AI-assisted GxP Validation in SAP: What decision-makers need to know now
Cloud releases are changing the rules of the game for GxP-regulated SAP environments. Companies must evaluate new features and technical adjustments within ever-shorter time frames—without compromising patient safety, product quality, data integrity, and auditability.
The joint web session led by Eduard Hergenreider (SAP) and Matthias Bothe (DHC) highlighted the key requirements and technologies involved. The focus is not on individual product features, but on the strategic question: How can a recurring release and change process be structured so that it operates quickly, in a risk-based manner, transparently, and scalably?
This post highlights the key takeaways for decision-makers as well as CSV, QA, and IT managers. The technical details and system demonstrations are available in the recording of the web session.
Key Findings at a Glance
- The pressure to act is mounting: For example, with the SAP Digital Manufacturing cloud MES solution, there is a time window of only two weeks between deployment on the Q system and the P system.
- Not every change is relevant: What matters is how it relates to the capabilities that are actually used and to your own validated business processes.
- Automation requires structure: A well-maintained service catalog, comprehensive release documentation, and linked validation objects are essential prerequisites.
- AI supports the assessment: The SAP GxP Release Change Assessment Agent helps with identification, GxP classification, risk analysis, and action planning.
- DHC bridges the gap to traceability: The DHC Smart Validation Accelerator (SVA) uses information from SAP Cloud ALM (Application Lifecycle Management) and the SAP GxP Release Change Assessment Agent to generate structured validation documentation.
- Responsibility remains with humans: AI provides well-founded recommendations and flags uncertainties; the technical decision and approval remain with qualified decision-makers.
- The greatest value comes from integration: Release information, processes, architecture, tests, and evidence must work together within a consistent working model.
The Need for Action: Cloud Releases meet short Validation Cycles
- high release frequency,
- short evaluation and testing periods,
- multiple business and IT roles involved,
- manual assessments that are difficult to compare,
- high demands on justification and auditability.
The crucial Shift in Perspective:
From Product Risk to Process Risk
A robust release assessment begins with a fundamental decision: The validation does not focus on an isolated transaction, a single Fiori element, or a function in isolation from its actual use. Instead, the assessment focuses on the regulated business processes that may be affected by the change.
The V-Model provides an established framework for this within the GAMP-5 context. Requirements, functional and technical specifications, risks, and tests are linked together. This ensures transparency regarding which process requirement was tested, which risk was considered, and what evidence supports the decision.
In practice, this means:
Don’t just ask what has changed in the product. What matters is which validated processes may be affected and what proportionate measures result from this.
This shift in perspective is relevant for management because it makes investments in validation more targeted. Not every product change automatically leads to a complete revalidation. Conversely, a seemingly minor technical change must not be underestimated if it affects a critical process, an interface, or a data flow.
What defines a robust Target Vision
A future-proof GxP release process integrates five information perspectives:
- Product and Release: What has changed?
- Capability and Usage: Which function is affected, and is it used within the company?
- Process and Architecture: Which validated processes, applications, and interfaces depend on it?
- Risk and Regulation: What are the implications for GxP-relevant criteria?
- Evidence and Action: What needs to be tested, documented, approved, or revalidated?
It is precisely this connection that distinguishes a robust impact assessment from a purely technical evaluation of release notes. A GxP impact assessment refers to the structured evaluation of whether and how a change affects a regulated process, a system, or relevant documentation.
The Digital Validation Platform as a Strategic Vision
To make recurring release cycles manageable, information must be consolidated throughout the entire validation process. The toolchain presented in the web session illustrates a possible target state for SAP and GxP-regulated environments:
SAP Cloud ALM as a Central Workspace
SAP Cloud ALM serves as the central hub for application lifecycle management. Requirements, changes, tests, and transports can be consolidated and linked together there. This provides management with a common foundation for status updates, responsibilities, and documentation.
SAP Signavio for the process perspective
Signavio enables the modeling of business processes. This allows the business unit’s process view to be linked to the technical implementation and validation planning. A change is not viewed in isolation but is evaluated within its specific process context.
SAP LeanIX for the architectural perspective
LeanIX supports the representation of enterprise and application architecture. This is particularly important when a validated process encompasses SAP and non-SAP applications, interfaces, or other technical dependencies.
DHC Smart Validation Accelerator for Documentation and Change Management
The DHC Smart Validation Accelerator (SVA) is designed as an extension for SAP Cloud ALM. It uses information already recorded in SAP Cloud ALM to automatically generate structured GxP validation documentation. This may include, among other things:
- User Requirement Specifications
- Functional Specifications
- Configuration Specifications
- Design Specifications
- Test Scripts
The advantage lies not only in automated document generation. Crucially, requirements, specifications, risks, test cases, and change information remain in a traceable context through the changes.
