Industry Guidelines for Computerized Systems Validation (GAMP, PDA Technical Reports)

Similar documents
Sparta Systems Stratas Solution

Sparta Systems TrackWise Digital Solution

GxP Compliant Laboratory Computerized Systems (2 nd edition)

GAMP Good Practice Guide: The Validation of Legacy Systems

21 CFR Part 11 LIMS Requirements Electronic signatures and records

Sparta Systems TrackWise Solution

Summary of PIC/S Guidance Good Practices for Data Management and Integrity in Regulated GMP/GDP Environments

AUDITOR / LEAD AUDITOR PHARMACEUTICAL AND MEDICAL DEVICE INDUSTRY

Touchstone Technologies, Inc. Course Catalog February 2017

OMCL Network of the Council of Europe QUALITY ASSURANCE DOCUMENT

Real World Examples for Part 11 Technical Controls

21 CFR PART 11 FREQUENTLY ASKED QUESTIONS (FAQS)

White Paper Assessment of Veriteq viewlinc Environmental Monitoring System Compliance to 21 CFR Part 11Requirements

Risk Based EBRS Implementation using GAMP 5

GXP, E-RAW DATA AND E-ARCHIVE QA PERSPECTIVE

Meeting regulatory compliance guidelines with Agilent ICP-MS MassHunter and OpenLAB Server

Leveraging ALCOA+ Principles to Establish a Data Lifecycle Approach for the Validation and Remediation of Data Integrity. Bradford Allen Genentech

Rotronic Monitoring System Technical paper Version 1.0. Rotronic Monitoring System - Technical paper - Understanding RMS from an IT perspective

Agilent Response to 21CFR Part11 requirements for the Agilent ChemStation Plus

Assessment of Vaisala Veriteq viewlinc Continuous Monitoring System Compliance to 21 CFR Part 11 Requirements

FDA 21 CFR Part 11 Compliance by Metrohm Raman

ABB Limited. Table of Content. Executive Summary

Frequently Asked Questions UNIFI v1.9 Service Release 4 Upgrade

EU Annex 11 Compliance Regulatory Conformity of eve

System Assessment Report Relating to Electronic Records and Electronic Signatures; 21 CFR Part 11. System: tiamo (Software Version 2.

By Cornelia Wawretchek. The Drug Manufacturer s Guide to Site Master Files

SDA COMPLIANCE SOFTWARE For Agilent ICP-MS MassHunter Software

CONTROL SYSTEMS DESIGN SPECIFICATION

COURSE BROCHURE. COBIT5 FOUNDATION Training & Certification

Comment sheet for MHRA draft document:

Part 11 is Dead Long Live Part CFR 11, the Electronic Records and Electronic Signatures 21 CFR PART 11. Introduction

FOUNDATION CERTIFICATE IN INFORMATION SECURITY v2.0 INTRODUCING THE TOP 5 DISCIPLINES IN INFORMATION SECURITY SUMMARY

MHRA GMP Data Integrity Definitions and Guidance for Industry January Initial Review and Critique March 2015

Validation of a CMS Software

ISA99 - Industrial Automation and Controls Systems Security

An Easy to Understand Guide 21 CFR Part 11

System Assessment Report Relating to Electronic Records and Electronic Signatures; 21 CFR Part 11. System: StabNet (Software Version 1.

Data Integrity and the FDA AFDO Education Conference

BENEFITS OF EXCIPACT CERTIFICATION TO SUPPLIERS, USERS AND PATIENTS The role in Supplier Qualification. March 2011

MHRA GMP Data Integrity Definitions and Guidance for Industry March Introduction:

MATERIALS: Each participant will receive: The Certified Biomedical Auditor Primer, published by Quality Council of Indiana Certificate of Attendance

Good Computer Validation Practices

Good Laboratory Practice GUIDELINES FOR THE ARCHIVING OF ELECTRONIC RAW DATA IN A GLP ENVIRONMENT. Release Date:

Data Integrity for the Microbiology Laboratory

Alexion Pharma International Trading

21 CFR Part 11 FAQ (Frequently Asked Questions)

"Charting the Course... Certified Information Systems Auditor (CISA) Course Summary

Introduction. So what is 21 CFR Part 11? Who Should Comply with 21CFR Part 11?

