Pharmacy Back-Office & PBM Claims Adjudication AI
AI performing prescription verification, drug-interaction and formulary screening, and pharmacy-benefit-manager (PBM) claims adjudication and reimbursement calculation in US pharmacy and PBM operations, distinct from general insurer prior-authorisation.
Indicative decision support, not legal advice. Risk classification depends on your concrete deployment context and can change with scope drift — validate the result with qualified counsel.
Target market(s)European UnionUnited States (federal)change
Changes which instruments below count as in scope for this profile.
Target markets: European Union, United States (federal)
Regulatory footprint
6 instruments across 3 of 7 regulatory domains, plus 5 standards references- AI law1 instrument
- Data protection2 instruments
- Cyber & resiliencenone triggered
- Online safety & platformsnone triggered
- Product safetynone triggered
- Financial servicesnone triggered
- Sector & employment3 instruments
- Standards5 references
By jurisdiction
- EU2European UnionEU AI Act, GDPR
- US3United States (federal)DEA Controlled Substances Act Dispensing & E-Prescribing Rules, FDA oversight of Software as a Medical Device (US), HIPAA (US Health Privacy)
- US-IL1thinUnited States — IllinoisIllinois Prescription Drug Affordability Act (PBM Reform)
The AI Act is one dimension of this footprint, not the whole of it — every domain above carries its own obligations and deadlines. See the instruments in the graph →
The chain holds, but at least one hop rests on a secondary source, an ageing verification or a practice-derived step. Check the flagged hops before you rely on them.
Computed weakest-link over 22 evaluated hops across 1 target market: a chain is only as strong as its weakest step, so the band follows the worst hop rather than an average that would hide it. Five factors per hop — source tier, verification age, status certainty, community hardening, derivation kind — all read from graph data, never from a hand-set score.
Why this band8 factors lowered the band — each links to the claim behind it
- Source tier: FDA oversight of Software as a Medical Device (US) carries no resolvable citation — the claim is uncited. open node →
- Source tier: JTC 21 Technical Package (prEN 18228/18229/18281–83) rests on a secondary source (tracker or summary), not on the primary text. open node → primary source →
- Source tier: IEEE CertifAIEd™ carries no resolvable citation — the claim is uncited. open node →
- Source tier: prEN 18229-1 (Trustworthiness Framework, part 1) rests on a secondary source (tracker or summary), not on the primary text. open node → primary source →
- Status certainty: FDA oversight of Software as a Medical Device (US) carries an unverified status — recorded from a secondary source and not confirmed against the primary text. open node →
- Status certainty: JTC 21 Technical Package (prEN 18228/18229/18281–83) is "draft", not settled in-force law. open node → primary source →
- Status certainty: prEN 18229-1 (Trustworthiness Framework, part 1) is "enquiry", not settled in-force law. open node → primary source →
- Verification age: IEEE CertifAIEd™ has no recorded verification date. open node →
Compliance brief
This use case is minimal-risk under the EU AI Act (Minimal Risk); no product-specific obligations beyond general AI literacy apply.
What is owed
- Art. 4. Providers and deployers must ensure sufficient AI literacy of staff dealing with AI systems.
- GDPR Art. 22. Right not to be subject to solely automated decisions with legal/similar effect; requires meaningful human involvement or explicit legal basis + safeguards.
- GDPR Art. 27. A controller or processor not established in the Union that falls within Art.
- GDPR Art. 17. Right to erasure collides with AI Act Art.
- GDPR Art. 25. Privacy by design & default: minimisation, pseudonymisation, PII filters in pipelines and vector stores.
Dates that bind
- 2024-08-01 — AI Act enters into force. Regulation (EU) 2024/1689 in force; countdown for all staged obligations starts.
- 2025-02-02 — Prohibitions + AI literacy. Art. 5 prohibited practices ban applies (manipulation, social scoring, untargeted face scraping, workplace emotion recognition); Art. 4 AI literacy duty.
Maximum exposure
- EU AI Act: Tiered: €35m / 7% (prohibited practices); €15m / 3% (Art. 9–15 high-risk obligations incl. data governance, documentation, logging); €7.5m / 1% (Art. 99(5) — incorrect, incomplete or misleading information to notified bodies or national competent authorities)
- GDPR: Up to €20m or 4% of worldwide annual turnover
- DEA Controlled Substances Act Dispensing & E-Prescribing Rules: DEA registration suspension or revocation (21 U.S.C. § 824(a)), civil penalties (21 U.S.C. § 842(c)) and criminal liability for unlawful dispensing (21 U.S.C. § 841); 21 CFR 1306.04(a) itself subjects a person knowingly filling a purported prescription not issued in the usual course of professional treatment to the penalties for controlled-substance violations.
