K · Practical guide

Practical Guide: Pharmaceuticals and Life Sciences

Validation discipline is the sector's strength and its trap: GxP thinking answers “is it qualified” beautifully and “has it changed since Tuesday” not at all.

Typical top tier
Tier 4 — pharmacovigilance case processing, anything supporting a submission
Already-owned ground
Computerized system validation, data integrity, audit trails, change control
Hardest gate
G4 — because continuous model change and periodic revalidation do not fit together
First record to fix
Context of use, written per system, in one paragraph

1. Where the risk actually concentrates

Life sciences already runs the most rigorous change control of any sector in this guide. Computerized system validation, audit trails, electronic signature controls and data integrity expectations are mature, inspected and taken seriously. The friction IRGF encounters here is not resistance to governance; it is that validation assumes a system that holds still, and the systems now arriving do not.

The useful bridge is context of use. Regulators assessing AI in the medicinal product lifecycle have converged on a risk-based idea that maps almost directly onto IRGF's tiering: how much of the regulatory decision rests on this model, and how severe is the consequence if it is wrong. Where a submission or a safety decision depends on model output, the evidence bar is high and IRGF should defer to the regulatory expectation rather than invent a parallel one. Where the model drafts an internal document, it should not.

The sector's characteristic risk is quiet: a model embedded in a validated process, changed by a supplier, in a system whose validation package still describes the old behaviour. The audit trail will be immaculate about the records and silent about the model.

Discovery target identification, screening Tier 2 Clinical trial design, matching, monitoring Tier 3 Regulatory evidence and dossier support Tier 4 Manufacturing process control, batch support Tier 4 Post-market pharmacovigilance, signal detection Tier 4
Tier follows context of use. The same model architecture is Tier 2 in discovery and Tier 4 when its output supports a regulatory or safety decision. That is the sector's version of the framework's central claim: govern the decision the system participates in, not the technology.

Indicative classification of the systems this sector keeps building. The scores are illustrative, not authoritative: they show how the anchors in Chapter 6 read against sector facts. Score your own system; do not copy a row.

Typical system Illustrative D1–D5 Tier What is usually mis-scored
Pharmacovigilance case intake, coding and seriousness assessmentD1 4 · D2 3 · D3 4 · D4 4 · D5 4Tier 4Auto-closure of non-serious cases is an autonomy setting nobody scored
Signal detection and prioritization in safety dataD1 4 · D2 2 · D3 4 · D4 4 · D5 4Tier 4A signal not surfaced cannot be un-missed; D3 is 4, not 2
Model evidence supporting a regulatory submissionD1 4 · D2 1 · D3 3 · D4 3 · D5 3–4Tier 3–4 by context of useAdvisory scoring on D2 despite the submission depending on the output
Clinical trial patient matching and site selectionD1 3–4 · D2 2 · D3 3 · D4 3 · D5 4Tier 3Exclusion is invisible: nobody complains about a trial they were never offered
Manufacturing process control and batch release supportD1 4 · D2 3 · D3 4 · D4 3 · D5 3Tier 4Treated as engineering; batch disposition is a regulated decision
Deviation and CAPA triageD1 3 · D2 2–3 · D3 3 · D4 3 · D5 3Tier 3Mis-triage of a deviation is a compliance finding, not an efficiency loss
Regulatory document drafting and dossier assemblyD1 3 · D2 1–2 · D3 3 · D4 3 · D5 3Tier 2–3A drafting tool whose output is submitted is part of the submission
Medical information response to a healthcare professional enquiryD1 4 · D2 2 · D3 4 · D4 3 · D5 4Tier 3–4Off-label content risk; a statement made cannot be unmade
Literature screening and internal knowledge retrievalD1 2–3 · D2 1 · D3 2 · D4 2 · D5 3Tier 2Fine — until the screening output feeds a safety process, at which point it is not

2. The regulatory interface

Regulatory note. The regimes below are named so each IRGF record can be pointed at the obligation it evidences, not to restate them. Applicability, thresholds and commencement dates differ by jurisdiction and several have moved during implementation. Nothing here is legal advice: confirm the current position with your own counsel, and record the answer in the Regulatory Overlay Reference so it is checkable later.

IRGF does not restate any of these obligations. It gives each one a record that carries the evidence, an owner, and a trigger that reopens it when the obligation or the system changes.

