Subscribe to our podcast, The Life Science Rundown, if you haven’t already.
There’s a version of quality leadership that starts every decision with “what will the auditor think?” Julio Salwen would like that version to end!
His argument is that when you build a quality system to please an auditor, compliance becomes the objective and safety becomes incidental. Flip it! Build a strong quality system aimed at controlling real risk, and compliance follows naturally. You do the compliance check after, not upfront.
Nick Capman sat down with Julio, SVP and Chief Quality Officer at MiniMed, to talk through what that looks like in practice when you’re standing up global quality across a newly separated company while AI reshapes the work underneath you.
Julio is an engineer by training with more than 35 years of experience across pharma, devices, and diagnostics, most of it in manufacturing and quality management, with regulatory compliance experience both in and outside the US. He’s held quality leadership roles across Puerto Rico, Europe, and the United States, including Global Head of Quality for Abbott Molecular, Divisional VP of Quality for Abbott Point of Care, and VP of Quality for Medtronic’s Diabetes Operating Unit before it became MiniMed.
He also builds his own AI agents, which makes his caution about them more credible than most you might ask!
Apple Podcasts | Spotify | YouTube | Web + Others
Julio’s key insights and practical takeaways
If you’re short on time, here are the most important lessons from the discussion.
“Regulatory confidence” means decisions you can explain (not paper you can produce). Julio defines it as controlled, transparent patient innovation. Confidence comes from risk being understood and decisions being explainable, not just documented. Five years ago the emphasis sat on documentation, validation, and procedure, a more canned approach. Today it’s more fluid, which raises the demand for governance, integrity, accountability, and monitoring. He put weight on that last one: things change every day, so monitoring isn’t optional.
Stop asking what the auditor will think. This is the mindset shift he pushes hardest. Leaders should start with what risk they’re actually trying to control, then let compliance follow. He’s a fan of the QMSR precisely because he argues it enables innovation through more effective risk management. Compliance is a side benefit of a strong quality system, not the main objective. Nick’s analogy: it’s the difference between asking how to pass the test and actually learning the material. Learn it and you’ll pass.
Turning people loose on AI without definition is the biggest unintentional risk. Telling your organization to “go use AI,” without controls or a clear intended use is how leaders take on regulatory risk without realizing it. As Julio put it, you can’t ChatGPT compliance. He uses AI tools as research assistants and is explicit that he keeps the decision-making in his own brain. Without a leader setting that tone, people follow the tools blindly. He also referenced the (now infamous) warning letter where a company’s justification amounted to “this is what the AI tool told me.” That doesn’t work, and if it did, anyone could form a company, buy a few tools, and hold nobody accountable.
Introduce AI where the risk is genuinely low, then build confidence. Nothing is zero risk, so the goal is controlled, proportionate risk. Julio shares his own example where he built an agent to monitor the warning letters the FDA posts every Tuesday. When he tested it, it missed two, so he trained it. That’s a low-risk use (general knowledge, no decision being made) so he could use it immediately. Research and document drafting are good entry points. Decisions stay with qualified professionals, and he stressed the word qualified. Being a quality professional doesn’t make someone a qualified quality AI professional, because a quality professional might assume a validated tool works the way validated tools traditionally work.
Senior leaders make organizations risk-averse, one overreaction at a time. Risk aversion is the default failure mode at the top, and Julio makes clear that his people can take risks, which means things will sometimes go wrong! When something does, and it isn’t a high risk, the response should be: understood, learn from it, move on. If leaders turn those events into a big deal, that’s the problem. This needs to be explicit, and that it’s a behavior rather than a policy. Patient risk is off the table. Other risks are part of the job.
Match your controls and your reaction to the actual severity. Nick offered a useful image from a talk on risk: two pits, one shallow and wide, easy to fall into but survivable, and one narrow and deep, unlikely but severe. The controls should be commensurate with the risk, and the response when something goes wrong should be as well. Julio’s phrase for the minor version is a slap on the wrist. It only takes one slap-on-the-wrist event treated as a catastrophe to make an entire organization risk-averse.
