Saturday, July 24, 2010

Risk-Based Validation of Commercial Off-the-Shelf Computer Systems 2

For lower risk devices, only baseline validation activities may be conducted. As the risk increases, additional validation activities should be added to cover the additional risk.
The "FDA Part 11 Guidance on Scope and Application" states:
We recommend that you base your approach (to implement Part 11 controls, e.g., validation) on a justified and documented risk assessment and a determination of the potential of the system to affect product quality and safety, and record integrity.
The most specific advice for risk-based compliance of computer systems came from the Pharmaceutical Inspection Convention's, "Good Practices for Computerized Systems Used in Regulated Environments" (5). It has several recommendations related to risks: For critical GXP applications, it is essential for the regulated user to define a requirement specification prior to selection and to carry out a properly documented risk analysis for the various system options. This risk-based approach is one way for a firm to demonstrate that it has applied a controlled methodology, to determine the degree of assurance that a computerized system is fit for its intended purpose.
The inspector will consider the potential risks, from the automated system to product/material quality or data integrity, as identified and documented by the regulated user, in order to assess the fitness for purpose of the particular system(s). The business/GXP criticality and risks relating to the application will determine the nature and extent of any assessment of suppliers and software products (5).
Basically, this means the FDA and other agencies expect a risk assessment for each computer system, otherwise full validation is required. Companies without justified risk assessments will not be able to defend their selected level of validation. The real value in a comprehensive risk-based validation approach is in doing exactly the right amount and detail of validation for each system.

Figure 1: Risk vs. validation costs.
The principle is quite clearly illustrated in Figure 1. Costs for validation increase when going from no validation to 100% validation. Full validation for a COTS system would mean, for example, the testing of each function of the software under normal and high load, across and beyond the expected application range, and this for each possible system configuration. In addition, whenever the system is changed, may it be computer hardware, operating system, or application software, full revalidation would require that the same tests be rerun. In today's rapidly changing computer environment, this could possibly mean that the system would be used 100% for testing. At the same time that testing increases, the risk of unexpected system failure decreases, because errors found during testing can be corrected or work-around solutions can be found and implemented.
The optimum testing is, obviously, somewhere between zero and 100%. The range depends on the impact the software or system has on (drug) product quality. For example, a system used in early drug development stages will have a lower impact and require less validation than a system used in pharmaceutical quality control.
In the past, companies frequently have applied the principles of such risk-based validation, but the rationale behind it was not documented and the approach was not implemented consistently within a company. The extent of validation depended more on individual validation professionals than on a structured rationale. As explained earlier, in new guidance, the FDA suggests that industry base the extent of its validations on a 'justified and documented' risk assessment.
Most confusing to the industry has been finding a structured way to prioritize risks. The FDA has been asked frequently to prepare a matrix of regulated processes indicating the level of risk associated with each. The FDA has made it very clear that this will not happen, because each situation is different. However, they have released criteria to be used in making these determinations. These are defined as: impact on product quality and patient safety.
General advice came from FDA's John Murray when he answered questions concerning FDA's expectations at the Institute of Validation Technology (IVT) Computer System conference in May 2004:

Risk-Based Validation of Commercial Off-the-Shelf Computer Systems 1

Pharmaceutical Technology
This article describes how to adopt risk-based approaches for the validation of commercial computer systems used in the regulated pharmaceutical industry. This paper will help to guide readers through a logical, risk-based approach for computer system validation. It offers recommendations on how to define risks for different system and validation tasks and for risk categories along the entire life of a computer system. The scope of this paper is limited to Commercial Off-the-Shelf (COTS) systems and does not include risks typically involved during software development.
The article contains two parts. Part one deals with risk assessment, in which we discuss approaches to categorizing computer systems into high, medium, and low-risk levels. (These levels serve as an example. Any ranking of levels of risk that is relevant to the product and the manufacturer may be substituted. The thought process of ranking is the same.) Part two offers recommendations for validation steps for the different categories as defined in part one.
Introduction

Computer systems are widely used in pharmaceutical industry for instrument control and data evaluation in laboratories and manufacturing. They are also widely used for data transmission, documentation, and archiving. When used in regulated environments they should be formally validated. The main compliance-related purpose of their validation is to ensure accuracy and integrity of data created, modified, maintained, archived, retrieved, or transmitted by the computer system. In addition, a computer validation, typically, is a pre-requisite to obtaining reliable system operation and the highest system uptime, which are business requirements of the industry. Depending on the complexity and functionality, validation of computer systems can be a huge task. The efforts for validation should be balanced against the benefits, which means the amount of work should be in line with the problems that can occur if the system is not fully validated. The mechanism to balance benefits against investments is risk assessment in which we define the extent of validation according to the risk a specific computer can have on data integrity, and ultimately, product quality and safety. The risk-based approach should enhance industry's ability to focus on identifying and controlling critical functions that affect product quality and data integrity.
Industry task forces have recommended risk-based approaches for validation for a long time. For example, Good Automated Manufacturing Practice (GAMP) has a chapter in its "Guide for Validation of Automated Systems in Pharmaceutical Manufacture"(1). Also, the United States Food and Drug Administration has recognized the importance of risk-based compliance. This became most obvious when the FDA announced its science and risk-based approaches as part of the Twenty-First Century drug Good Manufacturing Practice (GMP) initiative in 2003 (2).
"We will focus our attention and resources on the areas of greatest risk with the goal of encouraging innovation that maximizes the public health protection," said FDA Commissioner Mark McClellan at an FDA–industry training session (8). David Horowitz added, "there are two elements to a risk-based approach to inspections: We need to go to the right places and we need to look at the right things" (8).
One reason for this risk-based approach is FDA's limited resources to inspect all manufacturing sites every two years.
"We have over 6000 domestic drug facilities and the number of GMP inspections that we have been able to inspect has declined by about two thirds in the last 20 years. So we can't take the chance that we are squandering our limited resources on lower risk facilities. That would prevent us from doing a minimum level of scrutiny and oversight and working with the higher risk facilities," Horowitz said (8).
In the meantime, FDA has begun to allocate its resources based on risk. For example, beginning in the fall of 2004, FDA began using a risk-based approach for prioritizing domestic manufacturing site inspections for certain human pharmaceuticals. This approach should help the Agency predict where its inspections are likely to achieve the greatest public health impact (2).
The FDA is not only taking advantage of the risk-based approaches, but also encourages the industry to do so, for instance, in software and computer validation. The industry guidance on General Principles of Software Validation states:
The selection of validation activities, tasks, and work items should be commensurate with the complexity of the software design and the risk associated with the use of the software for the specified intended use (3).
The same guide has also specific recommendations on what is expected for lower risk systems:

Essentials of Validation Project Management Part 3

These four types of documents are common and essential to all validation projects, although the level of detail and content may vary. Design-document quality is usually closely associated with cost; the greater the upfront engineering costs, the more detail that can be found in drawings and lists. Because facility construction and protocol preparation require drawings that are detailed, accurate, and thoroughly checked, increased funding for engineering services is usually money well spent. In general, one can expect that the cost of facility-design services will be approximately 10–12% of the facility's total installed cost.
It is useful to identify project activities on a spreadsheet when establishing project scope. Systems and equipment requiring qualification and validation are first determined by reviewing the project documents described previously. Then, the spreadsheet is created and the first column is reserved for each identified system and piece of equipment. Adjacent columns become a matrix of activities necessary to complete system and equipment qualification. Column headings and subheadings usually consist of the following:
  • document collection and review (to develop protocols and SOPs);
  • calibration and metrology;
  • protocol preparation (installation qualification [IQ], operational qualification [OQ], performance qualification [PQ], and cleaning);
  • protocol execution (IQ, OQ, PQ, and cleaning);
  • final reports;
  • turnover packages (contain construction test reports, as-built drawings);
  • SOPs (operation, maintenance, cleaning).


