Qualitum automates the digital validation lifecycle end to end - from URS through DQ, IQ, OQ, PQ, FAT, SAT and change-control addenda. Every requirement is extracted, traced, evidenced and tested against the original source document, with a confidence score and a citation an auditor can open.
Validation fails audits at the joins - where a requirement is re-typed into a test script, or evidence is pasted without its source. Qualitum removes the joins. Each artefact is generated from the one before it and keeps a live link back to the page it came from.
Drop in the URS, the vendor quotations, mechanical and functional specs, layouts, alarm lists, P&IDs and signed change orders. Qualitum reads each one, identifies what it is, and makes it addressable at chapter and page level.
Why it matters: validation teams lose weeks re-finding the document that justified a decision. Here the library is the evidence base - nothing is cited that is not in it, and nothing in it is invisible to the engine.
| Document | Recognised as | Revision | Pages | Indexed | Used by |
|---|---|---|---|---|---|
| LYO4 - SKAN Isolator - URS Uploaded 12 Jun 2026 · 41 pages | User Requirement Spec | v2.1 | 41 | 247 requirements | Master source |
| CH14.303.A.0239_CO002.pdf | Basic Concept | 26.08.2025 | 24 | Indexed | DQ · 38 refs |
| CH14.303.A.0239_HDS001.pdf | Hardware Design Spec | v1.0 | 52 | Indexed | DQ · IQ · 61 refs |
| CH14.303.A.0239_FS001.pdf | Functional Spec | v1.2 | 88 | Indexed | OQ · 94 refs |
| CH14.303.A.0239_LA002.pdf | Layout drawing | Rev C | 6 | Indexed · OCR | DQ · 12 refs |
| CH14.303.A.0239_AL001.pdf | Alarm list | v1.0 | 19 | Indexed | OQ · 27 refs |
| MS - Mechanical Specification_51906.pdf | Mechanical Spec | v3.0 | 34 | Reading… 68% | - |
| Complete_with_Docusign_Automation_CO.pdf | Signed change order | - | 4 | Indexed | Change control |
Qualitum splits the specification into atomic, testable requirements, assigns a stable ID, and records exactly where each one came from: section, page, and the sentence itself. GxP relevance and criticality are proposed at the same time.
Why it matters: this is the step teams normally do by hand in Word and Excel over several weeks. Doing it once, correctly, with provenance intact, is what makes every later stage automatable.
| URS ID | Requirement | Source section | Page | GxP | Criticality |
|---|---|---|---|---|---|
| U3.3-1 v1.0 | Isolator description - Operator will use gloves, which are integrated in the isolator, and tools, which are inside the isolator, to execute tasks in the aseptic core. | 3.3 General Technical Requirements | 5 | No | Informational |
| U3.3-2 v1.0 | Operating modes - the following operating modes must be foreseen: Production · VHP decontamination (aeration included) · Standby. | 3.3 General Technical Requirements | 5 | Yes | Major |
| U3.3-3 v1.0 | Material transfer - pre-sterilised and not pre-sterilised parts can enter and leave the isolator without affecting the decontaminated status of the chamber. | 3.3 General Technical Requirements | 5 | Yes | Critical |
| U3.3-4 v1.0 | General - all cables and optical fibers shall be passed inside the isolator through gas tight bulkheads. The entire working area within the isolator must be cleanable. | 3.3 General Technical Requirements | 6 | Yes | Critical |
| U3.3-5 v1.0 | Air handling system - air during production and aeration: supply air always from surrounding Zone C area and exhaust in the same classified area. | 3.3 General Technical Requirements | 7 | Yes | Major |
| U3.10-22 v1.0 | The system should automatically generate an audit trail for user actions that create or modify electronic records including electronic signatures. | 3.10 ERES Requirements | 27 | Yes | Critical |
| U3.8-05 v1.0 | All rotating or otherwise moving parts should be correspondingly protected during operation against contact by hand - designed in accordance with EN ISO 13857. | 3.8 Health, Safety and Environment | 16 | No | Major |
The detail panel names the root document, the revision, the chapter and the page, and highlights the exact wording in the original PDF beside it. Nothing is paraphrased silently: if the platform rewrote a sentence to make it testable, both versions are shown.
Why it matters: in an inspection the question is never "what does the system say" - it is "show me where that came from". This panel is the answer, in one click, without leaving the tool.
Each requirement is classified for GxP impact, patient risk, data integrity and detectability. Qualitum proposes the classification with its reasoning, the quality lead confirms or overrides it, and the resulting test strategy - which protocols the requirement will appear in - follows automatically.
