← Blog

GxP AI Controls Mapping for Regulated Computerised Systems

Parminder Singh
Parminder Singh··9 min read
Summarize with AI

This GxP AI controls mapping connects FDA 21 CFR Part 11 and EU GMP Annex 11 requirements to a control point, accountable owner, repeatable test, retained evidence, explicit gap, and retest state. It separates regulated-system validation and quality decisions from the narrower routed request decision evidence an authenticated HTTP LLM gateway can produce.

Industry Verticalsai-complianceai-governanceauditcomplianceregulationarchitecture
GxP AI Controls Mapping for Regulated Computerised Systems

A cell containing validated by vendor collapses six separate controls into three words. Useful GxP AI controls mapping starts with the governing requirement, then points to the place where a decision happens. The row names its owner and test, retained artifact and open gap, plus the retest date. I would rather show a red cell beside model alias latest than let a green dashboard hide an unresolved production version. This map keeps that red cell visible and limits request-gateway credit to evidence it can actually produce.

TL;DR

  • Map each requirement to a control point and accountable owner, then record the test and evidence artifact, gap, and retest state.
  • Keep Part 11 scope tied to FDA predicate records, with Annex 11 scope tied to GMP-regulated activities.
  • Separate validation and supplier decisions from quality and record decisions instead of assigning them to one platform.
  • Treat gateway events as routed request decision evidence for authenticated HTTP LLM traffic only.

Build the map around source and scope

The source column needs the exact regime and provision, version and legal status, plus the applicability rationale. The scope provision in 21 CFR Part 11 covers electronic records under FDA record requirements and covered electronic submissions. A Part 11 row therefore starts with the predicate record and the decision to rely on the electronic record. AI output alone supplies no scope conclusion.

EU GMP Annex 11 applies to computerised systems used in GMP-regulated activities. It frames validation and data-integrity controls through justified and documented risk, considering patient safety and data integrity alongside product quality. Record the site and process, system and intended use, GxP impact and owner, plus the effective source version before grading coverage.

Use one status vocabulary across the sheet: designed and implemented, tested and gap open, remediation active and retest passed. Green should mean a named test passed for a defined scope and period.

Scope, intended use, and requirements

Requirement and objective: Part 11's scope provision sets the electronic-record boundary. Annex 11 connects risk management with the system inventory and GMP functionality, plus user requirements and lifecycle traceability. The objective is an approved use with a reproducible scope decision and testable requirements.

Control point: AI intake and system inventory approval, followed by user-requirements approval.

Owner: regulatory affairs and quality own applicability. The process owner defines intended use; the system owner maintains the controlled inventory entry.

Test and evidence: select one production AI function. Trace its regulated activity and predicate record, then its intended and prohibited uses, GxP impact and requirements, plus its risk assessment and approvers. Retain the scope memo and inventory row, system description and data-flow diagram, plus the requirements specification and trace matrix. The AI data lineage audit guide provides identifiers for model and prompt, retrieval source and release.

Gap and retest: flag missing predicate-rule references and generic chatbot requirements, plus unlisted interfaces and production endpoints absent from the approved system description. Retest after the controlled documents and route inventory agree.

Validation and computer software assurance

Requirement and objective: Part 11's closed-system validation provision requires accuracy and reliability, consistent intended performance and detection of invalid or altered records. Annex 11's validation section expects lifecycle records and justified methods, acceptance criteria and deviations, change records and error handling, plus assessed test tools and environments. The objective is evidence that the configured use performs as approved under the conditions that matter to the GxP process.

Control point: protocol approval and the release gate.

Owner: validation and quality approve the conclusion. Process and engineering owners, alongside data and model owners, supply qualified evidence within their assigned work.

Test and evidence: run declared normal and boundary scenarios, plus error and misuse scenarios, against the release candidate. Include data limits and unavailable dependencies, altered records and retrieval failures, plus human-review steps. Retain requirements coverage and protocol, actual results and deviations, tester identity and acceptance decision, plus the configuration manifest and release approval.

FDA's February 2026 final Computer Software Assurance guidance recommends a risk-based approach for automation used in medical-device production or a quality management system. Apply that guidance inside its stated scope; keep other GxP systems tied to their own governing sources.

