Life sciences
GAMP 5 validates the system, not the answer
GAMP 5 validates the computerized system. It was never written to govern the document an AI assistant retrieved, or the answer it assembled from that document. That gap sits outside every validation package.
Cognatum Team · Sep 22, 2026 · 6 min read
A life sciences company can hand an inspector a validation package for every computerized system in the building. The same company usually cannot say which version of which work instruction its AI assistant quoted to a technician on Tuesday morning.
Cognatum governs the entry
source · version · approver · permissions
Both things are true at once, and neither is a failure of the validation program. GAMP 5 does exactly what it was written to do. The answer an assistant assembles was never its object.
What GAMP 5 actually scopes
ISPE's GAMP 5: A Risk-Based Approach to Compliant GxP Computerized Systems is the leading international guidance on GxP computerized systems validation and compliance. Its stated aim is to protect patient safety, product quality and data integrity by delivering computerized systems that are effective, reliable and of high quality.
The object is a system
The guide scales life cycle activity to risk, complexity and novelty. Software categories run from infrastructure through non-configured and configured products to custom code, and the second edition is explicit that most systems combine components from several categories, and that categories three to five should be read as a continuum.
Every one of those decisions is made about a system. Which system, built how, carrying what GxP impact, verified to what depth.
The second edition went further than most people remember
The 2nd Edition added guidance on artificial intelligence and machine learning, blockchain, cloud computing and open source software. It underlines critical thinking by experienced subject matter experts over compliance-driven tick-box approaches, supports iterative and incremental development, and explores computer software assurance concepts from the FDA Case for Quality program.
One line in its summary of the management appendices is worth reading twice. Records and information are maintained because they are valuable to the regulated company as their source of truth, and not necessarily to demonstrate something to a third party. The same appendices acknowledge implicit as well as explicit knowledge.
Knowledge, on its own terms
That is a validation guide telling you the knowledge matters on its own terms. It still stops short of governing that knowledge, because governing it is not what a validation guide does.
Where the validated system stops
Validation establishes that a system does what it is specified to do, reliably and repeatably. A validated document management system will faithfully retrieve whatever it was asked for. If the thing it retrieves is a superseded work instruction that nobody withdrew, validation has not been violated. The retrieval worked.
Put a retrieval based assistant on top and the same property holds one level up. The assistant returns an answer assembled from whatever it could reach. Nothing in the validation package speaks to whether that material was current, or approved, or the only version in circulation.
The questions an inspector will actually ask
- Which document did the assistant use, and which version of it.
- Who approved that version, by name.
- When was it last reviewed, and against what.
- What happened to the answers already given from the version it replaced.
A validation report answers none of those, because it was never written to.
The frameworks already say knowledge matters
ICH Q10 names it an enabler
ICH Q10 sets out a pharmaceutical quality system model across the product life cycle and names knowledge management, alongside quality risk management, as an enabler of that system. Knowledge is treated there as something the quality system runs on rather than as an optional extra.
Q9(R1) pushed risk decisions toward what people know
ICH Q9(R1) revised the quality risk management guideline with added attention to subjectivity, formality in quality risk management and risk-based decision making. Those decisions are only as good as what the decider knows at the moment of deciding, which makes the state of your knowledge a risk input rather than background.
The MHRA assumes a record has a status
The MHRA's guidance on GxP data integrity sets expectations for organizations across the pharmaceutical life cycle and for GLP studies. It is thorough about records. It also assumes, reasonably, that a record has an owner and a status. A good deal of what an assistant reads has neither.
Retrieval is not approval
The usual reply is to point the assistant at the controlled repository and call the problem solved. A preregistered evaluation of retrieval based legal research tools found that products from LexisNexis and Thomson Reuters hallucinated between 17 and 33 percent of the time, despite vendor language about eliminating hallucinations.
Retrieval decides which document gets fetched. It does not establish that the document was right, current, or signed by anyone.
