This is a ready-to-use AI inventory built from the GxP process map rather than from a list of known data-science projects, because AI hides inside vendor features, spreadsheets, and browser plugins that nobody thought to log. It is distinct from an EU AI Act classification register (see the AI system inventory and EU AI Act classification register for that separate regulatory obligation): this register answers the GxP inspection question, does the company know everywhere a model touches a regulated decision, not the EU AI Act provider/deployer question. Replace every <<FILL: ...>> placeholder. A worked filled specimen follows the template.
Document control header
| Field | Entry |
|---|---|
| Document title | AI Inventory for GxP Inspection Readiness |
| Document number | <<FILL: reference, e.g. AII-QA-001>> |
| Version | <<FILL: version>> |
| Owner | <<FILL: role, e.g. Head of Quality / Digital Quality Lead>> |
| Review cadence | <<FILL: e.g. quarterly, and on any new tool procurement or vendor feature change>> |
1. Purpose
This inventory lists every place a model, algorithm, or automated prediction influences a GxP decision or record, so the company can put each one under control and so an inspector’s walk of any GxP process never surfaces something missing from the list. The most damaging AI inspection finding is not a weak validation; it is a model nobody told the auditor about.
2. How to build this inventory
- Start from the GxP process map, not the technology list. For each regulated process (deviation handling, complaint intake, batch review, environmental monitoring trending, document drafting, adverse event triage), ask whether any step is assisted by a model, a prediction, a ranking, a classification, or a generated draft.
- Sweep the vendor platforms. For each validated application, list its AI or ML features and whether they are enabled, including features marketed as assistants, copilots, anomaly detection, or predictive.
- Sweep the gray IT: spreadsheets, low-code tools, and analytics notebooks that score or predict, and any browser or desktop AI plugin used against regulated documents.
- For each entry, record the fields in section 3.
- Wire discovery of new AI into procurement and change control, so a newly enabled vendor feature or a newly built tool reaches this register before it goes live, not after an inspector finds it.
3. The inventory
| System / feature | GxP process(es) touched | Intended use (one sentence) | Risk class | Validation status | Owner | Last reviewed |
|---|---|---|---|---|---|---|
<<FILL: e.g. Deviation triage model>> | <<FILL>> | <<FILL>> | Advisory / Automated classification / Process control | <<FILL: Validated / In progress / Not required, rationale>> | <<FILL>> | <<FILL>> |
<<FILL: e.g. Document platform "suggested classification" feature>> | <<FILL>> | <<FILL>> | <<FILL>> | <<FILL>> | <<FILL>> | <<FILL>> |
<<FILL: e.g. Chromatography review aid, injection-ranking>> | <<FILL>> | <<FILL>> | <<FILL>> | <<FILL>> | <<FILL>> | <<FILL>> |
<<FILL: add every entry the sweep surfaces>> | <<FILL>> | <<FILL>> | <<FILL>> | <<FILL>> | <<FILL>> | <<FILL>> |
4. Risk class definitions
| Risk class | Definition | Typical control expectation |
|---|---|---|
| Advisory | A human decides; the model flags or suggests only | Real human review that samples what the model misses; monitored override rate |
| Automated classification / action | Output is acted on without per-record human review | Performance evidence on the consequential class, monitoring live from deployment, defined escalation |
| Process control | The model’s output moves a physical parameter or triggers an automated action with no human step | An engineered, deterministic safety interlock independent of the model, plus a model-specific failure mode analysis |
5. Acceptance criteria
The inventory is ready when every model influencing a GxP decision appears with an owner and a risk class, when a documented procedure catches new AI before it goes live (procurement and change control both check for it), and when a walk of any GxP process does not surface a model missing from this list. See inspection readiness for AI-enabled GxP systems for how an investigator tests this in practice.
6. References
21 CFR Part 11 and EU GMP Annex 11, for the scope of computerized systems creating or managing GxP records, which extends to any AI component of such a system. ICH Q9(R1), Quality Risk Management, for the risk-classification basis. GAMP 5, Second Edition (ISPE), for the computerized system lifecycle this inventory feeds.
Confirm the current version of each reference before issue.
7. Revision history
| Version | Date | Author | Summary of change |
|---|---|---|---|
<<FILL: 1.0>> | <<FILL: date>> | <<FILL: author>> | Initial issue. |
Filled specimen
The following shows a first-pass inventory for an example quality team, expanded from three known projects to seven entries after the process-map sweep, so you can see the level of detail expected. The systems and names are illustrative; replace them with your own.
| System / feature | GxP process | Intended use | Risk class | Validation status | Owner | Last reviewed |
|---|---|---|---|---|---|---|
| Deviation-triage model | Deviation management | Assigns a preliminary criticality tier from the free-text description to set the investigation clock | Advisory | Validated, VSR-AI-004 | QA Digital Lead | 2026-07 |
| Complaint-classifier | Complaint handling | Routes incoming complaints to product-quality vs. non-product-quality queues | Automated classification | Validated, VSR-AI-007 | Complaints Manager | 2026-07 |
| EM trend tool | Environmental monitoring | Flags out-of-trend plate counts for microbiologist review | Advisory | Validated, VSR-AI-009 | Micro Lead | 2026-06 |
| Document platform “suggested classification” (vendor feature) | Document control | Suggests a document type on upload | Advisory | Assessed, low risk, unscripted verification | Document Control Manager | 2026-08 |
| Microbiologist’s spreadsheet plate-count flagger | Environmental monitoring | Flags plate counts exceeding a coded threshold | Advisory, overlaps EM trend tool | Under assessment, duplicate function being retired | Micro Lead | 2026-08 |
| Chromatography injection-ranking aid | QC laboratory review | Ranks injections by likelihood of an integration problem | Advisory | Validated, VSR-AI-011 | QC Manager | 2026-05 |
| LLM browser plugin (analyst use) | None authorized | Was being used ad hoc to summarize investigation reports | N/A, no controlled use case | Removed, no use case approved | QA Digital Lead | 2026-08 |
Three of the four entries the sweep added beyond the three expected projects were doing real GxP work with no prior assessment, and the LLM plugin was removed outright because no controlled use case justified keeping it on the inventory.
Common inspection findings this register prevents
- No inventory at all, so the AI footprint is reconstructed live and incompletely during the inspection itself.
- An inventory that lists only deliberate AI projects and misses embedded vendor features or shadow spreadsheets doing the same work.
- A model on the inventory with no named owner or no risk class, which reads as a list rather than a governed record.
- New AI reaching production with no procurement or change-control gate that would have caught it before go-live.
How to adapt this register
- Set the owner and review cadence in the header; an inventory nobody owns goes stale within a quarter.
- Run the four-step sweep in section 2 for every GxP process at your site, not just the ones already known to use AI.
- Add a column for your organization’s specific obligations if needed (an EU AI Act cross-reference number, a device-software risk class for a combination product).
- Wire this register’s update trigger into procurement and change control so it is a live control, not a periodic paperwork exercise.