Gap and retest: a provider benchmark or model card, alongside a supplier test, can support the row. Each leaves the configured regulated use untested. Retest after the protocol covers the deployed model endpoint and prompt, retrieval versions and workflow, failure handling and approved acceptance criteria.

Supplier and service-provider control

Requirement and objective: Annex 11 section 3 calls for formal agreements with third parties that clearly state responsibilities. It also addresses supplier competence and reliability, risk-based audit need and review of commercial documentation against user requirements, plus inspector access to relevant quality and audit information. The objective is controlled dependency evidence and clear accountability through operation and exit.

Control point: supplier and contract approval, followed by service-change intake.

Owner: supplier quality owns qualification. Procurement owns contract custody, security assesses technical exposure, and the system owner evaluates changes against the approved use.

Test and evidence: choose one hosted-model provider and retrieve the assessment and responsibility matrix, support and incident terms, change-notice process and data-handling terms, plus quality information and the exit plan. Send a simulated version-change notice through intake and verify impact assessment reaches change control.

Gap and retest: mark the row partial when an agreement omits model-version notice and subcontractors, remote access and evidence availability, or record return. Retest by replaying the notice and retrieving the revised agreement plus assessment.

Access, authority, and electronic signatures

Requirement and objective: Part 11's closed-system controls cover authorized access and authority checks. Its signature provisions address manifestations and permanent signature-to-record linkage. Annex 11's security section adds risk-based controls and authorization lifecycle records, plus operator identity with date and time for relevant data actions. The objective is attributable operation and controlled approval.

Control point: IAM provisioning and application authorization, plus signature execution and periodic access review.

Owner: IAM manages identity lifecycle. The application owner enforces approved roles. Quality and records owners define which actions require signatures and what each signature means.

Test and evidence: attempt the same regulated action with an authorized operator and an expired role, then with a shared relay identity. Execute a test signature and export its printed name and timestamp, plus its meaning and linked record. Retain provisioning and deprovisioning records, the role matrix and access-test results, plus the signature output, linkage result, and review sign-off.

Gap and retest: a gateway can evaluate only the identity and context supplied to it. Flag shared credentials and missing user context, plus orphan accounts and signatures detached during export. Retest after the identity path and record linkage are corrected.

Audit trail and record integrity

Requirement and objective: Part 11's closed-system audit-trail provision calls for secure and computer-generated, time-stamped trails that independently record actions creating, modifying, or deleting electronic records. Record changes preserve earlier information. Annex 11's audit-trail section addresses GMP-relevant changes and deletions, documented reasons and intelligible output, plus availability and regular review through a risk-based approach. The objective is reconstructable and reviewable change history.

Control point: the record write path and reason-for-change workflow, plus scheduled review and evidence export.

Owner: the system owner maintains the mechanism. Quality or the designated process reviewer owns review and exception disposition. Records management controls retention and authorized retrieval.

Test and evidence: create and change a staged regulated record, then attempt deletion and administrator alteration. Confirm the original remains reconstructable. Review the trail for the stated period and follow one exception to closure. Retain before-and-after values and timestamps, actor and reason, review record and permissions, plus the integrity output and export result. The tamper-evident audit log guide describes the narrower integrity test for request events.

Gap and retest: common gaps include overwritten values and absent reasons, plus excluded failures and review populations containing only successful events. Retest the same scenarios after remediation and preserve both results.

Change, incident, and periodic evaluation

Requirement and objective: Annex 11 section 10 requires controlled system and configuration changes. Section 11 calls for periodic evaluation of valid state and GMP compliance, considering functionality and deviations, incidents and problems, upgrade history and performance, reliability and security, plus validation status where appropriate. Section 13 connects incident assessment and critical-incident root cause to corrective and preventive action. The objective is continued control after release.

Control point: change approval and deployment authorization, incident triage and corrective-action approval, plus periodic-review sign-off.

Owner: change control and the system owner manage configuration. Quality owns deviation and incident disposition, corrective action and effectiveness review, plus the valid-state conclusion.

Test and evidence: sample a provider endpoint change and trace impact and risk, validation and approval, deployment and rollback, plus monitoring. Select an incident and join it to the active configuration and investigation, root cause where required and quality impact, corrective action and effectiveness result, plus closure. Retain the current periodic evaluation with its source populations.

