Cognatum

Life sciences

GxP scope stops at the systems you classified

GxP compliance begins with a list of systems in scope. An AI answer is assembled across that list, from sources that were never on it, and the classification scheme never sees the answer at all.

Cognatum Team · Sep 29, 2026 · 6 min read

GxP compliance starts with a question that sounds administrative. Which of our systems are in scope?

Served to one approved entry
AI assistants & agents
Proposal tools
Internal search & chat
Customer portals
Compliance & audit

Cognatum governs the entry

source · version · approver · permissions

That answer decides where the controls land. Validation, audit trails, electronic signatures, retention, access review: all of it follows the classification. A system in scope gets the full treatment. A system outside it gets ordinary IT care.

The model held for thirty years, because a record sat in a system. Now your people ask an AI assistant instead of opening a system, and the answer it gives does not sit anywhere.

Scope is drawn around systems

Read any scoping guide and the unit is the system. Microsoft's own GxP page tells customers to "determine the GxP requirements that apply to their computerized systems based on the intended use." Intended use, one system at a time. The same page states there is no GxP certification for cloud providers at all, which is the honest position. A vendor can supply evidence. It cannot hand you compliance.

So the quality unit builds a list. The LIMS is in scope. The eQMS is in scope. The MES is in scope. The shared drive where people keep working copies is not. Neither is the chat channel, nor the deck a technical lead built for a supplier visit.

What GAMP 5 covers

GAMP 5, second edition, sharpens how that list gets handled. It presses for risk based approaches and for critical thinking by knowledgeable and experienced subject matter experts. Good advice for validating a system. It is still advice about systems.

The answer crosses the list

An operator has a question at ten past three. What is the maximum hold time for this intermediate?

A few years ago that meant opening the current procedure in the eQMS. Today it means typing the question into an assistant. The assistant reads what it can reach. It finds the procedure. It also finds a validation summary from 2023, a deviation write up, and a training deck with a number on slide eleven. It assembles one answer.

That answer is now a GxP answer. It is about to shape a GxP decision. Nothing on your scope list ever saw it.

Worse than a wrong document

A wrong document at least has a version, an owner and a change history. You can see who approved it. You can recall it and log the recall.

An answer has none of that. It was assembled once, read once, acted on once. Ask next week where the number came from and the honest reply is that nobody wrote it down.

Regulators are ahead of the scope list

The MHRA guidance on GxP data integrity is not built around systems. It sets out the core elements of a compliant data governance system across all GxP sectors, covering good laboratory, clinical, manufacturing, distribution and pharmacovigilance practice together. PIC/S PI 041-1 takes the same line for GMP and GDP. Both follow data through its life, wherever it travels.

ICH Q10 goes further. It names knowledge management as one of two enablers of an effective pharmaceutical quality system, alongside quality risk management. The wording is plain: product and process knowledge "should be managed from development through the commercial life of the product up to and including product discontinuation."

All of it is about knowledge

EU GMP Chapter 4 splits documentation into instructions and records, and asks that both be controlled. Every one of these texts is about knowledge. None of them is about a software licence.

And yet no system is required

Here is the gap, in the regulators' own words. The ICH Q9(R1) questions and answers ask whether inspectors expect a formal knowledge management approach. The answer: "No. There is no regulatory requirement for a formal knowledge management system. However, it is expected that knowledge from different processes and systems is appropriately utilised."

Read that twice. Knowledge has to be used well. No system has to hold it. So knowledge never reaches a scope list, and the controls never reach the knowledge.

What a classification scheme cannot see

Three questions expose it. Try them on your own estate this week.

Who approved the number that answer used? Not the document. The number, in the version that was read.

Which version was live at the moment the answer was given? An inspector asking about a batch released in March needs the March state of your knowledge, not today's.

What happens to that answer when the source changes next month? Somebody revises the procedure. The old answer is already out in a deck, a ticket and somebody's head.

Govern the knowledge, not the list

That is what the Cognatum Knowledge Loop is for. Eight steps, four phases, one gate. AI runs seven of the steps: it captures from every system where knowledge gets written, structures it, cleans it, enriches it, improves it, deploys it and serves it. A named person runs the sixth.

Capture is deliberately wide, and nothing captured is live. Breadth costs nothing when the gate is narrow.

Nothing has to move

Your departmental repositories stay where they are. Quality keeps its eQMS. Manufacturing keeps its MES. The shared drive carries on being a shared drive. Cognatum runs a bidirectional flow to the places you already work, so nobody is asked to migrate anything.

What changes is that something now sits above those repositories and can answer for what they say.

The step that stays human

Approve is the step a person holds. AI assembles the package: the entry, its sources, its history, and what changed since the last approved version. A named reviewer signs off. The decision is recorded with the approver, the date and the source, and the entry carries that record from then on.

Where two documents disagree, both are surfaced and the conflict goes to a person. Nothing is averaged. Nothing is settled by which file is newer.

When a source changes, Cognatum flags the entries that depend on it and queues a revision for the gate. It notifies. It does not quietly rewrite an approved answer, and it does not claim to keep itself current.

The uncomfortable test

Grounding an assistant in your own documents helps. It does not finish the job. The first preregistered study of retrieval based legal research tools found that products from LexisNexis and Thomson Reuters hallucinated between 17% and 33% of the time, against vendor claims of eliminating hallucinations.

Those tools read curated, authoritative material. Your assistant reads a shared drive.

Three facts, or none

So the test is not whether your systems are classified. It is whether you can name the person who approved the answer, the day they approved it, and the version of the source they read. If you cannot, that answer came from outside your GxP scope. It always did.

Your company's knowledge isn't missing. It's unusable. Cognatum changes that. You can book a 25 minute session and get a Knowledge Stack Report on your own estate.

Common questions

Questions this raises.

Does GxP compliance already cover answers from an AI assistant?

Not through system classification. GxP scoping assigns controls to computerized systems based on intended use, so validation, audit trails and retention attach to the system. An answer is assembled across several systems at once, some in scope and some not, and the assembled answer is not itself a classified record. The regulatory expectations about data integrity and knowledge do apply, which is exactly why the gap matters.

Our document management system is validated. Isn't that enough?

Validation shows the system does what it is specified to do. It says nothing about whether the content inside it is current, whether a second copy elsewhere contradicts it, or which version an assistant actually read when it answered. GAMP 5 governs the system lifecycle. It was never meant to govern the knowledge the system serves.

Does ICH Q10 require a knowledge management system?

No. ICH Q10 names knowledge management as an enabler of the pharmaceutical quality system and asks that product and process knowledge be managed across the product lifecycle. The ICH Q9(R1) questions and answers state plainly that there is no regulatory requirement for a formal knowledge management system, while adding that knowledge from different processes and systems is expected to be used appropriately.

Do we have to migrate our content into one place first?

No. Departmental repositories are normal and they are fine. Cognatum maintains a bidirectional flow to the systems where knowledge already lives, so the content stays where it is. The missing piece was never a single store. It was a governed layer above the stores that can say who approved an entry, when, and from what source.

Does Cognatum make us compliant with the EU AI Act or NIST AI RMF?

No, and no software can. Cognatum aligns with those frameworks and produces the evidence your reviewers ask for: approval records with approver, timestamp and source, version history, deployment records and retirement records. Compliance remains your obligation. The one settled certification is ISO 30401, which sits with Atokah Tech and holds while running on Atokah servers.

Knowledge governed. Intelligence everywhere.

See it on your own content, in your own environment.