← Back to all posts

Handling an Inspector's Question About Your AI Assistant

The question will come. Not in the opening meeting, and probably not from the lead inspector. It will come from the second inspector during a deviation review, when a QA reviewer opens a laptop to check a cleaning validation limit and the screen shows a chat interface instead of a PDF. The inspector will lean in and ask: "What is that system?"

How your team answers in the next ninety seconds determines whether the AI assistant becomes a two-line note in the report or a three-day excursion into your computerised systems programme. This post covers what to say, what to have ready, and what not to do — written for QA and CSV teams at DACH manufacturers and CDMOs facing national authority inspections (Swissmedic, the German Länder authorities, AGES) as well as FDA and MHRA visits.

The Framing That Works: Decision Support, Not Decision Making

The single most important sentence your staff can say is a clear statement of intended use. Something like:

"It is a document search assistant. It retrieves passages from our approved SOP and guideline corpus and shows me the source document, version, and section. I read the source before I act on anything. It does not make quality decisions, it does not generate records, and nothing it outputs becomes part of a GMP record unless I have verified it against the controlled document."

That framing does three things at once. It establishes the system as a retrieval tool rather than an autonomous decision-maker, it confirms a human remains the record author, and it signals that your team understands the distinction. Inspectors are trained to probe for systems where automation has quietly displaced human judgement without a corresponding validation effort. If the first answer they hear is confident, specific, and consistent with what your documentation says, the temperature of the conversation drops immediately.

What does not work: "It's just a tool we use internally," "It's not a GMP system," or "IT gave it to us." Each of those answers invites the follow-up you cannot survive — show me where that determination was made and who approved it.

The Five Questions You Will Actually Get

Across inspection debriefs and mock audits, the questions converge on a predictable set. Prepare direct answers and a document reference for each.

  • "Is this a validated system?" — Answer with the GAMP5 (Second Edition) software category assessment and the validation approach derived from it. For a retrieval assistant over controlled documents, the risk assessment typically lands on a Category 4 configured product with a critical thinking rationale documented. Reference your validation summary report by document number.
  • "How do you know the answers are correct?" — Point to the qualification protocol for retrieval: the defined question set, the acceptance criteria for source attribution, and the periodic requalification. Explain that correctness is assured not by trusting the model output but by mandatory verification against the cited source. The control is procedural, and the procedure is written down.
  • "What documents are in it?" — You need a corpus inventory: which document types, which effective versions, how superseded documents are removed, and the maximum latency between a document becoming effective in the DMS and being available in the assistant. Annex 11 §7 expectations on data accuracy apply to the corpus just as they do to any other electronic data set.
  • "Who has access and what is logged?" — Role-based access mapped to your existing identity management, plus an audit trail capturing user, timestamp, query, retrieved sources, and response. Annex 11 §12 and 21 CFR Part 11(e) frame the expectation; show a sample audit trail export, not a screenshot.
  • "Is this artificial intelligence? How does the EU AI Act apply?" — Yes, it is. Your answer is the documented classification: an internal decision-support tool for document retrieval, not a high-risk system under Annex III, and not a prohibited practice under Article 5. Reference your AI system inventory entry and the transparency and literacy obligations you have addressed under Articles 4 and 50.

The Evidence Pack: Six Documents, One Folder

Inspection readiness for an AI assistant is not a different discipline — it is the same discipline applied to a system many QA teams have not yet treated as in scope. Keep these six artefacts retrievable within minutes:

  • Intended use and system boundary statement, approved by QA, naming what the system does and explicitly what it does not do.
  • Risk assessment and GAMP5 categorisation, with the critical thinking rationale for the chosen validation rigour.
  • Validation summary report including retrieval qualification results and traceability from user requirements to test evidence.
  • Corpus control procedure covering ingestion, version synchronisation, and removal of superseded documents.
  • Supplier assessment under Annex 11 §3.1 — including hosting location, data processing agreements, and the supplier's own quality system. For DACH teams this doubles as your GDPR and data residency evidence.
  • Training records demonstrating that every user was trained on verification obligations and the limits of the tool, consistent with ICH Q10 §2.4 and Annex 11 §2.

Three Failure Modes to Avoid

The improvising user. An analyst who says "it just tells me the answer, it's really accurate" has undone your entire validation package in eight words. Train the phrasing, not just the concept. A one-page user card with the standard intended-use statement pinned near workstations is cheap insurance.

The shadow deployment. If a department is using a general-purpose chatbot with SOP text pasted into it, that is the finding — not the assistant you validated. Before any inspection, confirm your AI tool inventory matches reality. Undocumented tools in GxP workflows read as a failure of the pharmaceutical quality system under ICH Q10, not merely a CSV gap.

The over-answer. Do not volunteer architecture diagrams, model names, or embedding strategies. Answer the question asked, at the level of quality control and intended use. If the inspector wants technical depth, bring in the CSV specialist with the validation file. Scope discipline in inspections is a skill; it applies here as it does everywhere else.

The Standard You Are Being Held To

Nothing about AI creates a new regulatory framework for this conversation. The inspector is applying Annex 11, Part 11, and the GMP principle that computerised systems used in GxP activities must be fit for intended use, controlled, and evidenced. What is new is the speed with which these tools enter workflows without passing through change control. The teams that handle the question well are not the ones with the most sophisticated model — they are the ones who treated the assistant as a computerised system from day one and can prove it in under ten minutes.

Run the question as a mock audit item this quarter. Ask three users, unannounced, what the tool is and how they verify its output. Their answers tell you exactly how ready you are.

See how ComplianceGxP handles inspection readiness and inspector questions about AI assistants for pharma and CDMO teams: See how it works →

Running compliance on manual search? See how ComplianceGxP handles this.

See How It Works