Monday, March 23, 2009

Amazon Books2


Pharmaceutical Computer Validation Introduction Library Edition: Gmp (Good Manufacturing Practices) Training Introduction to Meet Fda Regulations in the ... Medical Device, Food, and (Part 11)Pharmaceutical Computer Validation Introduction Library Edition: Gmp (Good Manufacturing Practices) Training Introduction to Meet Fda Regulations in the ... Medical Device, Food, and (Part 11) by Daniel Farb
Buy new: $199.95 / Used from: $301.68
Usually ships in 24 hours
Pharmaceutical Computer Validation Introduction GuidebookPharmaceutical Computer Validation Introduction Guidebook by Daniel Farb; Bruce Gordon
Buy new: $49.95 / Used from: $45.95
Usually ships in 24 hours
Validation of Pharmaceutical Processes: Sterile Products, Second Edition, Revised and ExpandedValidation of Pharmaceutical Processes: Sterile Products, Second Edition, Revised and Expanded by Carleton
Buy used from: $192.34
Automation and Validation of Information in Pharmaceutical Processing (Drugs & the Pharmaceutical Sciences) (Drugs and the Pharmaceutical Sciences)Automation and Validation of Information in Pharmaceutical Processing (Drugs & the Pharmaceutical Sciences) (Drugs and the Pharmaceutical Sciences) by Despautz
Buy new: $229.95 / Used from: $364.42
Usually ships in 24 hours
Validation of Aseptic Pharmaceutical ProcessesValidation of Aseptic Pharmaceutical Processes by Frederick J. Carleton
Buy used from: $169.95
Pharmaceutical Computer Validation IntroductionPharmaceutical Computer Validation Introduction by Daniel Farb
Buy new: $99.95 / Used from: $99.95
Usually ships in 24 hours
Nanjin Pharmaceutical cited for 2 validation flaws.(Human/animal drugs): An article from: Validation TimesNanjin Pharmaceutical cited for 2 validation flaws.(Human/animal drugs): An article from: Validation Times by Joseph Pickett
Buy new: $5.95
Available for download now
ISPE guide seen helpful for post-approval scale-ups, but FDA wants validation specified. (Tech transfer).(International Society of Pharmaceutical Engineers): An article from: Validation TimesISPE guide seen helpful for post-approval scale-ups, but FDA wants validation specified. (Tech transfer).(International Society of Pharmaceutical Engineers): An article from: Validation Times by Elisa Ludwig
Buy new: $5.95
Available for download now
Blue Ridge, PDC get same letters on validation faults.(Pharmaceutical Development Center)(Brief Article): An article from: Validation TimesBlue Ridge, PDC get same letters on validation faults.(Pharmaceutical Development Center)(Brief Article): An article from: Validation Times
Buy new: $5.95
Available for download now
Blood/Biologics.(Parkdale Pharmaceuticals): An article from: Validation TimesBlood/Biologics.(Parkdale Pharmaceuticals): An article from: Validation Times
Buy new: $5.95
Available for download now

