Fields print as blank lines; the document-control table prints on page 1.
OrchestraPrime · AI in GxP template pack · T1 — AI Use Intake & GxP Assessment · v1.0 public edition · 2026-09-23 · https://orchestraprime.ai/ux/ai-validation-gxp/templates/t1-ai-use-intake.html
OrchestraPrime · AI in GxP template pack · T1 of T1–T10
Decide, at intake, whether an AI function is GxP-relevant, how critical it is, which validation posture applies, and which downstream deliverables are required.
When in the lifecycle
Intake. The first record in the AI lifecycle: complete it before any build, purchase, or "switch on the vendor feature" decision, and re-run it when the intended use changes. Control 8.1 of the eight lifecycle controls (AI GxP assessment). Its outputs, the risk tier and the validation posture, are inherited by every later template.
Who owns it
Business owner and system owner complete it; Quality / CSV reviews and approves; the Data Protection Officer signs when personal data is in scope.
Validate the controls around the model for a specific context of use, not the model in the abstract.
We do not validate "the model" in the abstract. We validate the controls around the model, fitted to a specific use-case and context of use. This intake defines that use-case and context of use, and every later template inherits from it.
Practitioner template, provided as-is. Adapt to your QMS, SOPs and risk method; it is not a substitute for your quality unit's approval. Worked-example values are illustrative. This template refers to the other templates in the pack by ID (T1–T10); T1, T2 and T8 are free on this site, the other seven are available on request.
Document Control
Field
Entry
Document ID
T1-AI-XXXX
Version
0.1
AI function / agent name
name
Registry / inventory ID
e.g., mfg.cpv.signal-agent
Host system (product / platform)
system name, version
Business owner (role)
role
System owner (role)
role
Quality / CSV reviewer
role
Date of intake
YYYY-MM-DD
Approvals
Role
Name
Signature
Date
Business owner
name
e-signature
date
System owner
name
e-signature
date
Quality / CSV
name
e-signature
date
Data Protection Officer (if personal data is in scope)
name
e-signature
date
Revision History
Version
Date
Author
Change summary
0.1
date
author
Initial intake
Instructions
1. Description of the AI Use
Field
Entry
Business process supported
e.g., Continued Process Verification, CSR authoring, deviation triage
idea / lab / candidate / production / already in use (retrospective)
2. GxP Relevance
#
Question
Answer (Y/N/Unknown)
Rationale / evidence
2.1
Does the AI output influence a GxP decision (GMP, GCP, GLP, GVP, GDP)?
2.2
Does the output become, or feed, a GxP record (Part 11 / Annex 11)?
2.3
Could an AI error affect patient safety, product quality, or data integrity?
2.4
Does the AI process personal data, including health data, subject data, or HCP data?
2.5
Does the output support a regulatory submission or regulatory decision-making?
3. Criticality (draft EU GMP Annex 22 §1)
#
Question
Answer
Rationale
3.1
Does the AI have a direct impact on patient safety, product quality, or data integrity (e.g., it decides accept/reject, release, or disposition without an independent check)?
Y/N
3.2
If a human is in the loop, is the human's review independent and effective, i.e., able to detect AI errors, not rubber-stamping?
Y/N/Not yet demonstrated
evidence: challenge-test result, or planned in T6
3.3
Classification
Critical / Non-critical with HITL / Non-GxP
4. Model Characteristics
#
Question
Answer
Consequence
4.1
Is behavior learned from data (ML/AI) rather than explicitly programmed?
Y/N
If N, this is conventional software. Use standard CSV/CSA and this template ends at Section 8
4.2
Static (frozen after release) or dynamic (learns in use)?
Static/Dynamic
Dynamic models: not for critical GMP use (Annex 22 §1)
4.3
Deterministic (identical input → identical output) or probabilistic?
Det./Prob.
Probabilistic models, including generative AI and LLMs: not for critical GMP use (Annex 22 §1)
Does it call tools or act across multiple steps (agentic)?
Y/N
If Y, T6 must include trajectory, tool-allowlist, and red-team tests
4.6
Does it depend on a third-party foundation model?
Y/N; vendor, model, pinning
Vendor model change becomes a planned change (T2 failure mode FM-12)
5. Validation Posture and Regulatory Frame
5.1 Posture (dual-path)
Option
Definition
Select
Pattern A: non-critical with HITL
AI drafts, summarises, or recommends. A qualified human decides and signs. Validate the system of controls: grounding, checker, human review, audit trail
Pattern B: deterministic core
The critical decision is made by deterministic or static components validated conventionally. The AI orchestrates and explains
Annex 22 critical use
A static, deterministic ML model is used in a critical GMP application. Full Annex 22 §3–10 applies
Not permitted as proposed
Dynamic or probabilistic model proposed for a critical GMP decision. Redesign as Pattern A or B
5.2 Applicable frames (select all that apply)
Frame
Applies?
