info@trustbridge-compliance.com
Home / Frameworks / AI Governance Stack
AI in GxP

The AI Governance Stack

You’ve decided AI belongs in your GxP operations. The Stack is the architecture for that move. Traditional CSV assumes a fixed expected result, a system that stays put, behaviour independent of data, and visible failure; AI breaks all four. The Stack is how you keep control anyway.

The layers, bottom up · governance precedes validation
06

Monitor & control

Drift, performance, human-in-the-loop and decision records.

05

Validation master plan

Risk-based and model-specific, not a one-size template.

04

Governance operating model

AI Governance Board, RACI, decision rights.

03

Classify & four-tier risk model

Tier the use case on impact and autonomy.

02

Reference architecture

Data, model, workflow, record, audit trail.

01

Regulatory spine

Annex 11 · draft Annex 22 · Part 11 · FDA CSA · FDA-EMA principles.

Governance precedes validation. Each layer rests on the one below it.

The four-tier GxP risk model

Classification is the most consequential hour in an AI system's lifecycle. The model tiers a use case by its impact on product quality and patient safety and by the system's autonomy, then sets the assurance accordingly. A worked example from the book: an HPLC chromatogram review classifier sits at Tier 2, and a case where a system drifted from Tier 2 to Tier 3 in eighteen months shows why reclassification triggers matter.

TierImpact & autonomyAssurance
Tier 1Low impact, assistive onlyLight, with basic controls
Tier 2Significant GxP, human sign-offModel validation and decision records
Tier 3High impact or higher autonomyFull validation, tight monitoring, strong oversight
Tier 4Critical or autonomous in critical useThe heaviest controls, or kept out of that use

Why AI breaks traditional CSV

Traditional CSV assumesAI reality
A fixed expected resultResults are probabilistic
A system that stays putThe model can change
Behaviour independent of dataBehaviour depends on training data
Failure is visibleFailure is often silent

The layers, bottom up

Governance precedes validation. The regulatory spine (Annex 11, the draft Annex 22, 21 CFR Part 11, FDA CSA, the FDA-EMA principles) is the base. On it sits the reference architecture: data, model, workflow, record and audit trail. Then classification and risk tiering; then the governance operating model (an AI Governance Board, RACI and decision rights); then a risk-based, model-specific validation master plan; and at the top, monitoring and control for drift, performance, human-in-the-loop and decision-integrity records that capture input, output, reviewer and disposition.

Key takeaways

  • Decision integrity is the new layer on top of data integrity.
  • Classify first; the tier drives every downstream control.
  • Monitoring is not optional: AI does not stay put, and failure can be silent.