QA·IT Systems and data
Quality Management for IT Systems
Get organized first. Then validate. The first question in an inspection is simple: do you have a compliant inventory of your systems? We build the quality foundation (inventory, criticality, policies and controls) so validation stops being a heroic project and becomes a process.
Signals
When do you need it?
- You don't know how many GxP systems you haveOr which ones impact product quality or data integrity.
- Every validation turns out differentlyIt depends on who does it, because there are no QA IT policies setting the criteria.
- An inspection is coming upAnd the inventory is outdated or scattered across several spreadsheets.
- IT and Quality speak different languagesChanges, incidents and access are managed without shared traceability.
Approach
Validation is the tip of the iceberg
A system validated on a disorganized foundation falls out of control again with the first change. That's why we start with the structure: which systems exist, what risk each one carries, who owns it and how changes are controlled.
We connect IT's work with Quality Assurance. The result is a management system your team can sustain on its own, one that demonstrates control from the first minute of an audit.
A missing or disorganized inventory is the worst way to start an inspection. And the easiest one to avoid.
How we do it
Service stages
- 01AssessmentSystems, interfaces, documentation and current compliance level.
- 02CriticalityGxP classification by impact on product, patient and data.
- 03Master inventoryTechnical, functional and regulatory profile of each system.
- 04ControlsChanges, incidents, access, backup and suppliers.
- 05HandoverApproved policies and a team trained to maintain them.
Regulatory framework
What the regulations require, point by point.
These are the references we work with for this service. We apply the ones that fit your market and your type of product.
PIC/S Inspectors' reference guidance
- PIC/S PI 011-3Good practices for computerized systems in GxP environments: inventory, life cycle and responsibilities.
- PIC/S PI 041-1Data management and integrity in GMP/GDP environments.
EU GMP EudraLex Volume 4
- Annex 11 §3 and §4Supplier management and life cycle. An up-to-date system inventory is an explicit requirement.
- Annex 11 §10 to §12Change management, periodic evaluation and security.
ISPE GAMP 5 Second Edition (2022)
- GAMP 5Risk-based approach, software categories and life cycle governance.
- GPG Records & Data IntegrityALCOA+ principles and controls over electronic records.
FDA United States
- 21 CFR Part 11Electronic records and signatures: audit trail, access and system controls.
- Data Integrity and Compliance with CGMP (2018)FDA expectations on data integrity.
ISO Management systems
- ISO/IEC 27001Information security as a pillar of data integrity.
Deliverables
What you get.
Inspection-ready documentation, fully traceable and in your format. And a team trained to maintain it.
- Current-state assessmentGaps against Annex 11, Part 11 and GAMP 5, prioritized by risk.
- Master system inventoryWith GxP criticality, GAMP category, owners and validation status.
- Critical data flow mapWhere each GxP data point is created, transformed and stored.
- QA IT policiesFormal criteria for validating, changing, granting access to and retiring systems.
- Supporting proceduresChange control, incident management, backup, access and periodic review.
- Action plan and trainingA validation roadmap and a team trained to sustain the system.
FAQ
What clients ask before we start
Why not start with validation right away?
Because without an inventory or criticality criteria you can't prioritize. You end up validating a critical system and one with no GxP impact with the same intensity, and inspectors ask about the structure first.
What's the difference between a QA IT policy and an SOP?
The policy defines the criteria (what and why). The SOP describes how it's done. Without policies, each SOP interprets the regulations its own way.
Is this useful if our systems are already validated?
Yes. We check that existing documentation is still current and bring it into the inventory, without redoing what's already right.
Works well with
Related services
-
CSV
System validation (CSV)
LIMS, ERP, MES, SCADA or QMS that must prove they do what they claim.- GAMP 5 Second Edition
- 21 CFR Part 11
- EU GMP Annex 11
-
XLS
Excel spreadsheet validation
Spreadsheets that calculate results, yields or stability and that nobody has validated.- GAMP 5
- 21 CFR Part 11
- EU GMP Annex 11
-
SOP
SOP development
SOPs written for compliance that nobody reads, understands or follows.- 21 CFR 211.100
- EU GMP Chapter 4
- ICH Q10
Next step
Be ready for your next
regulatory challenge.
Tell us what you need to validate, qualify or document. In the first conversation we get to know your operation and tell you how we would approach it.