Pharma batch records: Part 11 wants exactly this audit trail
Part 11 requires secure, computer generated, time stamped audit trails independent of the operator, and a sovereign on premise review system with a sealed, tamper evident record is the cleanest way to meet it while using AI on batch records.

FDA regulation 21 CFR Part 11 requires electronic records to carry secure, computer generated, time stamped audit trails that record operator entries and actions independently of the operator, and a sovereign review system that seals a signed, tamper evident record of every action before it runs is the cleanest way to meet that standard while using modern AI on batch records. We built Mickai around exactly that architecture: review on the manufacturer's own hardware, air gapped, with the evidence generated as the work happens.
What does 21 CFR Part 11 actually require of an audit trail?
Part 11, in force since 20 August 1997, requires that audit trails for electronic records are secure, computer generated and time stamped, and that they independently record the date and time of operator entries and actions that create, modify or delete those records. Two further conditions in the regulation matter for system design. Record changes must not obscure previously recorded information, and audit trail documentation must be kept at least as long as the underlying records and remain available for FDA review and copying. The word independently is doing real work. A trail an operator can edit, suppress or write by hand is not what the regulation describes. The trail must come from the system itself, stand apart from the person acting, and survive intact for as long as the record it protects.
Why is batch record review such a heavy lift for quality teams?
Batch record review is heavy because it is cross referencing at depth, performed under regulatory duty. FDA's drug CGMP rules require batch production and control records to document each significant step, and the quality unit must review them, deviations included, before release. In practice an executed batch record is checked against the master record, entries are checked for completeness and sequence, materials are traced to their certificates, in process results are compared with specifications, and every deviation is chased to a documented resolution. Each check is simple on its own. The burden is the volume, the repetition and the consequence of missing the one entry that does not add up. Quality professionals work carefully because a release decision sits at the end, and careful is slow.
Can we put batch records through a cloud AI service?
For most pharmaceutical manufacturers we believe the defensible answer is no, because doing so routes regulated records and proprietary process knowledge through infrastructure the manufacturer does not control. Data integrity expectations, set out in FDA's data integrity guidance for drug CGMP and in the MHRA's GXP data integrity guidance, turn on attributability, originality and control of records across their lifecycle. A batch record carries the recipe of the product itself. Sending that material to a third party service creates questions a quality director must then answer in an inspection: where did the data go, who could see it, and how is that environment validated and change controlled? An on premise system removes the questions rather than answering them. The data never leaves the building, and no third party enters the chain of custody.
How does a sovereign review system fit the architecture Part 11 describes?
The fit is direct because our Open Audit Record is built to a stricter standard than the regulation asks for. Part 11 wants a secure, computer generated, time stamped trail independent of the operator. The Open Audit Record is generated by the system, sealed before an action executes rather than logged after it, cryptographically signed, tamper evident, protected with post quantum cryptography and verifiable offline with no connection to anyone. Prior entries are never obscured because the record is append only by construction. On batch records, our document review capability applies that architecture to the work itself.
- Reads the executed batch record package end to end, every page and every entry
- Cross references entries against the master batch record, material certificates and specifications
- Drafts the review paperwork for the quality unit, each finding traced to its source
- Holds every anomaly, gap or deviation for a person to disposition, releasing nothing on its own
- Seals each of those actions to the Open Audit Record before it runs
The result is a first pass that is thorough because a machine is patient enough to check everything, wrapped in an evidence trail stronger than the one the regulation requires.
“Part 11 describes an audit trail the operator cannot touch. We built one that neither the operator nor an attacker can quietly edit, sealed before the action runs and verifiable offline years later.”
Who stays accountable when AI reads the batch record?
The quality unit does, because consequential actions in our system wait for a person's clearance. The machine does the first pass, the cross referencing and the drafting. A qualified reviewer sees every held anomaly, makes the disposition and signs the release decision. Clearance itself is gated by voice biometrics and a hardware held root of trust, and it is sealed to the same record. Nothing here dilutes the quality unit's responsibility for review and release. It moves the reviewer's hours from page turning to judgement. Where a review ever touches clinical material, our output is reference only, reviewed and signed by the treating clinician, never a diagnosis.
Regulators have spent two decades narrowing the space for records that cannot prove themselves, and we expect that direction to hold as inspectors grow more fluent in data integrity and as AI enters regulated manufacturing. The manufacturers in the strongest position will be those whose systems generate their own evidence: every review sealed as it happens, every disposition attributable to a named person, every record verifiable years later without trusting the machine that made it. That is the standard we build to, on hardware the manufacturer owns, in the building where the records already live.
Frequently asked questions
Does 21 CFR Part 11 apply to AI assisted batch record review?
Yes. Part 11 covers electronic records and signatures in FDA regulated activities, so records reviewed with AI assistance sit inside it like any other electronic record, and people still make and sign the decisions.
Does an AI review system need to be validated?
Yes. Software used in a regulated process falls inside the manufacturer's qualification and change control framework, and an on premise deployment makes that practical because the environment is the site's own hardware under the site's own control.
Does the Open Audit Record replace our existing audit trails?
No, it adds a stronger layer. Existing systems keep their own logs. The Open Audit Record seals what our system did, what it found and who cleared each disposition, before each action runs, standing as evidence rather than reconstructed history.
Can the review run fully offline?
Yes. Mickai runs air gapped on the manufacturer's own hardware, with no external connection needed for review, sealing or verification. The Open Audit Record verifies offline, so evidence never depends on reaching an outside service.
What happens when the system finds an entry that does not add up?
It holds the anomaly and waits. Nothing is corrected or released by the machine. The finding goes to the quality reviewer with the cross references that triggered it, the person makes the call, and both are sealed to the record.
What is MICKAI?
MICKAI is a Sovereign Intelligence Operating System, a SIOS that runs entirely on the customer's own hardware, on premise and air gapped, so data never leaves the building. Every action is sealed to the Open Audit Record, a cryptographically signed, post quantum, tamper evident record created before an action runs and verifiable offline. Mickai comprises 87 studios, with ten production ready at launch and 77 in development, and is protected by 104 filed UK patent applications across 2,340 claims, filed rather than granted.