What the Site Master File Actually Requires, and What It Does Not

The Site Master File is a short document with an unusual job. It is written by the manufacturer, held inside the manufacturer’s own quality management system, and read almost entirely by regulators. PE 008-4 describes it as containing specific information about the quality management policies and activities of the site, the production and quality control operations carried out there, and any closely integrated operations in adjacent and nearby buildings.1 The same text appears in the European Commission version published under EudraLex Volume 4 Part III,2 in the WHO guidance issued as Annex 14 to Technical Report Series 961,4 and in the Health Canada guidance for drug establishments.3 Four bodies, one template. That consistency is what makes the SMF worth getting right: the same file often serves inspections in several jurisdictions.

The current version is PE 008-4, with an effective date of 1 January 2011. It is listed among the publicly available PIC/S guidance documents.12 The revision history in the document itself shows four versions since 2002, and the 2011 change is described as a simplification of the document and implementation of requirements related to quality risk assessment policy. Nothing has been added since. That matters for the premise of this article, so it is worth stating plainly rather than implying it.

Correcting the premise. The SMF template has no AI-specific expectation. It has no machine learning expectation. It does not use the word model. The only place where software of any kind is addressed directly is subsection 4.2.3, GMP critical computerised systems, whose entire content is one line asking for a description of those systems, excluding equipment-specific programmable logic controllers.1 Subsection 5, Documentation, asks whether the documentation system is electronic or manual. Subsection 6.1 asks for a general statement on process analytical technology applications and the associated computerised systems, if applicable. That is the complete set.

A second correction is worth making because it changes where AI competency content can go. Section 3, Personnel, is two bullets long. It asks for the organization chart to be placed in Appendix 5 and for the number of employees engaged in quality management, production, quality control, storage and distribution. There is no training subsection in the SMF template at all. Training expectations live in EU GMP Chapter 2, not here. So a site that wants to say something about AI competency in the SMF is adding a sentence that the template does not ask for, and should make that sentence earn its place. More on that below.

25-30 Pages, plus appendices, that PE 008-4 sets as the target length for a complete Site Master File1
1 Subsection in the template devoted to computerized systems: 4.2.3, GMP critical computerised systems1
2011 Effective date of PE 008-4, the version still in force and adopted into EudraLex Volume 4 Part III2

The structure you are working inside

Nine numbered sections and eight appendices. General information on the manufacturer. Quality management system, which breaks into the quality management system itself, release procedure of finished products, management of suppliers and contractors, quality risk management, and product quality reviews. Personnel. Premises and equipment, which breaks into premises with subsections for heating, ventilation and air conditioning, water and other utilities, then equipment with subsections for major equipment lists, cleaning and sanitation, and GMP critical computerised systems. Documentation. Production, with type of products, process validation, and material management and warehousing. Quality control. Distribution, complaints, product defects and recalls. Self inspections.

The appendices carry the bulk: the manufacturing authorisation, the dosage form list, the GMP certificate, the contract manufacturer and laboratory list with supply chain flow charts, the organization charts, production area layouts, water system drawings, and the major equipment list.1 Appendix 4 is the one that matters most for AI, and almost nobody thinks of it that way. We will come back to it.

Whether an SMF is even mandatory for you

PE 008-4 is careful here. It says manufacturers should refer to regional and national regulatory requirements to establish whether preparing an SMF is mandatory.1 In practice, EU and PIC/S member authorities routinely request one, and a current SMF is a standard part of the file a competent authority holds on a site. The EMA maintains the compilation of Union procedures on inspections and exchange of information, which forms the basis for national inspectorate procedures across member states,6 and coordinates inspections for centrally authorized products.13 The United States is the notable exception. The FDA does not operate an SMF system, and the Drug Master File is a different instrument entirely: a submission about a specific facility, process, or article used in drug manufacturing, held for reference in applications.9 Do not merge the two documents or reuse text between them.

Why the AI Description Belongs There Anyway

The argument for putting AI content in the SMF is not a compliance argument. There is no clause to cite. The argument is about what the document is for.

The European Commission procedure titled Conduct of inspections of pharmaceutical manufacturers or importers, adopted in May 2023 and in force since 1 January 2024, is explicit about preparation. Before conducting an inspection, the inspector should familiarize themselves with the company to be inspected. The list of what that may include opens with assessment of a site master file, followed by review of products manufactured, previous inspection reports, follow-up actions, the manufacturing authorisation and its variations, recalls, product defects, and sample analyses.5 The SMF is first on that list. It is the document that shapes what the inspector expects to find and, in practice, where they choose to spend their days.

