A New Frontier of Regulatory Operations

The simultaneous adoption of eCTD v4.0 and GxP-compliant AI tools offers the biopharma industry potentially tremendous efficiency gains; however, success will ultimately depend upon organizational agility.

Global regulatory bodies are steadily advancing their digital infrastructures, moving the industry away from legacy, document-heavy workflows toward granular, data-driven frameworks. The simultaneous roll-out of the electronic common technical document (eCTD v4,0) and the integration of artificial intelligence (AI) across GxP environments present opportunities for operational acceleration; however, they also introduce potential friction points.

To delve into the details of high-level agency expectations and find out about how bio/pharma companies can meet these in day-to-day operations, The Pharma Navigator convened a panel of experts. The panel comprised Frits Stulp, Partner, Life Sciences, Implement Consulting Group; Renato Rjavec, Vice President of Product Management, Regulatory, ArisGlobal; Sachin Singh Gangwar, Head Global Quality Management System, Enzene; Bharti Bilolikar, AVP of Regulatory Affairs and IP, Enzene.

Translating Regulatory Expectations

TPN: How are companies translating the expectations of regulatory bodies around AI practice in drug development into practical day-to-day quality systems?

Stulp (Implement Consulting Group): The challenge will be to incorporate different AI frameworks into your global way of working as a marketing authorization holder. This requires a strong repository of product data and documents, so that your AI tools can draw on consistent, approved information. Often, ambitions will not extend beyond individual process tasks, such as analysis, UI [user interface] optimization, retrieval, or text creation. But the real power will come from combining these capabilities, alongside effective training of both the AI agents and the people using them.

Rjavec (ArisGlobal): Turning high-level AI regulation into practical daily controls means extending the traditional QMS into a more active governance model. Leading organizations are embedding AI risk classification into existing procedures, so requirements such as data provenance, explainability, bias monitoring, and performance oversight are managed with the same discipline as established quality controls. This is also driving more cross-functional governance, bringing together regulatory affairs, quality, clinical, safety, and data science teams. When supported by integrated ecosystems, such as ArisGlobal’s LifeSphere, these teams can connect policy, data, and operational workflows more effectively. The result is a quality system in which algorithmic transparency and continuous monitoring become part of routine operations, rather than a separate technology exercise.

Data lineage and quality will be the basis for the AI components of any quality system to be successful and will require data governance to be part of the quality system moving forward.

Gangwar (Enzene): The joint FDA-EMA guiding principles published earlier this year are a useful signal of direction, but their real value only emerges once companies translate 10 high-level statements into something a quality team can actually audit against. In practice, that translation is happening in a few concrete ways.

First, AI is being formally brought inside the quality management system (QMS) rather than treated as an IT or data-science initiative running alongside it. That means AI-generated outputs — whether from a predictive process-control model or an ML [machine learning]-based signal-detection tool — are now classified, documented, and validated the same way any other regulated evidence would be, with defined ownership, version control, and change-management triggers.

Second, validation is shifting from a one-time event to continuous monitoring. Because model performance can degrade as underlying data shifts, quality systems are building in scheduled re-verification and drift-detection checkpoints, not just an initial validation report that gets filed and forgotten.

Third, explainability requirements are being written into vendor qualification and technology transfer procedures. If a tool's logic can't be reasonably explained to an inspector, it doesn't get deployed in a GxP-relevant workflow, so procurement and QA are collaborating much earlier in tool selection than before.

Finally, cross-functional governance is becoming standard: a lightweight AI governance committee spanning quality, regulatory, data science, and IT, tasked with keeping SOPs [standard operating procedures] aligned as agency expectations evolve. This matters because the FDA-EMA principles are explicitly non-binding today, the practical work is anticipating where they'll harden into enforceable guidance and building quality systems flexible enough to absorb that without a rewrite.

The companies ahead of the curve aren't the ones with the most sophisticated AI, they're the ones whose quality systems can already answer, ‘show me how this was validated and how you know it's still working’ for any AI tool in use.