Table I: Estimated labor hours for commissioning and qualification.
A checkmark is placed in each cell for which a specific activity is required. This checkmark may be replaced eventually with the name of the individual responsible for the activity. Assigning labor hours to each checkmark is even more useful because this provides an estimate of the labor required for each activity and for the entire project . Project labor requirements and budgeting By revising the spreadsheet to include labor hours, and then totaling each row and column, a project labor estimate per activity and system can be derived (7). Dividing total project hours by 2080 h/year provides an estimate of personnel required to complete all activities. Total project headcount will vary depending on project duration, however. Anticipating the number of labor hours is important because the labor involved may exceed available resources, thus requiring that outside validation services be contracted. Assigning a dollar amount (e.g., $75) to each hour of labor provides an estimate of validation project costs, which often is used to justify requests for financial resources and to support the annual budgeting process.
Industry experience has shown that validation costs (excluding commissioning and process validation) typically range from 2.5–5% of the total installed cost of the facility. Aseptic-filling and biotechnology facilities frequently have the highest validation cost, whereas API facilities tend to be the least expensive. Care must be taken not to apply these guidelines too tightly because the percentage validation cost will vary with project size. As an example, the purchase and installation of a small steam sterilizer might have a total installed cost of $150,000; however, the validation costs may exceed $50,000 (33%), when protocol preparation and implementation, SOP development, and laboratory supplies are considered. 
The facility revalidation program also should be described in the master plan because the validation life cycle continues long after the facility is mechanically complete and handed over for operation. Revalidation usually takes two forms: time or event based (9). Time-based revalidation is the practice in which a system or process is recertified at a specified interval. Time-based assessments also can include a review of historical system performance data. Event-based revalidation is implemented whenever physical or operational changes are made to the system outside the scope of the original validation. All such modifications are the subject of the facility's change control program, which also should be described in detail in the master plan.
Turnover package (TOP) development also can be described in the master plan. Turnover package is a system for organizing all documents related to facility and system design, construction, and start-up relevant to the eventual commissioning and qualification of systems and equipment (10). Turnover packages are usually prepared by the construction manager and turned over to the owner at project completion. TOP documents construction activities and contributes to system IQ, OQ, and PQ and usually is a prospective or concurrent activity (i.e., design, construction and start-up documents are compiled as system construction proceeds). Turnover packages will be discussed in detail in Part 2 of this article.
Summary
This article provides a basic introduction to four components that are fundamental to all successful validation projects. Part 2 will describe three additional programs that should be considered and implemented. Before undertaking any validation project, careful planning to arrive at a logical, uncomplicated approach is required. All projects are labor and capital intensive, and incorrect or inefficient use of either resource ultimately escalates cost and extends the schedule. All validation projects must begin with a comprehensive design review and include FDA assistance if necessary. Once a compliant design is finalized, validation project scope must be established and properly communicated to all project stakeholders. Concurrent with project-scope definition is the development of a labor estimate, and by extension, a cost estimate. Knowing labor requirements and costs early helps identify potential shortfalls in personnel and permits appropriation of sufficient funding to complete the project. Accurately defining project scope also avoids misunderstandings, errors, and omissions when work is assigned to contractors and company personnel. A comprehensive validation master plan follows design review and scope definition in the project timeline. The master plan identifies critical project activities, communicates expectations, and conveys a quality mindset and state of control to regulators. Each of these project components, in conjunction with the guidelines and programs described in Part 2 that follows, helps assure that the project is completed on time and within budget. More importantly, quality is built into the project from the start, regulatory compliance is realized, and the transition from start-up to operation is optimized. In the current environment of cost control, expedited product introductions, and increased regulatory oversight, the benefits of efficient validation project management should be evident.
William Garvey is a senior advisor at Pfizer Global Research and Development, Eastern Point Road, Groton, CT 06340, tel. 860.715. 2277, fax 860.715.7806,
References
1. US Food and Drug Administration, Code of Federal Regulations, Title 21 (FDA, Washington, DC, April 1, 2005), pp. 120–141.
2. W. Garvey, "Integrated Validation Programs for Solid Dosage Facilities—Part 1," Am. Pharm. Rev. 2 (2), 33–39 (1999).
3. The Construction Specifications Institute (Alexandria, VA).
4. Department of Health, Education and Welfare, "Human Drugs—Current Good Manufacturing Practice in Manufacture, Processing, Packing or Holding of Large Volume Parenterals, and Request for Comments Regarding Small Volume Parenterals," Fed. Regist. 41 (106), 22022–22115 (June 1, 1976).
5. 3-A Sanitary Standards Inc., McClean, VA.
6. FDA, "ORA Field Management Directive 135, Pre-Operational Reviews of Manufacturing Facilities" (FDA, Washington, DC, Dec. 4, 1995).
7. W. Garvey, "Effective Validation Project Management," oral presentation given at Interphex Conference 2005, New York, NY, April 26–28, 2005.
8. ISPE Baseline Pharmaceutical Engineering Guide, Pharmaceutical Engineering Guides for New and Renovated Facilities, Vol. 5, Commissioning and Qualification, (International Society for Pharmaceutical Engineering [ISPE], March 2001), pp. 11–15.
9. ISPE Baseline Pharmaceutical Engineering Guide, Pharmaceutical Engineering Guides for New and Renovated Facilities, Vol. 5, Commissioning and Qualification, (ISPE, March 2001), p. 111.
10. M. Chin, "TOP: A Rational Approach For Ensuring Proper Biopharmaceutical Plant Construction," in proceedings from PharmTech Conference '87 (Aster Publishing Corporation, Eugene, OR, 1987), p. 73.

