Skip to main content
    SectorsHealth and life sciences

    A system in scope is not finished when it works. It is finished when it can be shown.

    The pressure here is not model risk in the financial sense. It is validated systems and the protection of patient and trial data. Reign operates the delivery estate and records who changed what, who approved it and when, in a form a validation process can consume. Reign Assurance prepares that evidence and does not perform validation.

    Two available today, one in beta Start a conversation Regulatory alignment →

    The categories of patient, trial and personal data in scope for an engagement are written into the agreement before work begins. We do not assume them, and we do not discover them halfway through.

    When the record is written at the change
    Assembled afterwards ticket system chat history email thread somebody’s memory weeks, and a reader still has to trust it Captured as it happens The change and what it was for who made it who reviewed it who approved it and when attributable to a named person, which is the whole of Part 11 We prepare the record. Your quality function validates. We do not perform validation, and we do not decide what is validated.
    A trail assembled after the fact carries less weight than one captured as the work happened. That is the whole of the difference, and it is a design decision taken before the first change.
    The pressure

    Validation rests on a trail somebody can read years later.

    Everything below follows from the difference between a record captured as the work happened and one assembled once there is something to report.

    01The record is the load-bearing part
    A trail reconstructed after the fact carries far less weight than one captured at the change.

    Attribution to a named person, at the moment of the action, is the whole of what 21 CFR Part 11 and Annex 11 are asking for. Reconstruction produces an answer, and it produces an answer nobody fully trusts.

    AskIs your approval trail captured at the moment of the change, or assembled afterwards?

    02Data categories decide everything
    Patient and trial data carry obligations that change the shape of an engagement.

    The categories in scope determine the controls, the location and the terms, which is why they belong in the agreement rather than in an assumption.

    AskHas anybody written down exactly which categories of data an engagement will touch?

    03AI-enabled work is getting its own annex
    Europe is not folding AI into the computerised-systems annex. It is writing a separate one.

    The July 2025 EudraLex package put a revised Annex 11 and a new Annex 22 on artificial intelligence out for comment together. Attributing AI requirements to Annex 11 is the most common error in circulation on this subject.

    AskIf a model contributed to a change in a system in scope, does your record say so?

    04The AI Act deadline moved, and it is a delay rather than a reprieve
    High-risk obligations covering AI embedded in regulated products, medical devices included, now apply from 2 August 2028.

    The AI Omnibus entered into force on 27 July 2026 and replaced a conditional trigger with fixed calendar dates. Anything planned against the original 2027 date has sixteen more months, and the obligations themselves are unchanged.

    AskWas your AI Act readiness plan built against the old dates?

    What the frameworks ask

    Four texts, and two of them are not final yet.

    We describe what these ask for because they shape the work. We make no statement about our standing under any of them, and where a text is still a draft this page says so rather than letting it read as an obligation.

    What is measuredWhose figure, and whenWhy it is on this page
    21 CFR Part 11 — electronic records and electronic signatures: control of changes, and the ability to attribute an action to a person.United States, FDA. In force since 1997, unchanged. Current interpretive guidance for clinical investigations finalised 2 October 2024.The attribution requirement is the one that decides how a delivery estate has to be operated, and it is the reason the record is captured rather than reconstructed.
    EudraLex Volume 4, Annex 11 — computerised systems. The revision expands it from five pages to nineteen and moves the centre of gravity from validation to security, identity and access management, and audit trail.European Union. The 2011 version is still in force. Revision released for comment 7 July 2025, consultation closed 7 October 2025, not adopted.A page that describes the revision as current would be wrong. We have not seen a confirmed adoption or effective date and we are not going to offer one.
    Draft Annex 22, Artificial Intelligence — intended use, acceptance criteria, test data, test execution, explainability, confidence and operations.European Union. Released for comment in the same 7 July 2025 package. Draft.This is where AI obligations for GMP computerised systems are being written, not Annex 11. It is the single most useful thing to get right on this page.
    EU AI Act and ISO/IEC 42001:2023 — obligations that scale with risk, and a management system standard organizations can be assessed against, with policy, roles, risk assessment and documented controls.Annex I high-risk, covering AI in regulated products including medical devices, now applies 2 August 2028; Annex III 2 December 2027. ISO/IEC 42001 published 18 December 2023.The AI Act dates moved in July 2026. ISO/IEC 42001 has not changed, and any global certification count you are shown does not trace back to ISO or an accreditation body.