- Illinois Prescription Drug Affordability Act (PBM Reform): Administered and enforced by the Illinois Department of Insurance; Company Bulletin 2025-20 describes the Department's enforcement of the PDAA's report and fee deadlines, including a stated exercise of enforcement discretion. A statutory penalty schedule is not captured in this node. Enforcement of the reporting requirements as applied to ERISA plans is preliminarily enjoined (see status note).
First five actions
- Confirm in writing whether this organisation builds/places the system on the market (provider) or only operates it (deployer), since the role is not yet established.
- Commission and confirm the Art. 4, GDPR Art. 22, GDPR Art. 27 obligations named above as active workstreams with an accountable owner.
- Design and document a human-oversight procedure appropriate to how this system is used.
- Produce the technical documentation and evidence artefacts already mapped to this use case (HITL Escalation Queue & Review UI, Adverse-Decision Reason Generator, Bitemporal Memory (GDPR×Art.12)) before they are requested.
- Put 2024-08-01 — AI Act enters into force — into the compliance calendar with an owner and lead time.
Terms used above: · · ·
This brief is based on partial coverage — no threat profile is mapped yet.
Consensus reading: Minimal Risk open in the graph →
Pharmacy back-office and PBM adjudication AI sits on a regulatory track distinct from insurer prior-authorisation (uc-priorauth), and its hooks are mostly US. Where the system supports a DEA-registered pharmacy, the pharmacist's 'corresponding responsibility' for controlled-substance prescriptions (21 CFR 1306.04(a)) stays with the pharmacist, and electronic Schedule II-V prescriptions may only be processed through a pharmacy application that meets 21 CFR Part 1311 Subpart C. Its drug-interaction and formulary alerts stay outside FDA device regulation only while they meet all four Non-Device CDS criteria of FD&C Act section 520(o)(1)(E), including that the pharmacist can independently review the basis of each alert (Criterion 4); the claims-adjudication and reimbursement logic is administrative rather than clinical and is reached instead by state PBM law such as Illinois's Prescription Drug Affordability Act (spread-pricing and steering ban, 100% rebate and fee pass-through) and by HIPAA, with GDPR added for EU patients. No EU AI Act Annex III point covers a private PBM's claims adjudication, so the default classification is minimal risk.
What the reading rests on — the provisions this classification actually pulls in:
- Art. 4 — AI Literacy
- EU AI Act (Regulation (EU) 2024/1689)
- GDPR (Regulation (EU) 2016/679)
- DEA Controlled Substances Act Dispensing & E-Prescribing Rules (Controlled Substances Act, 21 U.S.C. § 801 et seq., as implemented by DEA regulations at 21 CFR Part 1306 (Prescriptions) and 21 CFR Part 1311 (Requirements for Electronic Orders and Prescriptions))
- FDA oversight of Software as a Medical Device (US) (FDA SaMD / Digital Health regulatory framework)
- Illinois Prescription Drug Affordability Act (PBM Reform) (Prescription Drug Affordability Act, Public Act 104-0027 (eff. 1 July 2025; entire Act effective 1 January 2026), Article XXXIIB of the Illinois Insurance Code, 215 ILCS 5/513b1 et seq.)
- HIPAA (US Health Privacy)
Baseline: of 100+, 40% were not definitively classifiable (18% clearly high-risk, 42% clearly low-risk). appliedAI Institute — AI Act risk classification of AI systems from a practical perspective
Applicable Regulations (6)
Legal Obligations (10)
Control Objectives (2)
Standards & Evidence
Evidence you will need (9)
The concrete deliverables this use case's obligations ask for — grouped by what kind of artifact they are. Documentation is the largest single conformity cost block, so the list is a work plan, not a reading list. Full evidence matrix →
Assessments (2)
A structured judgement about risk, rights or a management system.
Test reports (1)
Measured results from testing, evaluation or red-teaming.
Log records (1)
Machine-generated records produced while the system runs.
Process records (5)
Traces that a process actually happened, and who did it.
