Skip to content
All worked examples

Pharmaceutical logistics

GOIllustrative · 7 min read

Designing against the signature that means nothing

A distributor drowning in temperature-excursion investigations wanted them automated. The regulation settles quickly who signs. The hard part was the failure nobody asks about, an assistant good enough to be approved without being read.

A fluent draft is persuasive whether or not it is right, so the edit rate became the thing to watch.

Problem

Every temperature excursion in transit triggers an investigation: quarantine the stock, assess the impact on product quality, decide release or destruction, and document it. The quality team was the bottleneck, and stock sat quarantined while it queued.

Context

Cold-chain distribution across several countries, with data loggers on pallets and a quality team of modest size.

Current architecture

A warehouse management system, logger data downloaded per shipment into a shared drive, and investigations written by hand in a quality management system.

Constraints

  • Regulatory: all excursions must be investigated, documented and evaluated for effect on product quality, with corrective and preventive actions.
  • Regulatory: a wholesale distributor operates under a Responsible Person named on its distribution authorisation (Directive 2001/83/EC Art. 79 and the GDP guidelines), and that judgement cannot be delegated to software. The Qualified Person is the GMP batch-release role at a manufacturer and does not sit in this workflow.
  • Data residency: quality records must remain within the EU.
  • Auditability: an inspector must be able to reconstruct any decision.

Evidence

Each statement placed on the ladder before it was used.

  • fact

    Under EU good distribution practice, all excursions from required temperature must be investigated, documented and evaluated for potential effect on product quality, with corrective and preventive actions recorded. Even brief deviations require investigation.

    Source: EU GDP guidelines; industry compliance guidance

  • fact

    Transparency obligations under the EU AI Act, including Article 50, apply from 2 August 2026: providers of generative systems must ensure outputs are marked machine-readable and detectable as artificially generated. That duty falls on the provider of the system. The deployer duties in Article 50(4) are narrower. They cover two things: deep fakes, and AI-generated text published to inform the public on matters of public interest. An internal, human-reviewed regulated record is neither.

    Source: EU AI Act Article 50; European Commission, regulatory framework for AI

  • fact

    High-risk obligations were rescheduled by the AI Omnibus: Annex III stand-alone systems move to 2 December 2027, and high-risk AI embedded in regulated products to 2 August 2028.

    Source: European Commission, regulatory framework for AI, application timeline

  • assumption

    A large share of investigations reach the same conclusion by the same reasoning. Believed by the quality lead; supported by a sample of files, not by a full audit.

    No external source: stated for the example

  • constraint

    Stock cannot be released on an automated assessment, regardless of how accurate that assessment is.

    No external source: stated for the example

Questions that changed the answer

  1. 01Which parts of an investigation are retrieval and transcription, and which are judgement?
  2. 02How long does an investigation take, split by those two parts? Nobody had measured the split.
  3. 03If a drafted investigation is wrong and a Responsible Person signs it, what failed, the tool or the process?
  4. 04How is a machine-drafted section marked, so an inspector can see what was generated?

Options

Including the one nobody wanted to discuss.

  • Automated disposition

    The system assesses the excursion and releases or rejects stock.

    What it costs: Places a regulated judgement in software and would not survive inspection.

  • Drafting assistant with mandatory sign-off

    chosen

    The system assembles logger data, product stability limits and precedent investigations into a draft; the Responsible Person reviews, edits and signs. Machine-drafted sections are marked as such.

    What it costs: Saves less than full automation, and introduces a real risk of rubber-stamping that must be designed against.

  • Hire more quality staff

    Add headcount to clear the queue.

    What it costs: Linear cost for a linear gain, and the recruitment market for Responsible Persons is thin.

Economics

Four horizons, not one estimate.

Build
Retrieval over logger data and precedent files, plus a drafting step and an audit trail. The audit trail was the larger half.
Run
Inference per investigation is small against the quality-team hours it returns. Validation and periodic review are the recurring costs that matter.
Change
Stability data and product portfolios change; every change requires re-validation. Budgeted as a standing cost instead of a project.
Exit
Low by design. Drafts land in the existing quality management system, so removing the assistant leaves the records intact and the process working.

Decision

Build a drafting assistant that prepares investigations and cites its sources. Sign-off stays with the Responsible Person. Machine-drafted content is marked in the record.

Why

The regulation defines where judgement sits, so the only question worth asking was which parts of the work are not judgement. Retrieval, assembly and transcription are the bulk of the elapsed time and none of the decision.

Why not the alternatives

  • Automated disposition: It would place a regulated judgement in software and fail inspection, regardless of accuracy.
  • Hire more quality staff: Pursued partially, but it scales linearly against a thin labour market and leaves the transcription burden untouched.

Trade-offs accepted

  • Rubber-stamping risk: a fluent draft invites approval. Countered by showing the evidence beside every claim and by sampling signed investigations for independent review.
  • A validation burden that recurs with every material change.

Reversibility

low reversibility

The assistant writes into the existing quality system rather than replacing it. Switching it off returns the team to the current process with every record intact, which is what made it approvable.

Non-functional requirements

  • Every generated claim cites the logger reading or document it came from
  • Machine-drafted sections are marked in the record and in the audit trail
  • Quality records stay within the EU
  • The assistant is unavailable rather than wrong when source data is missing

Decision gate

GOPAUSESTOP

GO, with the human sign-off, the source citation and the marking of generated content treated as requirements rather than as later enhancements.

Implementation

Retrieval over logger data, stability limits and precedent investigations; a drafting step; a diff view so the Responsible Person sees exactly what they are changing; and an audit trail recording draft, edits and signature.

What the decision was expected to achieve

Stock should spend less time in quarantine, and excursions should reach disposition faster. Elapsed time per investigation and the edit rate on drafts would show whether it had. A rate near zero would be a warning, not a success.

No outcome is claimed. This is an illustrative example, so there is nothing measured to report, and a real engagement would state what happened and how it was verified.

Lessons

  • Automation that needs a human signature invents a new failure mode. The signature comes to mean nothing. Design for it, or you have moved the risk rather than reduced it.
  • Watch the edit rate, not the approval rate. Approvals near 100% with edits near zero is the signal that review has stopped happening.
  • Mark what the machine wrote. Here that is because the GDP audit trail demands it, not because Article 50 obliges this distributor. Check which duty actually binds you before citing it as the reason.

Free · 30 minutes · one real problem

Bring a problem. Leave with clarity.

Thirty minutes, one real problem, structured thinking. If there's no value, there's no engagement.