Build1 publisher3 min readPublished
A 90-day inactivity timer closed a CAPA that never got a root cause review
A quality engineer writing on dev.to argues that ISO 13485, EU MDR and FDA guidance all assume an accountable human without listing the approvals an AI may not make, so each site has to write that list itself.
The Engineer · Build desk

What happened
- A quality engineer writing on dev.to says he watched an AI approve a CAPA closure and could find no written record of who had decided the AI was allowed to make that call.
- That team caught one corrective action closed without a root cause review and spent two days reconstructing the record and changing the workflow.
- The post sorts boundaries into three kinds: enforced by the platform, written into an SOP only, or merely implied because the AI cannot yet perform the action.
Compiled by The EngineerSomething wrong?How this is made
Why it matters
- exposure The liability sits in the record, not in the decision quality: an auto-closed CAPA presents to an auditor as closed with nobody's name against the adequacy determination.
- decision Anyone buying an eQMS with AI features now has to ask which state transitions the software itself refuses, and test the answer, because an SOP boundary is only as strong as staff compliance.
- constraint A boundary that exists only because the AI lacks the capability cannot be relied on across upgrades, since a vendor release can add the capability without touching your procedures.
- precedent With the practice documented only in practitioner accounts and undated vendor pages, the first enumerated list of AI-prohibited approvals to reach an audit file will set the shape others copy.
The near-miss in the post turned on a timer. A peer at a smaller Class I shop in Europe told the author that their eQMS auto-closed low-risk CAPAs after 90 days of no activity, and it ran that way for months [11]. Then a legitimate corrective action turned up closed with no formal root cause review, because the system treated the silence as acceptance [12]. The team caught it and spent two days reconstructing the record and updating the workflow [13]. The AI in that story did not have to be very clever to close the file.
ISO 13485:2016 clause 8.5.2 wants to see that corrective action adequacy was reviewed, the post notes [15]. An inactivity rule produces a closed state and no reviewer. Had a notified body audited during that window, the author writes, the CAPA would have shown as closed with no human sign-off [14].
The three-way split the post draws is the part worth copying [9]. Platform-enforced means the software refuses the state transition. SOP-enforced means you wrote the rule and the software expects you to keep it. Implied means the AI cannot do it yet, so nobody asks. The author calls that third case "a gap waiting to surface" [10].
Which one you have is testable, and the test is cheap. In a validation instance, sign in as whatever identity the AI features run under and try to close a CAPA. Capture what happens. If nothing stops you, the boundary lives in your SOP and nowhere else.
For vendor-side boundaries the post offers one example. The author writes that qmsWrapper has documented its AI blocking on CAPA closure, reportability, risk acceptability and regulated submissions [7], which is four decision types [8]. At his own site, Class II, about 200 people, running Greenlight Guru, the AI features are advisory: flagging possible nonconformities from complaint text, suggesting CAPA linkages, drafting risk matrix summaries [5]. Closing a CAPA requires a named human in the approval chain, and that is written into the SOP [6].
The post carries no notified body finding, no reproduced clause text and no vendor document [19]. The qmsWrapper list is secondhand and the auto-close story comes from an unnamed peer at an unnamed company [19]. The regulatory reading is one practitioner's: that ISO 13485:2016 covers management responsibility, that EU MDR Article 2 (46) defines human oversight in terms implying someone is accountable, that FDA's AI/ML software guidance keeps returning to intended use and meaningful human control, and that none of them hands you a list of AI-forbidden tasks [4].
His own rule is two sentences. "AI can recommend. Humans must approve", he wrote [17]. He also wrote that "The line is only as good as the evidence that someone drew it and the system respects it" [16], and he expects the EU AI Act and ISO 42001 to formalise the question over time [18].
What to watch
- Whether Greenlight Guru or qmsWrapper publish a customer-citable list of workflow states their AI cannot move, with the enforcement point named.
- Whether ISO 42001 or the EU AI Act produces an enumerated set of automated approvals that a medical device QMS may not delegate.
- Any notified body finding that turns on a CAPA record closed by an automated rule with no human sign-off.