← Back to all posts

Training the Reviewers: Building AI Competency Requirements Under GxP

Every validation package for an AI compliance assistant eventually reaches the same weak point: the human on the other side of the screen. You can qualify retrieval, lock down the audit trail, and document intended use to the satisfaction of any inspector — and still fail an inspection because the QA reviewer who accepted an AI-generated answer could not explain what the system does, what it cannot do, or why they trusted the output. Under GxP, competency is not a nice-to-have layered on top of validation. It is part of validation.

This has become sharper since 2 August 2025, when Article 4 of the EU AI Act — the AI literacy obligation — became applicable to all providers and deployers of AI systems, well ahead of the broader high-risk obligations. Pharma manufacturers and CDMOs deploying an AI assistant against their own SOPs are deployers. The obligation is not optional, not risk-tiered, and not satisfied by a vendor slide deck.

The regulatory basis is older than the AI Act

Before anyone reaches for the AI Act, the classic GMP requirements already cover most of this ground:

  • EU GMP Chapter 2 requires sufficient qualified personnel, with training appropriate to duties, and periodic assessment of training effectiveness — not just attendance records.
  • EU GMP Annex 11, clause 1 and clause 2 explicitly address personnel: risk management must consider the criticality of the system, and there must be close cooperation between key personnel, IT, and process owners. Annex 11 clause 2 requires that all personnel have appropriate qualifications, level of access, and defined responsibilities.
  • 21 CFR 211.25 requires training in current GMP as it relates to the employee's functions, conducted by qualified individuals, on a continuing basis.
  • 21 CFR Part 11 §11.10(i) requires that persons who develop, maintain, or use electronic record systems have the education, training, and experience to perform their assigned tasks.
  • ICH Q10 places training within the pharmaceutical quality system as a management responsibility, tied to continual improvement.
  • GAMP 5 Second Edition reinforces that supplier and user competence are inputs to the risk assessment, and its AI/ML appendix places explicit emphasis on human oversight of model outputs.

Read together, the message is unambiguous: if an AI assistant informs a GxP decision, the person interpreting the output must be demonstrably competent to do so, and you must hold the record proving it.

Competency is role-specific, not company-wide

The most common mistake is a single 30-minute "AI awareness" e-learning module assigned to everyone in QA. Inspectors — and increasingly, client auditors qualifying a CDMO — will ask what the deviation investigator specifically was trained to do. Build a role-based matrix instead. A workable structure for a mid-size manufacturer or CDMO:

  • End users (QA associates, production supervisors, deviation authors): what the system retrieves from, what document scope is indexed, how to read a citation, how to verify a source against the controlled DMS, when the assistant declines to answer, and the absolute rule that AI output is never a GxP record on its own.
  • Reviewers and approvers (QA Directors, Qualified Persons, batch record reviewers): everything above, plus how to challenge an answer, how to identify plausible-but-wrong output, how to document that verification occurred, and how AI use interacts with their signature under Annex 11 clause 14 and Part 11 §11.50.
  • System owners and CSV specialists: retrieval architecture, chunking and indexing effects on completeness, change control triggers for model or corpus updates, audit trail review procedures, and periodic review obligations.
  • QA management: intended-use boundaries, EU AI Act deployer duties, supplier oversight under Annex 11 clause 3.1, and criteria for withdrawing the system from use.

What "AI literacy" must actually contain

Article 4 of the AI Act asks deployers to ensure a sufficient level of AI literacy "taking into account their technical knowledge, experience, education and training, and the context the AI systems are to be used in." For a GxP context, that translates into four concrete competencies your curriculum must cover and assess:

  • Mechanism. Users must understand at a functional level that a retrieval-augmented system searches an indexed corpus and generates language from retrieved passages. It does not "know" the SOP. It does not reason about GMP. This single concept prevents most misuse.
  • Failure modes. Incomplete retrieval, stale index versions, ambiguous queries, conflicting source documents, and confidently phrased but unsupported statements. Users should be able to name at least three.
  • Verification behaviour. The trained expectation is: read the answer, open the cited document, confirm the version is effective, confirm the passage says what the answer claims. Nothing goes into a deviation report, CAPA, or change control without that step.
  • Escalation. When retrieval confidence is low, when sources conflict, or when the question touches an area outside the indexed scope, the user escalates to the process owner rather than improvising.
Training effectiveness under Chapter 2 is measured by demonstrated behaviour, not completion status. If your assessment is a five-question multiple choice, you have documented awareness, not competency.

Practical assessment methods that survive an inspection

DACH quality units are used to structured Schulungspläne and documented Qualifizierung of personnel, and the same rigour applies here. Assessment options that produce defensible evidence:

  • Scripted challenge exercises. Give the trainee a set of queries where the correct behaviour is to reject or escalate — a question about a superseded SOP, a question outside the indexed scope, a question with a deliberately ambiguous term. Record whether they caught it. Retain the exercise sheet as training evidence.
  • Verification walkthrough. Observe the trainee tracing one AI answer back to the controlled document in the DMS, confirming the effective version. Sign off as an on-the-job qualification.
  • Read-and-understand plus discussion. The intended-use statement and system boundary document should be a controlled training item, not an internal wiki page.
  • Requalification cadence. Tie retraining to change control. A material model change, a corpus expansion, or a change in intended use should trigger a delta training event, documented against the change record.

Documentation you should be able to produce on request

When an inspector or a client auditor asks about your AI assistant, the training file should contain: the role-based training matrix, curriculum content under document control, the intended-use and boundary statement referenced in that curriculum, individual training records with dates and assessment outcomes, the trainer's qualification, the effectiveness check method, and the link between change control records and delta training. For CDMOs, expect clients to request this during qualification audits — several DACH sponsors now include AI tool usage in their supplier questionnaires.

One further point often missed: the people who maintain the corpus need training too. If a document controller uploads an uncontrolled draft into the index, no amount of user training will save the output. Corpus governance is a competency requirement in its own right.

AI competency requirements are not a separate compliance workstream. They are an extension of the training system you already run under Chapter 2 and ICH Q10 — applied to a system whose failure modes happen to be linguistic rather than mechanical. Treat them that way, and the AI Act's literacy obligation becomes an update to an existing SOP rather than a new programme.

See how ComplianceGxP handles AI competency and training requirements for pharma and CDMO teams: See how it works →

Running compliance on manual search? See how ComplianceGxP handles this.

See How It Works