This is a ready-to-use training curriculum matrix for the roles an AI program either creates outright (AI steward, AI risk officer) or changes the content of (an operational reviewer now supervises a model, not just a process). It complements a general role-based training matrix by going one layer deeper: for each AI-adjacent role, it names what the person must be able to do, not just what document they must read, and requires an applied judgment assessment wherever a mistake could let a model error through uncaught. Replace every <<FILL: ...>> placeholder, map the generic roles and curriculum items to your real titles and document numbers, and route it through document control. A worked filled specimen follows the template. Verify each cited regulation against the current source before you rely on it.
Document control header
| Field | Entry |
|---|---|
| Document title | AI-Adjacent Role Training and Competency Curriculum |
| Document number | <<FILL: MTX-ID, e.g. MTX-QA-019>> |
| Version | <<FILL: version, e.g. 1.0>> |
| Effective date | <<FILL: effective date>> |
| Document owner | <<FILL: role, e.g. Training Lead / AI Risk Officer>> |
| Applies to | <<FILL: sites / functions / AI use cases in scope>> |
| Parent SOP | <<FILL: SOP-ID for training and qualification>> |
| Managed in | <<FILL: LMS name and validation reference, or "paper matrix">> |
How to read this matrix
Each AI-adjacent role has a defined curriculum. Every item carries two attributes:
- R, Read-and-understand: the trainee reads and signs an acknowledgement. Appropriate for awareness-only content, for example a policy statement or a high-level AI concept the role does not have to apply under pressure.
- A, Assessed competency: the trainee demonstrates the skill against a defined standard before being released to work unsupervised. Appropriate wherever a mistake could let an AI error reach a record or a decision uncaught, which for AI-adjacent roles is most of the curriculum. Evidence is a graded case-based assessment or a qualified-trainer sign-off, not a signature alone.
Two dates govern every assignment: an initial due date tied to an event (before first unsupervised use, not a fixed calendar date), and a refresher interval with defined triggers that force an out-of-cycle retrain: a material model retrain, a new discovered failure mode, a related deviation, or a role change. A model retrain resets the clock for every role whose curriculum names that model, the same way a document revision resets read-and-understand training in a conventional GxP curriculum.
Roles
Map each generic role to your real title. These roles are defined in workforce and organizational readiness for AI in quality; add or remove roles to fit your organization.
| Code | Generic role | Your title |
|---|---|---|
| REV | Operational reviewer (human-in-the-loop) | <<FILL>> |
| SUP | Human-on-the-loop supervisor | <<FILL>> |
| MO | Model owner | <<FILL>> |
| AIS | AI steward | <<FILL>> |
| ARO | AI risk officer | <<FILL>> |
| CIT | Citizen developer | <<FILL>> |
| DS | Data scientist / ML engineer | <<FILL>> |
| LDR | Senior leader / sponsor | <<FILL>> |
Curriculum matrix
Cells use R or A. A blank cell means the role does not need that item.
Foundation curriculum (all AI-adjacent roles)
| Curriculum item | REV | SUP | MO | AIS | ARO | CIT | DS | LDR | Initial due | Refresher |
|---|---|---|---|---|---|---|---|---|---|---|
<<FILL: AI and data literacy foundations, e.g. TRN-101>> | A | A | A | A | A | A | R | R | Before any AI-related task | Annual |
<<FILL: AI governance policy and register, e.g. SOP-QA-030>> | R | R | A | A | A | A | A | R | Before any AI-related task | Annual |
<<FILL: Automation bias and over-trust awareness, e.g. TRN-102>> | A | A | R | A | R | R | R | A | Before any AI-related task | Every 2 years |
Role-specific curriculum
| Curriculum item | REV | SUP | MO | AIS | ARO | CIT | DS | LDR | Initial due | Refresher |
|---|---|---|---|---|---|---|---|---|---|---|
<<FILL: This model's known failure modes and case-based recognition, e.g. TRN-201>> | A | A | Before independent review of this model | On material model change | ||||||
<<FILL: Reading aggregate performance, drift, and sampling protocol, e.g. TRN-202>> | A | A | Before independent supervision of this model | On material model change | ||||||
<<FILL: Intended-use definition and risk tiering, e.g. SOP-QA-031>> | A | A | A | R | C | R | Before defining or approving a new use case | Every 2 years | ||
<<FILL: AI validation and change-control lifecycle, e.g. SOP-VAL-014>> | R | A | A | A | Before owning a lifecycle deliverable | On revision | ||||
<<FILL: Citizen-development guardrails and sanctioned platform use, e.g. SOP-QA-032>> | A | Before building any GxP-adjacent tool | Annual | |||||||
<<FILL: Training-data integrity and labeling quality, e.g. SOP-QA-033>> | C | A | Before contributing to a training dataset | Every 2 years | ||||||
<<FILL: Portfolio risk tiering and escalation, e.g. SOP-QA-034>> | A | Before independent risk-tiering decisions | Annual |
(C above denotes consulted-level awareness only where a full curriculum item is not warranted; convert to R or A if your program does not use an awareness tier.)