Amazon Books1

Validation of Pharmaceutical Processes, 3rd EditionValidation of Pharmaceutical Processes, 3rd Edition
Buy new: $292.00 / Used from: $364.84
Usually ships in 24 hours
Pharmaceutical Equipment Validation: The Ultimate Qualification GuidebookPharmaceutical Equipment Validation: The Ultimate Qualification Guidebook by Phil Cloud
Buy new: $239.96 / Used from: $229.95
Usually ships in 24 hours
Pharmaceutical Process Validation: An International Third Edition (Drugs and the Pharmaceutical Sciences)Pharmaceutical Process Validation: An International Third Edition (Drugs and the Pharmaceutical Sciences)
Buy new: $239.96 / Used from: $210.00
Usually ships in 24 hours
Method Validation in Pharmaceutical Analysis: A Guide to Best PracticeMethod Validation in Pharmaceutical Analysis: A Guide to Best Practice
Buy new: $192.00 / Used from: $186.12
Usually ships in 24 hours
Pharmaceutical Water: System Design, Operation, and ValidationPharmaceutical Water: System Design, Operation, and Validation by William V. Collentro
Buy new: $239.96 / Used from: $250.53
Usually ships in 24 hours
21 CFR Part 11: Complete Guide to International Computer Validation Compliance for the Pharmaceutical Industry21 CFR Part 11: Complete Guide to International Computer Validation Compliance for the Pharmaceutical Industry by Orlando Lopez
Buy new: $183.96 / Used from: $199.53
Usually ships in 24 hours
Handbook of Computer and Computerized System Validation for the Pharmaceutical Industry (1stbooks Library (Series).)Handbook of Computer and Computerized System Validation for the Pharmaceutical Industry (1stbooks Library (Series).) by Stephen Robert Goldman
Buy new: $79.76 / Used from: $70.19
Usually ships in 24 hours
Pharmaceutical Master Validation Plan: The Ultimate Guide to FDA, GMP, and GLP CompliancePharmaceutical Master Validation Plan: The Ultimate Guide to FDA, GMP, and GLP Compliance by Syed Imtiaz Haider
Buy new: $183.96 / Used from: $100.00
Usually ships in 24 hours
Pharmaceutical and Medical Device Validation by Experimental DesignPharmaceutical and Medical Device Validation by Experimental Design
Buy new: $199.64 / Used from: $190.44
Usually ships in 24 hours
Development and Validation of Analytical Methods (Progress in Pharmaceutical and Biomedical Analysis)Development and Validation of Analytical Methods (Progress in Pharmaceutical and Biomedical Analysis) by C.M. Riley
Buy new: $104.00 / Used from: $99.98
Usually ships in 24 hours

Wednesday, March 11, 2009

GAMP Standards For Validation Of Automated Systems

Strategies to validate automated systems while balancing internal and external demands
By Joseph DeSpautz Business Development Asia Pacific Rockwell Automation Kenneth S. Kovacs Life Sciences Technical Consultant Rockwell Automation Dr. Gerhard Werling Manager Compliance & Validation EMEA Rockwell Automation

Manufacturing and process automation have significantly improved quality, productivity, costs and flexibility in virtually every industry, and life sciences is no exception. The rapid adoption of automation in life sciences is being driven by the fundamental need for greater consistency, reliability and efficiency in an increasingly dynamic and complex environment.

A number of holistic approaches have emerged to address quality and efficiency issues that impact the life sciences industry. Though no single solution has yet to emerge, one approach to ease the burdens of balancing external and internal demands – for example lowering costs without negatively impacting quality – has focused on validating automated systems.
What’s GAMP?
The Good Automated Manufacturing Practice (GAMP) Forum was founded in 1991 by pharmaceutical industry professionals in the United Kingdom to address the industry’s need to improve comprehension and evolving expectations of regulatory agencies in Europe. The organization also sought to promote understanding of how computer systems validation should be conducted in the pharmaceutical industry.

In 1994, GAMP partnered with the International Society for Pharmaceutical Engineering (ISPE) to publish the first GAMP guidelines. GAMP quickly became influential throughout Europe as the quality of its work was recognized internationally. Over time, GAMP has become the acknowledged expert body for addressing issues of computer system validation.

GAMP's guidance approach defines a set of industry best practices to enable compliance to all current regulatory expectations. More than simply a strict compliance standard, GAMP is a guideline for life sciences companies to use for their own quality procedures. As a result, it can be tailored to a number of computer system types.

Computer system validation following GAMP guidelines requires users and suppliers to work in concert so that responsibilities regarding the validation process are understood. For users, GAMP provides a documented assurance that a system is appropriate for the intended use before it goes “live.” Suppliers can use GAMP to test for avoidable defects in the supplied system to ensure quality product leaves the facility.

The GAMP framework addresses how systems are validated and documented, in other words “how one will validate and document the system.” Companies do not need to follow the same set of procedures and processes of a GAMP framework to achieve validation and qualification levels that satisfy inspectors. Instead, GAMP examines the systems development lifecycle (SDLC) – a conceptual model that lays out the deliverable documents required by GAMP – of an automated system to identify issues of validation, compliance and documentation.

In essence, GAMP asks:

* Do you know what you want to do?

* Have you broadly defined the function requirements?

* How will you do it?

Identifying the “how” is essential to the design and testing phases of validation. Once the design is tested, and if it works as intended, then you have satisfied not only the function requirements, but the overall requirements for system use. A regulatory body expects to see documentation of the process.
‘V’ for Validation
GAMP recommends an SDLC called the V-model (see graphic) because it is a commonly used design, but there are others that can be followed. The V-model shows how the three main qualification activities (installation, operation and performance) are linked back to the design process.
http://www.pharmpro.com/images/0803/pp83_ROCKWELL01_large.jpg
These main steps correspond to deliverables within a computerized validation framework. The left side of the V represents the specification stream – user requirements, functional specifications, hardware and software design, and module specifications. The right side of the V represents the system testing stream against the specifications. The bottom of the V indicates the code modules.
Specification Stream
With the V-model, the document that initiates the validation process is the user requirement specification (URS). The URS describes the equipment or system as it is intended to function, and it is typically written by the system user. The original version should contain the essential requirements and the desirable requirements. As part of the validation process, the organization checks the software system before launch. Clear documentation of a properly functioning system is typically found in the URS to detail what the system should do and what it could do.

Next, the URS is matched with the functional and design specifications, which often come from the system or software developer. The functional specifications describe the functions of the system and how it was built. In the V-model, the functional specifications correspond to the operational qualifications, as each of the parameters should be tested. A gap analysis is performed to identify areas where an internal requirement isn’t met. This allows recognition of risks and outlines approaches to correct the shortcomings. The design specifications define the production of the hardware, software and instrumentation and how the software meets the requirements of the functional specifications for proper function.
Testing Stream
Validation is applied to several aspects of a pharmaceutical manufacturing system. The objective is to produce “documented evidence, which provides a high degree of assurance that all parts of a system will consistently work correctly when brought on-line. Validation includes three core elements:

* Installation qualification (IQ) – confirms complete documentation, which includes checking purchase orders, proper hardware installation, and software verification according to the manufacturer’s specifications; both user and supplier share primary testing responsibility.

* Operational qualification (OQ) – confirms the system operations by testing the design requirements that are traced back to the function specifications, including software and hardware functions under normal load, and under realistic stress conditions to assess whether equipment and systems are working correctly; both user and supplier share primary testing responsibility.

* Performance qualification (PQ) – confirms that a system is capable of performing or controlling the activities of the process, while operating in a specific environment – namely, a series of checks by the user against the original requirement specifications of the system; responsibility falls solely on the user.

Though there isn’t a singular method for achieving and maintaining traceability, regulatory agencies have an essential level of expectation. Despite the lack of a standard procedure, the selected process and method used by a system for traceability should be documented and understood. The core principles of traceability link system requirements, design specifications and testing documents with the processes and supporting documentation. In other words, traceability should demonstrate that by testing the documents, one is able to verify the system requirements a nd the design specifications.

The linkage among requirements, design and testing may be identified by the following relationships:

* Multiple requirements may be checked by a single design specification and confirmed by a single test;

* Multiple design specifications may be coupled to a single requirement; and

* Multiple tests may be necessary to verify one requirement or one design specification.

Traceability may be achieved through:

* A requirements traceability matrix;

* Automated software tools; and

* Embedded references directly within documents.

Organizations use GAMP guidelines to achieve traceability by checking whether a system is:

* Appropriate in its size, complexity, impact and risk;

* Documented and approved in the validation planning stage; and

* Integral to the overall project life cycle and for the support and maintenance of the system.
Top Three Challenges
As a voluntary program, GAMP offers both challenges and benefits. The top three challenges in implementing GAMP are establishing procedural control, handling management and change control, and finding an acceptable standard among the existing variations.

