This report collects the primary regulatory texts that make five requirements legal or normative in GxP-regulated work: attribution of actions to identifiable authorized individuals; contemporaneous recording; controlled change of records and systems; second-person review; and audit-trail capture and review. Sources are FDA, EMA and EudraLex, MHRA, PIC/S, ICH, EU law, NIST and ISPE public material. Verbatim quotes are retained with section numbers and dates. Searches: 20 or more independent queries across the eCFR API, FDA, EMA, the European Commission, EUR-Lex, ICH, NIST, PIC/S, ISPE and secondary GxP sources.
One caveat applies throughout: none of these frameworks is satisfied by a tool. Validation, GMP, GLP and GCP compliance, data accuracy and predicate-rule compliance are obligations on the regulated firm.
1. 21 CFR Part 11: electronic records and electronic signatures
Final rule 62 FR 13464, effective 20 August 1997; quotations from the current eCFR text.
Audit trails and authority checks
Where Part 11 applies, records must be protected, access limited to authorized individuals, and every operator action that creates, modifies or deletes an electronic record must be independently recorded by a secure, computer-generated, time-stamped audit trail that does not obscure prior information.
Source: 21 CFR §11.10(c), (d), (e), (g), controls for closed systems. URL: https://www.ecfr.gov/current/title-21/chapter-I/subchapter-A/part-11 Date: current eCFR, up to date as of 29 September 2026, checked 1 October 2026. Confidence: High, Tier-1, verbatim.
"(c) Protection of records to enable their accurate and ready retrieval throughout the records retention period. (d) Limiting system access to authorized individuals. (e) Use of secure, computer-generated, time-stamped audit trails to independently record the date and time of operator entries and actions that create, modify, or delete electronic records. Record changes shall not obscure previously recorded information. Such audit trail documentation shall be retained for a period at least as long as that required for the subject electronic records and shall be available for agency review and copying. … (g) Use of authority checks to ensure that only authorized individuals can use the system, electronically sign a record, access the operation or computer system input or output device, alter a record, or perform the operation at hand."
Note: §11.10(e) requires independent recording of actions and §11.10(g) requires authority checks, so the regulation treats "authorized individuals" as a state to be enforced at the moment of action. §11.10(e) mandates capture; review is driven by predicate rules and by the data-integrity guidance below.
Signature manifestation
Signed electronic records must display who signed, when, and the meaning of the signature.
Source: 21 CFR §11.50(a). URL: as above. Confidence: High, verbatim.
"(a) Signed electronic records shall contain information associated with the signing that clearly indicates all of the following: (1) The printed name of the signer; (2) The date and time when the signature was executed; and (3) The meaning (such as review, approval, responsibility, or authorship) associated with the signature. (b) The items identified in paragraphs (a)(1), (a)(2), and (a)(3) of this section shall be subject to the same controls as for electronic records and shall be included as part of any human readable form of the electronic record (such as electronic display or printout)."
Note: Part 11 compliance additionally requires validation under §11.10(a).
Signature-to-record linkage and uniqueness
Signatures must be inseparably linked to the record, and electronic signatures must be unique to one individual and never reused.
Source: 21 CFR §11.70, §11.100(a), (b). URL: as above. Confidence: High, verbatim.
§11.70: "Electronic signatures and handwritten signatures executed to electronic records shall be linked to their respective electronic records to ensure that the signatures cannot be excised, copied, or otherwise transferred to falsify an electronic record by ordinary means."
§11.100(a): "Each electronic signature shall be unique to one individual and shall not be reused by, or reassigned to, anyone else."
Note: Part 11 applies only where a predicate rule requires the record.
Enforcement policy and inspection practice
FDA's August 2003 guidance "Part 11, Electronic Records; Electronic Signatures, Scope and Application" states that FDA does "not intend to take enforcement action to enforce compliance with the validation, audit trail, record retention, and record copying requirements of part 11 as explained in this guidance. However, records must still be maintained or submitted in accordance with the underlying predicate rules…" Source: FDA guidance, August 2003. URL: https://www.fda.gov/media/75414/download Confidence: High, verbatim.
On audit-trail review, PIC/S PI 041-1 §9.6 directs inspectors to "Verify that audit trails are regularly reviewed (in accordance with quality risk management principles) and that discrepancies are investigated." Source: PIC/S PI 041-1, 1 July 2021. URL: https://picscheme.org/docview/4234 Confidence: High, verbatim.
2. 21 CFR Parts 210 and 211: cGMP for finished pharmaceuticals
§211.22, the authority of the quality unit
The quality control unit holds explicit responsibility and authority to approve or reject, and to review production records and investigations.
Source: 21 CFR §211.22(a), (c), (d). URL: https://www.ecfr.gov/current/title-21/chapter-I/subchapter-C/part-211 Confidence: High, verbatim.
"(a) There shall be a quality control unit that shall have the responsibility and authority to approve or reject all components, drug product containers, closures, in-process materials, packaging material, labeling, and drug products, and the authority to review production records to assure that no errors have occurred or, if errors have occurred, that they have been fully investigated. … (c) The quality control unit shall have the responsibility for approving or rejecting all procedures or specifications impacting on the identity, strength, quality, and purity of the drug product. (d) The responsibilities and procedures applicable to the quality control unit shall be in writing; such written procedures shall be followed."
Note: "Authority" is a legal object in GMP, not a metaphor.
