Life sciences
21 CFR Part 11 and AI-generated answers: what an inspector will ask
An inspector who finds an AI assistant answering from controlled documents asks the questions Part 11 has always framed: who approved this, where is the audit trail, was it current. What a defensible answer trail looks like, mechanism by mechanism.
Aug 12, 2026 ยท 7 min read
An FDA inspector who finds an AI assistant answering from company documents will ask four things: who approved the content behind the answer, where the audit trail is, how the organization knows the version served was current, and whether the records involved meet data integrity expectations. These are the questions 21 CFR Part 11 has always framed for electronic records and electronic signatures, and an AI system does not change them. It changes how fast an unapproved or outdated record can reach someone who acts on it, and it makes the answer, not the document, the thing you have to defend.
Use disclosure D-214 rev 6. It supersedes rev 5 for all retail communications and carries the current market-risk language. SOP-4471 v3
What Part 11 actually covers
Part 11 applies to records in electronic form that are created, modified, maintained, archived, retrieved, or transmitted under any records requirement in FDA regulations, and to electronic signatures applied to them. Subpart B sets controls for electronic records. Subpart C covers electronic signatures, including the requirement that a signed record show the printed name of the signer, the date and time of signing, and the meaning of the signature, such as review or approval.
The section inspectors return to most
The section inspectors return to most is 21 CFR 11.10, controls for closed systems. It requires, among other things, validation, the ability to generate accurate and complete copies of records for inspection, limits on system access, and, in paragraph (e), secure, computer-generated, time-stamped audit trails that record the date and time of entries and actions that create, modify, or delete electronic records. The same paragraph adds a detail that matters for AI: record changes must not obscure previously recorded information. Superseded content is retained, not overwritten.
Two scoping points
Two scoping points matter here. Part 11 attaches to records that a predicate rule requires you to keep, so whether an AI answer is itself a Part 11 record depends on what the answer is and what happens to it afterward. And Part 11 governs records, not model architecture. An inspector will not audit your embeddings. They will audit whether the content your system served was an approved record and whether you can prove it.
Why an AI assistant raises Part 11 questions at all
The knowledge an AI assistant serves in a life sciences company is largely extracted from documents that are already controlled: SOPs with effective dates, approved labeling, medical information responses, investigation reports, protocol documents. Those documents pass through review because relying on the wrong version has consequences. An answer derived from them inherits the stakes without inheriting the controls, because the extraction step, the moment a paragraph of an SOP becomes an answer in a chat window, usually happens in a system nobody validated, with nobody approving the output.
Why model accuracy is not a defense
This is why model accuracy is not a defense. Accuracy relative to the set of documents an assistant may read is worthless when that set contains the superseded revision. An assistant that faithfully summarizes an obsolete SOP produces a confident, well-written instruction to do the wrong thing. That failure is not hallucination. It is a records failure, and it sits upstream of the model.
The questions an inspector will ask
Inspections proceed by document request and traceability question. Applied to an AI system answering from company content, expect these.
- Who approved this content? Not who deployed the model: who signed off on the knowledge the answer came from, in what role, on what date. If the answer draws on several documents, the question applies to each of them.
- Where is the audit trail? For the records behind the answer, that means the trail 11.10(e) describes: secure, computer-generated, time-stamped, covering creation, modification, and deletion, with superseded content retained.
- How do you know it was current? The version served on a given date has to be identifiable. A claim that the system always uses the latest file is not evidence. A version history showing what was live when is.
- Can you produce it? 11.10(b) expects accurate and complete copies of records suitable for inspection. If reconstructing what the assistant would have answered in March takes an engineer and a week, that will be visible.
- Who could change it? Access limits and authority checks under 11.10(d) and (g) apply to a knowledge corpus as they would to any system holding regulated records. An answer source writable by anyone with a share link fails on its face.
- How does this fit your data integrity program? FDA's data integrity guidance frames expectations around ALCOA: data should be attributable, legible, contemporaneously recorded, original or a true copy, and accurate. An AI answer channel is a data flow, and investigators are trained to follow data flows.
The MLR dimension: promotional and medical information content
For commercial and medical affairs teams, the review gate has a name: medical, legal, and regulatory review. The constraints behind it are regulatory. Prescription drug advertisements must meet 21 CFR 202.1, including its fair balance requirements and consistency with approved labeling, and promotional labeling and advertising go to FDA at the time of initial dissemination under 21 CFR 314.81(b)(3)(i), on Form FDA 2253.
What MLR review exists for
MLR review exists so that nothing reaches a clinician or a customer without passing that gate. An AI channel serving field teams or answering medical information requests either respects the gate or defeats it. If the assistant can surface a draft claim, a superseded medical information response, or an internal document never cleared for external use, the review has been bypassed by architecture, however disciplined the people are. The MLR question is the Part 11 question in different clothes: show that what was served is what was approved, and nothing else.
