03Regulatory

Named Data Ownership Beats Any Agent

The largest regulatory information management benchmark yet found a single organisation genuinely ready for what is coming. What separated the top performers was not technology spend but whether a named person owned the data.

Gens & Associates put its Future Readiness Indicator to 59 life-science organisations and found exactly one that qualified as ready and leading. Twenty-one per cent were rated at risk. The rest sat in between, carrying gaps that will not close by themselves. That is the headline of the 2025 Operational Excellence and World Class RIM study, whose findings were released in April 2026 and written up by the firm's managing partner Steve Gens on 11 May 2026.

The interesting number is not the one. It is the four. Four organisations in the sample practised explicit end-user data accountability — individuals and teams named as responsible for the accuracy of the data in their systems. Those four recorded an aggregate data-quality confidence score of 93 per cent against 50 per cent for everyone else, aggregate efficiency of 93 per cent across 15 core RIM capabilities against 70 per cent, and 100 per cent high confidence in their authoritative sources against 44 per cent.

Meanwhile 47 per cent of the sample reported AI pilots or implementations underway. Across all of them, 131 benefit-realisation responses were captured. Six exceeded expectations. Both findings come from the same 59 companies in the same cycle, which makes the comparison unusually clean: the organisational intervention with a four-fold cost of roughly nothing outperformed the technology programme that consumed the budget.

In short
  • Of 59 organisations benchmarked, 1 rated ready and leading on the Future Readiness Indicator; 21% rated at risk.
  • The 4 organisations with named end-user data accountability reported 93% data-quality confidence versus 50% — on a subgroup of four, so treat the size of the gap as directional and the direction as solid.
  • 47% ran AI pilots. Of 131 benefit-realisation responses, 6 exceeded expectations.
  • The binding EU obligation is Article 57(2) of Regulation (EC) No 726/2004. The June 2026, December 2026 and June 2027 PMS dates are implementation milestones under it, not new law.
  • Every recurring IDMP readiness failure is a master-data governance failure. No model creates a canonical product record that was never built.

What the study measured, and what it found

The World Class RIM benchmark has run since 2015. This cycle introduced the Future Readiness Indicator, which asks a different question from the usual maturity survey: not how well an organisation performs today, but whether it is structurally equipped to keep performing through the change already scheduled. Gens frames that change as a confluence — AI, cloud-based regulatory spaces, data aggregation platforms, structured data mandates and workforce turnover landing inside the same two-to-three-year window. The indicator scores core process, organisational, data and digital capability together, which is why so few organisations clear it. A company can be excellent at submissions and still fail, because the indicator penalises the gap between the four.

The process-maturity findings are worth reading next to the readiness score, because they show what the gap costs. Organisations at higher process maturity reported operational throughput improvement of 80 per cent against 47 per cent for their peers, operating cost improvement of 90 per cent against 39 per cent, user productivity gains of 90 per cent against 50 per cent, and improvement in time to filing in secondary markets of 70 per cent against 26 per cent.

Two caveats a senior reader will want stated. These are self-reported figures from a blinded benchmark of 59 organisations, not audited operational data — the confidence scores in particular measure what regulatory leaders believe about their data, which is a proxy for quality and not a measurement of it. And the data-accountability subgroup is four companies. A 43-point gap on n=4 is a signal, not an effect size. What makes it credible is that the same four also lead on efficiency and on authoritative-source confidence, which are separate questions, and that the direction matches what the IDMP evidence shows independently.

The 4 organisations that did one thing differently

Gens is precise about what data accountability means in his sample, and the precision is the whole point. It is holding individuals and teams explicitly responsible for the accuracy and quality of the data in their systems at three levels simultaneously — functional, individual and team — with product teams owning regulatory data quality for their own portfolios.

