Robert Morris and Koko are Violators of International Standards

The Declaration of Helsinki is the bedrock of international principles in human research, and the foundation of governmental practices, including the ICH E6 Good Clinical Practice. The core principle is respect for the individual (Article 8), their right to self-determination and the right to make informed decisions (Articles 20, 21 and 22) regarding participation in research, both initially and during the course of the research. Principles that Dr Robert Morris violated when his firm, Koko, used artifical intelligence to engage in medical research on uninformed participants. The man, and his company, deserves the full force of international censure, including disbarment by the NHS and all other international bodies with even a shred of oversight on healh practices.

I’m infuriated by this. AI is already an ethically ambigious area full of concerns, and for this callous individual and his company to waltz in and break a fundamental principle of human research is unconsciouable.

Another reason why we need serious regulatory oversight of AI. We won’t see this from the US, so hopefully the EU gets their act together and pushes forward. GPDR may not be perfect but we are in a better place with something rather than nothing, and as the actions of callous companies like Koko show we are in desperate need for protection when it comes to the ‘promises’ of AI.

Also, shame on Stonybrook’s Institutional Review Board. While not a case of IRB shopping, they sure did their best to avoid grappling with the issues behind the study.

I am pretty sure this AI counts as software as a device, in which case a whole lot of regulations were broken.

“Move fast and Break Things” is a horrible mantra, especially when health and well being is involved. Robert Morris, like Elizabeth Holmes, are examples of why we need a strong oversight regime when it comes to scientific research and why technology on its own is never the solution.

Roche Limit – a Powerpoint Game

My fellow PowerPoint jockies, we have been outdone by ROCHE LIMIT, a surrealist point and click horror adventure that was created (and is played in) Microsoft PowerPoint.

The current build of ROCHE LIMIT takes around 20 minutes to play through and features one of the multiple planned endings to the full game. The actual narrative is quite Lynchian and appears to revolve around you accepting your (and possibly the human race’s) inevitable demise and a higher power’s ambivalence towards it. It’s a fun, quick little game, with excellent audio design and pixel art animation throughout. 

Our PowerPoint presentations have a new standard, and that standard is this wild little game.

Follow The Development of ROCHE LIMIT Here

Check Out a Gameplay Video Here

Download The ROCHE LIMIT Beta Here (Requires Microsoft PowerPoint to Run)

European Guideline on Data Integrity in GCP Studies

The EMA has published “Guideline on computerised systems and electronic data in clinical trials.”

Anyone familiar with Annex 11 of Eudralex Annex 4 won’t be surprised by the content, but frankly I expect a lot of folks who have primarily experience on the clinical side will be scratching their heads. The fact that the authors felt the need to have an entire paragraph dedicated to unique user names is telling.

This is a great resource for sponsors who need to figure out just what to evaluate at investigators sites, a requirement this guideline repeats multiple times.

I’ll be very curious how effective sponsors are in ensuring this requirement is met “The investigator should receive an introduction on how to navigate the audit trail of their own data in order to be able to review changes.”

Choose Your Font!

For a lot of reasons paper (and paper-on-glass) documents are with us for a long time. So it continually surprises me when I see documents in some basic, reduced readability font .

Even when we go to electronic systems that choice of font is going to be an important one. And it’s probably not the same font as what worked for you in a paper world.

And then there is all that training material and presentations (including conference material).

So spend some time and choose the fonts that works for you and your users. But please for goodness sake don’t default to a font because it is what you have always used.

I’m a huge fan of Roboto.

There was a nice writeup on fonts on SlideModel: 20 Best PowerPoint Fonts to Make Your Presentation Stand Out in 2023

Detectability in Risk Management is a “Sort of” “Sometimes” thing

I’ve recently seen a few audits that point out something along the line of “Recommendation to revise Quality Risk Management Process/Procedure to include detectability as a variable in determining Risk Priority Numbers (RPNs).  The current process only includes the frequency and severity of impact in the calculation.  However, ICH Q9 also recognizes the use of risk management tools which include the ability to detect harm (detectability) in the estimation of risk (refer to the section titled “Risk analysis”).”

So, first of all, that’s not what Q9 says. Q9 (R1) is actually pretty clear here, stating “Risk analysis is the estimation of the risk associated with the identified hazards. It is the qualitative or quantitative process of linking the likelihood of occurrence and severity of harms. In some risk management tools, the ability to detect the harm (detectability) also factors in the estimation of risk.”

Q9 later goes on to state “Quality risk management supports a scientific and practical approach to decision-making. It provides documented, transparent and reproducible methods to accomplish steps of the quality risk management process based on current knowledge about assessing the probability, severity and sometimes detectability of the risk.”

Q9 clearly recognizes that detectability is useful sometimes, with specific tools in specific cases. This is in alignment with risk management thinking in general, for example ISO 31000:2018 states that Risk analysis should consider factors such as:

— the likelihood of events and consequences;
— the nature and magnitude of consequences;
— complexity and connectivity;
— time-related factors and volatility;
— the effectiveness of existing controls;
— sensitivity and confidence levels.

Detectability is then one of several methods to consider in risk analysis. The selection criteria for tools should take into account situations when detectability is desired and drive to use of those tools, for example, the FMEA which is built to determine how and when a failure can be detected. In other tools, detectability is usually built into the evaluation of current controls and is often captured in likelihood or somewhere else

When it comes to risk, avoid a one-size fits all. Think of what the intent is and use the right tool for the job.