Now consider a site where a convolutional model performs the accept and reject decision on a filled vial line, or where a language model produces a first-pass summary of deviations that a reviewer works from during batch record review. Neither is exotic in 2026. Both change the shape of a GMP decision. If the SMF describes only the automated visual inspection machine and the electronic batch record system, the inspector arrives with an accurate but incomplete map. The gap surfaces on day one, on the floor, in front of the model rather than in front of the documentation. That is the worst possible order.

The framing that works. This is not a new regulatory requirement. It is a description an inspector will ask for anyway, written down before they ask, in the document they read first, in the place a reader would expect to find it. That is the whole case, and it is enough.

The Annex 22 question, handled honestly

Draft Annex 22 on artificial intelligence went out for consultation alongside the draft Annex 11 revision in 2025. It is a draft. There is no final text and no implementation date. Nothing in it is in force, and nothing in it requires an SMF entry. Sites preparing for it should read our companion pieces on what to practice now rather than treat any of it as settled. The point for SMF purposes is narrower: if and when AI expectations do become binding, the site that already has two clean paragraphs in its SMF will update two paragraphs. The site that has nothing will be writing under time pressure while an inspection date approaches.

The certification hook already in the template

There is one place where the existing template invites AI content without any interpretation at all. Subsection 2.1 asks for information on activities for which the site is accredited and certified, including dates and contents of accreditations and the names of accrediting bodies.1 A site certified to ISO/IEC 42001:2023, the AI management system standard published in 2023, has an accreditation that belongs in 2.1 by the plain reading of the existing text. No stretch required. Sites pursuing that certification should plan for the SMF line as part of the closeout.

The Sections That Should Carry AI Content

Five sections carry the weight. Four more take a sentence each when relevant. The table below is the mapping we use, and the sections after it explain what to write in each.

SMF sectionWhat to writeTypical length
2.1 Quality management systemOne sentence stating that AI and machine learning applications are governed under the site quality system, naming the governing procedure. Any AI-related certification under the accreditation bullet.2 to 3 sentences
2.3 Management of suppliers and contractorsHow AI vendors and model providers are qualified. Whether any model is hosted or operated by a third party. Cross-reference to Appendix 4 where a contractor performs a GMP activity using AI.2 to 4 sentences
2.4 Quality risk managementWhether AI applications are assessed under the same quality risk management methodology as other GMP systems, or under a distinct one, and at what level.1 to 2 sentences
3 PersonnelOnly if genuinely distinctive: the function accountable for AI oversight and where it appears on the chart in Appendix 5.1 sentence or nothing
4.2.3 GMP critical computerised systemsThe main entry. Each AI application listed with its intended use, the GMP decision it supports, the level of human oversight, and its validation status.1 short paragraph per application
5 DocumentationWhether AI is used in the creation, review, or approval of GMP records, and how records generated with AI assistance are identified.2 to 3 sentences
6.1 Type of productsOnly where a model forms part of a process analytical technology application, which 6.1 already asks about.1 sentence
7 Quality controlOnly where a model performs or supports a QC test or inspection decision, described as part of the QC activity.1 sentence
9 Self inspectionsWhether AI applications are included in the self-inspection scope and selection criteria.1 sentence
Appendix 4Any contract manufacturer or laboratory performing an outsourced GMP activity in which AI materially contributes to a decision on your product.Existing list entry, annotated

2.1 Quality management system: the anchor sentence

This is where you establish that AI is inside the quality system rather than beside it. One sentence does the work: applications using artificial intelligence or machine learning that support GMP activities are managed under the site quality management system, with governance defined in a named procedure. The named procedure is the important part. It tells the inspector that a document exists, that it has an identifier, and that they can ask for it. It also stops the SMF from having to explain your governance model, which it has no room to do.

Resist the urge to describe the framework. A sentence that begins with your governance philosophy will grow to a page and add nothing an inspector can act on. If you want a fuller treatment of what that procedure should contain, that belongs in the procedure, not here.

