Skip to main content Skip to search Skip to main navigation

Applying the FDA’s 7-Step Model for AI/ML Validation in GMP Environments: One Year Later

10 min. reading time | by Dr. Ulrich Köllisch (Managing Director & Principal Consultant, umk consulting GmbH), Dr. Jennifer Roebber (Senior Consultant, GxP-CC)
Published in LOGFILE 18/2026 

Artificial intelligence is becoming increasingly important in GMP-regulated environments, presenting companies with new regulatory challenges. This article summarizes the latest regulatory developments, introduces a validation framework based on the FDA's seven-step model, and outlines initial practical experience with AI/ML validation.


Overview

Artificial Intelligence has become the singular, titular buzzword within all businesses, with immense pressure to implement faster, smarter and more efficient processes. This pressure is also applicable in GMP regulated environments. However, we also see the opposing push, with a worldview that AI/ML systems are just not possible to validate and control in a compliant way. The last two to three years have been a ‘wild west’ of new projects implemented and changes in regulatory guidelines and best practices approaches. In this article we will take a look back on the latest regulatory developments, propose a validation framework for AI/ML subsystems which is guided by FDA’s 7 step approach published early last year [1] and share some lessons learned from our first real-life AI/ML validation projects.


AI/ML Systems: Characteristics and Validation Challenges

One big surprise over the past year has been the diversity of AI/ML tools and systems that have emerged. We have seen projects that process all kinds of data—from images and text to entire data lakes—and models that exhibit varying degrees of autonomy and human interaction. AI/ML is always a software subsystem [6] within a computer system framework, or embedded within a piece of equipment, and not a standalone piece divorced from existing systems. In this sense, AI/ML validation approaches often resemble an extension of existing frameworks (e.g., the CSV framework) rather than an entirely new paradigm. On the other hand, these projects all bring new challenges not seen in existing ‘traditional’ tools: we need to expand and re-think specifics of data integrity, testing, and monitoring and apply the new regulatory guidelines that define the specialties for AI/ML such as: 

  • Limited explainability (“black box” behavior): 
    It is often more difficult to explain the behavior of AI/ML models depending on the complexity of the model and transparency of the supplier.
  • Probabilistic models: 
    AI/ML models can operate in a probabilistic way, that means the same input does not lead to the same output in repeated operation. This is not the case for all AI/ML models!
  • Dynamic models: 
    AI/ML models might be dynamic, that means that the models change over time with provided data and feedback. This is not the case for all AI/ML models!


Regulations and Guidelines 

First on the stage, the FDA released their draft guidance in January 2025 [1], which introduces a shift in validation concepts and nomenclature. Instead of using the term ‘validation’ the FDA has picked up the more humanist term of ‘credibility’ or simply ‘establishing trust’ for their new framework. It is comprised of a 7-step process for establishing credibility based on risk. Interestingly, the process is very generalist; it has no special provisions for complex AI systems such as Generative AI and emphasizes credibility within a narrow context of use and descriptive documentation to cover system risks. In implementation, the approach lends an overall familiar quality assurance approach but lacks some detail and nuance in specific scenarios and risk assessment complexity.

We see a different focus in the draft guidelines from the EMA: Just 6 months after the FDA published their framework, the EMA released the new Annex 22 Draft [4] – a completely new annex on just AI. Their approach differs from the FDA being more prescriptive. In this initial draft, different AI systems are scoped from the very beginning: For critical GMP applications, probabilistic and dynamic models are out of scope. Probabilistic models include Generative AI which covers all large language models. The logic on this is clear: these systems violate change control and testing principles and will require a more nuanced approach with high level of expert review. For now, the EMA feels that these risks are too great to allow for in critical cases but indicated that updates to this thinking are possible with the revision of the draft. 

