Deviations and CAPA
Groups deviations that describe the same problem in different words, searches the history for similar cases and how they were closed, and proposes a draft investigation with its sources cited.
Decides: quality assurance.
We bring AI models into the company's processes and deliver the evidence that they do what they claim: what they are used for, how they were tested, which version is in production and who approved each proposal.
What a model does well today.
AI pays off where qualified staff spend hours reading, comparing and filling in forms. In every case the model prepares and a person decides, and the system keeps a record of both.
Groups deviations that describe the same problem in different words, searches the history for similar cases and how they were closed, and proposes a draft investigation with its sources cited.
Decides: quality assurance.
Reads the complete batch record and presents only what went out of range, what is missing and what doesn't match previous batches.
Decides: the Qualified Person who certifies the batch.
Compares your procedures with a revised standard and lists the gaps with the exact clause. Turns a paper procedure into guided execution steps.
Decides: the process owner.
Extracts the data of a case from email, the form or the literature, proposes the MedDRA coding, detects duplicates and translates the original text. The reporting clock starts at receipt.
Decides: the case assessor.
Drafts dossier sections from the source data, with a reference for each data point, and finds in earlier dossiers how a similar question from the agency was answered.
Decides: regulatory affairs.
Proposes requirements, test cases and the traceability matrix, and when something changes it shows which evidence is affected and which is not.
Decides: the validation lead.
What we deliver for each model.
A model is not validated like a spreadsheet formula. Its output is probabilistic and its provider releases new versions. That is why the documentation of a system with AI includes pieces a conventional system doesn't need. Together they make up the model documentation: the evidence package you show in an inspection.
Prevent, detect and contain.
No control is perfect on its own, so we combine them in three layers. Each one is tied to a specific failure mode and a measurable acceptance criterion, and the risk assessment is updated when an unforeseen failure mode appears.
Data and model provider.
Nor does it leave the European Union or the country your regulations require, whether the system runs on your infrastructure or we run it for you.
What a person always decides.
Certifying a batch, deciding to notify an authority, approving a change and deciding the disposition of an out-of-specification result belong to people with a name and accountability. The model can prepare the information for those decisions, but it doesn't make them.
The draft Annex 22 to the EU GMP Guide currently restricts critical applications to static, deterministic models and leaves generative models for non-critical uses, with a person reviewing the output. Since the consultation, the European Medicines Agency has been considering allowing them with a risk-based control strategy, and the report of its latest workshop stresses that accountability stays with people and cannot be delegated to AI. The final text has not been published yet, and we design so the system can adapt to it without being rebuilt. We explain it section by section in the Annex 22 guide.
And if the risk assessment concludes that a model's uncertainty cannot be controlled, the conclusion is not to use it, and that conclusion is documented.
We start from a real case in your process and tell you whether a model adds enough to justify validating it.