2.3 Management of suppliers and contractors: where most sites are thin

Subsection 2.3 already asks for a brief description of the qualification system for contractors, API manufacturers and other critical material suppliers, and for use of outside scientific, analytical or other technical assistance in relation to manufacture and analysis.1 A vendor supplying a model that makes or supports a GMP decision on your product is technical assistance in relation to manufacture and analysis by any reasonable reading. Most SMFs currently say nothing about it because the vendor qualification narrative was written before models were in scope.

What to write: that AI suppliers and model providers are qualified through the same supplier qualification process as other GMP system suppliers, with any additional assessment steps named; whether any model is hosted by a third party and in what geography; and whether any model is retrained or updated by the supplier rather than by the site. That last point is the one inspectors follow up on, and stating it plainly saves an exchange later.

4.2.3 GMP critical computerised systems: the main entry

This is the natural home. The subsection already asks for a description of GMP critical computerised systems. An AI application supporting a GMP decision is a GMP critical computerized system, and describing it here requires no interpretation of the template at all. It is simply a fuller answer to a question already asked.

The practical approach is to keep the existing 4.2.3 content structured as it is, usually a short list or table of systems, and add the AI applications as entries in the same list with a small number of extra fields. Do not build a separate AI subsection under 4.2 unless the site runs enough applications that a subsection genuinely helps the reader. A site with two applications should list two applications.

5 Documentation: the question nobody expects

Subsection 5 asks for a description of the documentation system and whether it is electronic or manual. In 2026 there is a third question hiding inside that one: is any GMP record created, summarized, reviewed, or triaged with AI assistance, and can a reader tell which records those are? A site using a documentation assistant in batch record review has to answer this eventually. Answering it in the SMF, in two or three sentences, is easier than answering it live.

The content is narrow. State whether AI is used in creating, reviewing or approving GMP records. State how a record produced with AI assistance is identified in the record itself or in the audit trail. State who performs the human review and approval. That is all section 5 has room for, and all it needs.

How Much Detail Belongs in a Document That Goes to Authorities

PE 008-4 sets a target: a site master file should contain adequate information but, as far as possible, not exceed 25 to 30 pages plus appendices. It also states a preference for simple plans, outline drawings or schematic layouts instead of narratives.1 That guidance is the discipline that keeps the SMF useful. An SMF that grows to seventy pages stops being read carefully and starts being skimmed, which defeats the purpose of writing it.

Work backward from the page budget. Nine sections across roughly 27 pages gives about three pages per section, and the sections are not equal: premises and equipment and production take more, self inspections takes a paragraph. AI content across the whole document should be somewhere between half a page and a page and a half, concentrated in 4.2.3. If your AI content approaches three pages, you are writing a governance document inside an inspection preparation document, and the wrong readers will see it.

RIGHT ALTITUDE

Describe, then point

State what the application does, what decision it supports, who oversees it, and its validation status. Then name the document that holds the detail. The SMF is an index with enough context to be readable on its own.

WRONG ALTITUDE

Explain and defend

Describing model architecture, training set composition, performance metrics, or the reasoning behind your validation approach. All of that is legitimate content. None of it belongs in a 27-page document read by a regulator planning an inspection.

RIGHT ALTITUDE

One paragraph per application

Four to six sentences covering intended use, decision role, oversight, validation status, and hosting. Consistent structure across applications so a reader can compare them without re-reading.

WRONG ALTITUDE

One paragraph per model version

Version-level detail belongs in the model registry and change control records. An SMF that names model versions will be out of date within a quarter and will draw questions about why it was not updated.

The test for whether a sentence stays

Ask what an inspector would do with the sentence. If it would change which system they look at, which record they pull, or which person they interview, keep it. If it would only reassure them that you have thought about the topic, remove it. The SMF is a planning document for someone else’s work, not a statement of your position.

This test removes a surprising amount. Statements about your commitment to responsible AI, descriptions of your internal review board’s charter, summaries of the regulatory landscape, and explanations of why your approach is risk-based all fail it. None of them tell an inspector where to go.

Describing Intended Use and Decision Role Without Overclaiming

The single most common drafting failure in this area is not omission. It is a sentence that describes the model as doing more, or less, than it actually does. Both directions create problems. Overclaiming invites scrutiny the application cannot support. Underclaiming reads as evasive when the inspector sees the system in operation and finds it more consequential than the description suggested.

