-design.md","Levels of Development: Scope Discipline for Regulated Facility Design",{"type":9,"value":3951,"toc":4053},[3952,3955,3959,3965,3997,4001,4007,4013,4019,4023,4030,4034,4037,4040,4042],[12,3953,3954],{},"Regulated facility design projects — cleanroom retrofits, greenfield GMP manufacturing builds,\nlaboratory fit-outs — share a recurring failure pattern: design effort is committed before the\nscope is properly confirmed, the client did not fully know their requirements at project inception,\nand new information part-way through triggers rework that nobody budgeted for. The Levels of\nDevelopment (LOD) framework, originally a BIM design-maturity standard, gives regulated design\npartners such as PharmOut a practical tool for avoiding all three.",[22,3956,3958],{"id":3957},"what-lod-actually-standardises","What LOD actually standardises",[12,3960,3961,3962],{},"LOD is not primarily a geometry standard — it is a design-maturity standard. It answers a specific\nquestion at each project stage: ",[1940,3963,3964],{},"at this point, how much do we know, and how much should we trust\nthis information?",[30,3966,3967,3973,3979,3985,3991],{},[33,3968,3969,3972],{},[61,3970,3971],{},"LOD 100 — Conceptual:"," massing, orientation, indicative only. Reliable for direction and\norder-of-magnitude cost; not reliable for specific dimensions or specifications.",[33,3974,3975,3978],{},[61,3976,3977],{},"LOD 200 — Approximate geometry:"," generic systems, approximate size and location. Reliable for\ngeneral arrangement and rough cost; not reliable for equipment placement or regulatory\ncompliance detail.",[33,3980,3981,3984],{},[61,3982,3983],{},"LOD 300 — Specific geometry:"," defined dimensions, quantities, and specifications, with\nregulatory requirements (GMP, HVAC classification, containment zones) incorporated.",[33,3986,3987,3990],{},[61,3988,3989],{},"LOD 350 — Construction documentation:"," systems coordinated across disciplines, interfaces\ndefined.",[33,3992,3993,3996],{},[61,3994,3995],{},"LOD 400–500 — Fabrication and as-built:"," field-verified final conditions, aligning with\nqualification documentation (IQ\u002FOQ\u002FPQ) in a GMP context.",[22,3998,4000],{"id":3999},"the-three-problems-this-framework-addresses","The three problems this framework addresses",[12,4002,4003,4006],{},[61,4004,4005],{},"Front-loading:"," investing significant effort in high-detail deliverables before the conceptual\nstage has been validated by the client. In a staged framework, this risk concentrates at the\nboundary between scope confirmation and detailed design — committing to detailed work on an\nunconfirmed brief is the direct mechanism by which rework occurs later.",[12,4008,4009,4012],{},[61,4010,4011],{},"Client uncertainty:"," most clients know their outcome — a licensed, compliant facility — without\nyet knowing the full path to it. Regulatory requirements are not always visible until they are\nencountered. A staged framework accommodates this by making sign-off at each level a formal gate:\nthe client does not need to know everything at the concept stage, only to confirm what is known so\nfar is correct.",[12,4014,4015,4018],{},[61,4016,4017],{},"Rescoping:"," without a staged framework, design changes driven by new client information get\nabsorbed as \"normal project activity\" — the design team bears the cost. A staged framework changes\nthat: if a client approved an early-stage scope and then changed direction, that is a documented\ndesign variation, not a design error, and post-approval changes become billable.",[22,4020,4022],{"id":4021},"the-reverse-brief","The reverse brief",[12,4024,4025,4026,4029],{},"A reverse brief is produced by the design team, not the client, at the end of discovery: ",[1940,4027,4028],{},"\"Based on\nwhat you have told us, here is what we understand your project to be. These are our assumptions.\nPlease review, correct, and confirm.\""," It converts the client's words into the design team's\ninterpreted understanding, made explicit so errors of interpretation are caught before they become\nerrors of design — and it maps naturally to the transition from initial brief to a confirmed\nrequirements package.",[22,4031,4033],{"id":4032},"practical-application","Practical application",[12,4035,4036],{},"The discipline generalises well beyond physical design: define the expected level of detail at each\nstage gate in the contract itself; treat early-stage requirements packages as a client-confirmed\ndocument rather than an internal input; treat stage sign-off as a documented contract milestone, not\na verbal understanding; and price early discovery and scoping stages as standalone engagements\nrather than absorbing them into detailed design.",[12,4038,4039],{},"The underlying discipline — do not do high-detail work until an earlier stage is confirmed — applies\nequally to validation projects, GMP consulting engagements, and regulatory submissions. Agreeing\nwhat level of detail will be delivered, delivering it, confirming it, and only then proceeding is not\na slowdown. It is the mechanism by which regulated projects stay on scope and on budget.",[22,4041,1645],{"id":1644},[30,4043,4044,4048],{},[33,4045,4046],{},[55,4047,3188],{"href":3187},[33,4049,4050],{},[55,4051,4052],{"href":576},"Quality systems pathway",{"title":232,"searchDepth":233,"depth":233,"links":4054},[4055,4056,4057,4058,4059],{"id":3957,"depth":233,"text":3958},{"id":3999,"depth":233,"text":4000},{"id":4021,"depth":233,"text":4022},{"id":4032,"depth":233,"text":4033},{"id":1644,"depth":233,"text":1645},"Quality Systems","How the BIM Levels of Development framework, applied by partners like PharmOut, gives regulated facility projects a shared language for design maturity and scope.",{},"\u002Fblog\u002Flevels-of-development-framework-for-regulated-facility-design",{"title":3949,"description":4061},"blog\u002Flevels-of-development-framework-for-regulated-facility-design",[4067,4068,4069,4070,4071],"project-delivery","scope-management","gmp-facility-design","lod","pharmout","cmUSKVLoQsGsYb0yCF0adextZkrV3yjpAIB5CX6vNMM",{"id":4074,"title":1659,"author":7,"body":4075,"category":1668,"date":1669,"description":4279,"draft":244,"excerpt":245,"extension":246,"heroImage":245,"heroImageAlt":245,"meta":4280,"navigation":248,"path":1658,"seo":4281,"slug":245,"stem":4282,"tags":4283,"__hash__":4287},"blog\u002Fblog\u002Foperating-ai-agents-in-gxp-qa-practitioners-guide.md",{"type":9,"value":4076,"toc":4268},[4077,4080,4084,4087,4091,4141,4144,4148,4151,4155,4158,4218,4222,4225,4229,4232,4236,4239,4243,4246,4248],[12,4078,4079],{},"AI agents are entering the GxP quality landscape, and the professionals best placed to govern them\nare Quality Assurance practitioners, qualified persons, and auditors — not AI specialists. The\ngovernance and oversight required to maintain a validated state can be understood without a\ntechnical background, provided one core reframe is made first.",[22,4081,4083],{"id":4082},"the-core-reframe","The core reframe",[12,4085,4086],{},"Stop viewing AI solely as software to be validated. Treat it instead as an autonomous worker to be\ngoverned. The primary risk is not the technology itself — it is the absence of rigorous operational\ncontrol around it.",[22,4088,4090],{"id":4089},"eight-operating-principles","Eight operating principles",[1573,4092,4093,4099,4105,4111,4117,4123,4129,4135],{},[33,4094,4095,4098],{},[61,4096,4097],{},"Specification before execution."," Validate that the task is appropriate for AI application;\nensure the operational scope is strictly defined and explicitly prohibits open-ended or\nnon-deterministic execution.",[33,4100,4101,4104],{},[61,4102,4103],{},"Deterministic inputs."," Verify that source records are comprehensive, authorised, and\nversion-controlled; maintain data integrity protocols that prevent unauthorised post-hoc\nmodification.",[33,4106,4107,4110],{},[61,4108,4109],{},"Bounded autonomy."," Clearly define the limits of AI authority; ensure decision-making remains\nhuman-centred and prevent the silent escalation of agent authority over time.",[33,4112,4113,4116],{},[61,4114,4115],{},"Evidence-first outputs."," Treat AI outputs as draft evidence; review the underlying logic and\nrationale, not just the final result, to ensure conclusions are substantiated by auditable data.",[33,4118,4119,4122],{},[61,4120,4121],{},"Human-in-the-loop verification."," Conduct risk-based verification of outputs; focus oversight\non high-impact findings, and ensure human accountability for any data supporting GxP compliance.",[33,4124,4125,4128],{},[61,4126,4127],{},"Full traceability."," Maintain continuous audit readiness; guarantee decision pathways are\nreconstructible and aligned with ALCOA+ expectations.",[33,4130,4131,4134],{},[61,4132,4133],{},"Segregated agent roles."," An executing agent must never review its own output; use a secondary\nagent with independent prompts and evaluation criteria for objective oversight.",[33,4136,4137,4140],{},[61,4138,4139],{},"Contextual task alignment."," Reserve agent use for tasks requiring complex reasoning — pattern\nidentification, semi-structured data interpretation — and avoid agent-based automation for rigid\nrule enforcement or binary logic.",[12,4142,4143],{},"The one-line rule: if the answer is algorithmic, avoid agents. If the challenge is interpretive,\nleverage them.",[22,4145,4147],{"id":4146},"what-qa-remains-accountable-for","What QA remains accountable for",[12,4149,4150],{},"QA maintains absolute authority over compliance determinations, batch disposition, regulatory\ninterpretation, and audit defence. AI serves as a high-fidelity analytical tool; QA remains the sole\ndecision-making entity. The recurring governance failures are cognitive bias toward AI outputs,\nsubstandard data pedigree, uncontrolled scope expansion, and fragmented audit trails — lapses in\noperational governance, not technological deficiencies.",[22,4152,4154],{"id":4153},"governing-agents-within-the-qms-you-already-have","Governing agents within the QMS you already have",[12,4156,4157],{},"AI agents do not need a parallel quality system — they need to be fully integrated into the\nexisting QMS:",[371,4159,4160,4170],{},[374,4161,4162],{},[377,4163,4164,4167],{},[380,4165,4166],{},"Quality system element",[380,4168,4169],{},"How it applies to AI agents",[390,4171,4172,4180,4188,4195,4203,4210],{},[377,4173,4174,4177],{},[395,4175,4176],{},"SOPs",[395,4178,4179],{},"Define agent scope, functional responsibilities, and standardised operating procedures",[377,4181,4182,4185],{},[395,4183,4184],{},"Controlled records",[395,4186,4187],{},"Maintain agent specifications, execution logs, and verification outputs as formal GMP records",[377,4189,4190,4192],{},[395,4191,170],{},[395,4193,4194],{},"Manage modifications to agent scope, prompt libraries, or workflow logic",[377,4196,4197,4200],{},[395,4198,4199],{},"Deviation management",[395,4201,4202],{},"Address AI-related performance anomalies through standard deviation procedures",[377,4204,4205,4207],{},[395,4206,769],{},[395,4208,4209],{},"Evaluate agent performance and control effectiveness on a defined schedule",[377,4211,4212,4215],{},[395,4213,4214],{},"Training",[395,4216,4217],{},"Verify personnel operating or validating AI outputs are qualified on established criteria",[22,4219,4221],{"id":4220},"documenting-agents-as-quality-roles","Documenting agents as quality roles",[12,4223,4224],{},"Before integration into GxP workflows, every agent role requires formal, approved documentation\ncovering intended use and human-oversight boundaries; defined scope and exclusions, including data\nsets in scope and functions outside authority; verification responsibilities, methodology, and\nacceptance criteria; and known limitations, prohibited use conditions, and failure modes requiring\nmonitoring. This documentation fulfils the specification-before-execution principle directly.",[22,4226,4228],{"id":4227},"change-control-that-is-actually-risk-based","Change control that is actually risk-based",[12,4230,4231],{},"Not every AI modification needs formal change control. It is required for changes to scope or\nintended use, prompt or instruction logic, workflow or integration, and input source dependencies.