What QMS validation involves
The documents, the sequence, and the one fact about responsibility that decides everything else.
Validation means documented evidence that a system does what you specified it should do. Not that it works. That it does what you wrote down, and that you can prove it.
This page sets out the documents, the sequence and the division of responsibility.
Who is responsible
Regulatory responsibility for a validated computerized system rests with the regulated company that uses it. It cannot be transferred to the software supplier. This is the position of EU GMP Annex 11 and of GAMP 5.
A supplier can validate their product. That is the supplier's own work, and it is useful. It is not your validation.
A company that believes the supplier has already validated the system for them is exposed at inspection. This is the most common and most expensive misunderstanding in this subject.
The two tiers
Validation happens twice, by two parties, for two different purposes.
| Tier 1 | Tier 2 | |
|---|---|---|
| Performed by | The supplier | You |
| Establishes | The product works as specified | The system, as configured for you, is fit for your use |
| Environment | The supplier's | Yours |
| Owns the release decision | The supplier | You |
Under GAMP 5 you may rely on supplier documentation and testing to avoid repeating work. That reliance has to be justified by a supplier assessment. This is why customers audit their software suppliers.
The documents
Tier 2 needs five things.
- An intended-use statement and user requirements. What you will use the system for, and what it must do. Only you can write this.
- IQ, Installation Qualification. Evidence that the system is installed as specified, in the environment you will use. It records your configuration baseline.
- OQ, Operational Qualification. Evidence that each function works against your requirements, including your workflows, picklists, roles and license assignment.
- PQ, Performance Qualification. Evidence that trained users, following your SOPs, can run your processes on production-representative data.
- A traceability matrix. A table linking each requirement to the test that verifies it. An inspector uses it to check that nothing was specified and left untested.
A risk assessment sits alongside these and decides how much testing each function needs.
The sequence
- Write the intended-use statement and the user requirements.
- Assess risk, and set the depth of testing.
- Write or adopt the IQ, OQ and PQ protocols.
- Approve the protocols before executing them. A protocol approved after the fact is not evidence.
- Execute them. Record the actual result beside each expected result, with a signature and a date.
- Raise a deviation for anything that fails, and record its disposition.
- Have somebody independent review the executed package.
- Make and sign the release decision.
Two practical constraints
You need at least two people who can sign. A quality system separates the person who performs an action from the person who approves it. One tester cannot complete a workflow protocol alone. This is a scheduling problem, not a software problem, and it is usually discovered late.
Validation does not end at release. Every change is assessed. A vendor upgrade is a change. Most companies also perform a periodic review, typically annually, to confirm the system is still in its validated state.
What it costs
Published figures put internal QA time at 150 to 400 hours, and an external validation consultant at $175 to $250 per hour for 100 to 250 hours. Keeping a system validated costs $20,000 to $75,000 per year.
Writing the documents is most of that cost. Executing them is a much smaller part.
The full cost of a QMS, with the other three numbers.
What Hemeralis supplies
Hemeralis QMS is supplied with the Tier 2 documents already written:
- requirement specifications for each module;
- IQ, OQ and PQ protocols;
- a traceability matrix linking every requirement to the test that verifies it.
You execute these documents instead of writing them. Writing them is most of the cost and most of the elapsed time.
The system also enforces the controls the protocols test. Electronic signatures use two authentication factors. The audit trail is tamper-evident. Segregation of duties is enforced by the workflow, so a protocol step that requires two signers cannot be completed by one.
What Hemeralis does not do
Hemeralis does not validate your instance for you, and no supplier can. The intended-use statement is yours. The risk assessment is yours. The execution, the deviations and the release decision are yours.
What a supplier can remove is the writing. That is the part worth removing.