Despite these variable approaches, regulatory bodies have emphasized repeatedly their positive perspective towards implementation of new technology in general, and AI and machine learning systems specifically. From the FDA, we see publications on the implementation of AI platform use for agency efficiency in the ELSA 4.0 application [11]. This is very fitting to the FDA’s overall CGMP requirement [9] emphasizing that current technologies should be used to improve process quality. 

Figure 1  | AI-specific regulatory guidelines are supported by industry standard current best practices. AI policies are derived from quality framework principles that are longstanding in the industry. 


Validation Concept

One common theme across guidelines, as well as the wealth of best industry practices that have been published since (see citations, Figure 1) is that AI/ML subsystem validation is best started using a modified risk framework approach.

Our understanding of the underlying risk management is that instead of examining every possible system permutation and searching for explicit regulatory statements, it is better to use guiding star principles. One such favorite is the Annex 11 [2] (recently re-iterated in the revision [3]) statement that “when a system is computerized or updated – there should be no increase in the overall risk of the process”. We combine this with the ICH Q9 (R1) [5] system for identifying and handling risks:

  • Identify hazards within the process first, then assess, evaluate, and mitigate risks
  • Once this is complete, it is much more straightforward to make a transparent risk decision based on product quality, patient safety, and product availability.
  • Identify and assess the risks which are specifically introduced by the use of an AI/ML subsystem (within your existing risk management process). 

As AI/ML subsystems are integrated into larger computerized systems, we recommend embedding AI/ML validation processes into existing procedures on CSV rather than developing a segregated ‘AI-specific’ policy. Regardless of size, the AI system is always embedded in a larger operating environment and interacts with other software, hardware, people and procedures. As we know from ICH Q9, Annex 11/15, and EU GMP Chapter 4 (Documentation), the larger and often less obvious risks come from interactions between systems, procedures, and people. An integrated policy manages these interactions more effectively. 

Figure 2 | 7-step approach to establishing credibility using the FDA’s model. 


Run Through the 7 Steps 

Figure 2 shows the 7-step approach that is proposed by the FDA to establish credibility in models in an adoption with our proposed framework, mapping the seven steps to three documents: High Level Risk Assessment (HLRA), Credibility Assessment Plan (CAP) and Credibility Assessment Report (CAR). After one year of applying this model to actual validation projects we find the following takeaways:

  • The High-level Risk Assessment (The Funnel in the above diagram): It is advisable to combine the first three steps of the FDA process into one document. The purpose of this is to determine very early in the validation process if the use case is acceptable at all and to determine the overall validation effort based on the identified risk classification. It can be utilized to determine if the scope is too broad, or the model too risky, before over-committing to a particular scenario. However, even for a very high-level check, we find that the FDA’s risk category approach is too simplistic: most models fall into a poorly defined ‘medium risk’ category with no clear next steps. We find that process and data flow mapping are a prerequisite for any meaningful risk assessment. This helps to foster a common understanding of the intended use (= the question of interest and the context of use). In general, a combination of the criticality of the proposed intended use with the vulnerability of the model (see Figure 2) is required to understand the overall risk. This approach identifies higher risk categories for some models (e.g. probabilistic/dynamic models) and demonstrates where the risk arises from. For example, a model with high vulnerability arising from a dynamic model could be mitigated with more model review and lower autonomy. A similar approach is presented in [8] and [6]. As a full development dataset might need to be curated at the beginning of the project and the context of use (e.g., the degree of human interaction) might not be set in stone, the planning and project phase are iterative/agile by nature for AI/ML subsystems.
  • The Credibility Assessment Plan: The purpose of this step is to create a plan and document how the model does (or does not) address risk questions specific to AI/ML subsystems. Within the regulatory guidelines, the FDA and EMA respectively list chapters of model-specific topics to consider, these requirements and scenarios can be incorporated into a checklist. In application, we find that this step is best applied as an exercise with a multi-disciplinary team including technical suppliers (if applicable) and discuss what aspects are relevant to the project in scope. The CAP can be sorted according to the life cycle steps of the AI/ML subsystem and provides an excellent roadmap to identify, assess and explain hazards and their related risks to different stakeholders and to inspectors and auditors. The results feed into the validation project and influence different documents: In particular the URS and the functional risk assessment and from there the requirements, hazards and related risks are controlled in the ‘regular’ validation project. Again an iterative approach has proven most benefit in real life application as not all information relevant for the CAP might be available upfront. The implementation design might need to be changed as a result of an initial credibility assessment (e.g., selection of a technical supplier; addition of guardrails and monitoring concepts to secure stringent operation).
  • The Credibility Assessment Report: The purpose of this step is to document the performed actions (e.g., design decisions, testing and procedural controls) vs the planned activities stated in the CAP. Because of this, validation activities occur between the CAP and the CAR, and the report is usually completed very late in the project, before the validation report is closed. We find that this step usually acts as a final check: any deviations from the CAP need to be managed by the QMS.
  • The last step of the FDA guideline is the determination of adequacy: Is the AI model credible for the intended use? This can either be answered directly in the CAP or formally be incorporated into the validation report. 