Architecture Blueprint
Required Technical Components (22)
Build or Buy — Vendor Layer (9)
| Example | Sub-category | What it does | Hosting | Claimed alignments |
|---|---|---|---|---|
| LangChain / LangGraph | agent framework | Graph-structured agent runtime; interrupt/pause nodes support implementing human approval at defined steps. Typical: multi-step agents, approval workflows. | not checked | supports implementing Art. 14 oversight (claimed)supports Art. 12 step logging (claimed) |
| LlamaIndex | RAG framework | Indexing and query abstractions over documents and structured sources. Typical: enterprise RAG, document agents. | open source | retrieval-governance positioning |
| Microsoft AutoGen | multi-agent framework | Conversational multi-agent patterns with pluggable tool executors. Typical: multi-agent research, code agents. | not checked | research/OSS, no vendor certification |
| CrewAI | multi-agent framework | Role-based agent teams with task delegation and process templates. Typical: process automation, role-based agents. | not checked | vendor-stated security posture |
and 6 more in the stack advisor →
Community-maintained, disputable examples — not an endorsement and not a ranking. Alignments are as claimed by vendors or the source compilation, not verified by RAIN; a certification is shown as a certification only where a certificate or registry reference is recorded.
Disclosure: RAI·N·avigator operates in this category too, so we have a commercial interest in any comparison here. That is why this layer maps product classes to control objectives and lists named products as community-maintained examples — we publish no rankings, no quadrants and no coverage assertions about any vendor, including ourselves.
| Example | Sub-category | What it does | Hosting | Claimed alignments |
|---|---|---|---|---|
| LangSmith | agent tracing & evaluation | Trace capture and evaluation over LangChain/LangGraph runs with dataset-based scoring. Typical: step tracing, regression evaluation. | not checked | SOC 2 (claimed)supports Art. 12 record-keeping (claimed) |
| Langfuse | agent tracing & evaluation | Open-source tracing, prompt management and evaluation; self-hostable for retention control. Typical: self-hosted tracing, cost/latency analytics. | open source | GDPR-positionedsupports Art. 12 record-keeping (claimed) |
| Arize AI / Phoenix | ML & LLM observability | Production monitoring with drift and performance analysis; Phoenix is the open-source tracing side. Typical: drift monitoring, production analytics. | not checked | SOC 2 (claimed)drift-monitoring positioning (SR 11-7 style, claimed) |
| Helicone | LLM gateway & logging | Proxy-level logging of prompts, costs and latency across providers. Typical: gateway logging, cost control. | not checked | SOC 2 (claimed)supports Art. 12 record-keeping (claimed) |
and 11 more in the stack advisor →
Community-maintained, disputable examples — not an endorsement and not a ranking. Alignments are as claimed by vendors or the source compilation, not verified by RAIN; a certification is shown as a certification only where a certificate or registry reference is recorded.
Disclosure: RAI·N·avigator operates in this category too, so we have a commercial interest in any comparison here. That is why this layer maps product classes to control objectives and lists named products as community-maintained examples — we publish no rankings, no quadrants and no coverage assertions about any vendor, including ourselves.
| Example | Sub-category | What it does | Hosting | Claimed alignments |
|---|---|---|---|---|
| Credo AI | AI governance platform | Policy packs, risk tiering and evidence workflows mapped across frameworks. Typical: AI registry, policy administration. Scope overlap: Its scope overlaps this platform's own; we have a commercial interest in the comparison. | not checked | ISO 42001 alignment (claimed)EU AI Act readiness positioning |
| Holistic AI | AI governance & audit | Risk assessment, bias auditing and regulatory reporting workflows. Typical: bias audit, regulatory reporting. Scope overlap: Its scope overlaps this platform's own; we have a commercial interest in the comparison. | not checked | NYC LL144 audit support (claimed)EU AI Act readiness positioning |
| IBM watsonx.governance | AI governance platform | Governance, factsheets and monitoring integrated with the IBM stack. Typical: factsheets, model monitoring. Scope overlap: Its scope overlaps this platform's own; we have a commercial interest in the comparison. | not checked | ISO 42001 alignment (claimed)Art. 11 documentation support (claimed) |
| ModelOp | AI/model governance | Model and agent inventory with automated lifecycle controls for large estates. Typical: model inventory, control automation. Scope overlap: Its scope overlaps this platform's own; we have a commercial interest in the comparison. | not checked | model-risk positioning (SR 11-7 style, claimed)ISO 42001 alignment (claimed) |
and 3 more in the stack advisor →
Community-maintained, disputable examples — not an endorsement and not a ranking. Alignments are as claimed by vendors or the source compilation, not verified by RAIN; a certification is shown as a certification only where a certificate or registry reference is recorded.
