Services

Two lanes. One method: assurance commensurate with risk.

Every engagement ends with a capability your team owns and can run without me: a validation approach scaled to risk, a review routine that actually happens, or an AI workflow with a human decision recorded at every compliance-critical step.

Lane A

Data Integrity & Computerized System Assurance

The regulatory core: the work QA and IT need this quarter, delivered by the person who did it for nine years inside a global GxP consultancy.

Data Integrity governance and remediation

Most sites have a data integrity policy and a training slide. Fewer have data-flow maps, criticality classification, or a remediation plan with owners and dates.

Risk

Unreviewed audit trails and uncontrolled spreadsheets are the findings inspectors write first (EU Annex 11 §9; 21 CFR 11.10(e); MHRA GxP Data Integrity Guidance 2018).

  • DI policy and program design
  • system- and process-level DI assessment (access control, audit trail, e-signature, backup, spreadsheets, hybrid records)
  • historical data verification before an inspection or migration
  • risk-prioritized remediation plan and execution
  • audit trail review methodology (review SOP, frequency by risk, reviewer training, exception reporting)
  • continuous DI monitoring inside periodic review

Who it's for: QA managers and data owners who need a DI posture they can show an inspector, not just a policy.

When review by sampling stops being enough, see Lane B: full-coverage audit trail review with a human decision on every flag.

Not sure where you stand? Take the twelve-question self-check.

Computerized System Validation and Assurance (CSV/CSA)

Every system gets the same protocol depth regardless of what it touches. The team runs out of hours before it runs out of systems.

Risk

Under-scoped validation on a high-risk system invites a 483; over-scoped validation on a low-risk one buries the team in paper with no added assurance. EU Annex 11 §1 requires the extent of validation to follow a documented risk assessment.

  • validation strategy and Validation Master Plan (GAMP 5 categories, CSA critical-thinking scope)
  • validation packages (URS, risk assessment, specification review, scripted and unscripted testing, traceability, summary report)
  • system-specific validation for ERP, MES, LIMS, CDS, eQMS, ELN, process control and cloud SaaS
  • data migration verification (Annex 11 §4)
  • 21 CFR Part 11 and Annex 11 per-system assessments with gap closure
  • maintaining the validated state: change control, periodic evaluation, incident handling, archiving (Annex 11 §10, §11, §13, §17)
  • supplier assessment (Annex 11 §3)

Who it's for: QA and validation managers who need a validation posture they can defend, scaled to what each system warrants.

IT infrastructure qualification

The applications are validated; the platform they run on is not. Servers, networks, virtualization, backup and cloud accounts have no qualification record.

Risk

Annex 11 §7 expects data to be secured and backups to be checked and monitored; §16 expects business continuity for critical systems. An unqualified platform undermines every validated application on it.

  • infrastructure qualification (on-premise and cloud)
  • IT process compliance: change, incident, access, backup and restore, disaster recovery procedures mapped to GxP expectations
  • validation impact of OS and platform upgrades
  • technical fixes for data integrity gaps

Who it's for: IT managers who inherited GxP obligations without the qualification framework.

Quality and compliance audits

Supplier questionnaires get filed, not read. Internal audits check the SOP, not the system.

Risk

Annex 11 §3 makes you responsible for your suppliers' competence and reliability, and an inspector will ask for the assessment.

  • internal GxP audits with a systems and data integrity focus
  • supplier and software-vendor audits, on site or remote, with a DI/CSV-specific checklist
  • due-diligence IT and GxP audits for acquisitions, CMO and CRO selection
  • mock inspection on CSV and DI scope with a readiness plan

Who it's for: QA leaders who need an auditor who reads the audit trail, not only the certificate.

Training

Data integrity training is an annual slide deck. Reviewers are never taught how to read an audit trail.

Risk

Annex 11 §2 expects personnel to have the qualifications for their assigned duties. Untrained reviewers produce reviews that do not hold up.