Essentials of Validation Project Management Part 2

Reliable and controlled. Control systems such as programmable logic controllers (PLCs) should be used to control equipment. Automation allows processes to be replicated without variability, a fundamental principle on which GMPs are based. Mechanical-type (cam) controllers should be avoided because regulations require that current and modern technology be used. Manual control also should be avoided where possible because replication is inherently difficult. Any system that may alter batch-to-batch uniformity, and ultimately the product therapeutic response, must be very carefully considered.
Correct for application. The correct design criteria must be specified. For example, clean compressed air must have a dewpoint temperature of approximately –40 °F to prevent condensation. Refrigerated air driers cannot meet this requirement. Oil-free compressors should be used to exclude oil contamination unless several levels of filtration are used (4). Industry standards allow no more than 1 ppm (1 mg/m3 ) of oil/hydrocarbon in compressed air.
Besides developing some original standards for process equipment design and construction, the pharmaceutical industry has borrowed standards from industries that produce similar consumer products, most notably the dairy industry. The 3-A Sanitary Standards are voluntary guidelines followed by dairy equipment vendors and dairy operators. The standards provide material specifications, design criteria, and other necessary information for the construction of dairy equipment to satisfy public health concerns. The ultimate objective is to safeguard public health from contaminated dairy products.
To meet this objective, 3-A Sanitary Standards and 3-A Accepted Practices ensure that dairy, food, and other microbial-sensitive products are protected from contamination; that all product contact surfaces can be cleaned in place or easily dismantled for manual cleaning; and that all product contact surfaces can be easily inspected to confirm cleaning effectiveness (5). The purpose of these standards and their application to pharmaceutical manufacturing are readily apparent. The 3A Sanitary Standards should be consulted when equipment such as holding tanks, clean-in-place systems, valves, and pumps are undergoing GMP compliance review. Design errors are uncommon, however, because most equipment vendors already fully understand and comply with these standards. For high-value projects and facilities intended to manufacture sterile products, it is often required and worthwhile to contact the local FDA district office. This alerts the agency that inspections must be scheduled, often to coincide with critical construction milestones and events. FDA Office of Regulatory Affairs Field Management Directive (FMD) 135 also encourages manufacturers to contact FDA when facility and equipment designs are being prepared (6). The following is a summary of FMD 135, which can be found on FDA's Web site:
Providing [FDA] review and comment is desirable because it may reveal [design] defects early and prevent costly construction errors which could lead to defective operations and products. It also affords FDA the opportunity to become aware of future work load obligations and, in some cases, new technologies. Early field involvement with new or modified facilities will increase efficiency and result in the timely processing of applications (6).
Companies should understand and recognize that partnering with FDA to review proposed designs is beneficial to both parties. Costs and delays associated with rework can be avoided if problems are detected early. Definitive dates for facility inspections can be established, which serve as endpoints that motivate project completion. Current agency inspectional focus also may be apparent, foretold by the types of questions that are asked. Overall, early dialogue and FDA involvement may expedite facility completion, reduce engineering and construction costs, and lead to a smooth transition from start-up to operation. These results are desirable for all manufacturers, regardless of company size or complexity.
Scope definition, organization, and planning
Successfully implemented validation projects all begin with a well-defined scope (i.e., the set of activities and deliverables that must occur to complete the project). Scope definition is critical if contracted validation resources are used because it becomes the basis for cost estimates and assessing job completion.