Why it matters: risk-based validation is expected by GAMP 5 and by every inspector, but it is usually argued in a spreadsheet nobody can reconstruct later. Here the argument, the decision and the consequence sit on the same record.
Bring a requirement document to a 30-minute working session and watch it get decomposed live.
The traceability matrix runs each requirement against each document in the project and returns the chapters that actually answer it - with chapter number, page and a supporting quote. Where the engine finds several plausible answers, it presents them as candidates rather than guessing.
Why it matters: this is the work that normally takes a senior engineer four to six weeks per system, document by document. Qualitum does the reading; the engineer does the deciding.
| URS ID | Requirement | CO002 · Basic Concept | LA002 · Layout | HDS001 · Hardware Design |
|---|---|---|---|---|
| U3.3-1 | Isolator description - operator will use integrated gloves and internal tools to execute tasks in the aseptic core. |
Awaiting selection7 Key features / legend 7 Key features / legend 12 Concept P&ID |
Awaiting selection3 Layout 3 Layout |
Awaiting selection4 Utility supply table |
| U3.3-2 | Operating modes - production, VHP decontamination (aeration included), standby. |
7 Key features / legend 19 · 114 Production mode normal 15 · 704 Conditioning phase 16 · 708 Aeration 1 phase 9.1 |
No relevant chapter | 6 Control philosophy 8.7 |
| U3.3-3 | Material transfer - pre-sterilised and non pre-sterilised parts enter and leave without affecting decontaminated status. |
Awaiting selection11 Leak test & decontamination options 12 Concept P&ID |
Awaiting selection3 Layout 3 Layout |
9 Transfer systems 6.4⚠ |
| U3.3-4 | All cables and optical fibers passed through gas tight bulkheads; entire working area cleanable. |
No relevant chapter | 3 Layout 8.2 |
12 Penetrations & bulkheads 9.3 |
| U3.3-9 | Glove integrity testing must be possible without breaking the decontaminated state. |
No relevant chapter | No relevant chapter | Gap - no evidence Raise design question to vendor |
Each candidate carries its chapter name, chapter number, supporting quote, page and confidence. The reviewer selects, edits or adds a candidate; the decision, the reviewer and the timestamp go to the audit trail. Confidence is never used to auto-approve a critical requirement.
Why it matters: an automated matrix nobody trusts is worse than none at all. Presenting candidates with evidence turns review into a minute-long confirmation instead of an hour-long search - and keeps a qualified human accountable for the decision.
Load two or more supplier quotations and Qualitum answers the only question that matters: for each of your 247 requirements, does this offer meet it - fully, partially, or not at all? Every verdict carries the supplier's own wording and the page it appears on.
Why it matters: technical bid evaluation is normally a subjective read of two long PDFs. This turns it into a defensible, itemised comparison you can put in front of procurement, quality and the vendor at the same time.
| URS ID | Requirement | Source section | Page | Vendor 1 ▾ | Vendor 2 |
|---|---|---|---|---|---|
| U3.8-05 v1.0 | All rotating or otherwise moving parts should be correspondingly protected during operation against contact by hand - designed in accordance with EN ISO 13857. |
3.8 Health, Safety and Environment | 16 | Partial ⚠ "Transparent safety guard, complete machine protection made of aluminium profiles…" 8.0p.6 |
Partial ⚠ "The guarding is built up in aluminium profiles…" 7.1p.4 |
| U3.8-17 v1.0 | All equipment and installations must be designed in such a way that it is possible to use the LOTOTO (Lock-out / Tag-out / Try-out) system during maintenance. |
3.8 Health, Safety and Environment | 18 | Partial "The system includes a 'lockable main switch'…" 8.4p.11 |
Not addressed Not mentioned in the document. |
| U3.3-38 v1.0 | Machine must be designed for manual feeding and removing of the trays. |
3.3 General Technical | 8 | Partial ⚠ "The products are placed crosswise by a…" 6.2p.9 |
Meets "The machine is a stand-alone manually fed…" 9.5p.3 |
| U3.10-22 v1.0 | The system should automatically generate an audit trail for user actions that create or modify electronic records including electronic signatures. |
3.10 ERES Requirements | 27 | Partial "The data to be stored are: machine…" 6.6p.19 |
Not addressed "Software interface TBD" |
Confidence is not decoration. It reflects how directly the source text answers the requirement, whether the wording is verbatim or inferred, and whether other passages in the same document contradict it. Open the score and the platform highlights the passage in the supplier's own PDF.