The pattern that holds up is three parts in one or two sentences: what the model produces, what it does not decide, and who decides. Every element is verifiable on the floor, and none of them requires you to characterize the model’s quality.

AvoidWhy it failsWrite instead
The model ensures no defective units are released.An absolute claim no model can support, and one the site will be held to.The model classifies each unit as accept or reject against defect categories defined in the qualification protocol. Rejected units are removed from the batch. A defined sample of accepted units is verified by qualified inspectors.
The system uses advanced AI to optimize quality outcomes.Says nothing an inspector can act on and signals that the writer did not want to be specific.The system applies a trained image classification model to inline camera images to identify particulate and container closure defects.
The assistant reviews batch records.Attributes the review to the tool. Review is a GMP act performed by a person.The assistant produces a draft summary of entries flagged against predefined criteria. The batch record review decision is made and recorded by the qualified reviewer.
The model is validated and fully compliant.Compliant is a conclusion for the inspector to reach, not a claim for the site to assert in an SMF.The application was validated under protocol reference and is subject to periodic review under the site procedure for computerized system periodic review.
Human oversight is maintained at all times.Unfalsifiable, and it collapses the difference between a person approving each output and a person reviewing a monthly trend.Each output is reviewed and approved by a named role before the associated GMP decision is recorded.
The model continuously learns from production data.Almost always inaccurate, and it raises a validated state question the SMF cannot answer.Model parameters are fixed. Retraining is performed only under change control, and no production data updates the deployed model in operation.

Naming the decision, not the technology

Inspectors care about decisions. A useful discipline is to write the decision first and the technology second. Not “we have deployed a vision model, which is used in inspection” but “the accept and reject decision for filled vials on line 3 is made by an automated inspection system incorporating a trained image classification model, with the following human verification step.” The second version tells the reader where the decision lives, and the technology becomes an attribute of the decision rather than the subject of the sentence.

This also makes the SMF entry robust to technology change. If the model is replaced with a different architecture next year, the decision sentence still holds and only the attribute changes.

The word that causes trouble: autonomous. Avoid it. It carries different meanings for a data scientist and an inspector, and neither meaning helps you. If a model output is acted on without a person reviewing that specific output, say exactly that and describe the compensating control. If a person reviews every output, say that. The word autonomous will be read as the former even when you meant something narrower.

Proposed Example Text for Two Cases

The text below is written to be adapted, not copied. Placeholders in square brackets are the site’s own identifiers. Both examples assume the model parameters are fixed in production and that retraining occurs only under change control, which is the configuration most GMP sites operate and the one the draft Annex 22 consultation contemplated.

Case one: a QC visual inspection model

Automated visual inspection is the most developed AI application in sterile manufacturing and the one with the most published practitioner work behind it. A PDA Journal review by Veillon and colleagues gathered industry experience with machine learning applied to the visual inspection of filled injectable drug products and set out points to consider for applying it, including the practice of freezing a trained model so that existing qualification strategies remain applicable.7 A related case study presented through the Product Quality Research Institute covers the same territory from a single implementation.8 That published base is useful when an inspector asks whether your approach is unusual. It is not.

Text for subsection 4.2.3, GMP critical computerised systems

[System name and identifier], automated visual inspection, [line or area]. The accept and reject decision for filled and sealed [container type] on [line] is made by an automated visual inspection system incorporating a trained image classification model. The model classifies each container against the defect categories defined in [qualification protocol reference], covering [for example: particulate, fill level, closure integrity, cosmetic]. Model parameters are fixed in production; no production data updates the deployed model. Rejected containers are segregated and reconciled under [procedure reference]. Accepted containers are subject to [describe the verification step, for example a qualified manual inspection of a defined sample, or an acceptable quality limit inspection] under [procedure reference]. The system was validated under [protocol reference] and is subject to periodic review under [procedure reference]. Performance is monitored through [name the routine check, for example daily challenge set runs using the qualified defect kit], with results reviewed by [role].

That is seven sentences and roughly 150 words. It names the decision, the boundary of the model’s role, the human verification, the validated state, the ongoing monitoring, and the accountable role. An inspector reading it knows to ask for the qualification protocol, the defect kit records, and the reject reconciliation. That is exactly the outcome you want, because those are the records you have.

