← Blog

GxP AI Audit Evidence for Regulated Computerised Systems

Parminder Singh
Parminder Singh··7 min read
Summarize with AI

GxP AI audit evidence should connect a regulated use and approved requirements to risk, validation, change control, access, operation, incidents, audit trails, retention, and historical retrieval. This guide separates FDA 21 CFR Part 11 scope from EU GMP Annex 11 expectations and limits an HTTP gateway to routed request decision evidence, never validation of the regulated system.

Industry Verticalsai-complianceai-governanceauditcomplianceregulationforensic-audit
GxP AI Audit Evidence for Regulated Computerised Systems

An investigator opens deviation DEV-2041 after an AI assistant summarized a laboratory exception. The approved protocol names model release 6.2, while the provider route resolved to 6.3 on the event date. GxP AI audit evidence has to explain that difference through controlled records and tests. It also has to show the disposition. A green gateway event can prove which routed request was permitted. It cannot validate the laboratory system or establish intended use. It also cannot decide product impact. That boundary belongs on page one of the package.

TL;DR

  • Start with regulatory scope and intended use, then freeze the system and release populations along with the change and incident populations.
  • Trace reviewer-selected samples through requirements and risk, then validation and approval. Continue through operation and deviation before documenting disposition.
  • Test audit-trail integrity and access. Test backup restoration, archive retrieval, and provider-version resolution.
  • Use gateway events only as evidence for routed HTTP decisions; qualified GxP owners retain system validation and quality decisions.

Establish the legal scope before collecting logs

GxP is an umbrella term, so the evidence index should name the governing regime and regulated activity. It should also name the predicate record requirement and site, along with the process and accountable quality owner. FDA's current 21 CFR Part 11 applies to electronic records created or modified under FDA record requirements. It also applies when those records are maintained, archived, retrieved, or transmitted, plus covered electronic submissions. The predicate rule and the firm's decision to rely on an electronic record matter to scope.

EU GMP Annex 11 on computerised systems applies to computerised systems used as part of GMP-regulated activities. Its principle says the application should be validated and IT infrastructure qualified. It also calls for lifecycle risk management based on patient safety and data integrity, with product quality included.

Put the applicability rationale and source version on the index. Counsel and the quality unit own that determination. A platform inventory can identify candidate systems; it cannot declare a record subject to Part 11 or a function GMP-critical.

Freeze the evidence populations

Build separate populations for systems and approved configurations. Do the same for changes and routed AI events, along with deviations and incidents. Keep periodic reviews separate. Include retired versions and failed tests. Include denied requests and missing-identity events, plus route errors. For hosted models, preserve the provider and endpoint. Preserve the resolved model identifier and region where relevant. Keep the system prompt or template version, retrieval source version, and activation window.

Annex 11 section 4 calls for an up-to-date system inventory and, for critical systems, a description covering physical and logical arrangements. The description should also cover data flows and interfaces, along with prerequisites and security. User requirements should be based on documented risk and remain traceable through the lifecycle. Use those elements to build the reviewer manifest rather than treating the event log as the population.

Freeze each manifest before sample selection. Internal audit or the quality unit can then select a production configuration and one change, plus one incident and one historical record. The AI data lineage audit guide provides a join pattern for source and release identifiers.

Trace a selected configuration through validation

For one production configuration, start with intended use and GxP impact. Link approved user requirements to the risk assessment and specifications. Add the supplier assessment and test plan. Connect the executed evidence and deviations to the acceptance decision and release approval, then the deployed configuration. Annex 11 sections 4.1 and 4.2 expect validation documentation to cover relevant lifecycle steps and include applicable change-control records plus reported validation deviations. Section 4.7 addresses test methods and scenarios. It also addresses limits and error handling, along with assessment of automated testing tools.

Part 11 section 11.10(a) requires validation of closed systems for accuracy and reliability, along with consistent intended performance and the ability to discern invalid or altered records. The regulated company defines the intended performance and validation strategy under its quality system. For a hosted LLM dependency, supplier evidence may inform that work. The regulated user still owns fitness for the intended use.

My preference is a one-page trace cover with live controlled links. Copying files into an inspection folder creates stale twins and muddies custody.

Test data integrity and audit-trail operation

Part 11 section 11.10 requires accurate and complete copies plus protected records available throughout retention. It also requires authorized access and secure computer-generated time-stamped audit trails for operator actions that create or modify records, as well as actions that delete records. Changes must preserve previously recorded information. The audit-trail documentation follows the subject record's retention period and remains available for FDA review and copying.

Annex 11 section 9 takes a risk-based approach to system-generated audit trails for GMP-relevant changes and deletions. Reasons for changes or deletion should be documented, with audit trails available and intelligible. They should also be regularly reviewed. Section 12 requires controls restricting access and records of authorization creation and change, plus cancellation. It also expects operator identity plus date and time for data entry and change, as well as confirmation or deletion.

