[{"data":1,"prerenderedAt":123},["ShallowReactive",2],{"\u002Fblog\u002Fai-agent-governance-scenarios-part-5-the-inspection-question":3},{"id":4,"title":5,"author":6,"body":7,"category":105,"date":106,"description":107,"draft":108,"excerpt":109,"extension":110,"heroImage":109,"heroImageAlt":109,"meta":111,"navigation":112,"path":113,"seo":114,"slug":109,"stem":115,"tags":116,"__hash__":122},"blog\u002Fblog\u002Fai-agent-governance-scenarios-part-5-the-inspection-question.md","AI Agent Governance Scenarios, Part 5: The Inspection Question","QikSolve",{"type":8,"value":9,"toc":92},"minimark",[10,14,19,22,26,29,33,36,40,43,47,50,54,57,61,64,68,71,75],[11,12,13],"p",{},"This is the final part of a five-part series of practical AI-governance scenarios for quality\nprofessionals.",[15,16,18],"h2",{"id":17},"the-scenario","The scenario",[11,20,21],{},"An organisation has used an AI agent to assist QA reviewers with batch record review for six\nmonths, identifying missing entries, arithmetic inconsistencies, and potential documentation issues\nfor QA consideration. During a routine regulatory inspection, the auditor learns AI is used in the\nprocess and asks for a full explanation of how the system is governed.",[15,23,25],{"id":24},"question-1-how-is-this-ai-system-used-within-your-quality-process","Question 1 — \"How is this AI system used within your quality process?\"",[11,27,28],{},"The first and most important move in any audit defence involving AI is to position the system\ncorrectly from the outset: the agent performs a structured scan of the batch record to highlight\npotential areas of concern, and presents findings in a review summary for QA consideration. It does\nnot make compliance decisions and does not determine whether a batch is releasable — every output is\nreviewed by a qualified reviewer, who performs the final assessment and takes full professional\naccountability. Regulators are not inherently opposed to AI in GMP; what they require is evidence\nthat it is properly governed and that human judgement remains at the centre of the decision.",[15,30,32],{"id":31},"question-2-how-do-you-ensure-the-system-operates-within-an-appropriate-scope","Question 2 — \"How do you ensure the system operates within an appropriate scope?\"",[11,34,35],{},"A common weakness in AI governance is a failure to formally define what a system is, and is not,\npermitted to do. The system is permitted to identify missing fields, arithmetic issues, and\nformatting anomalies; it is explicitly prohibited from determining compliance conclusions or release\ndecisions, and that boundary is documented in the system's intended-use statement and reviewed as\npart of quality governance — not assumed or informally understood.",[15,37,39],{"id":38},"question-3-what-controls-ensure-the-inputs-are-reliable-and-appropriate","Question 3 — \"What controls ensure the inputs are reliable and appropriate?\"",[11,41,42],{},"The system exclusively reviews controlled batch record exports generated as part of the review\nprocess — not drafts, working copies, or documents from outside the defined input boundary, and it\nhas no access to uncontrolled data. Controlling inputs is a fundamental GMP principle that applies\nequally to AI systems: if the inputs were uncontrolled, the findings could not be relied upon as a\nmeaningful review aid.",[15,44,46],{"id":45},"question-4-are-reviewers-independently-assessing-outputs-not-simply-accepting-them","Question 4 — \"Are reviewers independently assessing outputs, not simply accepting them?\"",[11,48,49],{},"The AI summary is presented as a structured list of potential concerns, not a compliance finding or\nan authoritative assessment. QA reviewers are required to independently assess each flagged item —\nacceptance without independent verification is not permitted, and the reviewer's assessment,\nincluding any disagreement with the AI output, is formally recorded as part of the batch record\nreview documentation. That creates a clear audit trail demonstrating human judgement at every\nstage; the AI summary does not appear in the record as a compliance document, the reviewer's\nassessment does.",[15,51,53],{"id":52},"question-5-how-are-changes-to-the-system-managed","Question 5 — \"How are changes to the system managed?\"",[11,55,56],{},"Any modification to configuration, prompts, or workflow integration is processed through the\norganisation's established change control procedure, with a documented impact assessment for any\nchange that could affect system behaviour. The AI system is not governed through a separate\nframework — it is a component of the quality workflow, subject to the same QMS controls as any\nother regulated process.",[15,58,60],{"id":59},"question-6-how-do-you-monitor-ongoing-performance","Question 6 — \"How do you monitor ongoing performance?\"",[11,62,63],{},"The system is subject to periodic review as part of quality oversight, evaluating performance\nagainst expectations, incorporating reviewer feedback, and assessing discrepancies identified during\nuse — including whether the system continues to operate within its defined intended use, with any\nscope drift addressed through the change control and governance process before use continues.",[15,65,67],{"id":66},"why-this-defence-holds-up","Why this defence holds up",[11,69,70],{},"Five elements make this a strong defence: clearly defined intended use with documented limitations;\nAI outputs never treated as compliance decisions; inputs restricted to controlled sources only;\nmandatory, documented human verification at every stage; and change control and periodic review\nhandled through existing QMS processes rather than a parallel framework. A strong audit defence for\nAI in GMP does not require explaining transformer architectures or training methodology — it\nrequires showing that the same disciplined governance thinking already applied to every other\nquality-critical process has been extended to AI. The language of the defence is the language of\nquality, not technology.",[15,72,74],{"id":73},"related-reading","Related reading",[76,77,78,86],"ul",{},[79,80,81],"li",{},[82,83,85],"a",{"href":84},"\u002Fblog\u002Fai-agent-governance-scenarios-part-4-the-efficiency-shortcut","Part 4: The \"Efficiency Shortcut\"",[79,87,88],{},[82,89,91],{"href":90},"\u002Fblog\u002Foperating-ai-agents-in-gxp-qa-practitioners-guide","Operating AI Agents in GxP: A QA Practitioner's Guide",{"title":93,"searchDepth":94,"depth":94,"links":95},"",2,[96,97,98,99,100,101,102,103,104],{"id":17,"depth":94,"text":18},{"id":24,"depth":94,"text":25},{"id":31,"depth":94,"text":32},{"id":38,"depth":94,"text":39},{"id":45,"depth":94,"text":46},{"id":52,"depth":94,"text":53},{"id":59,"depth":94,"text":60},{"id":66,"depth":94,"text":67},{"id":73,"depth":94,"text":74},"AI Governance","2026-09-10","A strong audit defence for AI-assisted batch record review does not require explaining the technology — only clear governance, defined scope, and human oversight.",false,null,"md",{},true,"\u002Fblog\u002Fai-agent-governance-scenarios-part-5-the-inspection-question",{"title":5,"description":107},"blog\u002Fai-agent-governance-scenarios-part-5-the-inspection-question",[117,118,119,120,121],"ai-agents","gxp","workshop-scenario","inspection-readiness","audit-defence","i3OfPwcR4qzwSj4UonZuuFItV_mCXKxAR60qqL9QPhU",1789037363501]