Practical Guide: Pharmaceuticals and Life Sciences
Validation discipline is the sector's strength and its trap: GxP thinking answers “is it qualified” beautifully and “has it changed since Tuesday” not at all.
- Typical top tier
- Tier 4 — pharmacovigilance case processing, anything supporting a submission
- Already-owned ground
- Computerized system validation, data integrity, audit trails, change control
- Hardest gate
- G4 — because continuous model change and periodic revalidation do not fit together
- First record to fix
- Context of use, written per system, in one paragraph
1. Where the risk actually concentrates
Life sciences already runs the most rigorous change control of any sector in this guide. Computerized system validation, audit trails, electronic signature controls and data integrity expectations are mature, inspected and taken seriously. The friction IRGF encounters here is not resistance to governance; it is that validation assumes a system that holds still, and the systems now arriving do not.
The useful bridge is context of use. Regulators assessing AI in the medicinal product lifecycle have converged on a risk-based idea that maps almost directly onto IRGF's tiering: how much of the regulatory decision rests on this model, and how severe is the consequence if it is wrong. Where a submission or a safety decision depends on model output, the evidence bar is high and IRGF should defer to the regulatory expectation rather than invent a parallel one. Where the model drafts an internal document, it should not.
The sector's characteristic risk is quiet: a model embedded in a validated process, changed by a supplier, in a system whose validation package still describes the old behaviour. The audit trail will be immaculate about the records and silent about the model.
Indicative classification of the systems this sector keeps building. The scores are illustrative, not authoritative: they show how the anchors in Chapter 6 read against sector facts. Score your own system; do not copy a row.
| Typical system | Illustrative D1–D5 | Tier | What is usually mis-scored |
|---|---|---|---|
| Pharmacovigilance case intake, coding and seriousness assessment | D1 4 · D2 3 · D3 4 · D4 4 · D5 4 | Tier 4 | Auto-closure of non-serious cases is an autonomy setting nobody scored |
| Signal detection and prioritization in safety data | D1 4 · D2 2 · D3 4 · D4 4 · D5 4 | Tier 4 | A signal not surfaced cannot be un-missed; D3 is 4, not 2 |
| Model evidence supporting a regulatory submission | D1 4 · D2 1 · D3 3 · D4 3 · D5 3–4 | Tier 3–4 by context of use | Advisory scoring on D2 despite the submission depending on the output |
| Clinical trial patient matching and site selection | D1 3–4 · D2 2 · D3 3 · D4 3 · D5 4 | Tier 3 | Exclusion is invisible: nobody complains about a trial they were never offered |
| Manufacturing process control and batch release support | D1 4 · D2 3 · D3 4 · D4 3 · D5 3 | Tier 4 | Treated as engineering; batch disposition is a regulated decision |
| Deviation and CAPA triage | D1 3 · D2 2–3 · D3 3 · D4 3 · D5 3 | Tier 3 | Mis-triage of a deviation is a compliance finding, not an efficiency loss |
| Regulatory document drafting and dossier assembly | D1 3 · D2 1–2 · D3 3 · D4 3 · D5 3 | Tier 2–3 | A drafting tool whose output is submitted is part of the submission |
| Medical information response to a healthcare professional enquiry | D1 4 · D2 2 · D3 4 · D4 3 · D5 4 | Tier 3–4 | Off-label content risk; a statement made cannot be unmade |
| Literature screening and internal knowledge retrieval | D1 2–3 · D2 1 · D3 2 · D4 2 · D5 3 | Tier 2 | Fine — until the screening output feeds a safety process, at which point it is not |
2. The regulatory interface
Regulatory note. The regimes below are named so each IRGF record can be pointed at the obligation it evidences, not to restate them. Applicability, thresholds and commencement dates differ by jurisdiction and several have moved during implementation. Nothing here is legal advice: confirm the current position with your own counsel, and record the answer in the Regulatory Overlay Reference so it is checkable later.
