AI Assurance Academy · Part 1

GxP Applicability and Risk-Based Scoping

Chapter 4 of 20 · Professional AI assurance starts by identifying the governing process and record—not by declaring that every AI tool is GxP or that every assistant is merely “productivity software.” This chapter provides a feature-level scoping method.

Author
Sandip Thorat
Published
September 4, 2026
Last reviewed
September 4, 2026
Category
AI Assurance
Reading time
6 min
Version
1.0
01Context02AI failure03Control envelope04Lifecycle evidence
A decision-focused assurance chain: every transition requires proportionate evidence.

Professional AI assurance starts by identifying the governing process and record—not by declaring that every AI tool is GxP or that every assistant is merely “productivity software.” This chapter provides a feature-level scoping method.

Published: September 4, 2026 | Version 1.0

Editorial owner: CSV to CSA Knowledge Hub | Review status: Open for practitioner peer review

THE SCOPE DECISION TREE

Step 1: Identify the actual feature

Name the operation, not the brand. A single platform may contain search, drafting, classification, workflow, and agent features with different uses.

Step 2: Identify the process and authority

Which production, laboratory, quality, clinical, safety, or regulatory process uses the output? Which law, regulation, protocol, specification, procedure, or quality-system obligation establishes the record or decision?

Step 3: Determine the role

Direct use

The feature performs, controls, evaluates, or records a regulated process or quality activity.

Supporting use

The feature supports monitoring, testing, development, recordkeeping, or administration without directly performing the process decision.

General business or infrastructure use

The feature is not specific to production or the quality management system. Context can change this conclusion; cloud storage that holds required quality records differs from general file storage.

Step 4: Identify the record

Does the output become source data, a quality record, a temporary aid, metadata, an audit trail, or a transitory working artifact? Is the authoritative record elsewhere? Retention and Part 11 analysis depend on the answer.

Step 5: Follow failure to consequence

Could the feature’s failure lead to an incorrect controlled decision, lost or altered evidence, missed signal, unacceptable product, compromised safety, or failure to meet a requirement?

Step 6: Set proportionate assurance

Applicable does not mean identical rigor. Scale activities to intended use, process risk, uncertainty, control strength, and detectability.

FOUR COMMON AI SCOPING ERRORS

Error 1: Tool-based scope

“The enterprise chatbot is non-GxP.” The same chatbot can summarize a public meeting and draft a root-cause conclusion from a deviation. Scope follows use.

Error 2: Output-only scope

“The output is reviewed, so it is not GxP.” Review may be a control, but the AI still influences a regulated process and must be assessed.

Error 3: Record-only scope

“The AI text is never stored.” A transient recommendation may still alter a batch, trial, complaint, or quality decision.

Error 4: Blanket validation

“Any AI is high risk.” This consumes resources without distinguishing the failure that matters and can weaken attention to critical features.

FEATURE-LEVEL EXAMPLES

Meeting transcription for a voluntary project meeting

Generally business productivity unless the transcript becomes an authoritative regulated record or directly controls a required decision.

Drafting a training quiz from an approved SOP

Supports a quality process. Evaluate source fidelity, answer correctness, human approval, version linkage, and control of the final training item.

Visual inspection model that rejects units

Direct production use. Evaluate false accept and false reject, inspection conditions, product families, line speed, challenge defects, reject mechanism, data retention, and fallback.

LLM that proposes a deviation root cause

Materially influences a quality decision. Risk may be unacceptable if the model invents evidence, narrows inquiry, or drives confirmation bias. A strong program may restrict the use to brainstorming questions rather than proposing the conclusion.

Agent that creates a change control record from a ticket

Action-taking use. Verify identity, permissions, field mapping, attachments, duplicate prevention, confirmation, audit trail, and safe failure. Do not let the agent approve its own transaction.

RECORD CLASSIFICATION QUESTIONS

  • Is the AI input an original record, true copy, reference, or uncontrolled duplicate?
  • Must the original prompt and output be retained?
  • Does the output contain evidence, interpretation, or a decision?
  • What metadata is needed to reconstruct the event?
  • Are citations or retrieved passages part of the evidence?
  • What is the retention period?
  • Can the record be rendered human-readable with context?
  • Does deletion from the chat interface delete the enterprise record?

RISK STRATIFICATION

For each scoped feature, describe:

Consequence: What can happen if the output is wrong, missing, late, biased, or unauthorized?

Reliance: How directly does the process depend on it?

Detectability: Can a qualified person or independent system detect the error before impact?

Uncertainty: How variable is behavior across inputs and time?

Control strength: Are controls preventive, independent, timely, and evidenced?

Exposure: How often and how broadly is the feature used?

Use numerical scoring only if it helps the decision. A written causal argument is required.

WORKED EXAMPLE: AI-ASSISTED AUDIT-TRAIL REVIEW

The AI clusters audit-trail entries and highlights unusual sequences for a reviewer. It does not suppress entries, change the source audit trail, or close the review.

Scope conclusion: The feature supports a required data-integrity control and influences reviewer attention. It requires assurance even though a human signs the final review.

Critical risks:

  • Relevant events are not surfaced
  • Benign events dominate and create alert fatigue
  • The interface omits records during ingestion
  • Clustering changes after a silent model update
  • Reviewer treats absence of an alert as proof of absence

Controls and evidence:

  • Completeness reconciliation against the source audit trail
  • Deterministic rules for known critical events
  • Recall-focused challenge dataset with rare sequences
  • Review of non-alerted samples
  • Clear statement that the complete source remains authoritative
  • Model and rule version recorded with each review
  • Monitoring of overrides, misses, and event-volume shift

SCOPE RECORD

Feature:

Process and governing requirement:

User:

Input and record status:

Output and record status:

Direct, supporting, or general use:

Failure and consequence:

Electronic record or signature considerations:

Risk and controls:

Assurance conclusion:

Owner, reviewer, date:

PROFESSIONAL INTERPRETATION

The scoping decision should survive two questions from an inspector or auditor: “Why is this feature in scope?” and “Why is this level of assurance enough?” A feature-level causal explanation is stronger than a platform label.

PRIMARY SOURCES

FDA CSA final guidance, intended-use and risk framework:

www.fda.gov/media/188844/download

FDA, Part 11—Scope and Application:

www.fda.gov/regulatory-information/search-fda-guidance-documents/part-11-electronic-records-electronic-signatures-scope-and-application

MHRA, GxP Data Integrity Guidance and Definitions:

www.gov.uk/government/publications/guidance-on-gxp-data-integrity