
Auditing an AI application under GxP requirements requires a different mindset than auditing a traditional computerized system. The auditor must understand not only the regulatory expectations but also the technical characteristics that make AI systems unique. This blog provides a practical guide to planning, executing, and reporting AI application audits in GxP environments. It also explains how GxP Cellators can support your organization through every phase of the audit process.
Phase 1: Audit Planning and Preparation
Understanding the AI Application
Before the audit begins, the auditor must understand the AI application being audited.
- What is the intended use of the AI application
- What GxP activities does it support
- What is the risk level of the application
- What type of AI or machine learning model is used
- How was the model developed and trained
- How does the model produce outputs
- What human oversight exists
Reviewing Documentation
The auditor should review available documentation before the audit.
- System requirements specification
- Validation plan and report
- Model development documentation
- Training data documentation
- Risk assessment
- Standard operating procedures
- User manuals and training materials
Defining Audit Scope and Criteria
The audit scope should clearly define what will be examined and against what criteria.
- Which AI systems or models will be audited
- Which GxP regulations and standards apply
- What processes and documentation will be reviewed
- What personnel will be interviewed
- What testing or verification will be performed
Phase 2: Audit Execution
Opening Meeting
The audit begins with an opening meeting to confirm scope, objectives, and logistics.
- Introduce the audit team
- Confirm the audit scope and criteria
- Explain the audit process and timeline
- Confirm confidentiality arrangements
- Schedule interviews and document reviews
Document Review
The auditor reviews documentation to verify compliance.
- Is the validation documentation complete and approved
- Is the risk assessment documented and appropriate
- Is the training data documentation sufficient
- Is the model development documentation complete
- Are standard operating procedures current and followed
Interviews
Interviews with key personnel provide insight into actual practices.
- System owners and administrators
- Quality assurance personnel
- End users of the AI application
- IT and data management personnel
- Vendor representatives if applicable
System Walkthrough
The auditor examines the AI system in operation.
- How is the system accessed and used
- What controls are in place for data input
- How are outputs generated and reviewed
- What audit trails exist
- How are model updates managed
Testing and Verification
The auditor may perform testing to verify controls.
- Verify that audit trails capture required information
- Verify that access controls are effective
- Verify that outputs are attributable to the system
- Verify that human oversight is documented
- Verify that model version control is effective
Phase 3: Findings and Classification
Identifying Findings
Findings are identified when practices or documentation do not meet audit criteria.
- Critical findings: direct impact on patient safety or data integrity
- Major findings: significant deviation from requirements
- Minor findings: isolated or low impact issues
- Observations: opportunities for improvement
Classifying Findings
Each finding should be classified based on risk and impact.
| Classification | Definition | Response Required |
| Critical | Direct impact on patient safety or data integrity | Immediate action required |
| Major | Significant deviation from requirements | Corrective action required |
| Minor | Isolated or low impact issue | Correction recommended |
| Observation | Opportunity for improvement | Consideration recommended |
Phase 4: Reporting and Follow Up
Audit Report
The audit report documents findings and recommendations.
- Executive summary
- Audit scope and criteria
- Methodology
- Findings with classification
- Root cause analysis where applicable
- Corrective and preventive action recommendations
- Attachments and evidence
Close Out Meeting
The close out meeting presents findings to the auditee.
- Present findings and classifications
- Discuss root causes and corrective actions
- Confirm timelines for CAPA
- Document agreements and disagreements
CAPA Follow Up
The auditor verifies that corrective and preventive actions are implemented.
- Review CAPA plans
- Verify implementation
- Assess effectiveness
- Close findings when appropriate
How GxP Cellators Supports AI Application Audits
GxP Cellators provides comprehensive AI application audit services for GxP organizations. Our auditors have experience with both traditional CSV and emerging AI technologies. We help you navigate the unique challenges of auditing AI systems and demonstrate compliance to regulators.
Our AI Audit Services Include:
- Full scope AI application audits from planning through reporting
- Pre audit readiness assessments for AI systems
- Mock AI audits to prepare your team for regulatory inspection
- AI governance framework assessments
- Data integrity audits for AI systems
- AI model validation documentation reviews
- Vendor and supplier audits for AI applications
- CAPA verification and follow up audits
- Training on AI auditing best practices
Why Choose GxP Cellators for AI Audits:
- Auditors with deep experience in both GxP and AI technologies
- Coverage of FDA, EMA, Health Canada, MHRA, and WHO requirements
- Risk based audit approach tailored to your AI applications
- Clear, actionable reports that support remediation
- Full confidentiality for your proprietary systems
Frequently Asked Questions
Q1: What is the first step in auditing an AI application under GxP?
The first step is understanding the AI application. You must know its intended use, the GxP activities it supports, the type of model used, how it was developed and trained, and what human oversight exists. This understanding forms the basis for the audit plan.
Q2: How long does an AI application audit take?
The duration depends on the complexity of the AI application, the scope of the audit, and the availability of documentation. A focused audit of a single AI application may take several days. A comprehensive audit of multiple AI systems across an organization may take several weeks.
Q3: What qualifications should an AI auditor have?
An AI auditor should have experience with GxP regulations including 21 CFR Part 11 and EU GMP Annex 11. They should understand computer system validation principles. They should also have knowledge of AI and machine learning technologies, including model development, training data, and performance monitoring.
Q4: What are common findings in AI application audits?
Common findings include incomplete AI system inventories, lack of AI governance frameworks, inadequate training data documentation, insufficient model validation documentation, and inadequate human oversight processes.
Q5: How does GxP Cellators support AI application audits?
GxP Cellators provides full scope AI application audits, pre audit readiness assessments, mock audits, governance reviews, data integrity audits, and vendor audits. We help you identify gaps and prepare for regulatory inspections.
Q6: How do I contact GxP Cellators for AI audit support?
You can reach us through our contact page at /contact/ to discuss your AI audit requirements.
Contact GxP Cellators
If you need support with AI application audits under GxP requirements, please contact GxP Cellators.
Contact: /contact/

