Insights

Glossary

Working definitions as I use them on this site. Where a regulation defines the term, the clause is named.

ALCOA+
Attributable, Legible, Contemporaneous, Original, Accurate, plus Complete, Consistent, Enduring, Available. The data integrity principles used by MHRA (2018) and named in the draft Annex 11 revision §2.4.
Audit trail
Metadata that lets you reconstruct who did what, when, and why to a record. Required by 21 CFR 11.10(e) and EU Annex 11 §9; defined in MHRA DI Guidance 2018 §6.13.
Audit trail review
The documented, risk-based check of audit trail data for abnormal activity, with a positive statement of the outcome (MHRA 2018 §6.15). Review by exception uses a validated tool to screen all records and route flags to a human.
CSV (Computerized System Validation)
Documented evidence that a computerized system does what it is intended to do, consistently, throughout its life cycle (EU Annex 11 §4; GAMP 5).
CSA (Computer Software Assurance)
A risk-based approach to assurance that scales testing and documentation to the system's impact on patient safety, product quality and data integrity, using critical thinking, unscripted testing where appropriate, and supplier evidence. Described in FDA guidance and in GAMP 5 second edition.
GAMP 5
ISPE's Good Automated Manufacturing Practice guide, second edition 2022. The reference framework for risk-based CSV/CSA, software categories, and supplier leverage.
GAMP software categories
Category 1 infrastructure, 3 standard product, 4 configured product, 5 custom application. A continuum, not a checklist (GAMP 5 Appendix M4).
Periodic review (periodic evaluation)
A scheduled evaluation that a validated system remains in a validated state, covering changes, incidents, access, audit trail reviews, backup and documentation (EU Annex 11 §11; draft revision §14).
HITL (human in the loop)
A design in which a qualified person decides on an AI system's output at defined control points, and the record shows both the proposal and the decision.
Annex 22
The draft EU GMP annex on artificial intelligence (2025 consultation, not adopted). Covers static, deterministic models in critical GMP applications; excludes generative AI and LLMs from critical use.
Intended use (AI)
The documented statement of what an AI model is for, the input space it must handle including rare variations, and the acceptance criteria it must meet (draft Annex 22 §3, §4).
Foundation model
A large pre-trained model used as a starting point inside an AI sub-system. Requires rigorous testing with or without fine-tuning (ISPE GAMP AI Guide 2025 §2.4.2, §9.7.3.3).
QMSR
The amended 21 CFR Part 820 Quality Management System Regulation, harmonised with ISO 13485:2016, in force for medical devices marketed in the US.
Validated state
The condition in which a system's controls, documentation and configuration still match what was validated. Maintained through change control, periodic review and incident management (EU Annex 11 §10, §11, §13).

Want this applied to your systems?

Book a discovery call. We will map where manual review is costing you the most, and whether CSV/CSA, AI governance, or an AI tool assessment is the right place to start.