\nIt is not required for vendor-managed platform updates that do not affect scope or authorised\nintended use, routine performance monitoring, or purely cosmetic formatting changes. The test is\nwhether the change alters the agent's functional purpose, interpretive logic, or the resulting\nquality decisions.",[22,4233,4235],{"id":4234},"treating-ai-deviations-as-quality-events","Treating AI deviations as quality events",[12,4237,4238],{},"AI-related quality issues belong inside existing deviation and CAPA frameworks, and root cause\nanalysis should prioritise governance controls over technical debugging: identify which control —\nspecification, input validation, verification, or traceability — failed; analyse contributing\nfactors such as scope ambiguity or training gaps; assess the impact on product quality, patient\nsafety, and compliance; and remediate through governance fixes, such as SOP revision or refined\nscope, rather than purely technical fixes.",[22,4240,4242],{"id":4241},"the-final-takeaway","The final takeaway",[12,4244,4245],{},"AI agents do not weaken compliance postures; poorly governed agents do. Operationalised with rigour,\nAI agents strengthen consistency, analytical coverage, and the precision of quality decision-making\n— because GxP's institutional documentation rigour, standardised procedures, explicit ownership, and\nestablished verification culture already provide an optimal environment for governing a new kind of\nworker.",[22,4247,1645],{"id":1644},[30,4249,4250,4254,4260,4264],{},[33,4251,4252],{},[55,4253,1683],{"href":1809},[33,4255,4256],{},[55,4257,4259],{"href":4258},"\u002Fblog\u002Fregulatory-expectations-for-ai-agents-in-gmp","Regulatory Expectations for AI Agents in GMP",[33,4261,4262],{},[55,4263,1653],{"href":1652},[33,4265,4266],{},[55,4267,2360],{"href":2359},{"title":232,"searchDepth":233,"depth":233,"links":4269},[4270,4271,4272,4273,4274,4275,4276,4277,4278],{"id":4082,"depth":233,"text":4083},{"id":4089,"depth":233,"text":4090},{"id":4146,"depth":233,"text":4147},{"id":4153,"depth":233,"text":4154},{"id":4220,"depth":233,"text":4221},{"id":4227,"depth":233,"text":4228},{"id":4234,"depth":233,"text":4235},{"id":4241,"depth":233,"text":4242},{"id":1644,"depth":233,"text":1645},"The core reframe for AI agent governance in regulated quality work — stop treating AI as software to validate, and start governing it as a worker within your QMS.",{},{"title":1659,"description":4279},"blog\u002Foperating-ai-agents-in-gxp-qa-practitioners-guide",[1813,1814,4284,4285,4286],"qa","quality-management-system","agent-governance","-c-Gyeyl54NswB8u9zQUT5q5wp98DBFqGa1iMVS2D80",{"id":4289,"title":2350,"author":7,"body":4290,"category":1668,"date":1669,"description":4474,"draft":244,"excerpt":245,"extension":246,"heroImage":245,"heroImageAlt":245,"meta":4475,"navigation":248,"path":2349,"seo":4476,"slug":245,"stem":4477,"tags":4478,"__hash__":4481},"blog\u002Fblog\u002Fpharma-does-not-need-a-new-ai-governance-religion.md",{"type":9,"value":4291,"toc":4466},[4292,4295,4299,4302,4306,4309,4347,4350,4354,4357,4429,4433,4440,4444,4447,4450,4452],[12,4293,4294],{},"Most industries are still working out how to implement and govern AI. Pharma is in a different\nposition. In GMP environments, governance is already an operating discipline. The Pharmaceutical\nQuality System, supported by Quality by Design, Critical to Quality attributes, and process\nparameter control, already provides a practical foundation for governing a new type of worker: the\nAI agent. The opportunity is not to invent a parallel governance stack. It is to map AI agent\nmanagement maturity to quality management maturity, and run it with the same rigour already applied\nto every other regulated process.",[22,4296,4298],{"id":4297},"pharma-already-speaks-the-language","Pharma already speaks the language",[12,4300,4301],{},"Recent agentic-AI direction from major platform vendors emphasises lifecycle controls, trust\nboundaries, layered verification, and continuous evaluation for AI agents. For pharma teams, that is\nnot unfamiliar territory — it maps closely to existing GMP operating logic: define intended use and\nquality objectives up front; control the process conditions that materially influence quality\noutcomes; verify continuously against defined critical-to-quality attributes; and act on drift with\ncorrective action when performance deviates from approved operating ranges. That is already how\nmature quality systems are managed. The vocabulary of AI agent governance and GMP governance are, in\npractice, the same.",[22,4303,4305],{"id":4304},"governance-is-a-systems-view-not-a-model-check","Governance is a systems view, not a model check",[12,4307,4308],{},"When an AI agent participates in a regulated workflow, governance cannot rely on isolated model\nchecks alone — the full operating system has to be brought under control:",[30,4310,4311,4317,4323,4329,4335,4341],{},[33,4312,4313,4316],{},[61,4314,4315],{},"Role and intended use:"," a clearly defined function within the regulated workflow, with\ndocumented decision boundaries and scope limitations.",[33,4318,4319,4322],{},[61,4320,4321],{},"Approved data and tool boundaries:"," explicit allow-lists for data sources, retrieval scope,\nand tool permissions, controlled rather than assumed.",[33,4324,4325,4328],{},[61,4326,4327],{},"Execution controls:"," runtime configuration, model version, prompt version, and fallback\nrouting treated as controlled parameters.",[33,4330,4331,4334],{},[61,4332,4333],{},"Human review points:"," mandatory review gates at compliance-critical decision points, with\nevidence of review captured.",[33,4336,4337,4340],{},[61,4338,4339],{},"Evidence and traceability:"," audit-ready provenance records for every agent output used in a\nregulated decision.",[33,4342,4343,4346],{},[61,4344,4345],{},"Change control and revalidation:"," formal lifecycle gates for model updates, prompt changes,\nand configuration modifications.",[12,4348,4349],{},"That is a systems view, and it aligns directly with the quality-system principles already embedded\nin mature pharmaceutical organisations.",[22,4351,4353],{"id":4352},"a-five-level-maturity-map","A five-level maturity map",[12,4355,4356],{},"AI agent management maturity maps directly to QMS maturity levels, with a characteristic governance\nsignal at each stage:",[371,4358,4359,4372],{},[374,4360,4361],{},[377,4362,4363,4366,4369],{},[380,4364,4365],{},"Level",[380,4367,4368],{},"QMS analogue",[380,4370,4371],{},"Typical signal",[390,4373,4374,4385,4396,4407,4418],{},[377,4375,4376,4379,4382],{},[395,4377,4378],{},"1 — Ad hoc",[395,4380,4381],{},"Reactive quality posture",[395,4383,4384],{},"Inconsistent output quality, low traceability",[377,4386,4387,4390,4393],{},[395,4388,4389],{},"2 — Documented",[395,4391,4392],{},"Basic defined system",[395,4394,4395],{},"Repeatable process, fragile under variation",[377,4397,4398,4401,4404],{},[395,4399,4400],{},"3 — Controlled",[395,4402,4403],{},"Managed quality system",[395,4405,4406],{},"Stable operation with auditable evidence",[377,4408,4409,4412,4415],{},[395,4410,4411],{},"4 — Predictive",[395,4413,4414],{},"Capable quality system",[395,4416,4417],{},"Risks detected before quality failure occurs",[377,4419,4420,4423,4426],{},[395,4421,4422],{},"5 — Optimised",[395,4424,4425],{},"Continuous-improvement maturity",[395,4427,4428],{},"Sustained performance improvement, controlled risk",[22,4430,4432],{"id":4431},"applying-quality-by-design-to-agents","Applying Quality by Design to agents",[12,4434,4435,4436,4439],{},"Before any AI agent enters a regulated workflow, teams can define an ",[61,4437,4438],{},"Agent Quality Target\nProfile"," — the agent equivalent of a product quality target profile: intended role, decision\nboundaries, required evidence outputs, acceptable failure modes, and mandatory human checkpoints.\nCritical-to-quality attributes for an agent include output accuracy against approved references,\nprovenance completeness of retrieved information, explainability at the required review depth, and\ntimeliness within approved process windows. Critical process parameters — model version, prompt\nversion, retrieval scope, tool permissions, confidence thresholds, timeout and retry policy — are\nthe controlled inputs that materially influence those attributes, and treating them as informal\nsettings rather than controlled parameters is where AI agent governance breaks down.",[22,4441,4443],{"id":4442},"a-stage-gated-rollout","A stage-gated rollout",[12,4445,4446],{},"Teams do not need to reach maturity level 5 before deploying AI agents responsibly. A structured\nrollout mirrors the phased approach used in process validation and CAPA management: map current\nmaturity, apply Quality by Design and critical-to-quality frameworks to define and measure agent\nperformance as a regulated process, verify continuously against defined attributes, and feed\nperformance findings into CAPA-style improvement cycles over time.",[12,4448,4449],{},"The fastest path to safe AI adoption in GMP is to govern agents with the same discipline already\nused for any critical process. The bedrock for AI agent governance already exists inside mature\nquality systems — the work now is structured adaptation, not reinvention.",[22,4451,1645],{"id":1644},[30,4453,4454,4458,4462],{},[33,4455,4456],{},[55,4457,1653],{"href":1652},[33,4459,4460],{},[55,4461,1659],{"href":1658},[33,4463,4464],{},[55,4465,2360],{"href":2359},{"title":232,"searchDepth":233,"depth":233,"links":4467},[4468,4469,4470,4471,4472,4473],{"id":4297,"depth":233,"text":4298},{"id":4304,"depth":233,"text":4305},{"id":4352,"depth":233,"text":4353},{"id":4431,"depth":233,"text":4432},{"id":4442,"depth":233,"text":4443},{"id":1644,"depth":233,"text":1645},"AI governance in pharma is not a greenfield problem. It is a quality-systems extension problem — mapping AI agent management maturity to QMS maturity that already exists.",{},{"title":2350,"description":4474},"blog\u002Fpharma-does-not-need-a-new-ai-governance-religion",[2375,257,4479,1813,4480],"qms","quality-by-design","ufbstCZlnGivKyHIEPfyRDtTAmKJ5rIAkcSorXFGjJk",{"id":4483,"title":4484,"author":7,"body":4485,"category":241,"date":1669,"description":4609,"draft":244,"excerpt":245,"extension":246,"heroImage":245,"heroImageAlt":245,"meta":4610,"navigation":248,"path":3187,"seo":4611,"slug":245,"stem":4612,"tags":4613,"__hash__":4618},"blog\u002Fblog\u002Fpractical-risk-based-computerised-system-validation.md","Practical Risk-Based Computerised System Validation (CSV): Assurance Over Paperwork",{"type":9,"value":4486,"toc":4600},[4487,4493,4496,4500,4503,4506,4510,4513,4527,4530,4534,4537,4557,4561,4564,4568,4571,4575,4582,4584],[12,4488,4489,4490],{},"Computerised system validation (CSV) is, at its core, about confidence. Regulated organisations use\ncomputerised systems to manage critical processes and data; when those systems fail or behave\nunexpectedly, the consequences range from minor inconvenience to serious harm. Validation exists to\nanswer one question, repeatedly: ",[61,4491,4492],{},"what risk are we controlling, and how do we know it is\ncontrolled?",[12,4494,4495],{},"That question — not document volume — is what inspectors are actually assessing.",[22,4497,4499],{"id":4498},"why-context-matters-more-than-system-labels","Why context matters more than system labels",[12,4501,4502],{},"A common misconception treats validation effort as determined by what a system is called: an eQMS\ngets one level of rigour, a LIMS another, a document-management platform a third. In practice, the\nlevel of control required is determined by what the system does, how it is used, and what could go\nwrong — not by its category label.",[12,4504,4505],{},"A low-category system can still require extensive functional verification where a specific function\ncarries high risk. Electronic signature controls within an otherwise lower-risk batch-release system\nare a good example: the function, not the system category, drives the depth of testing.",[22,4507,4509],{"id":4508},"where-validation-value-is-actually-created","Where validation value is actually created",[12,4511,4512],{},"The majority of validation value is created upfront, before testing begins, in two steps:",[1573,4514,4515,4521],{},[33,4516,4517,4520],{},[61,4518,4519],{},"Define user requirements."," What does the business depend on the system to do? What is\ncritical to product quality and patient safety? If this step is weak, everything downstream\nbecomes reactive rather than controlled.",[33,4522,4523,4526],{},[61,4524,4525],{},"Risk-assess every requirement."," For each requirement: what happens if it fails, who or what\nis affected, how severe would the impact be, how likely is it, and how would it be detected or\nprevented? This determines which functions are high-risk and where testing effort should\nconcentrate.",[12,4528,4529],{},"Strong requirements and risk assessment make testing focused and evidence coherent. Weak\nrequirements mean no amount of testing fully compensates — effort gets spent on low-risk activity\nwhile real gaps remain undetected.",[22,4531,4533],{"id":4532},"a-minimum-evidence-pack","A minimum evidence pack",[12,4535,4536],{},"A defensible, proportionate CSV evidence pack typically includes:",[30,4538,4539,4542,4545,4548,4551,4554],{},[33,4540,4541],{},"requirements, risk assessment, and validation planning;",[33,4543,4544],{},"traceability from requirement to risk to test to release decision;",[33,4546,4547],{},"verification evidence scaled to risk, not exhaustive by default;",[33,4549,4550],{},"data-integrity controls mapped to ALCOA+ (attribution, audit trails, timestamps, original\nrecords);",[33,4552,4553],{},"electronic signature meaning and authority checks;",[33,4555,4556],{},"change-trigger logic for revalidation scope, and evidence for data migration or system\nretirement.",[22,4558,4560],{"id":4559},"supplier-and-saas-governance","Supplier and SaaS governance",[12,4562,4563],{},"Modern computerised systems are increasingly configured platforms and vendor-managed services.