Technical and Operational Hurdles

TPN: What are the most significant technical and operational pain points regulatory operations teams are encountering during the transition over to eCTD v4.0?

Bilolikar (Enzene): There are a few challenges ahead of companies transitioning to eCTD v4.0: First of all, there is a skills gap to overcome as personnel need to layer a new discipline on an existing job, which requires a shift from XML/DTD/STF fluency to FHIR/RPS and metadata lifecycle thinking, and will cause bottlenecks in expertise.

Compounding the skills shortage is the burden of managing a dual-track workload as companies will be required to run v3.2.2 and v4.0 in parallel for years with no clarity on how long. In practice, this dual-track workload means two SOPs, two validation checklists, and constant context switching. Immature tooling is another potential hurdle for companies as piloting the new eCTD v4.0 on publishing software that doesn’t fully support regulated product submissions (RPS) yet could lead to validation bugs and gaps.

Additionally, there is a risk of off-system communication as FDA’s v4.0 two-way query channel hasn’t yet (at the time of writing) been fully built, meaning that some clarifications still happen via email. On the governance side, companies now need to manually verify manufacturing sites and substance terms against EMA’s Referentials Management Service (RMS)/Organization Management Service (OMS) before submitting dossiers. In this case, a mismatch of verification can bounce the whole filing.

Furthermore, regulatory operations teams need to overcome the portfolio tracking burden — manually monitoring which format governs which application/submission event, which can lead to rejection if the wrong format is used. Finally, shifting authority mandate dates and a lack of clarity on when actual executive needs to happen, add to the challenges.

Rjavec (ArisGlobal): The move to eCTD v4.0 is not simply a version upgrade; it marks a shift from document-centered submissions to a more granular, data-driven model based on HL7 FHIR. For regulatory operations teams, one of the main challenges is mapping and migrating existing content, especially where legacy XML structures need to be aligned with submission units and context of use. Organizations often encounter difficulty when older ecosystems cannot manage these relationships without significant manual effort. Addressing this effectively requires a publishing and regulatory information environment that can support structured data objects natively, allowing teams to focus on submission strategy rather than data remediation.

eCTD v4.0 requires prior eCTD versions to be of top-quality for a smooth transition.

Stulp (Implement Consulting Group): As always, differences in the timing of adoption create the cost and complexity of running two approaches in parallel. This may also come at the expense of the established skills and processes associated with eCTD v3 creation. All of this requires more intensive planning and quality management within a process that had already been optimized to production grade. And this is happening while the benefits of eCTD v4.0 are still difficult to realize.

My answer probably illustrates the dilemma: although v4.0 should enable greater exchange of data, which I strongly support, I currently feel that the benefits are relatively limited compared with the effort required. However, as adoption is mandatory, we should focus on optimizing the process as much as possible.

Evolving Validation Frameworks

TPN: How are regulatory and quality teams adapting validation frameworks to handle non-deterministic, continuously learning AI algorithms without creating insurmountable compliance overhead?

Rjavec (ArisGlobal): For adaptive AI systems, validation needs to move beyond the idea of confirming a single static end state. Regulatory and quality teams are increasingly adopting risk-based Computer Software Assurance (CSA) principles, combined with Machine Learning Operations (MLOps) practices, to validate the process by which the model is developed, monitored, and maintained. This includes defining clear performance thresholds, documenting intended use, monitoring for model drift, and setting escalation triggers when outputs move outside agreed boundaries. The aim is to enable innovation without creating unnecessary compliance burden, while ensuring that evolving AI tools remain controlled, transparent, and aligned with patient safety expectations.

Dependent on the type of AI technology used, a full check of reasoning and processing may become less relevant. Validation will focus more on result than on process.

Gangwar (Enzene): Traditional CSV [computer system validation] assumed you could freeze a system's behavior at a point in time, test it exhaustively against that frozen state, and sign off. That premise simply doesn't hold for a model that's meant to keep learning. The industry isn't trying to force AI into the old IQ/OQ/PQ [installation qualification/operational qualification/performance qualification] mold, it’s building a parallel set of controls designed for systems that change. Three shifts are doing most of the work.

