Cognatum

Life sciences

Inspection readiness never tests the answer

Inspection readiness programs test two things: whether you can produce the document, and whether your people can speak to it. Both assume someone reached for a record. Increasingly, they asked an assistant instead.

Cognatum Team · Oct 5, 2026 · 6 min read

An inspection can begin with a knock at the door. Teams in regulated industries plan for that. SOPs are kept current. Mock audits run without warning. One person is named to escort the investigator, and another is named to take notes.

Served to one approved entry
AI assistants & agents
Proposal tools
Internal search & chat
Customer portals
Compliance & audit

Cognatum governs the entry

source · version · approver · permissions

Then a technician asks an AI assistant what the procedure says, and works from the reply. That exchange leaves nothing behind. No readiness program has a line for it.

What a readiness program tests

The firms that run these programs agree on the shape of the work. Keep documentation current and traceable. Run internal inspections without notice. Assign clear roles. Keep CAPA moving. The FDA Group's 2026 readiness guide lists the mock inspection practices plainly, and two of them matter here: "Test document retrieval and presentation systems" and "Practice SME interviews and facility tours."

Gates Healthcare Associates puts the same test in one line. "Test retrieval. Ask staff to locate key records without advance preparation." Delays and inconsistent answers, the firm notes, point to a document control or training problem underneath.

Two tests, one assumption

So a mature program checks two things. Can you produce the document. Can your people speak to it. Both tests run against records. Both assume the person answering reached for one.

The path nobody rehearses

That assumption has quietly stopped being true. An assistant reads a shared drive, a chat thread, a slide deck and a wiki page. It returns a paragraph. The paragraph is fluent, and it is not a record. It carries no version, no effective date and no approver.

Because it is not a record, it never enters document control. Because it never enters document control, the mock audit cannot sample it. The readiness program is complete, internally consistent, and blind to the route most answers now travel.

A worked example

Ask how long a bulk intermediate may be held before reprocessing. A validation summary from 2023 says thirty days. The current SOP says fourteen. A chat thread from last spring says it depends on the campaign, and links nothing. All three sit in systems the assistant can read.

The assistant answers with one number. Nobody is told which of the three it used. The number is then written into a batch record by a person who believed they were following the procedure.

Why the trail breaks

A document trail runs backwards from an artifact. You hold the record, so you can find its version, its approval and its history. An answer has no artifact to start from. There is no thread to pull.

Knowledge is already in scope

This is not a gap the regulators left open. ICH Q10 names knowledge management as one of two enablers of a pharmaceutical quality system, alongside quality risk management, and defines it as "a systematic approach to acquiring, analysing, storing, and disseminating information related to products, manufacturing processes and components." EU GMP Chapter 1 arrives from the other direction. It requires that "product and process knowledge is managed throughout all lifecycle stages."

The ICH Q9(R1) questions and answers settle the obvious follow-up. Is a formal system required? "No. There is no regulatory requirement for a formal knowledge management system. However, it is expected that knowledge from different processes and systems is appropriately utilised."

What that leaves you holding

No inspector will ask to see your knowledge platform. An inspector can ask how a person knew what they knew, and expect the answer to hold up. The MHRA's GxP data integrity guidance exists because of failures found during GLP, GCP, GMP and GDP inspections, many of which drew regulatory action. PIC/S takes the same line on data integrity across regulated environments.

Grounding is not a readiness control

The usual reassurance is that retrieval grounds the answer in your own approved content. Grounding helps. It does not settle the matter.

The first preregistered study of retrieval-based legal AI tools found that Lexis+ AI, Westlaw AI-Assisted Research and Ask Practical Law AI each hallucinated between 17 and 33 percent of the time. The vendors had claimed to eliminate hallucination outright. Grounding cut the rate. It did not remove it.

A second problem survives a perfect retrieval rate. Grounding tells you the answer came from a document. It does not tell you that the document was approved, that it was current, or that it was the only one in the library with something to say on the subject.

What the law asks logs to hold

The EU AI Act requires high-risk AI systems to allow automatic recording of events over the lifetime of the system, so their functioning is traceable. The detailed minimum list applies to one narrow class of biometric systems. It covers periods of use, the reference database, the matched input data and the people who verified a result. The approval status of a source document is not on the list, because it is not a fact about the system.

What readiness for answers would need

Cognatum is a knowledge base built so the answer carries a record. Its framework is the Cognatum Knowledge Loop: eight steps in four phases, running continuously. AI runs seven of them. A named person holds step six, Approve, and nothing reaches a colleague or an AI system without passing it.

What the gate produces

Every live entry carries its approver, the approval date, the source it came from and its version. When an assistant answers from Cognatum, the answer ties back to the entry and the version it drew from. Cognatum also keeps where the knowledge stood at the moment the answer was given, which is what a reviewer asks about months later.

The three cases that break a library

Where two approved entries disagree, both are held apart and routed to a named person. Neither is averaged, and neither wins on recency. Where a source changes, dependent entries are flagged and a revision queues for the gate, so readers keep the last approved version until a person signs off. Cognatum notifies. It does not quietly rewrite.

Where nothing approved covers the question, the assistant says so and the gap is recorded with an owner. A list of what your library does not cover is evidence in its own right. It is better held in advance than discovered one bad answer at a time.

What this is not

None of this confers compliance. No software makes an organization compliant with the EU AI Act, with NIST's AI Risk Management Framework, or with a GxP expectation. What governed knowledge supplies is the trail a reviewer asks for: approver, date, source, version, deployment and retirement. ISO 30401 certification is the one exception, and it sits with Atokah Tech, holding while Cognatum runs on Atokah servers.

One test to add to your next mock audit

Do not ask the quality team to find a document. Ask the question the way the floor asks it, into the assistant the floor actually uses. Then ask for the approved entry behind the reply, the person who approved it and the date. If that takes a meeting, the readiness program has a hole in it.

Your company's knowledge isn't missing. It's unusable. Cognatum changes that.

Common questions

Questions this raises.

Does inspection readiness cover AI assistants?

Not in the usual form. Readiness programs test whether a record can be retrieved and whether staff can speak to it. An AI answer is neither a record nor a person, so it falls outside both tests while still shaping what people do.

Is a knowledge management system required under GxP?

No. The ICH Q9(R1) questions and answers state plainly that there is no regulatory requirement for a formal knowledge management system, while adding that knowledge from different processes and systems is expected to be appropriately utilised. ICH Q10 names knowledge management as an enabler of the quality system, and EU GMP Chapter 1 requires product and process knowledge to be managed across all lifecycle stages.

Does retrieval make an AI answer inspection ready?

No. Retrieval anchors an answer to a document, which is useful and not sufficient. A preregistered study of retrieval-based legal research tools measured hallucination rates between 17 and 33 percent. Retrieval also says nothing about whether the document it found was the approved and current one.

What should an AI answer carry to be defensible?

A named approver, an approval date, the source it derives from and the version of that source. It also helps to record where the knowledge stood at the moment the answer was given, since a reviewer usually asks long after the fact.

Does Cognatum keep knowledge current on its own?

No, and it is not described that way. When a source changes, Cognatum flags the entries that depend on it and queues a revision for the human Approve gate. Readers keep the last approved version until a person signs off. Cognatum notifies rather than rewriting.

Knowledge governed. Intelligence everywhere.

See it on your own content, in your own environment.