IRGF does not restate any of these obligations. It gives each one a record that carries the evidence, an owner, and a trigger that reopens it when the obligation or the system changes.
| Regime or standard | What it obliges in practice | IRGF record that carries the evidence |
|---|---|---|
| Good practice regulations and computerized system validation expectations (GxP, GAMP 5 second edition) | Risk-based validation, supplier assessment, critical thinking about what actually needs testing, and lifecycle records. | Validation package referenced by the AI Assurance Summary; IRGF adds the runtime comparison, not a second validation |
| Electronic records and signatures rules (for example 21 CFR Part 11, EU GMP Annex 11) | Audit trails, record integrity, controlled access, signature attribution. | The audit link of the agent chain and the Drift/Alert Record must satisfy the same integrity standard as any other GxP record |
| Data integrity expectations (ALCOA+ principles) | Attributable, legible, contemporaneous, original, accurate — plus complete, consistent, enduring and available. | Applied to governance evidence itself, which is where most AI programmes fall short |
| Pharmacovigilance obligations | Case processing timelines, seriousness and expectedness assessment, signal management, and inspection readiness. | Timeliness and completeness registered as assurance criteria; auto-closure thresholds registered as autonomy settings |
| Regulator expectations for AI in the medicinal product lifecycle (for example the EMA reflection paper and FDA's risk-based credibility framework for AI supporting regulatory decisions) | A stated context of use, credibility evidence proportionate to how much the decision relies on the model, and lifecycle maintenance. | Context of use written into the AI Use-Case Canvas; credibility evidence is the tier-scaled assurance depth |
| Clinical trial regulation and good clinical practice (ICH E6 and equivalents) | Participant protection, data integrity, documented oversight of vendors and systems. | Vendor oversight fields in the ADR; trial-system changes routed through G4 |
3. Calibrating the five dimensions
The dimensions do not change. What changes is what a 3 and a 4 look like when the subject matter is this sector, and which reading an assessor under delivery pressure reaches for first.
| Dimension | How to read it here | The mis-score to watch for |
|---|---|---|
| D1 Decision Consequence | Patient safety decisions and anything supporting a regulatory submission or batch disposition are 4. Internal efficiency work is 1 to 2 until its output enters a regulated process. | Scoring the immediate user's inconvenience rather than the regulated decision downstream. |
| D2 Autonomy | Auto-closure, auto-coding and auto-triage thresholds are autonomy settings. Score the highest-autonomy path, including the one used only for the routine 80%. | Scoring the exception path that a human reviews and ignoring the bulk path that nobody does. |
| D3 Reversibility Deficit | A safety signal not raised, a batch released, and a statement made to a healthcare professional are all 4. Documents can be corrected; decisions taken on them cannot. | Scoring document correctability as reversibility. |
| D4 Exposure and Scale | Global processes reach every market and every product. A change to a coding dictionary or an intake rule propagates everywhere at once. | Scoring per affiliate when the system is global. |
| D5 Sensitivity and Uncertainty | Patient-level safety and trial data are 4. Generative extraction from narrative case reports carries uncertainty 3 to 4 because omission is the failure mode. | Assuming that structured output implies verified extraction. |
4. One system, end to end
The overlay above is a map. This is one route across it: a single adverse event report followed from intake to submission, with the record or control that attaches at each step.
5. What each gate adds
Additions only. Everything in the base gate definitions still applies; see the gate checklists for the common set.
