The Next GxP Problem Isn't Validation. It's Evidence.

Why the next generation of Digital GxP™ may depend on understanding the evidence our regulated operations already produce

For years, the life sciences industry has invested enormous effort in validating computerized systems, and rightly so. We need confidence that systems supporting regulated activities are fit for their intended use, appropriately controlled, and capable of reliably supporting the processes they were designed to enable. The evolution from traditional Computer System Validation (CSV) toward risk-based Computer Software Assurance (CSA) has helped organizations approach that responsibility with greater emphasis on intended use, risk, and critical thinking.

But as regulated environments become more digital and interconnected, another question is becoming increasingly important: What evidence demonstrates that the complete regulated business process continues to operate as intended?

Beyond System Assurance

Consider an ordinary GxP process. An approved procedure may describe how it should operate, an eQMS or other computerized system may be configured to support it, employees may have completed their required training, and the technology may have been appropriately validated or assured. Each of those controls matters, but together they still represent only part of the picture.

The organization continues to change after implementation. Processes evolve, configurations change, new releases are deployed, responsibilities shift, integrations are introduced, vendors change, and workarounds develop. Over time, the process operating today may begin to look different from the one originally designed and assured.

The Four States of a Regulated Process

Throughout my career in Quality and regulated technology, I've seen different versions of the same business process emerge within an organization. I think about these as The Four States of a Regulated Process:

Documented: What the approved procedure or business process says should happen.
Configured: What the supporting technology is configured to make happen.
Actual: What people and systems are really doing every day.
Effective: Whether the process is consistently achieving its intended outcome.

Ideally, these four states remain closely aligned. But as organizations evolve, gaps can develop between them. A procedure changes while the workflow does not, responsibilities move without corresponding system changes, or employees create workarounds to keep the business moving. This gradual separation is what I describe as Operational Drift.

The Evidence Already Exists

What's interesting is that regulated organizations already generate tremendous amounts of evidence about how their operations are performing. Audit trails, deviations, CAPAs, training records, approvals, change controls, configuration changes, system activity, metrics, and business-process data are being created every day.

The problem is not necessarily a lack of evidence. The challenge is connecting the evidence we already have and understanding what it tells us about the operation as a whole.

Today, much of this information is reconstructed when there is a reason to examine it, such as an audit, inspection, investigation, periodic review, validation activity, or significant change. Yet regulated operations themselves generate evidence continuously.

That raises an important question: If regulated operations generate evidence continuously, could our approach to assurance become more continuous as well?

Why AI Makes This More Important

Artificial Intelligence adds another dimension. As AI begins participating more directly in regulated workflows, intended use, risk management, data integrity, governance, accountability, and human oversight become even more important.

Simply putting a "Human in the Loop" does not solve the problem. A qualified person needs appropriate evidence and context to make an informed and defensible GxP decision. They need to understand what the technology is doing, recognize uncertainty or exceptions, and have the authority to challenge or reject its output.

If AI influences a deviation, CAPA, change control, validation activity, or another regulated process, the question should not simply be whether a human approved it. Did the qualified person have sufficient evidence and context to make that approval meaningful?

From System Assurance to Operational Integrity™

CSA remains essential because organizations need confidence in the computerized systems supporting regulated activities. But system assurance alone cannot tell us whether people, processes, technology, data, evidence, governance, and human judgment continue working together effectively as the organization evolves.

That's the broader challenge I describe as Operational Integrity™. The objective isn't more documentation, and it isn't replacing Quality professionals or subject-matter experts with technology. It's giving qualified people better visibility, better evidence, and better context with which to make regulated decisions.

This changes how we think about the evidence our organizations already produce. A training record tells us something. An audit trail tells us something else. CAPAs, system activity, process metrics, configuration changes, and deviations each provide another piece of the picture. The opportunity is understanding what those pieces tell us when considered together.

Where Digital GxP™ Goes Next

I believe the next evolution of Digital GxP™ will extend beyond assuring individual technologies. Organizations will increasingly need ways to understand whether the complete regulated operating environment remains aligned as people, processes, systems, data, and eventually AI continue to change.

This thinking is also shaping what I have begun to describe as Agentic GxP™, the intersection of intelligent technology with the processes, systems, evidence, governance, and human judgment required to operate successfully in a regulated environment. There is considerably more behind this work than we are ready to publish publicly, but it is an area we are continuing to develop at Mindful FDA.

The opportunity ahead may not be to generate more GxP evidence. Regulated organizations already generate enormous amounts of it every day. The opportunity is to become much better at connecting that evidence, understanding what it tells us, and putting it in the hands of qualified people before a problem forces us to look for it.

That may be one of the most important steps from system assurance toward Operational Integrity™.

© 2026 Mindful FDA Compliance, LLC
Operational Integrity™ | Digital GxP™ | Agentic GxP™

Next
Next

The Digital GxP™ Organization