01
Digital strategy, portfolio & architecture
What the organisation intends to run digitally and why: target architecture, roadmap, investment, ownership of each capability, deliberate reuse, and the technical debt already carried.
Regulated organisations accumulate systems faster than they retire them, and each one carries a validation and support obligation for its whole life. Strategy is where that obligation is taken on deliberately rather than discovered later.
HOW IT FAILS
- Systems are selected per function, so four departments run four tools that do substantially the same thing, each validated separately.
- Retirement is never funded, so legacy systems stay live for data-retention reasons long after their support ended.
- Technical debt is acknowledged in architecture reviews and never appears in a budget.
WHAT CONTAINS IT
- A capability-level target architecture that new system requests are assessed against before procurement.
- Retirement and data-migration planned and funded as part of any replacement, not deferred.
- Technical debt tracked with the validation and security exposure it represents, visible to governance.
EVIDENCE IT OPERATES
- Target architecture and roadmap with capability ownership.
- System selection decisions assessed against existing capability.
- Retirement plans and the debt register with exposure.
02
GxP application landscape
The regulated application estate — eQMS, LIMS, MES, ERP, RIM, clinical and safety systems — and the boundaries that say which system is authoritative for which record.
When two systems hold the same fact, the organisation has two answers and no way to tell which is right. Boundary clarity is what makes a record retrievable and defensible rather than merely present in several places.
HOW IT FAILS
- The same master data are maintained in two systems, and reconciliation happens by periodic export rather than by design.
- A system used for a GxP decision was procured as a business tool and never entered validation scope.
- Boundaries are defined at implementation and drift as functionality is added by configuration.
WHAT CONTAINS IT
- One authoritative system per record type, with the others consuming rather than maintaining.
- A trigger that brings any system into validation scope when its output starts supporting a GxP decision.
- Periodic reconciliation of documented boundaries against the functionality actually in use.
EVIDENCE IT OPERATES
- System landscape with authoritative-record ownership per data domain.
- Validation scope decisions including systems assessed and excluded.
- Periodic review of boundary and functionality drift.
03
Integration & interoperability
How systems exchange information: interfaces and APIs, events, master data, the semantics on each side, reconciliation, error handling and lineage across the boundary.
Integrations are where regulated data most often lose their meaning — not through corruption but through a field that means something slightly different on each side. Errors here are silent by construction, because a successful transfer looks identical to a correct one.
HOW IT FAILS
- Failed or partial transfers are retried without alerting, so a gap in the receiving system is never noticed.
- Units, precision or time zones differ across an interface, and the discrepancy is small enough to look plausible.
- Lineage stops at the interface, so a value in a downstream report cannot be traced to the record it came from.
WHAT CONTAINS IT
- Reconciliation by count and content after transfer, with exceptions raised rather than logged.
- Interface specifications that define semantics, units, precision and time base explicitly on both sides.
- Lineage maintained across the boundary so a downstream value resolves to its source record.
EVIDENCE IT OPERATES
- Interface specifications and their verification records.
- Transfer reconciliation reports and exception handling.
- Lineage documentation traceable from report back to source.
04
Data governance & stewardship
Deciding who owns data, what each element means, how good it must be, how it is classified, where it came from, how long it is kept and who may use it for what.
Every analytical and AI capability inherits the quality of the governance beneath it. Where definitions are unowned, two reports disagree and both are defensible, and the organisation debates the numbers instead of the decision.
HOW IT FAILS
- Ownership is assigned to IT, which controls the system but cannot rule on what a business term means.
- Data quality is measured on completeness alone, so a field that is fully populated with the wrong values scores perfectly.
- Retention rules exist per system rather than per record type, so the same record is kept differently depending on where it landed.
WHAT CONTAINS IT
- Business data ownership with authority to define terms, distinct from system custodianship.
- Quality measured on accuracy and validity, not only completeness and timeliness.
- Retention driven by record type and regulatory obligation, applied consistently across systems.
EVIDENCE IT OPERATES
- Data ownership register and business glossary with approval.
- Data quality measures and remediation records.
- Retention schedule mapped to record types and its application per system.
05
Data integrity & records
The attributes a regulated record must hold throughout its life — attributable, legible, contemporaneous, original, accurate, and enduring — together with audit trails, review and the metadata that make them verifiable.
Data integrity is the most common subject of serious regulatory findings, and the failures are rarely fabrication. They are ordinary conveniences — a shared login, an unreviewed audit trail, a reprocessed result — that make the record unable to prove what it asserts.
HOW IT FAILS
- Shared or generic accounts remain in use, so no record is attributable to a person.
- Audit trail review is required by procedure and not performed, or performed without a defined scope.
- Records are complete in the system and unreadable after the application version that wrote them is retired.
WHAT CONTAINS IT
- Individual accounts with privileges that prevent a user deleting their own data.
- Risk-based audit trail review with defined scope, frequency and recorded outcome.
- Enduring readability verified across software change, not assumed from backup existence.
EVIDENCE IT OPERATES
- Access and privilege records with periodic review.
- Audit trail review records with scope and findings.
- Archive readability verification across application versions.
