The 5 Documents an AI Inspection Will Ask For — and the 7-Question Self-Test That Tells You If You Have Them
Regulatory inspectors are already asking questions about AI. FDA and EU AI Act enforcement do not operate on your implementation timeline, and the organizations that will navigate an AI inspection with confidence are not those with the most advanced capabilities — they are those with the most complete governance documentation.
The exposure is widespread. By USDM’s own assessment data, 73% of enterprise AI implementations in 2024–2025 were deployed without a formal validation framework or documented governance architecture (USDM AI Governance Readiness Assessment Data, 2025 — drawn from client assessments and industry engagements; directional, not a probability sample). And the regulatory ground is shifting underneath those deployments: three forces — the FDA’s AI/ML Action Plan, the EU AI Act, and ICH E6(R3) plus emerging GAMP AI good-practice guidance — are converging on life sciences AI simultaneously, and their combined effect will reshape what “compliant AI” means within two years.
The inspection does not wait for readiness. Organizations that build AI governance architecture before that moment answer regulators from a position of strength; those that don’t will remediate on an inspector’s timeline.
This post extracts the inspection playbook from USDM’s CxO Guide to Sustainable AI: the five documents an inspection will ask for, a seven-question self-test to see whether you have them, and why the controls are proportionate.
The five documentation requirements
An inspection team evaluating AI governance looks for evidence in five specific areas. The absence of documentation in any one of them is a finding.
| ID | Requirement | What an inspector expects to see |
|---|---|---|
| D-01 | Audit Trail | Complete, tamper-evident records of AI system inputs, outputs, model versions, and human review decisions. |
| D-02 | HITL Evidence | Documented human review at each control point: named reviewer, review rationale, approval decision, and timestamp. |
| D-03 | Model Version Control | Records of which model version was validated for each use case, and the change-control decisions made for each vendor model update. |
| D-04 | Drift Monitoring Records | Periodic performance-review records showing the system operates within validated parameters, including breach-response documentation. |
| D-05 | Intended Use Statement | A formal, approved document defining each AI system’s specific intended use, validated scope, and explicit exclusions. |
None of these is exotic. Each is the AI-specific expression of a discipline your quality unit already practices for computerized systems — which is exactly why their absence reads, to an inspector, as a gap you chose not to close.
The 7-question self-test
Use this self-assessment to see where you stand. Each item is an evidence gap a regulatory inspection would identify — score yourself honestly, item by item.
- For each AI system in GxP-adjacent use, do we have a current, approved Intended Use Statement that defines scope and exclusions?
- Do our AI systems produce complete, queryable audit trails that capture model version, input, output, and human review decisions?
- Are human-in-the-loop control points defined, documented in validation plans, and is evidence of human review captured in the audit trail?
- Do we have a documented process for evaluating vendor model updates and making risk-informed change-control decisions?
- Is drift monitoring active for all validated AI systems, with defined performance thresholds, monitoring frequency, and response procedures?
- Do we have a formal AI incident reporting SOP that integrates with our existing CAPA process?
- Would our AI governance documentation survive a regulatory inquiry today — without a remediation sprint?
If the last question gives you pause, that is the finding. The AI Governance Readiness Assessment turns this self-test into a current-state gap analysis, a maturity scorecard, and peer benchmarks — a structured answer to “where do we actually stand?”
Why this is proportionate, not paralysis
None of this means a human in every loop or full validation on every use case. The controls scale to risk. USDM’s AI Risk Zone Model classifies every AI system — Green, Yellow, or Red — by its proximity to GxP processes, its degree of autonomous action, and the consequence of an error. Risk-zone classification is the first governance decision made for any deployment, and it is what keeps governance from becoming a bottleneck.
- Green (low). AI assists and a human reviews all outputs — document drafting, meeting summaries, literature review. Controls: an intended-use statement, an acceptable-use policy, and periodic review.
- Yellow (medium). AI informs GxP-adjacent decisions with human approval before consequential action — submission drafting with review, quality-event triage. Controls: a CSV/CSA validation plan, HITL control points, and change-control integration.
- Red (high). AI outputs directly affect GxP records with continuous human oversight mandatory — batch release review, AI-driven CAPA, clinical decision support. Controls: a full validation protocol, mandatory HITL at every step, an AI Risk Register, and an incident SOP.
This extends what Quality already runs rather than replacing it: USDM’s framework augments the existing CSV/CSA approach with five specific additions — an AI Risk Intake Addendum, AI-specific protocol testing, a Change Control Addendum with revalidation triggers, an Ongoing Compliance Controls Pack for drift and incidents, and an AI Lifecycle Integration Map.
One principle sits above the whole model: human accountability cannot be delegated to an AI system. The person who reviews and approves an AI-assisted output in a GxP context bears the same accountability as if they had produced it independently. The HITL control point is not a rubber stamp — it is a meaningful review with documented rationale.
The stakes are rising: agentic AI
The AI most organizations govern today is assistive. The AI arriving over the next 18 to 36 months is different in kind: agents act autonomously, in sequence, across systems — and the standard HITL model, which assumes a human gate at each step, breaks down. The governance response is not to ban agentic AI in regulated environments; it is to design governance for the agentic context.
That means classifying agentic patterns. Some are approvable today (automated report generation, read-only queries with HITL action gates, data extraction with human verification). Some are conditional on a formal validation plan (document drafting with a defined approval gate, cross-system retrieval with access logging, low-risk triggers with rollback). And some are prohibited for autonomous use: direct writes to validated systems, patient or batch-record modification, regulatory submission without a human author of record, and any action affecting product release or patient safety.
Agents also introduce a new category of non-human identity that existing PAM and IAM frameworks were never designed for. Sustainable agentic governance extends identity governance to agents explicitly: scoped service accounts with least-privilege access, session logging, regular access reviews, and integration into the broader IRM monitoring program.
From self-test to gap analysis
Every AI program lacking governance architecture today reflects a decision — conscious or not — to move fast and address compliance later. In regulated life sciences, “later” arrives faster than anticipated, and the cost of retroactive governance is an order of magnitude higher than building it in from day one: rearchitecting governed AI at scale, under time pressure, with an inspection clock ticking. Governance built once amortizes across every subsequent use case — which is why governed delivery gets faster as the program matures, not slower. Governance-first is not a brake on innovation; it is the architecture that makes innovation sustainable.
The organizations that are inspection-ready in 2027 are deciding now. Run the self-test above, then close the gaps it exposes.
Start with the AI Governance Readiness Assessment — a short, low-commitment evaluation that delivers a current-state gap analysis, a maturity scorecard, and peer benchmarks, and pinpoints where to begin. Take the AI Governance Readiness Assessment → From there, for most life sciences organizations, the path to inspection-ready governance is a defined 90-day AI Launchpad, scoped to your maturity and urgency by the assessment itself.
For the full framework — the validation tiers, the five-layer TCO model, and the agentic governance patterns in depth — see the anchor white paper, the CxO Guide to Sustainable AI.
Sources: Adapted from USDM’s CxO Guide to Sustainable AI. The 73% figure is USDM AI Governance Readiness Assessment Data, 2025 — drawn from client assessments and industry engagements; directional, not a probability sample. Platform-agnostic throughout: the documentation requirements, Risk Zone Model, and readiness checklist apply to any AI platform or model vendor. USDM is the independent governance layer.