Gap and retest: flag unresolved model aliases and missing incident-to-release joins, plus overdue effectiveness checks and periodic reviews built from incomplete populations. Retest after the joins and source manifests are frozen.

Copies, retention, continuity, and archive retrieval

Requirement and objective: Part 11's closed-system copy and protection provisions require accurate and complete human-readable and electronic copies plus protected records available through the required retention period. Annex 11's data-storage and continuity provisions, alongside its archiving provisions, address secured data and tested restoration, documented continuity arrangements, plus archive accessibility and readability, integrity and retrieval after relevant system changes. The objective is usable evidence across failure and time.

Control point: retention assignment and backup monitoring, restoration exercise and continuity activation, plus archive migration and inspection export.

Owner: records management sets the approved retention rule. Infrastructure operates backup and archive services. Business continuity owns recovery procedures, while quality approves GxP suitability and exceptions.

Test and evidence: retrieve one old record and its audit trail, then produce readable and electronic copies. Restore a selected backup in a controlled environment. Time the continuity procedure and compare record counts and integrity results. Retain the executed procedure and query, export and restoration log, missing-join report and review, plus the remediation ticket. The LLM audit log retention guide separates retention configuration from proved retrieval.

Gap and retest: unreadable legacy formats and detached signatures, plus missing trails and untested restore jobs, keep the row open. Retest after repair or migration using the same reviewer-selected identifier.

Routed authenticated HTTP LLM requests

Requirement and objective: enforce approved identity and workflow, content and destination policy at the routed request point, then retain a decision event that can join the applicable GxP records. This row is an implementation mapping rather than a claim that Part 11 or Annex 11 prescribes an HTTP gateway.

Control point: the stateless HTTP policy point between a manufacturer-controlled application and an approved LLM endpoint.

Owner: the application owner supplies authenticated identity and approved purpose. Security engineering owns policy and routed egress. Records and quality owners approve retention and joins, review use and incident handling.

Test and evidence: send permit and redact cases, deny and missing-identity cases, plus disallowed-destination and response-policy cases. Retain the calling application and supplied principal, purpose and classification, provider and endpoint, policy version and decision, timestamp and response disposition, plus the correlation identifier, integrity result, and protected export.

Gap and retest: direct browser activity and local or embedded inference, opaque vendor-managed calls and stolen credentials, plus application bypasses sit outside this control point. Assign each exclusion to IAM and application owners, supplier and endpoint owners, or network owners as appropriate. Call the retained event routed request decision evidence. It identifies one HTTP decision and never validates the regulated system.

DeepInspect

DeepInspect provides the inline control point for authenticated HTTP requests deliberately routed to an LLM endpoint. It evaluates application-supplied identity and workflow context, applies versioned request and response policy, and writes a signed and tamper-evident event containing the route decision.

In this map, that event supports the routed-request row and selected joins into change or incident review. DeepInspect leaves intended use, Part 11 and Annex 11 scope, system validation and supplier qualification, signatures and periodic evaluation, corrective action and retention policy, plus product disposition with the regulated organization's assigned owners. Book a technical deep dive at deepinspect.ai.

Frequently asked questions

Can one row map to Part 11 and Annex 11?

A shared control can support both sources. Keep separate anchors and applicability statements, plus expected evidence, because the regimes have different scope and wording. One restoration test may serve both rows while preserving each requirement and conclusion.

What makes a mapping test repeatable?

The test names the controlled environment and input, configuration and expected result, plus the evidence location and reviewer. A second qualified person should reproduce the result without asking the original tester which hidden settings mattered.

How should partial coverage appear?

Mark the exact function and route, period and evidence join that remains uncovered. Assign an owner and interim measure, plus a target date and retest. A single percentage obscures the difference between one missing archive link and an entire bypass route.

Does CSA replace validation under Part 11?

FDA's February 2026 CSA guidance recommends a risk-based assurance approach for automation used in medical-device production or quality management systems. Part 11 retains its closed-system validation requirement where the rule applies. Map each source within its scope and preserve the evidence used for the regulated conclusion.

Can routed request evidence close the audit-trail row?

It can close the defined event controls for traffic that crossed the gateway. The regulated application's record creation and modification, deletion and signature, review and retention, plus validation controls need their own tests and evidence. Join the request event to those records with a stable correlation identifier.