    FDA’s Considerations for the Use of Artificial Intelligence To Support Regulatory Decision-Making for Drug and Biological Products (January 2025) remains a draft and is marked not for implementation; FDA and EMA published ten joint guiding principles on good AI practice in drug development in January 2026, which are also non-binding. Naming a framework is not a claim of standing under it.

    Where the record fits

    We prepare evidence. We do not validate.

    The distinction matters more here than anywhere else on this site, so we will state it without softening it. Reign Assurance arranges the evidence a validation process needs into a form a reviewer can work through, and stops there. It does not certify, does not attest, does not issue an audit opinion and does not provide independent assurance, in any tense.

    What the record carries
    For each change in a system in scope: what changed, who made it, who reviewed it, who approved it and when, attributable to a named person and written at the time rather than assembled later. Where a model took part in producing the change, that participation is part of the record rather than an omission from it.
    The part worth being precise about. Your quality function owns the validation. Your data protection function owns the data determination. We supply the record they work from, and we do not decide whether a system is validated. iTmethods makes no compliance, certification or accreditation claim under any framework. How the boundary works → · Regulatory alignment →
    Shared responsibility

    Who holds what, before the first change in a system in scope.

    Agreed and recorded in the agreement, including the data categories, before work begins.

    WhoWhat they hold
    iTmethodsOperate the delivery estate as a single-tenant dedicated instance. Record who changed what, who approved it and when, attributable to a named person. Provide a named engineer for the agreed population who appears in the record.
    Your quality functionValidation, and the determination of whether a system is validated. Which systems are in scope. The acceptance criteria. Every approval. We supply the evidence; the decision is not ours and we will not describe it as shared.
    Your data protection functionThe lawful basis, the categories of patient, trial and personal data in scope, and the determination of whether an engagement meets your obligations. Those categories go into the agreement before work starts.
    Before the scoping call

    The questions that arrive every time.

    Do you validate systems?
    No, and this is the one answer on the page we will not soften. Reign Assurance prepares evidence for a validation process. It does not perform validation and it does not decide whether a system is validated. It does not certify, does not attest, does not issue an audit opinion and does not provide independent assurance, in any tense. Reign prepares; people decide.
    Does the revised Annex 11 cover AI?
    No, and this is worth getting right because it is commonly stated the other way round. The European Commission released a revised Annex 11 and a separate new Annex 22 on artificial intelligence in the same package on 7 July 2025. AI obligations are being written into Annex 22. Both are still drafts; the 2011 Annex 11 remains the text in force.
    Where would patient or trial data sit?
    Wherever your agreement says, and the categories go into the agreement before work begins. Deployment is a single-tenant dedicated instance, and that includes deployment into your own AWS or Azure account, which is available today. If your requirement is air-gapped or sovereign, the accurate answer is that both are in development, and we will give you that answer rather than a date.
    What can you actually evidence today?
    The only figures we publish about this way of working are our own. Across eight of our own repositories, 326 merge requests were merged. Median time from merge request open to merge was 19 hours. 326 of 326 merged with a recorded approval from a named iTmethods engineer. Measured on our own engineering, 11 July to 11 August 2026, GitLab, release commits excluded, internal environment only, two-person team. The method is written up in full at what we measured. It is not a customer result, and we do not present it as one.
    Which deployment shapes can we have?
    A single-tenant dedicated instance, in your own AWS or Azure account or in infrastructure iTmethods operates. Both are available today, which includes deployment into your own cloud account; Google Cloud is planned for 2027. Air-gapped and sovereign are in development. There is no multi-tenant or shared option at any tier. Deployment options states which is which without softening any of them.
    AWS Advanced Tier Services Partner SOC 2 Type II on Reign Ops
    AWS Advanced Tier Services Partner and Validated Managed Service Provider. Twenty-one years operating regulated engineering environments.
    Next step

    Start with the data and the scope.

    Tell us which systems are in scope and which categories of data are involved, and we will show you what the record looks like at the end of a real population of work.