Data Integrity for the Microbiology Laboratory

Avoid experiments in monitoring important parameters. Measuring instruments and solutions for the pharmaceutical, medical and healthcare industries

Position Description IT Auditor

Automated Cloud Compliance. GxP and 21 CFR Part 11 Compliance

ISO/IEC INTERNATIONAL STANDARD. Conformity assessment Supplier's declaration of conformity Part 1: General requirements

ETSI TR V1.1.1 ( )

EXCiPACT: taking an idea to global reality

Approaches for Auditing Software Vendors

HCL GRC IT AUDIT & ASSURANCE SERVICES

System Assessment Report Relating to Electronic Records and Electronic Signatures; Final Rule, 21 CFR Part 11

ITU Asia-Pacific Centres of Excellence Training on Conformity and Interoperability. Session 2: Conformity Assessment Principles

Integration of Agilent UV-Visible ChemStation with OpenLAB ECM

INFORMATION. Guidance on the use of the SM1000 and SM2000 Videographic Recorders for Electronic Record Keeping in FDA Approved Processes

Vaccine data collection tool Oct Functions, Indicators & Sub-Indicators

ETSI European CA DAY TRUST SERVICE PROVIDER (TSP) CONFORMITY ASSESSMENT FRAMEWORK. Presented by Nick Pope, ETSI STF 427 Leader

ISA99 - Industrial Automation and Controls Systems Security

ITIL Intermediate: Service Operation Lesson Plan. Included in Course (x2)

Jointly Organised by: Presenter: Certificates endorsed by the National. Training Grant is available under HRDF SBL Scheme

IPC Certification Scheme IPC Management Systems Auditors

EXAM PREPARATION GUIDE

CIP Cyber Security Configuration Change Management and Vulnerability Assessments

Security Monitoring Engineer / (NY or NC) Director, Information Security. New York, NY or Winston-Salem, NC. Location:

End-to-end Safety, Security and Reliability Keys for a successful I4.0 Migration

ILNAS/PSCQ/Pr004 Qualification of technical assessors

October p. 01. GCP Update Data Integrity

ENISA s Position on the NIS Directive

BRE Global Limited Scheme Document SD 186: Issue No December 2017

Medical Device Cybersecurity: FDA Perspective

Organisation de Coopération et de Développement Économiques Organisation for Economic Co-operation and Development

CA ELAP Expert Review Panel Meeting January 31, EPA Perspective: Effective Laboratory Certification Program Implementation

EXAM PREPARATION GUIDE

System Assessment Report Relating to Electronic Records and Electronic Signatures; Final Rule, 21 CFR Part 11. System: tiamo 2.3

Conformity assessment Requirements for bodies providing audit and certification of management systems. Part 6:

Compliance Matrix for 21 CFR Part 11: Electronic Records

± ± ± ± ± ± ± ± ± ± ± ± ± ñ ± ± ƒ

YEAR Endorsed by: Training Grant is available under HRDF SBL Scheme

ASSURING DATA INTEGRITY LIFE SCIENCES FOR. Edited by Siegfried Schmitt.

Security Training Seminars An integral part of The Open Group Security Programme

Introduction to ISO/IEC 27001:2005

An Introduction to the ISO Security Standards

BHConsulting. Your trusted cybersecurity partner

Data Integrity: Technical controls that demonstrate trust

Compliance of Shimadzu Total Organic Carbon (TOC) Analyzer with FDA 21 CFR Part 11 Regulations on Electronic Records and Electronic Signatures

This Document is licensed to

DATA INTEGRITY (EMA AUGUST 2016)

VALIDATION PRINCIPLES AND PRACTICES FOR THE MEDTECH INDUSTRY

Data Integrity and Electronic Records Compliance with DoseControl

Part 11 Compliance SOP

FRAMEWORK MAPPING HITRUST CSF V9 TO ISO 27001/27002:2013. Visit us online at Flank.org to learn more.

Understanding Particle Counter Technology and the risks of data integrity of particle counts. by Jason Kelly

EXAM PREPARATION GUIDE

Solutions Technology, Inc. (STI) Corporate Capability Brief

Transcription:

Training Course Computerized System Validation in the Pharmaceutical Industry Istanbul, 16-17 January 2003 Industry Guidelines for Computerized Systems Validation (GAMP, PDA Technical Reports) Wolfgang Schumacher Roche Pharmaceuticals, Basel

Agenda New Trends GAMP Categorization Risk GAMP SIGs IT infrastructure PDA technical reports

2001 / 2002 - Busy Years for Guidances PIC/S Draft Guidance - Good Practices in the GxP Regulated Environment Many FDA Guidances (21 CFR Part 11) GAMP 4 and other GAMP Guidances GERM documents (21 CFR Part 11)

FDA Guidances FDA - General Principles of Software Validation FDA - 21 CFR Part 11 Guidances Glossary Validation Time Stamps Maintenance Copies

Industry Guidance ISPE Calibration Management - practical approach to calibration management - regulatory, quality, safety and environmental issues - instrument criticality assessment - instrument lifecycle approach - examples as appendices GAMP Good Practice Guide Calibration Management

GAMP 4 Strategic Principles Structure Project Management Project Development Operational Support Good Practice Guidance

GAMP 4 Strategic Principles Scalability of GAMP approach Leverage of suppliers expertise Guidance on maintaining validated state Harmonisation of terminology Raise awareness internationally Collaboration with other industry groups

GAMP 4 Structure Strategic Framework Quality Management Procedures Good Practice Guidance Training and Education Materials