Read that against how most regulatory functions actually run. Data quality is owned by a data governance council, which is a committee, which means it is owned by nobody in the sense that matters: nobody's objectives change if the pack-size field is wrong. The system is owned by IT. The submission is owned by the regulatory affairs lead for that market. The substance record was created by whoever first needed it. When the record turns out to be wrong, the organisation runs a remediation project rather than a conversation, because there is no one to have the conversation with.

Accountability is not the same as stewardship, and the distinction is where most programmes fail. A steward maintains a record. An accountable owner carries the consequence of the record being wrong. Gens's own read is that the principles here are broadly understood and rarely executed — clinical and supply chain functions have run this way for years — and that the obstacle is implementation rather than insight. That is an uncomfortable finding for anyone selling a system, and a useful one for anyone who has to fix a function.

ModelWho is namedWhat happens when a field is wrongObserved in the benchmark
Governance councilA committeeRemediation projectCommon
System ownership in ITAn application ownerTicket, then a data fix requestCommon
Data stewardshipA steward per domainSteward corrects, cause unaddressedIncreasingly common
Named accountabilityThe product team, plus an individualThe owner's objectives are affected4 of 59

Why 47% adoption produced 6 wins out of 131

Forty-seven per cent of these companies reported AI pilots or implementations underway. Cloud-based regulatory spaces show a similar posture: 41 per cent actively participating in an initiative, 47 per cent planning to within a year, and 71 per cent expecting the model to fundamentally change how they interact with regulators within five years. Appetite is not the constraint.

Yet of the 131 benefit-realisation responses tracked across all of the AI work, six exceeded expectations, and the study reports implementation timelines being recalibrated to 2027 and 2028. That pattern is not unique to regulatory affairs — MIT's NANDA analysis of enterprise generative AI reached a comparable conclusion across industries — but the RIM version has a specific and diagnosable cause.

Regulatory operations AI is overwhelmingly aimed at data work: reconciling product records, extracting attributes from dossiers, mapping internal terms to controlled vocabularies, drafting from structured content. Every one of those tasks takes a data estate as its input. If the estate has four candidate values for a pack size across RIM, ERP, the xEVMPD record and a submission PDF, a model does not resolve the conflict. It surfaces it, faster and in higher volume than the team can adjudicate, and the queue becomes the bottleneck that the pilot was supposed to remove. The organisations with named ownership were not better at AI. They had an input the others did not have, and a person who could say which value was right without convening anybody.

What is binding on 30 August 2026, and what is only a deadline

This is where regulatory teams get sold urgency that does not survive inspection, so it is worth setting out precisely.

The binding obligation is Article 57(2) of Regulation (EC) No 726/2004, introduced by the 2010 pharmacovigilance legislation and Regulation (EU) No 1235/2010. It requires every holder of a marketing authorisation in the EU and EEA to submit and maintain information on its authorised medicines, within 15 calendar days of notification for a new authorisation and 30 calendar days for changes arising from variations, transfers, renewals, suspensions, revocations or withdrawals. That obligation is in force today and has been since 2012.

The ISO IDMP standards — ISO 11615, 11616, 11238, 11239 and 11240 — are standards, not legislation. They acquire force through the EU implementation that EMA builds on top of Article 57(2), which is the Product Management Service inside the PLM Portal.

The PMS dates are implementation milestones published by EMA, not statutory deadlines with their own penalty regime. As set out on EMA's substance and product data management services pages: structured manufacturer data and pack sizes for non-centrally authorised products on the Union list of critical medicines were due by June 2026, extended from December 2025; structured manufacturer data for all other non-CAPs remains due by December 2026; and pack sizes for those products moved to June 2027, extended from December 2026. Two of those three have already moved once. The first has already passed as of this writing.

The legal basis itself is being replaced, but has not been. The revision of the EU pharmaceutical legislation reached provisional political agreement in trilogue on 11 December 2025; Coreper endorsed the compromise text on 6 March 2026 and the Parliament's SANT committee on 18 March 2026. As recorded by the European Parliament's legislative train, formal Council adoption follows legal-linguistic checks and the plenary vote was indicatively scheduled for November 2026. The new Regulation would repeal Regulation (EC) No 726/2004. It is not in the Official Journal, and on 30 August 2026 it is not law.

