AI, Validation and 21 CFR Part 11: Regulating AI in Clinical Data Management

|Anders Mortin

There is no separate rulebook for AI in Clinical Data Management. AI-supported work in trials is regulated through the frameworks that already govern computerized systems: 21 CFR Part 11 for electronic records and signatures, computer system validation expectations, and the data integrity principles summarized as ALCOA+. What AI changes is not which rules apply but how hard some of them are to satisfy, because systems that learn sit uneasily inside a validation paradigm built for systems that stay fixed. This article explains where the friction is and what regulators have said so far.

The broader technology landscape is covered in the pillar guide AI in Clinical Data Management. This article is the regulatory deep-dive.

First, the Terminology Trap: Two Different Validations

The word validation means two unrelated things in Clinical Data Management, and conflating them derails most AI compliance discussions. Data validation is the cleaning discipline: edit checks, queries and discrepancy management applied to trial data, covered in Data Validation in Clinical Data Management. Computer system validation, the subject here, is the documented demonstration that a computerized system does what it is intended to do, consistently. The practical CSV workflow for trial systems, including IQ, OQ and UAT, is walked through in EDC Validation Requirements. An AI feature inside an EDC platform is a computer system validation question, even when the feature's job is data validation.

What 21 CFR Part 11 Requires, and Why AI Does Not Change It

21 CFR Part 11 governs electronic records and electronic signatures in FDA-regulated work. Its core demands are technology-neutral: systems must be validated, records must be protected and retrievable, access must be controlled, electronic signatures must be attributable, and changes to records must be captured in secure, computer-generated, time-stamped audit trails. Nothing in that list has an AI exemption, and nothing in it becomes optional when a vendor adds machine learning.

Two consequences follow for AI features. Every action an AI component takes on trial data must be captured in the audit trail with the same rigour as a human action, so that who or what changed a record, and when, remains answerable. And attributability sharpens rather than blurs: when an AI drafts a query or suggests a code, the record must show both the machine step and the human approval that made it a regulated decision. How audit trails carry this evidence load is covered in Quality Control and Audit Trails in Clinical Data Management.

The Hard Problem: Validating Systems That Can Change

Classic computer system validation assumes a fixed system: validate it once against its intended use, then control every change. A deterministic edit check fits that model perfectly. A machine learning model does not, for two reasons. Retraining changes behaviour without a traditional code change, and even an unchanged model's real-world performance can drift when the incoming data shifts, for example when a study population or a dictionary version changes.

The emerging answer has three parts. Lock what can be locked: many production deployments use frozen model versions, so a retrain is handled as a formal change with revalidation, not a silent update. Monitor what cannot be locked: learned components get ongoing performance monitoring against defined acceptance metrics, rather than a single acceptance test. And document intended use precisely, because a model validated for suggesting MedDRA codes has demonstrated nothing about any other task. Industry guidance is catching up: ISPE's GAMP 5 second edition, the de facto reference for computerized system compliance in life sciences, added guidance addressing artificial intelligence and machine learning within this life-cycle approach.

What Regulators Have Said So Far

The clearest signal to date came on January 6, 2025, when the FDA published draft guidance titled Considerations for the Use of Artificial Intelligence To Support Regulatory Decision-Making for Drug and Biological Products. It proposes a risk-based credibility assessment framework: the sponsor defines the model's context of use, assesses the risk of the model's output in that context, and matches the depth of credibility evidence to that risk. The scope is deliberate: it covers AI used to produce information supporting regulatory decisions about safety, effectiveness or quality, and explicitly excludes drug discovery and purely operational uses. For Clinical Data Management, the message is that the closer an AI output sits to data supporting a submission, the heavier the evidence burden.

The same direction runs through the wider framework. The latest revision of ICH E6 GCP strengthens quality by design and risk-proportionate approaches, which is the posture AI oversight requires. And across guidance documents, one expectation repeats without exception: human oversight of AI output in regulated decisions. No current regulatory text contemplates removing the accountable person.

A Practical Compliance Baseline

For a data management team adopting AI features, five controls form a defensible baseline. Define the intended use of each AI feature in writing, narrowly. Keep the human approval step for every regulated output, and make it visible in the audit trail. Treat model versions as configuration items under change control, with retraining triggering revalidation. Monitor learned components continuously against predefined performance metrics, and act when they drift. And record the AI's actions in the audit trail with the same completeness as human actions, so ALCOA+ holds end to end. Teams that can show these five controls have answered most of what an inspector will ask about AI, because the questions are the classic ones: what does the system do, how do you know it works, and who decided.

TriTiCon's course The practical use of AI in clinical development builds the practical foundation for working with AI in a regulated environment, and the full catalogue is in the Clinical Development Training collection. A dedicated course on AI in Clinical Data Management is currently in development.

Frequently Asked Questions

Does 21 CFR Part 11 apply to AI in clinical data management?

Yes, fully. Part 11's requirements on system validation, secure time-stamped audit trails, access control and attributable electronic signatures are technology-neutral, so they apply to AI features exactly as to any other computerized function. AI actions on trial data must be audit-trailed with the same rigour as human actions.

Can a machine learning model be validated for clinical trial use?

Yes, with an adapted approach: validate a locked model version against a precisely defined intended use, handle retraining as formal change control with revalidation, and add ongoing performance monitoring against predefined metrics, since a learned model's real-world performance can drift even without a retrain.

What does the FDA say about AI in drug development?

In January 2025 the FDA published draft guidance proposing a risk-based credibility assessment framework for AI used to support regulatory decisions on drug safety, effectiveness or quality: define the model's context of use, assess output risk in that context, and match the credibility evidence to the risk. Drug discovery and purely operational AI uses are outside its scope.

Do AI decisions need to appear in the audit trail?

Yes. Every AI action on trial data, and the human approval that follows it, must be captured in secure, time-stamped audit trails so that what changed, what suggested the change and who approved it remain answerable. This is a direct consequence of existing Part 11 and ALCOA+ expectations, not a new AI rule.

Is human oversight of AI legally required in clinical trials?

Human oversight of AI output in regulated decisions is a consistent expectation across current guidance, and accountability for regulated decisions rests with people, not software. Practical designs keep a named person approving AI-drafted queries, codes and other regulated outputs before they take effect.

Anders Mortin

Clinical Data Management Expert

TriTiCon delivers clinical data management training based on extensive hands-on experience from real clinical trials across sponsors, CROs, and life sciences organizations. The training is developed by industry professionals who work directly with clinical data, systems, documentation, and cross-functional trial teams.

30+
Years Experience
50+
Clinical Trials