Search This Blog

Showing posts with label GMPs. Show all posts
Showing posts with label GMPs. Show all posts

Monday, February 14, 2011

Managing the Validation of Custom Databases

Written by Frederick Sperry - Validation Manager, QPharma


The management of custom databases does not need to be an onerous task.  When taken seriously, one can justify the management of the details associated with the database as Good Business Practices.  Even the elephant can be eaten – one bite at a time. 

Initially, as in any other activity in the regulated industry, know your process.  Identify the key parameters that user requirements have defined for the database.  What are the macros supposed to be doing, or any critical connections or formulas expected to produce?  Document the findings as an initial deployment of the system, and get a system user review and approval of the requirements for the database.

Validate your process.  Document the settings and verify the any formulas, macros of interfaces do what they are supposed to accomplish.  Adjust any settings that do not meet the needs of the end users.  Then update your documentation, and get review and approval signatures of the documentation.  Typically this is in the form of a System Design Specification, System Configuration or Functional Specification document.  The title of the document is not important; the current information is the critical item.

After the ‘deployment’ of the database keep the documentation current.  The database configuration and settings are liable to change over the course of normal system usage.  Keep track of the changes and periodically update the system documentation, and obtain the crucial user or management review, approval and sign off of the updated system settings.

Keep current with the data and database and embrace the new era paradigm shift from documentation to information.  The documentation must empower the system users to be able to use the information as knowledge.  In this new millennia day and age of information, knowledge is truly power.

Tuesday, November 16, 2010

Recommendations for an Effective Vendor Qualification Program - Part 2 of 2

Written by Teresa Jaworski – Subject Matter Expert, QPharma


In last week’s post, I shared with you some preliminary guidelines for qualifying a vendor. Here is Part 2 of that post:

Pre-Audit Questionnaire


If it is determined that a new vendor is needed, you should select a minimum of three (3) vendors, if possible, which can supply the product or services needed ( raw materials, components, manufacturing equipment, testing equipment, consulting services, etc.). The approved procedure should provide guidance for selecting these vendors. Once the potential vendors are selected, a pre-audit questionnaire should be provided to and completed by each of the potential vendors. The results from the completed questionnaire should be used to determine if the vendor will continue in the qualification process.


Onsite Vendor Audit


If it is determined that the potential vendor meets the criteria for continuing the qualification process per review of the completed questionnaire, schedule an initial, onsite audit as defined in the approved procedures.


When conducting the audit, the appropriate audit checklist should be used according to whether the vendor is defined as a critical or non-critical vendor. In addition, the onsite audit should include verification that the established requirements and specifications can be met by the vendor. Then based on the overall results, the potential vendor can be either accepted or rejected. If accepted, the vendor is considered qualified. If rejected, the company can either work with the vendor to resolve discrepancies and qualify the vendor or select another potential vendor. All auditing activities and results should be documented and maintained.


Quality Agreement


If it is determined that the vendor is qualified, a written Quality Agreement should be developed and approved between the company and the vendor. According to Hasselbalch, “a GMP guidance detailing expectations for quality agreements is in the works as well, and the regulations may be further upgraded to support the guidance in this area. The guidance will explain the expectation that the agreement be in writing and specify clearly what each party commits to do.”


Development and approval of the Quality Agreement should include members from all relevant areas within the company’s organization, including but not limited to quality, procurement, manufacturing, product development, process development, regulatory, and legal. This agreement should define required quality standards; products or services provided; quality requirements and specifications including but not limited to training, qualifications, and monitoring expectations; key contacts; quality roles and responsibilities; locations; and necessary communications regarding quality-related activities.

Tuesday, September 7, 2010

FDA Announces Plans to Revise cGMP Regulations for Auditing Vendors


By year end 2010, FDA is planning to release new regulations that will include requirements for Pharmaceutical manufacturers to physically audit their vendors, no longer allowing paper audits to be acceptable. This change is being considered because of the large number of gaps being found in manufacturers’ quality systems due in part to the growth of production outsourcing. It is expected that once the drafting process of these proposed regulations is completed, they will be available for review and comments for approximately three to six months.

Brian Hasselbalch
According to Brian Hasselbalch, representing the Office of Compliance’s Division for Manufacturing and Drug Product Quality within FDA’s Center for Drug Evaluation and Research, at a conference held jointly by the agency and Xavier University in Cincinnati, Ohio, June 13-16, “between 2001 and 2007, the number of products manufactured outside the United States and the number of manufacturing sites abroad doubled. Some of the new products being imported into the US come from countries with less developed regulatory systems.”

