Skip to main content

AI Governance

AI Agent Governance Scenarios, Part 5: The Inspection Question

A strong audit defence for AI-assisted batch record review does not require explaining the technology — only clear governance, defined scope, and human oversight.

Published 2026-09-10QikSolve

This is the final part of a five-part series of practical AI-governance scenarios for quality professionals.

The scenario

An organisation has used an AI agent to assist QA reviewers with batch record review for six months, identifying missing entries, arithmetic inconsistencies, and potential documentation issues for QA consideration. During a routine regulatory inspection, the auditor learns AI is used in the process and asks for a full explanation of how the system is governed.

Question 1 — "How is this AI system used within your quality process?"

The first and most important move in any audit defence involving AI is to position the system correctly from the outset: the agent performs a structured scan of the batch record to highlight potential areas of concern, and presents findings in a review summary for QA consideration. It does not make compliance decisions and does not determine whether a batch is releasable — every output is reviewed by a qualified reviewer, who performs the final assessment and takes full professional accountability. Regulators are not inherently opposed to AI in GMP; what they require is evidence that it is properly governed and that human judgement remains at the centre of the decision.

Question 2 — "How do you ensure the system operates within an appropriate scope?"

A common weakness in AI governance is a failure to formally define what a system is, and is not, permitted to do. The system is permitted to identify missing fields, arithmetic issues, and formatting anomalies; it is explicitly prohibited from determining compliance conclusions or release decisions, and that boundary is documented in the system's intended-use statement and reviewed as part of quality governance — not assumed or informally understood.

Question 3 — "What controls ensure the inputs are reliable and appropriate?"

The system exclusively reviews controlled batch record exports generated as part of the review process — not drafts, working copies, or documents from outside the defined input boundary, and it has no access to uncontrolled data. Controlling inputs is a fundamental GMP principle that applies equally to AI systems: if the inputs were uncontrolled, the findings could not be relied upon as a meaningful review aid.

Question 4 — "Are reviewers independently assessing outputs, not simply accepting them?"

The AI summary is presented as a structured list of potential concerns, not a compliance finding or an authoritative assessment. QA reviewers are required to independently assess each flagged item — acceptance without independent verification is not permitted, and the reviewer's assessment, including any disagreement with the AI output, is formally recorded as part of the batch record review documentation. That creates a clear audit trail demonstrating human judgement at every stage; the AI summary does not appear in the record as a compliance document, the reviewer's assessment does.

Question 5 — "How are changes to the system managed?"

Any modification to configuration, prompts, or workflow integration is processed through the organisation's established change control procedure, with a documented impact assessment for any change that could affect system behaviour. The AI system is not governed through a separate framework — it is a component of the quality workflow, subject to the same QMS controls as any other regulated process.

Question 6 — "How do you monitor ongoing performance?"

The system is subject to periodic review as part of quality oversight, evaluating performance against expectations, incorporating reviewer feedback, and assessing discrepancies identified during use — including whether the system continues to operate within its defined intended use, with any scope drift addressed through the change control and governance process before use continues.

Why this defence holds up

Five elements make this a strong defence: clearly defined intended use with documented limitations; AI outputs never treated as compliance decisions; inputs restricted to controlled sources only; mandatory, documented human verification at every stage; and change control and periodic review handled through existing QMS processes rather than a parallel framework. A strong audit defence for AI in GMP does not require explaining transformer architectures or training methodology — it requires showing that the same disciplined governance thinking already applied to every other quality-critical process has been extended to AI. The language of the defence is the language of quality, not technology.