Saturday, July 24, 2010

Compliance Risk Management Using a Top-Down Validation Approach 6

Validation doesn't replace any of the required CGMP activities, it merely confirms their appropriateness. There is no substitute for sound process design and development, and of course CGMP compliance in all activities. Validation failures are not a consequence of the validation, but rather of poor designs, inadequate development, or CGMP problems in operations. In essence, validation only serves to keep score.
The inability to validate a process or product is usually associated with one or more of the following causes:
  • Inadequate development (poor science)
  • Poor process control (inferior equipment or poor maintenance)
  • Inadequate instructions (poor documents or sloppy development)
  • Lack of knowledge (poor science or engineering)
  • Poor validation practice (inadequate know-how).

Examples of top-down application
The following examples are drawn from real-life situations where the validation and quality focus was misdirected because the firm had lost sight of the objectives they were striving for. In each case, end-product quality was placed at risk because of inappropriate priorities in the validation or control of other processes Environmental worries trump sterilization. One firm was experiencing a significant failure rate in its bioreactors (close to 20%), which was greatly reducing its ability to support product sales. Investigation into the problem revealed that steaming-in-place of the system was being hampered by faulty steam traps and back pressure in the condensate line. When pressed to allow the traps to discharge into the surrounding ISO-8 room, the firm's environmental-quality unit objected that the condensate would degrade the environmental conditions in the room. The ability to sterilize the bioreactors and produce contamination-free products was compromised to protect an environment without product contact.
Pursuit of sterilization effectiveness risks microbial contamination. Parts for aseptic compounding and filling were sterilized as individual components to ensure maximum exposure during the steam-sterilization process. After sterilization, the individual parts were assembled aseptically into the final fluid-handling system. The risk of contamination during the assembly was ignored in pursuit of better sterilization. The firm relied on media fills to support the efficacy of this process.
The effect of the top-down approach
The top-down approach focuses the validation on the key quality attributes of the product rather than on less critical concerns. The products manufactured in this industry are intended to serve the patient, whose needs must be paramount in the development of any validation effort. Validation began as a means to ensure sterility and protect patient welfare. It is essential that as the industry maintain a connection between what it is endeavoring to do and whom it is doing it for. The patients deserve the safest and most efficacious products possible, and the cost to provide them should be realistic as well. Misplaced efforts that fail to support patient needs are anathema.
The approach described in this article is inherently risk-based because the validation activities that directly affect critical product-quality attributes are given the greatest emphasis and priority over potentially conflicting, but certainly less important indirect concerns. Validation efforts must focus on patient needs. Risk-based validation is a significant step in the right direction. Remember, "If a thousand people do a foolish thing, it is still a foolish thing." 
References
1. FDA, "Proposed Current Good Manufacturing Practices in the Manufacture, Processing, Packing or Holding of Large Volume Parenterals," Fed. Regist. 41 (106), 22202–22219 (June 1, 1976; Rescinded-Dec. 31, 1993).
2. FDA, "Preapproval Inspections/Investigations" CPGM 7346.832, http://www.fda.gov/cder/dmpq/CPGM7346832.htm, accessed June 9, 2008.
3. ISPE, Commissioning and Qualification, Baseline Guide, (Tampa, FL, 2001).
4. American Society for Testing and Materials, E2500-07—Standard Guide for Specification, Design, and Verification of Pharmaceutical and Biopharmaceutical Manufacturing Systems and Equipment (West Conshohocken, PA, 2007).
5. FDA, "Guideline on Sterile Drug Products Produced by Aseptic Processing," 2004, http://www.fda.gov/cder/guidance/5882fnl.htm, accessed June 9, 2008.
6. FDA, "21 CFR 210.1 (a)," Fed. Regist. 43 (45076), (Rockville, MD, 1978).
7. ASTM, E2500-07—Standard Guide for Specification, Design and Verification of Pharmaceutical and Biopharmaceutical Manufacturing Systems and Equipment (West Conshohocken, PA, 2007).
8. K. Chapman, "The PAR Approach to Process Validation," Pharm. Technol. 8 (12), 22–36, 1984.
9. FDA, "Guidance for Industry, PAT—A Framework for Innovative Pharmaceutical Development, Manufacturing, and Quality Assurance" (Rockville, MD, 2004).
10. B. Spiller, "Process Validation of Solid Dosage Forms," in proceedings of Manufacturing Controls Seminar (The Proprietary Association, Cherry Hill, NJ, 1979), pp. 17–31.

Compliance Risk Management Using a Top-Down Validation Approach 5

What is PQ?
The term "performance qualification" (PQ) was developed to clarify the distinction between the process and product efforts and those related to equipment. It was a way to distinguish between the equipment-focused activities (e.g., installation, operational, or equipment qualification) and those related to the product or process (i.e., PQ). Certain firms call the product and process effort "process validation," but this term is by no means universal. Coincidently, PQ can also stand for "process qualification" or "product qualification." Fortunately, though these terms have been expressed, neither has seen widespread use. It might be advisable to consider yet another definition of the acronym PQ: "product quality." The author believes it best to use the term "performance qualification" for activity that focuses on the essential quality attributes of the product as delivered by the process. It must be recognized that the process and product cannot be separated. One is the result of the other, and knowledge of their interaction is critical to success.
The PQ of a pharmaceutical process must demonstrate how the process ensures product quality. The completed effort must demonstrate how the independent variables of the process (i.e., temperature measurement, addition rate, mix speed, and mix time) result in a product that meets its defined quality attributes (i.e., content uniformity, viscosity, and color).
The recommended approach to PQ considers process parameters, product attributes, and their interrelationship. Only in combination can a process or product validation be properly addressed. The link between process parameters and quality attributes should be established during the developmental process and documented in technology-transfer reports. The development must determine the relationship between the important process parameters and product attributes such as:
  • Drying time and moisture content
  • Mixing time and content uniformity
  • Reaction conditions and impurity levels.

Establishing the link between parameters and attributes during the developmental process facilitates the execution of the process on the commercial scale. Kenneth Chapman's classic article, "The PAR Approach to Validation," provides an excellent example of the need to link the independent process parameters and the resulting dependent quality attributes (8). Independent variables are established by the pharmaceutical manufacturer as necessary for successful process operation and include aspects such as equipment operating set points, operating instructions, material and equipment specifications, required in-process tests, mole ratios, and addition rates. Each of these can be chosen to realize the desired outcome as defined by the dependent variables. The dependent variables are product attributes that are the result of applying the selected independent variables. The goal of the development is to determine the relationship between the independent and dependent variables and use that knowledge to ensure an acceptable outcome. The more that is known about that relationship, the more robust the process and the more likely that the performance qualification will be a success.
Successful performance qualification is a largely a result of sound development and adherence to CGMP on the commercial scale. To accomplish this, it is critical that firms understand the importance of a development effort that increases their process knowledge. A trendy term for this information is the "design space," and the overall effort has been termed "quality by design." Much of these ideas were embodied in FDA's recent initiative on risk-based compliance, which declared the attainment of process knowledge to be essential (9). That this effort and new terminology are necessary only indicates how misguided validation efforts have become in recent years. The following modest paraphrase of an early definition of validation is an appropriate way to consider process development efforts: "The goal of development (validation) is to identify the process variables necessary to ensure the consistent production of a product or intermediate (10)."
Development is not about great science; it's about robust processes that make quality products consistently.
The product- and process-qualification activities should be the centerpiece of the any firm's validation effort. Any loss of focus wastes resources and risks patient safety. We must maintain a clear link between what we are doing and what we are trying to achieve.

Compliance Risk Management Using a Top-Down Validation Approach 4

Identity addresses:
  • Chemical structure
  • API synthesis
  • Bulk labeling
  • Primary-container label
  • Product name
  • Dosage
  • Lot number
  • Expiration date
  • Barcode
  • Secondary-container labeling
  • Product name
  • Product insert.