Establishing procedural control is a challenge in using GAMP guidelines because new frameworks may be necessary to gauge the validity of systems. Most pharmaceutical companies have already established a baseline that adheres to standards and regulations that exist today, but they may not have a procedure to check the processes that are in place. This could cause resistance among software developers who may prefer not to work within the confines of specifications and procedures developed by others. Specifications and procedures developed by previous software developers may hinder ways to adjust computer systems, but varying interpretations of GAMP guidelines allow for multiple solutions.

Another hurdle is change control. In the development or modification of computer systems, companies with even the highest of standards can suffer setbacks along the SDLC. Sometimes minor tweaks by the software programmer, whether necessary or not, may cause breakdowns after validation changes have been implemented. Internal processes and procedures must be established to guard against these occurrences.

Whether utilizing another company’s specifications and procedures or your own, effective documentation management is fundamental for compliance. Any inaccuracies or missing information renders all other efforts moot. Moreover, implementing a formal document management application may be cost-prohibitive for some organizations. Some companies simply use what’s in the GAMP checklists to evaluate their systems. Today’s environment demands a thorough process to show validation.
Get GAMP
How do companies become GAMP-aware when it comes to dealing with the variability of process and procedures that exist in the industry? Some manufacturers that operate plants in numerous locations have established their own set of specifications and procedures to follow GAMP guidelines, and may add and drop some criteria to dictate the level of validation necessary to work with them. Suppliers reference GAMP because they’re following another company’s pre-established procedures. The customer can dictate changes to the supplier if they are necessary.

The ubiquitous pharmaceutical industry deals with not only domestic and international companies, but also a number of regulatory bodies as well. Inevitably, they’re facing some code of federal regulations along with GAMP, especially when a company wishes to export to the U.S., Europe and other parts of the world.

There are many companies that are capable of validating their systems to their specifications because they know they have to satisfy the FDA and have aligned their efforts accordingly. However, the FDA requirements are not prescriptive with step-by-step procedures, but are guidelines with an approximation of checks and balances. Some companies demonstrate validation by documenting the process to make a product consistent and repeatable to their own specifications. In some cases, companies simply follow what the customer wants. The lack of a rigid guideline should signal to companies that some give-and-take is necessary - whether satisfying customers or regulatory agencies.
What Do I Need?
If a life sciences company wishes to use GAMP guidelines to set up its validation systems, some of the elements may already be in place. Certain aspects, such as the maturity of the hardware or software, must be taken into consideration to check whether these elements are “industry proven.” To test the validity of elements in the system, the appropriate hardware, infrastructure and network must be in place. When beginning the testing environment, the test author should understand the testing environment in terms of:

* Correct hardware (peripherals and interfaces);

* Software (validated tools, software configuration);

* Data units (inputs, outputs, quality and quantity of data);

* Procedures (especially for user acceptance testing); and

* People (training and experience), (GAMP Good Practice Guide, pg. 69).

Suppliers can offer highly scalable automation architectures, which can be applied to a stand-alone one-server/one-user application, or to multiple users interfacing with multiple servers. This allows companies the ability to improve flexibility, reduce downtime and improve productivity. For example, a database system that wasn’t 21 CFR Part 11-compliant would require the company to make adjustments to the computer system to become compliant. This means the automation infrastructure must drive regulatory compliance to ensure that products meet guidelines. Likewise, OEMs are now looking at ways to provide the pro forma operational qualifications for all features in their equipment, so companies can test each of the features. Likewise, automation suppliers offer technology enhancements, as well as parts, small systems, total systems and integrated systems to help streamline the qualification process and reduce validation costs.

Typically, the costs of validating a larger system often represent between 20-25% of the total cost of the system qualification. Reducing the cost adds value to the bottom line and enables a system to go on-line faster. It makes sense to have procedures and systems in place to make validation easier.