\nOutsourcing infrastructure or software does not outsource accountability. A proportionate approach\nassesses supplier capability and evidence, uses quality agreements to define responsibilities\nclearly, and applies retained internal oversight for security, availability, backup, and data\nintegrity — without duplicating the supplier's own testing.",[22,4565,4567],{"id":4566},"validated-state-does-not-end-at-go-live","Validated state does not end at go-live",[12,4569,4570],{},"Most audit findings occur after implementation, not at it. Sustaining a validated state requires\nactive governance: change control with impact assessment, regression assessment scoped to the\nchange, periodic review of continued fitness for use, and treating incidents and deviations as\nvalidation inputs rather than a separate quality activity.",[22,4572,4574],{"id":4573},"the-takeaway-for-inspection-readiness","The takeaway for inspection readiness",[12,4576,4577,4578,4581],{},"Defensibility comes from decision quality and evidence coherence, not document volume. A validation\npackage that shows ",[1940,4579,4580],{},"why"," the selected controls are sufficient — with full traceability from\nrequirement to risk to test to release — will hold up under audit pressure better than a much larger\npackage that cannot explain its own reasoning. Risk-based CSV is not a shortcut around rigour; it is\nwhere the rigour is deliberately placed.",[22,4583,1645],{"id":1644},[30,4585,4586,4592,4596],{},[33,4587,4588],{},[55,4589,4591],{"href":4590},"\u002Fblog\u002Fwhat-fda-csv-citations-reveal-about-your-next-gmp-inspection","What FDA CSV Citations Reveal About Your Next GMP Inspection",[33,4593,4594],{},[55,4595,222],{"href":221},[33,4597,4598],{},[55,4599,4052],{"href":576},{"title":232,"searchDepth":233,"depth":233,"links":4601},[4602,4603,4604,4605,4606,4607,4608],{"id":4498,"depth":233,"text":4499},{"id":4508,"depth":233,"text":4509},{"id":4532,"depth":233,"text":4533},{"id":4559,"depth":233,"text":4560},{"id":4566,"depth":233,"text":4567},{"id":4573,"depth":233,"text":4574},{"id":1644,"depth":233,"text":1645},"Computerised system validation exists to build confidence, not paperwork. A practical, risk-based approach to CSV for teams moving from paper to electronic systems.",{},{"title":4484,"description":4609},"blog\u002Fpractical-risk-based-computerised-system-validation",[4614,4615,4616,4617,257],"csv","computerized-system-validation","gamp5","risk-based-validation","xHBNvLvlX5BkYS78dAmo8538aFD-_TVUmoXJZA8wgW0",{"id":4620,"title":1653,"author":7,"body":4621,"category":1668,"date":1669,"description":4704,"draft":244,"excerpt":245,"extension":246,"heroImage":245,"heroImageAlt":245,"meta":4705,"navigation":248,"path":1652,"seo":4706,"slug":245,"stem":4707,"tags":4708,"__hash__":4713},"blog\u002Fblog\u002Fqxaios-compliance-centric-operating-model-for-ai-systems.md",{"type":9,"value":4622,"toc":4697},[4623,4626,4630,4636,4642,4648,4654,4660,4664,4667,4671,4674,4678,4681,4683],[12,4624,4625],{},"Modern AI platforms are powerful but probabilistic — they generate outputs through contextual\nreasoning rather than deterministic logic. That single fact is the root of most AI governance\nfailure patterns: systems that perform work and self-validate, no lifecycle control or versioning,\nlimited audit trails, over-automation without human verification, and an inability to demonstrate\nedge-case behaviour. QxAIOS treats AI as an operational system subject to governance, oversight, and\ncontinuous improvement — good practice first, regulation second.",[22,4627,4629],{"id":4628},"five-operating-principles","Five operating principles",[12,4631,4632,4635],{},[61,4633,4634],{},"1. Separation of doing and checking."," A structural separation between agents that perform work\nand agents or humans that independently review it. Performing agents generate outputs — analysis,\nextraction, classification, recommendations. Reviewing agents or humans independently assess those\noutputs against defined criteria. This aligns with four-eyes principles and data integrity\nexpectations, and reduces error propagation and silent failure modes.",[12,4637,4638,4641],{},[61,4639,4640],{},"2. Bounded agent roles and intent."," Each agent has a clearly defined purpose, scope, and\nresponsibility — designed as a role, not a general-purpose problem-solver, with explicit and\ncontrolled inputs, expectation-bound structured outputs, and a declared remit that prohibits\noperation outside scope. This supports validation, risk assessment, and impact analysis, and\nimproves predictability, maintainability, and organisational trust.",[12,4643,4644,4647],{},[61,4645,4646],{},"3. End-to-end traceability by design."," Every AI action is linked across the full lifecycle:\nsource inputs, agent configuration (prompt version and settings), reasoning artefacts where\nappropriate, outputs and findings, and human review disposition and approval. This enables defensible\naudit trails and root-cause analysis, and makes AI systems explainable and improvable rather than\nopaque.",[12,4649,4650,4653],{},[61,4651,4652],{},"4. Controlled change and versioning."," AI behaviour changes when prompts, models, tools, or\ncontext change — QxAIOS treats these as controlled changes: agent definitions are versioned, changes\nare reviewed and approved before deployment, and outputs remain linked to the configuration that\nproduced them. This aligns with change-control and validation lifecycle expectations, and prevents\nunintentional drift while supporting safe innovation.",[12,4655,4656,4659],{},[61,4657,4658],{},"5. Human-in-the-loop as a feature."," QxAIOS explicitly designs for human verification wherever\noutcomes matter — not as a limitation, but as a strategic advantage. AI accelerates preparation,\nanalysis, and detection at scale; humans retain authority for confirmation, approval, and release\ndecisions. This preserves accountability and decision ownership while improving decision quality.",[22,4661,4663],{"id":4662},"platform-agnostic-by-design","Platform-agnostic by design",[12,4665,4666],{},"QxAIOS principles are not tied to any single vendor or model, and are commonly implemented on\nMicrosoft Azure, Copilot Studio, or similar enterprise platforms. Responsibility for AI outcomes\nsits with the regulated entity, not the technology provider — which is precisely why the operating\nmodel, not the platform, is what needs to be demonstrable. QxAIOS lets an organisation show that AI\nusage is governed internally, that design decisions are aligned to risk, and that its AI systems can\nbe defended on control rather than vendor assurances.",[22,4668,4670],{"id":4669},"beyond-compliance-organisational-maturity","Beyond compliance: organisational maturity",[12,4672,4673],{},"Organisations adopting this kind of operating model report benefits that extend beyond regulatory\nrequirements: increased internal trust in AI outputs across teams, faster onboarding of new AI use\ncases because clear patterns already exist, reduced friction between IT, quality, and business\nfunctions, and improved audit readiness for future scrutiny. The model reframes AI from an\nexperimental capability into a managed operational asset.",[22,4675,4677],{"id":4676},"the-question-that-matters","The question that matters",[12,4679,4680],{},"AI will increasingly participate in high-value, high-risk work. The question is no longer whether\norganisations can use AI — it is whether they can do so responsibly, transparently, and sustainably.\nA compliance-centric operating model that embeds good-practice principles naturally aligned with\nregulatory expectations lets an organisation move with confidence rather than caution, and positions\ncompliance not as a constraint but as an enabler of responsible AI adoption at scale.",[22,4682,1645],{"id":1644},[30,4684,4685,4689,4693],{},[33,4686,4687],{},[55,4688,1659],{"href":1658},[33,4690,4691],{},[55,4692,2350],{"href":2349},[33,4694,4695],{},[55,4696,2360],{"href":2359},{"title":232,"searchDepth":233,"depth":233,"links":4698},[4699,4700,4701,4702,4703],{"id":4628,"depth":233,"text":4629},{"id":4662,"depth":233,"text":4663},{"id":4669,"depth":233,"text":4670},{"id":4676,"depth":233,"text":4677},{"id":1644,"depth":233,"text":1645},"A structured, compliance-aligned approach to operating AI agents as controlled digital workers in regulated environments — good practice first, regulation second.",{},{"title":1653,"description":4704},"blog\u002Fqxaios-compliance-centric-operating-model-for-ai-systems",[4709,2375,4710,4711,4712],"qxaios","operating-model","human-in-the-loop","traceability","UZzE2x1Cp4qbi37iUSGYm1rLy551azZXrqOjrE6qQMw",{"id":4715,"title":4259,"author":7,"body":4716,"category":1668,"date":1669,"description":4826,"draft":244,"excerpt":245,"extension":246,"heroImage":245,"heroImageAlt":245,"meta":4827,"navigation":248,"path":4258,"seo":4828,"slug":245,"stem":4829,"tags":4830,"__hash__":4836},"blog\u002Fblog\u002Fregulatory-expectations-for-ai-agents-in-gmp.md",{"type":9,"value":4717,"toc":4820},[4718,4724,4728,4731,4734,4738,4747,4753,4759,4765,4771,4777,4783,4789,4793,4796,4803,4805],[12,4719,4720,4721],{},"Global regulators now recognise that AI agents and large language models play an active role in\nGxP environments, and their guidance is converging on a consistent principle: ",[61,4722,4723],{},"AI agents may\nsupport quality operations, but they cannot replace human accountability.",[22,4725,4727],{"id":4726},"where-fda-tga-ema-and-mhra-agree","Where FDA, TGA, EMA, and MHRA agree",[12,4729,4730],{},"Across current guidance, draft annexes, and public statements, regulators are aligned on five core\nprinciples: AI agents constitute a computerised system under GMP; intended use remains the primary\nregulatory anchor; validation prioritises fitness for purpose over model internals; human oversight\nis mandatory for compliance-critical decisions; and traceability and data integrity remain\nnon-negotiable. This consensus appears in FDA draft guidance on AI credibility and risk-based\nvalidation, the draft EU GMP Annex 22 on artificial intelligence, MHRA's participation in\ninternational AI principles and sandbox programmes, and TGA consultation outcomes on software and AI\nin regulated use.",[12,4732,4733],{},"Regulators do not expect organisations to validate or explain the internal workings of commercial AI\nagents. They do require control over the rationale for AI agent use, the defined tasks it performs,\nits data access parameters, the output review and application process, and the accountability\nframework around it — the same expectations already applied to ERP and QMS platforms.",[22,4735,4737],{"id":4736},"eight-practical-expectations","Eight practical expectations",[12,4739,4740,4743,4744],{},[61,4741,4742],{},"1. Define intended use clearly."," Intended use is the single most important document produced for\nregulatory purposes — it defines the scope of deployment, sets validation boundaries, and\ndetermines the level of human oversight required. A well-formed statement is specific and bounded:\n",[1940,4745,4746],{},"\"AI agents are used to assist with contextual review of GMP records. They do not approve, release,\nor certify data.