Skip to content

Compliance and trust

Trust is architectural, not a marketing word

What the software is allowed to draft, what a human must sign, and what the audit trail records. Here is how each is built in, and how we prove it.

7
Controls in every app

Audit trail to human approval

6
Frameworks mapped

Part 11 to the FDA AI draft

9
ALCOA+ principles

Each with its mechanism

0
Signatures by software

Ever

Regulation to control

Six frameworks. Seven controls. One platform.

What each regulation asks of a system, and the built-in control that answers it.

RegulationWhat it asks forAudit trailE-signaturesAccess controlData at sourceVersioningValidation packHuman approval
Trustworthy electronic records and signatures
Computerised systems under GMP control
Method validation structure and traceability
Data integrity through the record lifecycle
Risk-based validation of the software
Context of use, credibility, human oversight

21 CFR Part 11 is met by 5 built-in controls: audit trail, e-signatures, access control, versioning, validation pack.

Pick a regulation to hold it. A tick means the control is the mechanism, not a policy.

Follow one record

The life of an AI-drafted protocol

Drafted by the Digital Scientist, edited and signed by people, locked by the system. Every step in the audit trail.

One record · Protocol VAL-2026-031, assay by HPLC

Quickflow MVS · VAL-2026-031 · Protocol

v1.0
MOA-0417 rev 3 PT-ASSAY-HPLC v7
Specificity
Linearity range
Accuracy
Precision

Audit trail

Read-only

Step 1 of 5Digital Scientistv1.0

Drafted

Protocol VAL-2026-031 generated from MOA-0417 rev 3 and template PT-ASSAY-HPLC v7.

Data integrity

ALCOA+, principle by principle

Nine principles, each with the mechanism that meets it. Tap one.

Attributable

Every entry carries a unique user, or the Digital Scientist as a named actor with its human approver.

On the record

Pick a principle to hold it.

Electronic signatures

Six components, bound to one version

A Part 11 signature is not a checkbox. It carries who, what it means, when, why, which version, and how the signer proved who they were. It cannot be moved to another record.

  • Two-component authentication at the moment of signing
  • Meaning chosen from a controlled list
  • Signature and record version sealed together
  • Manifested on every printed and exported copy
Electronic signature manifestation21 CFR Part 11 · Subpart C
Signer
Rohan Mehta

Printed name, unique user ID

Meaning
Approved

Review, approval, authorship or responsibility

Date and time
24 Sep 2026 09:16:40 IST

System clock, not the user

Reason
Protocol ready for execution

Captured with the signature

Record
VAL-2026-031 v1.1

Signature bound to this version

Authentication
User ID + password

Two components, re-entered at signing

Linked to the record. Cannot be copied to another. Signed
The six components of an electronic signature record: signer, meaning, date and time, reason, the record version it is bound to, and the authentication method. An attempt to apply it to another record is refused.

AI in a GxP environment

The Digital Scientist reasons. The scientist approves.

A Digital Scientist owns the science, and the evidence to defend it.

That is the whole governance model. Everything else on this page exists to make it verifiable.

  1. AI draftsfrom MOA and template
  2. Version recordedaudit trail entry
  3. Scientist reviewsedits in the editor
  4. E-signaturemeaning, date, time
  5. Locked recordinspection-ready
  • Explainable

    Every drafted section traces to its inputs

  • Template-governed

    Templates promoted Dev to QA to Prod on approval

  • Never a signer

    Approval and release are human-only gates

What your CSV team receives

The validation package, before you ask

GAMP 5 category 4, assured the CSA way: effort scaled to risk, evidence where it matters.

  • Validation plan and CSA rationaleScope, risk assessment and the assurance approach, scaled to intended use
  • Installation qualificationEnvironment, versions, configuration as installed
  • Operational qualificationFunctions tested against requirements, with evidence
  • Performance qualificationYour methods, your templates, your users, in your environment
  • Traceability matrixRequirements to tests to evidence, including the AI drafting function
  • Change control and release notesEvery version promoted through VMS, with what changed and why

One thread through the traceability matrix

  1. RequirementURS-014
  2. TestOQ-031
  3. EvidenceEV-031-02
  4. ApprovedQA

For IT and security

Where it runs, and who can reach it

The four questions every IT review starts with. The architecture note covers the rest.

  • Hosting

    On AWS. Mumbai (ap-south-1) by default, or the region your data-residency rules require.

  • AI models

    Served through Amazon Bedrock in the same region. Your data is never used to train models.

  • Sign-in and access

    Single sign-on with Active Directory, role-based permissions and unique users in every application.

  • Change control

    Model, configuration and application versions promoted Dev to QA to Prod, only on approval.

Questions QA, CSV and IT ask

Straight answers

Is the AI output explainable?

Yes. Drafts are generated from your method of analysis, specifications and approved templates, and each generated section can be traced to its inputs. That is what makes review by a scientist practical rather than ceremonial.

Does any data leave our environment to train models?

No. The AI models run on Amazon Bedrock in the same AWS region as your deployment, and neither Quickflow nor the model providers use your prompts, records or results to train models.

What does the audit trail capture?

Who did what, when, from where, the previous and new value, and the reason for change where the workflow requires one. Read-only, retained with the record, exportable for inspection.

Can the AI approve, release or sign anything?

No. Approval, release and signature are workflow gates that only a named person can pass, and the system enforces it. The AI is an actor in the audit trail, never a signer.

Who is responsible for the validation documents the AI drafts?

Your CSV team. The platform drafts the URS, risk assessment, specifications, qualification scripts and traceability matrix as the application is built; your reviewers edit, approve and e-sign each one. Nothing is released on a draft.

How is a change to the AI model controlled?

The model and its configuration are part of the validated release. Changing either is a change like any other: tested, documented and promoted from development to quality to production through the Version Management System, only on approval. Calculations run in validated code and never depend on the model.

Where is it hosted, and can we choose the region?

Quickflow runs on AWS. The default region is Mumbai (ap-south-1); where your data-residency rules call for another region, the applications and the AI models are deployed there instead.

How are SSO, network and tenancy handled?

Users sign in through single sign-on with Active Directory, with role-based permissions on top. Network design, tenancy and integration details are set out in an architecture note shared with your IT and infrastructure team during evaluation.

Put the audit trail in front of the people who will inspect it.

The fastest way to evaluate a regulated system is a live record, a validation package and a signature workflow, reviewed by QA and IT together.