The idea
In Life Sciences, everyone audits everyone. The stakes are too high not to — these are systems supporting human trials, and a mistake doesn't just cost money, it costs trust or worse. And yet the tools meant to validate those systems often come from vendors who also profit from housing the very data being reviewed. Nobody says that conflict out loud, but I spent 24 years watching it play out. RCA — Requirements Compliance Architect — is what happens when you design a reviewer with no stake in the outcome at all — it doesn't win if your study succeeds, doesn't lose if it doesn't. Its only interest is whether the process was actually followed.
What it does
RCA reviews requirements specifications and use-case documentation — the earliest artifact in a regulated software build — and flags what won't survive an audit before an audit ever sees it. It's a small, deliberate piece of a much larger validation picture; a complete FDA-ready package also needs test cases, traceability, vendor assessments, and qualification documents that RCA doesn't touch. It stays in its lane on purpose. What it does within that lane, it does thoroughly: catching ambiguous language, weak or untestable requirements, broken traceability, missing fields, and gaps that would otherwise surface as a much more expensive conversation weeks later.
How I built it
RCA is a controlled reviewer, not a collaborator. It doesn't write requirements, doesn't edit anything, doesn't approve anything — it finds problems and hands them back to a human. I built it to be resistant to the thing every AI reviewer is vulnerable to: being talked into softening its own standard. It can't be pressured, bargained with, or convinced to look past something, and any attempt to try gets documented rather than acted on. It's also intentionally disconnected from the systems it reviews — by design, not oversight — because a validation tool that also stores your regulatory records has a conflict of interest baked into its business model, whether anyone admits it or not.
That independence runs deeper than just RCA. IRONClad Clinical's final full-package review runs through a separate reviewer, blind to what RCA or any other specialist already found — so no single agent's read can quietly bias the final call. Every gate checks the evidence itself, not another AI's opinion of it.
What I was exploring
The deeper question was whether an AI could hold a genuinely adversarial-to-nobody stance — strict enough to actually catch what needs catching, but transparent enough that a human always understands why. I think of it as the Bull Dog auditor: it won't let something through it can't verify, but it will always show you exactly where the evidence fails, so the fix is obvious rather than mysterious. That balance — uncompromising on the standard, generous on the explanation — turned out to be the whole design problem.
My role
Concept, requirements/domain expertise, product architecture, and the review doctrine itself — built from lived experience inside exactly the kind of process IRONClad Clinical now audits.
What's next
RCA exists as a working prototype with a defined pilot structure; IRONClad Clinical, the larger vision it's the first piece of, is still maturing behind it.