Expert Consulting for Your Business Growth
Transform your strategies with our expert consulting services.
Transform your strategies with our expert consulting services.

At SQA llc, our mission is to protect Sports and Active Nutrition brands through:
Regulatory Compliance Consulting can be tailored to investigate specific areas of a brand owner's business:
Supplier Audits
can be tailored to investigate specific areas of a supplier's business:
Supplier Qualification audit:
System Monitoring audit:
"For Cause" audit:
Internal/GAP Audit
Internal and/or GAP audits can be performed at specified intervals, either on-site or remotely.
Internal Auditor and/or cGMP Training Classes
Classes can be either on-site or remote.
We aim to provide tailored solutions that drive efficiency and growth in every project we undertake.
Please reach us at David@SQA-Verify.com if you cannot find an answer to your question.
At SQA LLC, we offer a wide range of consulting services including
The duration of a consulting project varies depending on the scope and complexity of the project. We will work with you to determine a timeline that meets your needs.
Supplier monitoring audits can take 1 day for simple agendas to 2 days in cases of a For-Cause audit.
We have experience working with clients in various industries, including Dietary Supplements, Functional Foods, Private Label, Contract Manufacturers, Holding Warehouses, Distributors, Ingredient, Component and Service Suppliers, Laboratories, Medicated Animal Feed, Pet Treats, x-ray inspection, Lyophilization,
Plastic Injection Molding and Urethane Extrusion.
For use with regulated activities, ChatGPT, OpenAI and the like is not compliant with 21 CFR Part 11 "out-of-the-box" because the standard versions do not meet the strict requirements for data security, validation, and control. Any organization that uses ChatGPT, OpenAI, Scribe and the like must implement its own rigorous controls and validation processes to meet FDA regulations.
While these options are indeed powerful, the regulations do not release you from the responsibility to have the system overseen by a qualified person, usually a Process Controls Qualified Individual (PCQI).
Custom or enterprise versions, typically with and associated Business Associate Agreement (BAA), can be used to build a compliant solution for specific workflows.
Key Challenges for Standard ChatGPT
Standard ChatGPT logs and stores every conversation, including any confidential or
sensitive data users input. The information can then be used to train future AI
models. This makes it unsuitable for handling electronic records in FDA-
regulated activities.
Part 11 requires that any software used for electronic records be properly validated
to ensure accuracy, reliability, and consistent performance. The standard version of
ChatGPT is not developed for this purpose, and a user organization cannot perform
the necessary validation.
Commercial versions of ChatGPT lack the robust, computer-generated audit trails
and specific access controls required by Part 11 to track changes and limit access to
authorized personnel.
Part 11 specifies strict controls for using electronic signatures, including unique IDs
and passwords, that do not exist in the consumer version of ChatGPT.
OpenAI does not automatically sign a Business Associate Agreement (BAA) with
standard users. A BAA is a legal agreement required under HIPPA (and aligned with
Part 11 goals) to ensure a third-party vendor handling protected health information
(PHI) implements required safeguards.
Path to a Compliant Solution
For organizations in regulated industries, creating a compliant solution requires a customized approach that isolates the AI model within a secured, validated environment. Steps include:
Use OpenAI's Enterprise solution or API with BAA. which allows the organization to
control the security and validation process.
Deploy the AI within a secure, controlled environment, such as a private cloud, that
implements strict access controls and encryption.
Formally validate and document the entire system, including all workflows, data
processing, and security measures, to ensure it performs as intended. This will
generally be performed by a PCQI.
Implement processes to de-identify any confidential data before it is sent to the AI,
further reducing he risk of a breach.
Require a human reviewer (PCQI) to verify and/or validate all AI-generated content
before it is used in any formulation context.
Sign up to hear from us.