\"",[12,4748,4749,4752],{},[61,4750,4751],{},"2. Apply risk-based validation."," Validation depth should match the risk profile of the task.\nRegulators expect scenario-based testing across typical and edge cases, testing with representative\ndata, subject-matter-expert review of outputs, and performance benchmarks against prior methods.\nThey do not require mathematical proof of correctness, access to model weights, or revalidation\nafter every vendor model update.",[12,4754,4755,4758],{},[61,4756,4757],{},"3. Maintain mandatory human oversight."," Every major agency has stated clearly that AI agents may\ninform, assist, and accelerate quality work, but may not replace qualified human judgement. The\ndistinction is between assistive use, where an agent supports a human decision, and autonomous use,\nwhere an agent makes or finalises a decision without review. Delegating a task to an agent does not\ntransfer regulatory responsibility.",[12,4760,4761,4764],{},[61,4762,4763],{},"4. Prioritise evidence-based outputs."," An agent output accepted without review, challenge, or\ntraceability is indistinguishable from an undocumented decision — a data integrity risk. Treat all\nagent outputs as working papers, ensure every output is reviewable by a qualified person before it\ninfluences a GMP decision, and ensure all outputs trace back to the source data reviewed.",[12,4766,4767,4770],{},[61,4768,4769],{},"5. Maintain traceability and data integrity."," Every interaction between an agent and quality data\nshould be captured, timestamped, and linked to a human action, covering input data, timestamp,\nagent output, and human decision — mapping directly to ALCOA+ principles.",[12,4772,4773,4776],{},[61,4774,4775],{},"6. Apply segregation of duties."," Regulators respond positively to architectures where no single\nagent both performs and approves a task. A two-agent model — one executes, a second independently\nreviews, a human verifies and decides — mirrors the author\u002Freviewer patterns already embedded in\npharmaceutical quality systems.",[12,4778,4779,4782],{},[61,4780,4781],{},"7. Set explainability expectations pragmatically."," Regulators do not expect explanation of neural\nnetwork internals or reproducibility of individual outputs. They do expect clear documented\ndescriptions of the agent workflow, transparent criteria for evaluating outputs, and honest\nacknowledgement of known limitations.",[12,4784,4785,4788],{},[61,4786,4787],{},"8. Manage change control and monitoring."," Prompt iterations, workflow adjustments, and data\nsource changes belong inside existing change control. Vendor-managed model updates sit outside\ndirect control, and the risk from those changes is mitigated through human verification, periodic\noutput review, and defined escalation — not by attempting to control what cannot be accessed.",[22,4790,4792],{"id":4791},"preparing-for-inspection","Preparing for inspection",[12,4794,4795],{},"Auditors typically ask why AI agents are used in a given process, how reliability is validated, who\nverifies outputs, what the contingency is for errors, and whether the organisation can demonstrate a\nconcrete example. They generally avoid probing training methodology, internal algorithmic function,\nor vendor-selection rationale — the focus is on governance, not technical architecture.",[12,4797,4798,4799,4802],{},"A regulatory-safe position statement, consistent across FDA, TGA, and EMA\u002FMHRA expectations, reads:\n",[1940,4800,4801],{},"\"We use AI agents as a controlled, assistive tool within our quality system. Human authority drives\nall compliance-critical decisions, ensuring full traceability and oversight.\""," Adopting AI agents\nunder that governance model — retaining full accountability, anchoring use in human oversight, and\nmanaging the governance rather than the technology — is what regulators across jurisdictions are\nconverging on.",[22,4804,1645],{"id":1644},[30,4806,4807,4811,4816],{},[33,4808,4809],{},[55,4810,1659],{"href":1658},[33,4812,4813],{},[55,4814,4815],{"href":3824},"From Annex 22 to Agentic AI",[33,4817,4818],{},[55,4819,1653],{"href":1652},{"title":232,"searchDepth":233,"depth":233,"links":4821},[4822,4823,4824,4825],{"id":4726,"depth":233,"text":4727},{"id":4736,"depth":233,"text":4737},{"id":4791,"depth":233,"text":4792},{"id":1644,"depth":233,"text":1645},"What FDA, EMA, MHRA, and TGA actually expect of AI agents in GxP — appropriately scoped, risk-based, transparent, human-overseen, and fully traceable.",{},{"title":4259,"description":4826},"blog\u002Fregulatory-expectations-for-ai-agents-in-gmp",[1813,257,4831,4832,4833,4834,4835],"fda","ema","mhra","tga","regulatory-compliance","uc0Ctu_pVFioOOYkmtoIamuBo5hftYlgjtP1HJ2nBH0",{"id":4838,"title":4839,"author":7,"body":4840,"category":4973,"date":1669,"description":4974,"draft":244,"excerpt":245,"extension":246,"heroImage":245,"heroImageAlt":245,"meta":4975,"navigation":248,"path":4976,"seo":4977,"slug":245,"stem":4978,"tags":4979,"__hash__":4983},"blog\u002Fblog\u002Funlocking-productivity-with-microsoft-365-copilot-tasks.md","Unlocking Productivity with Microsoft 365 Copilot Tasks",{"type":9,"value":4841,"toc":4965},[4842,4845,4848,4852,4878,4882,4888,4894,4900,4906,4910,4913,4939,4943,4946,4950,4953,4955],[12,4843,4844],{},"Copilot Tasks is a Microsoft 365 capability that lets a user delegate complex, multi-step work to\nCopilot using plain natural language — describe what you need done, and Copilot interprets intent\nand acts, handling entire workflows end-to-end rather than a single instruction, either on demand or\non a defined schedule.",[12,4846,4847],{},"For consulting firms operating in high-stakes, regulated environments, that capability matters more\nthan it does for a generic office task list. Consultant time is finite; client, regulator, and\nleadership expectations are constant; and a large share of the workload is repetitive coordination\nthat adds no professional judgement of its own.",[22,4849,4851],{"id":4850},"what-copilot-tasks-can-do","What Copilot Tasks can do",[30,4853,4854,4860,4866,4872],{},[33,4855,4856,4859],{},[61,4857,4858],{},"Web and portal interaction:"," browse websites, interact with portals, and perform actions on\nthe user's behalf.",[33,4861,4862,4865],{},[61,4863,4864],{},"File generation and editing:"," create and edit Word, Excel, and PowerPoint files from a single\ninstruction.",[33,4867,4868,4871],{},[61,4869,4870],{},"Scheduled recurring actions:"," run automatically on a defined cadence without a manual trigger.",[33,4873,4874,4877],{},[61,4875,4876],{},"Monitoring and control:"," pause, interrupt, or review task progress at any point, with full\ntransparency.",[22,4879,4881],{"id":4880},"where-the-value-concentrates-in-regulated-consulting-work","Where the value concentrates in regulated consulting work",[12,4883,4884,4887],{},[61,4885,4886],{},"Project management:"," auto-generating structured weekly status reports from emails, files, and\ntask lists; drafting charters, project plans, and risk logs from templates; compiling post-workshop\nfollow-ups and action items automatically.",[12,4889,4890,4893],{},[61,4891,4892],{},"Regulatory and compliance support:"," continuously monitoring regulator portals and publications\nfor updates affecting active projects; generating structured summaries that translate new guidance\ninto actionable insight; tracking overdue corrective actions and quality-system escalations before\ndeadlines are missed.",[12,4895,4896,4899],{},[61,4897,4898],{},"People leadership and client management:"," aggregating team updates into concise briefings;\nscheduling training and certification reminders; distilling lengthy client correspondence into\nactionable summaries; drafting first-pass proposals and responses at speed.",[12,4901,4902,4905],{},[61,4903,4904],{},"Reporting to leadership:"," compiling portfolio, team, and financial data into executive-ready\nweekly briefings; flagging risks and commercial concerns early; assembling pre-meeting packs from\nclient summaries, regulatory updates, and portfolio overviews.",[22,4907,4909],{"id":4908},"governance-is-the-feature-not-an-afterthought","Governance is the feature, not an afterthought",[12,4911,4912],{},"Copilot Tasks is designed with user authority at its centre — Copilot acts as a capable delegate,\nnot an autonomous agent:",[30,4914,4915,4921,4927,4933],{},[33,4916,4917,4920],{},[61,4918,4919],{},"User-initiated only:"," tasks execute only when explicitly started, with no unsanctioned action.",[33,4922,4923,4926],{},[61,4924,4925],{},"Interrupt and stop:"," any task can be halted immediately at any point in execution.",[33,4928,4929,4932],{},[61,4930,4931],{},"Step-by-step transparency:"," the user can monitor exactly what Copilot is doing and why.",[33,4934,4935,4938],{},[61,4936,4937],{},"Approval gating:"," sensitive or high-impact actions require explicit approval before\nproceeding.",[22,4940,4942],{"id":4941},"a-practical-rollout-pattern","A practical rollout pattern",[12,4944,4945],{},"A structured rollout manages risk while delivering value quickly: identify recurring, high-volume,\nor highly manual workflows as first candidates; assess each candidate against data sensitivity and\napproval requirements before automating; pilot within a single team to validate and learn; and\nbuild clear usage guidelines for sensitive data handling and approval thresholds before scaling\nfurther.",[22,4947,4949],{"id":4948},"the-underlying-shift","The underlying shift",[12,4951,4952],{},"The benefit is not simply \"less admin work.\" It is that consultants in regulated environments spend\nproportionally more of their time on judgement — client value, regulatory interpretation, quality\ndecisions — and proportionally less on the coordination work that surrounds it. That shift matters\nmost precisely where missing a regulatory update, or missing an overdue corrective action, is never\nan acceptable outcome.",[22,4954,1645],{"id":1644},[30,4956,4957,4961],{},[33,4958,4959],{},[55,4960,3209],{"href":3554},[33,4962,4963],{},[55,4964,2360],{"href":2359},{"title":232,"searchDepth":233,"depth":233,"links":4966},[4967,4968,4969,4970,4971,4972],{"id":4850,"depth":233,"text":4851},{"id":4880,"depth":233,"text":4881},{"id":4908,"depth":233,"text":4909},{"id":4941,"depth":233,"text":4942},{"id":4948,"depth":233,"text":4949},{"id":1644,"depth":233,"text":1645},"Productivity","Copilot Tasks lets teams delegate multi-step work to a governed digital delegate. For regulated consulting firms, the highest value clusters around reporting, monitoring, and compliance.",{},"\u002Fblog\u002Funlocking-productivity-with-microsoft-365-copilot-tasks",{"title":4839,"description":4974},"blog\u002Funlocking-productivity-with-microsoft-365-copilot-tasks",[2376,4980,4981,4982,1817],"productivity","consulting","regulatory-monitoring","lo78Rm2JHTNHyQu6K_3tgX93GCggQqacuIsgnM_CN7c",{"id":4985,"title":4986,"author":7,"body":4987,"category":241,"date":1669,"description":5093,"draft":244,"excerpt":245,"extension":246,"heroImage":245,"heroImageAlt":245,"meta":5094,"navigation":248,"path":475,"seo":5095,"slug":245,"stem":5096,"tags":5097,"__hash__":5099},"blog\u002Fblog\u002Fvalidating-a-sharepoint-quality-register.md","Validating a SharePoint Quality Register: A Worked Example",{"type":9,"value":4988,"toc":5085},[4989,4995,4999,5002,5006,5012,5018,5024,5030,5036,5042,5046,5049,5053,5056,5060,5063,5065],[12,4990,4991,4992,4994],{},"This is a companion piece to\n",[55,4993,545],{"href":544},",\nworking through what validating a SharePoint deviation register actually looks like once the\nrecord-versus-register boundary is settled. This is a proposed risk-based approach — the final\nvalidation strategy should be appropriate to the organisation's own procedures, regulatory context,\nand intended use.",[22,4996,4998],{"id":4997},"what-is-being-validated","What is being validated",[12,5000,5001],{},"A SharePoint List configured as a deviation register, where the paper system remains the\nauthoritative GMP record. The paper record stays responsible for the deviation and investigation\nnarrative, root-cause analysis, impact and risk assessment, investigation approval, and signatures\nand supporting evidence. The SharePoint List supports identification and status tracking, ownership\nand due-date monitoring, risk categorisation, root-cause trending, and resource prioritisation.",[22,5003,5005],{"id":5004},"six-core-deliverables","Six core deliverables",[12,5007,5008,5011],{},[61,5009,5010],{},"1. User requirements specification."," Define intended use, required functions, users, data, and\nboundaries — describing what the organisation needs, not every capability SharePoint offers.