KI im GxP-Umfeld · Annex 11 · Annex 22

AI in GxP environments · Annex 11 · Annex 22

KI nutzen.
Compliance
nicht riskieren.

Leverage AI.
Without risking
compliance.

KI-Einsatz in GxP-Prozessen ist keine Frage der Vorsicht — sondern der Architektur. Ob ein System regulatorisch konform ist, entscheidet sich nicht im Betrieb, sondern in der Struktur des Rahmens, in den es eingebettet ist. Den richtigen Rahmen zu entwerfen ist unsere Aufgabe.

AI deployment in GxP processes is not a question of caution — but of architecture. Whether a system is regulatorily compliant is determined not in operation, but in the structure of the framework it is embedded in. Designing that framework correctly is our job.

Regulatorische Basis: EU-GMP Annex 11 (Rev.) und Annex 22 — Bezug auf Draft-Stand Juli 2025; finale Fassung für Mitte 2026 erwartet.

Regulatory basis: EU GMP Annex 11 (Rev.) and Annex 22 — referencing the July 2025 draft; final version expected mid-2026.

Regulatorische Rahmenbedingungen

Regulatory frameworks

EU GMP Annex 22 (Draft)

Erstes GMP-Regelwerk spezifisch für KI — schließt LLMs aus kritischen Anwendungen aus

First GMP framework specifically for AI — excludes LLMs from critical applications

EU GMP Annex 11 (Rev.)

Computergestützte Systeme: Validierung, Audit-Trail, Datenintegrität, Lieferanten

Computerised systems: validation, audit trail, data integrity, suppliers

GAMP5 (rev. 2022)

KI/ML als Sonderkategorie — risikobasierte Validierungsstrategie

AI/ML as a special category — risk-based validation strategy

EU AI Act

Risikoeinstufung, Hochrisiko-KI-Anforderungen, technische Dokumentation

Risk classification, high-risk AI requirements, technical documentation

Die Grundfragen

The fundamental questions

Bevor die Frage „Wie?" kommt, steht die Frage „Wann überhaupt — und unter welchen Bedingungen?"

Before the question "how?" comes the question "when at all — and under what conditions?"

01

Wann darf ich KI überhaupt einsetzen?

When am I even allowed to use AI?

Erst wenn nachgewiesen ist, dass die Risiken bekannt, bewertet und durch geeignete Maßnahmen beherrschbar sind. Nicht als Absichtserklärung — als auditierbarer Nachweis.

Only once it is proven that the risks are known, assessed, and controllable through appropriate measures. Not as a declaration of intent — as an auditable proof.

02

Unter welchen Bedingungen ist der Einsatz vertretbar?

Under what conditions is deployment defensible?

KI darf keine qualitätsbestimmende Entscheidung allein treffen. Der Human-in-the-Loop-Ansatz muss konsequent und nachvollziehbar implementiert sein — nicht nominell.

AI must not make quality-determining decisions alone. The human-in-the-loop approach must be consistently and traceably implemented — not nominally.

03

Wie weise ich das nach?

How do I prove it?

Durch Prozess- und Systemarchitektur, die den Nachweis strukturell erzeugt — nicht durch nachträgliche Dokumentation eines bereits laufenden Systems.

Through process and system architecture that structurally produces the proof — not through retrospective documentation of an already running system.

Paradigmenwechsel

Paradigm shift

Risikomanagement wird wichtiger —
nicht um Aufwand zu reduzieren,
sondern um KI überhaupt erst zu ermöglichen.

Risk management becomes more important —
not to reduce effort,
but to make AI use possible in the first place.

Im klassischen GxP-Verständnis ist Risikomanagement eine Compliance-Pflicht — ein Nachweis, der erbracht wird. Mit KI dreht sich das Verhältnis um: Der Nachweis, dass Risiken bekannt und verstanden sind, ist die Voraussetzung, um KI überhaupt unter kontrollierten Bedingungen einsetzen zu dürfen. Wer diesen Nachweis nicht führen kann, darf nicht beginnen.

In classical GxP understanding, risk management is a compliance obligation — a proof to be provided. With AI, the relationship inverts: proof that risks are known and understood is the prerequisite for being allowed to use AI under controlled conditions at all. Those who cannot provide this proof must not start.

Das Ziel ist Validated by Design: Nicht das Modell wird validiert — was bei nicht-deterministischen LLMs kaum möglich ist — sondern der Prozess stellt die Validität sicher und macht sie nachvollziehbar.

The goal is Validated by Design: not the model is validated — which is barely possible for non-deterministic LLMs — but the process ensures validity and makes it traceable.