§211.68, automated and electronic equipment
Changes to master production and control records through computer systems must be restricted to authorized personnel, and input and output must be checked for accuracy.
Source: 21 CFR §211.68(a), (b). URL: as above. Confidence: High, verbatim.
"(a) … If such equipment is so used, it shall be routinely calibrated, inspected, or checked according to a written program designed to assure proper performance. Written records of those calibration checks and inspections shall be maintained. (b) Appropriate controls shall be exercised over computer or related systems to assure that changes in master production and control records or other records are instituted only by authorized personnel. Input to and output from the computer or related system of formulas or other records or data shall be checked for accuracy. The degree and frequency of input/output verification shall be based on the complexity and reliability of the computer or related system."
Note: This is the core "who may change what" control for computerized GMP systems. An AI agent writing to a master production and control record falls under it. The "checked for accuracy" and validation-data obligations remain on the regulated firm.
§211.101(c), second-person verification of critical operations
Source: 21 CFR §211.101(c). Confidence: High, verbatim.
"(c) Weighing, measuring, or subdividing operations for components shall be adequately supervised. Each container of component dispensed to manufacturing shall be examined by a second person to assure that: (1) The component was released by the quality control unit; (2) The weight or measure is correct as stated in the batch production records; (3) The containers are properly identified. If the weighing, measuring, or subdividing operations are performed by automated equipment under § 211.68, only one person is needed to assure paragraphs (c)(1), (c)(2), and (c)(3) of this section."
Note: Regulatory second-person review of critical steps. Where these operations are performed by automated equipment under §211.68, the regulation requires only one person to assure items (1) to (3), and the record of who checked is itself regulated evidence.
§211.180, records retention, originals or true copies, availability
Source: 21 CFR §211.180(c), (d), (e). Confidence: High, verbatim.
"(c) All records required under this part, or copies of such records, shall be readily available for authorized inspection during the retention period at the establishment where the activities described in such records occurred. … (d) Records required under this part may be retained either as original records or as true copies such as photocopies, microfilm, microfiche, or other accurate reproductions of the original records."
Paragraph (e) requires that written records "be maintained so that data therein can be used for evaluating, at least annually, the quality standards of each drug product"; the FDA data-integrity guidance cites §211.180(e) for legibility.
§211.188(b)(11), identification of who performed and who checked each significant step
Source: 21 CFR §211.188(b)(11). Confidence: High, verbatim.
"Batch production and control records shall be prepared for each batch of drug product produced and shall include complete information relating to the production and control of each batch. These records shall include: … (b) Documentation that each significant step in the manufacture, processing, packing, or holding of the batch was accomplished, including: … (11) Identification of the persons performing and directly supervising or checking each significant step in the operation, or if a significant step in the operation is performed by automated equipment under § 211.68, the identification of the person checking the significant step performed by the automated equipment."
Note: Where automated equipment, and by extension an AI system, performs a significant step, the batch record must identify the person who checked it. The regulation requires the check itself, not merely a log of it.
§211.192, mandatory quality-unit review before release
Source: 21 CFR §211.192. Confidence: High, verbatim.
"All drug product production and control records, including those for packaging and labeling, shall be reviewed and approved by the quality control unit to determine compliance with all established, approved written procedures before a batch is released or distributed. Any unexplained discrepancy … or the failure of a batch or any of its components to meet any of its specifications shall be thoroughly investigated, whether or not the batch has already been distributed. … A written record of the investigation shall be made and shall include the conclusions and followup."
§211.194(a)(7) to (8), laboratory records: performer and second-person reviewer
Source: 21 CFR §211.194(a)(7), (8). Confidence: High, verbatim.
"(7) The initials or signature of the person who performs each test and the date(s) the tests were performed. (8) The initials or signature of a second person showing that the original records have been reviewed for accuracy, completeness, and compliance with established standards."
Note: The explicit second-person review requirement in the laboratory, and the strongest cGMP regulatory anchor for dual-control attribution.
3. GLP: 21 CFR Part 58, nonclinical laboratory studies
§58.130(e), contemporaneous and attributable recording
Contemporaneous, attributable recording and non-obscuring corrections are required for all study data, including automated data collection.
Source: 21 CFR §58.130(e). URL: https://www.ecfr.gov/current/title-21/chapter-I/subchapter-A/part-58 Confidence: High, verbatim.
"(e) All data generated during the conduct of a nonclinical laboratory study, except those that are generated by automated data collection systems, shall be recorded directly, promptly, and legibly in ink. All data entries shall be dated on the date of entry and signed or initialed by the person entering the data. Any change in entries shall be made so as not to obscure the original entry, shall indicate the reason for such change, and shall be dated and signed or identified at the time of the change. In automated data collection systems, the individual responsible for direct data input shall be identified at the time of data input. Any change in automated data entries shall be made so as not to obscure the original entry, shall indicate the reason for change, shall be dated, and the responsible individual shall be identified."
Note: For automated systems, GLP already requires identifying the responsible human at the point of data input.
Also captured in the original research but not quoted here for length: §58.35, the duties of the quality assurance unit, which monitors and reports status to management and the study director, and the attribution of inspections. Confidence: High.
