GxP Frame Visual Reference · White Paper v4.2 · Overview

Governing AI in Pharmaceutical Operations

The AI-Supported Work Authorization Cycle: six gate decisions for whether a defined AI-supported quality workflow may proceed, be narrowed, or be stopped.

A defensible authorization decision applies to a defined workflow, not AI in the abstract. Passing a model test or completing a course does not establish that the combined workflow will produce acceptable work: testing supplies evidence, but the decision also depends on the system's authority, whether people can perform their assigned role, and whether the organization can find and correct failures.

The Cycle: Six Gates, One Loop

Restrict, requalify
0

Inventory & ownership

1

Define work & risk

2

Set authority & records

3

Test the workflow

4

Authorize & monitor

5

Change, correct, retire

Change or failure: reassess scope and authority

The Question Each Gate Has To Answer

0

Inventory

What AI is in use, including unapproved use, and who owns it?

Register · Contain · Prohibit · Assign owner
1

Define

What task will AI support, and what could failure affect?

Approve · Narrow · Reject
2

Authority

What may the system read, recommend, change, or approve?

Authorize bounded functions · Prohibit
3

Test

Can the system and people perform representative work reliably, within a reviewer burden they can sustain?

Authorize pilot · Correct · Narrow · Stop

Reviewer-burden limit: pass/fail, not a monitoring nicety

4

Authorize

Does pilot evidence justify routine use, and does performance hold?

Continue · Expand · Restrict · Investigate · Suspend

Register tracks the burden limit; threshold fires regardless of omission rate

5

Respond

What changed, what was affected, and did the response work?

Reinstate · Narrow · Stop · Retire

Decide Before The Work Proceeds

Before allowing AI to support a consequential quality decision: name the task and accountable owner, examine representative results, and agree on what finding would make the team stop or restrict use.

What evidence would justify authorizing this workflow?

What finding would make us restrict or stop it?

Answer both before authorizing a pilot, and again before authorizing routine use.

Governing AI in Pharmaceutical Operations · Version 4.2 · Brian Drapeau, GxP Frame

Gate-by-gate requirements → page 2  ·  Toolkit, roles & regulatory basis → page 3

GxP Frame Visual Reference · White Paper v4.2 · Reference Sheet 1 of 2

Gate Requirements: Question, Evidence, Owner, Decision

What each of the six gates in the AI-Supported Work Authorization Cycle requires, and what “tested” has to mean before routine use.

Gate Detail: Question, Evidence, Owner, Decision, Toolkit Record

0

Inventory & ownership

Gate decision
Register Contain Prohibit Assign owner
Question

What AI is in use, including unapproved use, and who owns it?

Evidence

Use inventory; systems, data, users; named owners.

Owner
AI governance lead + quality unit.
Toolkit record: AI Use Inventory
1

Define work & risk

Gate decision
Approve Narrow Reject
Question

What task will AI support, and what could failure affect?

Evidence

Intended use, source boundary, measured baseline, risk.

Owner
Process owner + quality owner.

Toolkit record: Gate Decision Record (light path)

2

Set authority & records

Gate decision
Authorize bounded functions Prohibit
Question

What may the system read, recommend, change, or approve?

Evidence

Permissions, approval design, record/signature rules.

Owner
System owner, quality owner, IT, data owner.

Enforced, not just instructed: the agent's own credentials must technically enforce the envelope, and each approval stays tied to the record state it reviewed. If that state changes before the agent acts, the system determines whether the approval still applies, and another review is required only where the change undermines its original basis.

Toolkit record: Gate Decision Record (Authority Envelope)

3

Test the complete workflow

Gate decision
Authorize pilot Correct Narrow Stop
Question

Can the system and people perform representative work reliably?

Evidence

Challenge cases, omissions, false alarms, recovery.

Owner
Evaluation owner + quality unit.

A reviewer's presence is not proof of review: test whether the review design detects seeded and naturally occurring errors under realistic workload. Automation bias is treated as a control failure mode, not assumed away.

Reviewer-burden limit: a pre-set pass/fail condition, not a monitoring nicety. It is set alongside the omission criterion and carried into Stage 4 and the Authorization Register.

Toolkit record: Workflow Evaluation Scoring Sheet + Adjudication Protocol

4

Authorize routine use & monitor

Gate decision
Continue Expand Restrict Investigate Suspend
Question

Does pilot evidence justify routine use, and does performance hold?

Evidence

Pilot results, incidents, overrides, drift, feedback.

Owner
Process owner + quality unit.

Reviewer burden is monitored against the Stage 3 limit here: the register carries the limit and the current burden against it; the action threshold fires whether or not the omission rate still looks acceptable.

Toolkit record: AI Authorization Register + Independent Effectiveness Review

5

Change, correct, reauthorize, retire

Gate decision
Reinstate Narrow Stop Retire
Question

What changed, what was affected, and did the response work?

Evidence

Change impact, regression, requalification, CAPA.

Owner
Change owner, system owner, quality unit.

