Designing the Human-AI Handoff in a Regulated Workflow
In the previous lesson you learned to map a regulated workflow at step granularity and to place a human handoff at every transition. That map is the skeleton. This lesson builds the muscle: it turns each handoff from a vague gesture, "a human reviews it," into a formal verification gate with a defined object of review, a defined acceptance criterion, a defined record, and a named signatory. The reason this matters is that the word "review" is the most dangerously elastic word in a regulated AI workflow. To a tired co-author it can mean reading the paragraph and nodding. To an FDA Office of New Drugs reviewer reading your audit trail on Day 74, it means something specific and demonstrable, and the gap between those two meanings is where submissions lose credibility. A verification gate is the engineering of that word into something an inspector can see, anchored to 21 CFR Part 11 Subpart C on electronic signatures and to ICH E6(R3) Section 4 on the sponsor's responsibilities, so that "reviewed" stops being an adjective and becomes a logged, attributable, defensible act.
Why "Review" Is the Most Dangerous Word in the Workflow
Every AI-assisted submission carries the word "reviewed" somewhere, on the document, in the cover letter, in the validation plan, and the word does almost no work unless it is defined at the gate. The danger is that human review of AI output degrades in a predictable way the previous lessons explained: the model writes a true claim and an invented one in the same even tone, so a reviewer reading for plausibility passes both, because both are plausible. Fluency-driven review is not review; it is proofreading prose that was engineered to read well. The verification gate exists to forbid plausibility-based review and to require source-based review, where the object of the act is not the sentence but the claim, and the standard is not "does this read right" but "does this reconcile to the source the gate names."
Consider the difference operationally. At an ungated handoff, the writer reads the AI-drafted efficacy paragraph, finds it well written, and advances it. At a gated handoff, the writer is presented with the paragraph and an explicit verification object: every numeric claim must be reconciled to a named TLF cell, every population claim to the analysis-set definition, every cross-reference to the actual target, and the gate does not release until each reconciliation is recorded with a disposition. The first produces a document that says "reviewed" and means nothing. The second produces a document that says "reviewed" and is backed by a row-by-row reconciliation log an inspector can read. Same word, opposite defensibility, and the entire difference is whether the gate defined what review consisted of before the human performed it.
This reframing has a cultural consequence inside a writing team. Once review is gated, the question "did you review it" becomes answerable only by reference to the gate's record, not by the reviewer's recollection. "I read it carefully" is no longer a valid answer; "the reconciliation log for step 7 is complete and signed" is. This is uncomfortable at first, because it removes the comfortable ambiguity that let busy people advance AI output on a feeling. That removal is the point. The FDA-EMA accountability principle and Part 11 Subpart C both demand that a human act be attributable and demonstrable, and a feeling is neither, so the gate is the mechanism that converts the felt sense of having reviewed into the recorded fact of having reconciled.
The Anatomy of a Verification Gate
A verification gate has four named components, and a gate missing any one of them is not a gate. The first is the verification object: the precise thing the human must check, stated as claims to reconcile rather than as "the document." For an AI-ready table-to-narrative step, the object is the set of numeric, population, directional, and structural claims in the paragraph, each paired with its source cell. For an AI-assistive consistency step, the object is the set of discrepancies the AI flagged, each to be adjudicated against the TLF. Naming the object is what prevents the gate from collapsing into plausibility review, because the human cannot check "the paragraph"; they can only check specific claims against specific sources.
The second component is the acceptance criterion: the explicit condition under which the gate releases. "Every numeric claim reconciles to its named source cell with zero unresolved discrepancies" is an acceptance criterion. "Looks good" is not. The criterion must be binary at the level of each claim, reconciles or does not, so that the gate's release is a determinate event rather than a judgment call, and so that a half-verified document cannot slip through on the strength of the verified half. The third component is the record: the durable artifact the gate produces, typically a reconciliation log with one row per claim carrying the claim text, the claim type, the source locator, the disposition, the verifier's identity, and the timestamp. The record is what makes the gate inspectable, and a gate that produces no durable record is, to an auditor, a gate that did not operate.
The fourth component is the signatory: the named human who attests, under an electronic signature meeting Part 11 Subpart C, that the verification object was checked against the acceptance criterion and the record is complete and true. The signatory is not a rubber stamp at the end; the signatory is the person whose name carries the legal and professional weight of the attestation, and who therefore must have actually performed or supervised the reconciliation. These four components, object, criterion, record, signatory, are the irreducible anatomy of a gate, and the discipline of this lesson is to specify all four for every transition in the map you built, so that the abstract handoff becomes a concrete, operable, inspectable control.
What Gets Logged at the Gate
The log is where the gate meets the audit trail, and the contents of the log are not arbitrary; they are determined by the questions an inspector will ask on Day 74. The inspector wants to reconstruct, for any AI-touched claim in the submission, what the AI produced, what source it was checked against, who performed the check, what the outcome was, and when it happened. So the log must carry, per gate event, the AI output under review, the model and version that produced it, the system prompt identity, the sources that were loaded into the context window, the verification object, the disposition of each claim in that object, the named verifier, the signatory, and the timestamps of both the generation and the verification. This is the same metadata set the Level 1 audit-trail lesson introduced for a single run, now extended to a gate that may cover many claims and elevated from a personal note to a controlled record in Veeva Vault QualityDocs.
