Building a 24-Month AI Roadmap for Your Function
A roadmap is not a list of tools you will buy. It is a defensible argument, made to a Chief Regulatory Officer and a Quality Council, about how a regulated function will move from supervised drafting to integrated lifecycle workflows to autonomous-with-oversight, in an order that never outruns its validation posture and never gets ahead of what the FDA-EMA Guiding Principles expect. The function leader who presents a roadmap with twelve vendor logos and a vague "AI everywhere by Q4" has produced a wish, not a plan. The leader who presents three phases, each with a named entry gate, a named exit gate, a named regulatory dependency, and a named rollback condition, has produced something a CRO can fund and an inspector can read. This lesson builds that roadmap, phase by phase, anchored to the readiness audit from the previous lesson and to the EMA jurisdictional implementation workstream whose timing is still to be determined and must therefore be tracked, not assumed. The discipline of the roadmap is that it phases capability against validation, never validation against ambition.
Why Phasing Is the Whole Game
The central insight of a function-level AI roadmap is that the sequence is the strategy. Two functions can buy the same tools, hire the same champions, and end at the same place, and one will pass every inspection along the way while the other generates a Form 483 in month eight, purely because of the order in which they deployed. Phasing matters because each level of AI autonomy demands a level of validation maturity that takes real calendar time to build, and you cannot compress that time by spending money. You can buy a tool in a week; you cannot build a Computer Software Assurance approach, an ongoing performance monitoring capability, and a trained body of practitioners in a week. The roadmap's job is to make the capability curve and the validation curve rise together, so that the function never holds a power it cannot defend.
This is why the roadmap inherits directly from the readiness audit. The weakest dimension in that audit sets the starting phase, and the rate at which that dimension can improve sets the pace between phases. A function gated at validation posture cannot phase into integrated workflows until the validation posture rises, no matter how strong its talent or how clean its data. The roadmap is therefore not a generic three-year template downloaded from a consultancy deck; it is a specific argument about this function's specific constraints. When a CRO asks "why not faster," the answer is never "we are being cautious"; it is "the validation curve cannot rise faster than this without creating an inspection exposure, and here is the dependency that governs it." That answer is what separates a roadmap from a roadmap-shaped slide.
Phase One: Supervised Drafting-Assist (Months 0 to 8)
Phase one deploys AI as a drafting accelerant under heavy, documented human verification, and nothing more. In this phase the AI produces first drafts, consistency checks, and reformatting, and a named human reconciles every factual claim to source before anything enters a regulated artifact. The Module 2.5.4 efficacy section drafted by the tool is treated as a starting point that a writer verifies claim by claim against the final TLF package, exactly as the Level 1 and Level 2 lessons teach. The defining property of phase one is that the human is in the loop on every output, the audit trail captures every run, and no AI output reaches a submission without a documented verification gate. This is the phase where the function builds the muscle of working with AI safely, and it is the phase where most functions should spend the better part of a year, not because the technology is immature but because the organizational habits are.
The entry gate to phase one is a passing readiness audit on the minimum dimensions: a documented process map with defined verification gates, a governed channel to source content, a baseline validation approach with intended-use statements, and a body of practitioners trained to Level 2 competency. The exit gate, the condition that lets the function consider phase two, is evidence: a sustained track record of AI-assisted drafts passing verification, a populated audit trail, demonstrated reductions in time-to-first-draft without quality degradation, and at least one cycle of inspection-style internal review that found the workflow defensible. The work of phase one is not the drafting; the drafting is easy. The work is building the evidence base that makes the next phase fundable and defensible, because a CRO will not authorize integrated workflows on a promise, only on a record.
Phase Two: Integrated Lifecycle Workflows (Months 8 to 18)
Phase two connects the drafting-assist of phase one into multi-step, validated workflows that span a lifecycle, the kind of end-to-end Module 2 production the Level 3 chapters design. Here the AI does not just draft a 2.5.4 in isolation; it participates in a chained workflow from TLF intake through Module 2.7.3 sub-summary drafts to the integrated Module 2.5 draft to a cross-Module consistency check, with the audit trail and verification gates integrated into Veeva Vault QualityDocs and the AI use-log written where the submission requires it. The increase in autonomy is real, and so is the increase in validation rigor required to support it. Each step in the chain now needs its own intended-use statement, its own acceptance criteria, and its own monitoring, because a failure in an early step propagates through the chain, and a fabricated cross-reference can now replicate across modules before a human sees it.
