KI im GxP-Umfeld · Annex 11 · Annex 22
AI in GxP environments · Annex 11 · Annex 22
KI-Einsatz in GxP-Prozessen ist keine Frage der Vorsicht — sondern der Architektur. Ob ein System regulatorisch konform ist, entscheidet sich nicht im Betrieb, sondern in der Struktur des Rahmens, in den es eingebettet ist. Den richtigen Rahmen zu entwerfen ist unsere Aufgabe.
AI deployment in GxP processes is not a question of caution — but of architecture. Whether a system is regulatorily compliant is determined not in operation, but in the structure of the framework it is embedded in. Designing that framework correctly is our job.
Regulatorische Basis: EU-GMP Annex 11 (Rev.) und Annex 22 — Bezug auf Draft-Stand Juli 2025; finale Fassung für Mitte 2026 erwartet.
Regulatory basis: EU GMP Annex 11 (Rev.) and Annex 22 — referencing the July 2025 draft; final version expected mid-2026.
Regulatorische Rahmenbedingungen
Regulatory frameworks
EU GMP Annex 22 (Draft)
Erstes GMP-Regelwerk spezifisch für KI — schließt LLMs aus kritischen Anwendungen aus
First GMP framework specifically for AI — excludes LLMs from critical applications
EU GMP Annex 11 (Rev.)
Computergestützte Systeme: Validierung, Audit-Trail, Datenintegrität, Lieferanten
Computerised systems: validation, audit trail, data integrity, suppliers
GAMP5 (rev. 2022)
KI/ML als Sonderkategorie — risikobasierte Validierungsstrategie
AI/ML as a special category — risk-based validation strategy
EU AI Act
Risikoeinstufung, Hochrisiko-KI-Anforderungen, technische Dokumentation
Risk classification, high-risk AI requirements, technical documentation
Die Grundfragen
The fundamental questions
01
Erst wenn nachgewiesen ist, dass die Risiken bekannt, bewertet und durch geeignete Maßnahmen beherrschbar sind. Nicht als Absichtserklärung — als auditierbarer Nachweis.
Only once it is proven that the risks are known, assessed, and controllable through appropriate measures. Not as a declaration of intent — as an auditable proof.
02
KI darf keine qualitätsbestimmende Entscheidung allein treffen. Der Human-in-the-Loop-Ansatz muss konsequent und nachvollziehbar implementiert sein — nicht nominell.
AI must not make quality-determining decisions alone. The human-in-the-loop approach must be consistently and traceably implemented — not nominally.
03
Durch Prozess- und Systemarchitektur, die den Nachweis strukturell erzeugt — nicht durch nachträgliche Dokumentation eines bereits laufenden Systems.
Through process and system architecture that structurally produces the proof — not through retrospective documentation of an already running system.
Paradigmenwechsel
Paradigm shift
Im klassischen GxP-Verständnis ist Risikomanagement eine Compliance-Pflicht — ein Nachweis, der erbracht wird. Mit KI dreht sich das Verhältnis um: Der Nachweis, dass Risiken bekannt und verstanden sind, ist die Voraussetzung, um KI überhaupt unter kontrollierten Bedingungen einsetzen zu dürfen. Wer diesen Nachweis nicht führen kann, darf nicht beginnen.
In classical GxP understanding, risk management is a compliance obligation — a proof to be provided. With AI, the relationship inverts: proof that risks are known and understood is the prerequisite for being allowed to use AI under controlled conditions at all. Those who cannot provide this proof must not start.
Das Ziel ist Validated by Design: Nicht das Modell wird validiert — was bei nicht-deterministischen LLMs kaum möglich ist — sondern der Prozess stellt die Validität sicher und macht sie nachvollziehbar.
The goal is Validated by Design: not the model is validated — which is barely possible for non-deterministic LLMs — but the process ensures validity and makes it traceable.