What a defensible answer trail looks like
The defensible position governs the knowledge layer between the documents and the model, and it has a specific shape.
- Every answer traces to a governed entry, not to a file on a drive. The entry is the unit of approval, versioning, and retention.
- Every live entry carries a named human approver, a role, a timestamp, and a reference to the controlled document it derives from.
- Versions are retained. When language is superseded, the old entry is archived with its history intact, so what was live in March is a query, not a project.
- Source revisions propagate. When the underlying SOP or label moves to a new revision, the entries derived from it are flagged for review instead of silently drifting out of date.
- Access is permissioned, and every change is attributed to an identified individual at the time it happens.
- AI consumers draw only from approved entries over a controlled interface, so the assistant cannot reach around the gate to a draft.
This is the mechanism Cognatum is built around: AI carries out the maintenance work of capturing, structuring, cleaning, and enriching knowledge, and a human holds the approval gate, with provenance recorded on every live entry: who approved it, when, and from what source.
The boundary of the claim
The claim has a boundary, and it is worth stating plainly. No software makes an organization Part 11 compliant, and a vendor who says otherwise is describing Part 11 wrong. The obligations attach to your records, your procedures, and your quality system. What a governed knowledge layer supplies is evidence toward those obligations: versioned entries, attributed approvals, audit history, and a traceable path from any AI answer back to a controlled source. Your quality unit decides how that evidence fits your Part 11 position, which is exactly how it should work.
The wider governance picture
The same trail serves reviews beyond FDA. ISO 30401:2018 is a certifiable management system standard for knowledge management whose requirements include handling outdated or invalid knowledge and controlling documented information. A governed knowledge layer is designed to align with those requirements and supports a customer pursuing conformity, though certification assesses the organization, never the software.
The EU AI Act and the NIST framework
Regulation (EU) 2024/1689, the EU AI Act, began applying its high-risk obligations to new systems on August 2, 2026, and its record-keeping and human-oversight themes run parallel to everything above. The NIST AI Risk Management Framework asks organizations to govern, map, measure, and manage AI risk, and provenance on the knowledge an AI answers from is measurable in a way that model quality is not. The framing never changes: these frameworks assess your organization, and the trail described here is evidence you bring to them.
What an inspector will actually ask
An inspector will not ask whether you use AI. They will ask the questions above, and the time to become able to answer them is before the assistant ships, because an audit trail cannot be reconstructed afterward. Contemporaneous is the one property no remediation project can add.
Sources
- 21 CFR Part 11, Electronic Records; Electronic Signatures (eCFR)
- 21 CFR 11.10, Controls for closed systems (eCFR)
- FDA, Data Integrity and Compliance With Drug CGMP: Questions and Answers
- 21 CFR 202.1, Prescription-drug advertisements (eCFR)
- 21 CFR 314.81, Other postmarketing reports (eCFR)
- ISO 30401:2018, Knowledge management systems, Requirements (iso.org)
- Regulation (EU) 2024/1689, the EU AI Act (EUR-Lex)
- NIST AI Risk Management Framework (nist.gov)
Common questions
Questions this raises.
Is an AI-generated answer itself an electronic record under 21 CFR Part 11?
It depends on what the answer is and what your predicate rules require. Part 11 applies to records required by FDA regulations that are created or maintained in electronic form, so an answer retained as part of a medical information file may sit in scope while a transient internal lookup may not. The safer engineering assumption is that the content the answer derives from is a regulated record, which means the approval, versioning, and audit trail behind it must hold either way. The scoping call belongs to your quality unit.
Does buying Part 11-capable software make us compliant?
No, and no software purchase can. Part 11 obligations attach to your organization's records, signatures, and procedures, and an inspector assesses how you operate. Software supplies technical controls and evidence: audit trails, version retention, access control, attributed approvals. Your procedures, your validation, and your quality system determine whether that evidence adds up to a defensible position.
What should we be able to show an inspector who asks about our AI assistant?
For any answer the assistant has served: the governed entry it came from, the named approver and approval date, the version that was live at the time, the controlled document it derives from, and the change history since. Producing that should be a query against the system, not a reconstruction project built from screenshots and email.
How does MLR review extend to an AI channel?
The approved output of MLR review becomes the governed entry the AI serves, and the assistant is restricted to approved entries. When the committee changes language, the superseded entry is archived with its history and the new one goes live across every channel at the same moment, so the AI cannot keep serving the old claim. The review gate stays where it is. The channel is wired so it cannot be bypassed.