AI Assurance Academy · Part 1
GxP Applicability and Risk-Based Scoping
Chapter 4 of 20 · Professional AI assurance starts by identifying the governing process and record—not by declaring that every AI tool is GxP or that every assistant is merely “productivity software.” This chapter provides a feature-level scoping method.
Professional AI assurance starts by identifying the governing process and record—not by declaring that every AI tool is GxP or that every assistant is merely “productivity software.” This chapter provides a feature-level scoping method.
Published: September 4, 2026 | Version 1.0
Editorial owner: CSV to CSA Knowledge Hub | Review status: Open for practitioner peer review
THE SCOPE DECISION TREE
Step 1: Identify the actual feature
Name the operation, not the brand. A single platform may contain search, drafting, classification, workflow, and agent features with different uses.
Step 2: Identify the process and authority
Which production, laboratory, quality, clinical, safety, or regulatory process uses the output? Which law, regulation, protocol, specification, procedure, or quality-system obligation establishes the record or decision?
Step 3: Determine the role
Direct use
The feature performs, controls, evaluates, or records a regulated process or quality activity.
Supporting use
The feature supports monitoring, testing, development, recordkeeping, or administration without directly performing the process decision.
General business or infrastructure use
The feature is not specific to production or the quality management system. Context can change this conclusion; cloud storage that holds required quality records differs from general file storage.
Step 4: Identify the record
Does the output become source data, a quality record, a temporary aid, metadata, an audit trail, or a transitory working artifact? Is the authoritative record elsewhere? Retention and Part 11 analysis depend on the answer.
Step 5: Follow failure to consequence
Could the feature’s failure lead to an incorrect controlled decision, lost or altered evidence, missed signal, unacceptable product, compromised safety, or failure to meet a requirement?
Step 6: Set proportionate assurance
Applicable does not mean identical rigor. Scale activities to intended use, process risk, uncertainty, control strength, and detectability.
FOUR COMMON AI SCOPING ERRORS
Error 1: Tool-based scope
“The enterprise chatbot is non-GxP.” The same chatbot can summarize a public meeting and draft a root-cause conclusion from a deviation. Scope follows use.
Error 2: Output-only scope
“The output is reviewed, so it is not GxP.” Review may be a control, but the AI still influences a regulated process and must be assessed.
Error 3: Record-only scope
“The AI text is never stored.” A transient recommendation may still alter a batch, trial, complaint, or quality decision.
Error 4: Blanket validation
“Any AI is high risk.” This consumes resources without distinguishing the failure that matters and can weaken attention to critical features.
FEATURE-LEVEL EXAMPLES
Meeting transcription for a voluntary project meeting
Generally business productivity unless the transcript becomes an authoritative regulated record or directly controls a required decision.
Drafting a training quiz from an approved SOP
Supports a quality process. Evaluate source fidelity, answer correctness, human approval, version linkage, and control of the final training item.
Visual inspection model that rejects units
Direct production use. Evaluate false accept and false reject, inspection conditions, product families, line speed, challenge defects, reject mechanism, data retention, and fallback.
LLM that proposes a deviation root cause
Materially influences a quality decision. Risk may be unacceptable if the model invents evidence, narrows inquiry, or drives confirmation bias. A strong program may restrict the use to brainstorming questions rather than proposing the conclusion.
Agent that creates a change control record from a ticket
Action-taking use. Verify identity, permissions, field mapping, attachments, duplicate prevention, confirmation, audit trail, and safe failure. Do not let the agent approve its own transaction.
RECORD CLASSIFICATION QUESTIONS
- Is the AI input an original record, true copy, reference, or uncontrolled duplicate?
- Must the original prompt and output be retained?
- Does the output contain evidence, interpretation, or a decision?
- What metadata is needed to reconstruct the event?
- Are citations or retrieved passages part of the evidence?
- What is the retention period?
- Can the record be rendered human-readable with context?
- Does deletion from the chat interface delete the enterprise record?
RISK STRATIFICATION
For each scoped feature, describe:
Consequence: What can happen if the output is wrong, missing, late, biased, or unauthorized?
Reliance: How directly does the process depend on it?
Detectability: Can a qualified person or independent system detect the error before impact?
Uncertainty: How variable is behavior across inputs and time?
Control strength: Are controls preventive, independent, timely, and evidenced?
Exposure: How often and how broadly is the feature used?
Use numerical scoring only if it helps the decision. A written causal argument is required.
WORKED EXAMPLE: AI-ASSISTED AUDIT-TRAIL REVIEW
The AI clusters audit-trail entries and highlights unusual sequences for a reviewer. It does not suppress entries, change the source audit trail, or close the review.
Scope conclusion: The feature supports a required data-integrity control and influences reviewer attention. It requires assurance even though a human signs the final review.
Critical risks:
- Relevant events are not surfaced
- Benign events dominate and create alert fatigue
- The interface omits records during ingestion
- Clustering changes after a silent model update
- Reviewer treats absence of an alert as proof of absence
Controls and evidence:
- Completeness reconciliation against the source audit trail
- Deterministic rules for known critical events
- Recall-focused challenge dataset with rare sequences
- Review of non-alerted samples
- Clear statement that the complete source remains authoritative
- Model and rule version recorded with each review
- Monitoring of overrides, misses, and event-volume shift
SCOPE RECORD
Feature:
Process and governing requirement:
User:
Input and record status:
Output and record status:
Direct, supporting, or general use:
Failure and consequence:
Electronic record or signature considerations:
Risk and controls:
Assurance conclusion:
Owner, reviewer, date:
PROFESSIONAL INTERPRETATION
The scoping decision should survive two questions from an inspector or auditor: “Why is this feature in scope?” and “Why is this level of assurance enough?” A feature-level causal explanation is stronger than a platform label.
PRIMARY SOURCES
FDA CSA final guidance, intended-use and risk framework:
www.fda.gov/media/188844/download
FDA, Part 11—Scope and Application:
MHRA, GxP Data Integrity Guidance and Definitions:
www.gov.uk/government/publications/guidance-on-gxp-data-integrity