Disclosure: RAI·N·avigator operates in this category too, so we have a commercial interest in any comparison here. That is why this layer maps product classes to control objectives and lists named products as community-maintained examples — we publish no rankings, no quadrants and no coverage assertions about any vendor, including ourselves.
| Example | Sub-category | What it does | Hosting | Claimed alignments |
|---|---|---|---|---|
| Docling | document parser | Open-source layout-aware parsing of PDFs and office formats into structured chunks. Typical: RAG ingestion, air-gapped pipelines. | self-hostable | EU sovereignty positioning |
| LlamaParse | document parser | Managed parsing service tuned for tables and complex documents feeding RAG. Typical: RAG ingestion, table extraction. | not checked | SOC 2 (claimed) |
| Amazon Textract | document parser | OCR and form/table extraction with per-page pricing inside AWS. Typical: document intake, claims processing. | not checked | SOC 2 (claimed)HIPAA-eligible (claimed)ISO 27001 (claimed) |
| Diffbot | web/knowledge extraction | Structured extraction and knowledge-graph construction from web sources. Typical: market monitoring, entity resolution. | not checked | vendor-stated security posture |
and 12 more in the stack advisor →
Community-maintained, disputable examples — not an endorsement and not a ranking. Alignments are as claimed by vendors or the source compilation, not verified by RAIN; a certification is shown as a certification only where a certificate or registry reference is recorded.
Disclosure: RAI·N·avigator operates in this category too, so we have a commercial interest in any comparison here. That is why this layer maps product classes to control objectives and lists named products as community-maintained examples — we publish no rankings, no quadrants and no coverage assertions about any vendor, including ourselves.
| Example | Sub-category | What it does | Hosting | Claimed alignments |
|---|---|---|---|---|
| Anjuna | confidential computing | Runs workloads inside hardware enclaves without application rewrites. Typical: data-in-use protection, regulated inference. | not checked | confidential-computing positioningDORA-positioned (claimed) |
| Fortanix | confidential computing & KMS | Enclave runtime plus key management and tokenisation services. Typical: key management, data-in-use protection. | not checked | FIPS 140-2 (claimed)DORA-positioned (claimed)HIPAA-positioned (claimed) |
| Skyflow | privacy vault | Polymorphic data vault de-identifying records before they reach a model. Typical: PII vaulting, pre-model redaction. | not checked | SOC 2 (claimed)HIPAA-positionedGDPR-positioned |
| Private AI | PII detection & redaction | Detection and redaction of identifiers across text, documents and audio. Typical: inline redaction, document de-identification. | not checked | GDPR-positionedHIPAA-positioned |
and 1 more in the stack advisor →
Community-maintained, disputable examples — not an endorsement and not a ranking. Alignments are as claimed by vendors or the source compilation, not verified by RAIN; a certification is shown as a certification only where a certificate or registry reference is recorded.
Disclosure: RAI·N·avigator operates in this category too, so we have a commercial interest in any comparison here. That is why this layer maps product classes to control objectives and lists named products as community-maintained examples — we publish no rankings, no quadrants and no coverage assertions about any vendor, including ourselves.
| Example | Sub-category | What it does | Hosting | Claimed alignments |
|---|---|---|---|---|
| Azure AI Search | managed retrieval | Managed hybrid search with security trimming against tenant identities. Typical: ACL-aware RAG, enterprise search. | not checked | ISO 27001 (claimed)SOC 2 (claimed) |
| Databricks Unity Catalog | governed lakehouse | Catalog and lineage spanning tables, features and RAG chunks. Typical: lineage evidence, governed RAG. | not checked | SOC 2 (claimed)lineage/Art. 10 support (claimed) |
| Relyance AI | code-level data & AI lineage | Parses source repositories to map data and inference flows at code level, with CI checks on changes to those flows. Typical: data lineage, shift-left privacy review. Scope overlap: Its AI-governance reporting scope overlaps this platform's own; we have a commercial interest in the comparison. | SaaS (vendor cloud) | GDPR programme tooling (claimed)EU AI Act readiness positioning |
| Snowflake Cortex | governed lakehouse | Model calls inside the warehouse boundary with masking and clean rooms. Typical: in-warehouse inference, governed analytics. | not checked | SOC 2 (claimed)ISO 27001 (claimed)HIPAA-eligible (claimed) |
Community-maintained, disputable examples — not an endorsement and not a ranking. Alignments are as claimed by vendors or the source compilation, not verified by RAIN; a certification is shown as a certification only where a certificate or registry reference is recorded.