4. EudraLex Volume 4, EU GMP
4a. Annex 11, computerised systems, revision of January 2011
Principle, and §1 risk management: Principle: "The application should be validated; IT infrastructure should be qualified." §1: "Risk management should be applied throughout the lifecycle of the computerised system taking into account patient safety, data integrity and product quality. As part of a risk management system, decisions on the extent of validation and data integrity controls should be based on a justified and documented risk assessment…"
Source: EudraLex Volume 4, Annex 11. URL: https://health.ec.europa.eu/document/download/8d305550-dd22-4dad-8463-2ddb4a1345f1_en (annex11_01-2011_en.pdf). Date: effective 30 June 2011. Confidence: High, verbatim.
Note: Validation is the manufacturer's burden.
§9, audit trails: "Consideration should be given, based on a risk assessment, to building into the system the creation of a record of all GMP-relevant changes and deletions (a system generated 'audit trail'). For change or deletion of GMP-relevant data the reason should be documented. Audit trails need to be available and convertible to a generally intelligible form and regularly reviewed."
Note: Reason for change and regular review are explicit. The wording "consideration should be given" is softer than a mandate, but EU and PIC/S inspectors treat audit trails as expected for GMP-relevant systems.
§10, change and configuration management: "Any changes to a computerised system including system configurations should only be made in a controlled manner in accordance with a defined procedure."
§12.3 and §12.4, security: "Creation, change, and cancellation of access authorisations should be recorded." And: "Management systems for data and for documents should be designed to record the identity of operators entering, changing, confirming or deleting data including date and time."
§14, electronic signature: "Electronic records may be signed electronically. Electronic signatures are expected to: a. have the same impact as hand-written signatures within the boundaries of the company, b. be permanently linked to their respective record, c. include the time and date that they were applied."
§15, batch release: "When a computerised system is used for recording certification and batch release, the system should allow only Qualified Persons to certify the release of the batches and it should clearly identify and record the person releasing or certifying the batches. This should be performed using an electronic signature."
§8.2, printouts: "For records supporting batch release it should be possible to generate printouts indicating if any of the data has been changed since the original entry."
Sections 8 to 15: source, URL, date and confidence as above. High, verbatim.
Note: §15 is the EU's sharpest authority-gating clause: the system must allow only Qualified Persons to certify release, an authorization check at the moment of a consequential act, with recorded identity. Annex 11 is under revision, draft of July 2025, with a parallel draft Annex 22 on AI. Both remained drafts as of 1 October 2026: the European Commission consultation ran from 7 July to 7 October 2025, and the EudraLex Volume 4 page still lists the January 2011 Annex 11 and no Annex 22. Treat them as direction of travel, not law.
4b. EudraLex Chapter 4, documentation, revision of January 2011
§4.7 to §4.9, good documentation practices. Source: EudraLex Volume 4 Chapter 4. URL: https://health.ec.europa.eu/document/download/104b3eb8-81a7-4858-9419-cb06562adb66_en (chapter4_01-2011_en.pdf). Confidence: High, verbatim.
"4.7 Handwritten entries should be made in clear, legible, indelible way. 4.8 Records should be made or completed at the time each action is taken and in such a way that all significant activities concerning the manufacture of medicinal products are traceable. 4.9 Any alteration made to the entry on a document should be signed and dated; the alteration should permit the reading of the original information. Where appropriate, the reason for the alteration should be recorded."
Note: §4.8 is the EU's contemporaneity clause and §4.9 the non-obscuring-correction clause.
§4.20(c), batch processing record: "A Batch Processing Record should be kept for each batch processed. It should be based on the relevant parts of the currently approved Manufacturing Formula and Processing Instructions, and should contain the following information: … c) Identification (initials) of the operator(s) who performed each significant step of the process and, where appropriate, the name of any person who checked these operations." Confidence: High, verbatim. Performer and checker attribution at batch level.
4c. Annex 15, qualification and validation, effective 1 October 2015
Any planned change affecting product quality must be formally documented and its impact on validated status assessed.
"It is a GMP requirement that manufacturers control the critical aspects of their particular operations through qualification and validation over the life cycle of the product and process. Any planned changes to the facilities, equipment, utilities and processes, which may affect the quality of the product, should be formally documented and the impact on the validated status or control strategy assessed. Computerised systems used for the manufacture of medicinal products should also be validated according to the requirements of Annex 11. The relevant concepts and guidance presented in ICH Q8, Q9, Q10 and Q11 should also be taken into account."
The Annex 15 glossary defines change control as: "A formal system by which qualified representatives of appropriate disciplines review proposed or actual changes that might affect the validated status of facilities, systems, equipment or processes. The intent is to determine the need for action to ensure and document that the system is maintained in a validated state."
URL, primary: https://health.ec.europa.eu/document/download/7c6c5b3c-4902-46ea-b7ab-7608682fb68d_en (2015-10_annex15.pdf). Confidence: High, verbatim, checked against the primary PDF.
5. Data integrity guidance: FDA 2018, MHRA 2018, PIC/S 2021
5a. FDA, "Data Integrity and Compliance With Drug CGMP: Questions and Answers", December 2018
Audit trail, definition: "For purposes of this guidance, audit trail means a secure, computer-generated, time-stamped electronic record that allows for reconstruction of the course of events relating to the creation, modification, or deletion of an electronic record. For example, the audit trail for a high performance liquid chromatography (HPLC) run should include the user name, date/time of the run, the integration parameters used, and details of a reprocessing, if any. Documentation should include change justification for the reprocessing."
Source: FDA guidance, media/119267. URL: https://www.fda.gov/media/119267/download Date: December 2018. Confidence: High, verbatim.