| Gate | Sector addition | Why it is here |
|---|---|---|
| G1 | Write the context of use in one paragraph: what regulatory or safety decision relies on this output, and how much. State whether output enters a GxP process. | It sets the evidence bar for everything downstream and it is cheap to write at intake, expensive to reconstruct at inspection. |
| G2 | Supplier assessment covering model provenance, training data claims, change notification commitments and audit rights. Lineage for every source in a GxP path. | Change notification is the clause that determines whether your validated state is knowable. |
| G3 | Validation package and IRGF assurance summary cross-referenced, with the delta stated: what IRGF checks that validation did not, namely continued conformance after change. | Two documents that overlap without a stated relationship are an inspection finding waiting to happen. |
| G4 | Model change is the gate that matters. Define in advance which changes are inside the validated state and which force revalidation, and record supplier-initiated changes as change events even when nothing local moved. | Continuous model change is structurally incompatible with periodic revalidation unless the boundary is agreed in advance. |
| G5 | Retention to the regulatory record standard, with the ability to reproduce an output for a given case on a given date. | Inspections reach back years and ask about specific records. |
6. Controls and evidence worth adding
| Control | Where it attaches | Evidence it produces |
|---|---|---|
| Context of use statement, one per system, reviewed at each G4 | AI Use-Case Canvas; assurance summary | A single paragraph an inspector can read that fixes the evidence bar |
| Supplier change-notification clause with a defined notice period | ADR vendor fields; contract | Written commitment, plus a log of notifications actually received |
| Auto-closure and auto-coding threshold register | Change record; configuration baseline | Current thresholds, owner, and the D2 consequence of each |
| Reproducibility check: same input, same version, same output | Assurance cycle | A periodic test result, retained as a GxP record |
| Human review sample on the bulk automated path | Control Matrix | Sampled cases with error rate by category, not just an aggregate |
| Audit-trail conformance for governance records themselves | Evidence store | Attributable, contemporaneous, tamper-evident governance evidence |
7. Runtime signals to wire first
Control Plane onboarding order matters more than coverage in the first year (Chapter 18). These are the signals that earn their place earliest in this sector.
| Signal | Drift category | Suggested response |
|---|---|---|
| Supplier notifies, or fails to notify, a model version change | AI-model behavioral | Assess against the agreed validated-state boundary; revalidate or record why not, in the change record |
| Coding dictionary or terminology version updates | Data lineage and governance | Planned change with a defined test set; treat an unplanned update as a Material change |
| Auto-closure rate for safety cases moves outside the agreed band | Behavioral | Route to the qualified person for pharmacovigilance, not to engineering |
| Reproducibility check fails | Behavioral / configuration | Stop the automated path. A non-reproducible GxP system is not in a validated state |
| Regulatory guidance on AI evidence changes in a mapped jurisdiction | Policy and regulatory | Re-open the context-of-use statements for affected systems; this is a re-read, not a re-build |
8. Failure modes this sector produces
Validated once, silently different
The tell. The validation package describes behaviour the current model no longer has, because the supplier improved it.
The response. Make supplier change notification contractual, and treat the absence of notification as a finding. Where notification cannot be obtained, cap the system at a tier where that is acceptable, or do not use it in a GxP path.
The bulk path nobody reviews
The tell. Ninety percent of cases are auto-processed and the quality metrics are computed on the ten percent a human touched.
The response. Sample the automated path specifically, with a sample size that can detect the error rate you would care about. Report both paths separately.
Drafting tools inside the submission
The tell. A generative tool drafts sections of a dossier, and nobody records that it did.
The response. Record the tool, its version and its scope of use in the submission's own documentation. The question at inspection is not whether AI was used but whether its use was controlled.
Validation theatre for a probabilistic system
The tell. Test scripts with expected results are written for a generative system, and pass by being vague enough.
The response. Evaluate distributionally: a held-out set, a defined pass criterion agreed before the run, and a recorded failure analysis. See the generative systems guideline.
9. A ninety-day start
If the sector is yours and the framework is new, this is the order that produces something defensible fastest. It assumes one part-time architect and one risk lead, not a programme.
- Write context-of-use statements for every AI system touching a GxP process. One paragraph each, no exceptions, signed by the process owner.
- Separate the estate into GxP-path and non-GxP-path systems, and stop applying validation effort to the second group.
- Audit supplier contracts for model change notification. The gaps found here set the next year's procurement agenda.
- Register every auto-closure, auto-coding and auto-triage threshold in the safety and quality systems.
- Score pharmacovigilance and batch-relevant systems first, with quality assurance countersigning.
- Stand up the reproducibility check on the highest-tier system and retain the result as a GxP record.
- Agree the validated-state boundary for model change with quality assurance, in writing, before the next supplier release.
- Run one inspection-style dry run: pick a case from six months ago and reconstruct which version decided what, and on what evidence.