GMP Core · Phase 1

Choose the GMP workflow your team needs first.

Start with Document Control, Deviation, RCA, CAPA or Inspection Readiness. Use one scoped workflow or connect related workflows under an agreed process. MIRA provides bounded assistance within the workflow. Qualified humans remain responsible for review, disposition and approval.

Phase 1 covers five GMP Core workflows — In Design-Partner Validation. Verixa verifies under its SDLC; the customer validates intended use.

21 CFR Part 211
EU GMP Annex 11
21 CFR Part 11
Annex 22 (Draft 2025)
SHA-256 audit trail
The Challenge

Where quality workflows lose time and context

Regulatory complexity is rising while QA resources stay flat.

Fragmented deviation work

Intake, investigation evidence and review decisions are often distributed across documents, email and disconnected systems.

Reconstructing evidence

QA teams can spend days or weeks locating records and rebuilding context before audits, inspections and internal reviews.

Disconnected Quality Records

Related events, investigations, CAPAs and supporting records may be managed separately, making the full decision trail harder to review.

AI outside the workflow

When AI is used outside the controlled process, its source context, output and reviewer disposition may not remain connected to the quality record — the record cannot show how AI participated.

How the Workflows Connect

Five bounded workflows. Governed handoffs between them.

Each workflow is complete on its own, with its own steps, human decision gates and record. Where one workflow ends, a recorded decision — not an assumption — initiates the next.

Deviation

Intake & identificationClassificationCriticality assessmentInvestigationDisposition & closure

The Deviation investigation establishes and reviews the relevant facts and determines whether formal root-cause analysis is required. Criticality assessment is a qualified-human disposition; MIRA can surface similar prior events for reviewer assessment. Where required, RCA proceeds as a separate bounded workflow through a recorded handoff.

Decision gate

A qualified-human disposition determines whether the deviation is closed within the current workflow or whether a separate RCA workflow is initiated. Initiation criteria are governed by the customer’s approved procedure and configured workflow scope.

Root Cause Analysis

Method selection (5-Why, fishbone, fault tree)Evidence & analysisRoot cause determination, reviewed and approved by QA
Decision gate

Following root-cause determination and review, a qualified-human disposition determines whether a separate CAPA workflow is initiated, per the customer’s approved procedure.

CAPA

Action definition (owners, due dates, acceptance criteria)Implementation & verificationEffectiveness reviewClosure

Document Control

Standalone — no gate into the event chain
Controlled authoringReview cyclesApproval & versioningControlled distributionPeriodic review

Inspection Readiness

Standalone — no gate into the event chain
Scope & evidence assemblyGap reviewReviewer sign-offSealed evidence pack

Bounded AI assistance

MIRA assists within defined workflow tasks — surfacing missing context, organising source material and drafting content for review.

Human decisions remain explicit

Reviewers accept, modify or reject AI-assisted content. Regulated dispositions and approvals remain human responsibilities.

Evidence stays connected

Relevant source context, AI-assisted output and reviewer disposition are designed to remain connected to the workflow record — including each handoff gate: who initiated the next workflow, on what basis, and when.

Each handoff is a qualified-human decision, designed to be recorded — who initiated the next workflow, on what basis, and when — and governed by your approved procedure. Use one workflow alongside your existing processes, or connect related workflows under an agreed scope.

AI assists. Humans decide. The record shows both.

Phase 1 · GMP Core

Five workflows · In Design-Partner Validation

Verixa is designed to keep relevant AI-assistance context connected to the workflow record — the applicable model or deployment identifier, configuration version, source context, generated output and reviewer disposition. Applicable approval and electronic-signature events are included according to the workflow’s implemented and verified control scope.

1

Four-tier libraries, versioning, review cycles, and controlled distribution — every change captured in the audit trail.

Document Control
2

Classification, severity, investigation, and closure — with MIRA surfacing gaps for a qualified human to disposition.

Deviation Management
3

5-Why, fishbone, and fault-tree methods. MIRA suggests angles and cites evidence; a human decides.

Root Cause Analysis
4

Corrective and preventive actions with owners, due dates, effectiveness verification, and e-signature.

CAPA Management
5

A sealed, tamper-evident inspection evidence pack from live records — scorecard, exceptions summary, and one-click audited export.

Inspection Readiness
In Detail

The five workflows in detail

Each workflow, bounded and complete on its own — the problem it removes, what it gives you, and where AI assists while humans decide.

01

Document Control

Four-tier libraries, versioning, review cycles, and controlled distribution — every change captured in the audit trail.

The problem

SOP revisions live in email threads and shared drives; reviewers approve drafts they haven’t compared against the event that triggered the change; the “current” version on the floor isn’t always the effective one.

What you get

  • Four-tier document libraries with a controlled lifecycle — draft, review, approval, effective, superseded — and controlled distribution.
  • Human e-signatures on approvals (controls under verification); the approval carries the reviewer’s signature, never the AI’s.
  • MIRA advisory review: a draft checked against the record that triggered it, gaps flagged for the human reviewer to judge. The reviewer decides; MIRA never edits the document.
  • Periodic review cycles and cross-links to the quality events that shaped each revision.

In practice

In the end-to-end scenario, the revised SOP arrives with its new safety gate missing from the draft — the human reviewer, with MIRA’s advisory review beside them, catches it before approval.

See the full scenario

Related: CAPA Management (preventive actions land as SOP revisions) · Deviation Management (the events that trigger them).

02

Deviation Management

Classification, severity, investigation, and closure — with MIRA surfacing gaps for a qualified human to disposition.