The disposition field deserves particular attention because it is where the gate earns its keep. A disposition is not "reviewed"; it is one of a small set of determinate outcomes per claim: reconciled to source, corrected against source, flagged and escalated, or rejected and reworked. A claim that the AI generated as a hazard ratio of 0.68, which the verifier checked against the TLF and found to be 0.71, produces a disposition of "corrected against source" with both values recorded, so the audit trail shows not only that verification happened but that it caught and fixed an error. This is the affirmative evidence that the workflow works: an inspector who sees a population of gate events with a healthy rate of "corrected against source" dispositions is looking at proof that the human layer is doing real work, whereas a log with one hundred percent "reconciled, no change" across a large, complex draft is itself a signal that the verification may be perfunctory.
There is a second, subtler thing the log must capture, which is the boundary of AI involvement at prohibited steps. At the transition into the Module 2.5.6 benefit-risk conclusion, the log records that the AI's contribution stopped at the scaffold and that the named author drafted the conclusion, so that the record affirmatively shows the prohibited step was honored. This is the exclusion-boundary record from the previous lesson, now formalized as a logged gate event with its own signatory. Without it, the audit trail is silent on the most sensitive transition in the document, and silence at a prohibited boundary reads, to an inspector, exactly like a violation, because nothing distinguishes "the human authored this" from "we did not log who authored this" except the affirmative record that the gate produces.
Who Signs, and What the Signature Means Under Part 11 Subpart C
21 CFR Part 11 Subpart C governs electronic signatures, and its core demand is that a signature be uniquely attributable to one individual, be linked to the record it signs so it cannot be transferred or repudiated, and carry the meaning of the signing, such as authorship, review, or approval. Applied to a verification gate, this means the signatory's electronic signature is not a convenience; it is a legal attestation that this named person performed or supervised the verification, that the record is complete, and that they accept responsibility for the AI-touched content advancing past the gate. The signature meaning must be explicit, because "signed" is as elastic as "reviewed" unless the record states whether the signature means "I verified this reconciliation," "I approved this for the next step," or "I authored this conclusion," and these are different acts carrying different responsibility.
The choice of signatory is a design decision, not an afterthought, and it follows the step's class. At an AI-ready transformation gate, the signatory is the writer who performed the reconciliation, attesting that every claim traced to source. At an AI-assistive consistency gate, the signatory is the person who adjudicated the flags, attesting that each discrepancy was resolved against the authoritative source. At a prohibited-conclusion gate, the signatory is the named author of the conclusion, attesting that they, not the model, rendered the judgment. A common and costly error is to route all gates to a single senior approver who signs everything at the end, which both overloads that person and, more dangerously, attaches their name to verifications they did not perform, hollowing out the attestation that Part 11 requires to be genuine and undermining the very accountability the signature exists to establish.
ICH E6(R3) Section 4 sharpens this further for the sponsor context. The R3 revision modernized the sponsor's responsibilities around oversight of computerized systems and the integrity of the processes that produce trial records, and it makes the sponsor accountable for ensuring that the systems and the human controls around them are fit for purpose and that data integrity is maintained throughout. A verification gate is precisely the kind of human control E6(R3) Section 4 contemplates: a defined, documented step where the sponsor's named personnel exercise oversight over AI-produced content before it enters the controlled record. Designing the gate so that the right person signs, with the right meaning, against the right object, is how you operationalize the sponsor-oversight obligation that E6(R3) places on you, rather than asserting compliance in a procedure no one follows.
Sizing the Gate to the Step Class
Not every gate is the same weight, and a workflow that treats them identically fails in both directions: it under-protects the dangerous transitions and over-burdens the safe ones until writers begin to defeat the gates to get their work done. The sizing principle follows directly from the three-class model. An AI-ready gate is a complete but bounded reconciliation: every claim is checked, but the universe of claims is finite and the source is fixed, so the gate is thorough yet fast, and its acceptance criterion is binary and mechanical. The risk here is not in the difficulty of any single check but in the temptation to skip checks because the prose looks right, so the gate's design emphasis is on completeness, ensuring no claim advances unreconciled.
An AI-assistive gate is heavier in judgment because the human is not reconciling against a single fixed answer but adjudicating among candidates the AI surfaced, deciding which value or statement is authoritative and recording the rationale. The acceptance criterion here is that every flag is dispositioned and every adjudication is grounded in a named authoritative source, and the record must capture the reasoning, not just the outcome, because an adjudication without recorded rationale is a judgment an inspector cannot evaluate. The design emphasis is on the quality and traceability of the human judgment, because this is the class where over-trust is most likely, the AI's flagged output looking enough like an answer that a hurried human accepts it rather than adjudicating it.