GAMP 4 Lifecycle Continuity User Requirements Specifications related to Performance Qualification Functional Specifications related to Operational Qualification Design Specifications related to Installation Qualification System Build

Customer - Supplier Relationship Primary Responsible for Specification Primary Responsible for Testing User User Requirements Specification Testing of the URS User User and Supplier Supplier Functional Specification Hardware Design Specification Software Software Design Design Specification Specification Software Software Module Module Specification Specification Testing of the Functional Specification Testing of the Hardware Specification Code Modules Code Modules System System Acceptance Acceptance Testing Testing (Operational (Operational Qualification Qualification of of Computer/PLC) Computer/PLC) Hardware Hardware Acceptance Acceptance Testing Testing (Installation (Installation Qualification Qualification of of Computer/PLC) Computer/PLC) Software Integration Software Integration Testing Testing Software Module Testing Software Module Testing Review and Test Modules User and Supplier Supplier

The GAMP 4 Software Categorization System Category Type of Software Validation Approach 1 2 3 4 5 Operating Systems Firmware Standard Software Packages Configurable Software Packages Bespoke Systems Record version, check applications Record configuration, test functions Document requirements, Validate application Audit supplier, validate application and any bespoke code Audit supplier and validate complete system

What about Tools? Development tools Test tools Monitoring tools Question: Standard or Customised? Customised tools need validation Change control for upgrades

The GAMP 4 Hardware Categorization System Category Type of Software Validation Approach 1 Standard Hardware Components IQ, installation and connections 2 Custom-built Hardware IQ, design specification, acceptance testing Category 1 standard hardware Category 2 customised hardware

Project Development and Implementation - Risk Considerations 1 Risk Assessment much more significant each system function evaluated for risk (GxP and Business) for severity of impact for probability of detection before impact Guidance available (annex to GAMP 4)

Project Development and Implementation - Risk Considerations 2 Mitigation strategies discussed modification of process or design: avoidance, process design, system design, external process project strategy: Project structure, auditable built-in quality validation strategy: modify test strategy rigour

Benefits of Risk Assessment little or no validation for low risks more focus on higher risks communicating risks focussed training regulatory confidence

GAMP 4 - Quality Management Procedures The Management Appendices M 1 to M 10 Revised Quality Management Guidelines Project management and control Project development Operational support

GAMP 4 - Project Management and Control Validation Planning Quality and Project Planning Document Mangement Risk Management Design Review - including Traceability Analysis Project Change Control Configuration Management Validation Reporting

GAMP 4 - Good Practice Definitions (11.1( to 11.3) Revised good practices Good documentation practice Good testing practice Good engineering practice

GAMP 4 - Operational Support Guidelines Backup and Recovery Business Continuity Planning Operational Change Control Performance Monitoring Periodic Review Record Retention, Archive and Retrieval Security Service Level Agreements

GAMP Good Practice Guidance (Topics Under Consideration) Legacy Systems Infrastructure Process Systems Skid Mounted Equipment Calibration* Electronic Records and Signatures* Analytical Laboratory Equipment Global IT Systems Good Engineering Practice Web-based Applications * Published

IT Infrastructure - Important Aspects design specification layout and hierarchical drawings installation records change control

The IT Infrastructure elements 1 2 GxP-relevant business applications dealing with GxP-data 2 3 GxP-relevant infrastructure that delivers a qualified platform Network (WAN/LAN) Back-end (servers) Front-end (desktops) Platforms and middleware* Key processes 1 2 Frontend Backend Business Key Platforms Network Middleware Processes * also called enablers, core or base applications Applications

IT Infrastructure - the Qualification Lifecycle Qualification Certificate 1. Planning create Qualification Qualification Report Plan Qualification Qualification Report Report compile 5. Review & Report Change Control 2. Specification create Technical Design- Specification Functional Specification Requirement or Service Specification 4. Testing 3. Define test & acceptance criteria execute create OQ Report IQ Form IQ Report OQ Form

The APV interpretation of Annex 11 EU Guide to GMP Published already in 1994 Regulators contributed to interpretation Good document, easy to read Contains many useful information English translation in GAMP 4 Recommended reading for CSV beginners APV: Arbeitsgemeinschaft Pharmazeutische Verfahrenstechnik

PDA Technical Report No. 18 Validation of Computer Related Systems Published in 1994 Consultants contributed to guidance Contains advanced, but useful information Recommended reading for CSV beginners Can be ordered via PDA PDA: Parenteral Drug Association

PDA Technical Report No. 31 Validation and Qualification of Laboratory Data Acquisition Systems (LDAS) Published in 1999 Contains advanced information for LDAS system owners Recommended reading for LDAS experts Can be ordered via PDA PDA: Parenteral Drug Association

PDA Technical Report No. 32 Auditing of Suppliers providing computer products for regulated pharmaceutical operations Published in 1999 Contains advanced information for auditors of computerized system suppliers Recommended reading for Auditors Can be ordered via PDA PDA: Parenteral Drug Association