Test those mechanisms. Alter a staged record and verify the original remains reconstructable. Attempt deletion with an application administrator role and retain the result. Review one audit trail for unexplained changes. The tamper-evident audit log guide describes a separate request-event write path, which can support this test only for records it actually creates.

Reconstruct change, incident, and quality disposition

Select one provider or application change. Trace the request and impact assessment, then the risk assessment and validation plan. Connect the executed tests and deviations to approval and deployment. Preserve the rollback target and post-change monitoring. Annex 11 section 10 calls for controlled changes to systems and configurations under a defined procedure. Section 11 calls for periodic evaluation of valid state and GMP compliance, considering functionality and deviations. It also considers incidents and problems, along with upgrade history and performance. The evaluation covers reliability and security, plus validation status where appropriate.

Then select an incident. Annex 11 section 13 says all incidents should be reported and assessed, with root cause for critical incidents feeding corrective and preventive action. The package should join the event to the affected process and records. It should connect those items to the investigation and product-impact assessment, then the quality disposition and corrective action. Add the effectiveness check and closure.

A routed LLM record may identify the endpoint and policy. It may also identify the classification and supplied principal, along with response handling. It supplies one fact pattern for the investigation. Qualified quality and process owners decide deviation severity and product impact. They also decide root cause and corrective action, plus batch disposition.

Prove backup, archive, and inspection retrieval

Annex 11 section 7 calls for secured data and accessibility. It also calls for readability and accuracy, along with regular backups and tested restoration. Section 17 adds archive checks for accessibility and readability, plus integrity, with retrieval tested after relevant system changes. Part 11 section 11.10(b) requires accurate and complete human-readable and electronic copies suitable for FDA inspection and review, as well as copying.

Choose an old, reviewer-selected record. Retrieve it with its audit trail and signature linkage where applicable. Include its validation state and configuration, plus the related incident or change. Restore an archived package or backup in a controlled environment. Compare record counts and integrity results, document elapsed time, and preserve the executed procedure.

The physical detail matters here: an inspector with a silver USB drive and a five-year-old sample identifier should receive a readable export plus its audit trail, without a developer rebuilding the record by hand. The audit log chain of custody guide covers the custody and transfer questions for evidence exports.

State the HTTP gateway boundary

A request gateway covers authenticated HTTP calls deliberately routed through it to an LLM. It can evaluate application-supplied identity and workflow context. It can also evaluate content classification and destination, plus policy version. It can retain the decision and timestamp. It can also retain the model endpoint and response treatment. Those fields can join a larger GxP evidence package.

The gateway leaves several controls elsewhere. IAM owns identity proofing and role lifecycle. The application and quality teams own correct context and intended use. They also own requirements and risk, plus validation. Supplier management owns qualification and agreements. Records owners define retention and signatures. Quality owns deviations and audit-trail review. It also owns periodic evaluation and CAPA, plus product disposition. Embedded inference and direct browser sessions need separate evidence, as does provider activity hidden behind a SaaS interface.

Call the gateway record routed request decision evidence. Calling it proof that the regulated system is validated would be indefensible. It shows what crossed one policy point at one moment. The validation package establishes fitness for intended use across the governed system.

DeepInspect

DeepInspect sits on authenticated HTTP traffic that a regulated application routes to an LLM endpoint. It evaluates the identity and workflow context supplied by that application. It applies content and destination policy, inspects the response, and writes a signed, tamper-evident decision record.

That record can join the GxP package as routed request decision evidence. DeepInspect does not validate the regulated system. Quality and process owners retain their defined responsibilities. The same applies to regulatory and records owners, along with IAM and supplier owners. Traffic outside the routed boundary needs separate controls. Book a technical deep dive at deepinspect.ai.

Frequently asked questions

Does 21 CFR Part 11 apply to every AI output?

Part 11 scope depends on electronic records under FDA record requirements and covered submissions. The applicable predicate rule and the regulated firm's record design matter. Quality and regulatory counsel should document the determination for each use.

Does Annex 11 require every audit trail feature for every system?

Annex 11 frames audit-trail consideration through documented risk and GMP relevance. The assessment should identify which changes and deletions matter, then define creation and review controls, plus retention and testing controls. Preserve that rationale with the system record.

Can supplier validation replace user validation?

Supplier documentation can support the regulated user's assessment. Annex 11 places supplier assessment and lifecycle evidence inside the user's control framework. The regulated organization still justifies requirements and risk. It also justifies intended use and acceptance, plus continued valid state.

What belongs in a routed AI event?

Record the calling application and supplied principal. Add the purpose and provider, then the resolved endpoint and classification. Record the policy version and decision. Add the timestamp and response disposition, plus the correlation identifier. Store sensitive content according to approved minimization and access rules.

Can a gateway validate a GxP system?

It can supply controlled evidence about routed HTTP requests and decisions. System validation requires approved requirements and risk assessment. It also requires testing and deviations, along with acceptance and release. Add change control and continued-state evidence under the regulated organization's quality system.