\nRequirements should concentrate on intended use, critical data, access, traceability to the paper\nrecord, and reporting reliability, not on low-value platform features included merely to pad the\ndocument.",[12,5013,5014,5017],{},[61,5015,5016],{},"2. Functional risk assessment."," Identify credible failure scenarios and whether existing or\nproposed controls reduce risk to an acceptable level: incorrect classification affecting trend\nreports; a missing record reducing visibility of a quality event; incorrect status showing a\ndeviation as closed while the paper process remains open; unauthorised modification of\nclassification or status; lost traceability between the electronic entry and its paper file; and\nincorrect report output from flawed filters or dashboard logic. The paper source reduces some risks\nbut does not eliminate risks relating to trending, oversight, timeliness, or resource allocation.",[12,5019,5020,5023],{},[61,5021,5022],{},"3. Configuration specification."," Document the controlled configuration implementing the approved\nrequirements and risk controls — field types, required status, and controlled choice values for\nstatus, risk category, and deviation type — with screenshots supporting, not replacing, a clear,\nreviewable specification. Any Power Automate or Power BI connections should be documented here too.",[12,5025,5026,5029],{},[61,5027,5028],{},"4. Validation plan."," Define how assurance will be established and how the package scales to the\nsolution's risk, complexity, and novelty. In scope: the register configuration, critical data\nfields and classifications, permissions and version history, reporting outputs used for quality\ndecisions, and register-to-paper traceability. Excluded or leveraged: Microsoft's own\nsoftware-development processes, physical data-centre qualification, and generic testing of standard\nSharePoint functions unrelated to intended use. \"Do not re-test Microsoft\" does not mean Microsoft\nis automatically compliant — the organisation remains responsible for its own configuration, data,\naccess model, and reliance decisions.",[12,5031,5032,5035],{},[61,5033,5034],{},"5. Verification protocol and evidence."," Test that a deviation can be created with all mandatory\ninformation, that saving without a required field is prevented, that only approved risk and\nroot-cause values can be selected, that status history is retained after an update, that access\ncontrol correctly distinguishes editors from read-only users, that an electronic entry can be traced\nto its paper deviation, and that a report or dashboard sample matches the underlying list data.\nAttention should concentrate on critical classifications, access controls, traceability, and\ndecision-supporting reports — not on exhaustively exercising every SharePoint feature.",[12,5037,5038,5041],{},[61,5039,5040],{},"6. Validation summary report."," Summarise completed evidence and the documented basis for release\n— intended use confirmed, requirements verified, risk controls tested, configuration baseline\napproved, and any residual risk accepted by authorised stakeholders — referencing detailed evidence\nrather than repeating every requirement or test step in full. Bulk does not equate to rigour.",[22,5043,5045],{"id":5044},"why-the-first-register-costs-more-than-the-next-one","Why the first register costs more than the next one",[12,5047,5048],{},"The first implementation establishes reusable assets: validation templates, list-design standards,\npermission groups, a risk-assessment model, a standard test library, and operational procedures. A\nsubsequent register — a CAPA register, for example — reuses that framework but still needs its own\nprocess-specific assessment: the CAPA-specific intended use, source and ownership, effectiveness-check\nrequirements, and process-specific risk and verification. Reuse is justified where the platform,\ngovernance, controls, and verification methods remain equivalent; a new assessment is required\nwherever the process, data, reports, or quality decisions genuinely differ.",[22,5050,5052],{"id":5051},"when-the-lightweight-approach-is-no-longer-enough","When the lightweight approach is no longer enough",[12,5054,5055],{},"Risk is determined by intended use and reliance, not by the product name. Reassess the approach when\na solution introduces electronic approval of GMP records or electronic signatures, complete\nelectronic investigations, automated risk classification or product-impact decisions, complex\nworkflow branching or custom code, system-to-system integration, or replacement of the paper source\nrecord. Any of those conditions warrant a more extensive validation strategy than the lightweight\nregister approach described here.",[22,5057,5059],{"id":5058},"the-principle-underneath-it-all","The principle underneath it all",[12,5061,5062],{},"The goal is not to prove SharePoint works — it is to demonstrate that the organisation's configured\nregister, supporting processes, and controls provide reliable information for their defined GxP use.\nScale the documentation to the risk, complexity, and novelty of the intended use, and the validation\npackage earns its credibility on decision quality, not on volume.",[22,5064,1645],{"id":1644},[30,5066,5067,5072,5077,5081],{},[33,5068,5069],{},[55,5070,5071],{"href":544},"Beyond Excel: A Practical GxP Approach to Quality Registers",[33,5073,5074],{},[55,5075,5076],{"href":216},"Can an Excel quality register remain fit for purpose?",[33,5078,5079],{},[55,5080,2996],{"href":566},[33,5082,5083],{},[55,5084,2569],{"href":571},{"title":232,"searchDepth":233,"depth":233,"links":5086},[5087,5088,5089,5090,5091,5092],{"id":4997,"depth":233,"text":4998},{"id":5004,"depth":233,"text":5005},{"id":5044,"depth":233,"text":5045},{"id":5051,"depth":233,"text":5052},{"id":5058,"depth":233,"text":5059},{"id":1644,"depth":233,"text":1645},"A scalable, risk-based approach to validating a SharePoint quality register while the paper record remains the authoritative GMP source of truth.",{},{"title":4986,"description":5093},"blog\u002Fvalidating-a-sharepoint-quality-register",[601,5098,256,1814,2377],"quality-register","P_3QHF4JXPDdU-0iWASw2YN5G6vmYODvc-4Dh8DGH04",{"id":5101,"title":4591,"author":7,"body":5102,"category":241,"date":1669,"description":5343,"draft":244,"excerpt":245,"extension":246,"heroImage":245,"heroImageAlt":245,"meta":5344,"navigation":248,"path":4590,"seo":5345,"slug":245,"stem":5346,"tags":5347,"__hash__":5348},"blog\u002Fblog\u002Fwhat-fda-csv-citations-reveal-about-your-next-gmp-inspection.md",{"type":9,"value":5103,"toc":5329},[5104,5107,5110,5114,5117,5120,5123,5127,5130,5133,5136,5141,5145,5149,5152,5155,5159,5162,5165,5170,5174,5177,5197,5200,5204,5208,5211,5214,5218,5221,5253,5256,5260,5263,5268,5271,5274,5278,5281,5304,5310,5316,5318,5321,5324],[12,5105,5106],{},"If your organisation is preparing for a GMP inspection, reviewing computerised-systems and data-\nintegrity observations can reveal more than a list of regulatory citations. It can show where\ninspectors look beyond the validation binder and ask how systems actually operate.",[12,5108,5109],{},"This article is a practical interpretation of recurring themes in FDA inspection observations and\nrelated GMP guidance. It is not an inspection prediction, legal advice, or a determination that a\nparticular organisation or system is compliant. The applicable FDA communication, regulatory\nrequirements, intended use, risk assessment, and quality system remain the controlling context.",[22,5111,5113],{"id":5112},"the-inspection-question-behind-the-citation","The inspection question behind the citation",[12,5115,5116],{},"Organisations often read an observation as a question about one clause or one record. An\nexperienced inspection response also asks what risk the observation exposes.",[12,5118,5119],{},"An observation about an incomplete batch record may prompt a broader question: can the organisation\ntrust the information used to make quality decisions? An observation about electronic records may\nraise the question of whether GMP data can be changed without appropriate oversight. An observation\nabout input and output verification may point to uncertainty about whether data moved through the\nprocess correctly.",[12,5121,5122],{},"These questions have a common theme: whether data remains accurate, complete, attributable,\ncontemporaneous, and trustworthy throughout its lifecycle.",[22,5124,5126],{"id":5125},"why-validation-documentation-is-not-enough","Why validation documentation is not enough",[12,5128,5129],{},"An approved Validation Plan, User Requirements Specification, test evidence, traceability matrix,\nvalidation report, and operating procedures are important evidence. They do not, by themselves,\nshow that a system remains controlled after go-live.",[12,5131,5132],{},"Systems evolve. Users and permissions change. Suppliers release updates. Configurations and\nintegrations change. Business processes change. Incidents reveal new information. Periodic review\nshould connect those changes and findings to the system's current state of control.",[12,5134,5135],{},"The practical inspection question is therefore not only, “Was this system validated?” It is also,\n“How do you know this system remains fit for its intended GMP use today?”",[12,5137,2450,5138,5140],{},[55,5139,2903],{"href":2902}," explores\nthis lifecycle distinction in more detail.",[22,5142,5144],{"id":5143},"what-recurring-weaknesses-can-reveal","What recurring weaknesses can reveal",[300,5146,5148],{"id":5147},"_1-critical-data-is-not-clearly-understood","1. Critical data is not clearly understood",[12,5150,5151],{},"Not all data carries the same process impact. Some records directly support product release\ndecisions. Some influence process control, investigations, traceability, or reporting. Other data\nmay be informative without driving a GMP decision.",[12,5153,5154],{},"If critical data has not been identified, it becomes difficult to apply proportionate controls,\ndefine appropriate review, or explain why a validation approach was sufficient. Start with the\nprocess and intended use, then identify which data and decisions matter most.",[300,5156,5158],{"id":5157},"_2-audit-trails-exist-but-are-not-effectively-used","2. Audit trails exist but are not effectively used",[12,5160,5161],{},"An audit trail that nobody reviews provides limited assurance. The organisation should understand\nwhich changes matter for the process, who reviews them, how findings are assessed, and when a change\nrequires investigation or escalation.",[12,5163,5164],{},"The question is not simply whether the system can generate an audit trail. It is whether the audit\ntrail helps the organisation detect and explain changes that could affect quality or data integrity.",[12,5166,2450,5167,5169],{},[55,5168,2495],{"href":2494},"\napplies the same principle to AI-assisted work and its resulting decisions.",[300,5171,5173],{"id":5172},"_3-user-access-is-weaker-than-expected","3. User access is weaker than expected",[12,5175,5176],{},"Common access-control questions include:",[30,5178,5179,5182,5185,5188,5191,5194],{},[33,5180,5181],{},"Are privileges appropriate to the person's role?",[33,5183,5184],{},"Are shared accounts prohibited or controlled?",[33,5186,5187],{},"Are inactive users removed promptly?",[33,5189,5190],{},"Are access reviews performed at a defined frequency?",[33,5192,5193],{},"Are conflicting duties separated where the process requires it?",[33,5195,5196],{},"Is privileged access documented and justified?",[12,5198,5199],{},"Access control is part of data integrity. It helps establish who could create, change, approve, or\ndelete information and whether those actions can be attributed to the right person.",[12,5201,2450,5202,2570],{},[55,5203,2569],{"href":571},[300,5205,5207],{"id":5206},"_4-supplier-reliance-is-not-well-understood","4. Supplier reliance is not well understood",[12,5209,5210],{},"GMP operations increasingly depend on SaaS platforms, cloud hosting, managed services, and external\nconfiguration partners. Supplier evidence can support the assessment, but it does not remove the\nregulated organisation's responsibility for its intended use.",[12,5212,5213],{},"The organisation should understand supplier quality processes, security, service changes, incident\nhandling, support boundaries, contractual controls, and the evidence available to justify reliance.