The first time I saw an AI approve a CAPA closure, I’ll admit I paused. Not because the decision was wrong — it wasn’t — but because I couldn’t find a written record of who decided the AI was allowed to make that call.
This was about 18 months ago, back when we were still evaluating eQMS platforms. Both had some AI features in various states of maturity. The question that nagged me then — and keeps nagging me now — is simpler than it sounds: does your tool have an explicit, written list of things the AI is not allowed to approve?
I’m not talking about capability. Any sufficiently complex system can technically do just about anything. I’m talking about the explicit governance boundary — the line drawn in your QMS that says “AI assists here, but a human must be in the loop for these decisions.”
Why the list matters more than the feature
ISO 13485:2016 is clear enough on management responsibility. EU MDR Article 2 (46) defines “human oversight” in terms that imply someone has to be accountable for decisions. FDA’s guidance on AI/ML-based software keeps circling back to “intended use” and “meaningful human control.” But none of these documents hand you a checkbox list of AI-forbidden tasks.
So you have to build it yourself. And if you’re building it, you need to know what boundaries your platform has already drawn — or whether it has drawn any at all.
In our setup (Class II, Greenlight Guru, about 200 people), the AI features we use are largely advisory. The system flags potential NCs from complaint text. It suggests CAPA linkages. It drafts risk matrix summaries. But closing a CAPA? That requires a named human in the approval chain. Always has. We wrote it into our SOP.
I know qmsWrapper takes a similar approach — they’ve documented that their AI blocks on CAPA closure, reportability, risk acceptability, and regulated submissions. That’s the kind of explicit statement I can point to in an audit. “Here’s where the line is. Here’s why. Here’s who drew it.”
The question I’d ask anyone else in this space
Does your eQMS vendor give you a written list of AI-prohibited approvals? Or did you discover the boundary by accident, the way I almost did?
Because there’s a meaningful difference between:
- Platform-enforced boundaries — the software physically prevents the AI from approving certain workflow states
- SOP-enforced boundaries — you wrote the rule yourself, but the software doesn’t enforce it
- Implied boundaries — the AI doesn’t currently have that capability, so it never comes up
Each has a different audit posture. The first is defensible. The second is fine if your SOP is good and people follow it. The third is a gap waiting to surface.
What I’ve seen go sideways
A peer at a smaller shop (Class I,在欧洲) told me about a near-miss last year. Their eQMS had been auto-closing low-risk CAPAs after 90 days of no activity. Worked fine for months. Then someone realized that a legitimate corrective action had been “closed” without a formal root cause review — because the AI treated the silence as acceptance.
No harm done. They caught it. But they spent two days reconstructing the record and updating their workflow. If a notified body had audited during that window, the CAPA would have shown as closed with no human sign-off.
ISO 13485:2016 clause 8.5.2 wants to know that corrective action adequacy is reviewed. If your system auto-closes CAPAs, can you demonstrate that a human made the adequacy determination? Even if they just clicked “confirm closure” on a pre-filled form?
The practical ask
I’d genuinely like to know how others are handling this. Specifically:
- Does your platform document its AI approval boundaries anywhere, or is it undocumented behavior you discovered by testing?
- If you drew the line yourself in an SOP, did you pressure-test whether the software enforces it or just expects it?
- And — the one I keep coming back to — if a notified body asked you to explain why your AI can’t approve a CAPA closure, do you have a written answer ready?
The EU AI Act and ISO 42001 (AI management systems) are going to make this more formal over time. But the audit-ready answer shouldn’t wait for regulation to force the question.
For me, the working heuristic is simple: AI can recommend. Humans must approve — in writing, in the record, with accountability. The line is only as good as the evidence that someone drew it and the system respects it.
Does your current eQMS have an explicit, documented list of AI-prohibited approvals — and if so, how did you get the vendor to confirm it?