The first is the move from CSV to CSA, now finalized by the FDA. CSA replaces exhaustive scripted testing with proportional, risk-based assurance, the rigor applied scales with the system's impact on patient safety and data integrity, not with a fixed checklist. That risk-based mindset turns out to be essential groundwork for AI, because it already asks, ‘how much assurance does this specific use actually need?’ rather than ‘did we document every possible test case?’

The second is the predetermined change control plan, or PCCP, a pre-approved envelope defining exactly how a model is allowed to evolve (what data it can retrain on, what performance bounds it must stay within, what triggers a re-review). This plan is agreed with regulators upfront, so routine learning doesn't force a full revalidation every time the model updates. In effect, we're validating the boundaries of change rather than a single static snapshot.

The third is continuous performance monitoring, replacing one-time qualification. Models are now monitored in production for drift, degradation as real-world data diverges from training data, with defined thresholds that trigger investigation or retraining, much like a control chart in traditional process monitoring.

It's worth noting that regulators are also drawing firm lines to keep this manageable rather than open-ended. Emerging EU guidance on AI in manufacturing, for instance, restricts truly adaptive, self-updating models from critical GMP decisions altogether, permitting only static, locked models in those contexts. That's a pragmatic compliance safety valve, it lets teams use continuous learning where the risk profile supports it, while keeping the highest-stakes decisions on a validated, deterministic footing.

The net effect is that validation is becoming less of a one-time event and more of a lifecycle discipline, proportionate at the outset, bounded by pre-agreed change parameters, and continuously monitored thereafter. Done well, that's less overhead than trying to re-run full CSV every time a model is retrained.

Safeguarding Data Integrity

TPN: How can regulatory departments ensure that rapid digital transformation and continuous submission models do not inadvertently compromise data integrity, scientific rigor, or patient safety standards?

Rjavec (ArisGlobal): Faster submission timelines are valuable only if they are supported by reliable, well-governed data. Regulatory teams are managing this balance by maintaining human oversight at critical decision points and using automation to support, not replace, expert judgement. Standards such as IDMP also play an important role by creating a consistent data foundation across the product lifecycle. When companies establish a single source of truth and execute data migrations carefully, they can accelerate regulatory processes while protecting data integrity, scientific rigor and patient safety.

Essentially AI and ML are just speeding up the existing process, they do not provide a fundamentally different approach to data processing. Data integrity and scientific rigor remain just as relevant when using AI albeit at a much higher execution speed that will bring huge benefits to patients.

Stulp (Implement Consulting Group): In short, use AI to accelerate content creation while keeping human review firmly in the driving seat, potentially supported by smaller, specialized agents. The time saved in content creation will determine the overall efficiency gain, while continued human review will help ensure quality.

Bilolikar (Enzene): Regulatory departments can safely embrace AI and accelerated submission models by combining automation with strong governance, validated technologies, continuous quality controls, transparent audit trails, and expert scientific oversight.

AI should support decision-making, not replace regulatory accountability. Human accountability should be emphasized for critical decisions, which should include document authoring, data extraction and summarization, literature surveillance, publishing, submission assembly, and regulatory intelligence.

To ensure that rapid submission cycles do not compromise traceability or inspection readiness, strong governance should be in place, such as audit trails, role-based access controls, data lineage tracking, version management, and automated validation checkpoints.

Regulators will increasingly expect organizations to demonstrate that AI-generated outputs are reproducible, reliable, and fit for purpose. To achieve this, the key requirements that need to be in place include intended use documentation, performance qualification, bias and error assessments, periodic revalidation, change control procedures, and explainability requirements

Continuous submission models can create pressure to prioritize speed over quality. To avoid this, quality and compliance should be embedded into the continuous submission workflow. The shift is required from periodic quality checks to continuous quality monitoring.