Strength includes consideration of:
  • Potency
  • API synthesis
  • Bulk-package integrity
  • Final-package integrity
  • Storage conditions
  • Shipping conditions
  • Stability
  • Bulk material
  • Presterilization
  • Poststerilization
  • Finished goods.

Other concerns
The previous lists include the primary concerns. Others considerations include:
  • Stopper coreability
  • Stopper and glass siliconization
  • Stopper moisture content
  • Intermediate-package cleaning
  • Intermediate-package integrity
  • API facility environmental conditions
  • Fill-isolator integrity.
Analytical support to validation. To properly evaluate critical quality attributes, validated analytical methods are required. Validating a pharmaceutical process or product before the test methods used to evaluate it are validated severely limits the quality of the data and thus jeopardizes the entire effort. It is pointless to perform any analysis without being confident that the results can be considered reliable.
Sampling for microbial and foreign matter. Sampling methods can also play a major role in perceived and actual quality, especially as related to microbial and particulate (absence of foreign matter) quality. Taking a sample in these instances can harm the very property the sample is intended to evaluate. Sample procedures must be designed to avoid incidental contamination of the production materials and samples. Microbiological and foreign-matter test methods should incorporate appropriate controls to ensure the results are indicative of the material and not the test method itself.
System-performance qualifications. In addition to the product-quality attributes described above, the validation of other essential systems is necessary. The most important of these are water and environmental-control systems that have a significant albeit indirect effect on the product-quality attributes. Other systems with a less clear effect on end-product quality may be assessed in a less comprehensive manner. Utilities such as steam, compressed air, and jacket services, ordinarily do not have a direct effect on the key quality concerns and can be placed into service by commissioning rather than formal qualification. The American Society for Testing and Materials has developed an expanded analysis of risk-based qualification for pharmaceutical systems (7).

Compliance Risk Management Using a Top-Down Validation Approach 3

An example product applying the top-down approach

Figure 2
A sterile dry powder is filled into vials without excipients for later reconstitution with a sterile diluent (see Figure 2). The API is gamma-irradiated in bulk before the aseptic fill. The validation effort must support the methods and practices that ensure the product's critical quality attributes. In this example (and most others), it should be immediately evident that the various quality concerns will overlap to some extent. The critical quality attributes for this product (excluding the need for a sterile diluent, which should undergo a separate assessment) are:
  • Safety—sterility, endotoxin control, foreign matter, container-closure integrity, residual solvent
  • Purity—impurities, foreign matter, lack of cross-contamination
  • Efficacy—particle size, crystal morphology, weight control, shipping studies
  • Identity—chemical structure, labeling
  • Strength—potency, stability.

Each of these primary considerations must be defined to identify the individual qualification or validation activities required to support the quality attribute in total. Product safety requires many studies, including:
  • Aseptic filling capability
  • Sterilization of bulk powder
  • Sterilization or depyrogenation of glass containers and rubber closures
  • Sterilization of product-contact equipment
  • Sterilization of utensils
  • Filling-isolator decontamination
  • Environmental monitoring of the isolator environment
  • Water for injection systems at API, and fill–finish facility (i.e., endotoxin control)
  • Cleaning of API equipment
  • Cleaning of fill–finish equipment
  • Cleaning of empty bulk containers
  • Cleaning of container or closure
  • Bulk-container integrity
  • Final product container-closure integrity
  • Shipping studies
  • Validation of API drying.

Product purity requires attention to:
  • Impurity profiles
  • API process validation
  • API equipment cleaning
  • Foreign-matter removal
  • Absence of cross-contamination from prior products
  • Cleaning validation for API
  • Cleaning validation for fill–finish equipment
  • Bulk-container preparation
  • Container preparation
  • Stopper washing
  • Vial washing.

Efficacy mandates attention to:
  • Particle size (i.e., crystallization process)
  • Crystal morphology
  • API process validation
  • Suitability with filling equipment
  • Weight control
  • Filling equipment qualification
  • Shipping studies
  • Effect of pressure, temperature, and relative humidity
  • Bulk-powder stability (pre and poststerilization)
  • Filled-container stability.

Compliance Risk Management Using a Top-Down Validation Approach 2



These incidents resulted in deaths and serious injury to patients. Specific regulations in the US and elsewhere were instituted to force conformance to basic canons of pharmaceutical GMPs. Globally, firms must adhere to a defined set of CGMPs that ensure product safety. These practices can be summarized by seeking the following characteristics in all development and production activities:
  • Safety—a drug does no harm to the patient
  • Purity—a drug is free of contamination
  • Efficacy—a drug works as intended
  • Identity—a drug is what its supposed to be
  • Strength—a drug is sufficiently potent.

These qualities are briefly stated in FDA's CGMPs:
... this chapter contain[s] the minimum current good manufacturing practice for methods to be used in, and the facilities or controls to be used for, the manufacture, processing, packing, or holding of a drug to assure that such drug meets the requirements of the act as to safety, and has the identity and strength and meets the quality and purity characteristics that it purports or is represented to possess (6).
If we focus our intention on those elements of pharmaceutical operations that directly affect those concerns and pay reduced attention to activities whose effect is less apparent, the validation activities will have true meaning and purpose and be inherently risk-based. Addressing process and product validation properly
The product is the result of the process. The process exists only to make the product. The two are unalterably linked. We cannot speak of validating a process without evaluating the product, nor could we somehow support the efficacy of a product without knowledge of its underlying process. They exist in combination and must be evaluated in the same fashion. A product results from the process through the procedures applied to materials in a piece of equipment. In its simplest form, the product might be a single material such as an active pharmaceutical ingredient (API) transformed by a process such as sterilization, which, when filled into a suitable container, results in a parenteral dosage form. More commonly, the product is composed of many materials and undergoes several transformational processes before it is considered a drug product. The drug product can be considered the consequence of three primary elements:
  • Materials and components—the API, excipients, and its final product container
  • Batch records, standard operating procedures, and test methods—the instructions and practices that define the process steps and are the means for evaluating the product
  • Equipment and facilities—the mechanical systems that effect the material transformation.


Figure 1
The production of the drug product takes place in a CGMP environment under quality systems that provide the necessary controls to ensure the required quality attributes are attained (see Figure 1). The validation effort provides documented evidence of the controls' effectiveness. To properly validate any product or process, we must focus on the critical quality attributes of the specific drug product and the parts of the overall system that directly affect those attributes. To the extent that a material, piece of equipment, process utility, control system, or operating procedure affects one or more of those critical attributes, it requires greater attention in the overall validation exercise. Treated in this manner, the validation effort is inherently risk-based.