GAMP helps companies address current issues of operational/manufacturing challenges through standardizing data, monitoring systems and validating the system.

The benefits of utilizing the GAMP approach for both users and suppliers include:

* Improved understanding of the subject with the introduction of common terminology;

* Reduced cost and time to achieve compliant systems;

* Reduced time and resources for revalidation or regression testing and remediation;

* Reduced cost of qualification;

* Enhanced compliance with regulatory expectations; and

* Established responsibility for all involved parties.

Products are available to help companies avoid revalidating an entire system when a new version emerges. Software tools focused on the life sciences industry that support cost-effective, risk-based manufacturing approaches allow companies to see what testing has been done to examine the functions within the system.

When the FDA introduced its current Good Manufacturing Practices (cGMP) for the 21st century initiative, companies shifted their approach to validation. Formerly, they only had to heed a set of rules that accounted for every piece of equipment that was used. Now they can take a risk-based approach to validation by addressing patient safety, efficacy and quality in the product considerations. In essence, this enables the industry to place its investments where it makes the most sense. The onus ultimately falls on manufacturers to accept greater responsibility to validate their systems having the attendant benefits of cost and time to market savings.

GAMP helps provide a quality product from the manufacturer, and helps to limit the pharmaceutical industry’s culpability by ensuring proper steps were placed to deliver a quality product through validated systems. By incorporating input from the full spectrum of stakeholders, fine tuning and further development of the process is geared towards benefiting the life sciences industry and the general consumer market.

The tools exist for companies to take the steps needed to reap the benefits of validation. Clearly, if you aren’t taking the necessary steps to compete, then your competitors are assuredly doing what they can to gain a market advantage. Understanding and early adoption of GAMP can increase a company’s competitive position, especially with the introduction/implementation of new technologies. By staying aware of technological innovations, companies are able to increase efficiency, minimize risks and reduce costs.





Talkback!
Pharmaceutical Processing is pleased to provide you an opportunity to share your opinions on any of the news stories or articles on our site. We reserve the right to edit/remove comments.

A Personalized Approach To Validation

Tailor-made validation programs are often more successful than cookie-cutter approaches
A validation program for a complicated pharmaceutical project can be a daunting task. There are thousands of details to consider, from the day that you begin to lay out the project’s goals, to the day that you complete the project. However, the key to success is very simple: customization.

It is impossible to take the same validation master plan and apply it to two different projects. No matter how similar the projects may seem, it is essential to consider all details and shape the plan as precisely as possible. This tailor-made approach must continue throughout the entire project lifecycle.

It is also important to customize a program for each client that is consistent with their overall approach, standards, and philosophy, while still maintaining regulatory standards and industry-accepted practices. By personalizing a program and merging it with the client’s approach, the likelihood of consistent compliance can be enhanced.
Before you begin
Most of the critical work in validation occurs before the project even begins. The first key is to collect all the available information on the project, even things that may seem irrelevant at the time. In validation, the more information you have, the better the chance that you will avoid problems down the road.

Before beginning, define what the project goals are, what support is available, and the timeline that you will be working on. You should also identify what work will be contracted out, and what will be accomplished internally.

When Day & Zimmermann is hired for a validation project, our most important focus is on maintaining consistent quality throughout all projects. However, we must also reach a balance between the schedule and cost demands of our clients. For example, some clients request our services to assist in the routine qualification activities at a site. In such instances controlling cost while maintaining quality is the primary concern because quarterly budgets must be strictly adhered to. On the other hand, some clients have large, fast-track capital projects and a missed deadline can cost the company a substantial amount of money. In these instances, quality and schedule need to be the primary focus.

It is our job as contractors to balance all of the important aspects of a project in order to best meet our client’s needs. The issue of prioritizing is one that is important to consider, whether you are hiring an outside contractor, or performing the validation project internally. Sit down to determine your main concern – is it getting the job done as quickly as possible, or getting the job done with the smallest budget possible?

Of course, quality has to be the first consideration, so it is important to be realistic in your planning. You may want a project done in six months, but if bringing it in on time requires cutting corners, you may have to reconsider and adjust your timeline.

Once you have a detailed and realistic validation master plan developed, you are ready to choose your team and begin the project.
Communicating for success
Communication is one of the most important elements to focus on once your validation program is underway. Set a standard for conveying all decisions and data to the entire team, so that relevant information reaches the right people at the right time. Too often, it seems, the various departments involved in a project develop a “silo” approach, where groups are working independently instead of collaboratively, and cross-departmental communication and cooperation suffer.

One approach to avoid miscommunication is to meet individually with the various departments, determine their particular “hot buttons,” and devise a middle-ground strategy that can be generally accepted by all parties.

Every company has individual project needs and specific processes to handle work instructions. These particular work processes are often different for all projects, so it is important to establish systems to control costs and report the current project status. This helps ensure that all parties and departments have the proper communication channels to review project standings. And it helps avoid any surprises throughout the project lifecycle, and ensures a strong relationship.

Establish a simple, trustworthy Corrective Action, Preventive Action process as well. This way, in the event of unexpected issues, the team understands exactly how to resolve and prevent them quickly, efficiently and safely. It is also imperative that the team understands each member’s roles and expectations. To keep things clear, create a detailed matrix of each team member’s defined tasks as a reference point. This helps to avoid gaps or overlaps in responsibilities, so that no critical project element is overlooked or duplicated.
Meeting your deadline
Validation programs often involve meeting aggressive client milestones. The best way to mitigate this challenge goes back to proactive planning. Anticipating project needs is a key to success, and experience with similar projects can prove to be a great asset. Establish periodic milestones throughout the project, and measure your team against them consistently. Break these down by different sections of the schedule, and evaluate progress and compliance at each marker.

Setting expectations is equally important when establishing and following deadlines. Make sure to include all support teams, as well as management, in all communications. Tell them exactly what is needed, by when, and at what values. This keeps everyone fully involved and engaged, and also fosters teamwork. It will also help you realize in advance if you are likely to fall behind schedule, and allow you to make adjustments accordingly.

Throughout the life cycle of the project, it is important to establish periodic acceleration sessions. This is an opportunity for members to compress, or accelerate, the schedule where they can to save time and money. You can further motivate your team to cut the timeframe by offering incentives whenever possible. Making cuts to both cost and time help to give you some padding for unexpected delays and other issues.

That being said, anticipating challenges does not always work, due to the dynamic and ever changing nature of large capital projects. It is not uncommon to spend a great deal of time and resources to formulate a plan for successful project execution only to have the project scope change drastically. While this is certainly not ideal, it is often unavoidable. In such cases, it is important to remain flexible and to stay sound in your decision making. Often creative solutions can be made that offer a “win/win” solution so that the validation team doesn’t have to start from square one. The important thing is to have a plan to move forward that is agreeable to all parties while keeping in mind that the plan may change.
Learn from your successes and mistakes
It is essential at the close of a project to conduct a ‘lessons learned’ session to recap the project, reflect on the work done, and gain insight from the experience. This goes back to the value of personalization – once you have been through this process once, you can use the lessons learned to further customize the validation process the next time around. Learn how to avoid the same mistakes, figure out what resulted in successes, and decide what processes fit your company’s needs the best. While every project will be different, sharing takeaways and recommendations will enable you to be better prepared for your next validation project.

About the authors: Patrick Polhemus has spent ten years in the pharmaceutical industry, including almost eight years in commissioning and qualification. He is currently a project manager for Day & Zimmermann, and has been involved with projects performing the commissioning and qualification of filling and packaging equipment, utility systems, and automation. Warren Wanlund has over 25 years of experience in the pharmaceutical, biotechnology and medical device industries, including aseptic fill manufacturing, and the development, implementation and supervision of qualification and validation projects for numerous clients.





Talkback!
Pharmaceutical Processing is pleased to provide you an opportunity to share your opinions on any of the news stories or articles on our site. We reserve the right to edit/remove comments.
http://www.pharmpro.com

Pharma-IT: Virtualization and Validation


A collision between technology and regulation is fast approaching. As pharmaceutical companies and their suppliers look for ways to cut costs, technology is leaping to the forefront. Leading the pack is the idea of outsourcing data centers to vendors using computer virtualization. Stumbling along in the opposite direction is last century's 21 CFR Part 11 and all of its costly misinterpretations.

Computer Virtualization


Computer virtualization has many different meanings. At its narrowest sense, one physical computer runs different operations under different software systems (such as your production line monitoring software, your email software, your word processing software, and so on all on the same computer). Each piece of software thinks it has the computer to itself. Virtualization can also be much broader, spreading your software over many different computers connected across different regions and time zones all around the world. From a cost savings perspective, virtualization is loved by chief financial officers as it reduces costs by 30% under its narrowest use and up to much more dramatic cost reductions near 80% if you rely upon the broader sense of virtualization.

Today, only 15-20% of companies embrace virtualization. Technology analysts expect data center virtualization to be adopted by more than 60% of companies world-wide within the next two years, driven in large part by economic pressure. While virtualization may save money for pharmaceutical companies, especially those outsourcing their computer departments, the business risks from a compliance standpoint are very real. Virtualization is complex. Because so much can be spread in little bits and pieces across so many computers and networks (or all combined onto one computer), any single tiny, little change may have significant, unanticipated downstream impact. One of the closest analogies may be the way the internet works – and can break down.

Think about the way you access the internet today. When you start up your internet browser and go to a website like Google or Pharmaceutical Processing, the pathway taken by your computer to show you that site goes through your company's network or, when you are home, through your telephone or cable company's network. If the wrong tiny, little switch is turned off somewhere the vast telephone or cable network, you won't be able to access the internet or maybe just half of the websites based on the East Coast of the US. Google and the millions of internet websites are still there, you just cannot get to them. The same vulnerability holds true when you virtualize your data center. Your company's software, its production data, and so on is all still there – spread across a vast number of computers and networks (or all crammed onto one) – but any little glitch may cut off your access to it or, in the worst case, destroy some of that information. Information loss may be a minor irritant when trading emails with your friends, but the FDA does not smile kindly on companies that cannot produce production data.

Just as you manage your risk of accessing the internet at home by signing a contract with the professionals (e.g., your telephone or cable company) to handle the hook-ups, access rights and connection availability, so you should let those technology vendors that specialize in virtualization deal with all the network infrastructure and computer systems involved. You then focus on managing the risk of non-compliance with regulations. And therein lies the catch.

Virtualization is an advanced technology use that needs advanced regulatory interpretations. The slow pace of legislative and regulatory change provides a significant mismatch between the complexities of the fast-growing virtualization trend and the costly "validate everything" of 1997's Part 11.

Part 11 Revised


In talking with officials at the FDA in preparation for my seminar last year on revisions to Part 11 and the EU's Annex 11, it became clear that the work of the FDA Part 11 revision group is complete. As I mentioned to seminar attendees, and in my May SmarterCompliance newsletter, the FDA's 21 CFR Part 11 has been revised and is only awaiting final center approval before it can be published. Given the recent agency leadership change, I anticipate the revised Part 11 to be released to be sometime later this year.

For pharmaceutical companies looking at virtualization, the revised Part 11 will be just the change needed to avoid a headlong collision of technology and regulation. Details of the revised Part 11 and how to prepare your company are beyond the scope of this column; you can get the information, strategies and reference materials from the recorded version of my seminar, Understanding and Implementing the Revised FDA Part 11 and EU Annex 11, on my website (http://www.ceruleanllc.com/seminars).

Given the revised Part 11, its intent and its new focus, how then to tackle the compliance challenges inherent in virtualization and still save all that money?

