Cosine Metrics Scope a workflow
Illustrative sample. Fictional workflow and redacted content, for demonstration only. The final sample binder will replace this stand-in. Not regulatory advice.
Sample deliverable

AI Workflow Control Binder

This is a redacted, illustrative version of the exact artifact a Engagement produces — here for a fictional AI-assisted deviation-summary drafting workflow at a mid-size biologics manufacturer. It shows the structure, depth, and evidence you receive. Real binders are built for one of your workflows, with your systems and stakeholders.

Workflow: AI-assisted deviation summary (fictional)Risk class: GAMP 5 — high decision impactStatus: illustrative
Part 1

Use-Case Charter & Context of Use

QA specialists use a hosted LLM to draft the narrative summary of a manufacturing deviation from structured event data. The draft is reviewed and approved by a qualified QA reviewer before entry into the eQMS.

Context of use: assistive drafting only; the model never classifies severity, determines root cause, or closes a deviation. Prohibited: auto-entry into the quality system; use on any deviation involving a confirmed product-quality or patient-safety impact without senior QA review.
Part 2

Current-State Workflow Map

Event captured in eQMS-XX → specialist exports structured fields → drafts narrative (today: manual; proposed: AI-assisted) → QA reviewer edits/approves → entry to eQMS → CAPA evaluation. Six handoffs; two GxP-impacting steps identified.

Part 3

Data-Integrity & Part 11 Flow Map

Inputs: deviation ID, dates, batch ID, process step, observation. No PHI. ALCOA+ assessed at each step; the AI draft is marked as draft, attributable to the specialist, never an original record until QA-approved in the validated eQMS.

ALCOA+ attributeExposureControl
AttributableAI draft authored outside eQMSDraft tagged to specialist; approval recorded in eQMS audit trail
Original / AccurateHallucinated detail riskMandatory line-by-line QA review against source fields; correction log
ContemporaneousDraft/approval time gapTimestamped on eQMS entry, not on AI draft
Part 4

Risk & Impact Assessment (GAMP 5)

Classified high decision-impact: output enters a GxP record affecting batch disposition context. Top risks: fabricated specifics, omission of a material fact, over-reliance by reviewers, and silent model change. Each mapped to a control in Parts 5–9.

Part 5

Human-Review & Accountability Model

Specialist drafts; a qualified QA reviewer (defined competency) verifies every statement against source data and approves; QA manager accountable for the workflow. Nothing auto-accepted. Corrections logged and trended as a quality signal.

Part 6

Validation / Acceptance-Test Plan (CSA-aligned)

Risk-based test set of representative and adversarial deviations; acceptance criteria on factual fidelity, completeness, and absence of fabricated content; an error taxonomy (omission, fabrication, mischaracterization); before/after review-time and error-rate metrics.

Example acceptance criterion: 0 fabricated factual statements across the test set; ≥ defined completeness score; reviewer can trace every sentence to a source field.
Part 7

AI Tool & Vendor Assessment

Reviewed: data handling, retention, whether inputs train the vendor model (must be off), access controls, audit logging, SOC 2 posture, and the model-change/version-pinning policy. Security review led by a Security+-certified reviewer.

Part 8

SOP Pack

Workflow SOP · human-review SOP · data-handling SOP · exception/escalation SOP · tool-change review SOP · quality-sampling SOP. (Full SOP text redacted in this sample.)

Part 9

Monitoring & Quality-Sampling Plan

Defined sampling rate of approved summaries, error categories trended monthly, KPI dashboard (error rate, review time, correction types), and explicit revalidation triggers (model version change, error-rate threshold breach, workflow change).

Part 10

Training Deck & Sign-off

Role-based rules, side-by-side acceptable/unsafe examples, a competency check, and a training-record template for specialists and reviewers.

Part 11

Executive Go/No-Go Memo

Readiness: conditional go — pilot on low-severity deviations with the controls above. Residual risk: moderate, mitigated by mandatory review and monitoring. 30/60/90: pilot → measure error/time → expand or hold based on monitoring data.

This is what "inspection-ready" looks like

For one of your workflows, with your systems and stakeholders — fixed fee, 6–12 weeks.

← Back to resources