Faculty: Milan Kučera | Code: FDB1331


  • Date:09/22/2026 11:00 AM - 09/22/2026 12:30 PM
  • Location Online Event

 

Description

  • AI-enabled and cloud-based GxP systems increasingly depend on vendors for infrastructure, software development, security, data management, AI models, monitoring, and ongoing change. This creates a practical validation question: which vendor evidence can be leveraged, which claims must be challenged, and which controls or outcomes must be independently verified by the regulated company?

This webinar presents a risk-based approach to vendor assurance that goes beyond collecting certificates and supplier questionnaires. It addresses how to evaluate vendor documentation, audit evidence, validation packages, cloud controls, AI lifecycle information, data governance, service-level commitments, and change-management practices. Particular attention is given to defining the regulated company’s responsibilities under shared-responsibility models and to maintaining sufficient control over GxP-relevant data and decisions.


WHY YOU SHOULD ATTEND:

The traditional supplier-qualification approach is often not sufficient for modern cloud and AI-enabled GxP systems. Vendors may provide extensive evidence, but regulated companies remain accountable for determining whether that evidence is relevant, current, complete, and appropriate for the intended use. Participants will learn how to distinguish evidence that can reasonably be leveraged from evidence that requires challenge or independent verification.

The webinar provides a practical framework for assessing vendor assurance without unnecessarily duplicating vendor activities. It also addresses common gaps such as unclear shared responsibilities, insufficient transparency of AI models and changes, weak data-governance controls, and over-reliance on certifications. The result is a more efficient, defensible, and inspection-ready approach to supplier and system assurance.


LEARNING OBJECTIVES:

  • Apply a risk-based framework for vendor assurance of cloud-based and AI-enabled GxP systems.
  • Distinguish vendor evidence that can be leveraged from evidence that should be challenged or independently verified.
  • Evaluate shared-responsibility models and identify retained responsibilities of the regulated organization.
  • Assess vendor controls for data integrity, security, AI lifecycle management, monitoring, and change control.
  • Define proportionate audit, assessment, and verification activities based on GxP impact and system risk.
  • Recognize common vendor-assurance weaknesses that can create inspection and validation risks.


AREAS COVERED:

  • Vendor assurance in the context of GxP computerized systems and cloud services
  • Shared responsibility: what the vendor controls versus what the regulated company must control
  • Vendor documentation: certificates, audit reports, validation packages, testing evidence, and technical documentation
  • AI-specific assurance: model lifecycle, training data, monitoring, drift, transparency, and change management
  • Data integrity and security controls in cloud environments
  • How to challenge vendor claims and identify evidence gaps
  • Independent verification: when it is necessary and how far it should go
  • Building an inspection-ready vendor assurance package


WHO MUST ATTEND:

  • Quality Assurance Departments
  • Regulatory Affairs Departments
  • IT and Digital Transformation Departments
  • Manufacturing and Operations Departments
  • CSV and CSA Specialists
  • System Owners and Subject Matter Experts
  • Data Integrity Specialists
  • AI Governance Teams
  • Compliance and Audit Managers
  • SaaS and Cloud Service Providers
  • Vendors and Consultants Supporting GxP Systems

Course Director: MILAN KUCERA

Milan Kučera is a senior validation and GxP technology professional focused on computerized systems, laboratory systems, data integrity, cloud environments, and emerging technologies in regulated organizations. His work combines practical validation and compliance expertise with a strong focus on risk-based approaches, quality strategy, and inspection readiness. He has a particular interest in the application of modern technologies, including cloud computing and AI, within regulated GxP environments, with emphasis on governance, data integrity, validation strategy, lifecycle management, and effective human oversight. His approach is to translate complex regulatory and technological expectations into practical controls, evidence, and implementation strategies that can be applied by Quality, IT, validation, and business teams.