Guide · AI in GMP

EU GMP Annex 22 Readiness for India’s SME Pharma

What the draft signals about AI in GMP decisions — and how to build the evidence trail before the rules harden.

Vimal Veereshwarayya, PhD, RACFounder, Verixa 8 min read Draft, not law

EU GMP Annex 22 readiness means preparing your quality system so that, when AI or machine-learning tools touch a GMP decision, a qualified human still reviews and approves it — and every step is traceable. The draft (2025) signals emerging expectations, not enforceable law, that favour governed, human-in-the-loop AI with a defensible evidence trail.

AI assists.
The human decides.
The trail records.

That single idea is the through-line of the whole draft. Everything below unpacks what the text actually says, how it lines up with parallel moves from the FDA and ICH, and what an India SME exporter can do now — without over-investing in rules that are still being written.

01Why this lands on India's desk first

Two pressures arrive together.

India is the second-largest supplier of medicines to regulated Western markets. A large share of that volume comes from small and mid-sized manufacturers — emerging biotech, ATMP and cell-and-gene developers, and specialty CDMOs.

Many of these sites carry a real GMP burden but run quality records on a mixture of paper, spreadsheets, and a first-generation electronic system never designed with AI in mind. When a draft annex describes how AI should behave inside GMP decisions, these sites feel the gap first.

The regulatory direction across Europe and the US is converging: AI can assist, but a qualified human must own the decision and the record must show it.

The commercial pull toward AI in quality work is real — deviation triage, root-cause analysis, and CAPA drafting are exactly the slow, evidence-heavy tasks where assistance is tempting.

The risk for an SME is adopting AI in a way that later looks ungoverned. Readiness is about adopting it in a way that does not.

02What the Annex 22 draft actually says

Three signals stand out.

EU GMP Annex 22 is the European medicines framework’s draft annex on artificial intelligence in GMP. It was published for consultation in 2025 and is not yet enforceable. Read its direction, not any single line, as a settled requirement.

1

AI is an input, not the decision

The draft positions AI and machine-learning outputs as inputs to a decision rather than the decision itself. For anything affecting product quality, patient safety, or data integrity, a qualified person is expected to review and approve — the model proposes, the human disposes. Human-in-the-loop as a design principle.

2

Traceability extends to the AI step

Whatever the tool contributes — a suggested classification, a draft root-cause narrative, a proposed CAPA — must be captured so an assessor can later reconstruct it. What the model saw, what it proposed, who reviewed it, what they changed, and what was approved must all be visible.

3

The model has a lifecycle

The draft treats the model as something that must be defined, evaluated against its intended use, monitored, and controlled when it changes. Familiar language from computerised-system validation — now pointed at AI. You should be able to say what a tool is for, where its limits are, and how a human stays accountable.

Read it as a direction of travel. Because Annex 22 is still in draft, the smart move is not to chase a checklist that may shift. It is to make sure your AI use already embodies the principle the draft keeps returning to: a qualified human reviews and approves, and the evidence trail proves it.

03Annex 22 is not moving alone

One principle, echoed across the landscape.

An India SME exporting to multiple markets is effectively being asked the same question by several authorities at once.

EU GMP Annex 22 (draft, 2025)

AI assists; a qualified human reviews and approves critical GMP decisions; the AI step is traceable; the model has a defined, monitored lifecycle.

FDA — Computer Software Assurance (CSA)

Risk-based critical thinking over volume documentation. For pharma GMP it is a directional read-across that fits governed, well-evidenced AI tooling.

ICH Q9(R1) — Quality Risk Management

Decisions should be risk-based and documented; supports treating AI output as a risk input that a human weighs, not a verdict.

ICH Q10 — Pharmaceutical Quality System

CAPA and continual improvement must be traceable end-to-end — the chain AI is most often used to accelerate.

ISPE GAMP 5 (2nd Ed.) + ISPE/PDA guidance

Practical, risk-based framework for computerised systems and, increasingly, AI/ML; reinforces the same evidence-and-traceability expectations.

India — Revised Schedule M (revised GMP)

Deviation management, CAPA traceability, and audit-trail integrity are now explicitly expected of Indian manufacturers.

Build for the shared principle — governed AI, human-in-the-loop, fully traceable — and you move toward all of them at the same time.

Note on currency: regulatory status reflects mid-2026; confirm the current Annex 22 draft and FDA CSA status against the European medicines framework and fda.gov.

04The readiness gap

For an SME without a mature eQMS, the gap is structural.

For a large pharma with a mature electronic quality system, absorbing a new annex is mostly configuration and procedure work. For an emerging biotech or specialty CDMO running parts of quality on paper and spreadsheets, the gap is structural.

The most common failure mode is a CAPA that cannot be traced cleanly from the original deviation through risk assessment and root-cause analysis to verified closure. When that chain is stitched across a shared drive, an email thread, and a signed PDF, it is hard to defend even before AI enters the picture.

Introduce an AI assistant into that environment and the exposure compounds. If a tool helps draft a root cause or suggests a CAPA and there is no record of what it proposed, who reviewed it, and what they changed, you have made the traceability problem worse.

Key takeaway

Annex 22 readiness for these sites is two jobs at once — close the underlying evidence-trail gap, and make sure any AI you adopt strengthens that trail rather than puncturing it.

05The AI evidence trail

One governed chain, not a black box bolted on.

Quality work runs as a single governed chain. The AI assists at each step but never owns the decision — every step is captured as defensible evidence.

1

Deviation

The event is captured and classified — a qualified human sets the severity.

2

Root-cause analysis

MIRA cites evidence and proposes angles; a human decides the cause.

3

CAPA

Actions, owners, due dates and effectiveness checks — captured with e-signature.

4

Audit preparation

A sealed, tamper-evident evidence pack, exportable in one click.

A qualified human reviews and approves at every gate. Nothing is auto-closed, auto-signed, auto-released, or auto-disposed — and each hand-off between AI and human is recorded in the trail.

06Where Verixa fits

Governed AI for regulated quality workflows.

Verixa is an AI-native GxP quality system that runs the deviation → RCA → CAPA → audit-preparation chain inside defined human-review gates.

Advisory AI, human-in-the-loop by design

MIRA surfaces missing context, organises cited source material and drafts content as labelled suggestions. A qualified reviewer approves, edits, or rejects it. MIRA never approves, closes, signs, releases or disposes of a regulated record, and never sets a severity.

A tamper-evident, hash-chained audit trail

Each step — what the assistant saw, what it proposed, who reviewed it, what changed, and the final approval — is designed to be recorded so the sequence cannot be quietly altered.

Part 11-oriented e-signature controls

Approvals are captured with electronic-signature controls built toward 21 CFR Part 11 and EU GMP Annex 11 expectations.

Start with one scoped workflow

Begin with one scoped GMP workflow, prove it alongside a design partner, and expand across the QMS over time — not a rip-and-replace.

Standard disclosure. Verixa is validation-ready and in design-partner validation. Customer validation is required before production use. Compliance is a customer determination based on intended-use validation, not a vendor claim — your organisation owns intended-use validation. Verixa does not claim to be validated, compliant, audit-ready, inspection-ready, or GxP-ready. Annex 22 is referenced here as an emerging, draft expectation, not a compliance claim.

07What an India SME can do now — without over-building

A pragmatic sequence.

1

Map your deviation-to-CAPA chain honestly

Pick a recent deviation and reconstruct it end-to-end from your records alone. Wherever the trail breaks, you have found your real readiness gap.

2

Set a human-in-the-loop policy before any AI

Write down which GMP decisions a qualified person must always own, and require that any tool records what it proposed and what the human did with it.

3

Insist on traceability of the AI step

If a vendor cannot show exactly how an AI-assisted action is logged and protected from later alteration, treat that as a gap.

4

Prove it on one bounded workflow first

Run the governed evidence trail on a single workflow at a single facility, see whether the record is genuinely defensible, and expand from there.

5

Keep the customer's validation explicit

Whatever system you adopt, your organisation owns its validation before production use. A credible vendor will say so plainly.

08The honest bottom line

No one can sell you compliance with a draft.

What you can do is read where the regulatory landscape is heading — governed AI, a qualified human in the loop, a traceable record — and make sure your quality system already works that way.

For an India SME without a mature eQMS, the fastest, most defensible route is to close the deviation-to-CAPA evidence gap and adopt AI that strengthens that trail instead of obscuring it.

Get that right on one workflow, and the next annex — from whichever authority — becomes a refinement rather than a scramble.

Frequently asked questions

No. Annex 22 was published in draft form in 2025 for consultation and is not yet an enforceable part of the EU GMP guide. It signals the direction European authorities are taking on AI in GMP — an emerging expectation rather than a binding requirement. Confirm its status against the European medicines framework before relying on any specific clause.

Keep a qualified human in the loop and make every AI-assisted step traceable. Whenever an AI tool contributes to a GMP decision affecting product quality, patient safety, or data integrity, a qualified person must review and approve, and the record must show what the model proposed, who reviewed it, what changed, and what was finally approved.

They converge on the same idea. The FDA's Computer Software Assurance guidance favours risk-based critical thinking over volume documentation. ICH Q9(R1) and ICH Q10 expect risk-based, fully traceable decisions and CAPA. India's revised Schedule M raises the domestic baseline. Building for governed, human-in-the-loop, traceable AI moves you toward all of them at once.

Reconstruct a recent deviation end-to-end from your records alone. Wherever the deviation-to-CAPA chain breaks, you have found your real readiness gap. Then set a human-in-the-loop policy before adopting any AI, require that any tool logs and protects its contribution, and prove the approach on one bounded workflow before expanding.

No tool can make you compliant with a draft, and a credible vendor will not claim it. An AI-native system can help you work in line with the draft’s direction — governed AI, human-in-the-loop control, and a tamper-evident audit trail that captures the AI step — but your organisation still owns validation before production use. Verixa is validation-ready and in design-partner validation; it does not claim to be validated, compliant, or audit-ready.

Primary sources referenced

  • EU GMP Annex 22 — Artificial Intelligence (draft for consultation, 2025), European Commission / EMA GMP framework.
  • FDA — Computer Software Assurance for Production and Quality System Software (final 24 Sep 2025, superseded by the 3 Feb 2026 version), fda.gov.
  • ICH Q9(R1) — Quality Risk Management; ICH Q10 — Pharmaceutical Quality System.
  • ISPE — GAMP 5 (Second Edition) and related ISPE AI/ML guidance.
  • PDA technical reports on data integrity.
  • India — Revised Schedule M, Drugs and Cosmetics Rules, CDSCO.
VV

Vimal Veereshwarayya, PhD, RAC

Founder, Verixa (a product of Navira Quality Systems Pvt Ltd)

A pharma and biotech operator with 20+ years in the industry and 16+ years in Quality Assurance and Regulatory Affairs, Vimal has lived the deviation-to-CAPA evidence burden from inside regulated GMP environments. Verixa is the result of that experience: an AI-native quality system built governance-first, designed to be honest about what is built, tested, and validation-ready rather than over-claiming a regulatory state it has not reached.

Close the evidence gap on one workflow.

See how Verixa runs the deviation → RCA → CAPA → audit-preparation chain inside human-review gates — or start with a Navira gap assessment against your current deviation-to-CAPA trail.