Why it matters: reviewers need to know where to spend attention. High-confidence verbatim matches are confirmed in seconds; anything below threshold is routed to a human before it can reach a protocol or a report.
Validation status is normally a monthly slide built by hand. Here it is a live view: how much of the URS is evidenced, how much is tested, where confidence is thin, what is blocking, and who owns the next action.
Why it matters: the head of validation can answer "are we ready for FAT?" with a number and a list rather than an opinion - and can show an inspector that the open items were known and managed.
| U3.3-9 | No design evidence for glove integrity testing | Vendor question · open 6 d |
| U3.10-22 | Audit trail scope partial in both offers | Clarification CL-014 |
| U3.3-3 | Transfer system match below threshold (6.4) | Awaiting reviewer |
| U3.12-08 | Material certificate not in the document set | Document request |
| OQ-114 | Test step edited after approval - re-signature needed | QA signature |
We will run one of your systems end to end - URS through PQ - and show you the evidence pack.
Every approved requirement produces test steps written against its own acceptance criteria, in your company's protocol format. Each step keeps the URS ID, the design evidence it was derived from, and the reason it exists. Steps with no requirement behind them cannot be created.
Why it matters: orphan tests and untested requirements are the two findings inspectors reach for first. When protocols are generated from the traceability matrix, neither can occur - and the drafting week disappears.
| Test ID | Traces to | Test step | Acceptance criteria | Derived from | Status |
|---|---|---|---|---|---|
| OQ-041 | U3.3-2 | Select Production mode at the HMI. Record the mode indicator, differential pressure and air velocity after stabilisation. | Mode indicator reads "Production". Δp ≥ 15 Pa. Air velocity 0.36–0.54 m/s. | CO002 §7 Key features / legend · p.8 HDS001 §6 Control philosophy |
In review |
| OQ-042 | U3.3-2 | Initiate VHP decontamination cycle. Record conditioning, decontamination and aeration phase transitions. | All four phases execute in sequence. H₂O₂ residual < 0.5 ppm at cycle end. | CO002 §15 · 704 Conditioning phase CO002 §16 · 708 Aeration 1 |
In review |
| OQ-114 | U3.10-22 | Create an electronic record as User A. Modify one field. Open the audit trail. | Entry shows user ID, UTC timestamp, previous value and new value. Record is not overwritten. | Risk classification - Critical 21 CFR 11 §11.10(e) |
Approved |
| OQ-115 | U3.10-22 | Attempt to delete an audit trail entry using an administrator account. | Action is refused. Attempt is itself recorded in the audit trail. | Negative test required by criticality rule | Approved |
| OQ-088 | U3.3-4 | Verify all cable and fiber penetrations against the bulkhead schedule; perform a chamber leak test. | Leak rate ≤ 5% of isolator volume at twice operating pressure. | HDS001 §12 Penetrations & bulkheads CO002 §11 Leak test options |
Draft |
Testers record the observed result against the acceptance criteria, attach photographs or instrument printouts, and sign. A failing step raises a deviation on the spot, links it to the requirement, and blocks the protocol from closing until it is resolved or justified.
Why it matters: the gap between a marked-up paper protocol and a final report is where weeks and credibility are lost. Executing in place means the report is already written when the last step is signed.
| Test ID | Acceptance criteria | Observed result | Attachments | Signed | Outcome |
|---|---|---|---|---|---|
| FAT-018 | Δp ≥ 15 Pa in production mode | Δp = 52 Pa, stable over 30 min | Trend export.pdf | J. Meier · 09:41 M. Baškovč · 09:44 | Pass |
| FAT-019 | Air velocity 0.36–0.54 m/s at working height | 0.41 m/s across 9 measurement points | Grid measurement.xlsx 2 photos | J. Meier · 10:12 M. Baškovč · 10:15 | Pass |
| FAT-047 | H₂O₂ residual < 0.5 ppm at cycle end (drying phase excluded) | 0.8 ppm after 4 h aeration; cycle extended to 5 h 20 to reach 0.4 ppm | Sensor log.csv Cycle report.pdf | J. Meier · 14:03 | Deviation DEV-004 |
| FAT-051 | Glove leak test executable without breaking decontaminated state | Not executable - test port not fitted on gloveport 4 | 1 photo | J. Meier · 15:20 | Deviation DEV-005 |
| FAT-052 | Alarm A-114 triggers at Δp < 10 Pa within 5 s | Alarm raised at 3.2 s, logged and acknowledged | Alarm log.pdf | J. Meier · 15:48 M. Baškovč · 15:49 | Pass |
A revised URS clause, a design change, a new supplier revision - Qualitum runs the impact across the whole chain and lists the design evidence, test steps, executed results and signatures affected. Approve the change and the addendum protocol is drafted with only the delta re-tested.
