Independent and not affiliated with the FDA, MHRA, ISPE, PDA, or any agency. Get the appgoutham@madhadi.com
madhadi.comData Integrity & GxP Quality
Browse all topics → Articles Templates & Procedures Learning paths GlossaryScenariosToolsRegulatory ReferencesLearning PathsTopics About Start here
Form Plug-and-play starting point Manufacturing Automation

Form: Digital Twin Intended-Use and Risk Classification

A plug-and-play form that captures the one anchor a digital twin's whole validation is sized from: the intended-use statement, the decision it drives, the accountable role, the ICH Q9(R1) risk class, and the boundary of validity, with a filled specimen.

Document type: Form

Read and copy the template below into your own quality system. It is a generic starting point for your own internal use, provided as is, with no warranty; see the Terms and License. Adopting it does not by itself create compliance.

This is a ready-to-use form that captures the single anchor a digital twin’s whole validation is sized from: what the twin outputs, what action that output triggers, who owns the consequence, the risk class, and the boundary of validity. If this form is filled cleanly, the validation plan can be sized correctly; if it cannot be filled cleanly, the scope is not defined and everything downstream is mis-sized. Complete one form per twin per intended use. Replace every <<FILL: ...>> placeholder with your own specifics. A filled specimen follows. Verify each cited standard against the current source before you rely on it.

Form control

FieldEntry
Form titleDigital Twin Intended-Use and Risk Classification
Document number<<FILL: FORM-ID, e.g. FRM-TWIN-002>>
Version<<FILL: version>>
Twin name / ID<<FILL: TWIN NAME / ID>>
Physical asset bound to<<FILL: specific asset>>
Model version<<FILL>>
Prepared by / date<<FILL>>

1. Intended-use statement

One sentence: the output, the action it triggers, and the accountable role.

<<FILL: The twin estimates ___ ; the estimate feeds ___ ; ___ (named role) confirms or acts and owns the consequence.>>

If you cannot write this sentence cleanly, stop and define the use before proceeding.

2. Output and decision

FieldEntry
What the twin outputs<<FILL: the variable and its units>>
How the output is used<<FILL: the action or recommendation it feeds>>
Accountable role for the decision<<FILL: the named role, not the twin>>
Is there a conventional measurement of the same variable?<<FILL: Yes/No; if Yes, does it still run?>>
Is the twin on the critical release path?<<FILL: Yes/No>>

3. Risk classification (ICH Q9(R1))

Select one use pattern and record the rationale.

Use patternSelected?GxP weightRationale
Development advisory<<FILL>>Low<<FILL>>
Scale-up prediction<<FILL>>Medium<<FILL>>
Advisory control<<FILL>>High<<FILL>>
Closed-loop control<<FILL>>Highest<<FILL>>
Commercial monitoring<<FILL>>Medium to high<<FILL>>

Assigned risk class: <<FILL>>. Consequence of the twin being wrong: <<FILL: what lands on product quality or the patient>>.

4. Model type and the draft Annex 22 check

FieldEntry
Model family<<FILL: mechanistic / data-driven / hybrid>>
Is the data-driven component locked for this GxP use?<<FILL: Yes/No>>
Does the model self-update on live data in production?<<FILL: Yes/No>>
Static/deterministic for the intended use?<<FILL: Yes/No, with reasoning>>

The draft EU Annex 22 (not in force) points critical GMP applications toward static, deterministic models and pushes continuously learning models to non-critical uses with human oversight. For a critical use, lock the data-driven component and route changes through change control so the twin reads as static and deterministic. Record the reasoning here.

5. Boundary of validity (planned)

DimensionIntended validated range
Inputs<<FILL>>
Scale<<FILL>>
Product(s)<<FILL>>
Process conditions<<FILL>>

6. Human oversight

FieldEntry
Who stands between the twin and the action<<FILL>>
For closed-loop: the deterministic interlock<<FILL: the engineered limit, validated independently>>
How automation bias is watched<<FILL: e.g. override-rate monitoring>>

7. Approval

RoleNameSignatureDate
Process / System Owner<<FILL>>
Data Science<<FILL>>
QA<<FILL>>

8. References

ICH Q9(R1), Quality Risk Management; ICH Q8; ICH Q10. 21 CFR Part 11; EU GMP Annex 11 (in-force 2011 version); draft Annex 22 on artificial intelligence (7 July 2025, not in force), treated as direction of travel.

Confirm the current version of each reference before issue.


Filled specimen

The following shows the form completed for an example titer soft-sensor twin, so you can see the expected detail. The values are illustrative; replace them with your own.

Intended-use statement: The twin estimates product titer in real time for bioreactor BR-204; the estimate feeds the harvest-timing recommendation; the process engineer confirms or overrides and owns the harvest decision.

FieldEntry
What the twin outputsProduct titer, g/L
Accountable roleProcess engineer on shift
Conventional measurementOffline titer assay, still runs, is the record of truth
On critical release path?No
Risk classHigh (advisory control)
Model familyHybrid (mechanistic mass balances + data-driven cell-specific productivity)
Data-driven component locked?Yes, locked at validation; changes via change control
Self-updates in production?No
Static/deterministic for this use?Yes, the model is frozen; same inputs give the same output

In this example the twin is high risk but advisory, the offline assay remains the record of truth, and the data-driven component is locked so the twin reads as a static, deterministic model consistent with the draft Annex 22 direction. That combination is exactly what makes an advisory-control twin defensible, and it is all visible on one page.

Common inspection findings this form prevents

  • A twin whose intended use was never written down, so its validation was mis-sized from the start.
  • A risk class asserted with no rationale, the first thing an inspector probes.
  • A self-updating model used in a critical decision with no locking, against the direction of the draft Annex 22.
  • No named accountable person, so the twin was effectively deciding.

How to adapt this form

  1. Write the intended-use sentence first; if it will not come out cleanly, the use is not defined yet.
  2. Select exactly one use pattern and record why, tied to the consequence of error.
  3. For any critical use, resolve the Annex 22 check by locking the data-driven component.
  4. Carry the assigned risk class straight into the validation plan as the justification for its depth.
  5. Confirm every standard in section 8 against the current published version before issue.
Use madhadi.com as an app Full screen, works offline, one tap from your home screen.