Tareef Roustom
Principal, Pharmasight
Tareef Roustom is the principal of Pharmasight. He has spent his career building AI systems that run inside regulated pharmaceutical operations, for organisations including Johnson & Johnson, Boehringer Ingelheim, Gilead, Novo Nordisk, Sanofi, Merck and Chiesi.
His shipped work includes a clinical trial document processing and management platform integrated with Veeva Vault, where CDMO document dumps are classified into a sponsor eTMF through an architecture that lets eTMF owners change the taxonomy in real time without retraining a model; a marketing asset creation and management platform with MLR review built in; a dedicated MLR review orchestration and triage platform; and the Merck Life Science Marketing Hub, which researches accounts, recommends products, and builds the commercial package and outreach strategy behind them.
He writes here about what actually happens between an AI pilot and a validated, inspected, production system — the part the vendor deck skips.
What the experience actually covers.
E-E-A-T is a search engine's phrase for something a pharma buyer works out in ten minutes anyway. Here is the version that survives that conversation, including the parts that are outside the remit.
- Regulatory frameworks worked in
- GCP, GMP, GVP and GLP; GAMP 5 Second Edition; EU GMP Annex 11 and the draft Annex 22; 21 CFR Part 11; ICH E6(R3), Q9(R1) and Q10; EU AI Act obligations as they land on regulated systems.
- Platforms integrated with
- Veeva Vault (Clinical, PromoMats, QualityDocs), eTMF and eCTD estates, eQMS and LIMS, CRM and marketing stacks, and the document repositories that sit behind all of them.
- Where the systems ran
- Johnson & Johnson, Boehringer Ingelheim, Gilead, Novo Nordisk, Sanofi, Merck and Chiesi — top-20 pharma through to mid-size biotech, in clinical operations, quality, regulatory and commercial.
- What is deliberately not claimed
- No published clinical outcomes, no peer-reviewed pharmacology, no legal or regulatory advice. Where an article states a regulatory position it names the instrument and the date, and where a claim cannot be sourced it says so.
How the writing here is made.
Regulatory guidance moves. An article that does not say when it was right is a liability in this industry, so every one of them does.
- 01
Every regulatory claim names its instrument
Not "the regulator requires" but which annex, which clause, which guidance, and whether the text is binding, draft or expected. The distinction between a binding 2011 Annex 11 and a draft revision under consultation is exactly the kind of thing a QA director tests a consultant on.
- 02
Every article carries the date its position was current
Shown in the document control strip at the top of the page and in the margin. When a guidance finalises, the article is revised and the revision date changes — it is not quietly edited.
- 03
Numbers are sourced or they are not used
Widely-quoted industry statistics are often circular citations back to a single unsourced slide. Where that is true, the article says so instead of repeating the number.
- 04
Nothing here is generated and published unread
AI is used in the research and drafting, as it is in the client work. The judgement, the sourcing and the position are the author’s, and the author is named on every page.
Latest from Pharmasight.
- 01How to Validate a Non-Deterministic LLM Without Pretending It Is DeterministicBounded nondeterminism, guardrail qualification, abstention thresholds and revalidation triggers, a complete test strategy for generative systems inside regulated pharmaceutical processes.
- 02Named Data Ownership Beats Any AgentOne organisation in fifty-nine is ready; the variable predicting regulatory operations performance is accountability for data, not artificial intelligence. today
- 03Review by Exception After Twenty Years of TryingPfizer struggled two decades with electronic batch records; costs per site fell eighty percent once leadership changed, not the software.
- 04Your Validated Model Has a Retirement DateCloud platforms silently upgrade model deployments unless disabled, turning one deployment property into a genuine change-control obligation for validated systems.
- 05Which GCP Clause Actually Governs Your Clinical AI ModelFull-text analysis shows the guideline never names artificial intelligence, so governance assembles from computerised systems, oversight and monitoring clauses instead.
- 06Human Oversight Is a Control You Qualify, Not a Sentence in Your Risk AssessmentReduced model testing is bought with monitored operator performance; most oversight designs never budget for that second expensive operating obligation.
- 07Costing a Health Authority Query Response Before You Automate ItQuery volume, hours per response, Module 3 hotspots: building a credible automation business case from measured baselines, not vendor claims.
- 08Validating AI Under GxP in 2026: What Binds You, What Is Draft, What Inspectors CiteA regulator-sourced map of every rule touching AI in GxP today, separating binding text from draft guidance with inspection evidence.