# We connect nothing to your document system.

It is the first thing we say to an IT department, and it usually surprises them: a vendor normally sells integration. **We refuse it by design** — and that is what lets a programme start in two weeks rather than two years.

Annex 11

A computerised system replacing a manual GxP operation must be validated, covered by an audit trail, managed under change control and backed by a continuity plan. The scope of that requirement depends on what the system does, not on what it is.

Two architectures: the permanent link, which triggers validation, and the export, which does not.What we get asked forDMSToolValidation, audit trail, change control.What we doDMSexportToolNo GxP record created.

Annex 11 of the European Union GMP guide, on computerised systems.

That is where the whole reasoning turns. **A tool that reads a copy of your documents, produces an analysis, and never writes anything back into the source system creates no GxP record.** It replaces no regulated operation: it informs a decision your teams will then take, in your tools, under your procedures.

"To be useful, a tool has to be integrated into the information system."

True of a production tool, which must follow the flow continuously. Much less true of an analysis tool, whose work bears on the state of the document set at a given moment. **Integration here brings marginal convenience and a major regulatory cost**: infrastructure qualification, validation, access management, audit trail, recovery plan, and an entry in your computerised systems validation plan — that is, in most groups, twelve to twenty-four months before the first result.

## Four questions, four short answers.

### Connection to the IS

None. We work from an export, supplied by you, in whatever format your document system can produce. No API, no service account, no permanent flow to monitor. Nothing to open in the firewall.

### GxP status

The tool neither produces nor modifies a regulated record. The deliverables are analyses and draft documents, which then enter _your_ approval loop and acquire their status there. The chain of responsibility stays intact.

### Data hosting

In Europe, on our infrastructure, with largely local models — your documents do not go off to feed a third-party service. And for organisations that require it, most of our tools can be transferred into your own environment.

### Reversibility

At the end of the assignment, your documents stay with you, in your document system, with no dependency on an external tool. There is nothing to unplug, so nothing holding you. That is the logical counterpart of not integrating.

## The accelerators serve the consultant, not the other way round.

A model that compares two hundred procedures and flags the contradictions does overnight what would occupy a consultant for weeks. **It decides nothing.** The decision to merge, withdraw or rewrite belongs to your quality teams, with their risk analysis and their change control loop. That division is what makes the tool compatible with a regulated environment — and what makes it defensible on inspection.

## Starting in two weeks.

Time

An export takes a few days to produce. An integration project takes months to negotiate. On a documentation programme, the first result lands before the second has had its architecture board.

Cost

Validating a GxP computerised system often costs more than the programme it was meant to serve. Not triggering it for an analysis tool is a direct saving, with no trade-off.

Risk

No permanent access to open, no accounts to manage, no attack surface added. For an IT department it is the simplest case to assess — and usually what unblocks the project.

That leaves the case where integration genuinely makes sense: daily use, by your teams, over time. We handle that as it should be handled — **by transferring the tool to you**, into your environment and under your governance, rather than through a permanent outbound link.

## Go further.

[

### Make your DMS talk

What an export already contains.

Read →](/en/blog/data-analysis-dms-document-repository/)[

### Data integrity and ALCOA

What the data must guarantee.

Read →](/en/blog/data-integrity-alcoa-isi-rule/)[

### Electronic batch records

When validation does apply.

Read →](/en/blog/electronic-batch-record-validated-excel/)

## AI in a GxP environment, plainly.

Does an AI tool used on quality documents need validating? +

The question to settle is: does this tool replace a GxP operation, or produce a regulated record? If the answer is no — it analyses, proposes, and a human decides in the official system — the computerised systems validation regime does not apply to it. That determination must be traced, and it is a short document.

How do you guarantee the model is not wrong? +

You do not, which is why none of its outputs is applied directly. Every proposal is reviewed by a consultant, then by your teams, and goes through your approval loop. The tool accelerates detection, not decision — the only architecture that holds in a regulated environment.

Are our documents used to train a model? +

No. They are processed for your assignment, on our European infrastructure, and returned. Using largely local models answers precisely that requirement: your procedures do not pass through a third-party service that would retain anything.

And if we want the tool in-house? +

That is provided for, and it is the right answer for daily use over time. Transferring it into your environment places the tool under your governance, with your access rules and your data policy. The validation scope is then discussed according to the use you make of it.

## Your IT team has questions. They have short answers.

No connection, no GxP record, European hosting, full reversibility. We can go through it with them directly.