Regime or standard What it obliges in practice IRGF record that carries the evidence
Good practice regulations and computerized system validation expectations (GxP, GAMP 5 second edition)Risk-based validation, supplier assessment, critical thinking about what actually needs testing, and lifecycle records.Validation package referenced by the AI Assurance Summary; IRGF adds the runtime comparison, not a second validation
Electronic records and signatures rules (for example 21 CFR Part 11, EU GMP Annex 11)Audit trails, record integrity, controlled access, signature attribution.The audit link of the agent chain and the Drift/Alert Record must satisfy the same integrity standard as any other GxP record
Data integrity expectations (ALCOA+ principles)Attributable, legible, contemporaneous, original, accurate — plus complete, consistent, enduring and available.Applied to governance evidence itself, which is where most AI programmes fall short
Pharmacovigilance obligationsCase processing timelines, seriousness and expectedness assessment, signal management, and inspection readiness.Timeliness and completeness registered as assurance criteria; auto-closure thresholds registered as autonomy settings
Regulator expectations for AI in the medicinal product lifecycle (for example the EMA reflection paper and FDA's risk-based credibility framework for AI supporting regulatory decisions)A stated context of use, credibility evidence proportionate to how much the decision relies on the model, and lifecycle maintenance.Context of use written into the AI Use-Case Canvas; credibility evidence is the tier-scaled assurance depth
Clinical trial regulation and good clinical practice (ICH E6 and equivalents)Participant protection, data integrity, documented oversight of vendors and systems.Vendor oversight fields in the ADR; trial-system changes routed through G4

3. Calibrating the five dimensions

The dimensions do not change. What changes is what a 3 and a 4 look like when the subject matter is this sector, and which reading an assessor under delivery pressure reaches for first.

Dimension How to read it here The mis-score to watch for
D1 Decision ConsequencePatient safety decisions and anything supporting a regulatory submission or batch disposition are 4. Internal efficiency work is 1 to 2 until its output enters a regulated process.Scoring the immediate user's inconvenience rather than the regulated decision downstream.
D2 AutonomyAuto-closure, auto-coding and auto-triage thresholds are autonomy settings. Score the highest-autonomy path, including the one used only for the routine 80%.Scoring the exception path that a human reviews and ignoring the bulk path that nobody does.
D3 Reversibility DeficitA safety signal not raised, a batch released, and a statement made to a healthcare professional are all 4. Documents can be corrected; decisions taken on them cannot.Scoring document correctability as reversibility.
D4 Exposure and ScaleGlobal processes reach every market and every product. A change to a coding dictionary or an intake rule propagates everywhere at once.Scoring per affiliate when the system is global.
D5 Sensitivity and UncertaintyPatient-level safety and trial data are 4. Generative extraction from narrative case reports carries uncertainty 3 to 4 because omission is the failure mode.Assuming that structured output implies verified extraction.

4. One system, end to end

The overlay above is a map. This is one route across it: a single adverse event report followed from intake to submission, with the record or control that attaches at each step.

Worked example — pharmacovigilance case intake and seriousness assessment D1 4 · D2 3 · D3 4 · D4 4 · D5 4 → IMPACT 4 · CONTROL DEFICIT 4 → TIER 4 IN THE WORLD IN THE RECORD, AND WHAT WATCHES IT Individual case safety report arrives Context of use in one paragraph: what safety decision rests on this output Model codes terms and assesses seriousness Coding dictionary version recorded; an unplanned update is a Material change Non-serious cases auto- close below a threshold The threshold is an autonomy setting, registered and owned, not a configuration flag Qualified person reviews a sample of the bulk path Sampling sized to detect the error rate you would care about, on the automated path Case submitted within the regulatory clock Drift watch: supplier model change, auto- closure rate, reproducibilit y check
The bulk path is the system. Quality metrics computed on the ten percent a human touched say nothing about the ninety percent auto-closed in column three. The reproducibility check in column five is what keeps the whole path inside a validated state when the supplier improves the model.

5. What each gate adds

Additions only. Everything in the base gate definitions still applies; see the gate checklists for the common set.

