Pharmaceutical logistics
Designing against the signature that means nothing
A distributor drowning in temperature-excursion investigations wanted them automated. The regulation settles quickly who signs. The hard part was the failure nobody asks about, an assistant good enough to be approved without being read.
A fluent draft is persuasive whether or not it is right, so the edit rate became the thing to watch.
Problem
Every temperature excursion in transit triggers an investigation: quarantine the stock, assess the impact on product quality, decide release or destruction, and document it. The quality team was the bottleneck, and stock sat quarantined while it queued.
Context
Cold-chain distribution across several countries, with data loggers on pallets and a quality team of modest size.
Current architecture
A warehouse management system, logger data downloaded per shipment into a shared drive, and investigations written by hand in a quality management system.
Constraints
- Regulatory: all excursions must be investigated, documented and evaluated for effect on product quality, with corrective and preventive actions.
- Regulatory: a wholesale distributor operates under a Responsible Person named on its distribution authorisation (Directive 2001/83/EC Art. 79 and the GDP guidelines), and that judgement cannot be delegated to software. The Qualified Person is the GMP batch-release role at a manufacturer and does not sit in this workflow.
- Data residency: quality records must remain within the EU.
- Auditability: an inspector must be able to reconstruct any decision.
Evidence
Each statement placed on the ladder before it was used.
Under EU good distribution practice, all excursions from required temperature must be investigated, documented and evaluated for potential effect on product quality, with corrective and preventive actions recorded. Even brief deviations require investigation.
Transparency obligations under the EU AI Act, including Article 50, apply from 2 August 2026: providers of generative systems must ensure outputs are marked machine-readable and detectable as artificially generated. That duty falls on the provider of the system. The deployer duties in Article 50(4) are narrower. They cover two things: deep fakes, and AI-generated text published to inform the public on matters of public interest. An internal, human-reviewed regulated record is neither.
High-risk obligations were rescheduled by the AI Omnibus: Annex III stand-alone systems move to 2 December 2027, and high-risk AI embedded in regulated products to 2 August 2028.
A large share of investigations reach the same conclusion by the same reasoning. Believed by the quality lead; supported by a sample of files, not by a full audit.
Stock cannot be released on an automated assessment, regardless of how accurate that assessment is.
Questions that changed the answer
- Which parts of an investigation are retrieval and transcription, and which are judgement?
- How long does an investigation take, split by those two parts? Nobody had measured the split.
- If a drafted investigation is wrong and a Responsible Person signs it, what failed, the tool or the process?
- How is a machine-drafted section marked, so an inspector can see what was generated?
Options
Including the one nobody wanted to discuss.
Automated disposition
The system assesses the excursion and releases or rejects stock.
What it costs: Places a regulated judgement in software and would not survive inspection.
Drafting assistant with mandatory sign-off
The system assembles logger data, product stability limits and precedent investigations into a draft; the Responsible Person reviews, edits and signs. Machine-drafted sections are marked as such.
What it costs: Saves less than full automation, and introduces a real risk of rubber-stamping that must be designed against.
Hire more quality staff
Add headcount to clear the queue.
What it costs: Linear cost for a linear gain, and the recruitment market for Responsible Persons is thin.
Economics
Four horizons, not one estimate.
- Build
- Retrieval over logger data and precedent files, plus a drafting step and an audit trail. The audit trail was the larger half.
- Run
- Inference per investigation is small against the quality-team hours it returns. Validation and periodic review are the recurring costs that matter.
- Change
- Stability data and product portfolios change; every change requires re-validation. Budgeted as a standing cost instead of a project.
- Exit
- Low by design. Drafts land in the existing quality management system, so removing the assistant leaves the records intact and the process working.
Decision
Build a drafting assistant that prepares investigations and cites its sources. Sign-off stays with the Responsible Person. Machine-drafted content is marked in the record.
Why
The regulation defines where judgement sits, so the only question worth asking was which parts of the work are not judgement. Retrieval, assembly and transcription are the bulk of the elapsed time and none of the decision.
Why not the alternatives
- Automated disposition: It would place a regulated judgement in software and fail inspection, regardless of accuracy.
- Hire more quality staff: Pursued partially, but it scales linearly against a thin labour market and leaves the transcription burden untouched.
Trade-offs accepted
- Rubber-stamping risk: a fluent draft invites approval. Countered by showing the evidence beside every claim and by sampling signed investigations for independent review.
- A validation burden that recurs with every material change.
Reversibility
The assistant writes into the existing quality system rather than replacing it. Switching it off returns the team to the current process with every record intact, which is what made it approvable.
Non-functional requirements
- Every generated claim cites the logger reading or document it came from
- Machine-drafted sections are marked in the record and in the audit trail
- Quality records stay within the EU
- The assistant is unavailable rather than wrong when source data is missing
Decision gate
GO, with the human sign-off, the source citation and the marking of generated content treated as requirements rather than as later enhancements.
Implementation
Retrieval over logger data, stability limits and precedent investigations; a drafting step; a diff view so the Responsible Person sees exactly what they are changing; and an audit trail recording draft, edits and signature.
What the decision was expected to achieve
Stock should spend less time in quarantine, and excursions should reach disposition faster. Elapsed time per investigation and the edit rate on drafts would show whether it had. A rate near zero would be a warning, not a success.
No outcome is claimed. This is an illustrative example, so there is nothing measured to report, and a real engagement would state what happened and how it was verified.
Lessons
- Automation that needs a human signature invents a new failure mode. The signature comes to mean nothing. Design for it, or you have moved the risk rather than reduced it.
- Watch the edit rate, not the approval rate. Approvals near 100% with edits near zero is the signal that review has stopped happening.
- Mark what the machine wrote. Here that is because the GDP audit trail demands it, not because Article 50 obliges this distributor. Check which duty actually binds you before citing it as the reason.

