Home / Frameworks / AI Governance Stack
AI in GxP

The AI Governance Stack

You’ve decided AI belongs in your GxP operations. The Stack is the architecture for that move. Traditional CSV assumes a fixed expected result, a system that stays put, behaviour independent of data, and visible failure; AI breaks all four. The Stack is how you keep control anyway.

The layers, bottom up 6 · Monitor & control:drift, performance, human-in-the-loop, decision records 5 · Validation master plan:risk-based, model-specific 4 · Governance operating model:AI Governance Board, RACI, decision rights 3 · Classify & four-tier GxP risk model 2 · Reference architecture:data, model, workflow, record, audit trail 1 · Regulatory spineAnnex 11 · draft Annex 22 · 21 CFR Part 11 · FDA CSA · FDA-EMA principles governance precedes validation →
Governance precedes validation. Each layer rests on the one below it.

The four-tier GxP risk model

Classification is the most consequential hour in an AI system's lifecycle. The model tiers a use case by its impact on product quality and patient safety and by the system's autonomy, then sets the assurance accordingly. A worked example from the book: an HPLC chromatogram review classifier sits at Tier 2, and a case where a system drifted from Tier 2 to Tier 3 in eighteen months shows why reclassification triggers matter.

TierImpact & autonomyAssurance
Tier 1Low impact, assistive onlyLight, with basic controls
Tier 2Significant GxP, human sign-offModel validation and decision records
Tier 3High impact or higher autonomyFull validation, tight monitoring, strong oversight
Tier 4Critical or autonomous in critical useThe heaviest controls, or kept out of that use

Why AI breaks traditional CSV

Traditional CSV assumesAI reality
A fixed expected resultResults are probabilistic
A system that stays putThe model can change
Behaviour independent of dataBehaviour depends on training data
Failure is visibleFailure is often silent

The layers, bottom up

Governance precedes validation. The regulatory spine (Annex 11, the draft Annex 22, 21 CFR Part 11, FDA CSA, the FDA-EMA principles) is the base. On it sits the reference architecture: data, model, workflow, record and audit trail. Then classification and risk tiering; then the governance operating model (an AI Governance Board, RACI and decision rights); then a risk-based, model-specific validation master plan; and at the top, monitoring and control for drift, performance, human-in-the-loop and decision-integrity records that capture input, output, reviewer and disposition.

Key takeaways

See the AI in GxP service → Take the AI-in-GxP Readiness Index