← Blog

GxP AI Compliance Checklist for Regulated Computerised Systems

Parminder Singh
Parminder Singh··8 min read
Summarize with AI

This GxP AI compliance checklist turns FDA 21 CFR Part 11 and EU GMP Annex 11 into eight gradable checks for scope, intended use, suppliers, validation, access, audit trails, change control, retention, and routed LLM traffic. Every check names an action, owner, pass condition, evidence artifact, and remediation trigger while preserving the regulated organization''s validation responsibility.

Industry Verticalsai-complianceai-governanceauditcomplianceregulationpolicy-enforcement
GxP AI Compliance Checklist for Regulated Computerised Systems

A release packet identifies assistant-prod while its approved protocol names model endpoint gpt-6.2-2026-07-18. The change record contains no impact assessment. That packet fails this GxP AI compliance checklist before a reviewer reaches the performance plots. I want every check to end in pass or remediate. A documented out-of-scope result is also valid. The owner and evidence link should fit on one screen. The test date and open action belong there too. A green status without those four fields is decoration.

TL;DR

  • Determine Part 11 and Annex 11 scope for each AI use before assigning controls.
  • Give every check an action and owner. Add a pass condition and evidence location, then record the remediation state.
  • Exercise validation and access. Test audit trails and changes, then verify restoration and historical retrieval with selected records.
  • Credit a gateway only for authenticated HTTP LLM requests deliberately routed through it.

Check 1: document the regulatory scope

Action: classify each AI-enabled workflow by regulated activity and intended use. Record its record type and site. Define the system boundary and accountable quality owner.

Owner: regulatory affairs and the quality unit, with the process owner supplying the workflow facts.

Pass condition: the scope memo identifies the FDA predicate record requirement before applying 21 CFR Part 11. The rule's scope provision covers electronic records created or modified under FDA record requirements. It also covers records maintained, archived, retrieved, or transmitted under those requirements, plus covered electronic submissions. For EU operations, the memo identifies the GMP activity. It explains the applicability of EU GMP Annex 11, which covers computerised systems used as part of GMP-regulated activities.

Evidence: approved applicability memo and system inventory entry. Include the data-flow diagram and predicate-rule reference. Add the Annex 11 rationale, approver, and date.

Remediate when: uses AI is the entire scope rationale. Also remediate when every model output is treated as a Part 11 record without examining the underlying record requirement.

Check 2: approve intended use, requirements, and risk

Action: connect the AI function to an approved intended-use statement and user requirements. Document its GxP impact and risk assessment.

Owner: the process owner and system owner, with quality approving the risk-based control strategy.

Pass condition: each requirement traces to a patient-safety or product-quality risk. A data-integrity risk must also trace to an acceptance criterion. Annex 11's risk-management and user-requirements provisions call for lifecycle risk management. They also require traceable requirements based on documented risk and GMP impact. The file names prohibited uses. A deviation-summary assistant, for example, may draft text while the qualified reviewer retains investigation and disposition authority.

Evidence: intended-use statement and user requirements specification. Include the risk assessment and control rationale. Add the prohibited-use register and trace matrix. The AI data lineage audit guide supplies the release and source identifiers needed for that trace.

Remediate when: the protocol tests a generic chatbot while production uses a retrieval layer or system prompt. The endpoint or response workflow must also appear in the approved requirements.

Check 3: assess suppliers and service arrangements

Action: assess each hosted model and retrieval service according to its GxP impact. Apply the same assessment to each integration vendor and infrastructure provider.

Owner: supplier quality works with the system owner. Procurement and security contribute their reviews, while records management covers record obligations.

Pass condition: Annex 11 section 3 responsibilities appear in a formal agreement. The assessment covers supplier competence and reliability. It addresses change notices and support. Remote access and data processing are documented, along with retention and inspection support. Commercial documentation is checked against the regulated user's requirements. The file records gaps and compensating controls rather than converting a supplier certificate into user validation.

Evidence: approved supplier assessment and risk tier. Include the agreement and security review. Keep the quality documentation and audit decision. The service inventory, exit plan, and named evidence contacts complete the file.

Remediate when: a procurement page says enterprise plan approved while model-version changes remain unassigned. Evidence access and data-location responsibilities must also be assigned.

Check 4: validate the configured use and apply CSA carefully

Action: validate the released configuration against intended performance. Use a risk-based protocol with controlled acceptance criteria.

Owner: validation and quality, supported by the process owner and technical leads.

Pass condition: Part 11's closed-system validation provision addresses accuracy and reliability. It also addresses consistent intended performance and detection of invalid or altered records. Annex 11's validation section adds lifecycle documentation and deviations. It covers change records and test scenarios. Parameter and data limits must be tested, with error handling documented. Automated test tools also require assessment. For software used in medical-device production or a quality management system, FDA's February 2026 final Computer Software Assurance guidance recommends a risk-based approach to establish confidence in automation and identify where added rigor fits. That guidance has a specific device-production and QMS scope.

Evidence: approved protocol and scripted test records. Include unscripted test records and actual results. Keep the deviations and acceptance decision with the released configuration and tester credentials.

Remediate when: a vendor benchmark replaces testing of the configured workflow or the evidence shows only successful cases.

Check 5: test access, authority, and signatures

Action: exercise access and authority controls with authorized and unauthorized accounts. Repeat the tests with expired and changed-role accounts.

Owner: IAM and the system owner handle access. Records and quality own electronic-signature use.

