GxP AI

What Inspectors Ask About AI: 14 Questions and How to Answer Them

The questions regulators are actually asking about AI in GxP environments, what a good answer contains, what a weak answer sounds like, and the evidence you need on hand before the inspection.

2026-09-20Cybroscape Technologies12 min read
Key takeaway

The questions regulators are actually asking about AI in GxP environments, what a good answer contains, what a weak answer sounds like, and the evidence you need on hand before the inspection.

Inspectors are not hostile to AI. They are, correctly, indifferent to it — their question is not "are you using AI" but "can you demonstrate this system does what you claim, and that a qualified person remains accountable for the decision". Teams that prepare for the first question are unprepared for the second.

Below are the questions regulators are asking about AI in regulated environments, what a strong answer contains, and what a weak answer sounds like. They are drawn from the expectations set out in EU GMP Annex 22, Annex 11, 21 CFR Part 11 and published inspection practice. For the underlying framework see GxP AI.

On scope and control

1. Where is AI used in your GxP processes?

Strong: a current inventory naming each use, the process it supports, its GxP impact rating, and its validation status. Weak: an answer that begins by describing a product rather than a list of uses. If you cannot enumerate it, you do not control it.

2. What decisions does the AI make?

This question contains a trap and the correct answer is usually "none". AI drafts, classifies, proposes and summarises; a qualified person decides. If any GxP-critical decision is genuinely made by the system without human approval, Annex 22 is the problem you now have to address. Be precise about the distinction — "it determines the GAMP category" and "it proposes a GAMP category which the validation lead approves or changes" are very different statements.

3. Who is accountable for the output?

A named role, defined in an SOP, with training records to match. Not a team, not a department, not the vendor.

On validation and performance

4. How was this AI validated?

Strong answers describe intended use, acceptance criteria defined before testing, an evaluation set representative of real inputs, results against those criteria, and documented limitations. Weak answers describe the vendor's testing. Their evidence may support yours; it does not replace it.

5. What is the acceptance criterion, and why that number?

The justification matters more than the figure. A criterion derived from the consequence of an error — and from what the human review step will and will not catch — is defensible. A round number with no rationale is not.

6. How do you know it still performs?

This is where most AI deployments are weakest. Point to ongoing monitoring with defined metrics, a review frequency, a threshold that triggers action, and records of those reviews having actually happened. See continuous monitoring for GxP AI.

7. What happens when the model is updated?

An update is a change and must go through change control with an impact assessment and, where warranted, revalidation. If your supplier can change model behaviour without telling you, say so plainly and explain the contractual and monitoring controls you have put around that — an inspector will respect a known risk that is managed far more than a risk you appear unaware of.

On oversight and data

8. Show me a case where the AI was wrong.

Have examples ready. A system with no recorded errors has either not been used meaningfully or is not having its errors captured — and an inspector will conclude the second. Being able to show detection, correction and the resulting adjustment is strong evidence that oversight is real.

9. How do you know reviewers are genuinely reviewing?

The automation-bias question, and the hardest to answer well. Evidence that helps: review time captured in the audit trail, modification rates showing reviewers change outputs, periodic sampling of approved items by a second reviewer, and trained competency specific to reviewing generated work.

10. What does the audit trail capture?

Input, system version, output, reviewer identity, what they changed, timestamp — tamper-evident and retained for the required period. And a follow-up you should expect: who reviews that audit trail, how often, and where is the record.

11. What data was used, and where was it processed?

Processing location, retention, and whether your regulated content contributes to model training. Covered in data privacy in GxP AI.

On resilience and competence

12. What do you do if the system is unavailable?

A documented, trained and periodically exercised fallback. A fallback procedure nobody has ever performed is a document, not a control.

13. How are people trained for this?

Training on the specific system, on its known limitations, and on what the reviewer is accountable for. General AI awareness training does not meet this. See updating SOPs and training for AI.

14. Which procedures did you change when you introduced this?

If the answer is none, the inspector now has a reason to look harder. Introducing AI changes who does what; the SOPs must show it.

How to prepare

Run these fourteen questions as an internal exercise before anyone external asks them. Have the person who would actually answer give the answer, and have someone independent judge whether the supporting evidence exists and can be retrieved in minutes.

Two habits separate teams that handle this well. The first is precise language about the boundary between proposing and deciding — imprecision there creates an Annex 22 problem out of a compliant workflow. The second is treating errors as evidence of working oversight rather than something to minimise.

The wider preparation discipline is the same as for any GxP audit: preparing for a GxP audit and maintaining continuous inspection readiness.

Where to go next

Explore GxP Copilot for AI-native validation, TraceDraft for source-traceable clinical documentation, or book a demo to see either on your own data.

ai inspection questionsfda ai inspectiongxp ai audit questionsregulator questions about aiai inspection readinessdefending ai to inspectors

Frequently Asked Questions

What do inspectors ask about AI in GxP environments?+

Their questions are not about AI as a technology but about control and accountability: where AI is used across your processes, what decisions it makes, who is accountable for output, how it was validated, how you know it still performs, what happens when the model updates, how you know reviewers genuinely review, what the audit trail captures, what happens if the system is unavailable, and which procedures you changed when you introduced it.

How should you answer 'what decisions does the AI make'?+

Usually the correct answer is 'none'. AI drafts, classifies, proposes and summarises; a qualified person decides. Be precise about the boundary — 'it determines the GAMP category' and 'it proposes a GAMP category which the validation lead approves or changes' are very different statements, and imprecision there creates an Annex 22 problem out of an otherwise compliant workflow.

Should you show inspectors cases where the AI was wrong?+

Yes, and have examples ready. A system with no recorded errors has either not been used meaningfully or is not capturing its errors, and an inspector will conclude the second. Being able to show detection, correction and the resulting adjustment is strong evidence that human oversight is real rather than ceremonial.

How do you prove reviewers are genuinely reviewing AI output?+

Evidence that helps includes review time captured in the audit trail, modification rates showing reviewers actually change outputs, periodic independent sampling of approved items by a second qualified reviewer, and training records showing competency specific to reviewing generated work. This addresses automation bias, which is the substantive risk in any human-in-the-loop design.

What if our vendor can change the model without telling us?+

Say so plainly and explain the contractual and monitoring controls you have placed around it. An inspector will respect a known risk that is actively managed far more than a risk you appear unaware of. The worst position is discovering the exposure during the inspection itself.

Next step

Bring a system. We'll show you the package.