GxP news - QFINITY
QFINITY · News · Insights & Events

What is driving the regulated quality of tomorrow.

Articles and analysis from our own work across GxP, pharma, quality management, GAMP and AI. They cover what is changing in the regulated environment, what it means in practice, and what is happening inside our company.

Latest articles

Events, case studies and insights.

Frank Henrichmann von QFINITY auf der Buehne der Vimachem Pharma Digitization and AI Conference 2026 in Athen - QFINITY

On 24 September 2026, Vimachem invited around 50 manufacturers, partners and experts to the Pharma Digitization & AI Conference at the Conrad Athens. The ISPE Greece and Cyprus Affiliate supported the conference. The agenda covered the draft EU GMP Annex 22, the ISPE GAMP Guide on artificial intelligence and case studies from manufacturing. Frank Henrichmann, Chair of the ISPE GAMP Global Steering Committee, spoke on behalf of QFINITY about how to validate AI-supported computerized systems in GMP. His starting point was that validation does not start from scratch. It builds on the principles that GAMP 5 already describes today.

Talk card by Vimachem: From guide to practice, validating AI-enabled systems in GMP, Frank Henrichmann, 24 September 2026
TALK CARDVimachem announced the talk with this card: “From guide to practice: validating AI-enabled systems in GMP” (source: Vimachem).

The conference centered on a question that has been on the agenda of the GAMP committees since the July 2025 draft of Annex 22. What does AI change about validation, and what does it leave unchanged? The title of the talk follows the vocabulary of the ISPE GAMP Guide, which refers to AI-enabled computerized systems. In our reading, the distinction runs one level deeper: The model is verified against its specification. The AI-supported computerized system is validated in its process, against the intended use. This separation allows the tools described in GAMP 5 to remain in use. The only addition is the layer for the specific properties of the model.

Four moves from GAMP 5 to operation

The talk followed four moves, as the slide behind the speaker showed: start with the foundations from GAMP 5, add what AI brings, spend most of the time on the part that decides whether it works, and carry it all into operation.

A
The foundations from GAMP 5. A risk-based approach, a documented intended use, supplier assessment and maintenance of the validated state across the lifecycle continue to apply unchanged. They are the starting point for every AI-supported computerized system in GMP.
B
The AI-specific layer. The model is trained on data, its performance can drift in operation, and a vendor update changes the validated state. That is why the model is verified against acceptance criteria using independent test data, as provided for in the draft Annex 22.
C
Human-in-the-Loop in practice. The talk focused on Human Oversight. It is a control only if the human can actually catch an error. That requires detectable errors, triage by the model’s uncertainty and a limited review volume.
D
Operation after go-live. Performance monitoring, defined triggers for re-verification and logging of every exception keep the performance of the model within its verified range.

The test for the third move: Would the reviewer notice an error made by the model, or merely confirm the result put in front of them?

Context: Annex 22, the GAMP AI Guide and the regulators’ position

Frank Henrichmann of QFINITY on stage at the Vimachem Pharma Digitization and AI Conference in Athens with the slide Where We're Headed
ON STAGEFrank Henrichmann spoke at the Conrad Athens on 24 September 2026 with the slide “Where We’re Headed” behind him: four moves from the foundations in GAMP 5 to operation after go-live.

The draft EU GMP Annex 22 was published in July 2025 and open for consultation until October 2025. For static models in critical applications, it provides for a documented intended use, acceptance criteria, independent test data and monitoring in operation. For generative AI, it provides for use outside critical applications only, as long as qualified personnel take responsibility for the results. The ISPE GAMP AI Guide supplies the accompanying methodology. Both documents were on the agenda in Athens. The draft signals the direction of the requirements on the model. The guide describes how a company implements them across the lifecycle.

The joint EMA and FDA guiding principles of 14 January 2026 assess the system as a whole, including the interaction between humans and AI. The third move of the talk takes up this approach.

QFINITY in Athens

QFINITY has worked on these questions for years in GAMP committees and in projects involving AI applications in GxP, as well as in its own publications. We set out our position on Human Oversight in detail in the September 2026 iSpeak article “Human-in-the-Loop as an Illusion of Control?”. Our service page describes how we validate AI-supported systems.

Frank Henrichmann is Chair of the ISPE GAMP Global Steering Committee and Senior Executive Consultant at QFINITY. Our thanks go to Vimachem and the ISPE Greece and Cyprus Affiliate for the invitation and the expert discussions on AI in manufacturing.