Two adjacent instruments are routinely misquoted in RIM business cases. The revised Annex 11 and the new Annex 22 on artificial intelligence were published for consultation on 7 July 2025 alongside a revised Chapter 4; the consultation closed on 7 October 2025 and final text is expected during 2026 with operative dates to be confirmed. On 30 August 2026 the binding EU text for computerised systems is still the 2011 Annex 11. And under the EU AI Act, the Digital Omnibus on AI was published in the Official Journal as Regulation (EU) 2026/1744 on 24 July 2026 and entered into force on 27 July 2026, deferring Annex III standalone high-risk obligations from 2 August 2026 to 2 December 2027 and product-embedded Annex I systems to 2 August 2028. What is live now and does reach a regulatory AI assistant is the Article 4 AI literacy duty, applicable since 2 February 2025, the GPAI obligations from 2 August 2025, and the Article 50 transparency requirements, which the Omnibus did not defer.

The 6 IDMP failure modes are all governance failures

A practitioner assessment of IDMP progress published on 16 July 2026 sets out six recurring readiness failure patterns. It is a synthesis rather than a survey, so treat the list as a diagnostic frame and not as measured incidence. Read it that way and the pattern is hard to miss: not one of the six is a technology problem.

Failure modeWhat it looks likeWhy no model fixes it
Fragmentation across systemsProduct data spread over RIM, ERP, PLM, LIMS and safety databases with no canonical recordThe canonical record has to be declared by someone with the authority to declare it
Unstructured document dependencyAttributes exist only inside dossiers and technical documentsExtraction produces candidates; someone must accept them into a record of truth
Ambiguous data ownershipSubstance, manufacturer and pack-size data owned by different functions, no owner of the product recordThis is the failure the other five inherit
Controlled vocabulary driftInternal lists in RIM and ERP drift out of alignment with EMA's referentialsAlignment is a maintained commitment with a named maintainer
Historical data debtLegacy xEVMPD records carrying accumulated shortcuts that surface as PMS failuresSomebody has to be accountable for retiring the debt rather than migrating it
Point-in-time thinkingIDMP treated as a migration project rather than continuous process integrationProjects end; obligations under Article 57(2) do not

The independent evidence points the same way. A Pistoia Alliance survey run with MAIN5 and Accurids in Q3 2024, covering 18 pharma companies including AbbVie, Amgen, AstraZeneca, Bayer, Boehringer Ingelheim and Novartis, found that only 40 per cent were confident they possessed an IDMP-compatible data model, even though 75 per cent were already using IDMP concepts to guide product information. Fifty-six per cent named lack of data standardisation as the main obstacle to integration, 44 per cent named resources and 41 per cent named ownership. More than 70 per cent saw IDMP's value as a cross-functional data integration enabler and only 11 per cent saw compliance as the primary goal — which tells you the industry understands the prize and is stuck on the plumbing.

Note the two-year gap between that survey and the Gens benchmark, and the different populations. They are not measuring the same thing. They agree anyway.

Where AI does earn its place in regulatory data work

None of this is an argument against automation. It is an argument about sequence, and about what an agent is actually good for.

The tasks where language models do reliable work in regulatory data are the ones where the output is a proposal and a named person holds the accept-or-reject decision. Extracting candidate structured attributes from an approved dossier and presenting them with the page citation. Detecting divergence between the same attribute across RIM, ERP and the xEVMPD record, and ranking the candidates by provenance. Proposing mappings from internal controlled lists to EMA referentials and flagging the ones that have drifted. Regression-testing what was submitted against what the system now holds, which is a comparison job that scales badly with people and well with machines.

