A system in scope is not finished when it works. It is finished when it can be shown.
The pressure here is not model risk in the financial sense. It is validated systems and the protection of patient and trial data. Reign operates the delivery estate and records who changed what, who approved it and when, in a form a validation process can consume. Reign Assurance prepares that evidence and does not perform validation.
The categories of patient, trial and personal data in scope for an engagement are written into the agreement before work begins. We do not assume them, and we do not discover them halfway through.
Validation rests on a trail somebody can read years later.
Everything below follows from the difference between a record captured as the work happened and one assembled once there is something to report.
Attribution to a named person, at the moment of the action, is the whole of what 21 CFR Part 11 and Annex 11 are asking for. Reconstruction produces an answer, and it produces an answer nobody fully trusts.
AskIs your approval trail captured at the moment of the change, or assembled afterwards?
The categories in scope determine the controls, the location and the terms, which is why they belong in the agreement rather than in an assumption.
AskHas anybody written down exactly which categories of data an engagement will touch?
The July 2025 EudraLex package put a revised Annex 11 and a new Annex 22 on artificial intelligence out for comment together. Attributing AI requirements to Annex 11 is the most common error in circulation on this subject.
AskIf a model contributed to a change in a system in scope, does your record say so?
The AI Omnibus entered into force on 27 July 2026 and replaced a conditional trigger with fixed calendar dates. Anything planned against the original 2027 date has sixteen more months, and the obligations themselves are unchanged.
AskWas your AI Act readiness plan built against the old dates?
Four texts, and two of them are not final yet.
We describe what these ask for because they shape the work. We make no statement about our standing under any of them, and where a text is still a draft this page says so rather than letting it read as an obligation.
| What is measured | Whose figure, and when | Why it is on this page |
|---|---|---|
| 21 CFR Part 11 — electronic records and electronic signatures: control of changes, and the ability to attribute an action to a person. | United States, FDA. In force since 1997, unchanged. Current interpretive guidance for clinical investigations finalised 2 October 2024. | The attribution requirement is the one that decides how a delivery estate has to be operated, and it is the reason the record is captured rather than reconstructed. |
| EudraLex Volume 4, Annex 11 — computerised systems. The revision expands it from five pages to nineteen and moves the centre of gravity from validation to security, identity and access management, and audit trail. | European Union. The 2011 version is still in force. Revision released for comment 7 July 2025, consultation closed 7 October 2025, not adopted. | A page that describes the revision as current would be wrong. We have not seen a confirmed adoption or effective date and we are not going to offer one. |
| Draft Annex 22, Artificial Intelligence — intended use, acceptance criteria, test data, test execution, explainability, confidence and operations. | European Union. Released for comment in the same 7 July 2025 package. Draft. | This is where AI obligations for GMP computerised systems are being written, not Annex 11. It is the single most useful thing to get right on this page. |
| EU AI Act and ISO/IEC 42001:2023 — obligations that scale with risk, and a management system standard organizations can be assessed against, with policy, roles, risk assessment and documented controls. | Annex I high-risk, covering AI in regulated products including medical devices, now applies 2 August 2028; Annex III 2 December 2027. ISO/IEC 42001 published 18 December 2023. | The AI Act dates moved in July 2026. ISO/IEC 42001 has not changed, and any global certification count you are shown does not trace back to ISO or an accreditation body. |
FDA’s Considerations for the Use of Artificial Intelligence To Support Regulatory Decision-Making for Drug and Biological Products (January 2025) remains a draft and is marked not for implementation; FDA and EMA published ten joint guiding principles on good AI practice in drug development in January 2026, which are also non-binding. Naming a framework is not a claim of standing under it.
We prepare evidence. We do not validate.
The distinction matters more here than anywhere else on this site, so we will state it without softening it. Reign Assurance arranges the evidence a validation process needs into a form a reviewer can work through, and stops there. It does not certify, does not attest, does not issue an audit opinion and does not provide independent assurance, in any tense.
Where this sits against the rest of Reign.
Four motions at four different stages of maturity. We state the stage every time, because a validated environment is the wrong place for ambiguity.
A single-tenant dedicated instance, in your own AWS or Azure account or in infrastructure iTmethods operates. Both are available today, which includes deployment into your own cloud account; Google Cloud is planned for 2027. Air-gapped and sovereign are in development. There is no multi-tenant or shared option at any tier. Deployment options →
Who holds what, before the first change in a system in scope.
Agreed and recorded in the agreement, including the data categories, before work begins.
| Who | What they hold |
|---|---|
| iTmethods | Operate the delivery estate as a single-tenant dedicated instance. Record who changed what, who approved it and when, attributable to a named person. Provide a named engineer for the agreed population who appears in the record. |
| Your quality function | Validation, and the determination of whether a system is validated. Which systems are in scope. The acceptance criteria. Every approval. We supply the evidence; the decision is not ours and we will not describe it as shared. |
| Your data protection function | The lawful basis, the categories of patient, trial and personal data in scope, and the determination of whether an engagement meets your obligations. Those categories go into the agreement before work starts. |
The questions that arrive every time.
Do you validate systems?
Does the revised Annex 11 cover AI?
Where would patient or trial data sit?
What can you actually evidence today?
Which deployment shapes can we have?
Start with the data and the scope.
Tell us which systems are in scope and which categories of data are involved, and we will show you what the record looks like at the end of a real population of work.