Essentials of Validation Project Management Part I

Pharmaceutical Technology


VECTOR CORPORATION
The qualification and validation of complex pharmaceutical manufacturing facilities requires the careful coordination of multiple activities. Conceptual, preliminary, and detailed designs must be reviewed to ensure compliance with current good manufacturing practices (CGMPs); protocol and standard operating procedure (SOP) formats must be developed; and project resources must be identified and obtained. A validation schedule must be created and integrated with the facility construction schedule. The Quality Assurance and Calibration–Metrology departments must be notified of impending increased workloads. And finally, the manufacturer should alert the local US Food and Drug Administration district office that a new facility is planned. Considering all these activities, careful planning and cautious management will increase the likelihood of a successful project outcome, no matter how difficult or complicated the project. Successful project completion is never guaranteed, but by implementing proven techniques and the programs described in this article, a favorable end-result is much more likely. Parts 1 and 2 of this article will examine seven critical components of a comprehensive validation program for new and renovated manufacturing facilities. The programs and procedures explained are appropriate for all commonly manufactured dosage forms (e.g., tablets and capsules, active pharmaceutical ingredients [APIs], parenterals). Given that the design, construction, and qualification and validation of a major facility are relatively infrequent events in most corporate life cycles, some of these project components are not well known or understood. For this reason, Part 1 of this article examines the following areas:
  • facility- and equipment-design review to ensure compliance with CGMP regulations;
  • project scope definition, organization, and planning;
  • project labor requirements and budget;
  • validation master plan development.

Part 2 will continue with a discussion of the following validation-related subjects:
  • protocol and SOP development, scheduling, and implementation;
  • design- and construction-document collection (turnover package);
  • evaluation of deviations and discrepancies.