Every one of those has the same architecture: the model raises the volume of candidate decisions, and the value is realised only where an accountable owner can clear the queue. Where nobody owns the record, the identical technology increases the backlog. That is the mechanism behind six benefit realisations out of 131, and it also explains why the four accountable organisations would be expected to get more out of the same tools — they have somewhere for the output to land.

The corollary is the sentence worth taking to a steering committee. No model creates a canonical product record that was never built. A model can read every dossier you own and still not tell you which pack size is true, because truth here is not a property of the text. It is a decision somebody is answerable for.

What this means in practice

Start by finding out whether you have owners. Pick five product families and ask, for each, who is accountable — by name, not by function — for the accuracy of the manufacturer data, the pack-size data and the substance record. If the answer takes more than a sentence, you have found your finding, and you have found it for free.

Then name them. The benchmark's four leaders assign accountability at the functional, individual and team level at once, with product teams owning the regulatory data quality of their own portfolio. That means it appears in objectives, it appears in the product team's operating rhythm, and there is an individual whose name is on the record. It costs nothing in licences and roughly a quarter's worth of organisational argument, which is why so few do it.

Make it measurable before you make it a programme. The leaders' distinguishing metric was confidence in authoritative sources — 100 per cent against 44 per cent. That is measurable this month: for each critical attribute, can the owner name the system of record without hesitating, and does the answer match what the next person says? Publish the disagreement rate. It is the single most useful number a regulatory operations function can put on a slide, and it will be worse than anyone expects.

Wire the ownership to a clock that already exists. Article 57(2) gives you 15 calendar days for a new authorisation and 30 for a change. Those are the beats the owner is accountable to. The PMS milestones — December 2026 for structured manufacturer data on remaining non-CAPs, June 2027 for pack sizes — are the deliverables, and they should be planned as such rather than as compliance emergencies, precisely because they have moved before and may move again.

Sequence the AI after the owners, not instead of them. If you are already mid-pilot, the salvage move is not to stop but to route the model's output to a named person per product family and measure clearance rate rather than extraction accuracy. Extraction accuracy was never the constraint.

And when the business case is written, be honest about the finding that funds it. One organisation in 59 was ready. Four had named accountability. The gap between those two numbers is the actual work, and no agent is going to do it for you.

Questions people ask about this

What did the 2026 World Class RIM study find about future readiness?
Gens & Associates surveyed 59 life-science organisations for its 2025 Operational Excellence and World Class RIM study, released in April 2026. Using its new Future Readiness Indicator, just one organisation qualified as ready and leading. Twenty-one per cent were rated at risk, and the remainder carried gaps requiring deliberate investment rather than incremental improvement.
Is the EMA IDMP deadline in 2026 legally binding?
The underlying obligation is binding: Article 57(2) of Regulation (EC) No 726/2004 requires marketing authorisation holders to submit and maintain data on every authorised medicine. The 2026 and 2027 PMS dates are EMA implementation milestones under that existing obligation, published through the PLM Portal, not a separate piece of legislation with its own penalties.
What are the current EMA PMS enrichment deadlines?
Structured manufacturer data and pack sizes for non-centrally authorised products on the Union list of critical medicines were due by June 2026, extended from December 2025. Structured manufacturer data for all other non-centrally authorised products remains due by December 2026. Pack sizes for those products moved to June 2027.
Can AI solve IDMP data readiness?
Not the part that matters. A model can extract candidate attributes from dossiers and flag inconsistencies between systems, which is genuinely useful. It cannot decide which of several conflicting records is authoritative, because that is an accountability decision rather than an inference. Without a named owner to accept or reject, extraction produces a fourth conflicting copy.
Does the EU AI Act apply to regulatory information management systems?
Mostly not as high-risk. Annex III categories target employment, credit, biometrics and essential services, so a RIM assistant rarely falls inside them, and those obligations were deferred to 2 December 2027 by Regulation (EU) 2026/1744. The AI literacy duty in Article 4 and the transparency obligations in Article 50 do apply now.