\nIt should also be able to explain what it controls itself.",[22,5215,5217],{"id":5216},"a-practical-inspection-readiness-check","A practical inspection-readiness check",[12,5219,5220],{},"Before an inspection, ask whether the team can answer these questions with current, retrievable\nevidence:",[1573,5222,5223,5226,5229,5232,5235,5238,5241,5244,5247,5250],{},[33,5224,5225],{},"Do we have an up-to-date inventory of GMP-relevant computerised systems?",[33,5227,5228],{},"Can we identify the critical functionality and data for each system?",[33,5230,5231],{},"Can we explain the intended use and process impact?",[33,5233,5234],{},"Are audit trails enabled, reviewed, and escalated where appropriate?",[33,5236,5237],{},"Are user access reviews routinely performed and evidenced?",[33,5239,5240],{},"Can we demonstrate that backup restoration has been tested?",[33,5242,5243],{},"Are interfaces and data transfers understood, verified, and controlled?",[33,5245,5246],{},"Can we explain why validation and assurance effort was proportionate to risk?",[33,5248,5249],{},"Can we demonstrate effective oversight of critical suppliers?",[33,5251,5252],{},"Can we show how the system remains in a validated state today?",[12,5254,5255],{},"These questions are often more revealing than asking whether a protocol was approved several years\nago.",[22,5257,5259],{"id":5258},"the-most-useful-question-in-csv","The most useful question in CSV",[12,5261,5262],{},"Many validation projects begin with, “What documents do we need?” A stronger question is:",[275,5264,5265],{},[12,5266,5267],{},"What could go wrong, and how do we know it is controlled?",[12,5269,5270],{},"That question shifts the conversation towards process understanding, intended use, criticality,\ndata integrity, risk controls, and assurance activities. Documentation then becomes evidence of\nthose decisions rather than the objective by itself.",[12,5272,5273],{},"The purpose of validation is to provide justified confidence that the system performs consistently\nand reliably for its intended GMP use and protects critical information. The right evidence depends\non the system, process, risks, and lifecycle stage.",[22,5275,5277],{"id":5276},"developing-better-csv-thinking","Developing better CSV thinking",[12,5279,5280],{},"Validation practitioners need more than the ability to write a requirement, execute a test script,\ncomplete a traceability matrix, or issue a report. They also need to make sound decisions about:",[30,5282,5283,5286,5289,5292,5295,5298,5301],{},[33,5284,5285],{},"intended use and process impact;",[33,5287,5288],{},"product quality and patient-safety relevance;",[33,5290,5291],{},"data-integrity risk;",[33,5293,5294],{},"supplier reliance;",[33,5296,5297],{},"appropriate testing and assurance;",[33,5299,5300],{},"system governance and operational controls;",[33,5302,5303],{},"ongoing review and change management.",[12,5305,5306,5307,5309],{},"These judgement skills matter as cloud platforms, software-as-a-service, automation, and artificial\nintelligence become more common in GMP operations. The ",[55,5308,2630],{"href":2629},"\nconnects these questions to practical quality-system work.",[12,5311,5312,5313,5315],{},"For AI-assisted processes, the ",[55,5314,3516],{"href":2359},"\nhub adds questions about output boundaries, human oversight, evaluation, traceability, and controlled\nchange. The technology may differ, but the underlying inspection question remains familiar: can the\norganisation explain what happened and demonstrate that the process remains under control?",[22,5317,3042],{"id":3041},[12,5319,5320],{},"Reviewing FDA CSV citations is most valuable when it changes the question from “How do we produce a\nlarger validation binder?” to “How do we demonstrate confidence?”",[12,5322,5323],{},"Confidence that systems are fit for intended use. Confidence that data can be trusted. Confidence\nthat quality decisions are based on reliable information. And confidence that, when an inspector\nasks how the organisation knows a system is controlled, the answer is clear, current, and supported\nby evidence.",[12,5325,5326,206],{},[55,5327,5328],{"href":228},"Discuss your GMP quality-system pathway",{"title":232,"searchDepth":233,"depth":233,"links":5330},[5331,5332,5333,5339,5340,5341,5342],{"id":5112,"depth":233,"text":5113},{"id":5125,"depth":233,"text":5126},{"id":5143,"depth":233,"text":5144,"children":5334},[5335,5336,5337,5338],{"id":5147,"depth":588,"text":5148},{"id":5157,"depth":588,"text":5158},{"id":5172,"depth":588,"text":5173},{"id":5206,"depth":588,"text":5207},{"id":5216,"depth":233,"text":5217},{"id":5258,"depth":233,"text":5259},{"id":5276,"depth":233,"text":5277},{"id":3041,"depth":233,"text":3042},"What recurring computerised-systems and data-integrity observations suggest about inspection readiness beyond the validation binder.",{},{"title":4591,"description":5343},"blog\u002Fwhat-fda-csv-citations-reveal-about-your-next-gmp-inspection",[4831,4614,257,2377,2212],"B3R9zKILbWy0JMFPrwOXxGcAeP6hBx8sc0mbATtu1CA",{"id":5350,"title":5351,"author":7,"body":5352,"category":1668,"date":1669,"description":5432,"draft":244,"excerpt":245,"extension":246,"heroImage":245,"heroImageAlt":245,"meta":5433,"navigation":248,"path":5434,"seo":5435,"slug":245,"stem":5436,"tags":5437,"__hash__":5441},"blog\u002Fblog\u002Fwhat-makes-a-good-ai-agent-designer-in-a-gmp-environment.md","What Makes a Good AI Agent Designer in a GMP Environment?",{"type":9,"value":5353,"toc":5425},[5354,5357,5361,5364,5368,5374,5380,5386,5392,5398,5402,5405,5409,5412,5414],[12,5355,5356],{},"As AI becomes embedded in quality and regulatory operations, one capability will quietly determine\nsuccess or failure: agent design. Not coding, not prompt experimentation, not \"AI strategy\" —\ndesign. In a GMP-regulated environment, the question is not whether AI can generate text. The\nquestion is whether it can operate within controlled systems, produce defensible outputs, and\nwithstand audit scrutiny. The professionals best positioned to design agents that meet that bar are\ntechnical writers, process engineers, and compliance professionals — not traditional software\nengineers.",[22,5358,5360],{"id":5359},"an-ai-agent-is-a-controlled-process-not-a-chat-feature","An AI agent is a controlled process, not a chat feature",[12,5362,5363],{},"An AI agent is a set of plain-English operating instructions applied to a large language model. The\nLLM is the reasoning engine; the instructions are what make it useful, safe, and controlled — think\nof it as an SOP written for a probabilistic worker rather than a human operator.",[22,5365,5367],{"id":5366},"five-disciplines-that-matter","Five disciplines that matter",[12,5369,5370,5373],{},[61,5371,5372],{},"Controlled process design."," In GMP, uncontrolled variability is not accepted — inputs, process\nsteps, decision criteria, acceptance thresholds, exception handling, and documentation requirements\nare all defined. A good agent designer asks what structured inputs are permitted, what validation\nrules must apply, what constitutes a compliant output, what evidence must be generated, and where\nhuman verification sits. This is process engineering thinking applied to a new kind of worker. AI\nwithout process control is novelty; AI within a controlled process is operational leverage.",[12,5375,5376,5379],{},[61,5377,5378],{},"Precision technical writing."," Large language models interpret instructions literally and\nprobabilistically — ambiguity produces variability, and variability produces risk. Strong designers\ndefine terms precisely, eliminate vague instructions, control scope, specify output schemas, and\nstate constraints and exclusions explicitly, mirroring the discipline of writing SOPs, validation\nprotocols, regulatory responses, and quality manuals. The audience is different — a probabilistic\nreasoning system rather than a human operator — but the underlying skill is the same one a\nconsultant already applies when writing a clear deviation-investigation procedure.",[12,5381,5382,5385],{},[61,5383,5384],{},"Risk-first thinking."," The useful question is not \"what can AI do for us?\" but \"what should AI be\nallowed to do, and under what controls?\" Designers need to weigh risk classification of outputs,\nGxP impact, traceability requirements, audit defensibility, and failure modes for every function an\nagent might touch — classifying deviations, extracting batch data, interpreting acceptance criteria,\nrecommending conclusions. Each requires a defined control boundary. Strong designers think like\nauditors before they think like innovators.",[12,5387,5388,5391],{},[61,5389,5390],{},"Separating intelligence from authority."," One of the most dangerous mistakes in AI adoption is\nletting generated output be treated as authoritative. A well-designed agent surfaces findings, flags\ninconsistencies, highlights missing information, and indicates uncertainty — it does not silently\nreplace quality review. The governing principle is simple: AI assists, humans remain accountable.\nThat is not a limitation; it is a governance design decision.",[12,5393,5394,5397],{},[61,5395,5396],{},"Auditability and traceability."," In an inspection scenario, an organisation must be able to answer\nwhat instructions governed the agent, what version was deployed, what inputs were used, what rules\nwere applied, and what the human verification step was. If those questions cannot be answered\nclearly, the system is not inspection-ready. This is document-control territory: versioning\ninstructions, structuring outputs, logging decisions, and maintaining configuration control — all\nfamiliar ground for GMP professionals.",[22,5399,5401],{"id":5400},"structured-data-over-narrative","Structured data over narrative",[12,5403,5404],{},"Effective agent design produces classified findings, extracted data points, traceable references,\nrisk flags, and structured review outputs — not persuasive paragraphs. That structure is what\nenables verification workflows, executive dashboards, trend analysis, and regulatory defensibility.\nThe agent is generating structured compliance artefacts, not just writing.",[22,5406,5408],{"id":5407},"why-this-is-a-leadership-question","Why this is a leadership question",[12,5410,5411],{},"Organisations that treat AI as a chat interface, a drafting tool, or a novelty feature will see\nmarginal efficiency gains. Organisations that treat it as a controlled review layer, a structured\ncompliance assistant, and a governed digital reviewer will reshape how quality and regulatory work\nscales. The differentiator will not be model choice — it will be the ability to design agents with\nprocess clarity, risk discipline, structured outputs, and governance control. Those are not software\nskills. They are consulting and quality skills, and they will not come primarily from Silicon\nValley — they will come from people who already understand SOP discipline, process mapping, risk\nassessment, validation logic, and audit defensibility. AI does not replace that discipline. It\namplifies it.",[22,5413,1645],{"id":1644},[30,5415,5416,5421],{},[33,5417,5418],{},[55,5419,5420],{"href":1672},"Agent Design Is a Systems Problem",[33,5422,5423],{},[55,5424,1653],{"href":1652},{"title":232,"searchDepth":233,"depth":233,"links":5426},[5427,5428,5429,5430,5431],{"id":5359,"depth":233,"text":5360},{"id":5366,"depth":233,"text":5367},{"id":5400,"depth":233,"text":5401},{"id":5407,"depth":233,"text":5408},{"id":1644,"depth":233,"text":1645},"The professionals best placed to design effective AI agents in regulated industries are not software engineers — they are technical writers and compliance professionals.",{},"\u002Fblog\u002Fwhat-makes-a-good-ai-agent-designer-in-a-gmp-environment",{"title":5351,"description":5432},"blog\u002Fwhat-makes-a-good-ai-agent-designer-in-a-gmp-environment",[5438,257,5439,5440],"ai-agent-design","technical-writing","compliance-engineering","SexyHoZKCBLNtc8EuRK1cKQjz2n0GrlkOi2mpW_wzvM",{"id":5443,"title":5444,"author":7,"body":5445,"category":5587,"date":5588,"description":5589,"draft":244,"excerpt":245,"extension":246,"heroImage":245,"heroImageAlt":245,"meta":5590,"navigation":248,"path":5591,"seo":5592,"slug":245,"stem":5593,"tags":5594,"__hash__":5596},"blog\u002Fblog\u002Fgmp-capa-management-cfr-21-part-11.md","Unlocking Excellence: CAPA Management with QikSolve — The Power of