Track 02FoundationalLocked by prerequisiteRequired

AI Governance & Regulatory Expectations

Connect published regulatory expectations for AI to the governance arrangements, records and decision rights that a life-sciences organisation must be able to demonstrate.

5 lessons · 6 frameworks · 4–5 hours · 0/5 complete · 0/5 exercises recorded

Locked by prerequisite

This track opens once its prerequisites are complete. Prerequisites are sequenced deliberately: each one supplies a competency this track assumes you already hold.

  • Track 01 — AI Fundamentals

Orientation

Why this matters

Regulators are not asking whether you use AI. They are asking whether you can explain what it does, show that its use is controlled, and produce the records that prove it. Every one of those questions has an owner inside your organisation — and part of the answer is you.

What you will be able to do (5)

  • Describe the published regulatory expectations that apply to AI in your function
  • Explain risk-based credibility assessment in plain language
  • Apply ALCOA+ data-integrity principles to AI-assisted records
  • Identify the governance roles and decision rights that must exist before AI is used
  • State what your organisation must be able to show an inspector

Aligned with (6)

FDA — AI in regulatory decision-making (published expectations)EU AI Act — risk-tiered obligationsEU GMP Annex 11 and draft Annex 22 expectationsICH E6(R3) and ICH Q9(R1)ALCOA+ / MHRA and PIC/S data-integrity expectationsISO/IEC 42001 — AI management systems

Maps to published expectations. Competency demonstrated through assessment.

Regulatory alignment indicates that curriculum topics map to published regulatory expectations. It does not constitute agency approval, certification, legal advice or a determination of organizational compliance.

View source evidence, status and applicability

FDA — AI in regulatory decision-making (published expectations)

Draft regulatory guidanceUnited States
Considerations for the Use of Artificial Intelligence to Support Regulatory Decision-Making for Drug and Biological Products
Relevant provisions
Risk-based credibility assessment framework and context-of-use analysis
Status and date
January 2025. Draft; not for implementation and non-binding.
Why it maps
Maps the lesson to FDA's context-of-use and credibility concepts without treating draft recommendations as law.
Applicability limit
Applies to AI used to produce information or data supporting FDA regulatory decisions for drugs and biological products. It is not a general AI-use mandate.

Primary source last verified 2026-08-24

EU AI Act — risk-tiered obligations

Binding lawEuropean Union
Regulation (EU) 2024/1689 — Artificial Intelligence Act
Relevant provisions
Article 6 and Annex III — classification; Articles 9–15 — high-risk requirements
Status and date
Official Journal, 12 July 2024. Entered into force 1 August 2024; phased application through 2 August 2027.
Why it maps
Connects the lesson to the Act's conditional duties while preserving classification, role and application-date limits.
Applicability limit
Specific duties depend on system classification, actor role, territorial scope and the applicable date. No duty should be extended beyond those conditions.

Primary source last verified 2026-08-24

EU GMP Annex 11 and draft Annex 22 expectations

GMP requirementEuropean Union GMP
EudraLex Volume 4, Annex 11 — Computerised Systems
Relevant provisions
Sections 1, 4, 7–9, 11–13 and 16–17
Status and date
Revision January 2011. Current Annex 11; came into operation 30 June 2011.
Why it maps
Supports the track's stated mapping to EU GMP Annex 11 and draft Annex 22 expectations without transferring duties beyond the source's scope.
Applicability limit
Applies to computerised systems used as part of GMP-regulated activities. Applicability follows the regulated process and intended use.

Primary source last verified 2026-08-24

Draft regulatory guidanceEuropean Union GMP
Proposed EudraLex Volume 4, Annex 22 — Artificial Intelligence
Relevant provisions
Draft lifecycle, data, model performance, change and human-oversight expectations
Status and date
Stakeholder consultation opened July 2025. Draft consultation text; not effective as of 24 August 2026.
Why it maps
Included to teach prospective change control; the track must preserve its draft, non-effective status.
Applicability limit
Used only as a prospective signal. It must not be presented as a current binding GMP requirement unless and until adopted and applicable.

Primary source last verified 2026-08-24

ICH E6(R3) and ICH Q9(R1)

Harmonised guidelineICH regions; implemented through regional frameworks
ICH Q9(R1) — Quality Risk Management
Relevant provisions
Sections 4–6 and Annexes I–II
Status and date
Step 4, 18 January 2023. Implementation depends on the relevant regional authority and regulated activity.
Why it maps
Supports the track's stated mapping to ICH E6(R3) and ICH Q9(R1) without transferring duties beyond the source's scope.
Applicability limit
Supplies quality-risk principles. It does not independently classify an AI system or prescribe one universal control set.