Supporting sentences elsewhere

  • Section 7, Quality control: one sentence noting that visual inspection of [product types] is performed by an automated system incorporating a trained model, cross-referenced to 4.2.3, so that a reader working through QC activities is not surprised.
  • Subsection 2.3: one sentence naming the supplier of the inspection system and whether model training and updates are performed by the supplier or by the site.
  • Appendix 8: the inspection system already appears in the major equipment list. No change needed beyond making sure the entry is current.

Case two: a documentation assistant used in batch record review

This case is harder to write because the model touches records rather than product, and because the temptation to overclaim the efficiency benefit is strong. Keep the benefit out of the SMF entirely. It is not the reader’s question.

Text for subsection 5, Documentation

Use of AI assistance in GMP record review. [System name and identifier] is used to support review of executed electronic batch records. The application produces a draft summary of entries meeting predefined review criteria defined in [procedure reference], including [for example: out-of-range results, unsigned entries, comment fields requiring assessment]. The application does not perform review, does not approve records, and does not determine batch disposition. The batch record review decision is made and recorded by the qualified reviewer, and the certification decision by the Qualified Person, under [procedure reference]. Records for which AI assistance was used are identified in [state where: the electronic batch record system audit trail, a system-generated attribute on the review record]. The application was assessed under [procedure reference] and is subject to periodic review under [procedure reference].

Text for subsection 4.2.3

[System name and identifier], documentation review assistant. A large language model application integrated with [electronic batch record system] that generates draft summaries of executed batch record entries against predefined criteria to support reviewer work. Model parameters are fixed; the application does not write to the electronic batch record and has read access only. Outputs are advisory and are not GMP records. All review and approval decisions are made and recorded by qualified personnel in [system]. Hosted [on premises / in a validated cloud environment operated by supplier, region]. Validated under [protocol reference].

Three points in that text carry disproportionate weight. Read access only, if it is true, removes a whole line of questioning about record alteration. The statement that outputs are advisory and are not GMP records sets the retention and audit trail expectations correctly. And naming where AI assistance is recorded answers the traceability question before it is asked. Sites that cannot yet make the third statement truthfully should fix that before writing the section, not write around it.

A useful sanity check for both examples. Hand the drafted paragraph to someone who operates the system daily and ask a single question: is every sentence here true on the floor today? Not intended, not planned, not true for the pilot line. True today. The SMF is the one document where an aspirational sentence becomes a finding, because the inspector arrives having read it and expecting it.

Vendors, Cloud Hosting, and Contract Manufacturers

Three arrangements complicate the drafting, and the template handles all three better than most people expect.

A model you did not build

Most GMP AI applications are bought, not built. The SMF entry does not change much, but two additions become necessary. First, name the supplier in 2.3 as part of the existing supplier qualification narrative. Second, state clearly who controls the model. If the supplier can update the model in your environment, say so and name the change control mechanism that governs it. If updates require your acceptance and revalidation, say that instead. This single distinction determines how much of the validated state you actually control, and an inspector will work it out within an hour of arriving. Writing it down first is straightforwardly better.

Avoid describing the model as a black box, even where the supplier will not disclose its architecture. The word invites a follow-up you cannot satisfy. Describe instead what the supplier does provide: performance specifications, qualification support, the defined inputs and outputs, and the change notification commitment in the agreement. Our companion article on vendor risk management for AI-enabled services covers what to negotiate for.

Cloud-hosted models

The SMF has no cloud section, which trips people up. The right home is a hosting clause inside the 4.2.3 entry for each application, plus a line in 2.3 if the hosting provider is separately qualified. State the hosting arrangement, the region or country where processing occurs, and whether the arrangement is covered by an existing qualification of that provider. Two lines. The detailed treatment lives in your supplier qualification file and your data residency assessment, both of which are pointer targets rather than SMF content.

One caution about scope. The SMF describes a site. A cloud-hosted model serving several sites is a corporate system, and each site’s SMF should describe it as used at that site, not reproduce the corporate description. Subsection 2.4 already makes this distinction for quality risk management, asking which activities are performed at corporate level and which locally.1 Use the same framing: state that the application is a corporate system, name the corporate governance, and describe local use and local oversight.

Contract manufacturers and laboratories using AI

This is the case sites most often miss. Appendix 4 already requires a list of contract manufacturers and laboratories with addresses, contact information, and flow charts of the supply chains for those outsourced activities.1 Subsection 2.3 already requires a brief overview of responsibility sharing between contract giver and contract acceptor. If a contract laboratory uses a machine learning model to interpret an analytical result on your product, or a CDMO runs model-assisted inspection on your batches, that is an outsourced GMP activity in which a model contributes to a decision about your material. It belongs in the responsibility sharing description.

