The Navata Briefing: July's nine field notes, one question
Hello,
Nine field notes went up on Navata Insights in July. They covered regulation, Quality AI and client-side Veeva delivery, but they were all examining the same underlying question:
When a regulated technology programme is challenged after go-live, can the client reconstruct what happened, explain why it happened, and show who owned the decision?
July began with regulatory reality. Annex 22 will define additional expectations for AI in GMP manufacturing. Annex 11 already governs the systems, data, suppliers, audit trails and evidence underneath it. The EU AI Act timetable for high-risk systems may have moved to 2027 and 2028. The obligation to maintain validated, controlled processes did not move with it.
From there, the focus shifted to the operating model. Inspection debt accumulates when validation is treated as a one-time event. Veeva's Deviation and Complaint Agents work with the records and design decisions already inside the QMS, including its unresolved weaknesses.
The same ownership issue appeared in implementation delivery. Configuration is not the same thing as capability. Quality may own the process, Digital the platform, and the implementation partner the configuration work. The client still has to own the architecture decisions, the acceptance evidence and the operating capability that remain after the partner leaves.
The final pieces examined the mechanics: qualifying non-deterministic RAG systems, reading a Veeva SOW against four tags, deliverable, assumption, risk allocation, test, and deciding which regulated actions should remain technically unavailable to an AI agent under the Non-Delegable Action Test.
The recurring risk sits in the gap between what was delivered and what the client can own, reconstruct and defend.
July's field notes:
Everyone Is Watching Annex 22. But Your Next Inspection Will Still Start With Annex 11.
The EU AI Act Deadline Just Moved to 2027. Your Validation Programme Shouldn't.
Validating Your AI Was the Easy Part. What Happens After Creates Inspection Debt.
Your Veeva Programme Has a Project Plan. Does It Have an Architecture?
How to Read an SOW Like an Implementation Architect (Part 1 of 2).
The Most Important AI Control May Be the Action It Cannot Take.
If Veeva delivery is your immediate concern, begin with "Does It Have an Architecture?" If you're working through Quality AI controls, begin with "The Action It Cannot Take."
Part 2 of the SOW series is next.
If this was useful, forward it to a colleague who'd want it too.
Rohith
Founder, Navata Ltd
Add a comment: