QFINITY events - QFINITY
QFINITY · Events · Meet QFINITY

Where you meet us in person.

An overview of the events QFINITY has taken part in or will be attending - conferences, talks and webinars. You'll often find us at ISPE and ACDM events. Stop by and talk to us in person.

Upcoming events

Conferences, talks and webinars.

Participants of the SAP expert workshop on AI in regulated pharma processes in front of the welcome wall in Walldorf, August 18, 2026

Recap of the SAP expert workshop on AI in regulated pharma processes, Walldorf, August 18, 2026.

On August 18, 2026, QFINITY, represented by Oliver Herrmann, brought the governance perspective to an SAP expert workshop on AI in regulated pharma processes. The workshop followed an ecosystem format: selected organizations each represented their role, SAP as the vendor, Merck for the regulated industry, alongside specialists in governance, validation and guardrails. They work on the same questions because none of them can solve them alone, and these questions concern everyone in a regulated environment. Who is accountable when agentic AI is deployed in GxP processes? And how do you know that the answer holds up?

What the vendor delivers and what stays with the customer

QFINITY’s contribution followed one principle: the software vendor delivers the technical capability, embedded in a GxP-shaped governance that fits the governance systems of its users. What no vendor can deliver is the regulatory accountability of each individual customer. It arises on the customer’s side: in their own governance, in the validation of the systems in their own process, in their own controls.

The structural challenge behind this is an asymmetry. One product governance meets many governance systems of regulated users, and each of those users carries its GxP accountability itself, including for outsourced activities, as Annex 11 provides in its section on suppliers and service providers. That asymmetry is built into the structure, and harmonization alone does not resolve it. It takes defined interfaces where evidence crosses the boundary: model changes, provenance of training data, monitoring signals, audit rights reaching into the supply chain of the model providers.

The capability is delivered. The accountability is not.

The human stays accountable

Human oversight does not mean that a human is involved. The test question is: can that person still intervene and stop? This holds at every level, up to the roles that personally answer for what is released. We therefore put three questions to every agentic system, whatever the vendor:

  • Can every action of an agent be attributed to an identifiable actor in the audit trail?
  • Is a change in behavior detected without a version change?
  • Are there defined paths for stop, rollback and re-verification?

In our ISPE iSpeak article Human-in-the-Loop as an Illusion of Control? we explain why the involvement of a human alone is not yet a control.

The yardstick is patient safety

The real yardstick of our industry applies to every activity: patient safety, product quality and data integrity. Audits are one of many controls in that picture. Good AI governance is not glamorous, it is downright unexciting. Instead of a dramatic stop, it shows in decisions that were carefully weighed before risks occur. The question we expect from an auditor is therefore no longer whether an AI policy exists, but: “Show me where your AI governance decisively shaped a decision.” The architecture has to be prepared for that question today.

Why we have a say here

These questions are not new to QFINITY. Supplier accountability, validation evidence and human responsibility have been our daily work for 22 years, for 200 clients in more than 20 countries, on the core team of GAMP 5 Second Edition and in the author teams of GAMP Good Practice Guides, from the RDI guide on data integrity to the eClinical guide. What is new is the context: AI is now arriving in regulated processes. Our role in this is that of the translator between the expectations of regulated users and those of the software vendor.

What comes next

The discussion continues. In October, Oliver Herrmann and Martin Heitmann take the topic to the ISPE Annual Meeting & Expo in Washington, D.C., with their talk “Progressive QA in AI-Enabled GxP Environments” on October 21. In December, QFINITY and Merck share the stage again. At the 19th Official GAMP 5 Conference in Mannheim, Oliver Herrmann and Alexander Kunz (Merck) moderate the panel “CSV at a turning point: Is our validation ready for digital reality?”

If you are asking yourself which role you play in this network and how your own governance stands up to the audit question, that is a conversation we are glad to have.

AI in Pharma 2026 Kraków - ISPE Poland GAMP CoP conference - QFINITY

On October 26 and 27, 2026, ISPE Poland and its GAMP Community of Practice host the English-language conference AI in Pharma 2026 at the Novotel Kraków Centrum, the fourth edition of the format. Two days are devoted to AI in pharmaceutical practice, across four tracks from “Trusted, Safe & Regulated AI” to “Sustainable & Responsible AI”. A student hackathon at AGH Kraków opens the event on October 25, built around real cases from pharmaceutical manufacturing.