What to write is short and specific: whether the technical agreement addresses AI use in the outsourced activity, whether the contract acceptor must notify you of model changes affecting your product, and which party holds validation responsibility. If your technical agreements do not currently address any of this, the honest SMF entry is silent, and the real work is the agreement, not the SMF. Do not write a sentence describing a control you do not have.

The audit question that follows. Once the SMF states that AI use at contract sites is addressed in technical agreements, the natural next request is to see one. Make sure the clause exists in the agreements for the contractors listed in Appendix 4 before the sentence goes in. A sentence that outruns the agreements is a finding waiting for a date.

What Not to Put in a Site Master File

The SMF is a summary document that goes to authorities. Some content is wrong for it because it is too detailed, some because it is commercially sensitive, and some because putting it in writing in this document creates an obligation the site cannot meet. The list below covers all three categories.

Keep out of the SMF:

  • Model architecture and hyperparameters. Layer counts, learning rates, and framework versions belong in the design documentation. They will be out of date, they invite questions the SMF cannot answer, and they do not help anyone plan an inspection.
  • Training data composition and provenance detail. This is real evidence and inspectors do ask for it, but the SMF is the wrong container. Reference the data management documentation instead.
  • Performance metrics. A stated sensitivity or false reject rate in the SMF becomes a commitment the site is measured against, in a document updated annually rather than continuously. Keep metrics in the validation report and the periodic review, where they carry their date and their conditions.
  • Model version numbers. They change. An SMF naming a version that has since been superseded reads as an uncontrolled document.
  • Applications not yet in GMP use. Pilots, proofs of concept, and applications in validation are not part of the site’s current GMP activities. Adding them creates an expectation that the inspector will ask about, and there is nothing to show.
  • Non-GMP AI use. Commercial analytics, HR tools, and administrative assistants are outside the scope PE 008-4 describes. Including them expands the inspection surface for no benefit.
  • Vendor commercial terms and pricing. Never relevant, occasionally damaging.
  • Governance philosophy and position statements. Statements of principle, ethics commitments, and framework summaries do not tell an inspector where to go. If they exist, they belong in the governance procedure.
  • Roadmap and planned deployments. The SMF describes current activities. A roadmap in the SMF is a list of questions for the next inspection.
  • Anything you cannot evidence today. The simplest rule, and the one that prevents most findings.

A note on regulatory documents that do want the detail

Some of the excluded material is genuinely required somewhere. Article 11 of the EU AI Act requires technical documentation for high-risk AI systems drawn up before placing on the market and kept up to date, with content specified in Annex IV.10 That is a different obligation with a different audience, and its high-risk obligations are deferred rather than currently applicable. The NIST generative AI profile, published as NIST AI 600-1, sets out risk management actions for generative systems that many sites use to structure their internal documentation.11 Neither is an SMF input. Keeping these documents separate, with the SMF pointing to them, is what stops the SMF from growing past the point where anyone reads it.

The Supporting Documents the SMF Should Point To

PE 008-4 is built around pointing. The manufacturing authorisation goes in an appendix, the equipment list goes in an appendix, the supply chain flow charts go in an appendix. The body text summarizes and refers. AI content should follow the same habit: a short description in the body, and a named document that holds the detail.

The table below lists what an inspector is likely to ask for after reading an AI entry, and where it should live. Every one of these should exist and be current before the SMF entry names it.

Question the SMF entry provokesDocument that should answer itHow the SMF refers to it
How is AI governed at this site?AI governance procedure or an existing computerized systems procedure extended to cover AINamed in 2.1 by document number
What applications are in GMP use, and at what risk level?Model registry or the computerized systems inventory extended with AI attributesNamed in 4.2.3 as the controlled inventory
How was this application validated?Validation plan, protocol and report; qualification protocol for inspection systemsProtocol reference in the 4.2.3 entry
How was the risk assessed?Quality risk management assessment for the applicationReferenced in 2.4 by methodology, not by individual assessment
What happens when the model changes?Change control procedure, with the AI-specific triggers definedOne clause in the 4.2.3 entry naming the procedure
How do you know it is still performing?Periodic review procedure and the completed reviews; routine monitoring recordsOne clause in the 4.2.3 entry
What happens when it fails?Deviation and CAPA procedures, with AI failure modes addressedUsually no SMF text needed; the existing deviation description covers it
How was the supplier qualified?Supplier qualification file and audit reportCovered by the existing 2.3 qualification narrative
Who is trained, and on what?Training records and role-based curriculaUsually no SMF text; the template has no training subsection
Where is the data processed?Data residency and hosting assessment; supplier agreementHosting clause in the 4.2.3 entry

