Methodology and standards

Every claim keeps its source, status and conditions

The Academy is designed for a field where a missing qualifier can be as misleading as a wrong citation. This page explains how curriculum content is sourced, translated, reviewed, versioned and corrected.

Development process

From workplace decision to assessed competency

  1. STEP 01

    Define the performance problem

    Start with the decision or behavior the learner must perform in a regulated context, not a list of facts to memorize.

  2. STEP 02

    Identify applicable authority

    Separate jurisdiction, regulated activity, actor, system classification, effective date and conditions before assigning a source.

  3. STEP 03

    Build the evidence route

    Use official legal text and regulator publications first. Standards and industry guidance are identified as separate authority types.

  4. STEP 04

    Translate without changing modality

    A recommendation remains a recommendation. A draft remains prospective. Conditions and qualifiers stay attached to the duty.

  5. STEP 05

    Design observable practice

    Lessons require a decision, practical response or evidence artifact that can be judged against stated criteria.

  6. STEP 06

    Set the assessment gate

    Assessment rules test knowledge, safety-critical judgment, documentation and escalation rather than attendance alone.

  7. STEP 07

    Review and version

    The curriculum owner reviews substance, links, dates and internal consistency before a version is released.

  8. STEP 08

    Monitor and correct

    Material source changes trigger review. Confirmed errors are corrected, dated and recorded under the corrections policy.

Source hierarchy

Primary evidence first

  1. 1. Official legislation and regulations
  2. 2. Regulator-issued guidance and adopted scientific papers
  3. 3. Harmonised guidelines and government frameworks
  4. 4. Consensus standards and recognized industry guidance
  5. 5. Secondary commentary only for context, never as the sole basis for a duty

Authority labels

Modality is preserved

Each source is labelled as binding law, a GMP requirement, regulator guidance, draft guidance, a harmonised guideline, a voluntary framework, a consensus standard or industry guidance. “Must,” “should,” “may” and “consider” are not blended.

Applicability

No duty without its conditions

Mappings retain jurisdiction, role, regulated activity, system classification, context of use and effective date. Conflicting authorities are shown separately. An evidence gap remains a gap rather than becoming a confident composite rule.

Review accountability

Named ownership and honest review status

Brian J. Drapeau is the curriculum owner and accountable editor. A page or module is not described as independently reviewed unless a qualified reviewer has actually completed that review and can be named or documented.

Release review

  • Source identity, link, status and date checked
  • Learning objectives traceable to lesson and assessment
  • Safety-critical items and remediation rules checked
  • Regulatory disclaimer and non-endorsement language retained
  • Material changes entered in curriculum version history

Independent review

Independent review is scoped to the reviewer's expertise and recorded separately from author review. Disagreements are preserved until adjudicated. Anonymous or AI-generated review is not represented as qualified human review.

Use of AI in content development

AI may assist the workflow; a person owns the published claim

AI tools may support outlining, comparison, formatting, code development or quality checks. They are not treated as legal authorities, named reviewers or evidence that a statement is correct. Published regulatory claims require an identified source and human accountability.

Sensitive client material, protected health information and confidential regulated records should not be entered into public AI systems. Client-specific AI use is governed by the applicable engagement, approved tools and data-handling requirements.

Regulatory source register

Primary sources used by the current curriculum

Status checked August 24, 2026. Each track shows the particular provisions and the reason for its mapping.

Draft regulatory guidance · United States

Considerations for the Use of Artificial Intelligence to Support Regulatory Decision-Making for Drug and Biological Products

U.S. Food and Drug Administration

Primary source ↗
Issued
January 2025
Application
Draft; not for implementation and non-binding
Mapped provisions
Risk-based credibility assessment framework and context-of-use analysis

Applies to AI used to produce information or data supporting FDA regulatory decisions for drugs and biological products. It is not a general AI-use mandate.