ALCOA anchored in predicate rules, footnote 5: "These characteristics are important to ensuring data integrity and are addressed throughout the CGMP regulations for drugs. For attributable, see §§ 211.101(d), 211.122, 211.186, 211.188(b)(11), and 212.50(c)(10); for legible, see §§ 211.180(e) and 212.110(b); for contemporaneously recorded (at the time of performance), see §§ 211.100(b) and 211.160(a); for original or a true copy, see §§ 211.180 and 211.194(a); and for accurate, see §§ 211.22(a), 211.68, 211.188, and 212.60(g)." Confidence: High, verbatim.
Note: ALCOA is not soft guidance. FDA maps each letter to enforceable CFR sections.
Access restriction, Q4: "You must exercise appropriate controls to assure that changes to computerized MPCRs or other CGMP records or input of laboratory data into computerized records can be made only by authorized personnel (§ 211.68(b))."
Shared logins, Q5: "When login credentials are shared, a unique individual cannot be identified through the login and the system would not conform to the CGMP requirements in parts 211 and 212. … Shared, read-only user accounts that do not allow the user to modify data or settings are acceptable for viewing data, but they do not conform with the part 211 and 212 requirements for actions, such as second person review, to be attributable to a specific individual." Both High, verbatim.
Note: FDA explicitly names "second person review … attributable to a specific individual", so dual-control attribution is an enforcement expectation, not best practice.
Audit trail review, Q7, "Who should review audit trails?": "Personnel responsible for record review under CGMP should review the audit trails that capture changes to data associated with the record as they review the rest of the record … For example, all production and control records, which includes audit trails, must be reviewed and approved by the quality unit (§ 211.192)."
Q8, "How often should audit trails be reviewed?": "If the review frequency for the data is specified in CGMP regulations, adhere to that frequency for the audit trail review. For example, § 211.188(b) requires review after each significant step in manufacture, processing, packing, or holding, and § 211.22 requires data review before batch release. In these cases, you would apply the same review frequency for the audit trail." Otherwise, FDA says to set the frequency "using knowledge of your processes and risk assessment tools." Confidence: High, verbatim.
5b. MHRA, "GxP Data Integrity Guidance and Definitions", revision 1, March 2018
§6.13, audit trail as who, what, when and why: "The audit trail is a form of metadata containing information associated with actions that relate to the creation, modification or deletion of GXP records. An audit trail provides for secure recording of life-cycle details such as creation, additions, deletions or alterations of information in a record, either paper or electronic, without obscuring or overwriting the original record. An audit trail facilitates the reconstruction of the history of such events relating to the record regardless of its medium, including the 'who, what, when and why' of the action. … It should be possible to associate all data and changes to data with the persons making those changes, and changes should be dated and time stamped (time and time zone where applicable). The reason for any change, should also be recorded. … Audit trails (identified by risk assessment as required) should be switched on. Users should not be able to amend or switch off the audit trail. Where a system administrator amends, or switches off the audit trail a record of that action should be retained."
Source: MHRA, gov.uk. URL: https://assets.publishing.service.gov.uk/government/uploads/system/uploads/attachment_data/file/687246/MHRA_GxP_data_integrity_guide_March_edited_Final.pdf Date: March 2018. Confidence: High, verbatim.
Note: The "who, what, when and why" formula is the cleanest statement of what a record must be able to reconstruct. "Users should not be able to amend or switch off the audit trail" is explicit.
§6.15, documented data review with a signed positive statement: "There should be a procedure that describes the process for review and approval of data. Data review should also include a risk-based review of relevant metadata, including relevant audit trails records. Data review should be documented and the record should include a positive statement regarding whether issues were found or not, the date that review was performed and the signature of the reviewer. A procedure should describe the actions to be taken if data review identifies an error or omission. This procedure should enable data corrections or clarifications to provide visibility of the original record, and traceability of the correction, using ALCOA principles." Confidence: High, verbatim.
5c. PIC/S PI 041-1, good practices for data management and integrity in regulated GMP and GDP environments, 1 July 2021
§9.6, audit trail review tied to batch release: "Critical audit trails related to each operation should be independently reviewed with all other records related to the operation and prior to the review of the completion of the operation (e.g. prior to batch release) so as to ensure that critical data and changes to it are acceptable. This review should be performed by the originating department, and where necessary verified by the quality unit… Non-critical audit trails reviews can be conducted during system reviews at a pre-defined frequency." And: "Audit trail functionalities should be enabled and locked at all times and it should not be possible to deactivate, delete or modify the functionality. If it is possible for administrative users to deactivate, delete or modify the audit trail functionality, an automatic entry should be made in the audit trail indicating that this has occurred."
Source: PIC/S PI 041-1, picscheme.org/docview/4234. Date: 1 July 2021. Confidence: High, verbatim from the PIC/S-hosted copy.
§9.7 items 1 and 2, second-operator verification and authorized change: "All manual data entries of critical data should be verified, either by a second operator, or by a validated computerised means. … Changes to entries should be captured in the audit trail and reviewed by an appropriately authorised and independent person." And: "Any and all changes and modifications to raw data should be fully documented and should be reviewed and approved by at least one appropriately trained and qualified individual." Confidence: High, verbatim.
§9.8, documented review evidence: "The audit trail review activity should be documented and recorded. Any significant variation from the expected outcome found during the audit trail review should be fully investigated and recorded." And: "Evidence of each review should be recorded and available to the inspector." On time zones: "Where global systems are used, it may be necessary for date and time records to include a record of the time zone to demonstrate contemporaneous recording." Confidence: High, verbatim.