AI can’t yet tell the shallow pit from the deep one, and that’s where humans matter. Julio’s view is that AI will largely treat both as equal, and the human has to say no — these actually aren’t the same. He agrees AI will get there, particularly as teams train tools on their own risk tolerance, which will differ from organization to organization. Today he’d use it as a reference and wouldn’t make a decision solely on it, gaining confidence over time.
Hybrid governance requires dropping the control tower. Global quality tends toward central control of everything, and Julio wants standards, accountability, and escalation mechanisms instead. That means clear policies, minimum standards, defined decision rights, and a shared definition of what counts as significant risk. His framing is the critical few versus the important many. The practical test is when a regulatory inquiry arrives, can your local person tell whether it carries real risk or is routine? A question from the FDA may land in a very different tone than one from HSA in Singapore. Set the guardrails, then equip people with the skills to interpret and know when to escalate. Otherwise, you’ve built a control tower and called it a hybrid.
Fragmentation and inconsistent execution are what regulators actually find. Julio’s emphasis is on the consistency of application in risk management, not on the consistency of decisions, a sharper distinction than most people draw. He’s a firm believer in qualifying people, and he sees that mattering more, not less, as tools proliferate. Policies need to describe what the system is, how it can be used, and what it can’t be used for.
Automating a broken process gives you a faster broken process. One of the most common pitfalls he named: a company doesn’t really have a process, but now it has a tool, so it wires the weak process into AI and expects improvement. The process stays broken. Fix it first, then look at where the tools fit.
High-performing organizations share a model rather than passing handoffs. When quality, IT, and data science operate in silos, innovation stalls. Each brings something the others need: quality brings the risk framework and process knowledge, IT brings architecture and security, data science brings models and analytics. They have to be in it from the start. Innovation gets held up when one group runs ahead without the others, then has to come back, data science building something impressive without accounting for infrastructure, security, or patient risk. He also flagged shared vocabulary as an underrated point of failure, since what you call things can quietly derail alignment.
Develop two capabilities: risk management and enough technical literacy to ask hard questions. Julio’s advice for quality leaders is to pair deep risk management skill with what he calls knowing enough to be dangerous. Understand the technology well enough to ask real questions, because if you don’t, you’ll hear things and follow them on trust. His counter-principle is the old quality standard: trust but verify. He spends real time learning and builds agents himself just to understand what the tools can do. He was blunt that you can’t be a PowerPoint leader. You need to know the quality system and the regulation. He praised QMSR for bringing ISO 13485 and ISO 14971 together into real application. You don’t need every detail; that’s what an organization is for, but you need enough.
You know you’ve reached “dangerous” when people can’t answer you immediately. This was the sharpest exchange in the conversation. Julio’s test: if he asks questions and people respond right away, he hasn’t asked anything challenging yet. When someone says “I hadn’t thought about that,” he’s adding value rather than checking boxes. He extends the same logic to leadership development, telling people they discover the limits of their authority by crossing a boundary and getting the slap on the wrist. Until then, you’re operating in the safe zone, and you don’t actually know where your edge is.
You’re on an escalator going down. Nick described the shift in how continuous learning feels: he used to read, attend conferences, and take training and come away feeling he’d gained an advantage. Now the same effort feels like keeping pace. Julio’s analogy was better. It’s an escalator coming down. The moment you stop, you go backward. Both agreed the useful response is accepting that this is now the condition rather than a personal failing. Everyone feels the same way. Don’t be hard on yourself, and don’t stop climbing.
Comfort with vulnerability is part of the job. Julio’s own framing as head of quality is that he knows he’s vulnerable every hour, and that isn’t catastrophic; it’s accurate. There’s no process so solid that nothing can go wrong. Things go wrong when you’re comfortable, so the working question becomes what could go wrong tomorrow that you can prevent today.