A prohibited-step gate is different in kind rather than degree, because its function is not to verify AI output but to prove that AI did not author the conclusion. Its acceptance criterion is that the conclusion originated with the named author and that AI involvement stopped at the permitted scaffold, and its record is the exclusion-boundary attestation. This gate is lightweight in volume, it covers a single conclusion, but maximal in consequence, because it sits at the most sensitive point in the document, the benefit-risk verdict that the limits-of-reasoning lesson established as a human-only domain. Sizing the three gate types correctly is the operational meaning of the risk-based principle applied to human effort: scrutiny is concentrated where the class demands it, so that the finite attention of skilled humans is spent on the transitions where it changes the outcome.
Failure Modes of a Poorly Designed Gate
A gate can exist on paper and fail in practice, and the failure modes are specific enough to name and design against. The first is the rubber-stamp gate, where the signatory signs without performing the verification, usually because the gate was routed to someone too senior or too distant from the work to do the reconciliation, or because the acceptance criterion was vague enough to satisfy with a glance. The defense is to route the signature to the person who does the work and to make the acceptance criterion binary per claim, so that signing without checking is detectable as a gap between the signed attestation and an empty or implausible reconciliation log. The second is the silent-skip gate, where the gate is bypassed under deadline pressure and the document advances without the record, which is why the gate must be enforced by the records system rather than by discipline, so that advancement is technically impossible without the completed record.
The third failure mode is the meaningless-disposition gate, where every claim is dispositioned "reconciled, no change" regardless of what actually happened, producing a record that is technically complete and substantively false. This is the hardest to detect because the log looks healthy, and the defense is partly statistical, a large complex draft with zero corrections is implausible and should trigger scrutiny, and partly cultural, building a team norm that catching and correcting AI errors at the gate is the visible evidence of competence, not a sign of poor drafting. The fourth is the unowned-conclusion gate, where the prohibited-step exclusion boundary is never recorded, so the audit trail cannot show that a human authored the benefit-risk conclusion, leaving the single most sensitive claim in the document indistinguishable from an AI-authored one. Each of these failure modes is a design defect in the gate, not a personal failing of the reviewer, which means each is fixable by better gate design, and the discipline of this lesson is to design the gate so that the easy path is the compliant path and the non-compliant path is technically blocked.
From Gate to Validated Spec
The verification gates you design here are not the end of the engineering; they are the input to the validation work of the next lesson. A gate with a defined object, criterion, record, and signatory is a specification of how the human control operates, and the IQ/OQ/PQ mindset of the following lesson asks whether that specification is installed correctly, operates as intended, and performs to its acceptance criteria under real workload. The Operational Qualification of an AI workflow tests, among other things, that the gates fire when they should, that advancement is blocked without the record, and that the disposition fields are populated truthfully. The Performance Qualification observes the gates over a real production run and asks whether the human verifiers are catching the errors the workflow exists to catch, which is exactly the disposition-rate signal introduced above.
This is why designing the handoff precedes validating the workflow: you cannot qualify a control you have not specified. A team that jumps to "we validated our AI tool" without first specifying the verification gates has validated the software while leaving the human control, the part that actually carries the regulatory weight, undefined and therefore unqualifiable. The end-to-end Module 2.5 workflow in the next chapter will instantiate these gates at every transition of a real production pipeline, and the audit trail it generates in Veeva Vault QualityDocs is nothing more than the accumulated records of the gates firing in sequence. The gate is the atom; the validated workflow is the molecule; the defensible submission is the organism, and it is built from the bottom up, starting with the precise, four-part specification of what happens when a human takes possession of what the AI produced.
Key Takeaways
- The word "review" is dangerously elastic, and the verification gate is what makes it demonstrable. Gated review forbids plausibility-based reading and requires source-based reconciliation, converting a felt sense of having reviewed into the recorded fact of having reconciled, as Part 11 Subpart C and the accountability principle demand.
- A verification gate has four irreducible components: object, criterion, record, and signatory. The object is the claims to reconcile, the criterion is the binary release condition, the record is the durable reconciliation log, and the signatory is the named human whose Part 11 electronic signature attests the verification actually happened.
- The disposition field is where the gate earns its keep, and "corrected against source" is affirmative evidence the human layer works. A large complex draft logged as one hundred percent "reconciled, no change" is itself a signal of perfunctory review, and the prohibited-step exclusion boundary must be logged or silence reads as violation.
- Route the signature to the person who did the work, with an explicit signature meaning, sized to the step class. ICH E6(R3) Section 4 makes the sponsor accountable for the human controls around computerized systems, and routing all gates to one distant senior approver hollows out the attestation Part 11 requires to be genuine.
- Design the gate so the easy path is the compliant path. Defend against the rubber-stamp, silent-skip, meaningless-disposition, and unowned-conclusion failure modes by enforcing gates in the records system, making acceptance criteria binary per claim, and feeding the resulting specification directly into the IQ/OQ/PQ validation of the next lesson.
Skill.re