Formats: classroom, remote, on the job, tailor-made.

  • Data Integrity and ALCOA+ for operators and reviewers
  • audit trail review for QA
  • CSV/CSA fundamentals
  • 21 CFR Part 11 and Annex 11 for IT
  • GAMP 5 risk-based approach
  • AI in GxP quality: what it may do, what it may never decide, how to review it

Who it's for: QA, IT and operations teams, and the managers who sign their training records.

Medical-device quality systems

Secondary Capability

Alongside the lane above, I assist medical-device companies with quality system compliance under 21 CFR Part 820, now the Quality Management System Regulation harmonised with ISO 13485:2016, including CAPA and complaint handling, software validation, and mock inspections. Same data integrity and validation discipline, applied to a device QMS.

Lane B

AI in GxP Quality

The frontier: no Israeli consultancy positions on it yet, and the regulatory direction is already visible.

AI governance framework

Pharma and biotech QA teams are adopting AI tools faster than they are building the governance to control them. Most organizations have no documented framework for how an AI system gets approved, monitored, or retired inside a GxP environment.

Risk

Without a governance framework, every AI deployment becomes a one-off decision made under pressure, with no consistent record of how risk was assessed or how a human stayed accountable for the output. That is exactly the gap an inspector or an internal audit will find first.

  • governance policy and SOP set
  • intended-use and risk classification per tool
  • acceptance criteria for AI output
  • human-review points at compliance-critical steps
  • retirement and change rules
  • alignment with the ISPE GAMP AI Guide (2025), the draft EU Annex 22 (labeled draft), and the EU AI Act where it applies

AI Tool Assessment

Vendors pitch AI tools with confidence that outpaces the evidence. QA and IT are left evaluating a tool's fit, security, and validation readiness with whatever the vendor's sales deck happens to disclose.

A decision made on a sales deck alone does not hold up when an auditor asks how you chose the tool, or when the vendor cannot produce what your validation process needs. By the time that gap surfaces, the tool is already in production.

I run a structured evaluation before and during adoption, covering business fit, data and security posture, vendor maturity, and validation readiness. The outcome is a documented, auditor-defensible decision, whether the answer is to adopt the tool, adopt it with conditions, or walk away.

Fixed-scope engagement. Price published once the scope sheet is final.

Who it's for: QA managers and IT/validation managers who need to put a vendor claim through a process before it becomes a production dependency.

AI implementation on the 5-Stage Automation Model

A pilot that never leaves the sandbox proves nothing to an inspector.

Risk

An AI step in a GxP process with no validation record is a computerized system without validation. Annex 11 §4 applies; Annex 22 (draft) shows where the expectations are heading.

  • Import, Foundation, Workflows, Automation and Schedule, Validation (CSA approach)
  • Reasoning Chain review
  • human-versus-agent comparison
  • continuous validation plan

Who it's for: QA teams ready to move one routine review from sampling to full coverage.

Read the 5-Stage Automation Model →

How We Work Together

Three ways to start

Neither path requires you to commit to a large program before you know it is the right one.

Discovery Engagement

The entry point for most clients. We map where manual review is costing your team the most time, and work out together whether CSV/CSA, AI governance, or an AI tool assessment is the right place to start, before either of us commits to anything larger.

Book a discovery call

Win-Win Pilot

An asymmetric-investment pilot for clients ready to move past discovery. You invest in the software licensing. I invest the architecture design, prompt engineering, SOP integration, and validation work needed to get the result into real, auditable use. If the pilot does not hold up under validation, you have not overpaid for something that does not work.

Data Integrity health check

A bounded review of one system's data integrity controls: audit trail, access and roles, electronic signatures, backup and restore, periodic evaluation status. Two weeks, one report, a risk-ranked gap list you own. Quote on request.

Request a health check

Not sure which service fits where you are today?

Book a discovery call. We will look at where manual review is costing you the most time, and whether CSV/CSA, AI governance, or an AI tool assessment is the right place to start.