Compliance Risk Management Using a Top-Down Validation Approach 1

Validation has been an established fact of life within the pharmaceutical and healthcare industries since the mid-1970s. It has evolved from a poorly understood concept into a major source of difficulty for manufacturers. Initially conceived in response to specific sterility problems in the large-volume parenteral industry, it has morphed into a broad-based regulatory expectation for a myriad of activities. In the healthcare industry, the difficulties associated with validation have much to do with its origins. Validation in the pharmaceutical industry was imposed on the pharmaceutical industry by regulators as an appropriate means to establish the sterility of large-volume parenterals where the earlier control methods had proved inadequate (1). Because it was first associated with the preparation of sterile materials, validation has always been pursued with a near-absolutist mentality in all aspects. It has never been considered a valuable activity, likely because of its regulatory origins, but one that is largely associated with maintaining compliance.
Where did we go wrong?
Nearly every early validation effort was focused on sterilization and depyrogenation processes, and this focus continued to predominate until the 1990s. Real consideration of the need to validate pharmaceutical products with respect to their critical quality attributes did not begin until the US Food and Drug Administration began its preapproval-inspection program (2). This initiative brought attention to what had largely been missing in validation efforts previously. What are the true objectives of validation in the broadest sense? The answer is rather simple: patient safety considerations must be the focus of validation activities. The sterility concerns of the 1970s might represent the most direct evidence of that focus, but other relevant patient-protection items must be addressed. Validation efforts must be properly defined and focused to the extent that they support patient needs. The value of validation diminishes markedly when it fails to focus on factors that clearly affect the patient's well-being. Excessive levels of documentation of systems with little link to the patient are all too commonplace. Risk, as it relates to how the validation effort should be shaped, has not been fully considered until quite recently (3, 4). The result is that costs are excessive, timelines are extended unnecessarily, and an entire industry is developed around preparing massive documents qualifying and validating increasingly irrelevant components of the overall manufacturing process.
An excellent example of this trend might be the delayed introduction of isolation technology into the US healthcare industry. Early implementation of the technology was hampered by efforts to eliminate leaks in the system, evaluate the microbial resistance on every substrate, sterilize the interior to a 1 in a million probability of a nonsterile unit, and other matters of little import. These endeavors wasted resources and greatly delayed the implementation of what is widely acknowledged to be a superior aseptic processing technology. These tasks were considered important for ensuring the sterility of the materials produced using isolators.
Although a degree of caution is always necessary, these concerns were clearly off target. Cleanrooms, which have never been sterile, have always leaked, and there are a myriad of substrates treated in a much less effective manner. In pursuit of the perfect isolator, firms lost sight of the real point: the substantial improvement in patient safety that isolation technology afforded. Isolators are inherently safer than cleanrooms and preferable in every way as an aseptic production technology. The hours spent on resolving these allegedly important issues delayed isolator implementation by nearly a decade. The perceived "problems" with isolators persist to this day, and FDA's 2004 aseptic processing guidance contains several misconceptions regarding isolators (5). Lack of awareness about how isolators benefited patients served no one's purposes.
Regulatory perspective
Globally, regulators understand their mission to be one of safeguarding patient health by ensuring that drugs are safe to administer. In the US, a steady evolution of drug regulation shaped the current environment in which the industry operates. The landmark events that resulted in the current good manufacturing practices (CGMPs) industry follows include:
  • Nostrums in the late 19th century that led to FDA's creation in 1906
  • Diethylene glycol erroneously used in drug products in the 1930s
  • Thalidomide administration to pregnant women outside the US in the 1950s
  • Large-volume parenteral sterility failures in the 1970s
  • Tylenol poisoning in the 1980s.

Risk-Based Validation of Commercial Off-the-Shelf Computer Systems 9



Figure 3: Validation tasks for system risks and GMP categories, showing only validation phases.
The principle is shown for early validation phases in Figure 3. Of course, to generate such information is more time consuming and only makes sense if several systems in GAMP category three or five should be validated. Conclusion
Risk analysis and evaluation of software and computer systems is a good tool to optimize validation costs by focusing on systems with high impact on both the business and compliance. Substantial cost savings are possible for medium and low-risk systems. Validation activities of a low-risk system can be limited to documenting which systems have been used. The risk is less dependent on the type of system than on the type of records generated by the system. For example, a LIMS system used in a research environment has a lower compliance risk than the same system used in pharmaceutical quality control.
Regulatory agencies require companies to base the extent of validation they complete on a justified and documented risk assessment. To do this efficiently, we recommend the following steps: 1. Develop a risk management master plan. This describes the company's approach to risk assessment and has templates and examples for easy and consistent implementation. This plan should also include validation tasks for each risk category.
2. Develop a risk management project plan for each computer system validation project. Use the risk management master plan approach as a source to define steps, owners, and deliverables.
3. Identify risks, possible hazards and harms and define the risk category, for example: high, medium, and low. This should be based on likelihood and severity. To estimate the severity, look at the records handled by the system and at their impact on product quality and consumer safety.
4. Determine validation tasks for each lifecycle phase. Use the approach, templates, and examples from the risk management master plan
5. Develop a risk management plan with a sound justification and the documentation of your results.
For the long term, we recommend that risk assessment be extended to full risk management with an action plan for risk mitigation and on-going review and control.
Ludwig Huber, PhD, is a compliance program manager at Agilent Technologies, tel. 1 49 7243 602 209,
References
1. "GAMP Good Automated Manufacturing Practice, Guide for Validation of Automated Systems in Pharmaceutical Manufacture," Version 3, March 1998, Version 4, December 2001.
2. US Food and Drug Administration,"Pharmaceutical CGMPs for the Twenty-First Century: A Risk-Based Approach," http://www.fda.gov/oc/guidance/gmp.html and "FDA Issues Final Report on its '21st Century' Initiative on the Regulation of Pharmaceutical Manufacturing," http://www.fda.gov/bbs/topics/news/2004/NEW01120.html (Rockville, MD, Sept. 2004).
3. US FDA, General Principles of Software Validation: Final Guidance for Industry and FDA Staff, (FDA, Rockville, MD, Jan. 2002).
4. US FDA, Guidance for Industry. Part 11, Electronic Records; Electronic Signatures—Scope and Application (FDA, Rockville, MD, Aug. 2003).
5. Pharmaceutical Inspection Convention, Good Practices for Computerized Systems Used in Regulated Environments (PIC/S, Geneva, Switzerland, Jan. 2002).
6. US FDA, Code of Federal Regulations, Title 21, Food and Drugs, Part 11 "Electronic Records; Electronic Signatures; Final Rule; Federal Register 62 (54), 13429-13466. 
7. Pharmaceutical Inspection Convention, Good Practices for computerized Systems in Regulated "GXP: Environments, (DRAFT) (PIC/S, Geneva, Switzerland, Jan. 2002).
8. DIA/FDA Industry Training Session, May 2003.
9. H. Mollah, "Risk Analysis and Process Validation," BioProcess Int., 2 (9),(2004).
10. ISO 14971:2000, "Medical Devices—Application of Risk Management to Medical Devices," (ISO, Geneva, Switzerland, 2000).11. Labcompliance, Risk Management Master Plan, 2004.
12. G. Stoneburner, A. Goguen, and A. Feringa, Risk Management Guide for Information Technology Systems. Recommendations of the National Institute of Standards and Technology," NIST Special Publication 800-30 (NIST, Gaithersburg, MD, July 2002).
13. PhRMA, "Letter to the FDA, Related to Proposed FDA Guidance on the Scope and Implementation of 21 CFR Part 11," on Oct. 29, 2001.
14. International Society for Pharmaceutical Engineering, White Paper, "Risk-Based Approach to 21 CFR Part 11," (ISPE, Tampa, FL, 2003).
15. J. Murray at the Institute of Validation Technology "Computer System Validation" conference, May 2004.
16. "Qualification and Validation," Annex 15 to the EU Guide to Good Manufacturing Practice, 2001.
17. ISPE, GAMP Good Automated Manufacturing Practice, Good Practice Guide: A Risk-Based Approach to Compliant Electronic Records and Signatures(ISPE, Tampa, FL, Feb. 2005).

Risk-Based Validation of Commercial Off-the-Shelf Computer Systems 8

Examples of low-risk systems include word processing systems that are used, for example, to generate validation records. The reasons for relegating these systems to the low-risk category include the relatively low likelihood that they would have errors, the likelihood that errors would be detected by proofreading, and, in this case, the likelihood that such errors would have no direct impact on product quality or patient safety.
Validation tasks
Once the risk level is identified, validation steps can be defined. Risk level information is used for considerations such as:
  • In what detail do we specify the system? For example, for a low-risk system, we only prepare a high-level system description and for high-risk systems we develop detailed system requirement specifications.
  • How extensively do we test the computer system? For example, high-risk systems will be tested under normal and high load conditions. Test cases should be linked to the requirement specifications.
  • How much equipment redundancy do we need? For example, for high-risk systems we should have validated, redundant hardware for all components. For medium-risk systems, redundancy of the most critical components is enough, and for low-risk systems, there is no need for redundancy.
  • How frequently must we back-up data generated by the system? While a daily back-up is a must for high-risk systems, weekly incremental back-up is sufficient for low-risk systems.
  • What type of vendor assessment is required? For example, high-risk systems will require vendor audits while, for medium and low-risk systems, an audit checklist and documented experience from the vendor should be enough.
  • What requirements of Part 11 should be implemented in the computer system? For example, high-risk systems' computer generated audit trails should be implemented, while for low-risk systems, a paper-based, manual audit trail is enough.