Disclosure: RAI·N·avigator operates in this category too, so we have a commercial interest in any comparison here. That is why this layer maps product classes to control objectives and lists named products as community-maintained examples — we publish no rankings, no quadrants and no coverage assertions about any vendor, including ourselves.
| Example | Sub-category | What it does | Hosting | Claimed alignments |
|---|---|---|---|---|
| Fact0 | cryptographic evidence ledger | Positions itself as a tamper-evident ledger for AI decision records. Typical: decision records, audit trail. | not checked | supports Art. 12 record-keeping (claimed) |
| Traccia | audit trail & traceability | Positions itself around traceability of AI pipeline steps and artefacts. Typical: traceability, artifact lineage. | not checked | supports Art. 12 record-keeping (claimed) |
Community-maintained, disputable examples — not an endorsement and not a ranking. Alignments are as claimed by vendors or the source compilation, not verified by RAIN; a certification is shown as a certification only where a certificate or registry reference is recorded.
Disclosure: RAI·N·avigator operates in this category too, so we have a commercial interest in any comparison here. That is why this layer maps product classes to control objectives and lists named products as community-maintained examples — we publish no rankings, no quadrants and no coverage assertions about any vendor, including ourselves.
| Example | Sub-category | What it does | Hosting | Claimed alignments |
|---|---|---|---|---|
| GitHub Copilot | developer copilot | Code completion and agent modes inside the IDE and repository workflow. Typical: software engineering, code review. | not checked | SOC 2 (claimed)enterprise data-handling commitments (claimed) |
| Microsoft 365 Copilot | productivity copilot | Assistant across mail, documents and meetings inheriting existing tenant permissions. Typical: knowledge work, meeting summaries. | not checked | ISO 27001 (claimed)SOC 2 (claimed)EU data-boundary positioning |
| Perplexity Enterprise | research assistant | Cited web and internal search with source attribution per answer. Typical: market research, citation-backed search. | not checked | SOC 2 (claimed)enterprise data-handling commitments (claimed) |
| Cursor | developer copilot | AI-native editor with repository-wide agent edits. Typical: software engineering, refactoring. | not checked | SOC 2 (claimed)privacy-mode option (claimed) |
and 5 more in the stack advisor →
Community-maintained, disputable examples — not an endorsement and not a ranking. Alignments are as claimed by vendors or the source compilation, not verified by RAIN; a certification is shown as a certification only where a certificate or registry reference is recorded.
Disclosure: RAI·N·avigator operates in this category too, so we have a commercial interest in any comparison here. That is why this layer maps product classes to control objectives and lists named products as community-maintained examples — we publish no rankings, no quadrants and no coverage assertions about any vendor, including ourselves.
| Example | Sub-category | What it does | Hosting | Claimed alignments |
|---|---|---|---|---|
| Saidot | public AI register | AI register with published system cards and regulation-mapped documentation workflows. Typical: public AI register, system cards. Scope overlap: Its documentation and register scope overlaps this platform's own; we have a commercial interest in the comparison. | SaaS (vendor cloud) | EU AI Act documentation positioningISO 42001 alignment (claimed) |
Community-maintained, disputable examples — not an endorsement and not a ranking. Alignments are as claimed by vendors or the source compilation, not verified by RAIN; a certification is shown as a certification only where a certificate or registry reference is recorded.
Disclosure: RAI·N·avigator operates in this category too, so we have a commercial interest in any comparison here. That is why this layer maps product classes to control objectives and lists named products as community-maintained examples — we publish no rankings, no quadrants and no coverage assertions about any vendor, including ourselves.
Outsourced delivery BPO · SaaS · Service-as-a-Software caveats
Delivery Model — BPO · SaaS · Service-as-a-Software
Threat Profile
No elevated threat is modelled for this use case yet.