The Approach
Validate to risk. Then automate what the evidence supports.
This page covers the validation philosophy behind every engagement, the maturity arc most QA organizations move through, the 5-Stage Automation Model for bringing AI into a quality routine, and the controls that run through every stage.
Validation Philosophy
Assurance commensurate with risk, not validation for its own sake
My validation approach follows GAMP 5's risk-based principle and FDA's Computer Software Assurance (CSA) guidance: the depth of assurance should match the risk the system actually carries. A batch-release system earns a deep test battery. A low-risk internal dashboard does not need the same one.
Running an identical, exhaustive script-based test battery against a low-risk system and a high-risk one does not make the low-risk system safer. It produces documentation that satisfies a checklist rather than evidence anyone, including the auditor, will actually read closely.
The same principle extends past validation into Data Integrity generally. ALCOA+ and 21 CFR Part 11 controls hold up only when they run continuously, as part of how the system operates day to day, not as a project with a defined start date and end date. MHRA's GXP Data Integrity guidance makes the same point from the regulator's side: data governance is an ongoing practice, not a one-time deliverable you can file and forget.
EU Annex 22, which addresses AI use in GMP-regulated environments, is still draft guidance as of this writing. I track its direction and design toward where it is heading, but I do not represent it to a client as adopted regulation until it is finalized. My AI governance work is grounded in the ISPE GAMP® Guide: Artificial Intelligence (2025), the industry's dedicated good-practice framework for AI-enabled GxP systems, alongside the draft EU Annex 22.
The Maturity Arc
Reactive, proactive, strategic: the same arc almost every QA organization moves through
I have not yet met a QA organization that skipped a stage. The question is not whether you will move through this arc. It is whether you move through it deliberately, on your own timeline, or get pushed through it by the next audit finding.
Reactive
QA answers after problems appear
What QA looks like
Deviation investigations, CAPA follow-up, and batch review happen after the fact, on a schedule set by headcount. Sampling substitutes for full coverage because there are not enough review hours to cover everything.
What it costs
Findings surface after the cost is already incurred. Audit prep is a scramble because the evidence was never continuously reviewed in the first place.
What changes
Nothing, until the next audit or a finding forces the issue. The gap to industry practice keeps widening while the organization stays here.
Proactive
Continuous scanning, full coverage
What QA looks like
Scanning and pattern detection cover the full record set instead of a sample. Trend dashboards flag drift toward a deviation before it becomes one.
What it costs
Real time up front to define, build, and validate the workflow, and a specialist agent rather than a general-purpose chatbot pointed at your documents.
What changes
Review time shifts from searching and transcription toward judgment calls. QA staff spend more time on the decisions that actually need a human.
Strategic
Compliance becomes an internal asset
What QA looks like
The workflow, the validation evidence, and the institutional knowledge behind both live inside the organization, run by the organization's own team.
What it costs
An ongoing commitment to keep the agent's instructions current as SOPs change, and to re-validate when the underlying system or model changes.
What changes
Compliance becomes a capability the organization owns, rather than a recurring line item paid to an outside vendor.
The Framework
The 5-Stage AI-in-Quality Automation Model
I built this model working with a pharma manufacturing client I've worked with for roughly ten years, refining it through a QA automation proof-of-concept we developed together inside their existing validation framework. It is the sequence I bring to every engagement since, adapted to each client's own SOPs, systems, and risk profile.
Stage 1
Import
What happens
Centralize the organization's SOPs, standards, and applicable regulations into dedicated, access-controlled folders. No agent work happens at this stage.
Why it matters
An agent is only as reliable as what it can read. Getting the source material organized and access-controlled first means every later stage builds on a known, bounded set of documents rather than on whatever the agent happens to find.
Stage 2
Foundation
What happens
Define the agent's Instructions, its system prompt or semantic layer, to produce a specialist agent tuned to the organization's actual language rather than a generic assistant.
Why it matters
A QA Specialist agent that already speaks in CAPA, deviation, and batch-review terms needs far less correction later, and its answers are easier for your reviewers to trust and verify against source documents.
Stage 3
Workflows
What happens
Move from general question-and-answer to structured, multi-step workflows: scanning, cross-referencing, pattern detection, validation, and a defined deliverable. Every workflow pairs a Reasoning Chain with Human-in-the-Loop (HITL) review.
Why it matters
A workflow that shows its reasoning and stops for human review at the steps that carry compliance risk is auditable. A workflow that only produces an answer is not.
Stage 4
Automation & Schedule
What happens
Move the agent from reactive, answering only when asked, to proactive: scheduled runs, periodic reports, and trend flags that surface drift before it becomes a deviation.
Why it matters
This is where full coverage actually replaces sampling. The agent runs on a schedule set by risk, not by how many hours a reviewer has left in the week.
Stage 5
Validation: the CSA approach
What happens
Apply FDA's Computer Software Assurance mindset: edge-case testing, Reasoning Chain review, continuous validation as the agent or its inputs change, and a human-versus-agent comparison run in a PQ-style format.
Why it matters
Validation effort that matches the workflow's actual risk, and that keeps being exercised after go-live rather than stopping at the first sign-off, is what lets this stage hold up under audit.
The endpoint across all five stages is not a deployed tool. It is an agent embedded in the daily operational routine, with the evidence in hand to show it stays trustworthy every time it runs.
The Guardrails
Four controls that run through every stage
None of these are optional add-ons applied after the build. They are built into the model from Stage 1 onward.
Human-in-the-Loop (HITL)
Every workflow stops for human review at the steps that carry compliance risk. The agent narrows the field of what a reviewer has to look at. It does not remove the reviewer.
Reasoning Chain & Explainability
Every output carries the reasoning that produced it, not only the conclusion. If an agent flags a pattern, the record shows what it checked and why, so a human reviewer, and later an auditor, can follow the logic.
Zero Training Policy & data control
Client data is never used to train an underlying model. Data stays inside the access-controlled boundaries defined at the Import stage, with retention set by the organization.
ALCOA+ throughout
Every workflow output is designed to be Attributable, Legible, Contemporaneous, Original, and Accurate, plus Complete, Consistent, Enduring, and Available, from Import through scheduled operation.
What AI must never decide unsupervised
Batch or lot disposition. Deviation and CAPA closure. Complaint classification affecting reportability. Release of a validated system for use. Any electronic signature (21 CFR Part 11 Subpart C; Annex 11 §14). The agent may prepare, flag, and draft. A qualified person decides, and the record shows both.
Ready to see where your organization would start on this model?
Book a discovery call. We will map which stage you're actually at today, and what Stage 1 looks like for your own SOPs and systems.
Book a discovery call