Choosing a QMS when you have no IT department
Most quality software assumes staff you do not have. These are the questions that decide whether you can run it.
Most quality software is designed for a company with an IT department, a validation department and a business analyst who owns the configuration.
A company of twenty people has none of these. That changes which systems you can run, not only which ones you can afford.
Six jobs have to be done by someone. This page asks who.
1. Installation and servers
An on-premise system needs a server, an operating system, a database, backups and security patching. That is an IT department.
Ask whether the system is cloud-only, or whether cloud is one option among several. A vendor whose main product is on-premise will treat their cloud version as secondary.
2. Configuration
Workflows, required fields, picklists and roles all have to be set up, and then changed as your processes change.
Ask two questions. Which changes can you make yourself, through screens? And for the rest, is the vendor doing it, or are you paying a consultant each time?
A system where every field change is a professional services request is a system you cannot afford to keep current.
3. User administration and access review
Someone must add users, assign roles, remove leavers and perform the periodic access review. EU GMP Annex 11 expects that review.
Ask whether user administration is self-service, and whether every role granted or removed is written to the audit trail. If it is not recorded, the access review becomes a manual reconstruction.
4. Backup and recovery
Ask for the recovery point objective and the recovery time objective, as figures, in the contract. "Backed up daily" is not an answer. It describes what the vendor does, not what you are entitled to.
5. Upgrades
In a cloud system the vendor upgrades the software. Each upgrade is a change you must assess.
Ask how much notice you get, what documentation comes with the release, and whether you can decline or defer an upgrade.
6. Integrations
Connecting a QMS to an ERP or a LIMS is IT work, and it is validated work.
Most small companies do not need it on day one. Decide whether you need it before you pay for it, because integration is often where an implementation budget goes.
Warning signs
- The demonstration is given by a consultant who will also quote for the implementation.
- Configuration is described as "flexible" and turns out to mean a scripting language.
- The quote has a services line larger than the license line.
- Recovery objectives are described in words instead of hours.
- The answer to "who does this?" is "your system owner", and you do not have one.
What Hemeralis does
Hemeralis QMS is vendor-operated. There is nothing to install, no server to run and no database to administer. It runs in Frankfurt, in the European Union.
The split between what you manage and what the vendor manages is deliberate.
You manage, through screens:
- users, licenses and roles;
- picklist values;
- company settings;
- record reassignment when somebody leaves;
- exports for inspections and audits.
The vendor configures:
- workflows and their approval steps;
- which fields are required, and when;
- notification rules and templates.
That division follows the skill each job needs. Adding a user is a daily task and belongs to you. Changing a workflow step in a validated system is a controlled change, and it belongs to the people who will also supply the qualification protocol for it.
Every role granted or removed is written to the audit trail, so the periodic access review is answered from the system rather than reconstructed.
What Hemeralis does not do
Hemeralis does not remove the need for a person who owns quality decisions. Someone still approves records, reviews access and signs. The software enforces who may do what; it does not decide.
It also does not validate your instance. Validation stays with the regulated company, and no supplier can take it.