Primary source last verified 2026-08-24

Harmonised guidelineICH regions; implemented through regional frameworks
ICH E6(R3) — Good Clinical Practice
Relevant provisions
Principles and Annex 1 provisions on roles, data governance, records and oversight
Status and date
Principles and Annex 1, Step 4, 6 January 2025. Implementation depends on regional adoption and the clinical-trial activity.
Why it maps
Supports the track's stated mapping to ICH E6(R3) and ICH Q9(R1) without transferring duties beyond the source's scope.
Applicability limit
Applies to clinical trials within its scope. It should not be transferred to manufacturing or other domains without an independent basis.

Primary source last verified 2026-08-24

ALCOA+ / MHRA and PIC/S data-integrity expectations

Regulatory guidanceUnited Kingdom GxP
MHRA GxP Data Integrity Guidance and Definitions
Relevant provisions
Data governance and ALCOA+ expectations across the data lifecycle
Status and date
March 2018; page updated September 2021. Current MHRA resource; OECD guidance takes precedence for UK GLP as stated by MHRA.
Why it maps
Supports the track's stated mapping to ALCOA+ / MHRA and PIC/S data-integrity expectations without transferring duties beyond the source's scope.
Applicability limit
Used for data-governance and inspection expectations. Its scope and MHRA's stated GLP qualification must be preserved.

Primary source last verified 2026-08-24

Regulatory guidancePIC/S participating authorities
PIC/S PI 041-1 — Good Practices for Data Management and Integrity
Relevant provisions
Data governance, lifecycle controls, audit trails and organisational responsibility
Status and date
Adopted 1 June 2021. Guidance for regulated GMP/GDP environments; legal effect follows national implementation.
Why it maps
Supports the track's stated mapping to ALCOA+ / MHRA and PIC/S data-integrity expectations without transferring duties beyond the source's scope.
Applicability limit
Inspection-oriented guidance. It supports, but does not replace, the binding requirements of the applicable jurisdiction.

Primary source last verified 2026-08-24

ISO/IEC 42001 — AI management systems

Consensus standardInternational consensus standard
ISO/IEC 42001:2023 — Artificial intelligence management system
Relevant provisions
Clauses 4–10 and Annex A controls
Status and date
December 2023. Voluntary unless adopted by contract, policy, certification scheme or applicable authority.
Why it maps
Supplies a recognised management or assurance practice; it is identified as non-binding unless separately adopted.
Applicability limit
Specifies requirements for an AI management system. Use of the standard does not itself establish regulatory compliance.

Primary source last verified 2026-08-24

Full source register and editorial method →

Credential

AI Governance and Regulatory Expectations Badge

Duration

4–5 hours

Audience

  • All personnel in GxP functions
  • Quality, validation and regulatory professionals
  • Managers accountable for AI adoption decisions

Prerequisites

  • Track 01

Behaviours practised (3)

UnderstandApplyDocument
An inspector opens with a simple question: 'You have told me an AI tool assisted this investigation. Show me who decided it could be used for that, what its limitations are, and how you knew the output was correct.' Everything in this track exists to make that question answerable.

Badge requirements (5)

  1. Complete all five lessons and their knowledge checks
  2. Achieve at least 80% across the final badge assessment
  3. Answer every safety-critical question correctly
  4. Produce an ALCOA+ assessment identifying all material record gaps
  5. Demonstrate accurate regulatory-alignment language in the inspection response exercise

Lessons (5)

Final badge assessment

AI Governance and Regulatory Expectations Badge

  • Regulatory framework knowledge check

    Mixed multiple-choice and select-all

    Fifteen questions covering applicable frameworks, risk-based credibility and data-integrity expectations.

  • Risk-based evidence determination

    Match control to riskSafety-critical

    Given four AI uses, determine the proportionate credibility evidence level and justify each determination.

  • ALCOA+ record assessment

    Practical exerciseSafety-critical

    Assess an AI-assisted record set against ALCOA+ and produce a remediation list for every gap identified.

  • Regulatory language accuracy

    Identify the unsupported statementSafety-critical

    Identify prohibited or unsupportable claims in a set of statements about AI tools and training.

Next recommended track

← All tracks