Toolkit record: Gate Decision Record + Management actions

What “Tested” Has To Mean

Deviation chronology example
59
independent, representative holdout cases
0
critical omissions allowed across the set
about 4.95%

95% one-sided upper confidence bound on the true critical-omission rate

These numbers are the acceptance criterion worked out for one example (a bounded pilot testing an AI-supported deviation chronology), not a fixed pass mark for every workflow. Each workflow sets its own criterion sized to its own risks and failure modes: zero critical omissions in 59 independent holdout cases yields a 95% one-sided upper confidence bound of about 4.95%; if one critical omission occurs, at least 93 total cases with no further failures are required to support the same below-5% rate claim; demonstrating a rate below 1% requires 299 zero-failure cases. Cases must be independent, representative of the authorized scope, and held out from any tuning or rehearsal. These are separate statistical bounds, not alternate ways to pass: one omission may still support the same rate claim with a larger sample, but it fails this example's preset zero-omission acceptance criterion.

Reviewer burden is set in the same acceptance criterion, as a pass/fail condition, not monitored separately. The criterion states the review effort per case a reviewer can sustain and still perform the verification authorization depends on. A result above that limit is a failed condition under the pre-set monitoring rule, not an operational inconvenience. The limit and the current burden against it carry into Stage 4 monitoring and the AI Authorization Register.

Governing AI in Pharmaceutical Operations · Version 4.2 · Brian Drapeau, GxP Frame

Six-gate cycle overview → page 1  ·  Toolkit, roles & regulatory basis → page 3

GxP Frame Visual Reference · White Paper v4.2 · Reference Sheet 2 of 2

Toolkit, Roles & Regulatory Basis

What runs the cycle, who is accountable at each step, and the regulatory requirements and supporting guidance it sits on.

The Control Basis: Regulatory Requirements And Supporting Guidance, Not A Replacement

21 CFR 211.22(c)  Quality-unit responsibility
21 CFR 211.25  Qualified personnel
ICH Q9(R1)  Quality risk management
ICH Q10  Pharmaceutical quality system

21 CFR 211.68 / Part 11  Electronic records & signatures

FDA data integrity / PIC/S PI 041-1  Provenance

GAMP Guide: AI / GAMP 5  Lifecycle practice

What Runs The Cycle: The AI Work Authorization Toolkit (v4.2.1, Eight Operating Artifacts)

1

AI Use Inventory

Identifies actual use, ownership, status, and disposition. Does not authorize.

2

Gate Decision Record

Records the decision to authorize a bounded workflow, supported by the required evidence and approvals: Authority Envelope, accepted risk, reconsideration triggers.

3

Workflow Evaluation Scoring Sheet

Records test evidence, critical-failure handling, holdout integrity, and gate recommendation.

4

Adjudication Protocol

Freezes the critical-omission classification method, calibrated and blinded, before the holdout is scored.

5

AI Authorization Register

Aggregates current state, Decision history, and Management actions. Indexes; does not replace GDRs.

6

Independent Effectiveness Review Record

Tests whether authorization, monitoring, and actions actually work in practice.

7

User Guide

Explains the connected control sequence, artifact crosswalk, and implementation boundary.

8

Role Quick-Start Cards

Gives each of the eight role groups an actionable starting point.

No single artifact authorizes a workflow or demonstrates continuing effectiveness. The eight operate as one control system, alongside the companion white paper (v4.2), a Release Notes / Verification Summary, and the v4.2.1 correction notice. gxpframe.com/ai-work-authorization-toolkit

Who Operates It: Eight Role Groups, One Connected Sequence

1. Process owner

Own the work and acceptable outcome.

Do: Define the bounded task, baseline, downstream decision, and record path.

Never: Authorize through an inventory or register entry alone.

2. Quality owner / unit

Decide whether evidence and controls support the regulated use.

Do: Approve thresholds, critical-failure mapping, and the Adjudication Protocol before results are examined.

Never: Approve after the fact.

3. System / data / security / privacy owners

Define and enforce what the workflow may access and do.

Do: Maintain and technically enforce the approved Authority Envelope.

Never: Rely on a prompt to prohibit an available action.

4. Evaluation owner

Run the scoring sheet and produce Stage 3 evidence.

Do: Freeze the rubric and calibrate on a seeded collection before the protected holdout is scored.

Never: Confirm your own mapping as the only reviewer.

5. Assessor / operational reviewer

Judge the evidence independently and document the basis.

Do: Complete the independent assessment before seeing the AI conclusion, when the protocol requires it.

Never: Score tone or polish instead of evidence.

6. AI governance / portfolio owner

Keep organizational evidence complete, current, and traceable.

Do: Reconcile the Use Inventory, Authorization Register, and Decision history.

Never: Replace local process and quality owners.

7. Independent effectiveness reviewer

Test whether authorization and monitoring controls work in practice.

Do: Test actual use against the Authority Envelope and authorized scope.

Never: Review work you designed or operate without disclosed safeguards.

8. Management review chair

Convert organizational evidence into accountable decisions and resources.

Do: Decide whether to restrict, suspend, requalify, resource, or retire affected workflows.

Never: Accept a portfolio average that hides a failed subgroup.

What This Method Does Not Establish

That every AI-supported workflow is acceptable.

Real-world performance of the Cycle or its worked examples.

A replacement for validation or existing GMP responsibilities.

Authorization without locally approved evidence and an accountable quality decision.

Governing AI in Pharmaceutical Operations · Version 4.2 · Brian Drapeau, GxP Frame

Six-gate cycle overview → page 1  ·  Gate-by-gate requirements → page 2