Lessons Learned 

In the application of this seven-step model, we find the following main lessons learned:

User requirements:

  • Have your requirements ready early: What are the categories where the system needs to deliver measurable improvement? What are the required thresholds for business? If the overall risk cannot be increased (according to Annex 11), the URS must show an improvement (or at least the same level) versus existing values. Decision for purchasing, design and validation cannot be taken when those numbers are not available from the beginning.
  • Machine learning models are ‘only’ mathematical models and cannot be perfect. There is always a tradeoff – should the URS be erring on high stringency, or would that make the business case non-feasible (e.g., too high false reject rates in visual inspection)?

Human review/sub-review is a very common mitigation measure, but

  • Is human review really possible and reasonable in the use-case? (e.g., high throughput)
  • Is it likely for the human machine team to work better together at all? For example: Well formulated and reasonable sounding outputs from LLMs – which are wrong or incomplete: Will a human really catch this error

Supplier management:

  • Early interaction with suppliers is key to understanding the options, their product and the models in use. Early interaction helps inform the decision for the right supplier and the right product. Question the supplier on their claims, e.g. with challenging test cases.
  • Involve suppliers in CAP development and include dedicated questions into audits or supplier review.

AI/ML Training

  • QA must be upskilled in AI/ML basics to enable adequate risk-based decision making. Risk scenarios and categories are changed within AI/ML subsystems to have much higher data focus and an enhanced importance of data governance and data management.
  • In case of uncertainty, the regulatory bodies (especially FDA) emphasize that companies should reach out, even early in the process, to discuss the project. 


Conclusion

In conclusion, within a continuously evolving regulatory landscape, we find that AI/ML subsystem validation has been successfully implemented and inspected using a combination of backbones of well-known validation principles in Annex 11 and ICH Q9 in combination with dedicated documentation for the AI/ML subsystem and its related risks. Interaction in multidisciplinary teams, and training of stakeholders such as teaching QA AI/ML principles and teaching data scientists QA and CSV principles has been key for successful implementation. 


References

[1] Considerations for the Use of Artificial Intelligence To Support Regulatory Decision-Making for Drug and Biological Products; FDA; 2025

[2] Eudralex Volume 4 Good Manufacturing Practice Medicinal Products for Human and Veterinary Use; Annex 11 Computerised Systems; 2011

[3] Draft Guidelines: Revised Annex 11 – Computerised Systems; EMA; 2025

[4] Draft Guidelines: New Annex 22 – Artificial Intelligence; EMA; 2025

[5] ICH Q9 (Revision 1) Quality Risk Management; ICH; 2023

[6] ISPE GAMP® AI Guide; ISPE; 2025

[7] VDI/VDE-EE3516 Blatt 7: Validation in GxP area - Usage of machine learning methods in pharmaceutical industry; VDI; 2024

[8] Blumenthal et al.; Machine Learning Risk and Control Framework; Pharmaceutical Engineering, 2024