QFINITY is on the program on the first conference day: Frank Henrichmann, Sr. Executive Consultant and Chair of the global GAMP Steering Committee, speaks in the “Trusted, Safe & Regulated AI” track on “AI-Enabled Computerized System Validation – Vision and Reality” (October 26, 10:30 am). The talk measures the vision of AI-supported validation against what actually holds up in regulated environments today.

The topic sits at the core of our work: how AI is changing the validation of computerized systems is the subject of our topic area Artificial Intelligence in GxP; the regulatory frame for AI in GMP comes from the draft EU GMP Annex 22.

Program and tickets at AI in Pharma (aiinpharma.pl)

Joining in Kraków and keen to talk about AI in a GxP environment? Frank looks forward to the conversation on site. Or book a call directly.

Oliver Herrmann at the lectern of the main conference of the Biopharmaceutical Bioprocess Development Summit in Shanghai

One conference day in Shanghai, packed and inspiring in equal measure: a keynote and a panel at the Biopharmaceutical Bioprocess Development Summit, plus the deep-dive AI session at the AI for Pharma 2026 running in parallel. The question raised on the panel is one we currently meet in projects and committees alike: how do the three European drafts Chapter 4, Annex 11 and Annex 22 work together? This article shares the reading we gave on stage and looks into the background of shifting responsibilities, authority cases and criticality, as a working hypothesis based on the drafts and our observations.

Oliver Herrmann and Martin Heitmann under the entrance arch of AI for Pharma 2026 in Shanghai
TWO INVITATIONSInvited independently, on stage together: Oliver Herrmann and Martin Heitmann at the venue in Shanghai.

The occasion was unusual enough to be worth telling: a CMC and bioprocess summit put EU GMP regulation on its keynote program, and the AI for Pharma 2026 running in parallel booked the matching AI deep dive. Martin Heitmann and I had been invited independently of each other and only discovered it during preparation. Companies there want to know the criteria while there is still time to design for them. One day on site, tightly scheduled, and on the main conference panel the question that carries this article: how do all these data integrity requirements actually fit together?

The order behind the three drafts

Keynote slide: One Delivery, Three Rule Books - delivery, cargo, truck, autopilot and driver as an image for Chapter 4, Annex 11 and Annex 22
KEYNOTE SLIDEOne picture, three rule books: the cargo is the data (Chapter 4), the truck is the application and the road the qualified infrastructure (Annex 11), autopilot and guardrails belong to Annex 22, and a human stays at the wheel, carrying responsibility.

Our answer on the panel starts with where the legal act sits. Chapter 4 lives in the main part of the EU GMP Guide, and that is also where batch certification takes place: the Qualified Person certifies the batch on the basis of the records. That is not a system function but a legal act, and it is now meant to rest entirely on records, beyond documents in the traditional sense. This is why Chapter 4 addresses the data and its governance.

Annex 11 is the technical implementation. Its job is to give this legal act technical and functional trust: the computerized system in which the records are created, validated against its intended use and operated in a validated state. Annex 22, finally, inherits from both. It governs AI in critical GMP applications and presupposes the data and system control that Chapter 4 and Annex 11 have built. In the end, the three texts have to add up to a coherent control system, or one of them has not done its job.

One caveat belongs to every one of these statements: all three texts are drafts from the consultation. What will finally be published is open. Until then, this reading is a working hypothesis, based on our observations in the industry and on the EMA’s communication.

As early as 2022, the EMA concept paper on the Annex 11 revision announced that the FDA guidance on Computer Software Assurance, then available as a draft, would be examined: "This guidance and any implication will be considered with regards to aspects of potential regulatory relevance for GMP Annex 11." A guidance from the medical device world, written for production and quality system software and final in the meantime, is thus explicitly on the radar of the pharma revision. The convergence reaches across the Atlantic.

Exhibit 1: The person who moved

To test the ordering formula, follow the Qualified Person through the texts. The Annex 11 of 2011 named them explicitly: "…only Qualified Persons [to] certify the release of the batches". In the 2025 draft, they no longer appear. Instead, they now stand in the Chapter 4 draft: "All records should be available to the Qualified Person at the time of the release decision."