Why it matters: re-validation cost is driven by not knowing the blast radius, so teams re-test everything. Knowing exactly which twelve steps are affected turns a six-week addendum into a three-day one.
Qualitum records who did what, when, from where, and what the value was before and after - including every action taken by the AI engine, named as such. Signatures carry the signer's printed name, the meaning of the signature and the record it applies to, and cannot be transferred or reused.
Why it matters: 21 CFR Part 11 and EU GMP Annex 11 do not care that a system is intelligent; they care that it is attributable, contemporaneous and unalterable. Automation only counts if its own actions are logged like anyone else's.
| Timestamp (UTC) | Actor | Action | Detail |
|---|---|---|---|
| 22.07.2026 08:14:02 | Qualitum engine AI | Requirement extracted | From URS v2.1 §3.3.2 p.5 · confidence 9.1 · verbatim |
| 22.07.2026 08:14:02 | Qualitum engine AI | Criticality proposed | Major · reasoning stored · model+prompt version recorded |
| 22.07.2026 09:31:47 | M. Baškovč Reviewer | Criticality overridden | Major → Critical · rationale: "affects decontaminated state" |
| 22.07.2026 09:32:10 | M. Baškovč Reviewer | Evidence confirmed | CO002 §7 selected from 4 candidates · 3 rejected |
| 04.07.2026 11:02:55 | A. Kern QA | Protocol approved · e-signature | Meaning: "Approved for execution" · OQ v0.3 |
| 22.07.2026 16:44:19 | System | Signature invalidated | Triggered by CC-2026-018 · re-signature required |
Requirement traceability matrix, DQ report, IQ/OQ/PQ protocols and summary reports, deviation log, vendor comparison and clarification list - generated from the live data in Word, Excel or PDF, in the customer's own templates, with citations preserved as footnotes.
Why it matters: the document is still the regulatory deliverable. Qualitum does not ask a quality organisation to change how it files - it removes the two weeks of copying, cross-checking and renumbering that produce the file.
| Deliverable | Format | Template | Last generated | State |
|---|---|---|---|---|
| Requirement Traceability Matrix 247 requirements · 18 documents | Excel · PDF | NVS-QA-TM-04 | 22 Jul · 09:16 | Current |
| Design Qualification Report Includes candidate rationale appendix | Word · PDF/A | NVS-QA-DQ-02 | 18 Jul · 14:02 | Signed |
| OQ Protocol & Summary Report 142 steps · 5 deviations | Word | NVS-QA-OQ-07 | 22 Jul · 16:50 | Regenerate - CC-2026-018 |
| Addendum Protocol - CC-2026-018 Delta only · 9 steps | Word | NVS-QA-AD-01 | - | Ready to draft |
| Vendor comparison & clarifications 2 offers · 31 clarifications | Excel · PDF | Internal | 21 Jul · 11:30 | Current |
| Deviation log 5 open · 12 closed | Excel | NVS-QA-DL-01 | 22 Jul · 17:02 | Current |
| Audit trail extract Full project · 14 812 entries | PDF/A · CSV | - | On demand | Generate |
A working session with a validation lead - no slides, your systems, your questions.
The model is the interchangeable part. What makes validation output defensible is the quality layer around it - the evaluations, guardrails, multi-pass sampling and validated reference data that sit between a language model and a regulated document. That layer is the product.
Nothing reaches a protocol on a single model pass. Each extraction and each match is sampled several times, checked against the source text, scored, and routed to a human where it is thin or where criticality demands it - regardless of score.
Why it matters: this is what separates an assistant from a validated system. It is also what lets Qualitum run inside your own environment, on your choice of model, without your data leaving it.
Same deliverables. Same SOPs. Same inspectors. What changes is that the reading, matching, drafting and reconciling is done by the platform - and every sentence in the file can be traced back to the page it came from.
Weeks of manual requirement extraction, document-by-document evidence hunting, protocol drafting and matrix reconciliation.
Your templates, your approval workflow, your risk methodology, and a qualified human on every decision that matters.
A live status you can defend, a confidence score you can interrogate, and change impact you can see before you commit.