Comment from NagaPranitha Chodavarapu

AnonymousSupportIndividual
Summary: A senior IT validation professional supports the proposed CSA guidance as a beneficial evolution but argues that it contains specific gaps regarding AI tools, decision-support analytics, and portfolio-level validated states. The commenter recommends adding specific examples to Appendix A to address these complexities, including human-in-the-loop controls for AI and cumulative change risk across integrated systems.
I am a senior IT validation professional with 13+ years of GxP computerized system validation/assurance experience in FDA-regulated medical device and pharmaceutical industries ensuring quality and compliance to FDA’s QMSR, 21 CFR Part 820, ISO 13485:2016, 21 CFR Part 11, and EU GMP Annex 11. I submit three practitioner comments on the February 2026 CSA guidance: (1) Enterprise AI Tools in QMS Activities: No Appendix A Example exists The February 2026 guidance brings artificial intelligence (AI) and machine learning (ML) tools within CSA scope (Section V.A). Currently, medical device manufacturers are implementing commercial enterprise AI systems including LLM-based tools that could potentially be used to perform CSA activities such as compliance/GxP applicability assessments, draft user requirement-level risk assessments, generate validation documents. Though the organizations’ quality system governance explicitly prohibits AI usage to replace formal quality review and approval process, the February 2026 FDA CSA guidance does not provide examples to clearly identify and scope the usage of AI tools in QMS/CSA activities. All four Appendix A examples address traditional computerized systems, none mention the usage of AI in their validation lifecycle. These specific gaps make AI tool usage under the current guidance ambiguous for practitioners. Firstly, the intended-use determination in Section V.A.1 does not address AI tools that generate draft QMS documents reviewed and approved by qualified personnel before any quality record is created. It is unclear whether these tools are used 'directly' as part of the QMS, used 'to support' the QMS, or fall outside scope as general productivity software. Secondly, the assurance activities in Table 1 that talks about scripted, scenario, error guessing, and exploratory testing were designed for software that has predictable behavior. AI tool outputs evolve over time; the same input can produce different outputs based on user actions, making traditional test strategy difficult to apply. Recommendation: Provide an example in Appendix A that addresses (1) intended use determination when AI outputs are subject to mandatory human review before quality record generation (2) Appropriate assurance activities for AI outputs including whether human review constitutes a sufficient control. (2) Decision-Support Analytics Platforms: Appendix A Example 3 Is Incomplete Example 3 of Appendix A provides clear guidance for business intelligence platforms used for monitoring and improvement scenarios. However, these platforms across medical device industries are widely used for reporting functions. The intended use of these reporting functions span across various risk-levels of quality or clinical decision-making dashboards. For example, an employee headcount dashboard would not have any impact on the patient safety or product quality while a dashboard that provides insights on patient outcomes data to healthcare providers to inform therapy adjustments for patients using a manufacturer’s device. In these types of implementations, it is not just the connectivity or monitoring trends, but they constitute inputs to clinical or quality decisions. Recommendation: Supplement Example 3 with an additional scenario to include reports or dashboards on business intelligence applications as they support high process risk in reporting and visualization functions. This is indeed crucial as these applications are mainly implemented to create dashboards on a large scale. (3) Portfolio-Level validated State: A Gap the Current Framework Does Not Address The CSA framework’s risk classification model operates at the individual software feature-level within a single system. However, modern medical device QMS environments operate as integrated GxP system portfolios. For example, ERP system integrate with eQMS, MES applications, which feed analytics dashboards that create inputs for quality decisions elsewhere in another business function. This complexity is not addressed in the current guidance and how the CSA strategy and its governance framework should be designed across these integrated portfolios especially a massive amount of quality data flows across. The guidance does not provide framework for assessing cumulative change risk across an integrated portfolio and for assessing the intended use and process risk of integration-layer functions between validated systems. Recommendation: Provide an example in Appendix A to show this complexity and governance controls that are practical in the current system landscapes. Additionally, it would add more clarity if governance models for portfolio-level validated state of integrated systems is addressed in detail along with data integrity aspect. See attached

View on Regulations.gov