Tricentis Tosca for Automated Testing
The integration of Tricentis Tosca extends the toolchain to include automated test execution. In the scenario described, automated testing at the OQ and PQ levels is supported. The results obtained can then be linked back to the validation documentation.
The SAP GxP Release Change Assessment Agent
The SAP GxP Release Change Assessment Agent supplements the platform with AI-powered evaluation of product changes. It analyzes release information, product and capability mappings, and other technical contexts to support validation teams in prioritization and action planning.
Integration into SAP Activate
The toolchain can be viewed across the SAP Activate phases: from Discover and Prepare through Explore, Realize, and Deploy to Run. Requirements and processes are first described, then implemented, tested, and put into operation. During ongoing operations, the same information base is used to manage releases, changes, and revalidation measures in a controlled manner.
For decision-makers, the distinction between individual tools is less relevant than the question of whether the handoffs between phases function properly. If requirements, processes, risks, architecture, changes, tests, and evidence are stored in separate information
What the SAP GxP Release Change Assessment Agent means in Practice
The SAP GxP Release Change Assessment Agent was developed as a forward-deployed engineering project in collaboration with companies in the life sciences industry. The presentation mentioned Roche, Novartis, AstraZeneca, Sartorius, and Gilead, among others, as participating companies.
Its strategic value lies in the repeatable preparation of release decisions. CSV and QA managers receive support in identifying changes relevant to their specific usage context, classifying GxP-related risks, and deriving a robust action plan from these findings.
The following benefits were cited during the web session:
- a potential reduction in the effort required for impact assessments by 40 to 60 percent,
- a faster adoption of innovations,
- fewer errors due to standardized and supported evaluations.
These figures should be understood as expected targets. The actual benefits depend on the quality of the release information, the maintenance of the capability model, the system context, and integration into the organization’s own quality management system.
The Six Technical Questions behind a robust Assessment
Regardless of the tool used, a GxP impact assessment should answer six questions:
- What has changed?
Changes are recorded from the available release information and assigned to a capability or function. - Is the change relevant to us?
The customer-specific service catalog shows which capabilities are activated, in use, and validated. - Which GxP criteria may be affected?
Factors considered include patient safety, product quality, data integrity, traceability, business continuity, and regulatory compliance. - How high is the risk?
An FMECA can structure failure modes, effects, severity, and the Risk Priority Number. - What action results from this?
The process leads to a consolidated decision regarding document updates, configuration checks, targeted tests, regression tests, or revalidation. - How is the decision documented?
Justification, sources, confidence, evidence, review, and approval must remain traceable. Even the decision “no impact” requires robust documentation.
The AI-supported analysis draws on specific regulatory sources such as 21 CFR Part 11, 21 CFR Part 211, EU Annex 11, ICH Q9, and ICH Q10. If the available information is insufficient, the change will be flagged for mandatory human review. The technical decision and the qualified approval remain
Why the technical context makes a difference
A simple review of the release notes shows what has changed according to the product documentation. However, for a reliable impact assessment, it is also important to consider how this change is technically integrated into the product.
In the SAP approach described, the so-called AI Impact Generator can incorporate information from product code repositories. For example, it considers technical metadata, dependencies between repositories, and relationships to configuration, master data, and other domains. This provides an additional system context for assessing business continuity, data integrity, traceability, and product quality.
The result can be exported as a System Impact Summary in CSV or JSON format and sent to the GxP Change Agent. For decision-makers, it is important to make a distinction here: Code analysis is a specific advantage for manufacturers and not a general requirement that every company must implement on its own. From the customer’s perspective, a robust usage context, a well-maintained capability model, and integration into the company’s own quality-assured process remain crucial.
The Connection between SAP Change Agent and DHC SVA
The Change Agent is only truly effective when its results are incorporated into the customer-specific validation process. This is precisely where the connection to the DHC Smart Validation Accelerator lies.
The technical and functional anchors are the Capability IDs from the Product and Service Catalog. They can appear in the SAP Change Information or the What’s New Viewer, as well as in the validation documentation generated by the SVA. There, they can be linked to user stories, functional specifications, and other validation objects.
This creates a consistent relationship:
Product change → affected capability → customer-specific process → validation objects → testing and evidence
This connection is crucial for targeted, rapid regression testing of updates. It illustrates how a technical change led to a business-oriented assessment and, in turn, to a specific validation measure. This ensures that the system remains in a valid state following changes, in a manner that is audit-proof, with minimal effort.
Why a “no influence” decision must also be documented
A professional impact assessment must not only identify high risks. A well-reasoned determination that a change has no impact on the validated scope should also be documented in a structured manner.