Regulatory guidance · European Union medicines regulation

Reflection paper on the use of AI in the medicinal product lifecycle

European Medicines Agency

Primary source ↗
Issued
Adopted September 2024
Application
Current reflection paper; read with applicable EU law and GxP requirements
Mapped provisions
Sections 2.2–2.8: risk, context of use, data, performance and human oversight

Describes regulatory considerations across the medicinal-product lifecycle. It does not replace binding legislation or GxP requirements.

Binding law · European Union

Regulation (EU) 2024/1689 — Artificial Intelligence Act

European Union

Primary source ↗
Issued
Official Journal, 12 July 2024
Application
Entered into force 1 August 2024; phased application through 2 August 2027
Mapped provisions
Articles 3, 6, 9–15, 16, 25–27, 50 and 73; Annex III

Specific duties depend on system classification, actor role, territorial scope and the applicable date. No duty should be extended beyond those conditions.

GMP requirement · European Union GMP

EudraLex Volume 4, Annex 11 — Computerised Systems

European Commission

Primary source ↗
Issued
Revision January 2011
Application
Current Annex 11; came into operation 30 June 2011
Mapped provisions
Sections 1, 4, 7–9, 11–13 and 16–17

Applies to computerised systems used as part of GMP-regulated activities. Applicability follows the regulated process and intended use.

Draft regulatory guidance · European Union GMP

Proposed EudraLex Volume 4, Annex 22 — Artificial Intelligence

European Commission

Primary source ↗
Issued
Stakeholder consultation opened July 2025
Application
Draft consultation text; not effective as of 24 August 2026
Mapped provisions
Draft lifecycle, data, model performance, change and human-oversight expectations

Used only as a prospective signal. It must not be presented as a current binding GMP requirement unless and until adopted and applicable.

Binding law · United States

21 CFR Part 11 — Electronic Records; Electronic Signatures

U.S. Food and Drug Administration / eCFR

Primary source ↗
Issued
Current electronic Code of Federal Regulations
Application
Applies when predicate-rule records are maintained or submitted electronically and Part 11 scope is met
Mapped provisions
§§ 11.10, 11.30, 11.50, 11.70 and 11.100–11.300

Part 11 does not make every electronic output a regulated record. Predicate rules and record use determine applicability.

Binding law · European Economic Area

Regulation (EU) 2016/679 — General Data Protection Regulation

European Union

Primary source ↗
Issued
27 April 2016
Application
Applicable since 25 May 2018 when material and territorial scope are met
Mapped provisions
Articles 5, 6, 9, 13–14, 22, 25, 32 and 35

The relevant duties depend on personal-data processing, role, lawful basis, location and data-subject context.

Binding law · United States

45 CFR Part 164 — HIPAA Privacy and Security Rules

U.S. Department of Health and Human Services / eCFR

Primary source ↗
Issued
Current electronic Code of Federal Regulations
Application
Applies to covered entities, business associates and protected health information within rule scope
Mapped provisions
45 CFR §§ 164.308, 164.312 and 164.502

HIPAA is not a general confidentiality law for every life-sciences dataset. Entity status and PHI determine scope.

Voluntary framework · Non-sector-specific; international use

NIST AI Risk Management Framework 1.0

U.S. National Institute of Standards and Technology

Primary source ↗
Issued
26 January 2023
Application
Voluntary; AI RMF 1.0 is under revision as of August 2026
Mapped provisions
GOVERN, MAP, MEASURE and MANAGE functions

Provides risk-management outcomes and practices. It does not create a legal mandate unless adopted through contract, policy or another authority.

Consensus standard · International consensus standard

ISO/IEC 42001:2023 — Artificial intelligence management system

International Organization for Standardization

Primary source ↗
Issued
December 2023
Application
Voluntary unless adopted by contract, policy, certification scheme or applicable authority
Mapped provisions
Clauses 4–10 and Annex A controls

Specifies requirements for an AI management system. Use of the standard does not itself establish regulatory compliance.