Tackling Virtualization and Validation


As members of my SmarterCompliance™ Toolkit program recognize, the solution lies in moving away from a spotlight on the computer toward a focus on controlling outputs. Technology – whether a computer or a virtualized data center – is just a tool, a means to an end. That end is an electronic record that is "attributable, legible, contemporaneous, original, and accurate" (Dr. Stephen Wilson, Deputy Director, CDER, FDA, FDA Regulatory Perspective: Data Integrity, May 2006). This is the pathway to adopting good technology and good compliance. To achieve success with virtualization and compliance, there are four key steps to take:

1. Homework. Do your homework on the type of technology outsourced provider you want. I've written a very popular article based on my own experiences years ago as a biotech and device executive trying to find good consultants and outsource providers. You can read the article in its entirety at this link: http://www.ceruleanllc.com/Resources/Choose_a_Consultant_Get_Results.htm. Follow the steps in that article (or in some of the others I've written that touch upon similar themes, "Cost-Effective IT Outsourcing" or "SMB Validation: Four Ways to do More for Less") to pick the right vendor for your company.

2. Quality/Technical Agreement. Craft a quality or technical agreement with the virtualization vendor that identifies your minimum expectations in terms of monitoring, reporting, security, uptime (i.e., availability) and backups. To identify realistic expectations, have your computer department research out typical levels for each of those categories (for instance, average uptime expectation email service might be 98.4%). Then, conduct a risk analysis, assessing the risk to the product, the patient and your compliance for that level of service. Be prepared to pay more if you want rates of service higher than typical.

3. Independent Controls. Include in your agreement the ability to conduct independent verifications – either yourself or by hiring an independent auditor – of the vendor's controls around the virtualized data center, the security of your information and access to your stored or archived data. Electronic data is most vulnerable sitting in storage – whether on a computer disk or backed up onto tape. Work with an independent consultant who has experience in both Part 11 and records management to craft a set of control points and check-ins to conduct during the course of your contract with the virtualization vendor.

4. Polices and SOPs. You need to complete your management of the risks of virtualization with a strong policy and procedural framework. Here too you may find it advantageous to work with someone with both an IT and records management background – particularly if that individual has had to deal with records and litigation; few things will give you a better sense of what to reasonably expect when it comes to controlling electronic information and data integrity than an experience or two justifying to a skeptical lawyer why some records were kept and some were destroyed. Practical policies and standard operating procedures need to be written, trained and enforced. The independent auditor you use to help you monitor or conduct due diligence on your virtualization vendor should make sure to incorporate of a review of the vendor's records control policies and procedures as well.

With these four tactics, virtualization compliant with the revised Part 11 can cut costs and lower risk. This, in turn, can help you speed drugs to market and pass some of the cost savings onto consumers, creating a "win-win-win" for everyone from shareholders and investors, to the regulators and the public.

Final Thoughts


Finally, having tackled compliance by shifting from physical computer and software validation to a risk-based validation of the overall virtualization environment and its outputs (e.g., the integrity of your electronic records), you will face an interesting question: Since that approach works for the complex virtualized data center, why are we still taking the costly 1997 "validate everything" strategy with the rest of our 21st century technology?

Are you ready?
About the Author John Avellanet is the founder of the regulatory intelligence and lean compliance program for executives and business owners, the SmarterCompliance™ Toolkit. He is the author of more than 30 articles on lean compliance and quality systems (including cost-effective tactics for Part 11), a co-author of a recent book on biotech business development, and a frequent speaker with FDA officials. He can be directly reached through his independent advisory firm, Cerulean Associates LLC, on the web at http://www.ceruleanllc.com





Talkback!
Pharmaceutical Processing is pleased to provide you an opportunity to share your opinions on any of the news stories or articles on our site. We reserve the right to edit/remove comments
http://www.pharmpro.com/ShowPR~PUBCODE~021~ACCT~0000100~ISSUE~0902~RELTYPE~ATO~PRODCODE~9139~PRODLETT~FP.html