Gate Sector addition Why it is here
G1Write the context of use in one paragraph: what regulatory or safety decision relies on this output, and how much. State whether output enters a GxP process.It sets the evidence bar for everything downstream and it is cheap to write at intake, expensive to reconstruct at inspection.
G2Supplier assessment covering model provenance, training data claims, change notification commitments and audit rights. Lineage for every source in a GxP path.Change notification is the clause that determines whether your validated state is knowable.
G3Validation package and IRGF assurance summary cross-referenced, with the delta stated: what IRGF checks that validation did not, namely continued conformance after change.Two documents that overlap without a stated relationship are an inspection finding waiting to happen.
G4Model change is the gate that matters. Define in advance which changes are inside the validated state and which force revalidation, and record supplier-initiated changes as change events even when nothing local moved.Continuous model change is structurally incompatible with periodic revalidation unless the boundary is agreed in advance.
G5Retention to the regulatory record standard, with the ability to reproduce an output for a given case on a given date.Inspections reach back years and ask about specific records.

6. Controls and evidence worth adding

Control Where it attaches Evidence it produces
Context of use statement, one per system, reviewed at each G4AI Use-Case Canvas; assurance summaryA single paragraph an inspector can read that fixes the evidence bar
Supplier change-notification clause with a defined notice periodADR vendor fields; contractWritten commitment, plus a log of notifications actually received
Auto-closure and auto-coding threshold registerChange record; configuration baselineCurrent thresholds, owner, and the D2 consequence of each
Reproducibility check: same input, same version, same outputAssurance cycleA periodic test result, retained as a GxP record
Human review sample on the bulk automated pathControl MatrixSampled cases with error rate by category, not just an aggregate
Audit-trail conformance for governance records themselvesEvidence storeAttributable, contemporaneous, tamper-evident governance evidence

7. Runtime signals to wire first

Control Plane onboarding order matters more than coverage in the first year (Chapter 18). These are the signals that earn their place earliest in this sector.

Signal Drift category Suggested response
Supplier notifies, or fails to notify, a model version changeAI-model behavioralAssess against the agreed validated-state boundary; revalidate or record why not, in the change record
Coding dictionary or terminology version updatesData lineage and governancePlanned change with a defined test set; treat an unplanned update as a Material change
Auto-closure rate for safety cases moves outside the agreed bandBehavioralRoute to the qualified person for pharmacovigilance, not to engineering
Reproducibility check failsBehavioral / configurationStop the automated path. A non-reproducible GxP system is not in a validated state
Regulatory guidance on AI evidence changes in a mapped jurisdictionPolicy and regulatoryRe-open the context-of-use statements for affected systems; this is a re-read, not a re-build

8. Failure modes this sector produces

Validated once, silently different

The tell. The validation package describes behaviour the current model no longer has, because the supplier improved it.

The response. Make supplier change notification contractual, and treat the absence of notification as a finding. Where notification cannot be obtained, cap the system at a tier where that is acceptable, or do not use it in a GxP path.

The bulk path nobody reviews

The tell. Ninety percent of cases are auto-processed and the quality metrics are computed on the ten percent a human touched.

The response. Sample the automated path specifically, with a sample size that can detect the error rate you would care about. Report both paths separately.

Drafting tools inside the submission

The tell. A generative tool drafts sections of a dossier, and nobody records that it did.

The response. Record the tool, its version and its scope of use in the submission's own documentation. The question at inspection is not whether AI was used but whether its use was controlled.

Validation theatre for a probabilistic system

The tell. Test scripts with expected results are written for a generative system, and pass by being vague enough.

The response. Evaluate distributionally: a held-out set, a defined pass criterion agreed before the run, and a recorded failure analysis. See the generative systems guideline.

9. A ninety-day start

If the sector is yours and the framework is new, this is the order that produces something defensible fastest. It assumes one part-time architect and one risk lead, not a programme.

  1. Write context-of-use statements for every AI system touching a GxP process. One paragraph each, no exceptions, signed by the process owner.
  2. Separate the estate into GxP-path and non-GxP-path systems, and stop applying validation effort to the second group.
  3. Audit supplier contracts for model change notification. The gaps found here set the next year's procurement agenda.
  4. Register every auto-closure, auto-coding and auto-triage threshold in the safety and quality systems.
  5. Score pharmacovigilance and batch-relevant systems first, with quality assurance countersigning.
  6. Stand up the reproducibility check on the highest-tier system and retain the result as a GxP record.
  7. Agree the validated-state boundary for model change with quality assurance, in writing, before the next supplier release.
  8. Run one inspection-style dry run: pick a case from six months ago and reconstruct which version decided what, and on what evidence.