The validation discipline that makes phase two defensible is the IQ/OQ/PQ mindset applied to the workflow rather than to a single tool, paired with the Computer Software Assurance approach that scales rigor to risk under FDA's September 2025 guidance. The entry gate is the exit evidence from phase one plus a workflow-level validation protocol that qualifies the chained process for its intended use, and the function's ongoing performance monitoring must now detect drift across the whole workflow, not just one model. Phase two is also where vendor integration becomes load-bearing: the Certara CoAuthor and Veeva Vault RIM integration moving into production rollouts across sponsors through 2026, and the Veeva Vault RIM AI Agents reaching general availability on the August 2026 Vault release, are the kind of integrated capabilities a phase-two workflow is built around. The rollback condition must be explicit: if monitoring detects performance degradation or an inspection raises a finding, the function reverts the affected step to phase-one supervised drafting until the issue is closed, and the roadmap names that condition in advance so the reversion is a designed control, not a crisis.
Phase Three: Autonomous-With-Oversight (Months 18 to 24 and Beyond)
Phase three is the most misunderstood phase, and the misunderstanding is dangerous, so name it precisely. Autonomous-with-oversight does not mean the AI files the submission. It means that for specific, bounded, lower-risk tasks with strong validation evidence, the human moves from verifying every output to verifying a sample and monitoring the aggregate, with the named author still owning the artifact and the final benefit-risk reasoning still entirely human. The tasks that can responsibly enter phase three are narrow: high-volume, well-structured, repetitive tasks where the validation evidence from phases one and two is overwhelming and the cost of an escaped error is bounded and detectable. A literature-surveillance triage that has run for a year with measured precision and recall, or a formatting and consistency pass with a long clean record, can move to sampled oversight. A Module 2.5.6 benefit-risk integration cannot, because the FDA-EMA principles and the function's own accountability model reserve that judgment for a human, permanently.
The entry gate to phase three is the highest of all: a long, monitored performance record, a PCCP-style change-control framework following the FDA's January 2025 guidance pattern for managing learning AI, acceptance criteria that define when sampled oversight is sufficient and when full verification must resume, and an explicit map of which tasks are eligible and which are categorically excluded. This is also where the EMA jurisdictional implementation workstream becomes a hard dependency rather than a background note. The specific publication dates for EMA's implementation of the Guiding Principles are not yet on the public EMA workplan and must be treated as to-be-determined, which means a roadmap that schedules phase-three autonomous workflows for a fixed date is making a planning error. The correct approach is to make phase-three milestones contingent on tracked regulatory developments, with the roadmap explicitly stating that the function will not advance a task to sampled oversight until both its internal validation evidence and the external regulatory expectation support it. A roadmap that gates phase three on regulatory clarity is defensible; one that assumes a date that does not exist is not.
Naming the Gates, Dependencies, and Rollback Conditions
What turns a phase diagram into a fundable, inspectable roadmap is the explicit naming of three things at every transition: the gate, the dependency, and the rollback. The gate is the evidence-based condition that must be met to advance, and it must be objective, a sustained metric, a passed validation protocol, a documented review, not a feeling that the function is ready. The dependency is the external factor outside the function's control that conditions the advance, most importantly the regulatory developments tracked through the EMA AI Workplan and the finalization of the FDA's May 2025 draft considerations, which remain in the comment-response window. Naming the dependency is what lets the CRO understand why a milestone is contingent rather than fixed, and it protects the function from committing to a date that a regulatory shift can invalidate. A roadmap without named dependencies looks confident and is brittle.
The rollback condition is the part most function leaders omit and inspectors most want to see, because it demonstrates that the function has thought about failure. Every phase transition that increases autonomy must specify, in advance, what observation triggers a return to the prior phase: a drift detection beyond acceptance criteria, an inspection finding, a quality-metric degradation, a vendor change that invalidates the validation. By naming the rollback before it is needed, the function converts a potential crisis into a designed control, and converts the roadmap from a one-way commitment into a managed, reversible progression. This is the language a Quality Council recognizes, because it is the language of change control. A roadmap presented in that language, with gates, dependencies, and rollbacks at every transition, is no longer a strategy slide; it is a governance instrument that the function can be held to and that the function can defend.