Building the inventory is the piece most sites are missing, and it is the one that makes everything else possible. Our guide to building an AI model registry covers the attributes worth tracking, and the SMF entry then becomes a summary of a list you already maintain rather than a fresh writing exercise every year.

Keeping the Section Current as Models Change

PE 008-4 sets the maintenance expectation directly. The SMF should be part of the quality management system documentation and kept updated accordingly. It should carry an edition number, the date it becomes effective, and the date by which it must be reviewed. It should be subject to regular review to ensure it is up to date and representative of current activities. And each appendix can have an individual effective date, allowing for independent updating.1

That last clause is the most useful sentence in the document for anyone managing AI content, and it is almost always overlooked. Appendices update independently. If the volatile content is placed in an appendix, the body text stays stable through an annual cycle while the appendix moves at the pace of the technology.

1

Write the body text at a level that does not change

Decision, boundary, oversight role, validated state, monitoring approach. None of those change when a model is retrained on new images or a supplier issues a point release. If your body text changes every quarter, it is written at the wrong level of detail.

2

Put the list in an appendix with its own effective date

Where a site runs several applications, an appendix listing them with intended use, risk classification and validation status can be reissued on its own date without touching the rest of the file. PE 008-4 permits this explicitly, and the compact list is easier for an inspector to use than paragraphs scattered across sections.

3

Add SMF review as a step in AI change control

The trigger list is short: a new application entering GMP use, an application retired, a change in the human oversight arrangement, a change in hosting or supplier, or a change in the GMP decision the application supports. Retraining within the approved envelope is not a trigger. Neither is a version increment. Adding this step to the change control template takes one checkbox and prevents the annual scramble.

4

Check the SMF entry during periodic review

Periodic review of the application already looks at whether the validated state holds. Reading the SMF paragraph at the same time, against what the system now does, takes two minutes and catches the drift between what was written and what is true. Our article on periodic review for AI systems sets out what else that review should cover.

5

Reconcile before every inspection, not after

Whatever the annual review cycle says, read the AI paragraphs against the current model registry when an inspection is scheduled. This is the single highest-value fifteen minutes in the whole process, because the SMF is the document the inspector has already read.

What good maintenance looks like in practice

A site with three GMP AI applications should be able to answer four questions in under a minute: which applications are in GMP use today, which SMF sections describe them, when the SMF text was last verified against reality, and what would trigger an update. If those answers require a search, the maintenance mechanism does not exist yet and the SMF entry will decay. The entry decaying is worse than never having written it, because an inaccurate description in the document the inspector read first is a credibility problem rather than a gap.

Conclusion

The honest position on this topic is the useful one. No regulator requires an AI section in a Site Master File. The template is fifteen years old, it addresses computerized systems in a single line, and nothing about artificial intelligence appears in it. Anyone telling you otherwise has misread the guidance or is repeating something they heard. What is true is narrower and more actionable: the SMF is the first document an inspector reads when preparing, the existing sections already have obvious places for AI content, and a site running models in GMP decisions that says nothing about them in the SMF has chosen to have that conversation in the least favorable setting. Half a page, written once and maintained through change control, changes where the conversation starts.

The wider point is about proportion. Most of the effort in AI compliance work right now goes into building governance frameworks, and comparatively little goes into the two or three paragraphs that a regulator will actually read first. Getting those paragraphs right takes very little time and it is a good test of whether the underlying work is real: if you cannot write six true sentences about what a model does, what it does not decide, and who decides, the governance behind it is not finished. That test is worth running before an inspector runs it for you.

Sakara Digital works with pharma and biotech organizations building the documentation and governance that AI in GxP operations requires. If you are working out how to describe your AI applications to a regulator, or want an independent read on whether your current SMF matches what is happening on the floor, we are happy to have that conversation.

For Further Reading