Note: PIC/S makes evidence of the review itself an inspectable record.
6. ALCOA and ALCOA+: origin and status
ALCOA, Attributable, Legible, Contemporaneous, Original, Accurate, was coined in the 1990s by Stan W. Woollen of FDA (QMSDoc). The "+", Complete, Consistent, Enduring, Available, emerged around 2010, when the EMA GCP Inspectors Working Group's reflection paper on electronic source data in clinical trials introduced it (same source). "Traceable" was added as a tenth principle, ALCOA++, in EMA's Guideline on computerised systems and electronic data in clinical trials (EMA/INS/GCP/112288/2023, 9 March 2023, §4.5), and the July 2025 draft revision of EU GMP Chapter 4 also defines ALCOA++ with Traceable (consultation draft).
Source: QMSDoc for the origin; the EMA guideline and the Chapter 4 draft for ALCOA++. Confidence: Medium for the origin, a secondary source; high for ALCOA++, primary documents.
Note: Two letters depend on an external record: A for attributable and C for contemporaneous, plus aspects of O, original and non-obscured. L, legible, and A, accurate, depend on the underlying data and the validated system.
7. FDA draft guidance, January 2025: AI to support regulatory decision-making
"Considerations for the Use of Artificial Intelligence to Support Regulatory Decision-Making for Drug and Biological Products", draft, January 2025, docket FDA-2024-D-4689.
Scope, drug discovery excluded: "For the purposes of this guidance, the term drug product life cycle includes nonclinical, clinical, postmarketing, and manufacturing phases. While the drug product life cycle generally also includes drug discovery, the use of AI for the purposes of drug discovery is not in the scope of this guidance…" (footnote 10). And: "This guidance does not address the use of AI models (1) in drug discovery or (2) when used for operational efficiencies (e.g., internal workflows, resource allocation, drafting/writing a regulatory submission) that do not impact patient safety, drug quality, or the reliability of results from a nonclinical or clinical study."
Source: FDA draft guidance. URL: https://www.fda.gov/media/184830/download Date: January 2025. Confidence: High, verbatim.
Note: Much back-office use of agentic AI is explicitly out of scope. The regulated zone is AI output that feeds regulatory decisions on safety, effectiveness or quality.
The seven-step risk-based credibility assessment framework: "The risk-based credibility assessment framework described here consists of the following 7-step process to establish and assess the credibility of an AI model output for a specific COU based on model risk: • Step 1: Define the question of interest that will be addressed by the AI model … • Step 2: Define the COU for the AI model … • Step 3: Assess the AI model risk … • Step 4: Develop a plan to establish the credibility of AI model output within the COU … • Step 5: Execute the plan … • Step 6: Document the results of the credibility assessment plan and discuss deviations from the plan … • Step 7: Determine the adequacy of the AI model for the COU…" Confidence: High, verbatim.
Note: Steps 6 and 7 are documentation steps: credibility is established by documented, deviation-tracked evidence reviewed against the context of use.
8. FDA discussion paper, 2023: artificial intelligence in drug manufacturing
FDA flags that continuously learning AI which adapts to real-time data strains existing change-control and CGMP expectations, and seeks input on how AI fits the current framework.
Source: FDA CDER discussion paper. URL: https://www.fda.gov/media/165743/download Date: March 2023. Confidence: High, verbatim.
"Disclaimer: This paper is for discussion purposes only and is not a draft or final guidance."
"The areas of consideration in this discussion paper are those for which FDA would like public feedback. … focus on the manufacture of drug products that would be marketed under a New Drug Application (NDA), Abbreviated New Drug Application (ANDA), or Biologics License Application (BLA)."
Area of consideration 5, page 10: "Continuously learning AI systems that adapt to real-time data may challenge regulatory assessment and oversight."
Note: A regulator-acknowledged gap between adaptive AI and static validated states. FDA has not endorsed any technical solution.
9. EMA reflection paper on the use of AI in the medicinal product lifecycle, final, September 2024
Traceable documentation of data and development: "The source(s) of data and the process of data acquisition, along with any processing such as cleaning, transformation, imputation, annotation, normalisation, and augmentation should be documented in a detailed and fully traceable manner in line with GxP requirements." And: "It is the responsibility of the sponsor, applicant or MAH to ensure that SOPs promote a development practice that favours model generalisability and robustness … and to keep traceable documentation and development logs to allow secondary assessment of development practices."
Source: EMA/CHMP/CVMP reflection paper. URL: https://www.ema.europa.eu/en/documents/scientific-guideline/reflection-paper-use-artificial-intelligence-ai-medicinal-product-lifecycle_en.pdf Dates: draft adopted by CHMP 10 July 2023 and by CVMP 13 July 2023; final agreed 6 September 2024; adopted by CHMP 9 September and CVMP 11 September 2024. Confidence: High, verbatim.
Freezing before unblinding: "Prior to the database lock and subsequent unblinding of the data used for hypothesis testing, the data pre-processing pipeline and all models should be frozen and documented in a traceable manner in the statistical analysis plan. Once a dataset has been opened, any non-prespecified modifications to data processing or models implies that analysis results are considered post hoc and hence not suited for confirmatory evidence generation." Confidence: High, verbatim.