Pass condition: Part 11's closed-system access and authority provisions restrict access and regulated operations to authorized individuals. Its signature-manifestation provision includes the signer's printed name and execution date and time. It also records the meaning of the signature. The signature-linking provision binds the signature to its record. Annex 11's security section expects records for authorization creation and change. Cancellation records are also required. Relevant data actions identify the operator and record the date and time.

Evidence: role matrix and account lifecycle records. Keep the executed negative-access tests and signature test. Include the signature-to-record linkage result and periodic access review.

Remediate when: the LLM route receives only a shared service identity and the application supplies no stable user or agent context for the regulated action.

Check 6: operate and review the audit trail

Action: generate a controlled record change and preserve the prior value. Review the trail. Retrieve it with the subject record.

Owner: the system owner operates the mechanism. Quality or a designated process reviewer performs the risk-based review. Records management controls retention.

Pass condition: Part 11's closed-system audit-trail provision calls for secure, computer-generated, time-stamped trails for operator actions that create or modify electronic records. Deletions must also appear. Earlier information remains visible, and trail documentation follows the subject record's retention period. Annex 11's audit-trail section takes a risk-based approach to GMP-relevant changes and deletions. It requires documented reasons and intelligible output. Availability must be maintained, followed by regular review.

Evidence: original and changed test records. Include the audit-trail export and reason-for-change field. Keep the review sign-off and exception record with the permissions and integrity result. The tamper-evident AI audit log guide describes integrity evidence for the narrower request-event record.

Remediate when: the review samples only approved events. Also remediate if the original value disappears or an administrator can alter the final trail without detection.

Check 7: control changes, incidents, continuity, and retention

Action: trace one configuration change and one incident through assessment and approval. Follow deployment and investigation. Continue through corrective action and periodic evaluation, then closure. Restore and retrieve an older record.

Owner: change control and the system owner coordinate the technical work. Quality owns incident disposition and corrective action. Records management and business continuity own restoration and retrieval procedures.

Pass condition: Annex 11 connects controlled configuration changes with periodic evaluation. Incident assessment is part of that control. Its data-storage and continuity provisions address backup restoration and continuity arrangements. The archiving provisions address archive retrieval. Part 11's closed-system copy and record-protection provisions require accurate and complete copies. Protected records must remain available through the required retention period.

Evidence: change request and impact assessment. Keep the test result and approval with the deployment record. Include the incident investigation and corrective-action record. Add the periodic review and restoration result. Finish with the timed archive retrieval. Use the LLM audit log retention guide to separate a configured duration from successful recovery.

Remediate when: the archive policy names seven years but the September 2026 retrieval test returns an unreadable payload or loses its audit trail.

Check 8: document the routed HTTP evidence boundary

Action: map every regulated application route that sends authenticated HTTP requests to an LLM. Test permit and redact cases. Exercise deny and missing-context cases, followed by response-policy and retrieval cases.

Owner: enterprise architecture and security engineering own the policy point. The application owner supplies identity and approved workflow context. Quality and records owners decide how the resulting event joins the regulated package.

Pass condition: the event records the calling application and supplied principal and purpose. It includes content classification and the provider and endpoint. The policy version and decision are recorded. Add the timestamp and response disposition, followed by the correlation identifier. The route inventory names bypasses. Direct browser use and embedded or local inference have separate owners and controls. So do opaque vendor-managed calls, stolen credentials, and applications that bypass the route.

Evidence: route diagram and egress rule. Include the identity schema and versioned policy. Keep the staged events and protected population export. Add the integrity check and exception register, then the retrieval result.

Remediate when: a clean gateway event is presented as validation of the GxP system. Its proper name is routed request decision evidence, covering one authenticated HTTP decision at one policy point.

DeepInspect

DeepInspect sits on authenticated HTTP requests that a regulated application deliberately routes to an LLM. It evaluates application-supplied identity and workflow context. It applies versioned content and destination policy, inspects the response, and writes a signed, tamper-evident decision event.

That event can close the bounded request-route checks and join a wider GxP package as routed request decision evidence. It cannot validate the regulated system or establish Part 11 and Annex 11 scope. Quality and process owners retain those decisions. Validation and regulatory owners retain theirs. Supplier, IAM, and records owners do the same. Book a technical deep dive at deepinspect.ai.

Frequently asked questions

Does Part 11 apply to every AI output?

Part 11 scope follows electronic records required by FDA predicate rules and covered electronic submissions. Record the relevant requirement and the firm's reliance on the electronic record for each use. An inventory entry can trigger review; regulatory affairs and quality make the documented scope decision.

Does FDA's Computer Software Assurance guidance cover every GxP AI system?

The February 2026 final guidance addresses computer software assurance for automation used in medical-device production or a quality management system. It supports risk-based assurance in that scope. Drug manufacturing and clinical uses still require analysis under their applicable requirements and guidance. The same applies to laboratory and other GxP uses.

Can supplier testing replace regulated-user validation?

Supplier evidence can support risk assessment and testing. Annex 11 keeps requirements and supplier assessment within the regulated user's control framework. The same framework retains the validation strategy and acceptance. Continued valid state also remains there. The configured use and its GxP process need evidence tied to the approved intended use.

What happens after a failed check?

Retain the result. Assign a remediation owner and interim measure. Set a target date and retest. The new evidence should link back to the original failure. Deleting a red row removes operating history at the moment the quality unit needs it.

Can a gateway complete this checklist?

A gateway can satisfy defined tests for authenticated HTTP LLM traffic that traverses it. Intended use and system validation remain with qualified organizational owners. Supplier qualification and electronic signatures do too. Those owners also retain audit-trail review and incident handling. Corrective action and retention decisions stay with them, along with product disposition.