← AI tools

CMC Risk Engine

Finds schedule and dependency risk before the governance report shows it.

Interactive walkthroughThis is a scripted walkthrough with synthetic data. It shows how the tool works without real program data.

CMC risk engine · Program B (viral vector vaccine) · sample data

Scenario

Select a schedule change to see how the ranking changes.

The engine reads plan dates and status from the schedule. It never sees product quality data.

First to slip: PPQ batches

6 weeks of float remain before the April 2027 PPQ milestone.

PPQ batch 1 depends on the CDMO slot. This handoff has the smallest margin in the plan.

Slip risk by chain

  • PPQ batches · Target Apr 202734%
  • Stability · Target Jun 202727%
  • Tech transfer · Target Jan 202721%
  • Module 3 draft · Target Sep 202716%
Proposed escalation

No escalation yet. Keep PPQ batch 1 on the weekly review while its float is more than four weeks. This item goes to the RAID log. The PM accepts or rejects it.

Why I built it

Late-stage surprises came from analytical release, comparability, PPQ timing, and dependencies that were critical to the filing. RAID logs often showed these risks too late to help. I built this tool to show them earlier.

This tool started from my work at Novavax. See the role →

What it does

  • Shows dependencies and schedule stress in one view.
  • Gives mitigation steps, not only a passive list of risks.
  • Helps you make one-page escalation documents for leadership.
  • It is a tool that you can use again and again, not a one-time analysis.
What goes in
Dependency chains, issue logs, milestone slips, RAID signals, comparability timing, and signs of stress on delivery.
What comes out
Risk summaries, mitigation options, escalation notes, updated scenarios, and one-page documents for intervention decisions.
What it changes
Teams can act before the damage to the timeline is clear in standard reports or in a formal governance review.

How it stays inside the rules

What it is for
The tool ranks schedule and delivery risk across CTM supply, PPQ execution, and regulatory milestone chains. Program management uses the ranks to escalate issues. The tool uses plan and status data, not product quality data.
What it never does
Designed to stay outside the GMP boundary: its intended use is to plan and coordinate work. It gives no input to quality or release decisions. With this use, it is in the category that the FDA draft guidance does not address. That category is operational efficiency that does not affect patient safety, drug quality, or the reliability of study results. If a team used it for a decision that could affect quality, the guidance would apply.
Who decides
Each risk rating is a proposal for the RAID log. The PM and the functional owner make the escalation and mitigation decisions, under the ICH Q9 governance for risk management.
Risk level
Low under FDA's draft AI framework (how much the output influences a decision × how serious that decision is)
Guidance it follows
FDA draft guidance · ICH Q8 to Q14

Where companies can use AI in regulated CMC work →

What already exists

  • Planisware, MS Project: Schedule models, critical path, and resource-constrained dates
  • TrackWise Digital, MasterControl: Quality events: deviations, CAPA, and change control
The gap it targets
Schedule tools model dates, and quality systems model events. On my programs, the risk that made milestones fail was often between them. For example, a comparability result moved a PPQ slot, and the PPQ slot moved a filing date. This demo scores that chain across domains, where RAID logs often only describe the risk.
What it is not
It does not forecast product quality outcomes. It does not replace the ICH Q9 risk assessment that the functional owners do.

Do you build tools like this?

I am glad to compare notes: what worked, what a reviewer did not accept, and where AI should stay out of the decision.