The move confirms the order: certification rests on the records, so the Qualified Person belongs in the chapter that governs the records. The system-side execution, meaning the signature in the system and the workflow behind it, remains a matter for Annex 11. On stage, we made the point in a single sentence:

The QP did not leave. The annex stopped being about them.

Exhibit 2: The numbers

The second test is quantitative. We measured the drafts against the 2011 versions, on the primary texts themselves:

1
Annex 11 grows from 5 to 19 pages. A statement of principles becomes a catalog of requirements that increasingly describes what control has to look like.
2
Chapter 4 grows from 9 to 17 pages and from 32 to 85 clauses. Both clause series are numbered without gaps; the chapter is still called "Documentation".
3
Four terms that appeared exactly zero times in 2011 now carry the chapter. Counted in the text: "governance" 19 times, "data integrity" more than twenty times, "lifecycle" 15 times, "criticality" 7 times.

The unassailable core of this measurement is the zero: a documentation chapter builds its foundation on terms it did not even know in 2011. The numbers show the direction, away from the document as a container, toward the data and its lifecycle as the object of control.

The test question both drafts ask: how strongly do these data influence the decision resting on them, and would you even notice an error?

Exhibit 3: Criticality has three readings and two axes

"Critical" appears several times across the drafts and does not mean the same thing three times over. The Chapter 4 draft defines data criticality in its glossary as "the degree of influence that data have on product safety as well as the regulatory compliance of processes, decisions and product quality". The same draft adds a second axis, detectability: would you see it if the data were wrong? The Annex 22 draft, in turn, calls applications critical when they have a "direct impact on patient safety, product quality or data integrity".

The third reading we took from a conference presentation: at the ISPE Pharma 4.0 conference in Barcelona in 2025, the EMA rapporteur explained the intention behind the critical-application concept along two axes, direct impact and detectability of the error. Detectability thus stands in both drafts, in Chapter 4 as in Annex 11 ("the likelihood of detection"), and additionally in the explained intention behind Annex 22; a single find becomes a pattern.

In practice, both converge on ALCOA++: criticality drives the rigor with which the ten attributes are demonstrated. And the second plus, Traceable, is the attribute-side counterpart of the detectability axis: it makes an error findable after the fact.

Exhibit 4: Existing requirements already apply to the use of AI

Anyone who considers the drafts a distant prospect should read two authority cases from this year. In April 2026, the FDA charged a manufacturer in a warning letter with "overreliance on artificial intelligence for your drug manufacturing operations". And in June 2026, the MHRA described AI-written inspection responses in its Inspectorate blog with "references to MHRA guidance that doesn’t exist", and drew the line that matters: "our concern isn’t whether you use AI; it’s whether your submissions are accurate, verifiable, and prepared under appropriate oversight".

Both authorities check the same thing: whether the evidence is accurate, verifiable and produced under appropriate oversight. The use of AI as such is not in question in either case. That is exactly the logic of the three drafts, applied before their finalization.

What follows from this

Oliver Herrmann at the microphone on the main conference panel in Shanghai
THE PANELThe question about the interplay of the requirements came from the main conference panel. This article’s answer is the worked-out version.

The consequence of our observations: the culture these drafts presuppose can be built today, with a data inventory, assigned criticality and a governance that puts the cross-cutting questions where they belong. Someone has to start, and what the first one builds sets the measure for every system that follows. That is exactly why these foundations belong at the overarching QA level: laid out once there, they carry across all systems instead of emerging by chance in whichever project comes first. QFINITY has supported this build-up since the ERES programs of the Part 11 era and from the core team of GAMP 5 Second Edition; we read the drafts before they become the rule.

And the sentence that drew the strongest reaction in Shanghai belongs at the end, because it explains why this control architecture exists in the first place:

Our industry is not machines serving patients. It is people serving people. The colleague who runs the bioreactor today may be the patient waiting for the vial tomorrow.

More on the foundation of this reading: our pages on the Annex 11 revision and the EU GMP Annex 22 track the state of the two drafts, and our analysis of PIC/S recommendation PI 006-4 shows how the same movement reaches the production level.