[9] Facts About the Current Good Manufacturing Practice (CGMP); FDA; 2025

[10] Guiding Principles of Good AI Practice in Drug Development; FDA/EMA; 2026 

[11] FDA News Release: FDA Expands AI Capabilities and Completes Data Platform Consolidation; May 2026


Do you have any questions or suggestions? Please contact us at: redaktion@gmp-verlag.de

You may also be interested in the following articles:

Swissmedic Updates Guidance on GMP Compliance of Foreign Manufacturers

Swissmedic Updates Guidance on GMP Compliance of Foreign Manufacturers

Swissmedic has revised its guidance document “GMP compliance by foreign manufacturers”. The new Version 7.0 has been valid since 7 September 2026. In particular, it introduces new provisions for demonstrating the GMP compliance of manufacturers inspected by the US FDA. 
Read more
Swissmedic Updates Requirements for Cooperation with Pre-Wholesalers

Swissmedic Updates Requirements for Cooperation with Pre-Wholesalers

Swissmedic has revised its Technical Interpretation “Market release and distribution in cooperation with a pre-wholesaler”. The document addresses market release and distribution where a Marketing Authorisation Holder works with a pre-wholesaler (logistics and distribution service provider).
Read more
News: Europe

IPEC Updates Two Guides on Pharmaceutical Excipients

The IPEC Federation has updated two key guides on pharmaceutical excipients. The IPEC Composition Guide for Pharmaceutical Excipients (Version 3, 2026) describes an approach for manufacturers to establish excipient composition profiles. The revised version now covers biotechnology- and fermentation-derived excipients, provides further details on component types and physicochemical characterisation, and includes an example composition profile template.
Read more
Applying the FDA’s 7-Step Model for AI/ML Validation in GMP Environments: One Year Later

Applying the FDA’s 7-Step Model for AI/ML Validation in GMP Environments: One Year Later

Artificial intelligence is becoming increasingly important in GMP-regulated environments, presenting companies with new regulatory challenges. This article summarizes the latest regulatory developments, introduces a validation framework based on the FDA's seven-step model, and outlines initial practical experience with AI/ML validation.

Read more
Question of the Week | GMP-Verlag

What are the General Requirements for Standard Documents?

Here's the answer:
Read more
News: Europe

EDQM: Revised Guidance on Sister File Applications

The European Directorate for the Quality of Medicines & HealthCare (EDQM) has revised its Guidance on applications for “sister files” (PA/PH/CEP (09) 141). The revision is intended to support consistent application of the procedure and provide greater clarity on the classification and assessment of the corresponding CEP applications.
Read more
Previous
Next

Related Products

Skip product gallery
GMP Compliance Adviser | Named User Licence | 12M

GMP Compliance Adviser | Named User Licence | 12M

The GMP Compliance Adviser is an online publication that covers all aspects of Good Manufacturing Practice (GMP) in one source.In the GMP Compliance Adviser you’ll find: GMP in Practice This part contains 21 chapters with GMP expert knowledge to base your decisions upon. It provides practical assistance with checklists, templates and SOP examples. It is written by more than 80 authors with hands-on experience directly linked to the industry. The individual chapters describe the different aspects of GMP in clear language. Technical, organizational and procedural aspects are covered.More than 700 checklists, templates and examples of standard operation procedures taken directly out of practice help you in understanding the GMP requirements.GMP RegulationsThese chapters cover the most important GMP regulations from Europe and the United States (CFR and FDA), but also PIC/S, ICH, WHO and many more.  Sample Documents In addition, the GMP Compliance Adviser contains many sample documents and practical examples that you can use.

delivery time appr. 2-5 workdays after receipt of payment
€1,368.00 net excl. VAT
GMP:KnowHow Pharma Logistics (GDP) | Named User Licence | 12M