Validation tasks should be defined for each phase starting from planning through specification settings, vendor qualification, installation, testing, and on-going system control. The tasks should be consistent within an organization for each risk category. They should be well documented and be included either in the risk management master plan or in the validation master plan.


Table IV: Examples of validation tasks.
Table IV summarizes examples with validation activities for each validation phase and task. For some validation tasks other factors should be considered besides the impact of the system on product quality. One such factor is vendor qualification. The question of how much to invest depends on two factors: product risk and vendor risk. Factors that impact vendor risk include:
  • experience with the vendor (software quality, responsiveness and quality of support);
  • size of the company;
  • company history;
  • represented and recognized in industry, e.g., Bio/Pharma;
  • expertise with (FDA) regulations;
  • future outlook;
  • How likely is the company to stay in business?

Table IV is recommended as a starting point for a commercial, networked Off The Shelf (OTS) system with user specific configurations (i.e., network configurations). Such an automated system would fall into category four, as defined by GAMP (1). This table can be extended to a third dimension to include systems or software that have been developed for a specific user (GAMP category five) and to include systems that do not require any user specific configurations (GAMP category three). GAMP categories indicate the level of system customization. The extent of validation is lower for GAMP category three and higher for systems in GAMP category five.

Risk-Based Validation of Commercial Off-the-Shelf Computer Systems 7

In the meantime, such VMPs have become a legal requirement in Europe through Annex 15 of the European GMP directive (16). The US FDA may not ask for a VMP; the inquiry may be for the company's approach to validation. The VMP, and the examples it contains, has become the perfect document to help answer any question about the level of validation.
An equivalent document in the area of risk assessment is a risk management master plan. Such a document should be developed at a fairly high level within the company. It should describe the company approach to risk management and assessment and should include templates for risk identification, evaluation, mitigation, and control. It also should include criteria and examples for severity and probability. The master plan can be used to derive risk management plans for individual projects. The main advantages are increased efficiency, and, even more importantly, consistent implementation.
A risk management master plan should also include examples of factors that impact risk categories. This is important to ensure a consistent approach in the company risk assessment. An example with some recommendations is shown in Table II.
ExamplesExamples are quite useful for getting an idea of what type of systems fall into the different categories. Another type of question that is frequently posed is whether, for example, a laboratory management system or a documentation system falls in the high, medium, or low-risk category. Sometimes even systems from specific vendors are mentioned. This is the wrong question. The risk is not dependent mainly on the system but more on the records created, evaluated, transmitted, or archived by the system.
A Laboratory Information Management System (LIMS) in a non-regulated research department is not a high-risk system, at least not from a compliance view. On the other hand, a LIMS in a pharmaceutical quality control laboratory is most likely a high-risk system because the records have a high impact on product quality.
Both the International Society for Pharmaceutical Engineering (ISPE) and the Pharmaceutical Research and Manufacturing Association (PhRMA) have given examples for what may qualify as high-risk. The PhRMA wrote a letter to the FDA on Nov. 29, 2001 related to the "Proposed FDA Guidance on the Scope and Implementation of 21 Code of Federal Regulations (CFR) Part 11." The letter included a ranking of five systems related to their risk on product quality. Those with the highest risk were manufacturing batch records and manufacturing LIMS and Quality Assurance (QA) systems (13).
The ISPE wrote a white paper on the "Risk-Based Approach to 21 CFR Part 11" with the recommendation that the focus of efforts should be on records that have a high impact, i.e.: those records upon which quality decisions are based. Examples of high impact records include batch records and laboratory test results (14).
Examples of records with low impact include environmental monitoring records not affecting product quality, training records, and internal computerized system information such as setup and configuration parameters. Other examples are planning documents and Standard Operating Procedures (SOPs) for non-critical operations.
GAMP has published a Good Practices Guide: A Risk Based Approach to Compliant Electronic Records (16). This document illustrates examples of records that have high, medium, and low impact on risk.
In general, systems fall into the high-risk category when they have a direct impact on product quality and patient safety. Examples are systems used in pharmaceutical manufacturing and quality control such as electronic batch record systems, analytical control systems, also document management systems and data bases with high-risk records. For example, wrong analytical test results that are used as a criterion to release a batch are highly critical, because there is no further testing and the product is released to the market immediately. An example of a system with high impact on patient safety is a distribution record system. If a product must be recalled because adverse effects on patients have been identified and some of the distribution records are lost, incorrect, etc., the product cannot be completely removed from the market, thereby having a high impact on patients.
Examples of systems in the medium-risk category include systems that are used to qualify and monitor the systems defined as high-risk. These would also include configuration management software.

Risk-Based Validation of Commercial Off-the-Shelf Computer Systems 6

Business continuity.
  • System must run 24 hours a day, 7 days a week.
  • Highly complex hardware, software, and system configuration;
  • Highly customized;
  • Unskilled operators;
  • No work-around solutions;
  • Vendor unrecognized in the pharmaceutical industry; no support from vendor, e.g., no documented evidence on validation during development, or no phone or on-site support in case of problems.

Compliance.
  • Used for GXP-regulated applications
  • System failure can impact data integrity or can cause loss of data.

Low-risk factors. Factors contributing to low severity risk levels include those related to product quality, health and safety, business continuity, regulatory compliance, and probability.
Product quality.
  • System is used in early product development stage.
  • System is fully automated and relies on well-validated processes.
  • High probability that problem will be detected and can be corrected.
Health and safety.
  • System failures or lack of data integrity do not have any impact on human health.

Business continuity.
  • used occasionally;
  • highly skilled operators;
  • widely used commercial systems;
  • no customization;
  • work-around solutions available;
  • full support from recognized vendor (e.g., documented evidence on validation during development, local language phone support or on-site support in case of problems).

Compliance
  • not used in regulated applications
  • Failure of the system does not have an impact on data integrity and cannot cause loss of data.

Probability. Probability should answer the question, What is the likelihood that the system will fail, generate wrong data, or that data are lost?
Probability should be expressed in occurrence within a set time period. We recommend using five categories:
  • Frequent (e.g., once every month);
  • Probable (e.g., once in 1–3 months);
  • Improbable (e.g., once in 3–12 months);
  • Occasional (e.g., once in 1–3 years);
  • Impossible.

We use past experiences from the same or similar systems to estimate probability.
Importance of a risk management master plan
The most significant task during the risk assessment process is to define criteria for criticality, which determines the final risk level. For example, this question frequently comes up: what if an inspector questions my decision? There are no absolute measures, so a dispute may occur. Discussing this question today is similar to an industry discussion of 10 to 15 years ago concerning computer validation when the frequently asked question was, How much validation is enough?
Answering this question about validation was nicely solved with the development of the Validation Master Plan (VMP). Companies developed such master plans on a fairly high level to guide validation specialists through the validation process by explaining the procedure for easy understanding, offering templates for convenient implementation, and giving examples on what to validate for different systems.

Risk-Based Validation of Commercial Off-the-Shelf Computer Systems 5

Risk evaluation process
This phase is used to categorize and prioritize the risk from a business and compliance, or health risk standpoint.

Table II: Template for risk evaluation.
Data should be entered into a form with entry fields for risk descriptions, business (continuity) impact, product quality, safety, and compliance impact, as well as probability of occurrence. An example is shown in Table II and the various impacts are described below. Impact on business continuity. This is related to a company's ability to market a new product and its reliance on system uptime for continuous shipment of product. Evaluating these issues will answer these questions: in currency, how big would be the losses due to delays of new product approval and shipment stoppages? Impact on product quality. The question here is whether the system has an impact on product quality. This question asks whether the system impacts the identity, strength, safety or efficacy of a drug. A direct impact on product quality means that any failure cannot be corrected before a new drug is approved for marketing or before a batch is released for shipment.
For a "high-risk" classification, the probability of detecting the problem would be low or zero. An example is an analysis system used in quality control where analysis results are used as criteria for the release of product.
Impact on human health and safety. Includes consumer safety and environmental hazards. An example of high severity would include circumstances whereby poor product quality could cause adverse effect to the health of patients or users.
Note: Because an impact on health and safety can only occur when there is also an impact on product quality, we combine both factors.
Impact on compliance. This is related to the risk of failing regulatory inspections and receiving single or multiple WLs or inspectional observation reports. A typical compliance issue is the insufficient integrity of regulated data.
There are other indirect affects wherein the health of a patient or a worker is affected, such as claims against the company, product recalls, a negative reputation for the company, etc.

Table III: Template to determine the overall risk factor.
Information from this category will be used to calculate an overall risk factor. In our example, the risk categories are converted into numeric values such that: high = 3, medium = 2, and low = 1 (See Table III). Risk factors are calculated using the following formula:
(Business Impact + Safety + Compliance Impact) × Probability of Occurrence = Risk Factor
Factors contributing to risk
High-risk factors. Examples of factors contributing to high-risk levels include those related to product quality and health and safety, business continuity, and regulatory compliance.
Product quality and health and safety.
  • Systems used to monitor, control, or supervise a drug manufacturing or packaging process.
  • Systems used in a production environment for testing, release, labeling, or distribution of products;
  • Users interact manually with the system and data having the ability to manipulate data.
  • System failure can have direct impact on product quality.
  • No or low probability that the problem will be detected or can be corrected;
  • Product quality problems may lead to death or serious and permanent injury.

Risk-Based Validation of Commercial Off-the-Shelf Computer Systems 4

Risk management overview
Risk management of a commercial computer system starts when the system is specified and purchased, continues with installation and operation, and ends when the system is taken out of service and all critical data have been successfully migrated to a new system.

Figure 2: Risk management (used with permission).
The approach we take is to divide risk management into four phases, as illustrated in Figure 2. The phases include risk analysis, risk evaluation and assessment, and ongoing evaluation and control. Risk analysis. Define computer system components and software functions. Identify potential hazards and harms using inputs from system specifications, system administrators, system users, and audit reports.
Risk evaluation and assessment. Define the severity, probability, and risk of each hazard, for example, by using past experience from the same or similar systems. Determine acceptable levels of risk and identify the hazards that would need mitigation to reach those levels. Identify and implement steps to mitigate risks.
On-going (re)evaluation and control. On an on-going basis, evaluate the system for new hazards and changes in risk levels. Adjust risk and mitigation strategy as necessary.
These activities should follow a risk management plan and the results should be documented in a risk management report.
Risk analysis
The first step in the risk management process is the risk analysis, sometimes called risk identification or Preliminary Hazard Analysis (PHA). The output of this phase is the input for risk evaluation. Inputs for risk analysis include:
  • specifications of equipment including hardware and software;
  • user experience with the same system already installed;
  • user experience with similar systems;
  • IT staff experience with the same or similar network equipment;
  • experience with the vendor of the system;
  • failure rates of the same or similar system (mean time between failures) and resulting system downtime;
  • trends of failures;
  • service records and trends;
  • internal and external audit results.

Inputs, for example, can come from operators, the validation group, Information Technology (IT) administrators, or from Quality Assurance (QA) personnel as the result of findings from internal or external audits.

Table I: Template for the identification of risks.
The project manager collects input on potential hazards including possible harm. For consistent and complete documentation, forms should be used. The forms should have entry fields to include relevant data on the individual who made the entry, risk description, possible hazards and harms, probability of occurrence, and possible methods of mitigation. An example is shown in Table I. Occasional problems and harms with computer systems include, but are not limited to the following:
  • Hard drive failure on local personal computers (PCs) or on the server computer can cause severe system downtime and loss of data.
  • Loss of network connectivity due to hardware failure, for example, the network interface card, can cause system downtime;
  • System overloads can cause a slow-down of operations and system downtime.
  • Inadequate vendor qualification or absent specifications on vendor support purchasing agreements can result in reduced uptime because of missing support—in the case of hardware, firmware, or software problems.
  • Inadequate or absent documentation of installation can make it difficult to diagnose a problem.
  • Inadequate or absent verification of security access functions can result in unauthorized access to the system.
  • An insufficient or absent plan for system backup can result in data loss in case of system failure.
  • Poor or absent documentation of hardware and software changes can make it difficult to diagnose a problem.
  • Inadequate quality assurance policies and procedures or inadequate reviews can lead to poor system quality.

Risk-Based Validation of Commercial Off-the-Shelf Computer Systems 3

Really, I don't recommend you do a detailed risk assessment on every record in the building. I think you need to set up a systematic way of doing it—and you are going to put certain records in certain categories from the very beginning. If a record is used to release product and this record is incorrect and you release an unsafe product – I would make that your highest category, direct impact to public health (15).
Risk-based validation takes two steps: Define the risk category—for example, high, medium, and low—and define the extent of validation for each category according to guidelines as laid out by the company.
One final comment before we start with risk-based approaches. The model proposed in this paper has two objectives. The first is to get started quickly to take immediate benefit of the risk-based approach. Start with a qualitative risk assessment based on experience with the same or similar systems and gain further experience for full risk management for later implementation. The second is to fulfill FDA requirement of basing the extent of validation for each level on justified and documented risk assessment.
It is quite obvious that there are no generally accepted models to copy, and there is no universal solution. Each company must figure out the answers for itself because success really does depend on the unique situation of a company. The model suggested in this article is just one example for implementation. The FDA would allow many others. For example, this model suggests three risk categories: high, medium, and low. It also would be acceptable to have only two: high and low, or five and more. All models would be accepted as long as the approach is justified and documented. Approaches for risk assessment and management
The National Institute for Standards and Technology (NIST) has defined the term risk as:
The probability that a particular threat-source will exercise (accidentally trigger or intentionally exploit) a particular information system vulnerability and the resulting impact if this should occur (12).
The types of risks a pharmaceutical company deals with include patient risk (safety and efficacy of drugs), regulatory risks [FDA 483's, Warning Letters (WLs), product recalls, etc.], and financial risk due to, for example: inability to get products approved for marketing, inability to ship finished products, or consequences of unauthorized disclosure of trade secrets and private information.
Risk management is the entire process from identifying and evaluating the risk to defining risk categories, and taking steps to reduce risk to acceptable levels. Risk assessment includes the first two parts: analysis and risk evaluation.
There are a number of standard risk assessment techniques available and widely used in the industry. The most important ones include the Failure Mode and Effects Analysis (FMEA) approach, Fault Tree Analysis (FTA), and the application of Hazard Analysis and Critical Control Point (HACCP) methodology. All three methods have been described in brief by H. Mollah (9).
An approach widely used in medical device industry is based on the International Organization for Standards (ISO) 14971.10 While FMEA and FTA are based more on quantitative, statistical data, the ISO approach is more qualitative in nature. The concept is to determine risk factors based upon their likelihood and severity, the mitigation of those risks, and monitoring and updating the process as necessary.
The model, as described by GAMP (1) is similar but adds detectability as another criterion: the more likely the problem will be detected, the lower the risk. Labcompliance has developed an extensive risk management master plan using the concept as described in the ISO standard (10).
For the scope of this publication, we follow the approach as described in the ISO standard. The model presented in this paper is more qualitative than quantitative and is very much based on the experience of users, validation groups, and auditors either with the same or with similar systems. For the scope of this paper, we introduce readers to the concept of full risk management, but then only focus on risk assessment. However, bear in mind that some of the current validation tasks, such as vendor assessment and even testing, are already steps towards the mitigation of risks involving computer systems.

Risk-Based Validation of Commercial Off-the-Shelf Computer Systems 2

For lower risk devices, only baseline validation activities may be conducted. As the risk increases, additional validation activities should be added to cover the additional risk.
The "FDA Part 11 Guidance on Scope and Application" states:
We recommend that you base your approach (to implement Part 11 controls, e.g., validation) on a justified and documented risk assessment and a determination of the potential of the system to affect product quality and safety, and record integrity.
The most specific advice for risk-based compliance of computer systems came from the Pharmaceutical Inspection Convention's, "Good Practices for Computerized Systems Used in Regulated Environments" (5). It has several recommendations related to risks: For critical GXP applications, it is essential for the regulated user to define a requirement specification prior to selection and to carry out a properly documented risk analysis for the various system options. This risk-based approach is one way for a firm to demonstrate that it has applied a controlled methodology, to determine the degree of assurance that a computerized system is fit for its intended purpose.
The inspector will consider the potential risks, from the automated system to product/material quality or data integrity, as identified and documented by the regulated user, in order to assess the fitness for purpose of the particular system(s). The business/GXP criticality and risks relating to the application will determine the nature and extent of any assessment of suppliers and software products (5).
Basically, this means the FDA and other agencies expect a risk assessment for each computer system, otherwise full validation is required. Companies without justified risk assessments will not be able to defend their selected level of validation. The real value in a comprehensive risk-based validation approach is in doing exactly the right amount and detail of validation for each system.

Figure 1: Risk vs. validation costs.
The principle is quite clearly illustrated in Figure 1. Costs for validation increase when going from no validation to 100% validation. Full validation for a COTS system would mean, for example, the testing of each function of the software under normal and high load, across and beyond the expected application range, and this for each possible system configuration. In addition, whenever the system is changed, may it be computer hardware, operating system, or application software, full revalidation would require that the same tests be rerun. In today's rapidly changing computer environment, this could possibly mean that the system would be used 100% for testing. At the same time that testing increases, the risk of unexpected system failure decreases, because errors found during testing can be corrected or work-around solutions can be found and implemented.
The optimum testing is, obviously, somewhere between zero and 100%. The range depends on the impact the software or system has on (drug) product quality. For example, a system used in early drug development stages will have a lower impact and require less validation than a system used in pharmaceutical quality control.
In the past, companies frequently have applied the principles of such risk-based validation, but the rationale behind it was not documented and the approach was not implemented consistently within a company. The extent of validation depended more on individual validation professionals than on a structured rationale. As explained earlier, in new guidance, the FDA suggests that industry base the extent of its validations on a 'justified and documented' risk assessment.
Most confusing to the industry has been finding a structured way to prioritize risks. The FDA has been asked frequently to prepare a matrix of regulated processes indicating the level of risk associated with each. The FDA has made it very clear that this will not happen, because each situation is different. However, they have released criteria to be used in making these determinations. These are defined as: impact on product quality and patient safety.
General advice came from FDA's John Murray when he answered questions concerning FDA's expectations at the Institute of Validation Technology (IVT) Computer System conference in May 2004:

Risk-Based Validation of Commercial Off-the-Shelf Computer Systems 1

Pharmaceutical Technology
This article describes how to adopt risk-based approaches for the validation of commercial computer systems used in the regulated pharmaceutical industry. This paper will help to guide readers through a logical, risk-based approach for computer system validation. It offers recommendations on how to define risks for different system and validation tasks and for risk categories along the entire life of a computer system. The scope of this paper is limited to Commercial Off-the-Shelf (COTS) systems and does not include risks typically involved during software development.
The article contains two parts. Part one deals with risk assessment, in which we discuss approaches to categorizing computer systems into high, medium, and low-risk levels. (These levels serve as an example. Any ranking of levels of risk that is relevant to the product and the manufacturer may be substituted. The thought process of ranking is the same.) Part two offers recommendations for validation steps for the different categories as defined in part one.
Introduction

Computer systems are widely used in pharmaceutical industry for instrument control and data evaluation in laboratories and manufacturing. They are also widely used for data transmission, documentation, and archiving. When used in regulated environments they should be formally validated. The main compliance-related purpose of their validation is to ensure accuracy and integrity of data created, modified, maintained, archived, retrieved, or transmitted by the computer system. In addition, a computer validation, typically, is a pre-requisite to obtaining reliable system operation and the highest system uptime, which are business requirements of the industry. Depending on the complexity and functionality, validation of computer systems can be a huge task. The efforts for validation should be balanced against the benefits, which means the amount of work should be in line with the problems that can occur if the system is not fully validated. The mechanism to balance benefits against investments is risk assessment in which we define the extent of validation according to the risk a specific computer can have on data integrity, and ultimately, product quality and safety. The risk-based approach should enhance industry's ability to focus on identifying and controlling critical functions that affect product quality and data integrity.
Industry task forces have recommended risk-based approaches for validation for a long time. For example, Good Automated Manufacturing Practice (GAMP) has a chapter in its "Guide for Validation of Automated Systems in Pharmaceutical Manufacture"(1). Also, the United States Food and Drug Administration has recognized the importance of risk-based compliance. This became most obvious when the FDA announced its science and risk-based approaches as part of the Twenty-First Century drug Good Manufacturing Practice (GMP) initiative in 2003 (2).
"We will focus our attention and resources on the areas of greatest risk with the goal of encouraging innovation that maximizes the public health protection," said FDA Commissioner Mark McClellan at an FDA–industry training session (8). David Horowitz added, "there are two elements to a risk-based approach to inspections: We need to go to the right places and we need to look at the right things" (8).
One reason for this risk-based approach is FDA's limited resources to inspect all manufacturing sites every two years.
"We have over 6000 domestic drug facilities and the number of GMP inspections that we have been able to inspect has declined by about two thirds in the last 20 years. So we can't take the chance that we are squandering our limited resources on lower risk facilities. That would prevent us from doing a minimum level of scrutiny and oversight and working with the higher risk facilities," Horowitz said (8).
In the meantime, FDA has begun to allocate its resources based on risk. For example, beginning in the fall of 2004, FDA began using a risk-based approach for prioritizing domestic manufacturing site inspections for certain human pharmaceuticals. This approach should help the Agency predict where its inspections are likely to achieve the greatest public health impact (2).
The FDA is not only taking advantage of the risk-based approaches, but also encourages the industry to do so, for instance, in software and computer validation. The industry guidance on General Principles of Software Validation states:
The selection of validation activities, tasks, and work items should be commensurate with the complexity of the software design and the risk associated with the use of the software for the specified intended use (3).
The same guide has also specific recommendations on what is expected for lower risk systems:

Essentials of Validation Project Management Part 3

These four types of documents are common and essential to all validation projects, although the level of detail and content may vary. Design-document quality is usually closely associated with cost; the greater the upfront engineering costs, the more detail that can be found in drawings and lists. Because facility construction and protocol preparation require drawings that are detailed, accurate, and thoroughly checked, increased funding for engineering services is usually money well spent. In general, one can expect that the cost of facility-design services will be approximately 10–12% of the facility's total installed cost.
It is useful to identify project activities on a spreadsheet when establishing project scope. Systems and equipment requiring qualification and validation are first determined by reviewing the project documents described previously. Then, the spreadsheet is created and the first column is reserved for each identified system and piece of equipment. Adjacent columns become a matrix of activities necessary to complete system and equipment qualification. Column headings and subheadings usually consist of the following:
  • document collection and review (to develop protocols and SOPs);
  • calibration and metrology;
  • protocol preparation (installation qualification [IQ], operational qualification [OQ], performance qualification [PQ], and cleaning);
  • protocol execution (IQ, OQ, PQ, and cleaning);
  • final reports;
  • turnover packages (contain construction test reports, as-built drawings);
  • SOPs (operation, maintenance, cleaning).