Sequencing Tools, Talent, and Validation Together
A roadmap that phases only the technology fails, because technology is the one thing money can buy quickly and therefore the one thing that is never the binding constraint. The roadmap must sequence three streams in parallel: the capability stream (what the AI does at each phase), the talent stream (the champions, practitioners, and leaders who operate and govern it), and the validation stream (the IQ/OQ/PQ, CSA, monitoring, and PCCP machinery that qualifies it). These three streams must rise together, and the roadmap's job is to show them as braided, not stacked. A common failure is to front-load the capability stream, buying integrated tools in month two, while the talent and validation streams lag, leaving the function holding capabilities it cannot operate or defend. The disciplined roadmap instead paces the capability stream to the slower of the talent and validation streams, because the function can only safely use what it can both operate and qualify.
This braiding is also how the roadmap connects to every other Level 4 deliverable. The talent stream is where the change-management and internal-certification work lives, including the identification of the first three to six champions whose enablement makes everything else scale. The validation stream is where the vendor scorecard and the validation framework template do their work, because a tool's validation posture determines how quickly it can move through the phases. The capability stream is where the use-case prioritization, the subject of the next lesson, decides what to deploy first. Presenting the roadmap as three braided streams rather than a tool timeline is what signals to the CRO that the function understands AI deployment as an organizational transformation, not a procurement, and an organizational transformation is the only frame in which a regulated function can adopt AI without putting the sponsor's signature at risk. The roadmap is the spine of the strategy, and the gates, dependencies, and rollbacks are the vertebrae that let it bear weight.
Presenting the Roadmap to the CRO and Quality Council
The final test of a roadmap is whether it survives the room. A CRO and a Quality Council will press on three things, and the roadmap must answer all three before it is asked. First, they will press on pace: why not faster, why not slower, and the answer must be the validation and talent curves and the named regulatory dependencies, not a vague appeal to caution. Second, they will press on risk: what happens when it goes wrong, and the answer must be the named rollback conditions and the monitoring that triggers them, demonstrating that failure is a managed state, not a catastrophe. Third, they will press on value: what does each phase return, and the answer must connect to the metrics the business case is built on, time-to-first-draft, submission cycle time, first-cycle approval rate, framed honestly against the productivity claims the next lessons examine critically.
Present the roadmap as a contingent, governed progression rather than a fixed schedule, because a fixed schedule in a domain with to-be-determined regulatory dependencies is a liability the moment a date slips. Make every milestone conditional on its gate, name every dependency the function is tracking, specify every rollback, and tie the whole progression back to the readiness audit that justified the starting phase. When the CRO understands that the roadmap is built to advance only as fast as the function can defend, and to retreat the moment it cannot, the conversation changes from "is this safe" to "what do we fund to move the gates," which is exactly the conversation the next two lessons, on use-case prioritization and business-case construction, are designed to win. A roadmap that earns that conversation has done its job: it has made the function's AI ambition legible, defensible, and fundable in the same document.
Key Takeaways
- The sequence is the strategy: two functions buying the same tools in a different order can end in the same place, with one passing every inspection and the other generating a Form 483. Phasing matters because each level of autonomy demands a level of validation maturity that takes calendar time to build and cannot be bought quickly. The roadmap makes the capability curve and the validation curve rise together.
- The three phases are supervised drafting-assist, integrated lifecycle workflows, and autonomous-with-oversight, and each transition names a gate, a dependency, and a rollback. The gate is an objective evidence condition; the dependency is an external regulatory factor tracked through the EMA AI Workplan and the FDA draft considerations; the rollback is the pre-named observation that returns a step to the prior phase.
- Autonomous-with-oversight does not mean the AI files the submission. It means sampled verification and aggregate monitoring for narrow, well-validated, bounded-risk tasks, while the named author still owns the artifact and benefit-risk reasoning stays permanently human; a Module 2.5.6 integration is categorically excluded.
- Phase-three milestones must be contingent on tracked regulatory developments, not fixed dates. The EMA jurisdictional implementation timing is to-be-determined, so a roadmap that schedules autonomous workflows for a fixed date is making a planning error; gating phase three on regulatory clarity is what makes it defensible.
- The roadmap braids three streams, capability, talent, and validation, and paces capability to the slower of talent and validation. Front-loading tools while talent and validation lag leaves the function holding powers it cannot operate or defend; presenting the roadmap as braided streams signals to the CRO that AI deployment is an organizational transformation, not a procurement.
Skill.re