Skip to main content Skip to docs navigation
Benchmark IT Solutions
Industries - Pharma & Life Sciences

Validation is changing.
Your systems should too.

The FDA has moved from documentation-heavy validation to risk-based computer software assurance, and the EU is rewriting Annex 11 around lifecycle, cloud and AI. Benchmark builds, assures and tests the systems that change has to run on, with AI accelerators for artwork, batch records and validation evidence.

For heads of quality, regulatory affairs, validation and manufacturing IT in pharma and life sciences.

Overview

Regulators moved first. Most validation practice has not caught up.

Two things changed for life sciences technology teams in the last eighteen months, and both point the same way.

FDA FINALISED SEP 2025 · UPDATED FEB 2026

Computer Software Assurance

Updated in February 2026 to align with the Quality Management System Regulation, and superseding the relevant section of the 2002 software validation guidance.

  • Risk-proportionate assurance instead of scripted testing of every function
  • Concentrated where patient safety, product quality and data integrity are at stake
  • Critical thinking rather than binder volume
EU CONSULTATION CLOSED OCT 2025 · NOT YET FINAL

Annex 11, Chapter 4 and the new Annex 22

The European Commission and the PIC/S inspectors working group consulted on a rewritten Annex 11, a revised Chapter 4 and a new Annex 22 on artificial intelligence. None has been published as final, so none is yet operative.

  • Supplier oversight, identity and access management
  • Cloud and continuous delivery practice
  • Cybersecurity as a GMP concern
  • Draft Annex 22 would permit only static, locked models in critical applications
The practical consequence
  • The evidence expectation is rising and becoming more technical.

    At the same time, tolerance for a two-year validated release cycle is falling.

  • Adding validation headcount does not resolve that.

    The new expectation is about engineering evidence rather than document count.

Benchmark works at that level.

We build and assure the systems, we automate the testing that keeps them qualified, and we deploy AI where the reviewer keeps the decision.

Who we serve

Segments we work in.

01 Batch records

Quality & Manufacturing Operations

Batch record review, deviation and CAPA handling, release documentation and shop floor systems. The pressure here is cycle time: a record waiting for a reviewer is inventory that cannot ship.

Our work concentrates on review by exception, so quality attention goes to the records that need judgement.
02 Artwork

Regulatory Affairs & Labelling

Artwork, labelling copy, submission content and change control across markets that do not harmonise.

This is where Laibel does the heaviest lifting, comparing artwork against approved content so the reviewer sees differences rather than pages.
03 Validation

Validation & Computerised Systems

The team carrying the computer software assurance transition and the Annex 11 rewrite.

We help move validation from a document exercise to an engineering one: risk-based assurance, automated regression, traceability that is queryable rather than filed.
04 Supply

Commercial, Serialisation & Supply

Serialisation systems built for DSCSA are now permanent infrastructure that has to integrate with everything else.

Product engineering for the data flows between manufacturer, CMO, distributor and market.
Capability pillars

What we do for life sciences organisations.

Pillar 01

Software Product Engineering

We build life sciences applications end to end, from architecture through release. Twenty years of product engineering discipline, applied to systems that have to hold up under inspection.

LaibelBMR/BPRVruuum
02

Software Architectural Assessment

Modernising a qualified system is a sequencing problem before it is a technology problem. We assess the estate, define the target and order the migration so qualification is never broken mid transition. This is also where supplier oversight and access management get designed in rather than retrofitted.

03

AI & Intelligent Automation

Applied AI for the work that consumes the most review effort: artwork comparison, batch record checking, document extraction. Deployed as accelerators, with the model's role bounded and its output reviewable.

04

Quality & Test Automation

This is what makes risk-based assurance practical rather than theoretical. Assurance still needs objective evidence, and automated regression produces it repeatably. FableRun generates and maintains suites so a qualified system can change without re-testing effort blocking the change.

05

Performance Engineering

Manufacturing and lab systems fail at the campaign peak or the month end release run, not on an average day. We engineer for the peak.

06

DevOps & Cloud

Controlled, auditable pipelines. Continuous delivery in a GxP environment is now a design problem rather than a prohibited one, and the change controls still have to be evidenced.