What the AI controls cover, and what they leave out
ISO/IEC 42001 specifies a management system for artificial intelligence. Article 12 of the EU AI Act requires high risk systems to technically allow the automatic recording of events over the lifetime of the system. Both are worth adopting, and software can align with them and produce evidence for them. No product confers compliance, and neither framework supplies the approved content itself.
A log tells you the assistant answered at 09:14 and which passages it pulled. It does not tell you that the passage it pulled was the approved one.
A governed layer above the repositories you already have
Cognatum is a knowledge base that sits above those repositories. Quality keeps its document system, legal keeps its Box folders, manufacturing keeps what it has always used. That split is normal and it is fine. Nothing migrates, because Cognatum does not house the data. It flows in both directions with the systems you already work in.
Approve is the step that stays human
The Cognatum Knowledge Loop runs eight steps across four phases, and one of them is a gate rather than a task. The AI finds, gathers, cleans and surfaces. It does not decide what is true. It routes the item to a named person, who can rework the wording before approving it.
What ships afterwards carries an approver, a date and a source, and the record shows where the knowledge stood at the moment the answer was given.
Disagreement is surfaced, not settled
Where two documents contradict each other, both are presented along with the point of disagreement, rather than one being quietly chosen. In a GxP setting that is the difference between a discrepancy somebody can investigate and one nobody ever sees.
Notification when a source moves
External systems are treated as external data. When a document, a table, a query or a stored procedure changes, anything tied to it is flagged so a named owner can decide what to do about it. It does not quietly rewrite an approved answer, and it is not self updating.
Where to start this week
Take the twenty documents your assistant cites most often and run the inspector's four questions against them. Owner, version, review date, downstream effect. If the answers thin out after the first column, the gap is not in your validation package.
Your company's knowledge isn't missing. It's unusable. Cognatum changes that.
The Cognatum Knowledge Loop is documented at cognatum.ai/the-loop.
Sources
- ISPE GAMP 5 Guide, 2nd Edition (ispe.org)
- What You Need to Know About GAMP 5 Guide, 2nd Edition (ispe.org)
- ICH Q10: Pharmaceutical Quality System (ich.org)
- ICH Q9(R1): Quality Risk Management, Step 4 (ich.org)
- Guidance on GxP data integrity, MHRA (gov.uk)
- Hallucination-Free? Assessing the Reliability of Leading AI Legal Research Tools (arxiv.org)
- ISO/IEC 42001:2023, AI management systems (iso.org)
- EU AI Act Article 12: Record-Keeping (artificialintelligenceact.eu)
- The Cognatum Knowledge Loop (cognatum.ai)
Common questions
Questions this raises.
What is GAMP 5?
GAMP 5 is ISPE's guidance on a risk-based approach to compliant GxP computerized systems. It scales validation effort to a system's risk, complexity and novelty, classifies software into categories, and in its second edition adds material on artificial intelligence and machine learning, cloud, blockchain, open source software and computer software assurance.
Does GAMP 5 cover AI?
The second edition includes an appendix on AI and machine learning, aimed at understanding those technologies and integrating them into a GxP environment. That is guidance about the system and its life cycle. It does not govern which internal document a retrieval based assistant reads, which version it read, or who approved it.
If the system is validated, are its answers compliant?
No. Validation demonstrates that a system performs as specified. A validated system will retrieve a superseded document just as reliably as a current one. The approval status of the content is a separate control, and in most organizations nobody owns it.
What does ICH Q10 say about knowledge management?
ICH Q10 describes a pharmaceutical quality system across the product life cycle and identifies knowledge management, together with quality risk management, as an enabler of that system. It establishes that knowledge is something the quality system depends on, without prescribing the tooling to govern it.
Do we have to migrate documents into one system to govern them?
No. Departmental repositories are legitimate and they can stay where they are. What is usually missing is a governed layer above them that carries a named approver, a date and a source for every answer, surfaces conflicts between documents rather than picking a winner, and notifies an owner when an underlying source changes.