Article ·
RAG in regulated environments: compliance is an architecture requirement
In pharma and other regulated sectors, a document assistant that "answers well" is not enough. It has to prove where its answers come from. That is decided in the architecture, not afterwards.
Why isn't a standard RAG enough?
The idea behind RAG (Retrieval-Augmented Generation) is simple: retrieve relevant passages from a document corpus, then ask a language model to answer based on them. For an ordinary internal knowledge base, a standard architecture — chunking, embeddings, vector database, model — quickly gives convincing results.
In a regulated environment, the question is no longer just "is the answer right?", but also: which version of which document does it come from? Was the user allowed to access it? Can the answer be reproduced six months from now, during an audit? A standard RAG cannot answer any of these questions.
What does GxP change for an AI architecture?
The "good practices" grouped under the term GxP (manufacturing, laboratory, clinical, distribution…) require, among other things, data integrity and traceability: knowing who did what, when, based on which information, and being able to prove it. Applied to an AI assistant, this translates into very concrete requirements on the corpus, access, answers and their retention.
That is why, when scoping a document assistant for a pharmaceutical environment, I treated compliance as an architecture requirement on a par with performance.
The five building blocks of an acceptable RAG
1. A controlled, versioned corpus
Only approved documents enter the corpus, with their version, status and effective date. When a procedure is updated, the old version is no longer offered — but it remains identifiable for past answers.
2. Traceable indexing
Every indexed chunk keeps its link to the source document, its version and its position. Without that, you cannot cite the source of an answer precisely.
3. Permission-filtered retrieval
Access rights are filtered at retrieval time, before the model sees anything. A language model must never receive a document the user is not allowed to read.
4. Sourced answers — or no answer
Every answer cites the passages it is based on. If no relevant source is found, the assistant says so rather than filling the gap with general knowledge. In this context, "I don't know" is a correct answer.
5. An audit log
Question, user, retrieved documents with their versions, generated answer, model version: everything is logged. That is what makes it possible to reconstruct an exchange during an audit or an investigation.
Where does the human fit in?
In a regulated environment, the assistant prepares and argues; it does not decide. It speeds up information retrieval, points to relevant passages, proposes a summary — and a qualified professional remains responsible for the decision. The same principle guides the interface: sources must be visible and one click away, not hidden behind the answer.
Where to start?
Not with a "big assistant for the whole company". In a pharmaceutical AI strategy covering R&D, quality, regulatory affairs and data, I favoured one roadmap per domain: a first, well-bounded document scope, identified users, measurable success criteria. Once that foundation — corpus, permissions, traceability — is validated, extending it to other domains becomes an extension, not a new project.
In short
- In regulated environments, compliance is designed into the architecture from the start.
- Versioned corpus, traceable indexing, permission filtering before the model, sourced answers and an audit log are the five essential building blocks.
- The language model is just one stage of the system, and the decision stays human.
- Start with one domain, validate the foundation, then extend.
Go further: my work as an AI architect and the diagram of this architecture.