06
Platforms, cloud & infrastructure services
What the applications run on: hosting model, shared services, environment management, observability, portability and the suppliers who operate any of it.
Moving to a managed platform moves the work, not the accountability. The regulated organisation still has to demonstrate control over a system whose infrastructure it neither operates nor can inspect directly.
HOW IT FAILS
- Supplier assurance rests on a certification report nobody has read against the specific controls that matter here.
- Environments drift, so testing is performed on a configuration that differs from production in ways nobody tracked.
- Exit is theoretically possible and practically impossible, because data portability was never tested.
WHAT CONTAINS IT
- Supplier assurance evidence assessed against the specific regulated requirements, not accepted as a certificate.
- Environment configuration managed and compared, so test and production differences are known.
- Exit and portability tested, including whether exported data remain readable and complete.
EVIDENCE IT OPERATES
- Supplier assessment records with the controls examined and the gaps carried.
- Environment configuration baselines and comparison results.
- Portability or exit testing evidence, including export readability.
07
Analytics, BI & decision support
Turning data into decisions: curated datasets, defined metrics, visualisation, statistical use, self-service tooling, reproducibility and the context a number needs to be read correctly.
Analytics is where a data-quality problem becomes a decision. Self-service accelerates that in both directions — the same freedom that lets a good question be answered quickly lets a wrong metric spread across the organisation before anyone checks it.
HOW IT FAILS
- The same metric is calculated differently in three dashboards, and each owner believes theirs is correct.
- A number is presented without the denominator, window or exclusions that determine what it means.
- Analyses used for regulated decisions are not reproducible, because the dataset behind them was not versioned.
WHAT CONTAINS IT
- Certified metric definitions with one owner, consumed rather than reimplemented by each report.
- Metric presentation that carries its definition, window and exclusions with it.
- Dataset versioning for analyses that support regulated decisions, so a result can be regenerated.
EVIDENCE IT OPERATES
- Metric catalogue with definitions, owners and calculation logic.
- Certified datasets with ownership and version history.
- Reproducibility evidence for analyses supporting regulated decisions.
08
AI, ML & agentic systems
Models and agentic systems in regulated work: context of use, the data behind them, evaluation, human oversight, the tools an agent may invoke, stated limitations, monitoring and change.
A model is a control whose failure mode is confident and plausible output. Unlike an instrument, it does not read out of range when it leaves the conditions it was built for — which is why the boundary must be enforced around it rather than expected from it.
HOW IT FAILS
- Deployment scope widens informally, so the model supports decisions its evaluation never covered.
- Human oversight is nominal: the reviewer sees the output but not the basis for it, and approves what looks reasonable.
- An agentic system is given tools whose blast radius was never assessed, so an error becomes an action.
WHAT CONTAINS IT
- A context-of-use statement enforced in the workflow, not only documented.
- Oversight designed so the reviewer sees the evidence and can disagree, with disagreement recorded.
- Tool permissions for agentic systems scoped and reviewed as privileged access.
EVIDENCE IT OPERATES
- Context of use, evaluation results and stated limitations.
- Human review and override records with the basis presented.
- Agent tool permissions, action logs and monitoring records.
09
Content, records & knowledge platforms
The platforms that hold documents and knowledge: structured content, document services, search, taxonomies, archival, retrieval and the reuse of what the organisation already knows.
A record that cannot be found within the time an investigation or inspection allows is functionally missing. Retrieval, not storage, is the obligation — and it is the one least often tested.
HOW IT FAILS
- Search returns by title only, so a document whose title does not match the question is effectively lost.
- Taxonomies are designed once and never maintained, so new content is filed wherever it fits.
- Retrieval within the required timeframe is assumed rather than periodically demonstrated.
WHAT CONTAINS IT
- Metadata and taxonomy governed and maintained, with content classified at creation.
- Retrieval tested against realistic inspection questions, not against known document identifiers.
- Archival that preserves searchability, not only bytes.
EVIDENCE IT OPERATES
- Taxonomy and metadata standards with maintenance records.
- Retrieval test results against representative queries and timeframes.
- Archival records demonstrating searchable, readable retrieval.
10
Digital product lifecycle & service management
Running digital services: requirements, delivery, release, incident and problem management, change, supplier management, service levels and retirement.
The validated state is maintained or lost in routine service management. Most loss happens through ordinary operational work — a patch, an emergency fix, a configuration change made under incident pressure — rather than through projects.
HOW IT FAILS
- Emergency changes bypass assessment and are retrospectively documented without anyone re-checking validation impact.
- Incidents are closed on service restoration without asking whether regulated data were affected.
- Service levels are agreed on availability and say nothing about data integrity or record retrieval.
WHAT CONTAINS IT
- An emergency change path that is fast but still assesses GxP impact, with mandatory retrospective review.
- Incident classification that explicitly asks whether regulated records or decisions were affected.
- Service levels covering integrity and retrieval obligations, not only uptime.
EVIDENCE IT OPERATES
- Change records including emergency changes and their retrospective assessment.
- Incident records with regulated-impact determination.
- Service level agreements and performance against the integrity-related terms.