Consensus standard · International consensus standard

ISO/IEC 23894:2023 — Guidance on AI risk management

International Organization for Standardization

Primary source ↗
Issued
February 2023
Application
Voluntary guidance unless adopted by contract or policy
Mapped provisions
Clauses 5–8: principles, framework and AI risk-management process

Supports integration of AI-specific risks into organisational risk management; it is not a sector-specific legal rule.

Consensus standard · International consensus standard

ISO/IEC 27001:2022 — Information security management systems

International Organization for Standardization

Primary source ↗
Issued
October 2022
Application
Voluntary unless adopted by contract, policy or certification scheme
Mapped provisions
Clauses 4–10 and Annex A information-security controls

Provides an information-security management system. Specific privacy, GxP and AI duties still require separate applicability analysis.

Harmonised guideline · ICH regions; implemented through regional frameworks

ICH Q9(R1) — Quality Risk Management

International Council for Harmonisation

Primary source ↗
Issued
Step 4, 18 January 2023
Application
Implementation depends on the relevant regional authority and regulated activity
Mapped provisions
Sections 4–6 and Annexes I–II

Supplies quality-risk principles. It does not independently classify an AI system or prescribe one universal control set.

Harmonised guideline · ICH regions; implemented through regional frameworks

ICH Q10 — Pharmaceutical Quality System

International Council for Harmonisation

Primary source ↗
Issued
Step 4, 4 June 2008
Application
Implementation depends on the relevant regional authority and product lifecycle
Mapped provisions
Sections 2–4: management responsibility, lifecycle elements and continual improvement

Provides the pharmaceutical quality-system model used to place AI controls within governance, CAPA, change and management review.

Harmonised guideline · ICH regions; implemented through regional frameworks

ICH E6(R3) — Good Clinical Practice

International Council for Harmonisation

Primary source ↗
Issued
Principles and Annex 1, Step 4, 6 January 2025
Application
Implementation depends on regional adoption and the clinical-trial activity
Mapped provisions
Principles and Annex 1 provisions on roles, data governance, records and oversight

Applies to clinical trials within its scope. It should not be transferred to manufacturing or other domains without an independent basis.

Regulatory guidance · United Kingdom GxP

MHRA GxP Data Integrity Guidance and Definitions

UK Medicines and Healthcare products Regulatory Agency

Primary source ↗
Issued
March 2018; page updated September 2021
Application
Current MHRA resource; OECD guidance takes precedence for UK GLP as stated by MHRA
Mapped provisions
Data governance and ALCOA+ expectations across the data lifecycle

Used for data-governance and inspection expectations. Its scope and MHRA's stated GLP qualification must be preserved.

Regulatory guidance · PIC/S participating authorities

PIC/S PI 041-1 — Good Practices for Data Management and Integrity

Pharmaceutical Inspection Co-operation Scheme

Primary source ↗
Issued
Adopted 1 June 2021
Application
Guidance for regulated GMP/GDP environments; legal effect follows national implementation
Mapped provisions
Data governance, lifecycle controls, audit trails and organisational responsibility

Inspection-oriented guidance. It supports, but does not replace, the binding requirements of the applicable jurisdiction.

Industry guidance · International industry practice

ISPE GAMP 5 — A Risk-Based Approach to Compliant GxP Computerized Systems, 2nd ed.

International Society for Pharmaceutical Engineering

Primary source ↗
Issued
July 2022
Application
Non-binding unless adopted by an organisation, contract or authority
Mapped provisions
Lifecycle, intended use, critical thinking, supplier involvement and risk-based assurance

Widely used industry guidance. It must not be described as legislation or a regulator-issued mandate.

Versioning, review cadence and corrections

Scheduled review: the source register and curriculum are reviewed at least quarterly.

Event-driven review: a new law, final guidance, material amendment, safety issue or broken primary link triggers targeted review.

Corrections: confirmed material errors are dated, corrected and described under the public corrections policy.