Klare Rollen und Verantwortlichkeiten in der Organisation. Vollständige, konsistente Dokumentation. Sind diese Voraussetzungen nicht erfüllt, gilt: garbage in, garbage out — unabhängig davon, wie gut die KI-Architektur ist.
Clear roles and responsibilities in the organisation. Complete, consistent documentation. If these prerequisites are not met: garbage in, garbage out — regardless of how good the AI architecture is.
Compliance entsteht nicht durch Prüfung am Ende, sondern durch Gestaltung von Anfang an. Nicht die Systemfunktionalität des LLM wird validiert — der Prozess erzeugt die Validität strukturell und macht sie nachweisbar.
Compliance is created by design from the start, not by testing at the end. The LLM's system functionality is not validated — the process structurally produces validity and makes it provable.
Die Reihenfolge ist entscheidend: Erst der Prozess muss verstanden und spezifiziert sein. Dann das System, das ihn umsetzt. Dann — und nur dann — die KI als Element innerhalb eines validierten Schritts.
The order is decisive: first the process must be understood and specified. Then the system that implements it. Then — and only then — the AI as an element within a validated step.
Der HITL-Ansatz und die Nachweisführung müssen technisch erzwungen werden — nicht durch Vereinbarungen, die im Betrieb unterlaufen werden können. Camunda ist das Tool, das diese Governance implementierbar und nachweisbar macht.
The HITL approach and evidence must be technically enforced — not through agreements that can be circumvented in operation. Camunda is the tool that makes this governance implementable and provable.
Fokusthema · Vollständige Ausarbeitung
Focus topic · Full elaboration
KI-Validierung & Annex 22 — Voraussetzungen, Architektur, Nachweis →
AI validation & Annex 22 — prerequisites, architecture, evidence →
Was wir konkret liefern
What we specifically deliver
Welche KI-Systeme in Ihren GxP-Prozessen sind nach Annex 22 kritisch — und welche nicht. Die Einstufung ist keine Meinungsfrage, sondern eine Architekturfrage. Wir dokumentieren die Begründung als auditierbares Artefakt.
Which AI systems in your GxP processes are critical under Annex 22 — and which are not. Classification is not a matter of opinion, but of architecture. We document the rationale as an auditable artifact.
Wir erarbeiten mit Ihnen die Architektur, die GxP-Konformität strukturell erzeugt — nicht nachträglich kontrolliert. Das schließt Prozessmodellierung, Schichtentrennung und Nachweisstrategie ein.
We develop the architecture with you that structurally produces GxP conformity — rather than controlling it retrospectively. This includes process modelling, layer separation, and evidence strategy.
Überführung des Blueprints in das unternehmensinterne Dokumentensystem: Validierungskonzept, SOPs, Templates, Periodic Review — Annex-11- und Annex-22-konform.
Translation of the blueprint into the company's document system: validation concept, SOPs, templates, periodic review — Annex 11 and Annex 22 compliant.
Retrieval Augmented Generation für interne Dokumentenlandschaften: SOPs, Validierungsdossiers, Auditberichte, Regulatory-Texte — versioniert, on-premise, ohne Cloud-Modell-Instabilität.
Retrieval Augmented Generation for internal document landscapes: SOPs, validation dossiers, audit reports, regulatory texts — versioned, on-premises, without cloud model instability.
Wir haben die regulatorische Architektur für LLM-Einsatz in GxP-Prozessen entwickelt — in der Auseinandersetzung mit konkreten Systemlandschaften, nicht aus dem Lehrbuch. Das macht einen Unterschied.
We developed the regulatory architecture for LLM deployment in GxP processes — through work with concrete system landscapes, not from textbooks. That makes a difference.
KI-Einsatz im regulierten Umfeld besprechen
Discuss AI deployment in a regulated context
Wir starten mit einem konkreten Assessment — ohne Verpflichtung.
We start with a concrete assessment — no commitment required.