For auditors, it is not only interesting to know which tests were conducted. Equally important is the question of why certain changes did not lead to further actions. A clear record should therefore show:
- which change was considered,
- what process and system context it was based on,
- which criteria were evaluated,
- which sources and facts were used,
- how the risk assessment was conducted,
- who reviewed and approved the decision.
AI-powered support can help ensure that justifications are documented more consistently and completely. Responsibility remains with the designated subject-matter and quality assurance functions.
What's Changing for CSV, QA, and IT Teams
Ein KI-gestützter Bewertungsprozess nimmt den Fachverantwortlichen nicht die GxP-Verantwortung ab. Er verlagert ihre Arbeit auf die Aufgaben, bei denen Erfahrung, Kontextwissen und Entscheidungskompetenz besonders wichtig sind:
- Qualität und Vollständigkeit der Eingabedaten sichern,
- den eigenen Capability- und Nutzungskontext pflegen,
- KI-Ergebnisse fachlich prüfen,
- Ausnahmen und Unsicherheiten bewerten,
- Risiken und Massnahmen verantworten,
- Freigaben und Nachweise steuern.
Das verändert auch die Anforderungen an Governance. Unternehmen sollten vor der Einführung festlegen, wie KI-Ergebnisse geprüft, versioniert, dokumentiert und freigegeben werden. Ebenso wichtig sind klare Rollen, ein nachvollziehbarer Umgang mit Unsicherheit und eine Regelung dafür, wann zwingend ein menschliches Review erforderlich ist.
What Companies should clarify before Implementation
An AI solution alone cannot eliminate structural deficiencies in release management. Before implementing one, companies should therefore answer at least the following questions:
- Is release information complete, clear, and available in a timely manner?
- Is there a well-maintained capability or service catalog?
- Is there documentation of which SAP functions and processes are actually being used?
- Are the validated scope, system architecture, and interfaces linked in a way that is easy to understand?
- Are requirements, specifications, tests, and evidence organized in a consistent structure?
- What regulatory criteria and sources should be included in the assessment?
- Which decisions can an IT/AI assistance system prepare, and which ones must be approved by a subject matter expert?
- How are changes to evaluation logic, prompts, sources, and models controlled?
These questions show that getting started with AI-supported GxP validation is not just a technology project. It is a combination of process design, data quality, CSV methodology, system integration, and change governance.
Conclusion: GxP expertise determines the value of AI
AI can accelerate the evaluation of SAP changes resulting from new releases and customer-driven enhancements. However, it will only have a lasting impact if it is embedded in an operational model that is robust from both a business and regulatory perspective.
The relevant added value for decision-makers therefore lies in three points:
- Prioritization: Relevant changes are filtered out of the total set more quickly.
- Consistency: Evaluations, justifications, and actions follow a clear line of reasoning.
- Traceability: The chain—from product changes through capability, process, and risk to testing, evidence, and approval—remains visible.
To this end, DHC combines GxP and CSV expertise with SAP know-how, an understanding of processes, and the practical implementation of digital validation processes. The DHC Smart Validation Accelerator is one component of a broader vision: integrated, risk-based, and audit-ready validation.
The key message of the joint SAP-DHC web session is therefore: AI does not replace a GxP organization. It can make a well-structured GxP organization faster, more consistent, and more scalable.
AI-driven GxP Validation for SAP
How SAP and DHC accelerate GxP Impact Assessments with AI, Cloud ALM, SVA, and risk-based Validation.
Frequently asked Questions about AI-based GxP Validation in SAP (FAQ)
What is the SAP GxP Release Change Assessment Agent?
How does AI support GxP impact assessments?
The AI can consolidate release information, capability mappings, system context, and regulatory sources. Based on this information, it supports the evaluation of GxP criteria, risk assessment, and the development of an action plan. The results must be reviewed and approved by subject matter experts.
Does the change agent replace the technical validation decision?
No. The change agent assists with analysis and preparation. The technical evaluation, the decision on necessary measures, and the authorized approval remain the responsibility of the designated individuals.
What role does the DHC Smart Validation Accelerator play?
The DHC Smart Validation Accelerator uses information from SAP Cloud ALM to generate structured validation documentation—such as requirements, specifications, and test scripts—and link them together. This enables a traceable representation of the relationship between changes, processes, risks, tests, and evidence.
The SAP GxP Release Change Assessment Agent provides in-depth information from the SAP backend regarding the changes, which are then linked to the customer-specific validation documentation in DHC SVA. This significantly reduces the time and manual effort required for regression testing,
What regulatory principles are taken into account in the approach described?
In der Websession wurden unter anderem 21 CFR Part 11, 21 CFR Part 211, EU Annex 11 sowie ICH Q9 und ICH Q10 als regulatorische Grundlagen für die Analyse genannt.