Note: A time-stamped record of when models and data were frozen, against when they were modified, has direct evidentiary consequences under this passage. The paper ties itself to the EU AI Act, GDPR and medicines legislation, "should be read in coherence with … the AI act", and adopts a risk-based approach keyed to regulatory impact and patient risk.
10. EMA and FDA, "Guiding Principles of Good AI Practice in Drug Development", joint, January 2026
Ten shared principles, including human-centricity, a clear context of use, traceable and verifiable documentation, risk-based performance assessment of the whole human and AI system, and lifecycle management.
Source: joint EMA and FDA principles document. URL: https://www.ema.europa.eu/en/documents/other/guiding-principles-good-ai-practice-drug-development_en.pdf Date: January 2026, first published by EMA on 14 January 2026. Confidence: High, verbatim.
Principle 1: "Human-centric by design, the development and use of AI technologies align with ethical and human-centric values."
Principle 4: "Clear context of use, AI technologies have a well-defined context of use (role and scope for why it is being used)."
Principle 6: "Data governance and documentation, data source provenance, processing steps, and analytical decisions are documented in a detailed, traceable, and verifiable manner, in line with GxP requirements. Appropriate governance, including privacy and protection for sensitive data, is maintained throughout the technology's life cycle."
Principle 8: "Risk-based performance assessment, risk-based performance assessments evaluate the complete system including human-AI interactions…"
Principle 9: "Life cycle management, risk-based quality management systems are implemented throughout the AI technologies' life cycles, including to support capturing, assessing, and addressing issues. The AI technologies undergo scheduled monitoring and periodic re-evaluation to ensure adequate performance (e.g., to address data drift)."
Note: The object of Principle 6 is data and analytical decisions, and compliance is framed as "in line with GxP requirements", which remain the firm's obligation. This is a principles document, not binding regulation.
11. EU AI Act, Regulation (EU) 2024/1689
OJ 12 July 2024; in force 1 August 2024. High-risk obligations apply from 2 December 2027 (Annex III systems) and 2 August 2028 (Annex I systems), under Article 113 as amended by Regulation (EU) 2026/1744 (OJ 24 July 2026, in force 27 July 2026).
Article 12, automatic event logging: "1. High-risk AI systems shall technically allow for the automatic recording of events (logs) over the lifetime of the system. 2. In order to ensure a level of traceability of the functioning of a high-risk AI system that is appropriate to the intended purpose of the system, logging capabilities shall enable the recording of events relevant for: (a) identifying situations that may result in the high-risk AI system presenting a risk … or in a substantial modification; (b) facilitating the post-market monitoring referred to in Article 72; and (c) monitoring the operation of high-risk AI systems referred to in Article 26(5)." Article 12(3) further requires, for the remote biometric identification systems referred to in Annex III, point 1(a), recording "the identification of the natural persons involved in the verification of the results."
Source: EUR-Lex, OJ:L_202401689. URL: https://eur-lex.europa.eu/legal-content/EN/TXT/HTML/?uri=OJ:L_202401689 Confidence: High, verbatim.
Article 14, human oversight: "1. High-risk AI systems shall be designed and developed in such a way, including with appropriate human-machine interface tools, that they can be effectively overseen by natural persons during the period in which they are in use. … 3. The oversight measures shall be commensurate with the risks, level of autonomy and context of use of the high-risk AI system…" Recital 73 adds that oversight persons need "the necessary competence, training and authority to carry out that role" and the ability "to intervene in order to avoid negative consequences or risks, or stop the system if it does not perform as intended." Confidence: High, verbatim.
Note: Relevance to pharmaceuticals is mostly indirect. AI embedded in devices regulated under MDR or IVDR becomes high-risk through Article 6(1), with obligations from 2 August 2028, while general drug-manufacturing AI is mainly governed by GMP rather than the AI Act. The EMA reflection paper and the January 2026 joint principles both read GxP alongside the AI Act. Logs are a provider-side design duty, not a compliance certificate. Phased dates under Article 113 of the Regulation, as amended by Regulation (EU) 2026/1744: prohibitions 2 February 2025; general-purpose AI 2 August 2025; Annex III high-risk 2 December 2027; Annex I products 2 August 2028.
12. ICH Q9(R1), Q10 and Q14
ICH Q9(R1), adopted 2023, quality risk management principles: "Two primary principles of quality risk management are: • The evaluation of the risk to quality should be based on scientific knowledge and ultimately link to the protection of the patient. … • The level of effort, formality and documentation of the quality risk management process should be commensurate with the level of risk." And §5.2: "Effective risk-based decision-making begins with determining the level of effort, formality and documentation that should be applied during the quality risk management process."
Source: ICH Q9(R1) Step 4, database.ich.org. URL: https://database.ich.org/sites/default/files/ICH_Q9%28R1%29_Guideline_Step4_2023_0126_0.pdf Confidence: High, verbatim.
Note: Quality-risk-management documentation scales with risk, and the decision record, who decided, on what basis, under what authority, is part of the quality-management-system record set.
ICH Q10, 2008, change management system, §3.2.3: "Innovation, continual improvement, the outputs of process performance and product quality monitoring and CAPA drive change. In order to evaluate, approve and implement these changes properly, a company should have an effective change management system. … The change management system should include the following, as appropriate for the stage of the lifecycle: (a) Quality risk management should be utilised to evaluate proposed changes. The level of effort and formality of the evaluation should be commensurate with the level of risk; (b) Proposed changes should be evaluated relative to the marketing authorisation… (c) Proposed changes should be evaluated by expert teams contributing the appropriate expertise and knowledge from relevant areas … to ensure the change is technically justified. Prospective evaluation criteria for a proposed change should be set; (d) After implementation, an evaluation of the change should be undertaken to confirm the change objectives were achieved and that there was no deleterious impact…"
Source: ICH Q10, database.ich.org. URL: https://database.ich.org/sites/default/files/Q10%20Guideline.pdf Confidence: High, verbatim.