Read-and-understand versus assessed competency, for AI-adjacent roles
| Use read-and-understand (R) when | Use assessed competency (A) when |
|---|---|
| The content is a policy or governance structure the role must be aware of but does not personally execute | The role reviews, approves, or supervises an AI output where a missed error could reach a record or decision |
| The role is informed of AI activity but has no operational task | The role sets or approves a risk tier, an intended-use statement, or a release decision |
| A senior leader needs enough grounding to sponsor and not undermine the controls | A citizen developer will build something that could touch GxP data or a GxP decision |
Acceptance criteria
This matrix is being used correctly when:
- Every person performing an AI-adjacent role has a recorded, complete curriculum for that role, dated before they performed the task unsupervised.
- Every assessed competency item has evidence beyond a signature: a graded case-based result or a qualified-trainer sign-off.
- A material model retrain or a newly discovered failure mode re-triggers the model-specific items for every role assigned them, and the prior record does not carry forward unchanged.
- The matrix matches the live AI register and the AI lifecycle RACI, and is reviewed when either changes.
References
21 CFR 211.25 (personnel qualifications, including continuing training) and EU GMP EudraLex Volume 4, Part I, Chapter 2 (personnel and training). ICH Q10, Pharmaceutical Quality System, on training and knowledge management as system enablers. FDA guidance, “Data Integrity and Compliance With Drug CGMP: Questions and Answers” (December 2018), on training as a control supporting reliable records, extended here to AI-supervising judgment. 21 CFR Part 11 and EU GMP Annex 11, on training records as electronic records where an LMS is used.
Confirm the current version and clause numbers of each reference before issue.
Revision history
| Version | Date | Author | Summary of change |
|---|---|---|---|
<<FILL: 1.0>> | <<FILL: date>> | <<FILL: author>> | Initial issue. |
Approvals
| Role | Name | Signature | Date |
|---|---|---|---|
| Author | <<FILL>> | ||
| Reviewer (QA) | <<FILL>> | ||
| Approver (Quality Head) | <<FILL>> |
Filled specimen
The following shows the role mapping and a completed curriculum slice for an illustrative QC data review AI-assist reviewer at a mid-size biologics company. Titles, document numbers, and dates are illustrative; replace them with your own.
Role mapping as adopted:
| Code | Generic role | Title at this company |
|---|---|---|
| REV | Operational reviewer | QC Analyst II, Release Testing |
| AIS | AI steward | Senior Quality Systems Specialist |
| ARO | AI risk officer | Associate Director, Digital Quality |
Completed curriculum for the QC Analyst II role (extract):
| Curriculum item | Document and version | R or A | Initial due | Completed | Refresher | Next due |
|---|---|---|---|---|---|---|
| AI and data literacy foundations | TRN-101 v2 | A (scenario-based test, 80% pass) | Before any AI-related task | 03 Mar 2026 | Annual | 03 Mar 2027 |
| AI governance policy and register | SOP-QA-030 v3 | R | Before any AI-related task | 03 Mar 2026 | Annual | 03 Mar 2027 |
| Automation bias and over-trust awareness | TRN-102 v1 | A (case discussion, facilitator sign-off) | Before any AI-related task | 04 Mar 2026 | Every 2 years | 04 Mar 2028 |
| QC data review model failure modes and recognition | TRN-201 v4 | A (twelve historical misflags, trainee must catch the safety-relevant ones) | Before independent review of this model | 18 Mar 2026 | On material model change | Event-driven |
In this example the analyst was released to review the model’s flags independently only after passing the case-based assessment on TRN-201, which used twelve real historical results the model had gotten wrong, including the assay’s known low-end blind spot. When the model was retrained in Q3 2026 with an updated data cut, TRN-201 was reissued as v5 and every assigned reviewer, including this analyst, was retrained on the new failure-mode set before continuing to review live results; the v4 record did not carry forward. That sequence, event-driven retrain tied to the model version rather than the calendar, is what an inspector expects to see when the underlying system the person supervises has changed.
Common inspection findings this matrix prevents
- A reviewer’s AI training record predates a material model retrain, and nothing shows they were retrained on the new failure modes before continuing to review.
- An AI steward or AI risk officer has no defined curriculum at all, because the role is new enough that training was never formally assigned.
- High-consequence AI-adjacent tasks (setting a risk tier, approving a release) are signed off as read-and-understand with no evidence of assessed competency.
- A citizen developer built a GxP-adjacent tool with no record of guardrail training, so the shadow-AI risk cannot be ruled out.
- The training matrix lists roles that no longer exist and omits current AI-adjacent staff, so completeness cannot be demonstrated.
How to adapt this matrix
- Set your document number, owner, and effective date in the header, and link your parent training procedure and LMS validation reference.
- Map every generic role code to a real title, consistent with the roles named in your AI lifecycle roles RACI.
- Replace each generic curriculum code with your real document number and current version, and delete items that do not apply.
- Set R or A for every populated cell by consequence, keeping every review, approval, or risk-tiering task an assessed competency.
- Define the event triggers (model retrain, new failure mode, role change) that force re-training outside the normal refresher cadence, and wire them to your change-control process so a model change automatically flags the affected curricula.
- Reconcile the matrix against the live AI register on a defined cadence, and confirm every regulation in the references against the current published version before issue.