This is a ready-to-use form that captures the single anchor a digital twin’s whole validation is sized from: what the twin outputs, what action that output triggers, who owns the consequence, the risk class, and the boundary of validity. If this form is filled cleanly, the validation plan can be sized correctly; if it cannot be filled cleanly, the scope is not defined and everything downstream is mis-sized. Complete one form per twin per intended use. Replace every <<FILL: ...>> placeholder with your own specifics. A filled specimen follows. Verify each cited standard against the current source before you rely on it.
Form control
| Field | Entry |
|---|---|
| Form title | Digital Twin Intended-Use and Risk Classification |
| Document number | <<FILL: FORM-ID, e.g. FRM-TWIN-002>> |
| Version | <<FILL: version>> |
| Twin name / ID | <<FILL: TWIN NAME / ID>> |
| Physical asset bound to | <<FILL: specific asset>> |
| Model version | <<FILL>> |
| Prepared by / date | <<FILL>> |
1. Intended-use statement
One sentence: the output, the action it triggers, and the accountable role.
<<FILL: The twin estimates ___ ; the estimate feeds ___ ; ___ (named role) confirms or acts and owns the consequence.>>
If you cannot write this sentence cleanly, stop and define the use before proceeding.
2. Output and decision
| Field | Entry |
|---|---|
| What the twin outputs | <<FILL: the variable and its units>> |
| How the output is used | <<FILL: the action or recommendation it feeds>> |
| Accountable role for the decision | <<FILL: the named role, not the twin>> |
| Is there a conventional measurement of the same variable? | <<FILL: Yes/No; if Yes, does it still run?>> |
| Is the twin on the critical release path? | <<FILL: Yes/No>> |
3. Risk classification (ICH Q9(R1))
Select one use pattern and record the rationale.
| Use pattern | Selected? | GxP weight | Rationale |
|---|---|---|---|
| Development advisory | <<FILL>> | Low | <<FILL>> |
| Scale-up prediction | <<FILL>> | Medium | <<FILL>> |
| Advisory control | <<FILL>> | High | <<FILL>> |
| Closed-loop control | <<FILL>> | Highest | <<FILL>> |
| Commercial monitoring | <<FILL>> | Medium to high | <<FILL>> |
Assigned risk class: <<FILL>>. Consequence of the twin being wrong: <<FILL: what lands on product quality or the patient>>.
4. Model type and the draft Annex 22 check
| Field | Entry |
|---|---|
| Model family | <<FILL: mechanistic / data-driven / hybrid>> |
| Is the data-driven component locked for this GxP use? | <<FILL: Yes/No>> |
| Does the model self-update on live data in production? | <<FILL: Yes/No>> |
| Static/deterministic for the intended use? | <<FILL: Yes/No, with reasoning>> |
The draft EU Annex 22 (not in force) points critical GMP applications toward static, deterministic models and pushes continuously learning models to non-critical uses with human oversight. For a critical use, lock the data-driven component and route changes through change control so the twin reads as static and deterministic. Record the reasoning here.
5. Boundary of validity (planned)
| Dimension | Intended validated range |
|---|---|
| Inputs | <<FILL>> |
| Scale | <<FILL>> |
| Product(s) | <<FILL>> |
| Process conditions | <<FILL>> |
6. Human oversight
| Field | Entry |
|---|---|
| Who stands between the twin and the action | <<FILL>> |
| For closed-loop: the deterministic interlock | <<FILL: the engineered limit, validated independently>> |
| How automation bias is watched | <<FILL: e.g. override-rate monitoring>> |
7. Approval
| Role | Name | Signature | Date |
|---|---|---|---|
| Process / System Owner | <<FILL>> | ||
| Data Science | <<FILL>> | ||
| QA | <<FILL>> |
8. References
ICH Q9(R1), Quality Risk Management; ICH Q8; ICH Q10. 21 CFR Part 11; EU GMP Annex 11 (in-force 2011 version); draft Annex 22 on artificial intelligence (7 July 2025, not in force), treated as direction of travel.
Confirm the current version of each reference before issue.
Filled specimen
The following shows the form completed for an example titer soft-sensor twin, so you can see the expected detail. The values are illustrative; replace them with your own.
Intended-use statement: The twin estimates product titer in real time for bioreactor BR-204; the estimate feeds the harvest-timing recommendation; the process engineer confirms or overrides and owns the harvest decision.
| Field | Entry |
|---|---|
| What the twin outputs | Product titer, g/L |
| Accountable role | Process engineer on shift |
| Conventional measurement | Offline titer assay, still runs, is the record of truth |
| On critical release path? | No |
| Risk class | High (advisory control) |
| Model family | Hybrid (mechanistic mass balances + data-driven cell-specific productivity) |
| Data-driven component locked? | Yes, locked at validation; changes via change control |
| Self-updates in production? | No |
| Static/deterministic for this use? | Yes, the model is frozen; same inputs give the same output |
In this example the twin is high risk but advisory, the offline assay remains the record of truth, and the data-driven component is locked so the twin reads as a static, deterministic model consistent with the draft Annex 22 direction. That combination is exactly what makes an advisory-control twin defensible, and it is all visible on one page.
Common inspection findings this form prevents
- A twin whose intended use was never written down, so its validation was mis-sized from the start.
- A risk class asserted with no rationale, the first thing an inspector probes.
- A self-updating model used in a critical decision with no locking, against the direction of the draft Annex 22.
- No named accountable person, so the twin was effectively deciding.
How to adapt this form
- Write the intended-use sentence first; if it will not come out cleanly, the use is not defined yet.
- Select exactly one use pattern and record why, tied to the consequence of error.
- For any critical use, resolve the Annex 22 check by locking the data-driven component.
- Carry the assigned risk class straight into the validation plan as the justification for its depth.
- Confirm every standard in section 8 against the current published version before issue.