The problem

Deviations raised hours after the event, typed from memory; severity set by whoever raises it; the reporter investigating their own report; evidence scattered across disconnected systems.

What you get

  • Point-of-occurrence capture with linked evidence — execution records, training matrices, affected SOPs and batches as cross-record links, not re-typed text.
  • Human-set severity — MIRA cannot set severity — with independent triage: a second person reassesses, escalates on product or patient impact, and assigns the investigator.
  • Segregation of duties enforced by the system: the reporter is blocked from investigating their own deviation.
  • Criticality assessment as a qualified-human disposition; MIRA can surface similar prior events for reviewer assessment. Closure gates hold the record open until its investigation and linked actions justify closing.

In practice

QA raises the deviation and sets the severity herself; a second reviewer escalates to Critical and assigns an investigator — the system won’t let the reporter investigate.

See the full scenario

Related: Root Cause Analysis (via the recorded decision gate) · CAPA Management · Inspection Readiness (where the closed chain becomes evidence).

03

Root Cause Analysis

5-Why, fishbone, and fault-tree methods. MIRA suggests angles and cites evidence; a human decides.

The problem

Root causes that stop at “operator error.” Investigations that restate the deviation instead of explaining it. Conclusions written by the person who led the analysis — and successfully challenged by the next inspector.

What you get

  • Structured methods — 5-Why, fishbone, fault tree — with each step backed by evidence on the record, not assertion.
  • MIRA assist, advisory only: investigation themes and next-why prompts arrive as labelled suggestions citing their evidence; the RCA record does not change until the human acts.
  • Independent conclusion enforced: the RCA lead cannot conclude their own analysis — root cause determination is reviewed and approved by QA.
  • Provenance preserved: MIRA’s original suggestion and the human’s final conclusion, side by side, each attributed.

In practice

The investigation lands on the process, not the person — and a different person, not the RCA lead, concludes it.

See the full scenario

Related: Deviation Management (the recorded gate in) · CAPA Management (the recorded gate out).

04

CAPA Management

Corrective and preventive actions with owners, due dates, effectiveness verification, and e-signature.

The problem

CAPAs that close on paper and recur in production. Action items without owners or acceptance criteria. Effectiveness “verified” by the person who owned the action. And — increasingly — AI-drafted corrective actions no human meaningfully decided.

What you get

  • Action definition with owners, due dates and acceptance criteria; implementation and verification tracked to closure, not to filing.
  • Independent item review: the CAPA owner cannot close their own action items.
  • Effectiveness review on the record — evidence the fix held, not a checkbox.
  • The MIRA refusal, by design: ask MIRA to draft a CAPA and it declines. Deciding what corrects a quality failure is a human judgement — and the refusal is itself part of your governance evidence.

In practice

The CAPA rejects the batch, opens a same-period review, and routes the SOP fix — and when asked to draft it, MIRA declines.

See the full scenario

Related: Root Cause Analysis (the source) · Document Control (where preventive actions land) · Inspection Readiness (where closure summaries surface).

05

Inspection Readiness

A sealed, tamper-evident inspection evidence pack from live records — scorecard, exceptions summary, and one-click audited export.

The problem

Inspection prep as a weeks-long project: chasing documents, rebuilding chains, hoping nothing is missing — and no way to prove the binder wasn’t assembled after the fact.

What you get

  • Scope and evidence assembly from live records: controlled documents, deviation and CAPA chains with closure summaries and per-record status, commitments, the open gap list, disposition history.
  • An exceptions summary on the first page — open critical deviations, overdue CAPAs, unresolved critical gaps. A factual list, not a compliance verdict.
  • A readiness scorecard that makes readiness a standing state you can check any week.
  • Gap review and reviewer sign-off, then a sealed, audited export carrying a verification hash bound to the pack identity and its disposition timestamp — anyone can verify that what you show is exactly what was sealed, and when.

In practice

The whole scenario chain — deviation to RCA to CAPA to revised SOP to training evidence — exports as one sealed pack when the inspector asks “show me.”

See the full scenario

Related: all four above — this is where their records become evidence.

Looking for managing the inspection itself? Request tracking during the visit, front-room/back-room coordination, observations and commitments — that’s Inspection Management, coming in Phase 2 · 2027. Inspection Management →

With every workflow

Evidence & Validation Pack

As each workflow runs, its records are organised into the Evidence & Validation Pack — supplier and workflow evidence structured to support your QA review, validation planning and inspection preparation. Not a workflow in itself: the output of the five.

In the pack

  • SDLC & AI-development controls
  • 21 CFR Part 11 controls
  • Security & per-tenant isolation
  • Requirements traceability
  • Verification evidence
  • Known defects & change control

The full Module Feature Matrix is a gated download for founding partners.

Informed By

The Standards We Design Against

Compliance is a customer determination based on intended-use validation — not a vendor claim.

21 CFR Part 211

Current Good Manufacturing Practice for finished pharmaceuticals.

EU GMP Annex 11

Computerised systems — operational reference for GMP IT controls.

21 CFR Part 11

Electronic records and electronic signatures — audit-trail and e-signature controls.

EU GMP Annex 22 (Draft 2025)

AI/ML in GMP — treated as an internal-control reference.

FDA CSA Final Guidance (Feb 2026)

Risk-based computer software assurance used as a risk-based design reference where its medical-device production and QMS scope applies.

MHRA Data Integrity (ALCOA+)

Data-integrity expectations across the record lifecycle.

WHO TRS No. 996 Annex 5

Guidance on good data and record-management practices.

Which workflow should Verixa map first?

Select one current quality process. We will show how Verixa could support it, where AI assists, where human decisions remain mandatory, and what validation responsibilities stay with your organization.