AI Governance
AI Agent Governance Scenarios, Part 3: The "Smart SOP Assistant"
An AI assistant that answers procedural questions quickly became popular across the site. Rapid adoption is not the same thing as compliance fitness.
This is the third in a five-part series of practical AI-governance scenarios for quality professionals.
The scenario
An AI assistant, deployed across the company intranet, helps operators and supervisors find answers to procedural and GMP-related questions quickly, drawing on a library that includes approved SOPs, work instructions, training materials, draft procedures, internal guidance notes, and historical investigation reports. Staff ask it questions with direct procedural and compliance consequences: can I continue if this section of the batch record is incomplete? Does this step require QA approval? Is this deviation minor or major?
The tool is widely used precisely because it provides quick answers. Speed of adoption is not evidence of compliance fitness — a QA review has surfaced four distinct risk areas.
Issue 1 — Controlled and uncontrolled documents mixed
The knowledge library does not distinguish approved SOPs from draft procedures, training slides, or historical investigation reports containing superseded conclusions — and the AI presents an answer citing any of them with no visible difference. If the system retrieves and presents guidance from an uncontrolled document, any manufacturing decision made on that basis is non-compliant, regardless of intent. Applicable principle: controlled inputs — the AI must operate only on approved, controlled sources, with technical controls preventing draft or superseded content from entering the library.
Issue 2 — The assistant interprets procedural requirements
Answering whether a deviation is minor or major, or whether a step requires QA approval, is procedural interpretation, not information retrieval — it requires contextual judgement in light of real-time manufacturing circumstances. The acceptable role for an assistant like this is to retrieve and display the relevant SOP section for the user to apply themselves; interpreting whether approval is needed or production may proceed belongs to qualified personnel. Applicable principle: define intended use and scope — procedural interpretation should be explicitly excluded, with the system declining or redirecting such queries.
Issue 3 — Operators treat the assistant as procedural authority
Operators are routinely relying on the summarised answer rather than opening and reading the controlled SOP — understandable, since the AI answer is faster to consume, but the controlled SOP, not the AI's interpretation of it, is the procedural authority. Errors or omissions in the summary propagate directly into manufacturing decisions, and version drift between the library and the live document-management system can go undetected if no one reads the source document. Applicable principle: human verification is mandatory — every response should display the source document and version, with a visible prompt to confirm understanding against the controlled document before acting.
Issue 4 — Knowledge library governance is unclear
There is no defined process for approving a document's inclusion, propagating SOP revisions to the knowledge base, or excluding draft and retired documents. Applicable principle: quality system governance — the knowledge library is, in effect, a controlled document repository, and needs a named owner, a documented change-control process for additions and removals, and a periodic audit schedule.
What has to happen before continued use is approved
Continued use should not be approved in its current form, though the tool could provide genuine value once the gaps are closed: suspend unrestricted access pending review; audit and restrict the knowledge library to confirmed-approved documents only; produce a formal scope statement excluding procedural interpretation; establish named ownership and change control for the library; and formally validate the system while updating training to address AI over-reliance.
Each of these is a prerequisite for a regulated deployment of this kind of tool, not an optional enhancement layered on afterward.