As indicated in the U.S. Food and Drug Administration (FDA) Guidance for Industry Q10 Pharmaceutical Quality System, which is in accordance with 21 CFR Part 820.50, Pharmaceutical companies are ultimately responsible for ensuring that processes are in place to assure the control of outsourced activities and quality. In doing so, companies should implement processes to access the suitability and competence of a vendor prior to outsourcing operations or selecting them as a vendor. This can be accomplished by establishing approved procedures, performing audits, and ensuring qualifications. Note that defined quality requirements should be used during the auditing process to ensure the vendor is capable of meeting these requirements. The evaluation results should be documented.

If it is determined that the vendor is qualified, an approved, written agreement, often referred to as a Quality Agreement, that defines quality requirements, responsibilities, and communications necessary for quality-related activities, should be created and approved between the two parties. Records of acceptable vendors should be established and maintained via an Approved Vendor List.

If a company does not have an Approved Vendor List, it cannot be concluded that vendors being used by the company are qualified to provide the products and services being used for cGxP purposes. With the establishment of an Approved Vendor List, a company can work smarter, not harder. A company will be able to determine if a qualified vendor is currently available that can provide the necessary products or services instead of going through the entire qualification process each time a new vendor is needed. It also ensures that several vendors are not being used for identical products or services. In the end, this will result in better utilization of resources, an improved state of regulatory compliance, and a cost reduction for the company.

However, having these procedures in place does not ensure proper implementation of them. Training should be conducted and documented on these approved procedures, emphasizing the need for quality in all aspects of the vendor qualification process including ensuring that all required vendor assessment and auditing documentation is stored in a centralized, secure location.

A vendor audit does not have to be conducted by a company representative. It is acceptable to use contracted resources to perform these audits as long as the resources are qualified to perform the tasks and the qualifications are documented. According to Hasselbalch, “We will not demand that you individually audit. We acknowledge and recognize a surrogate or a third party audit arrangement. It may be more efficient and more effective, quite honestly. A third party audit would have to be performed by a credible auditing arm [with] certain characteristics that assure the integrity and the quality of the audits.”

Refer to the links below for FDA MedWatch reports relevant to outsourcing.

Monday, June 21, 2010

FDA's New Push on Software as a Medical Device


On October 26, 2006, FDA issued a Warning Letter to Patterson Technology of Effingham, IL, for marketing an adulterated medical device. That "device" was their EagleSoft patient recordkeeping software package (I am passingly familiar with EagleSoft: my dentist uses it). In that Letter, FDA claimed that EagleSoft constituted an "unclassified" medical device, subject to GMPs and Design Controls (21 CFR 820.30(a)(2)(i)).

Immediately after this Letter was issued, I received a number of inquiries both directly from software companies and through associates. What did this Letter mean? How can software which does not itself "treat, diagnose, or mitigate a disease or function" (21 U.S.C. 321) possibly be a medical device? And what does it mean to be an "unclassified" device, when the Safe Medical Device Act specifies that within the United States, a Medical Device is always Class I, Class II, or Class III?

My short-term advice was: you should have basic quality systems in-place anyway, you should be doing design controls anyway. In my opinion, FDA had no legal authority to issue such Warning Letters since there was no such thing as an "unclassified" device in the Act but hey, that didn't stop them from going after a company marketing identification tags for subdermal implantation and pursuing them for years in the courts, only to finally have a judge rule that no way did Congress give FDA that authority. But since you should be doing these basic quality things anyway, don't bother fighting it.

Meanwhile, the number of software applications that potentially touch upon the medical care of the public has absolutely exploded. This is especially true in two areas: handheld devices used by Sales Reps to collect and transmit patient information (directly or through physicians), and web-based "cloud" systems.

This year, John Murray, CDRH's Subject Matter Expert on software (and therefore the person who largely determines FDA's policy on software enforcement) has been particularly busy. He has drafted a number of new guidance documents, including off-the-shelf software used inside medical devices and "cybersecurity" (more a list of topics than an actually useful guidance, IMHO...sorry, Mr. Murray). But his biggest contribution, hands-down, was a video he made earlier this year, CDRH Regulated Software: An Introduction.

In this video, Mr. Murray clarifies that he (meaning, of course, FDA) has determined that... (Click to read more)