Use cases we have built

Where we have actually built.

Six areas of life sciences where Benchmark has shipped working systems, not slideware.

Packaging artwork and labelling compliance

01

Where we go deepest, and where the product came from

Artwork versus approved copy comparisonRegulatory text checking Braille and barcode verificationMulti-language label review Change control evidenceArtwork approval workflowPrint proof validation

Batch record and quality review

02

The reviewer sees the exceptions, not every page

Batch record completeness checksMissing entry detection Deviation flaggingReview by exception Release documentation assemblyAudit trail generation

Validation and computer software assurance

03

Evidence you can query, not evidence you file

Risk-based assurance planningProtocol and script managementTraceability matrixChange impact assessmentPeriodic review

Regulatory document operations

04

Extract once, reuse across submissions

Document data extractionSubmission content assemblyDossier document handlingStructured content reuse

Release quality for qualified systems

05

Automated evidence is what makes assurance work

Regression suite generationQualified system regressionPerformance and load engineeringCI/CD with change controls

Serialisation and supply integration

06

Compliance infrastructure as a permanent system

Serialisation data handlingTrading partner integrationException managementTraceability reporting
AI accelerators for life sciences

Products built for regulated environments.

artwork_v3.pdf2 flags
reg text
braille!
barcode
languages!
print proof
Laibel
Artwork and label review
Problem

Artwork and label review that is manual, repetitive and unforgiving.

Automated comparison of packaging artwork against approved content, flagging text, regulatory and formatting differences so the reviewer works through exceptions rather than every line. Built to leave a record of what was checked and what was found.

Explore Laibel
BR-2291 · lot 44713 exceptions
! step 14 · missing entry p.7
! step 22 · deviation p.11
! step 38 · signature p.19
214 steps complete ready
BMR/BPR
Batch record review
Problem

Batch record review that holds up product release.

Automated checking of batch and production records for completeness, missing entries and deviations, so quality review starts from a prioritised exception list rather than page one.

Explore BMR/BPR
protocols
reqs traced318
protocols44
open CRs6
periodicdue
impacthours
Vruuum
Validation lifecycle management
Problem

Validation evidence that lives in documents nobody can query.

Validation lifecycle management that keeps protocols, traceability and periodic review in one place, so a change impact assessment takes hours rather than weeks.

Explore Vruuum

Xtractly handles the unstructured regulatory and quality documents that feed these processes, and FableRun generates the automated regression evidence that keeps a qualified system changeable.

Impacts

How we measure ourselves.

99%+

Client retention

30%

Of business from referrals

89%

On schedule deliveries

10%

Under this figure for escaped defects

Before you book

The questions buyers actually ask

Can’t find what you are looking for?

Contact Us

The FDA's Computer Software Assurance guidance is final as of September 2025 and was updated in February 2026 to align with the Quality Management System Regulation. It replaces the relevant section of the 2002 software validation guidance, so the risk-based approach is now the expectation rather than an alternative.

No. The consultation on the rewritten Annex 11, revised Chapter 4 and the new Annex 22 on artificial intelligence closed in October 2025, but none has been published as final. We track the drafts and design against the direction of travel, not against a rule that does not yet exist.

Yes, within bounds. The draft Annex 22 would permit only static, locked models in critical applications, which is exactly how we deploy Laibel and our other accelerators: the model narrows the review, and a person keeps the decision and the record of it.

It produces the objective evidence that risk-based assurance still requires. FableRun generates and maintains regression suites so a qualified system can change without the re-testing effort blocking the release, but the assurance plan and the risk judgement remain yours.

Yes, that is the usual arrangement. We build and automate the systems; your validation and quality teams keep ownership of the assurance strategy and the sign off.

No. We are a software engineering company. We build, assure and automate the systems that validation and regulatory decisions run on, and we do not advise on regulatory strategy or submission content.

A scoped assessment typically runs a few weeks, with a first production increment inside a few weeks after that. Accelerator deployments such as Laibel or BMR/BPR move faster than ground-up builds.
Get started

Start with the review that slows your releases most

Whether that is artwork sign off, batch record review, or a validation approach that has not caught up with computer software assurance, the first conversation is a working session, not a pitch.