What regulators will expect, starting now rather than in three years. Julio’s view is that “looking ahead” is really describing today. Companies need structured AI governance built into the quality system, with boundaries even if AI is used widely elsewhere in the business. If a company moves fast on AI, the governance has to keep pace. Monitoring matters: how many agents, what utilization, how people are making decisions. Change management matters because the policy you write today may not hold in six months as new tools arrive. Accountability and clear intended use must be explicit across the organization, with a risk-based split between what you can use a research assistant for without heavy validation and where a decision about a product is being made—decisions AI does not make. The concrete first step he recommends is to inventory your AI use cases and classify them by risk, so the organization can see what it can do, how it should do it, and what it probably can’t. And the scope extends past quality systems into patient information, data, and HIPAA. Then training, repeatedly. Your best people today may not be your best people in three to five years if you don’t train them, and that includes training yourself.
His closing advice. Use AI today responsibly within a framework. The framework already exists under QMSR and ISO 13485, and AI use aligns to it. Train yourself and your teams, and don’t underestimate how much a quality leader needs to genuinely understand what they’re walking into.
One thing to bring back to your team
Inventory your AI use cases and classify them by risk.
Most organizations can’t answer basic questions about their own AI exposure: how many tools are in use, by whom, for what, and where a human is genuinely making the decision versus rubber-stamping an output. Until you have that inventory, your governance is theoretical.
Then ask the harder cultural question underneath the whole conversation. The last time something minor went wrong in your organization, did leadership treat it as a slap on the wrist or as a catastrophe? Because as Julio put it, one overreaction to a low-risk event is enough to make a team risk-averse, and a risk-averse quality organization won’t innovate no matter what your policy says.
Julio Salwen is SVP and Chief Quality Officer at MiniMed, the diabetes company formerly part of Medtronic, where he shapes and executes global quality strategy across the full product lifecycle and advises the CEO, executive leadership, and board on quality, compliance risk, and patient safety. An engineer by training, he has more than 35 years of experience in the pharmaceutical, medical device, and IVD industries, with responsibilities spanning the product lifecycle, manufacturing, engineering, logistics, planning, and quality management. Before MiniMed, he was VP of Quality for Medtronic's Diabetes Operating Unit. Prior to that, he spent seven years at Abbott as Divisional Vice President of Quality Assurance and Technical Services for Abbott Point of Care and Global Head of Quality for Abbott Molecular. He spent more than two decades at Baxter Healthcare in roles including Director of Quality for Global Medical Products and Director of Quality for Medication Delivery EMEA, based in Puerto Rico, Switzerland, and the United States.
Connect with Leland on LinkedIn here.
Who is The FDA Group?
The FDA Group helps life science organizations rapidly access the industry's best consultants, contractors, and candidates. Our resources assist in every stage of the product lifecycle, from clinical development to commercialization, with a focus on staff augmentation, auditing, remediation, QMS, and other specialized project work in Quality Assurance, Regulatory Affairs, and Clinical Operations.
With over 3,750 resources worldwide, over 325 of whom are former FDA, we meet your precise resourcing needs through a fast, convenient talent selection process supported by a Total Quality Guarantee.
Here’s why 17 of the top 20 life science firms access their consulting and contractor talent through us:
Resources in 75 countries and 48 states.
26 hours average time to present a consultant or candidate.
Exclusive life science focus and expertise.
Dedicated account management team.
Right resource, first time (95% success).
97% client satisfaction rating.
Talk to us when you're ready for a better talent resourcing experience and the peace of mind that comes with a partner whose commitment to quality and integrity reflects your own.
Subscribe to The Life Science Rundown:
Apple | Spotify | YouTube | Web + Others
Check out our newly launched AI-powered QMS audit tool, AICA (the Audit Intelligence Compliance Assistant).