As submission content originates from multiple digital sources such as clinical, PV, CMC, and medical writing, governance boards should be established, including stakeholders from QA [Quality Assurance], RA [Regulatory Affairs], Clinical, IT, data sciences, R&D, and Manufacturing.

AI-generated summaries should always be linked to source data and evidence. While processes can be automated, scientific judgement should not; scientific rigor should be protected through structured review of content.

Organizations should maintain complete auditability/traceability for all AI-assisted regulatory documents and should be ready to answer the questions they may face from regulatory agencies, including questions about AI models, signing authority, and any change made after AI generated documents, etc,.

Safety evaluation timelines can be compressed due to accelerated development pathways. To mitigate the risk associated with this, monitor real-time PV [pharmacovigilance] data, integrate the signal detection platform, and establish rapid escalation procedures. As the product reaches patients faster, robust ongoing safety surveillance becomes even more important.

Digital submissions increasingly rely on cloud platforms, data exchanges, and AI services, so cybersecurity and data protection become increasingly important.

Adopt a Risk-Based Regulatory Framework, as not all submissions have the same risk. The most successful future-state organizations will not be those that automate the most processes, but those that balance speed with trust, innovation with compliance, and efficiency with an unwavering commitment to patient safety and scientific integrity.

Mitigating the Risk of Fragmentation

TPN: As regional regulatory authorities adopt digital initiatives and AI frameworks at varying speeds and with differing technical requirements, how can multinational biopharma companies mitigate the risk of regulatory fragmentation?

Stulp (Implement Consulting Group): In general, I believe regulatory fragmentation is impossible to avoid, and arguably it has never been realistic to expect complete alignment across regulatory developments. The challenge, therefore, is to maintain a strong, reliable source of truth: a process that produces high-quality, interoperable core datasets and documents that can then be adapted to regional requirements.

It would also seem sensible to make many AI-enabled steps modular, so that intermediate outputs, such as dossiers and datasets, can be reviewed at appropriate stages. Keeping regional and national requirements within dedicated agents, supported by appropriate human review, may provide greater transparency and, ultimately, better quality.

Rjavec (ArisGlobal): The most effective way to manage regional differences in AI and digital regulation is to build an agile, data-first regulatory foundation. A globally harmonized data model, informed by standards such as IDMP, allows organizations to separate core data management from local submission requirements. Integrated regulatory ecosystems can then support regional formatting, mapping and reporting without fragmenting the underlying data strategy. This approach helps multinational companies respond to local requirements more efficiently, while maintaining global consistency and reducing the need for reactive workarounds.

Fragmentation exists today and will continue to exist. In fact, it would seriously hamper progress if new developments would have to be rolled out globally from the start. Pharma companies are capable of handling this complexity today. Clearly, standardization will be of great benefit to reduce fragmentation

About the Contributors

Frits Stulp is Partner, Life Sciences at Implement Consulting Group, with more than 25 years’ experience across the pharmaceutical industry and consultancy. His work focuses on helping life sciences organizations improve the way they use data, technology and operating models across R&D, with particular expertise in regulatory affairs, data strategy and information standards. He previously co-founded Iperion, which was acquired by Deloitte, and has held senior life sciences leadership roles at Deloitte and within the pharmaceutical industry.

Renato Rjavec is Vice President of Product Management, Regulatory at ArisGlobal, with a keen focus on AI as a means for targeted automation of critical but labor-intensive processes where accuracy and precision are paramount. Renato has almost two decades of experience in ideation, development and implementation of regulatory and quality solutions for the life sciences industry.

Sachin Singh Gangwar is Head Global Quality Management System at Enzene, where he oversees quality governance, digital QMS integration, and compliance frameworks across global biomanufacturing operations.

Bharti Bilolikar is the AVP of Regulatory Affairs and IP at Enzene, leading regulatory strategy, global dossier submissions, and IP management for advanced biopharmaceutical products.

Image Credit: © Chor muang - stock.adobe.com

Next
Next

Moonwalk Biosciences Closes Oversubscribed Series B Financing Round