Data Integrity, CSV/CSA and AI in GxP Quality
Inspection-ready data integrity for GxP systems. And the governance to bring AI into them.
I help pharma, biotech, and med-device QA teams validate computerized systems to risk, keep their data ALCOA+ compliant, and introduce AI into quality work with controls an inspector will accept. Independent, hands-on, and built as a capability your team owns.
The Challenge
Two gaps, one quality system
Your systems are validated. Is your data?
Audit trails are enabled but nobody reviews them. Spreadsheets carry GxP decisions with no validation record. Periodic reviews are overdue because the validation team ran out of hours before it ran out of systems. None of this shows up until an inspector asks for the audit trail review SOP, or for the last periodic evaluation of a system that controls batch release. EU Annex 11 §9 expects audit trails to be reviewed; §11 expects periodic evaluation. Both are the first things I check.
AI is entering quality work faster than the governance to control it
Teams are already using AI tools on deviations, complaints and documentation, usually with no documented decision on what the tool may do, how its output is checked, and who stays accountable. The direction is visible in the draft EU Annex 22 and the ISPE GAMP AI Guide (2025). Waiting for the final text means paying an outside vendor a premium later to catch up on routines you could build now.
Where I Help
Two lanes, one method: assurance commensurate with risk
Each service starts from the same principle: assurance should be commensurate with risk, and the capability should end up inside your organization, not outside it.
Data Integrity & Computerized System Assurance
Risk-based validation strategy and packages (GAMP 5, FDA CSA), 21 CFR Part 11 and EU Annex 11 assessments, ALCOA+ programs and remediation, audit trail review methodology, IT infrastructure qualification, supplier and internal audits, inspection readiness, and training for QA, IT and operations.
See the Data Integrity lane →AI in GxP Quality
Governance frameworks for AI in a GxP quality system, structured assessment of AI tools before they become a production dependency, and implementation of AI agents in quality workflows with a human decision recorded at every compliance-critical step, validated with a CSA mindset.
See the AI lane →How I work
Validate to risk, not to a template. Drafts are labeled as drafts. No client names, no invented numbers. Every engagement ends with a capability your team runs without me: the 5-Stage Automation Model for AI, the Win-Win Pilot for a bounded first engagement.
See the Approach →Who I work with
QA Manager
You own the quality system and the inspection. You need validation effort that tracks risk, audit trails that are actually reviewed, and a defensible answer when the inspector asks about AI.
Validation / IT Manager
You have more systems than hours. You need a validation strategy that scales, infrastructure qualification that holds, and a way to bring SaaS and AI tools in without a 483.
Regulatory Affairs lead
You need the regulatory position on Annex 11, Annex 22 and the EU AI Act stated accurately, drafts labeled as drafts, before the company commits to a tool.
Med-device Quality lead
You run a 21 CFR Part 820 QMSR / ISO 13485 quality system and need software validation and data integrity discipline that fits it.
The Approach
From reactive checklists to a strategic asset
Most QA organizations move through the same maturity arc. My job is to move you along it deliberately, instead of waiting for the next audit to force the next step.
Reactive
QA answers after problems appear
Sampling instead of full coverage. Review happens on a schedule, not on a signal. Findings surface after the cost is already incurred.
Proactive
Continuous scanning, full coverage
Pattern detection and trend dashboards replace sampling. You see a drift toward a deviation before it becomes one.
Strategic
Compliance becomes an internal asset
In-house methodology, owned and run by your team, becomes a defensible position rather than a recurring line item paid to outside consultants.
Implementation runs on my 5-Stage Automation Model: centralizing your SOPs and standards, defining a specialist agent tuned to your organization's language, building structured multi-step workflows with human review built in, moving from reactive to scheduled operation, and validating the result the way FDA's CSA approach expects, with edge-case testing and continuous checks against human judgment.
Read the full 5-Stage Automation ModelHow We Work Together
An engagement structured to remove your risk, not add to it
Most AI pilots fail because the client carries all the risk of a science experiment. My Win-Win Pilot inverts that. You invest in the software license. I invest the architecture design, prompt engineering, SOP integration, and validation work needed to get it into real, auditable use. If it does not hold up under validation, you have not overpaid for something that does not work.
years
I've worked with a pharma manufacturing client for roughly ten years. The 5-Stage Automation Model behind my Approach page grew out of a QA automation proof-of-concept we built together inside their existing validation framework, not a theoretical exercise.
I also assist medical-device companies with quality system compliance under 21 CFR Part 820 and ISO 13485, as a secondary capability alongside the three services above.
Before You Book a Call
Questions I hear from QA leaders
Do we need to re-validate our systems for the Annex 11 revision?
Not yet, and not wholesale. The revision was a 2025 consultation draft and is not in force; the 2011 text still applies. What you can do now is map each system's current validation and periodic evaluation (Annex 11 §4, §11) against the draft's direction, so the gap list exists before the final text does.
Is sampling audit trails acceptable?
Regulators expect audit trails to be reviewed regularly and the review to be risk-based (EU Annex 11 §9; MHRA GxP Data Integrity Guidance 2018 §6.13). Sampling is a defensible starting point only if the sampling logic is documented and justified by risk. Full-coverage review is where scheduled automation earns its place, with a human deciding on every flagged record.
CSV or CSA: which do inspectors expect?
They expect assurance commensurate with risk. GAMP 5 (2nd edition, 2022) and FDA's Computer Software Assurance approach both push critical thinking over document volume. In practice that means less scripted testing on low-risk functions and more evidence where a failure could reach the patient or the batch record.
Isn't it safer to wait until AI governance guidance is more settled?
The direction is already visible. EU Annex 22 exists in draft form, and ISPE published its GAMP guide on AI in 2025. The capabilities your team needs are the same under any final wording: defining acceptance criteria for AI output, keeping human review at the compliance-critical steps, and documenting how each tool was assessed. Those take time to build and do not depend on the guidance being final. Teams that start now meet the final texts with a working routine. Teams that wait meet them with a project plan.
Does this replace my QA team?
No. The agent removes noise between your subject matter experts and the signal. The humans still make the calls that require judgment. Every workflow I build keeps human-in-the-loop review at the steps that matter for compliance.
What if we are not ready to commit to a pilot?
Start with a discovery call. We map where manual review is costing you the most, and whether CSV/CSA, AI governance, or an AI tool assessment is the right place to start, before either of us commits to anything larger.
Ready to talk about where your quality system stands?
A 30-minute discovery call, or a bounded Data Integrity health check on one system. Either way you leave with a gap list you own. Or start with the twelve-question Data Integrity self-check.