Table I: Estimated labor hours for commissioning and qualification.
A checkmark is placed in each cell for which a specific activity is required. This checkmark may be replaced eventually with the name of the individual responsible for the activity. Assigning labor hours to each checkmark is even more useful because this provides an estimate of the labor required for each activity and for the entire project . Project labor requirements and budgeting By revising the spreadsheet to include labor hours, and then totaling each row and column, a project labor estimate per activity and system can be derived (7). Dividing total project hours by 2080 h/year provides an estimate of personnel required to complete all activities. Total project headcount will vary depending on project duration, however. Anticipating the number of labor hours is important because the labor involved may exceed available resources, thus requiring that outside validation services be contracted. Assigning a dollar amount (e.g., $75) to each hour of labor provides an estimate of validation project costs, which often is used to justify requests for financial resources and to support the annual budgeting process.
Industry experience has shown that validation costs (excluding commissioning and process validation) typically range from 2.5–5% of the total installed cost of the facility. Aseptic-filling and biotechnology facilities frequently have the highest validation cost, whereas API facilities tend to be the least expensive. Care must be taken not to apply these guidelines too tightly because the percentage validation cost will vary with project size. As an example, the purchase and installation of a small steam sterilizer might have a total installed cost of $150,000; however, the validation costs may exceed $50,000 (33%), when protocol preparation and implementation, SOP development, and laboratory supplies are considered. 
The facility revalidation program also should be described in the master plan because the validation life cycle continues long after the facility is mechanically complete and handed over for operation. Revalidation usually takes two forms: time or event based (9). Time-based revalidation is the practice in which a system or process is recertified at a specified interval. Time-based assessments also can include a review of historical system performance data. Event-based revalidation is implemented whenever physical or operational changes are made to the system outside the scope of the original validation. All such modifications are the subject of the facility's change control program, which also should be described in detail in the master plan.
Turnover package (TOP) development also can be described in the master plan. Turnover package is a system for organizing all documents related to facility and system design, construction, and start-up relevant to the eventual commissioning and qualification of systems and equipment (10). Turnover packages are usually prepared by the construction manager and turned over to the owner at project completion. TOP documents construction activities and contributes to system IQ, OQ, and PQ and usually is a prospective or concurrent activity (i.e., design, construction and start-up documents are compiled as system construction proceeds). Turnover packages will be discussed in detail in Part 2 of this article.
Summary
This article provides a basic introduction to four components that are fundamental to all successful validation projects. Part 2 will describe three additional programs that should be considered and implemented. Before undertaking any validation project, careful planning to arrive at a logical, uncomplicated approach is required. All projects are labor and capital intensive, and incorrect or inefficient use of either resource ultimately escalates cost and extends the schedule. All validation projects must begin with a comprehensive design review and include FDA assistance if necessary. Once a compliant design is finalized, validation project scope must be established and properly communicated to all project stakeholders. Concurrent with project-scope definition is the development of a labor estimate, and by extension, a cost estimate. Knowing labor requirements and costs early helps identify potential shortfalls in personnel and permits appropriation of sufficient funding to complete the project. Accurately defining project scope also avoids misunderstandings, errors, and omissions when work is assigned to contractors and company personnel. A comprehensive validation master plan follows design review and scope definition in the project timeline. The master plan identifies critical project activities, communicates expectations, and conveys a quality mindset and state of control to regulators. Each of these project components, in conjunction with the guidelines and programs described in Part 2 that follows, helps assure that the project is completed on time and within budget. More importantly, quality is built into the project from the start, regulatory compliance is realized, and the transition from start-up to operation is optimized. In the current environment of cost control, expedited product introductions, and increased regulatory oversight, the benefits of efficient validation project management should be evident.
William Garvey is a senior advisor at Pfizer Global Research and Development, Eastern Point Road, Groton, CT 06340, tel. 860.715. 2277, fax 860.715.7806,
References
1. US Food and Drug Administration, Code of Federal Regulations, Title 21 (FDA, Washington, DC, April 1, 2005), pp. 120–141.
2. W. Garvey, "Integrated Validation Programs for Solid Dosage Facilities—Part 1," Am. Pharm. Rev. 2 (2), 33–39 (1999).
3. The Construction Specifications Institute (Alexandria, VA).
4. Department of Health, Education and Welfare, "Human Drugs—Current Good Manufacturing Practice in Manufacture, Processing, Packing or Holding of Large Volume Parenterals, and Request for Comments Regarding Small Volume Parenterals," Fed. Regist. 41 (106), 22022–22115 (June 1, 1976).
5. 3-A Sanitary Standards Inc., McClean, VA.
6. FDA, "ORA Field Management Directive 135, Pre-Operational Reviews of Manufacturing Facilities" (FDA, Washington, DC, Dec. 4, 1995).
7. W. Garvey, "Effective Validation Project Management," oral presentation given at Interphex Conference 2005, New York, NY, April 26–28, 2005.
8. ISPE Baseline Pharmaceutical Engineering Guide, Pharmaceutical Engineering Guides for New and Renovated Facilities, Vol. 5, Commissioning and Qualification, (International Society for Pharmaceutical Engineering [ISPE], March 2001), pp. 11–15.
9. ISPE Baseline Pharmaceutical Engineering Guide, Pharmaceutical Engineering Guides for New and Renovated Facilities, Vol. 5, Commissioning and Qualification, (ISPE, March 2001), p. 111.
10. M. Chin, "TOP: A Rational Approach For Ensuring Proper Biopharmaceutical Plant Construction," in proceedings from PharmTech Conference '87 (Aster Publishing Corporation, Eugene, OR, 1987), p. 73.

Essentials of Validation Project Management Part 2

Reliable and controlled. Control systems such as programmable logic controllers (PLCs) should be used to control equipment. Automation allows processes to be replicated without variability, a fundamental principle on which GMPs are based. Mechanical-type (cam) controllers should be avoided because regulations require that current and modern technology be used. Manual control also should be avoided where possible because replication is inherently difficult. Any system that may alter batch-to-batch uniformity, and ultimately the product therapeutic response, must be very carefully considered.
Correct for application. The correct design criteria must be specified. For example, clean compressed air must have a dewpoint temperature of approximately –40 °F to prevent condensation. Refrigerated air driers cannot meet this requirement. Oil-free compressors should be used to exclude oil contamination unless several levels of filtration are used (4). Industry standards allow no more than 1 ppm (1 mg/m3 ) of oil/hydrocarbon in compressed air.
Besides developing some original standards for process equipment design and construction, the pharmaceutical industry has borrowed standards from industries that produce similar consumer products, most notably the dairy industry. The 3-A Sanitary Standards are voluntary guidelines followed by dairy equipment vendors and dairy operators. The standards provide material specifications, design criteria, and other necessary information for the construction of dairy equipment to satisfy public health concerns. The ultimate objective is to safeguard public health from contaminated dairy products.
To meet this objective, 3-A Sanitary Standards and 3-A Accepted Practices ensure that dairy, food, and other microbial-sensitive products are protected from contamination; that all product contact surfaces can be cleaned in place or easily dismantled for manual cleaning; and that all product contact surfaces can be easily inspected to confirm cleaning effectiveness (5). The purpose of these standards and their application to pharmaceutical manufacturing are readily apparent. The 3A Sanitary Standards should be consulted when equipment such as holding tanks, clean-in-place systems, valves, and pumps are undergoing GMP compliance review. Design errors are uncommon, however, because most equipment vendors already fully understand and comply with these standards. For high-value projects and facilities intended to manufacture sterile products, it is often required and worthwhile to contact the local FDA district office. This alerts the agency that inspections must be scheduled, often to coincide with critical construction milestones and events. FDA Office of Regulatory Affairs Field Management Directive (FMD) 135 also encourages manufacturers to contact FDA when facility and equipment designs are being prepared (6). The following is a summary of FMD 135, which can be found on FDA's Web site:
Providing [FDA] review and comment is desirable because it may reveal [design] defects early and prevent costly construction errors which could lead to defective operations and products. It also affords FDA the opportunity to become aware of future work load obligations and, in some cases, new technologies. Early field involvement with new or modified facilities will increase efficiency and result in the timely processing of applications (6).
Companies should understand and recognize that partnering with FDA to review proposed designs is beneficial to both parties. Costs and delays associated with rework can be avoided if problems are detected early. Definitive dates for facility inspections can be established, which serve as endpoints that motivate project completion. Current agency inspectional focus also may be apparent, foretold by the types of questions that are asked. Overall, early dialogue and FDA involvement may expedite facility completion, reduce engineering and construction costs, and lead to a smooth transition from start-up to operation. These results are desirable for all manufacturers, regardless of company size or complexity.
Scope definition, organization, and planning
Successfully implemented validation projects all begin with a well-defined scope (i.e., the set of activities and deliverables that must occur to complete the project). Scope definition is critical if contracted validation resources are used because it becomes the basis for cost estimates and assessing job completion.