Facility- and equipment-design reviewBy definition, the construction of a new or renovated facility and the purchase and installation of mechanical equipment and process systems constitute a project. All projects have basic, common features: a logical start, a logical end, and little or no possibility of recurrence (i.e., the project will not repeat at some future time). In addition, the design process is common to all facility projects. All facilities start with a design, about which engineers, owners, scientists, and other stakeholders confer to determine how the facility will appear and operate and what equipment and systems are needed. The usual sequence starts with the development of a conceptual design by an engineering firm, from which preliminary decisions are made about facility layout and size, utilities required, and equipment capacity and material of construction. The process then continues into the preliminary and detailed engineering stages, in which costs are finalized and designs are completed and approved. It is at this point when the conceptual design transitions to preliminary engineering that formal review to verify GMP compliance begins.
In general, process equipment and utility systems affecting product quality or contacting product are the subject of design review. Typical reviewed utilities include heating, ventilation, and air-conditioning (HVAC), compendial waters (e.g., water-for-injection, purified water, clean steam), and compressed gases such as nitrogen and compressed air. At present, regulatory expectations for other utilities such as chilled water or plant steam are minimal, and these may be omitted. Design review is mandatory for highly customized or unique process equipment, particularly when the unit is custom manufactured. Equipment for critical processes such as aseptic filling and packaging, lyophilization, and final purification also requires rigorous evaluation. Because the GMP regulations are interpretive and nonspecific for equipment design and construction, the design engineer and owner are responsible for assessing compliance (1).
During the design review stage, the engineer and owner should evaluate all critical specifications and drawings to ensure that regulatory compliance is achieved. In general, experienced vendors understand the requirements imposed by GMP regulations and design and construct their equipment and systems accordingly. Rarely are serious design and construction errors uncovered because a reputable vendor's knowledge and understanding of GMP-compliant design often exceeds that of the owner and engineer combined (2). Design reviews should be performed using a structured and systematic approach. For mechanical systems such as HVAC, the evaluation of drawing sets takes precedence over most other documents. Vendor submittals always should be reviewed. Although less beneficial, Division 15, 22, and 23 type construction specifications (3) also should be examined, even though these are often standard with little customization. Checklists and other reviewing aids may be valuable because they prove that the designs were evaluated and they may be used again for subsequent projects.
Three critical steps must be taken in a design review:
  • identify and evaluate any potential areas or items of noncompliance;
  • ensure that designs are modified to eliminate noncompliant features;
  • prepare a brief report that summarizes the design-review process and obtain appropriate approvals, including quality assurance.

Much of the current content in both domestic and foreign GMP regulations is limited and nonspecific. The owner is obligated to review all designs and verify conformance with industry standards and regulatory guidelines. In the absence of standard equipment specifications within the GMPs, logic dictates that process equipment and utilities must be designed to be:

Figure 1: Valve orientation (45° above horizontal) and nonchloride insulation in purified water, USP system.
Nonreactive. Materials of construction must be inert and non-additive. Type 304 and Type 316 stainless steel are commonly used. Hastelloy C frequently is used in reactor systems and condensers. Wood should be avoided, even for utensils, because it can generate unwanted particulates and is porous and difficult to clean. Gaskets must withstand attack by process fluids and be dimensionally stable under expected temperature conditions. Chloride-containing insulation should not be used with stainless steel components (see Figure 1).

Figure 2: Fluidized bed dryer showing mechanical components requiring maintenance located outside the process space (photo courtesy of Vector Corporation).
Cleanable. Equipment surfaces must be smooth and free of voids and crevices in which material can accumulate. Welds must be polished smooth, although mirror polishing is not always recommended where glare is a concern. Short-radius corners are preferred at joined surfaces. Threaded fittings usually are not permitted on sanitary systems. Diaphragm valves must be installed on horizontal lines at 45° angles to ensure complete drainage (see Figure 1). Labeling and packaging equipment must be designed to permit thorough inspection. If cut labels are used, equipment should permit stray labels to fall to the floor unimpeded. Seamless floor coverings should be installed where practical because they prevent the infiltration and exfiltration of water and contaminants from and to sublayers. Valves and flanges should be minimized in concealed-piping runs over critical process areas where leakage or failure could be problematic.

Figure 3: Duplex steam-trap assembly at a critical air-handling unit.
Maintainable. Through-the-wall designs should be used where serviceable mechanical components are located outside process spaces (see Figure 2). Such items include HVAC air-control valves and instrumentation, process filters, and operator workstations. Remote grease fittings should be installed on fan bearings to minimize air handler entry. Adequate clearance should be allowed at heat exchangers to permit coil removal and inspection. Redundancy should always be considered for mission-critical systems, including sanitary pumps, steam traps (see Figure 3), filter assemblies and regulators, and recorders on sterilizers. Ergonomics also should be considered