SharePoint",{"type":9,"value":5446,"toc":5581},[5447,5460,5464,5467,5481,5485,5523,5527,5570,5574],[12,5448,5449,5450,5455,5456,5459],{},"Effective Corrective and Preventive Action (CAPA) management is the backbone of quality and compliance in regulated industries. Ensuring that your CAPA processes align with regulatory standards is paramount. At QikSolve, we bring you a powerful solution in our ",[55,5451,5454],{"href":5452,"rel":5453},"https:\u002F\u002Finq.qiksolve.com",[3592],"INQ platform"," with built-in CAPA management software configured on ",[55,5457,5458],{"href":2629},"SharePoint",", designed to meet the stringent compliance requirements of CFR 21 Part 11 and Annex 11.",[22,5461,5463],{"id":5462},"the-challenge-of-capa-management","The Challenge of CAPA Management",[12,5465,5466],{},"Corrective and Preventive Actions (CAPA) are essential in addressing non-conformities, improving processes, and preventing their recurrence. However, managing CAPA effectively in a regulated environment presents several challenges, including data security, electronic records, and electronic signatures.",[30,5468,5469,5475],{},[33,5470,5471,5474],{},[61,5472,5473],{},"CFR 21 Part 11"," — the FDA regulation outlining requirements for electronic records and electronic signatures, including CAPA records and signatures.",[33,5476,5477,5480],{},[61,5478,5479],{},"Annex 11"," — the EU GMP guideline focused on computerized systems, including CAPA management systems, emphasizing validation and data integrity.",[22,5482,5484],{"id":5483},"qiksolves-solution-sharepoint-capa-management-software","QikSolve's Solution: SharePoint CAPA Management Software",[1573,5486,5487,5493,5499,5505,5511,5517],{},[33,5488,5489,5492],{},[61,5490,5491],{},"Electronic Records Management"," — secure, unalterable CAPA records accessible only to authorized personnel, with detailed audit trails for traceability.",[33,5494,5495,5498],{},[61,5496,5497],{},"Electronic Signatures"," — facilitate electronic signatures for CAPA records in compliance with CFR 21 Part 11 through the INQ Platform, unique and verifiable.",[33,5500,5501,5504],{},[61,5502,5503],{},"Access Controls and Permissions"," — restrict access to sensitive CAPA data and align user roles with compliance requirements.",[33,5506,5507,5510],{},[61,5508,5509],{},"Data Validation and Integrity"," — validation rules to prevent data entry errors and ensure the integrity of CAPA records.",[33,5512,5513,5516],{},[61,5514,5515],{},"CAPA Workflow Automation"," — automate the initiation, investigation, and resolution of CAPA requests with compliant workflow steps.",[33,5518,5519,5522],{},[61,5520,5521],{},"Training and Documentation"," — train users on CAPA compliance and maintain comprehensive configuration documentation for validation.",[22,5524,5526],{"id":5525},"benefits-of-sharepoint-capa-management-software-with-qiksolve","Benefits of SharePoint CAPA Management Software with QikSolve",[30,5528,5529,5535,5546,5552,5558,5564],{},[33,5530,5531,5534],{},[61,5532,5533],{},"Efficiency"," — streamline CAPA processes, reduce errors, and enhance collaboration among teams.",[33,5536,5537,5540,5541,5545],{},[61,5538,5539],{},"Data Driven Decisions"," — use ",[55,5542,5544],{"href":5543},"\u002Fproduct\u002Fquality-dashboards","Power BI"," to trend and analyse data for better decisions.",[33,5547,5548,5551],{},[61,5549,5550],{},"Regulatory Confidence"," — SharePoint configured by QikSolve meets CFR 21 Part 11 and Annex 11 requirements.",[33,5553,5554,5557],{},[61,5555,5556],{},"Data Integrity"," — maintain the integrity and authenticity of electronic CAPA records and signatures.",[33,5559,5560,5563],{},[61,5561,5562],{},"Cost Savings"," — optimize resource allocation and reduce compliance-related costs.",[33,5565,5566,5569],{},[61,5567,5568],{},"Validation Support"," — comprehensive documentation supports the validation process and audit readiness.",[22,5571,5573],{"id":5572},"elevate-capa-management-with-qiksolve","Elevate CAPA Management with QikSolve",[12,5575,5576,5577,5580],{},"Effective CAPA management is vital for ensuring product quality and regulatory compliance. QikSolve's CAPA management software, configured on SharePoint in accordance with CFR 21 Part 11 and Annex 11, empowers your organization to streamline CAPA processes while maintaining strict compliance. ",[55,5578,5579],{"href":228},"Contact us"," today to discover how we can transform your CAPA management with SharePoint.",{"title":232,"searchDepth":233,"depth":233,"links":5582},[5583,5584,5585,5586],{"id":5462,"depth":233,"text":5463},{"id":5483,"depth":233,"text":5484},{"id":5525,"depth":233,"text":5526},{"id":5572,"depth":233,"text":5573},"GMP","2023-09-22","How QikSolve's INQ platform configures CAPA management on SharePoint to meet CFR 21 Part 11 and Annex 11 requirements.",{},"\u002Fblog\u002Fgmp-capa-management-cfr-21-part-11",{"title":5444,"description":5589},"blog\u002Fgmp-capa-management-cfr-21-part-11",[1923,257,601,5595,255],"cfr-21-part-11","hGnN6Z5_mS4oBayeJuE7MXZeu9xC9I2N5Tpm_UODzRg",{"id":5598,"title":5599,"author":7,"body":5600,"category":5587,"date":5588,"description":5706,"draft":244,"excerpt":245,"extension":246,"heroImage":245,"heroImageAlt":245,"meta":5707,"navigation":248,"path":5708,"seo":5709,"slug":245,"stem":5710,"tags":5711,"__hash__":5712},"blog\u002Fblog\u002Fgmp-compliance.md","Is SharePoint GMP Compliant? How QikSolve Sets the Standard",{"type":9,"value":5601,"toc":5700},[5602,5605,5609,5612,5619,5623,5660,5664,5690,5694],[12,5603,5604],{},"In regulated industries like pharmaceuticals and life sciences, compliance with Good Manufacturing Practices (GMP) is non-negotiable. Ensuring that your document management system meets the stringent requirements of regulations such as CFR 21 Part 11 and Annex 11 is paramount. But can SharePoint, a widely used collaboration platform, be GMP compliant? At QikSolve, we answer this question with a resounding \"Yes!\"",[22,5606,5608],{"id":5607},"understanding-gmp-compliance-and-sharepoint","Understanding GMP Compliance and SharePoint",[12,5610,5611],{},"Good Manufacturing Practices (GMP) are a set of guidelines and regulations that ensure the quality, safety, and consistency of products in regulated industries. In the pharmaceutical and life sciences sectors, GMP compliance extends to electronic records and signatures — a domain covered by CFR 21 Part 11 (issued by the U.S. FDA) and Annex 11 (issued by the EU).",[12,5613,5614,5615,5618],{},"SharePoint, with its robust document management and collaboration features, can be a valuable tool in achieving GMP compliance. However, proper ",[55,5616,5617],{"href":571},"configuration and adherence to best practices"," are essential.",[22,5620,5622],{"id":5621},"qiksolves-approach-to-sharepoint-gmp-compliance","QikSolve's Approach to SharePoint GMP Compliance",[1573,5624,5625,5630,5639,5644,5649,5655],{},[33,5626,5627,5629],{},[61,5628,5491],{}," — secure electronic records, accessible only to authorized personnel, with robust audit trails to track changes and maintain data integrity.",[33,5631,5632,5634,5635,5638],{},[61,5633,5497],{}," — enable electronic signatures that meet CFR 21 Part 11 requirements using the ",[55,5636,5454],{"href":5452,"rel":5637},[3592],", unique to the individual and traceable back to the signer.",[33,5640,5641,5643],{},[61,5642,5503],{}," — define granular access controls aligned with GMP compliance requirements.",[33,5645,5646,5648],{},[61,5647,5509],{}," — establish data validation rules to prevent entry errors and ensure integrity according to ALCOA+ principles.",[33,5650,5651,5654],{},[61,5652,5653],{},"Document Version Control"," — robust version control mechanisms with archived, accessible previous versions.",[33,5656,5657,5659],{},[61,5658,5521],{}," — train SharePoint users on GMP requirements and maintain comprehensive configuration documentation for validation purposes.",[22,5661,5663],{"id":5662},"benefits-of-sharepoint-gmp-compliance-with-qiksolve","Benefits of SharePoint GMP Compliance with QikSolve",[30,5665,5666,5671,5676,5681,5685],{},[33,5667,5668,5670],{},[61,5669,5550],{}," — SharePoint configured by QikSolve meets the requirements of CFR 21 Part 11 and Annex 11.",[33,5672,5673,5675],{},[61,5674,5556],{}," — maintain the integrity and authenticity of electronic records and signatures.",[33,5677,5678,5680],{},[61,5679,5533],{}," — streamline document management processes, reduce errors, and enhance collaboration.",[33,5682,5683,5563],{},[61,5684,5562],{},[33,5686,5687,5689],{},[61,5688,5568],{}," — comprehensive documentation supports the validation process.",[22,5691,5693],{"id":5692},"setting-the-standard-with-qiksolve","Setting the Standard with QikSolve",[12,5695,5696,5697,5699],{},"SharePoint can indeed be GMP compliant when configured and managed correctly. At QikSolve, we go the extra mile to ensure that SharePoint meets the rigorous standards of CFR 21 Part 11 and Annex 11. ",[55,5698,5579],{"href":228}," today to discover how we can configure SharePoint to meet your specific compliance needs.",{"title":232,"searchDepth":233,"depth":233,"links":5701},[5702,5703,5704,5705],{"id":5607,"depth":233,"text":5608},{"id":5621,"depth":233,"text":5622},{"id":5662,"depth":233,"text":5663},{"id":5692,"depth":233,"text":5693},"How QikSolve configures SharePoint electronic records, signatures, access controls, and validation to meet GMP compliance requirements.",{},"\u002Fblog\u002Fgmp-compliance",{"title":5599,"description":5706},"blog\u002Fgmp-compliance",[257,601,5595,255],"V5Dn7ONw-Iw0M5mmFJ39BigS1Y8SmbSKyh-uIcPz8Oc",{"id":5714,"title":5715,"author":7,"body":5716,"category":5818,"date":5588,"description":5819,"draft":244,"excerpt":245,"extension":246,"heroImage":245,"heroImageAlt":245,"meta":5820,"navigation":248,"path":5821,"seo":5822,"slug":245,"stem":5823,"tags":5824,"__hash__":5826},"blog\u002Fblog\u002Fiso-9001-qms.md","Elevating Quality Management: How QikSolve Configures SharePoint for ISO 9001 Compliance",{"type":9,"value":5717,"toc":5812},[5718,5726,5730,5733,5737,5740,5781,5785,5802,5806],[12,5719,5720,5721,5725],{},"In the world of quality management, ISO 9001 stands as the gold standard. Achieving ISO 9001 certification signifies a commitment to delivering exceptional products and services, but it also requires a well-structured Quality Management System (QMS). At QikSolve, we understand the significance of a robust ",[55,5722,5724],{"href":5723},"\u002Fproduct\u002Fiso-9001","QMS"," and how SharePoint can be configured to meet the various clauses of ISO 9001.",[22,5727,5729],{"id":5728},"the-power-of-iso-9001-compliance","The Power of ISO 9001 Compliance",[12,5731,5732],{},"ISO 9001 is more than a certification; it's a framework for continual improvement, customer satisfaction, and process excellence. The standard comprises several clauses that guide organizations on various aspects of quality management, from leadership to performance evaluation. Configuring SharePoint to align with these clauses can streamline compliance and enhance overall quality management.",[22,5734,5736],{"id":5735},"configuring-sharepoint-for-iso-9001-compliance","Configuring SharePoint for ISO 9001 Compliance",[12,5738,5739],{},"At QikSolve, we specialize in configuring SharePoint to meet the diverse requirements of ISO 9001:",[1573,5741,5742,5748,5754,5760,5766,5775],{},[33,5743,5744,5747],{},[61,5745,5746],{},"Leadership and Commitment (Clause 5)"," — SharePoint pages documenting leadership decisions and commitment to quality, with clear roles and responsibilities.",[33,5749,5750,5753],{},[61,5751,5752],{},"Planning (Clause 6)"," — SharePoint lists to define quality objectives, quality plans, and risk assessments, with libraries to manage project plans and requirements.",[33,5755,5756,5759],{},[61,5757,5758],{},"Support (Clause 7)"," — SharePoint lists for competencies, training records, and awareness programs, with libraries for controlled document access and versioning.",[33,5761,5762,5765],{},[61,5763,5764],{},"Operation (Clause 8)"," — SharePoint workflows for process management and change control, with lists for non-conformance management and CAPA.",[33,5767,5768,5771,5772,5774],{},[61,5769,5770],{},"Performance Evaluation (Clause 9)"," — data collection and analysis including KPIs and customer feedback, linked with ",[55,5773,5544],{"href":5543}," for trended information, with curated libraries for audits and management review.",[33,5776,5777,5780],{},[61,5778,5779],{},"Improvement (Clause 10)"," — track and monitor continuous improvement