Conference page at Vimachem (vimachem.com)↗

Building Trust in AI for Computerized System Validation - QFINITY

Frank Henrichmann, Senior Executive Consultant at QFINITY, spoke with Life Science Connect about the use of AI in computerized system validation. The interview appeared on September 4, 2026, published simultaneously on Pharmaceutical Online, Bioprocess Online and Biosimilar Development.

In the interview, he sets out which validation tasks can be handled reliably by machine. These include checking completeness, tracing requirements to evidence and comparing documents for consistency. It becomes more delicate where someone has to judge whether a piece of evidence is adequate or how a deviation should be assessed. Those judgments stay with people.

He describes two effects as the real danger: automation bias and cognitive ease. Anyone reading plausibly worded suggestions reviews them less rigorously, and that is precisely why putting a person into the process is not enough. It takes independent technical controls that hold even when human review slips. As the methodological framework, he points to the GAMP 5 Second Edition.

Jon O’Connell of Life Science Connect conducted the interview. You can read it here.

Participants of the SAP expert workshop on AI in regulated pharma processes in front of the welcome wall in Walldorf, August 18, 2026

Recap of the SAP expert workshop on AI in regulated pharma processes, Walldorf, August 18, 2026.

On August 18, 2026, QFINITY, represented by Oliver Herrmann, brought the governance perspective to an SAP expert workshop on AI in regulated pharma processes. The workshop followed an ecosystem format: selected organizations each represented their role, SAP as the vendor, Merck for the regulated industry, alongside specialists in governance, validation and guardrails. They work on the same questions because none of them can solve them alone, and these questions concern everyone in a regulated environment. Who is accountable when agentic AI is deployed in GxP processes? And how do you know that the answer holds up?

What the vendor delivers and what stays with the customer

QFINITY’s contribution followed one principle: the software vendor delivers the technical capability, embedded in a GxP-shaped governance that fits the governance systems of its users. What no vendor can deliver is the regulatory accountability of each individual customer. It arises on the customer’s side: in their own governance, in the validation of the systems in their own process, in their own controls.

The structural challenge behind this is an asymmetry. One product governance meets many governance systems of regulated users, and each of those users carries its GxP accountability itself, including for outsourced activities, as Annex 11 provides in its section on suppliers and service providers. That asymmetry is built into the structure, and harmonization alone does not resolve it. It takes defined interfaces where evidence crosses the boundary: model changes, provenance of training data, monitoring signals, audit rights reaching into the supply chain of the model providers.

The capability is delivered. The accountability is not.

The human stays accountable

Human oversight does not mean that a human is involved. The test question is: can that person still intervene and stop? This holds at every level, up to the roles that personally answer for what is released. We therefore put three questions to every agentic system, whatever the vendor:

  • Can every action of an agent be attributed to an identifiable actor in the audit trail?
  • Is a change in behavior detected without a version change?
  • Are there defined paths for stop, rollback and re-verification?

In our ISPE iSpeak article Human-in-the-Loop as an Illusion of Control? we explain why the involvement of a human alone is not yet a control.

The yardstick is patient safety

The real yardstick of our industry applies to every activity: patient safety, product quality and data integrity. Audits are one of many controls in that picture. Good AI governance is not glamorous, it is downright unexciting. Instead of a dramatic stop, it shows in decisions that were carefully weighed before risks occur. The question we expect from an auditor is therefore no longer whether an AI policy exists, but: “Show me where your AI governance decisively shaped a decision.” The architecture has to be prepared for that question today.

Why we have a say here

These questions are not new to QFINITY. Supplier accountability, validation evidence and human responsibility have been our daily work for 22 years, for 200 clients in more than 20 countries, on the core team of GAMP 5 Second Edition and in the author teams of GAMP Good Practice Guides, from the RDI guide on data integrity to the eClinical guide. What is new is the context: AI is now arriving in regulated processes. Our role in this is that of the translator between the expectations of regulated users and those of the software vendor.

What comes next

The discussion continues. In October, Oliver Herrmann and Martin Heitmann take the topic to the ISPE Annual Meeting & Expo in Washington, D.C., with their talk “Progressive QA in AI-Enabled GxP Environments” on October 21. In December, QFINITY and Merck share the stage again. At the 19th Official GAMP 5 Conference in Mannheim, Oliver Herrmann and Alexander Kunz (Merck) moderate the panel “CSV at a turning point: Is our validation ready for digital reality?”

If you are asking yourself which role you play in this network and how your own governance stands up to the audit question, that is a conversation we are glad to have.