Note
EU GMP Annex 11 / 21 CFR Part 11
Computerised system and electronic records
Draft EU GMP Annex 22 (AI)
Critical GMP use of static, deterministic ML; principles "may be considered" for non-critical use
FDA draft guidance (Jan 2025), AI to support regulatory decision-making
Seven-step credibility framework; context of use; model risk
GAMP 5 2nd Ed. + ISPE GAMP Guide: AI (2025)
Lifecycle and risk-based approach
FDA CSA (final Sep 2025)
Risk-based assurance. Device scope; applied to pharma by analogy
ICH E6(R3) / GCP
Clinical trial systems
ICH Q9(R1)
Quality risk management method (used in T2)
EU AI Act (high-risk classification)
Apply the classify-up policy where the use touches trial participants, safety, or profiling
GDPR (DPIA, Art. 22)
If personal data is in scope
6. Component Decomposition (multi-component systems and agents)
7. Vendor AI Features in SaaS (complete for any vendor-embedded AI)
#
Question
Vendor response / evidence
7.1
Which AI feature, in which release? Is it enabled by default?
7.2
Can the feature be switched off per tenant or per module?
7.3
Is a model card or intended-use statement available?
7.4
Is customer data used to train shared models? Can this be opted out?
7.5
What test evidence exists (metrics, test-set independence, subgroups)?
7.6
What is the model-change notification policy (advance notice, release notes, version IDs)?
7.7
Does the audit trail record that AI contributed (output, version, confidence, user action)?
7.8
Is the quality agreement updated with AI clauses?
Y/N; reference
7.9
Decision
Enable / Enable with restrictions / Keep disabled pending assessment
8. Decision Logic and Risk Tier
Is the use GxP (Section 2)?
├─ NO ─────────────────────────────────────────────► TIER 1 (register + acceptable-use SOP)
└─ YES
Is it an authoring aid whose output a qualified human reviews
and approves as a controlled record (Q5)?
├─ YES ───────────────────────────────────────► TIER 1 (register + AI-assisted authoring SOP)
└─ NO
Is it critical (Section 3.3)?
├─ NO (non-critical, HITL) ──────────────► TIER 2 (Pattern A)
└─ YES
Is every critical-decision component static AND deterministic (Section 4/6)?
├─ YES ─────────────────────────────► TIER 3 (Annex 22 / Pattern B)
└─ NO ──────────────────────────────► NOT PERMITTED AS PROPOSED
→ redesign to Pattern A or B, re-run T1
Appendix A — Worked Example: UC-M2 CPV Signal Agent (illustrative)Illustrative worked example
Section 1. Decision: "Has the validated process drifted, and which scientist needs to look today?" The agent monitors all CPPs/CQAs nightly and raises signals with a chart, the affected batches, and a named scientist. Human role: the process scientist dispositions each signal (confirmed / benign / investigate). Source: built in-house on the enterprise platform. Status: candidate.
Section 2. GxP = Yes (GMP; FDA PV Stage 3, Annex 15 OPV). The signal disposition is a regulated record (Part 11). Personal data = No. Regulatory submission = No.
Section 3. Critical = Yes. A missed drift can lead to an out-of-trend batch being released without investigation.
Section 6. Component decomposition
Component
Function
Learned?
Static/Dyn.
Det./Prob.
Critical?
Posture
Approach
C1 SPC / capability engine
Shewhart, CUSUM, EWMA; Nelson rules; Cpk/Ppk
No
n/a
Det.
Yes
GAMP 5 Cat 5
IQ/OQ/PQ against reference calculations
C2 MSPC model
PCA; Hotelling T² and Q-residual vs. NOC set
Yes
Static
Det.
Yes
Annex 22
Analytical-method lifecycle: NOC set, held-out detection test, QA approval in model registry
C3 Narrative LLM
Explains the signal in plain language
Yes
Static (pinned)
Prob.
No (HITL)
Pattern A
Grounding + checker numeric-consistency rule + human disposition
C4 Orchestrator
De-duplicates, prioritises, routes
No
n/a
Det.
Yes
GAMP 5 Cat 5
Deterministic control flow; OQ on routing rules
Section 5. Postures: Pattern B overall (critical decision made by C1 and C2); C3 under Pattern A. Frames: Annex 11/Part 11, draft Annex 22 (C2), GAMP 5 + GAMP AI Guide, ICH Q9(R1).
Section 8. Tier 3. Every component on the critical decision path is static and deterministic, so the use is permitted. Full deliverable set required. Periodic review aligned to the product APQR cycle.
This is one of ten templates.
The full pack — intake, risk, context of use, data management, design spec, validation plan, summary report, monitoring plan, predetermined change control and periodic review — is available on request.