GMP:KnowHow Pharma Logistics (GDP) | Named User Licence | 12M

Your knowledge portal for GDP-compliant pharmaceutical logistics.  It is important that you as a logistics service provider, but also as a client in the pharmaceutical industry, comply with regulatory requirements. The GMP:KnowHow knowledge portal guides you through the complex regulatory landscape of the pharmaceutical and logistical supply chain! The knowledge portal gives you an easy-to-understand overview of all the important topics. Interactive graphics help you navigate all areas covered by the EU GDP Guidelines (2013/C 343/01). You also have the relevant passages of the regulations directly at hand for each topic. This allows you to compare the requirements directly and saves valuable research time.One thing is certain: the knowledge portal answers your questions about the supply chain of medicinal products, active pharmaceutical ingredients and medical devices. You don't have to be an expert. Yet.You will find answers to your questions in the GMP:KnowHow Pharma Logistics (GDP). Where does GDP begin, where does GMP end? What does GDP-compliant mean? When do I also have to take GMP requirements into account? What permits do I need for certain activities? What requirements do I have to fulfil? What is the current legal basis? How am I covered? What authorizations do I have for my work, e.g. from my employer? Who is responsible — the client or the contractor? And many more What is the difference to the GMP Compliance Adviser? GMP:KnowHow Pharma Logistics (GDP) is a practical knowledge portal dedicated to Good Distribution Practice (GDP). It is a product that is independent of the GMP Compliance Adviser and concentrates on content that is essential for carriers of medicinal products, active pharmaceutical ingredients and medical devices as well as for logistics clients. The focus is on practical knowledge and how to apply it in your daily business. If necessary, the relevant regulations can be called up immediately alongside the practical knowledge, and you can see the relevant paragraphs at a glance. In addition, sample documents are available to help you make immediate progress. AuthorSimone Ferrante, currently Director Quality at Fisher Clinical Services, previously served as Head of Quality Control and Responsible Person (GDP) for the Grieshaber Group. She is also a long-standing author and GDP expert at GMP-Verlag.

delivery time appr. 2-5 workdays after receipt of payment
€610.00 net excl. VAT
E-Learning GMP:READY | Specialist Knowledge GMP for Engineers

E-Learning GMP:READY | Specialist Knowledge GMP for Engineers

Why are GMP rules important for technicians and engineers? Technicians and engineers play a key role in ensuring compliance with Good Manufacturing Practice (GMP) standards. They are involved in critical activities such as: planning and construction of ventilation systems, maintenance of water treatment plants, calibration of measuring sensors. Therefore, they are jointly responsible for the quality of medicines and must ensure that their work complies with GMP standards.Your advantages: Fast familiarization with GMP topics in approx. 2 hours, time- and location-independent online training, printable personal certificate, 12-month access for initial and follow-up training, automatic updates in case of legal changes,content compliant with Article 7(4) of Directive 2003/94/EC.The Author This e-learning course was developed with the collaboration of Dipl.-Ing. Andreas Nuhn (D & B Pharmadesign GmbH).

delivery time appr. 2-5 workdays after receipt of payment
€245.00 net excl. VAT
GMP Fundamentals | A Step-by-Step Guide

GMP Fundamentals | A Step-by-Step Guide

This handbook is a practical and easy to read guideline, giving you a quick and comprehensive overview of the complex world of Good Manufacturing Practice (GMP) without the need of previously acquired knowledge. Some topics are: GMP: Purpose and basic pharmaceutical terms Laws, licenses and inspections Personnel: Responsibility and hygiene Standard Operating Procedures (SOP) and documentation Design of rooms and facilities Processing and packaging Quality control and market release Suppliers, storage and logistics (Good Distribution Practice = GDP) Alphabetical index and abbreviations Using practical examples and comparisons to every-day life will help to easy understand GMP regulations.GMP Fundamentals is a helpful guide which facilitates the entry into the GMP world and teaches the necessary basics.

delivery immediately after receipt of payment
€44.90 net excl. VAT