AI system validation - QFINITY
Validation · CSV/CSA · Lifecycle Evidence

Validation of AI in a GxP environment.

Lifecycle Evidence for AI-enabled systems - from the model to the audit. Validation and lifecycle strategies that work in day-to-day operations and stand up in an audit.

The starting point

Traditional CSV doesn't fully capture how AI behaves.

What gets validated against its Intended Use is the computerized system as a whole; the AI model itself is verified against its specification and must be fit for purpose for its Context of Use - continuously, because it changes over time. “Validation of AI” is the common shorthand for this. Because models learn from data, data shifts, system behavior can drift - and an update can take effect without any conventional code change ever becoming visible. And even when the model itself is frozen, the Context of Use keeps moving - new usage patterns, new data landscapes, new process environments.

How do you validate an AI-supported system so that the evidence holds up across the entire lifecycle - even when the data, the model, the context of use or the behavior changes?
CSV & AI

CSV stays the foundation. AI calls for more.

We treat AI as a subsystem of a larger computerized system - embedded in interfaces, data flows, processes, roles and supplier models; the main page on AI in the GxP environment sets out which elements have to be looked at together. Traditional validation logic is built around fixed requirements and reproducible tests - AI-enabled systems work differently:

AspectTraditional CSVAI-enabled systems
Requirementsstable, defined up frontdata-dependent, evolving
Outputsdeterministic, reproduciblenot always deterministic, generative
System behaviorpredictable and testablecan drift, depends on the data
Changesvisible code changesre-training, supplier updates, shifts in context
Evidenceone-off validationLifecycle Evidence over time

The Intended Use itself originates in the process - solid process management lays that foundation.

AI doesn't replace validation. It widens the scope to cover data, model behavior, monitoring, drift, re-validation and Lifecycle Evidence.
Lifecycle

Validation across the AI lifecycle.

An AI (sub-)system isn't released just once. Its lifecycle activities - from specification through training and verification to operation and monitoring - and their evidence keep it explainable, and that is what keeps its quality assured.

  1. 1

    Data

    The selection, quality and representativeness of training, validation and test data - and, for generative and agentic systems, of the contextual data used at runtime (prompts, knowledge and retrieval sources). Including data provenance, data release, data integrity, bias risks and relevance to the Intended Use.

  2. 2

    Risk control & control strategy

    Describing and assessing AI-specific risks, selecting and justifying suitable guardrails - including the planned verification that the guardrails are fit for purpose and deliver what they promise. Plus Human Oversight design as part of the control strategy; how accountability is exercised is covered by AI Governance & Human Oversight.

  3. 3

    Model development & selection

    Documented design decisions, well-reasoned acceptance criteria and defined performance metrics - with known limitations, plus an assessment of transparency and explainability.

  4. 4

    Integration & system testing

    Testing the AI subsystem within the wider system: interfaces, data flows, user roles, process integration, error and exception handling, control points and the impact on GxP-relevant decisions.

  5. 5

    Demonstrated performance in real use

    Evidence that the system is fit for its Intended Use in the actual process - controllable, reliable enough and defensible in real regulated use, not just under test conditions.

  6. 6

    Ongoing monitoring

    Keeping watch on performance indicators, data drift and model behavior - including misclassifications, deviations, usage patterns, escalations and triggers for re-validation. The upcoming EU GMP Annex 22 (2025 draft) already sets out concrete expectations for this: defined metrics, regular performance monitoring of the model and drift monitoring of the input data.

  7. 7

    Change Control & Re-Validation

    Structured handling of model updates, re-training, data changes and supplier adjustments. Re-training is not a routine update - it needs clear assessment logic, re-validation triggers and evidence.

Approach

Driven by risk and Intended Use - not by theory.

We assess AI-enabled systems by how they are actually used in the regulated process - evidence depth follows intended use and risk, as Computer Software Assurance confirms.

Intended Use - what is the system actually used for?
Business Process - which process does it act on?
Data foundation - what data is used across the lifecycle?
Decision impact - which decision does it shape?
Human accountability - what stays with people?
Risk - to patient safety, product quality, data integrity
System context - platforms, suppliers, interfaces, controls
the right scope of validation
acceptance criteria that hold
the test strategy you need
the data requirements that apply
the monitoring that's called for
clearly defined re-validation triggers
evidence that stands up in an audit
Lifecycle Evidence

An unbroken chain of evidence - not a paperwork graveyard.

In an audit, what counts isn't whether an AI system was tested once - it's whether you can show, robustly and across the whole lifecycle, that it is and stays fit for its Intended Use. QFINITY brings CSV/CSA practice together with its work on the Core Team of GAMP 5 Second Edition.

traceable data provenance & data release
a well-reasoned model selection and acceptance criteria
documented test & validation activities
performance evidence from real-world use
monitoring results and drift assessment
structured Change Control
re-validation triggers and re-validations actually carried out
links to Governance & Human Oversight
supplier evidence & change communication
Supply chain

Managing suppliers of AI components.