initiatives, manage improvement ideas and action plans, and use Power Automate for notifications and reminders.",[22,5782,5784],{"id":5783},"benefits-of-sharepoint-for-iso-9001-compliance-with-qiksolve","Benefits of SharePoint for ISO 9001 Compliance with QikSolve",[30,5786,5787,5790,5793,5796,5799],{},[33,5788,5789],{},"Streamline quality management processes with SharePoint's automation and collaboration capabilities.",[33,5791,5792],{},"Gain real-time visibility into quality data and performance metrics.",[33,5794,5795],{},"Maintain an audit-ready QMS without the overhead of a paper system.",[33,5797,5798],{},"SharePoint grows with your business, accommodating evolving quality needs without increasing costs.",[33,5800,5801],{},"Maximize ROI with a cost-effective solution for ISO 9001 compliance.",[22,5803,5805],{"id":5804},"trust-qiksolve-for-iso-9001-compliance-with-sharepoint","Trust QikSolve for ISO 9001 Compliance with SharePoint",[12,5807,5808,5809,5811],{},"Elevate your quality management with QikSolve's expertise in configuring SharePoint for ISO 9001 compliance. Our tailored SharePoint solutions align with the diverse clauses of ISO 9001, empowering your organization to achieve and maintain excellence in quality management without the pain of running paper-based systems. ",[55,5810,5579],{"href":228}," today to discover how we can optimise your ISO 9001 SharePoint Quality Management System.",{"title":232,"searchDepth":233,"depth":233,"links":5813},[5814,5815,5816,5817],{"id":5728,"depth":233,"text":5729},{"id":5735,"depth":233,"text":5736},{"id":5783,"depth":233,"text":5784},{"id":5804,"depth":233,"text":5805},"ISO9001","How QikSolve configures SharePoint lists, pages, apps, and libraries to meet the clauses of ISO 9001.",{},"\u002Fblog\u002Fiso-9001-qms",{"title":5715,"description":5819},"blog\u002Fiso-9001-qms",[5825,601,4479],"iso9001","yU3fLmuL1JIfERmYsXh4jZp6cE_oVJKWQ-OyOwtQzCw",{"id":5828,"title":5829,"author":7,"body":5830,"category":5933,"date":5588,"description":5934,"draft":244,"excerpt":245,"extension":246,"heroImage":245,"heroImageAlt":245,"meta":5935,"navigation":248,"path":5936,"seo":5937,"slug":245,"stem":5938,"tags":5939,"__hash__":5942},"blog\u002Fblog\u002Fpower-bi-document-management.md","Unlocking Excellence: How QikSolve's Power BI Reports Drive ISO 9001 Document Management Metrics",{"type":9,"value":5831,"toc":5927},[5832,5839,5843,5846,5872,5876,5882,5886,5917,5921],[12,5833,5834,5835,5838],{},"In the world of quality management, ISO 9001 sets the bar high for organizations committed to excellence. An integral aspect of ",[55,5836,5837],{"href":5723},"ISO 9001 compliance"," is efficient document management, which plays a pivotal role in maintaining quality, ensuring consistency, and meeting regulatory requirements. At QikSolve, we understand the importance of tracking document management metrics, and that's where our Power BI expertise comes into play.",[22,5840,5842],{"id":5841},"the-significance-of-iso-9001-document-management-metrics","The Significance of ISO 9001 Document Management Metrics",[12,5844,5845],{},"Efficient document management encompasses the creation, revision, approval, distribution, and accessibility of documents critical to your quality management system. Monitoring key metrics not only ensures compliance but also drives continual improvement:",[30,5847,5848,5854,5860,5866],{},[33,5849,5850,5853],{},[61,5851,5852],{},"Document Authoring Time"," — tracking how long it takes to create and approve documents provides insight into efficiency and process bottlenecks.",[33,5855,5856,5859],{},[61,5857,5858],{},"Document Update Timeliness"," — monitoring the timely update of documents is crucial for maintaining compliance with evolving standards and regulations.",[33,5861,5862,5865],{},[61,5863,5864],{},"Document Usage"," — understanding how frequently documents are accessed and utilized can inform decisions on relevance and improvements.",[33,5867,5868,5871],{},[61,5869,5870],{},"Document Count per Department"," — keeping tabs on the number of documents per department provides insight into department-specific compliance and resource allocation.",[22,5873,5875],{"id":5874},"leveraging-power-bi-for-document-management-metrics","Leveraging Power BI for Document Management Metrics",[12,5877,5878,5879,5881],{},"QikSolve specializes in harnessing the power of ",[55,5880,5544],{"href":5543}," to provide meaningful insights into your document management process — tracking authoring time, update timeliness, usage, and per-department document counts.",[22,5883,5885],{"id":5884},"benefits-of-power-bi-reports-for-document-management-metrics","Benefits of Power BI Reports for Document Management Metrics",[30,5887,5888,5894,5900,5906,5912],{},[33,5889,5890,5893],{},[61,5891,5892],{},"Data-Driven Decision-Making"," — make informed decisions based on real-time document management data.",[33,5895,5896,5899],{},[61,5897,5898],{},"Efficiency Gains"," — identify bottlenecks and streamline the document creation and approval process.",[33,5901,5902,5905],{},[61,5903,5904],{},"Compliance Assurance"," — stay compliant with ISO 9001 document management requirements and reduce the risk of non-conformances.",[33,5907,5908,5911],{},[61,5909,5910],{},"Continuous Improvement"," — use insights to drive continual improvement in your document management practices.",[33,5913,5914,5916],{},[61,5915,5562],{}," — optimize resource allocation and reduce document management costs.",[22,5918,5920],{"id":5919},"elevate-document-management-with-qiksolves-power-bi-reports","Elevate Document Management with QikSolve's Power BI Reports",[12,5922,5923,5924,5926],{},"Unlock excellence in ISO 9001 document management with QikSolve's Power BI expertise. Our tailored reports and dashboards provide valuable insight into document creation, updates, usage, and department-specific document counts, empowering your organization to maintain compliance and drive continual improvement. ",[55,5925,5579],{"href":228}," today to discover how we can transform your document management process with Power BI.",{"title":232,"searchDepth":233,"depth":233,"links":5928},[5929,5930,5931,5932],{"id":5841,"depth":233,"text":5842},{"id":5874,"depth":233,"text":5875},{"id":5884,"depth":233,"text":5885},{"id":5919,"depth":233,"text":5920},"Reporting","How QikSolve's Power BI reports and dashboards unlock insights into document authoring time, update timeliness, usage, and per-department counts.",{},"\u002Fblog\u002Fpower-bi-document-management",{"title":5829,"description":5934},"blog\u002Fpower-bi-document-management",[5940,5825,5941],"power-bi","reporting","IadLxx9b9FPDwGppgZXaYK4TwgcY0lbyz-j1vFmCxe0",{"id":5944,"title":5945,"author":7,"body":5946,"category":241,"date":6080,"description":6081,"draft":244,"excerpt":245,"extension":246,"heroImage":245,"heroImageAlt":245,"meta":6082,"navigation":248,"path":6083,"seo":6084,"slug":245,"stem":6085,"tags":6086,"__hash__":6088},"blog\u002Fblog\u002Fachieving-gxp-compliance-with-azure-cfr-21-part-11-and-annex-11-made-simple.md","Achieving GxP Compliance with Azure — CFR 21 Part 11 and Annex 11 Made Simple",{"type":9,"value":5947,"toc":6074},[5948,5960,5964,5967,5979,5983,5986,6030,6034,6064,6068],[12,5949,5950,5951,5954,5955,5959],{},"In the highly regulated world of pharmaceuticals and life sciences, compliance with stringent regulations like CFR 21 Part 11 and Annex 11 is not just a choice — it's a mandate. Ensuring that your cloud infrastructure, particularly Microsoft Azure, is aligned with these regulations is crucial for maintaining data integrity, security, and the trust of regulatory authorities. At ",[55,5952,7],{"href":5953},"\u002Fabout"," we understand the complexities of GxP compliance and the significance of a well-configured ",[55,5956,5958],{"href":5957},"\u002Fproduct","Azure environment",". Let's explore how we make Azure GxP compliance a seamless reality.",[22,5961,5963],{"id":5962},"understanding-gxp-compliance-cfr-21-part-11-and-annex-11","Understanding GxP Compliance: CFR 21 Part 11 and Annex 11",[12,5965,5966],{},"Before diving into Azure's role in achieving GxP compliance, let's briefly clarify what CFR 21 Part 11 and Annex 11 entail:",[30,5968,5969,5974],{},[33,5970,5971,5973],{},[61,5972,5473],{},": This regulation by the FDA outlines requirements for electronic records and electronic signatures. It covers everything from data security to audit trails, ensuring the reliability and authenticity of electronic records used in various GxP processes.",[33,5975,5976,5978],{},[61,5977,5479],{},": Annex 11 of the EU GMP guidelines focuses on computerized systems used in pharmaceutical manufacturing. It emphasizes the validation and use of computerized systems, including the need for data integrity and electronic signatures.",[22,5980,5982],{"id":5981},"azure-the-foundation-for-gxp-compliance","Azure: The Foundation for GxP Compliance",[12,5984,5985],{},"Azure, Microsoft's cloud platform, offers a robust foundation for GxP compliance. However, configuring Azure to meet the specific requirements of CFR 21 Part 11 and Annex 11 can be intricate. Here's how QikSolve helps you achieve GxP compliance on Azure:",[1573,5987,5988,5994,6000,6006,6012,6024],{},[33,5989,5990,5993],{},[61,5991,5992],{},"Access Controls and Identity Management"," — implement stringent access controls and multi-factor authentication to safeguard against unauthorized access.",[33,5995,5996,5999],{},[61,5997,5998],{},"Data Encryption and Integrity"," — encrypt data in transit and at rest, and implement mechanisms to detect and prevent tampering.",[33,6001,6002,6005],{},[61,6003,6004],{},"Audit Trails and Logging"," — configure comprehensive logging and auditing capabilities to create detailed audit trails.",[33,6007,6008,6011],{},[61,6009,6010],{},"Validation and Documentation"," — conduct thorough validation of Azure services and maintain detailed documentation to meet regulatory requirements.",[33,6013,6014,6017,6018,6023],{},[61,6015,6016],{},"Disaster Recovery and Business Continuity"," — set up robust disaster recovery plans and use the ",[55,6019,6022],{"href":6020,"rel":6021},"https:\u002F\u002Fservicetrust.microsoft.com\u002F",[3592],"Microsoft Trust Centre"," to stay audit ready.",[33,6025,6026,6029],{},[61,6027,6028],{},"Training and Compliance Support"," — provide training and ongoing compliance support as regulations evolve.",[22,6031,6033],{"id":6032},"benefits-of-azure-gxp-compliance-with-qiksolve","Benefits of Azure GxP Compliance with QikSolve",[30,6035,6036,6041,6046,6052,6058],{},[33,6037,6038,6040],{},[61,6039,5550],{}," — face regulatory inspections knowing your cloud infrastructure complies with CFR 21 Part 11 and Annex 11.",[33,6042,6043,6045],{},[61,6044,5556],{}," — maintain the integrity of GxP data with robust security measures and audit capabilities.",[33,6047,6048,6051],{},[61,6049,6050],{},"Scalability"," — Azure's scalability ensures your GxP processes can adapt to your business needs.",[33,6053,6054,6057],{},[61,6055,6056],{},"Cost Efficiency"," — optimize cloud resources while meeting compliance requirements.",[33,6059,6060,6063],{},[61,6061,6062],{},"Focus on Innovation"," — with compliance handled, focus on driving your pharmaceutical or life sciences projects forward.",[22,6065,6067],{"id":6066},"trust-qiksolve-for-azure-gxp-compliance","Trust QikSolve for Azure GxP Compliance",[12,6069,6070,6071,6073],{},"At QikSolve, we believe GxP compliance should never be a hindrance to innovation. By configuring Azure to meet the stringent requirements of CFR 21 Part 11 and Annex 11 in a practical and pragmatic way, we empower pharmaceutical and life sciences organizations to thrive in a compliant, secure, and innovative environment. ",[55,6072,5579],{"href":228}," today to discover how we can make Azure GxP compliance a seamless reality for your business.",{"title":232,"searchDepth":233,"depth":233,"links":6075},[6076,6077,6078,6079],{"id":5962,"depth":233,"text":5963},{"id":5981,"depth":233,"text":5982},{"id":6032,"depth":233,"text":6033},{"id":6066,"depth":233,"text":6067},"2023-09-21","How QikSolve configures Microsoft Azure to meet CFR 21 Part 11 and Annex 11 requirements for pharmaceutical and life sciences organisations.",{},"\u002Fblog\u002Fachieving-gxp-compliance-with-azure-cfr-21-part-11-and-annex-11-made-simple",{"title":5945,"description":6081},"blog\u002Fachieving-gxp-compliance-with-azure-cfr-21-part-11-and-annex-11-made-simple",[1814,6087,5595,255],"azure","1oJUF9qsQdBizeVotJjyTF4lcf9AW1jAgH1Cg_P6VSg",1789388496335]