Note: Q10 is the canonical evaluate, approve, implement, re-evaluate chain. The quality of the evaluation is not evidenced by signatures alone.
ICH Q14, adopted November 2023, analytical procedure lifecycle and established conditions: "In line with ICH Q12, applicants may propose ECs for an analytical procedure. … ECs and related reporting categories are proposed by the applicant and assessed by the regulatory authorities for approval based on the scientific justification provided." And: "If justified and validated (see Chapter 5.2), a PAR or MODR allows movement within the approved range(s) to be managed within a company's PQS. Changes outside of the approved ranges or expansion of those ranges require regulatory communication."
Source: ICH Q14 Step 4. URL: https://database.ich.org/sites/default/files/ICH_Q14_Guideline_2023_1116.pdf Confidence: High, verbatim.
Note: Approved design space and established-condition boundaries mean an action can move outside its current authorization without any record changing. Evidence of which parameter envelope was in force at the time of the action is what distinguishes the two cases.
13. ISPE GAMP 5, second edition, July 2022, and public GAMP AI material
GAMP 5 Second Edition, ISPE, July 2022, 404 pages, keeps the risk-based computerized-system-validation framework, emphasizes critical thinking by knowledgeable subject-matter experts, supports agile and iterative development, supplier leverage, cloud and SaaS, and adds appendices M12 on critical thinking, D8 on agile, D10 on blockchain and D11 on AI and machine learning. It is industry good practice, not a regulation.
Source: ISPE product page, the guide's table of contents and ISPE Pharmaceutical Engineering. Confidence: High for the ISPE public pages; the guide text itself is paywalled.
ISPE: "GAMP aims to deliver a cost-effective framework of good practice to ensure that computerized systems are effective and of high quality, fit for intended use, and compliant with applicable regulations." … "This Guide highlights the importance of applying 'critical thinking' by knowledgeable and experienced SMEs when defining the appropriate approach for specific circumstances."
Note: GAMP cannot make a system compliant: it is a method for generating the evidence regulators expect. ISPE has also issued a series of GxP records and data-integrity guides, 2017 to 2024, and published the ISPE GAMP Guide: Artificial Intelligence in July 2025. The full text is paywalled, so no verbatim quotes are claimed from it.
14. NIST AI Risk Management Framework 1.0, NIST AI 100-1, January 2023
Trustworthy-AI characteristics: "valid and reliable, safe, secure and resilient, accountable and transparent, explainable and interpretable, privacy enhanced, and fair with their harmful biases managed." Four functions: GOVERN, MAP, MEASURE, MANAGE.
Source: NIST AI 100-1. URL: https://nvlpubs.nist.gov/nistpubs/ai/NIST.AI.100-1.pdf Date: January 2023. Confidence: High, verbatim.
§3.4, accountable and transparent: "Trustworthy AI depends upon accountability. Accountability presupposes transparency. … This characteristic's scope spans from design decisions and training data to model training, the structure of the model, its intended use cases, and how and when deployment, post-deployment, or end user decisions were made and by whom." And MAP 3.5: "Processes for human oversight are defined, assessed, and documented in accordance with organizational policies…" Confidence: High, verbatim.
Note: NIST's "decisions … made and by whom" is the voluntary-framework counterpart to the GxP attribution rules. It is voluntary unless referenced in a contract or in regulation.
What these frameworks do not establish
No external record or logging layer establishes any of the following. Each remains an obligation on the regulated firm.
- Validation, or a validated state: §11.10(a), Annex 11 §4, Annex 15. Validation is a lifecycle activity on the system itself.
- GMP, GLP or GCP compliance, batch releasability, or any regulatory approval.
- Data accuracy, correctness of AI output, or model credibility: the FDA 2025 draft Steps 4 to 7 require substantive evaluation.
- Predicate-rule compliance generally, or Part 11 conformance of the host system.
- The quality of human oversight: AI Act Article 14 requires competence and an effective ability to intervene, and a log of an override is not oversight.
- Quality-risk-management decision quality under ICH Q9, or the technical justification for a change under ICH Q10 §3.2.3(c).