Many AI-enabled systems aren't built in-house - they arrive as SaaS, a cloud service, a platform feature or an API-based component with embedded AI. QFINITY supports supplier assessment, supplier audits and the contractual and technical management of such components - the decisive questions include:

What evidence does the supplier need to provide?
What is known about how the model behaves?
How well does the supplied model fit the Context of Use?
Which limitations and model boundaries matter most?
What data was used for training, validation and testing?
What accountability stays with the regulated user?
How is black-box behavior assessed?
How are changes, updates and releases communicated?
Which audit & transparency rights need to be secured by contract?
How do supplier changes feed into Change Control and re-validation?
Interface

Validation and governance have to work hand in hand.

Validation shows that a system is and stays fit for purpose - it doesn't, on its own, show who is accountable. Establishing who decides, reviews, overrides and bears responsibility is the job of AI Governance and Human Oversight.

Validation

Establishes that the system can be used responsibly in the first place.

Governance & Human Oversight

Ensure that responsibility is actually exercised in day-to-day operation - effectively, and for the long term.

Services

What QFINITY does for AI-enabled systems.

From validation strategy to audit readiness - brought together in a single lifecycle architecture.

Validation strategy & testing

Risk-based strategies shaped by Intended Use, Business Process, data foundation and system context - with well-reasoned, verifiable acceptance criteria and test strategies for different model types.

Data strategy & Data Integrity

Assessing and steering training, validation and test data - and the context-relevant data of generative and agentic systems - woven into your existing Data Integrity and Data Governance structures.

Monitoring & Drift

Robust monitoring concepts for model behavior, performance and data drift - with thresholds, escalation paths and re-validation triggers.

Change Control & Re-Validation

Extending your existing Change Control processes with AI-specific assessment logic for updates, re-training, data changes and supplier changes.

Lifecycle Evidence architecture

An end-to-end evidence structure that ties validation, monitoring, Change Control, re-validation, governance and Human Oversight into one auditable chain of evidence.

Supplier assessment & Audit Readiness

Assessing AI suppliers and solutions, running supplier audits, plus gap assessments, audit storylines and preparing System Owners, QA and IT Quality.

In practice

Typical use cases.

QFINITY supports validation and lifecycle strategy in areas such as the following - what matters isn't whether AI is used directly or indirectly, but whether it can affect GxP-relevant data, processes or decisions:

AI-supported image analysis in clinical applications and diagnostics
visual checks & inspection on the production line
ML models for process optimization and yield improvement
generative AI in deviation management, CAPA and Change Control
LLM support in pharmacovigilance and Regulatory Operations
AI features in SaaS, cloud and platform solutions
supplier solutions with embedded AI capabilities
post-market surveillance in medical devices
Client voices

QFINITY supported us as a partner for CSV, CSA and AI in GxP throughout the development of Tenthpin Intelligent Certificate VerificAItion (T/ICV), our cloud-based, AI-driven certificate verification solution. Quality assurance and auditability were not treated as an afterthought but embedded in the agile development process from the outset: risk-based assurance, human in the loop as a design principle, quality oversight with clearly assigned responsibility. The result is a GxP-ready AI system with robust lifecycle evidence on which our customers can build their validation.

TW
Thomas Weber
Chief Product Officer - Tenthpin Solutions, Switzerland

As a truly AI-native startup in the patient safety space, where there's no margin for error, we brought QFINITY in at the very start to help build our QMS from the ground up. Their guidance provided a framework that held up under scrutiny as we secured early adopters. We've since passed comprehensive client vendor audits, including leading CRO's, with zero major or critical findings, and are supporting client regulatory inspections. Quality is a competitive advantage, not a compliance tax.

AM
Andrew Mitchell
AI for Pharmacovigilance / Patient Safety - YEZA.AI, USA
FAQ

Frequently asked questions.

CSV stays the foundation. For AI-enabled systems it has to be extended with AI-specific requirements - above all around data, model behavior, monitoring, drift, Change Control and re-validation.

AI is often embedded inside a larger computerized system. The AI subsystem has its own requirements for data, model and behavior; the whole system has to be validated in its process context - including the interplay between the AI subsystem and the rest of the system.

Through structured change management with defined triggers, assessment logic and re-validation concepts. Re-training can change how the system behaves, so it has to be assessed on a risk basis.

It depends on the risk and the use. The relevant evidence can cover Intended Use, the data foundation, model behavior, testing and verification activities, monitoring, change communication and transparency rights - set out both contractually and in your processes.

It's the ongoing evidence that a system is and stays fit for its Intended Use. It ties together validation, monitoring, Change Control, re-validation, governance and Human Oversight into one auditable chain of evidence.

Lifecycle evidence that holds up in an audit.

We work with you to scope the validation effort for the computerized system and its AI subsystem on a risk- and Intended-Use basis, then map the chain of evidence from data through monitoring to re-validation. It starts with a free intro call (about 30 minutes) where we frame your specific use case.

Book an intro call