AI Vendor Risk in Clinical Research Starts With the Trial Data Flow
FDA guidance expects sponsors to document electronic systems, data flows, access controls, contracts, audit trails, and service-provider responsibilities across a clinical investigation. An AI vendor that receives protocol text or participant records becomes part of that evidence chain. This article maps vendor review onto each authenticated model request.

A clinical operations agent sends an adverse-event narrative to a model endpoint as an HTTPS request. In that instant, the provider joins the trial data flow. The request may carry a participant identifier, the event chronology, investigator notes and the protocol arm. FDA's guidance on electronic systems in clinical investigations tells sponsors to document systems used to create, maintain or transmit pertinent records and to keep a diagram showing data movement through final storage. AI vendor risk clinical research therefore begins with the actual request path, rather than the questionnaire completed during procurement.
I want to work through the FDA record expectations, the evidence a sponsor needs from an AI service, and the control point that keeps a validated workflow from becoming an undocumented side channel.
TL;DR
- FDA guidance expects a sponsor to document electronic systems used for trial records and draw the data flow through final storage.
- Part 11 calls for authorized access, protected records and secure time-stamped audit trails that preserve earlier information.
- Vendor diligence must cover the deployed configuration, interfaces and changes that can affect participant safety or trial reliability.
- A per-request record ties the authenticated user, trial context, data classification, model destination and policy decision together.
The model endpoint becomes part of the trial data flow
The FDA guidance covers electronic systems that create, modify, maintain, archive, retrieve or transmit clinical investigation records. It names randomization, adverse-event processing, informed consent and product accountability among the activities that sponsors may run through their own systems or an IT service provider's system.
A general-purpose model can enter the same flow without appearing in the clinical systems inventory. A monitor asks it to condense a site note, while an agent retrieves four paragraphs from the electronic trial master file and requests a summary. The blue data-flow arrow on the validation diagram still ends at the clinical platform, while the live request continues to a model provider.
That missing arrow is a vendor-risk finding. FDA says documentation should include the systems used for pertinent electronic records and a diagram depicting data flow through final storage. The sponsor needs enough detail to place each model endpoint, interface and retained copy on that diagram. Shadow AI in clinical research covers the discovery problem. Vendor risk starts after discovery, when the sponsor decides which route may remain open.
Part 11 sets the evidence standard
21 CFR Part 11 applies to electronic records created, modified, maintained, archived, retrieved or transmitted under FDA record requirements. Its closed-system provisions require controls for authenticity and integrity, accurate and complete copies, record protection through the retention period and access limited to authorized individuals.
The audit-trail provision adds secure, computer-generated, time-stamped records of actions that create, modify or delete electronic records. Earlier information must remain visible, and the audit trail stays available for FDA review for at least as long as the underlying record.
A model provider's usage dashboard answers a narrower question. It may show a workspace, token volume and destination model. The sponsor's evidence question starts with a named trial action: who sent this participant record, under which role, using which approved route, and what happened to the request. A Part 11 assessment belongs with counsel and quality leadership. The architecture still has to produce evidence at that resolution.
Vendor review follows the deployed configuration
FDA recommends risk-based validation based on intended use, the importance of the data and the potential effect on participant welfare or trial reliability. The same guidance says validation should cover trial-specific configurations, customizations, data transfers and interfaces. When an IT service provider performs validation, the sponsor may review its development process, functional testing, change controls and tracking logs.
That makes a generic assurance report an input rather than the decision. The review has to reach the exact model route the study uses. It should identify the provider endpoint and approved model versions, retention settings and administrative access, data residency, change-notification terms, export capability for records, and the contract language assigning responsibilities. FDA inspectors may request validation documentation held by the service provider, and the guidance specifically points to contracts that detail functions and responsibilities.
My opinion is that a vendor questionnaire without a request inventory is theatre. A green spreadsheet cell beside "audit logging" says nothing about the protocol excerpt visible in a coordinator's browser tab at 4:40 p.m.
Continuous oversight depends on request evidence
The initial review establishes approved conditions. Live evidence shows that people and agents stayed inside them.
For each model call, the useful record includes the authenticated person or agent, study and site context, application, endpoint and model version, classification of the request body, policy version, decision, timestamp, and integrity reference for the request and response. The study identifier matters because quality teams investigate by protocol and site. An employee-only index turns a focused trial inquiry into a broad log search.
Changes need the same documented treatment across the system life cycle. FDA guidance calls for evaluation of software upgrades, security patches and other changes that could affect traceability or integrity. A model alias that silently advances to a new version is a configuration change in the live data path. The control plane should either bind an approved version or record the resolved version so the sponsor can assess it.
This is the operational distinction behind AI vendor risk management. Procurement establishes the formal relationship. Per-request evidence supervises its use.
The enforceable route sits before the provider
A policy document can name approved providers and prohibited data. Enforcement requires the decision to happen while the HTTP request is still inside the sponsor's control.
An identity-aware policy can allow a biostatistics agent to send de-identified aggregate text to one endpoint and block a coordinator from sending direct participant identifiers to the same provider. It can route a permitted workload to a study-specific deployment, attach the protocol identifier to the decision record and refuse an unapproved model version. Redaction can remove a direct identifier before transmission when the study's approved procedure permits that treatment. PII redaction in LLM traffic explains that request-path mechanism.
Coverage is the hard requirement. Browser chat, application integrations and agents all need to traverse the same authenticated HTTP boundary. A second route around the policy point recreates the missing arrow on the data-flow diagram and leaves quality staff reconstructing events from interviews.
DeepInspect
DeepInspect sits between authenticated users or agents and LLM endpoints as a stateless proxy. It evaluates identity, study context, request classification, provider route and model version before the HTTP request leaves the sponsor's control. Policies can block, redact or route the request, including a route to an internally hosted model for restricted trial data.
Each decision creates a signed audit record with the caller, application, trial context, classification, destination, policy version, outcome and timestamp. That record supports the system inventory, vendor oversight and inspection evidence described above. DeepInspect covers authenticated HTTP AI traffic. Protocol design, clinical validation, vendor contracting and Part 11 scope determinations remain with the sponsor's quality, legal and clinical teams.
Book a demo today.
Frequently asked questions
- Does every model request create a Part 11 record?
Scope depends on the request, the system's intended use and the records the sponsor is required to maintain. A request that creates, modifies, maintains or transmits a pertinent electronic record deserves direct review under the sponsor's Part 11 assessment. A request for generic drafting help using public material presents a different risk. Classification at the request boundary gives the sponsor evidence for that scoping decision instead of treating every model interaction alike.
- Is a provider's SOC 2 report enough for FDA vendor review?
A SOC 2 report can support diligence about the provider's control environment. FDA guidance asks the sponsor to consider the deployed system's intended use, trial-specific configuration, interfaces, data transfers, access controls, validation evidence and contractual responsibilities. Those facts sit partly with the provider and partly in the sponsor's own integration. The sponsor needs both views.
- Which physical artifact should the quality team maintain?
Maintain the system inventory and the data-flow diagram named in FDA guidance, with each approved model endpoint drawn through final storage. Beside it, keep the approved use, model version policy, validation evidence, owner, contract reference and audit-record location. That one-page diagram gives an inspector a concrete route into the supporting files.
- Can de-identification remove the vendor from the review?
De-identification reduces data risk and may change privacy obligations. The model route can still affect a regulated workflow, produce trial content or introduce changes that bear on trial reliability. The sponsor's intended-use and validation analysis remains necessary, with a scope proportionate to the actual function.