Essentials of Validation Project Management Part I

Pharmaceutical Technology


VECTOR CORPORATION
The qualification and validation of complex pharmaceutical manufacturing facilities requires the careful coordination of multiple activities. Conceptual, preliminary, and detailed designs must be reviewed to ensure compliance with current good manufacturing practices (CGMPs); protocol and standard operating procedure (SOP) formats must be developed; and project resources must be identified and obtained. A validation schedule must be created and integrated with the facility construction schedule. The Quality Assurance and Calibration–Metrology departments must be notified of impending increased workloads. And finally, the manufacturer should alert the local US Food and Drug Administration district office that a new facility is planned. Considering all these activities, careful planning and cautious management will increase the likelihood of a successful project outcome, no matter how difficult or complicated the project. Successful project completion is never guaranteed, but by implementing proven techniques and the programs described in this article, a favorable end-result is much more likely. Parts 1 and 2 of this article will examine seven critical components of a comprehensive validation program for new and renovated manufacturing facilities. The programs and procedures explained are appropriate for all commonly manufactured dosage forms (e.g., tablets and capsules, active pharmaceutical ingredients [APIs], parenterals). Given that the design, construction, and qualification and validation of a major facility are relatively infrequent events in most corporate life cycles, some of these project components are not well known or understood. For this reason, Part 1 of this article examines the following areas:
  • facility- and equipment-design review to ensure compliance with CGMP regulations;
  • project scope definition, organization, and planning;
  • project labor requirements and budget;
  • validation master plan development.

Part 2 will continue with a discussion of the following validation-related subjects:
  • protocol and SOP development, scheduling, and implementation;
  • design- and construction-document collection (turnover package);
  • evaluation of deviations and discrepancies.

Facility- and equipment-design reviewBy definition, the construction of a new or renovated facility and the purchase and installation of mechanical equipment and process systems constitute a project. All projects have basic, common features: a logical start, a logical end, and little or no possibility of recurrence (i.e., the project will not repeat at some future time). In addition, the design process is common to all facility projects. All facilities start with a design, about which engineers, owners, scientists, and other stakeholders confer to determine how the facility will appear and operate and what equipment and systems are needed. The usual sequence starts with the development of a conceptual design by an engineering firm, from which preliminary decisions are made about facility layout and size, utilities required, and equipment capacity and material of construction. The process then continues into the preliminary and detailed engineering stages, in which costs are finalized and designs are completed and approved. It is at this point when the conceptual design transitions to preliminary engineering that formal review to verify GMP compliance begins.
In general, process equipment and utility systems affecting product quality or contacting product are the subject of design review. Typical reviewed utilities include heating, ventilation, and air-conditioning (HVAC), compendial waters (e.g., water-for-injection, purified water, clean steam), and compressed gases such as nitrogen and compressed air. At present, regulatory expectations for other utilities such as chilled water or plant steam are minimal, and these may be omitted. Design review is mandatory for highly customized or unique process equipment, particularly when the unit is custom manufactured. Equipment for critical processes such as aseptic filling and packaging, lyophilization, and final purification also requires rigorous evaluation. Because the GMP regulations are interpretive and nonspecific for equipment design and construction, the design engineer and owner are responsible for assessing compliance (1).
During the design review stage, the engineer and owner should evaluate all critical specifications and drawings to ensure that regulatory compliance is achieved. In general, experienced vendors understand the requirements imposed by GMP regulations and design and construct their equipment and systems accordingly. Rarely are serious design and construction errors uncovered because a reputable vendor's knowledge and understanding of GMP-compliant design often exceeds that of the owner and engineer combined (2). Design reviews should be performed using a structured and systematic approach. For mechanical systems such as HVAC, the evaluation of drawing sets takes precedence over most other documents. Vendor submittals always should be reviewed. Although less beneficial, Division 15, 22, and 23 type construction specifications (3) also should be examined, even though these are often standard with little customization. Checklists and other reviewing aids may be valuable because they prove that the designs were evaluated and they may be used again for subsequent projects.
Three critical steps must be taken in a design review:
  • identify and evaluate any potential areas or items of noncompliance;
  • ensure that designs are modified to eliminate noncompliant features;
  • prepare a brief report that summarizes the design-review process and obtain appropriate approvals, including quality assurance.

Much of the current content in both domestic and foreign GMP regulations is limited and nonspecific. The owner is obligated to review all designs and verify conformance with industry standards and regulatory guidelines. In the absence of standard equipment specifications within the GMPs, logic dictates that process equipment and utilities must be designed to be:

Figure 1: Valve orientation (45° above horizontal) and nonchloride insulation in purified water, USP system.
Nonreactive. Materials of construction must be inert and non-additive. Type 304 and Type 316 stainless steel are commonly used. Hastelloy C frequently is used in reactor systems and condensers. Wood should be avoided, even for utensils, because it can generate unwanted particulates and is porous and difficult to clean. Gaskets must withstand attack by process fluids and be dimensionally stable under expected temperature conditions. Chloride-containing insulation should not be used with stainless steel components (see Figure 1).

Figure 2: Fluidized bed dryer showing mechanical components requiring maintenance located outside the process space (photo courtesy of Vector Corporation).
Cleanable. Equipment surfaces must be smooth and free of voids and crevices in which material can accumulate. Welds must be polished smooth, although mirror polishing is not always recommended where glare is a concern. Short-radius corners are preferred at joined surfaces. Threaded fittings usually are not permitted on sanitary systems. Diaphragm valves must be installed on horizontal lines at 45° angles to ensure complete drainage (see Figure 1). Labeling and packaging equipment must be designed to permit thorough inspection. If cut labels are used, equipment should permit stray labels to fall to the floor unimpeded. Seamless floor coverings should be installed where practical because they prevent the infiltration and exfiltration of water and contaminants from and to sublayers. Valves and flanges should be minimized in concealed-piping runs over critical process areas where leakage or failure could be problematic.

Figure 3: Duplex steam-trap assembly at a critical air-handling unit.
Maintainable. Through-the-wall designs should be used where serviceable mechanical components are located outside process spaces (see Figure 2). Such items include HVAC air-control valves and instrumentation, process filters, and operator workstations. Remote grease fittings should be installed on fan bearings to minimize air handler entry. Adequate clearance should be allowed at heat exchangers to permit coil removal and inspection. Redundancy should always be considered for mission-critical systems, including sanitary pumps, steam traps (see Figure 3), filter assemblies and regulators, and recorders on sterilizers. Ergonomics also should be considered