Upload any compliance document and receive a structured gap assessment report in about 3 minutes. Our AI reviews your document against the scope of the framework you select and typically returns 10 to 20 risk-rated findings, each with its regulatory reference and a specific remediation action.
01
Upload your document
PDF, DOCX, or TXT. SOPs, policies, validation plans, procedures.
02
Select a framework
FDA Part 11, CSA, EU AI Act, ALCOA+, or QMSR/ISO 13485.
FDA 21 CFR Part 11FDA CSA Feb 2026Data Integrity ALCOA+EU AI ActQMSR / ISO 13485
Step 1: Upload & Configure
Select your regulatory framework, then upload the document you want assessed.
Select Framework
FDA CSA (Feb 2026)
FDA 21 CFR Part 11
Data Integrity (ALCOA+)
EU AI Act
QMSR / ISO 13485
Upload Document
↑
Drop your document here or click to upload
PDF, DOCX, or TXT, files up to 25 MB. Up to 80,000 characters of extracted text; you'll see your document's count before you pay.
📄
SOP-QA-006_Software_Validation_v2.1.pdf
387 KB
Ready
Step 2: AI Analysis
The AI reviews your document against the framework you selected. Typical analysis takes about 3 minutes.
·
Reading document...
·
Mapping to the FDA CSA (Feb 2026) framework...
·
Evaluating intended use, process risk, and assurance activities...
·
Generating risk-rated findings...
What's happening: The AI checks your document against the areas the selected framework covers, identifies gaps, and typically returns 10 to 20 findings. Each finding carries its regulatory reference, a risk rating, and a specific remediation action.
Step 3: Your Gap Analysis Report
The report opens with an executive summary, compliance score, and risk distribution.
42Score
MajorOverall Risk Rating
SOP-QA-006 lacks fundamental FDA CSA requirements including intended use determination, risk-based process assessment, and distinction between production vs quality system software. The procedure follows traditional validation without risk categorization or proportionate assurance activities required by the Feb 2026 FDA guidance.
2
Critical
5
Major
3
Minor
2
Observations
Strengths Identified
✓ Procedure acknowledges both Agile and Waterfall methodologies with appropriate lifecycle approaches
✓ Validation plan template attachment provides structured documentation framework
✓ Deviation management process integrated for unresolved bugs (reference to SOP-QA-002)
The score reflects how well the document addresses the selected framework's requirements. Read the score together with the individual findings and their risk ratings.
Detailed Findings
Each finding includes the regulatory clause, current state, gap identified, risk rating, and a specific remediation action referencing your document's sections.
The full report lists these findings; this sample shows three.
FDA CSA Guidance Section V.A.(1) (Identifying the Intended Use)Critical
Software intended use must be clearly documented with distinction between production and quality management system software.
Current State
SOP-QA-006 states validation is for 'final product prior to production release' and 'software relating to services and products' but does not distinguish between production vs QMS software or define intended use categories.
Gap
No documented framework for determining software intended use or categorizing as production vs quality management system software.
Remediation
Add Section 5.1 defining intended use determination criteria and establish categories (production software, QMS software) with examples. Reference FDA CSA guidance categorization framework.
FDA CSA Guidance Section V.A.(2) (Determining the Risk-Based Approach)Critical
Risk assessment must determine high-risk vs not-high-risk processes to establish proportionate assurance activities.
Current State
The procedure applies uniform validation requirements regardless of software risk level, with no mention of risk-based categorization or differentiated assurance activities.
Gap
No risk assessment framework to distinguish high-risk from not-high-risk software processes before determining validation approach.
Remediation
Incorporate risk-based decision tree in Section 6 to assess patient safety impact, data integrity criticality, and product quality factors. Define criteria for high-risk determination per FDA CSA Section V.A.(2).
FDA CSA Guidance Section V.A.(4) (Determining the Appropriate Assurance Activities)Major
High-risk software requires rigorous testing with objective evidence; not-high-risk may use vendor documentation reliance and exploratory approaches.
Current State
SOP-QA-006 mandates validation plans and reports for all software without risk-based tailoring of assurance activities or allowance for simplified approaches for lower-risk software.
Gap
Testing approach is not proportionate to determined risk level; all software follows same validation rigor regardless of risk.
Remediation
Add Section 5.2 establishing tiered assurance activities: Not high process risk allowing vendor documentation review and unscripted testing; High process risk requiring formal validation with objective evidence.
Showing 3 of 12 sample findings (the full report lists all 12 with evidence citations)
Your Deliverable
Every analysis produces a branded, downloadable PDF report suitable for audit documentation and management review.
RegulatoryIQ
AI Gap Analysis Report
Report ID: RIQ-GAP-DEMO-001
March 14, 2026
FDA CSA (Feb 2026) Gap Assessment
Document: SOP-QA-006_Software_Validation_v2.1.pdf
42/100
Score
2
Critical
5
Major
12
Findings
The PDF report includes: cover page with document metadata, executive summary with compliance score, all findings with regulatory citations and remediation actions, strengths identified, regulatory references, and the data privacy disclaimer.
↓ Download PDF ReportRun Another Framework
Instant PDF download: Your PDF report is ready to download as soon as the analysis completes. RegulatoryIQ does not keep a copy of your AI Gap Analysis report, so save the PDF for your records. Need to re-run against a different framework? Each framework run is a separate $79 analysis.
Data Privacy & Security
We built this for regulated industries. Your data handling questions, answered directly.
🔒
Is my document stored on your servers?
No. For an AI Gap Analysis, your document text is extracted in your browser and sent over an encrypted connection to our analysis service. RegulatoryIQ does not store your document text: it is passed to our AI provider, Anthropic, for analysis and is not written to our servers, logs, or any database. Anthropic processes it under its commercial terms; any provider-side retention follows those terms.
🧠
Is my document used to train AI models?
No. Under Anthropic's Commercial Terms, Anthropic may not train models on content submitted through its API, so documents you submit for an AI Gap Analysis are not used for model training. Any retention on Anthropic's side follows those commercial terms.
📈
What data do you collect?
For an AI Gap Analysis, what Stripe requires for payment processing (your email, name, and billing information) and a usage record so that each purchase delivers one report: a one-way hash of the payment reference, the framework, timestamps and run status. RegulatoryIQ does not store the content of your uploaded documents. The PDF report you download is your only deliverable.
🔐
Is the transmission encrypted?
Yes. All data transmission uses TLS 1.2 or later encryption. For an AI Gap Analysis, your document text travels encrypted from your browser to our analysis service and on to our AI provider, Anthropic.
Important: This analysis tool provides AI-assisted preliminary compliance screening. Findings should be reviewed by a qualified regulatory professional. Resolution of identified gaps does not guarantee regulatory compliance, inspection readiness, or favorable regulatory outcomes. This tool does not establish an auditor-client or consulting relationship.
Get Started
Professional-grade gap analysis at a fraction of consulting costs. No login required.
Single Analysis
$79
One document, one framework
✓ Upload a PDF, DOCX, or TXT document (up to 80,000 characters of text)
Start with our audit-ready template packs. Build your SOPs, gap assessments, and compliance documentation, then run them through AI analysis to validate coverage before your next inspection.
Our regulatory team reviews your findings, validates the AI analysis, builds your remediation roadmap, and supports you through closure. 14+ years of hands-on audit experience across FDA, EU MDR, ISO 13485, and ICH GCP.