Sources
- 21 CFR Part 11, electronic records and electronic signatures. https://www.ecfr.gov/current/title-21/chapter-I/subchapter-A/part-11
- 21 CFR Part 211, cGMP for finished pharmaceuticals. https://www.ecfr.gov/current/title-21/chapter-I/subchapter-C/part-211
- 21 CFR Part 58, good laboratory practice for nonclinical laboratory studies. https://www.ecfr.gov/current/title-21/chapter-I/subchapter-A/part-58
- FDA, Part 11, Electronic Records; Electronic Signatures, Scope and Application, guidance, August 2003. https://www.fda.gov/media/75414/download
- EudraLex Volume 4, Annex 11, computerised systems, January 2011. https://health.ec.europa.eu/document/download/8d305550-dd22-4dad-8463-2ddb4a1345f1_en
- EudraLex Volume 4, Chapter 4, documentation, January 2011. https://health.ec.europa.eu/document/download/104b3eb8-81a7-4858-9419-cb06562adb66_en
- EudraLex Volume 4, Annex 15, qualification and validation, October 2015. https://health.ec.europa.eu/document/download/7c6c5b3c-4902-46ea-b7ab-7608682fb68d_en
- European Commission, stakeholders' consultation on EudraLex Volume 4, Chapter 4, Annex 11 and new Annex 22, July to October 2025. https://health.ec.europa.eu/consultations/stakeholders-consultation-eudralex-volume-4-good-manufacturing-practice-guidelines-chapter-4-annex_en
- European Commission, EudraLex Volume 4 page. https://health.ec.europa.eu/medicinal-products/eudralex/eudralex-volume-4_en
- European Commission, draft revision of EU GMP Chapter 4, consultation version, July 2025. https://health.ec.europa.eu/document/download/fa336a6e-753b-46fc-b53b-9178bacd8878_en?filename=mp_vol4_chap4_consultation_guideline_en.pdf
- FDA, Data Integrity and Compliance With Drug CGMP: Questions and Answers, December 2018. https://www.fda.gov/media/119267/download
- MHRA, GxP Data Integrity Guidance and Definitions, revision 1, March 2018. https://assets.publishing.service.gov.uk/government/uploads/system/uploads/attachment_data/file/687246/MHRA_GxP_data_integrity_guide_March_edited_Final.pdf
- PIC/S PI 041-1, Good Practices for Data Management and Integrity in Regulated GMP/GDP Environments, 1 July 2021. https://picscheme.org/docview/4234
- EMA, Guideline on computerised systems and electronic data in clinical trials, EMA/INS/GCP/112288/2023, 9 March 2023. https://www.ema.europa.eu/en/documents/regulatory-procedural-guideline/guideline-computerised-systems-and-electronic-data-clinical-trials_en.pdf
- FDA, Considerations for the Use of Artificial Intelligence to Support Regulatory Decision-Making for Drug and Biological Products, draft, January 2025. https://www.fda.gov/media/184830/download
- FDA CDER, Artificial Intelligence in Drug Manufacturing, discussion paper, March 2023. https://www.fda.gov/media/165743/download
- EMA, Reflection paper on the use of artificial intelligence in the medicinal product lifecycle, September 2024. https://www.ema.europa.eu/en/documents/scientific-guideline/reflection-paper-use-artificial-intelligence-ai-medicinal-product-lifecycle_en.pdf
- EMA and FDA, Guiding Principles of Good AI Practice in Drug Development, January 2026. https://www.ema.europa.eu/en/documents/other/guiding-principles-good-ai-practice-drug-development_en.pdf
- Regulation (EU) 2024/1689, the EU AI Act. https://eur-lex.europa.eu/legal-content/EN/TXT/HTML/?uri=OJ:L_202401689 (also https://data.europa.eu/eli/reg/2024/1689/oj)
- Regulation (EU) 2026/1744, the Digital Omnibus on AI, amending Article 113 of the AI Act. https://data.europa.eu/eli/reg/2026/1744/oj
- ICH Q9(R1), quality risk management, Step 4, 2023. https://database.ich.org/sites/default/files/ICH_Q9%28R1%29_Guideline_Step4_2023_0126_0.pdf
- ICH Q10, pharmaceutical quality system, 2008. https://database.ich.org/sites/default/files/Q10%20Guideline.pdf
- ICH Q14, analytical procedure development, Step 4, November 2023. https://database.ich.org/sites/default/files/ICH_Q14_Guideline_2023_1116.pdf
- NIST AI Risk Management Framework 1.0, NIST AI 100-1, January 2023. https://nvlpubs.nist.gov/nistpubs/ai/NIST.AI.100-1.pdf
- ISPE, GAMP 5 Guide second edition product page, July 2022. https://ispe.org/publications/guidance-documents/gamp-5-guide-2nd-edition ; table of contents https://ispe.org/sites/default/files/publications/guidance-documents/2022-TOC/ISPE-GAMP5-Ed2_TOC.pdf
- ISPE, GAMP Guide: Artificial Intelligence, July 2025. https://ispe.org/publications/guidance-documents/gamp-guide-artificial-intelligence
- ISPE Pharmaceutical Engineering, January and February 2024, description of GAMP 5 second edition. https://ispewebassets.org/files/attachments/public/PE_JanFeb24_CompleteIssue_v2aLR.pdf
Secondary sources:
- QMSDoc, ALCOA origin and Woollen, and the evolution to ALCOA+ and ALCOA++. https://qmsdoc.com/2026/01/20/alcoa-alcoa-and-the-evolution-to-alcoa-the-journey-of-data-integrity/
- Valkit, ALCOA evolution. https://valkit.ai/blog/pharma-data-integrity
All verbatim quotes were checked on 1 October 2026 against: the eCFR (Parts 11, 58, 211), fda.gov media PDFs (75414, 119267, 184830, 165743), health.ec.europa.eu PDFs (Annex 11, Chapter 4, Annex 15), the gov.uk MHRA PDF, picscheme.org (PI 041-1), the Official Journal texts of Regulations 2024/1689 and 2026/1744, ich.org PDFs (Q9(R1), Q10, Q14), nvlpubs.nist.gov (AI 100-1), ema.europa.eu PDFs (the reflection paper, the clinical-trials computerised systems guideline and the joint EMA and FDA principles) and ispe.org public pages.
