Home · Custom software · Pharmaceutical

Custom software and AI for pharma: built to be validated from day one

In a regulated environment, software isn't judged by what it does but by what it can prove it did. This is how a system is designed to survive an inspection from the first day, and what changes now that AI is getting its own rules in the GMP framework.

Nexus team · 7 min read

Why generic software clashes with GMP

Generic tools are built for flexibility; GMP demands control. Every change has to be traceable, every critical record attributable, every electronic signature bound to its record. When a laboratory or plant bends a generic tool to fit, the gap is filled with paper, spreadsheets and procedures that someone has to remember — which is exactly what an inspector looks for.

The framework that shapes any system

Computerised system validation: what's yours and what's ours

Computerised system validation (CSV) is the documented process that shows a system does what was specified, reproducibly, throughout its life cycle. Annex 11's principle is short: the application is validated and the IT infrastructure is qualified. GAMP 5, from ISPE, is the reference guide most quality departments use to scale that effort by risk; bespoke applications are the category that demands the most documentation, precisely because no external vendor answers for them.

Validation is the manufacturer's responsibility and your quality department runs it, with its own procedure. What we deliver is what that procedure needs: numbered and traceable user requirements, functional and design specifications, tests documented against every requirement with deviations recorded, change control with separate environments, and an audit trail born in the data model rather than bolted on.

Where a custom system fits in a laboratory or plant

Between the ERP and the shop floor: batch records, material flows, equipment data, deviations and CAPA workflows, or the integration that stops people retyping data from one validated system into another. And, as Annex 22 matures, AI used where it can be governed: clear intended use, measured performance and a human in the loop. Our industrial side is described in PLC, MES and ERP integration.

Why owning the code matters here

You have to be able to show exactly what the system running in your plant does, audit it when asked and keep it running even if the supplier disappears. Everything we write belongs to the client — code, documentation and data — with no per-user licence. In an inspected sector, that is the difference between answering a finding and waiting for a third party to reply to an email.

What it costs

Build ranges are the same as for any custom project (a first phase for a company of 30–80 employees runs €40,000–120,000); validation documentation, traceable testing and change control are added on top, and depend on the system's criticality and your internal procedure. Designing for validation from the start is what avoids redoing everything at the end.

How we start

Always the same way. Day zero: an NDA signed before you show us anything. Then the Nexus team analyses your operation and delivers a report with the exact changes, prioritised by impact on your P&L. Then you decide. Nexus Elite AI is an engineering boutique in Barcelona: two people, no juniors, no subcontractors, and never more than seven clients at a time. Apply and we reply within 24 business hours; if there is no fit, we tell you in writing.

Frequently asked questions

Can artificial intelligence be used in GMP processes?

Yes, and it is getting its own framework: the draft EU GMP Annex 22 on AI and machine learning asks for a defined intended use, performance metrics, control of training data quality, human review and ongoing oversight under change control.

Do you validate the system, or does our quality department?

Validation is the manufacturer's responsibility and your quality department runs it with its procedure. We build the system to be validatable and deliver the documentation that procedure needs: traceable requirements, specifications, tests against every requirement, change control and an audit trail from the data model.

What is the difference between Annex 11 and 21 CFR Part 11?

Annex 11 is the EU GMP guidance for computerised systems, covering validation, data integrity, audit trails, signatures and suppliers. 21 CFR Part 11 is the US FDA regulation on when electronic records and signatures are trustworthy and equivalent to paper. A system for both markets is designed against both.

Why does owning the code matter in a regulated environment?

Because you must be able to show what the system does, audit it on request and maintain it even if the supplier disappears. Everything we write belongs to the client: code, documentation and data, with no per-user licence.

7 clients at a time, maximum · Reply within 24 business hours

Apply