Die Grundlagen müssen stimmen

The foundations must hold

Klare Rollen und Verantwortlichkeiten in der Organisation. Vollständige, konsistente Dokumentation. Sind diese Voraussetzungen nicht erfüllt, gilt: garbage in, garbage out — unabhängig davon, wie gut die KI-Architektur ist.

Clear roles and responsibilities in the organisation. Complete, consistent documentation. If these prerequisites are not met: garbage in, garbage out — regardless of how good the AI architecture is.

Validated by Design

Validated by Design

Compliance entsteht nicht durch Prüfung am Ende, sondern durch Gestaltung von Anfang an. Nicht die Systemfunktionalität des LLM wird validiert — der Prozess erzeugt die Validität strukturell und macht sie nachweisbar.

Compliance is created by design from the start, not by testing at the end. The LLM's system functionality is not validated — the process structurally produces validity and makes it provable.

Prozess vor System vor KI

Process before system before AI

Die Reihenfolge ist entscheidend: Erst der Prozess muss verstanden und spezifiziert sein. Dann das System, das ihn umsetzt. Dann — und nur dann — die KI als Element innerhalb eines validierten Schritts.

The order is decisive: first the process must be understood and specified. Then the system that implements it. Then — and only then — the AI as an element within a validated step.

Governance durch Camunda

Governance through Camunda

Der HITL-Ansatz und die Nachweisführung müssen technisch erzwungen werden — nicht durch Vereinbarungen, die im Betrieb unterlaufen werden können. Camunda ist das Tool, das diese Governance implementierbar und nachweisbar macht.

The HITL approach and evidence must be technically enforced — not through agreements that can be circumvented in operation. Camunda is the tool that makes this governance implementable and provable.

Fokusthema · Vollständige Ausarbeitung

Focus topic · Full elaboration

KI-Validierung & Annex 22 — Voraussetzungen, Architektur, Nachweis →

AI validation & Annex 22 — prerequisites, architecture, evidence →

Was wir konkret liefern

What we specifically deliver

Von der Einstufung bis zum validierten System.

From classification to validated system.

Use-Case-Assessment & Kritikalitätsbewertung

Use-case assessment & criticality evaluation

Welche KI-Systeme in Ihren GxP-Prozessen sind nach Annex 22 kritisch — und welche nicht. Die Einstufung ist keine Meinungsfrage, sondern eine Architekturfrage. Wir dokumentieren die Begründung als auditierbares Artefakt.

Which AI systems in your GxP processes are critical under Annex 22 — and which are not. Classification is not a matter of opinion, but of architecture. We document the rationale as an auditable artifact.

Architektur-Blueprint für GxP-Prozesse

Architecture blueprint for GxP processes

Wir erarbeiten mit Ihnen die Architektur, die GxP-Konformität strukturell erzeugt — nicht nachträglich kontrolliert. Das schließt Prozessmodellierung, Schichtentrennung und Nachweisstrategie ein.

We develop the architecture with you that structurally produces GxP conformity — rather than controlling it retrospectively. This includes process modelling, layer separation, and evidence strategy.

Validierungsrahmen & Dokumentationskaskade

Validation framework & documentation cascade

Überführung des Blueprints in das unternehmensinterne Dokumentensystem: Validierungskonzept, SOPs, Templates, Periodic Review — Annex-11- und Annex-22-konform.

Translation of the blueprint into the company's document system: validation concept, SOPs, templates, periodic review — Annex 11 and Annex 22 compliant.

RAG-Systeme für regulierte Dokumente

RAG systems for regulated documents

Retrieval Augmented Generation für interne Dokumentenlandschaften: SOPs, Validierungsdossiers, Auditberichte, Regulatory-Texte — versioniert, on-premise, ohne Cloud-Modell-Instabilität.

Retrieval Augmented Generation for internal document landscapes: SOPs, validation dossiers, audit reports, regulatory texts — versioned, on-premises, without cloud model instability.

Wir haben die regulatorische Architektur für LLM-Einsatz in GxP-Prozessen entwickelt — in der Auseinandersetzung mit konkreten Systemlandschaften, nicht aus dem Lehrbuch. Das macht einen Unterschied.

We developed the regulatory architecture for LLM deployment in GxP processes — through work with concrete system landscapes, not from textbooks. That makes a difference.

KI-Einsatz im regulierten Umfeld besprechen

Discuss AI deployment in a regulated context

Wir starten mit einem konkreten Assessment — ohne Verpflichtung.

We start with a concrete assessment — no commitment required.

Gespräch anfragen Request a call