Watch an experienced CMC reviewer work and a pattern appears. Most of the findings that matter are not about the document on its own. They are comparisons. The batch size in this section does not match the batch record. The specification here differs from the one in the validation report. The study number cited does not exist in the study report.

That has a practical consequence for any review tool, AI or otherwise. A checker that only sees the document under review cannot make those comparisons — not because the check is difficult, but because the other half of the comparison is not in front of it.

Give the review its sources

DnXT’s document review starts by linking a document to the documents it was written from. Once the sources are linked, the numbers in each are compared, and a value that disagrees with its source — 4,000 g in the CTD section against 3,000 g in the batch record — is raised on the exact passage where it appears.

The numeric comparison is done by fixed rules, deliberately. Rules do not make arithmetic mistakes, and they do not invent a discrepancy that is not there. Judgements about meaning — whether “HDPE bottles” and “polycarbonate bottles” describe a real conflict, or whether “no expiry” contradicts “an expiry of two months” — are a different kind of problem, and they stay with reviewers or with a clearly labelled AI step.

Findings are identified by the values in conflict rather than the words around them, so the same discrepancy is raised once — not four times under four slightly different labels. Four flags for one problem is how a tool teaches people to stop reading its output.

The AI writes comments. People decide.

Where AI does help, it has to enter the review on the same footing as everything else. A panel of AI “findings” beside the document is not a review: it has no author, no disposition, no thread, and nobody is obliged to answer it.

So in DnXT, an AI first pass writes ordinary review comments, anchored to the passage they concern. From there, everything that applies to a human comment applies to it: it appears in the review pane, it blocks completion while it is open, a person accepts or rejects it, and it is printed in the reconciliation report.

Attribution is handled carefully. The comment records that a machine wrote it, while the person who ran the pass remains the accountable author. A machine cannot hold accountability, and recording a finding as if a person had made it would misrepresent the record that inspectors read to understand what a human considered.

From comment to tracked change

Suggested replacement text can be edited and accepted directly in the paragraph, with the change tracked. Simple checks run alongside — for example, an abbreviation the document never expands, in a document that expands its others.

External reviewers, safely

Many reviews involve people outside the company: a CRO, a consultant, a subject-matter expert. They are invited by secure link and a one-time code. Each invitation is its own identity, so every comment is attributed to the person who made it, and a review link cannot reach any document content beyond the review it was issued for.

Completion is a signature, not an email

A review completes only when every comment has been dispositioned. The reviewer records an outcome, accepts the meaning of the signature and re-authenticates, and the result is a signed reconciliation report listing every comment, how it was resolved and by whom. “Looks fine” in an email becomes a record that stands up in an inspection.

The principle

AI is useful in regulatory review when it widens what reviewers can see, and harmful when it narrows what they are responsible for. Design for the first: let the machine propose, label everything it proposes, and make sure a person answers every word of it.


DnXT builds eCTD publishing, submission planning, document management and dossier review software for regulatory operations teams. Book a demo to see a document reviewed against its sources, with an AI first pass a reviewer dispositions.