AIV tells you how much validation your AI system needs and builds the evidence to prove it.
You have an AI system in quality, or one on the way, and nobody can tell you how much validation it needs or what the evidence should look like. AIV classifies the system by GxP risk, sizes the validation to that risk, builds the evidence set and records every test, deviation and release under a signature made by a named person.
In development. Working prototype since July 2026.
Here is what AIV does with one AI system
Give it one system, a classifier, a vision model, an LLM application, a RAG assistant or an agent, built in-house or bought from a supplier. It works through 4 steps and leaves a record at each one.
Classify it
AIV sets the GxP risk tier from what happens when the output is wrong. A simple model that routes deviations carries more weight than a complex one that draws a dashboard. The 4-tier model is the one from the book, and the answer is traceable to the questions that produced it.
Size the validation to the risk
The tier decides how much validation the system gets. A dashboard nobody acts on gets a light touch. A system that routes a CAPA gets the full treatment. Nothing is padded and nothing is skipped.
Build the evidence set
Intended use, acceptance criteria, protocols and records come out ready for review. The AI layer drafts them. A named person reads and approves each one before it counts.
Record execution and release
Each test is recorded as pass, fail or blocked, with the tester and the timestamp. Deviations are logged. Release happens under an electronic signature, and the record shows who signed and what they meant by it.
After release, AIV keeps the system under control. Monitoring watches for drift, and a set of triggers sends the system back for reclassification when its scope, its data or its performance changes. Every decision the engine makes follows a published rule, so you can show an inspector why it decided what it did.
The AI drafts. A person signs.
The AI layer inside AIV drafts documents, proposes acceptance criteria, extracts facts from the material you give it and rehearses the inspection with you. That is where it stops. It never classifies a system, never signs a record and never lowers a criterion. Those 3 things stay with a named person, every time, and the rule is built into the product rather than written in a policy.
Roles are separated. A tester records the result. A different person approves it. Nobody can approve their own work, and the system will refuse the attempt rather than warn about it afterwards.
Every signature carries 4 things: the name, the role, the meaning of the signature and the timestamp. That is the shape 21 CFR Part 11 asks for, and it is the shape an inspector expects to find. A signature can be voided with a reason and the void is itself recorded. Nothing is ever deleted.
Your data trains nothing. The AI layer runs on a private endpoint, and what you put into AIV stays in your evidence record and goes nowhere else.
Here is what AIV does not do
AIV is built for the AI-specific part of validation and nothing else. It stays out of 4 things on purpose.
It does not validate non-AI software
Your ERP, LIMS, eQMS and the rest are validated the way they are today. AIV does not touch them.
It does not do equipment, process or cleaning validation
These live in your existing validation programme and platform. AIV has no view on them.
It does not write test scripts for your other systems
AIV writes the evidence set for an AI system. It does not generate test scripts for the customer systems around it.
It does not measure the model
AIV does not compute accuracy, precision or drift. It takes the numbers from your own tools and turns them into evidence with acceptance criteria and signatures.
Those needs are met by the validation platform you already run. AIV is designed to sit beside it, so you keep one system of record for validation and add the AI-specific evidence to it.
Try the classification step now
Answer 4 questions about one AI system and you'll see its GxP risk tier, what that tier means and the validation shape it calls for. The tier comes from what happens when the output is wrong, so a simple model can sit higher than a complex one.
1. Does the output influence a GxP decision at all?
2. If it were wrong on 10% of records for 6 months without anyone noticing, would patient safety, product quality or data integrity be at material risk?
3. Does a qualified human review and approve every output before a GxP action is taken?
4. Can a human override the decision through an exception path that actually exists in the deployed workflow?
This is the classification step. AIV takes it from here: it sizes the validation, builds the evidence set and records the execution.
Why a consultancy is building this
The method came first. It was written down in Validating AI in GxP: A Practitioner's Guide, then used on consulting engagements with pharma quality teams, then taught in training rooms. By the time the same 4 questions had been asked of enough AI systems, it was clear the method worked and that it worked the same way each time.
The prototype was built to run that method the same way every time, without a consultant in the room. It has been running since July 2026. Each time it runs, the rules stay the same and the evidence comes out in the same shape, which is exactly what an inspector wants to see.
TrustBridge Compliance is a DPIIT-recognised startup, Government of India, certificate DIPP285442. The product is being built in India for a global market, by the person who wrote the method and has taken validated AI systems through regulatory inspection.
There are 2 kinds of pilot and they start with one conversation
I'm running a small number of pilots with 2 kinds of organisation. Both get the same thing and both are asked for the same thing.
You run quality in pharma, biotech or a CDMO and have 1 or 2 AI systems in use or planned
You need those systems validated to a defensible standard before an inspector asks about them, and you'd rather do it once with a method that holds than improvise it. A pilot gets you early access to the working prototype, my own hands on the first validation and a say in what the product becomes.
You sell AI into pharma and your customers keep asking how to validate it
Every customer validates your product differently, and each one takes months. A pilot gets you one validated method your customers can inherit, my own hands on the first validation and a say in what the product becomes.
What I ask for in return: one real AI system, honest feedback and permission to describe the outcome without naming your company.
Questions people ask about AIV
Is AIV a replacement for my validation platform?
No. AIV sits beside your existing validation platform and handles the AI-specific part: the risk tier, the evidence set an AI system needs, the execution record and the controls that keep the system in check after release. Your ERP, LIMS and equipment validation stay where they are today.
Does AIV compute model metrics?
No. AIV takes the numbers your own tools produce, such as accuracy on a test set or drift readings in production, and turns them into evidence with acceptance criteria, a tester, a timestamp and a signature. Measuring the model stays with the tools built for that.
Who signs?
A named person does. The AI layer drafts and proposes. It never classifies a system, never approves a result and never lowers a criterion. Roles are separated, so the person who ran a test cannot approve their own result, and every signature carries a name, a role, a meaning and a timestamp. A signature can be voided with a reason. It can never be deleted.
Is my data used to train anything?
No. Nothing you put into AIV trains a model, ours or anyone else's. The AI layer runs on a private endpoint, and what you enter stays inside your evidence record.
When can I buy it?
AIV is in pilot with a working prototype that has run since July 2026. I'm publishing no release date. If you have an AI system you need to validate, ask about a pilot and we'll talk about whether it fits.
Tell me about the AI system you need to validate.
If you'd rather talk than fill in a form, book a conversation and bring the system with you.
Talk to Sachin