Validation Best Practice for a SaaS



Similar documents
The SaaS LMS and Total Cost of Ownership in FDA-Regulated Companies

A Model for Training/Qualification Record Validation within the Talent Management System

GAMP 5 as a Suitable Framework for Validation of Electronic Document Management Systems On Premise and 'In the Cloud' Keith Williams CEO GxPi

GAMP 4 to GAMP 5 Summary

ComplianceWire COMPLIANCE MANAGEMENT FOR LIFE SCIENCE ORGANIZATIONS

Top Seven Risks to Consider When Selecting a Life Science LMS

GAMP 5 and the Supplier Leveraging supplier advantage out of compliance

A Quality and Compliance Training Road Map for Emerging FDA-Regulated Companies

Services Providers. Ivan Soto

Best Practices for Deploying a Learning Management System

GE Healthcare Life Sciences. Validation Services. Compliance support through life cycle management

Learning Management System Evaluation Guide

Using Training Data to Drive Up Quality Metrics SURVEY OF QUALITY ASSURANCE EXECUTIVES

Computerised Systems. Seeing the Wood from the Trees

OECD DRAFT ADVISORY DOCUMENT 16 1 THE APPLICATION OF GLP PRINCIPLES TO COMPUTERISED SYSTEMS FOREWARD

ComplianceSP TM on SharePoint. Complete Document & Process Management for Life Sciences on SharePoint 2010 & 2013

Considerations When Validating Your Analyst Software Per GAMP 5

Validated SaaS LMS SuccessFactors Viability

Clinical Platform Compliance in the Cloud

How To Run A Cloud Based Data Centre

Considerations for validating SDS Software v2.x Enterprise Edition for the 7900HT Fast Real-Time PCR System per the GAMP 5 guide

CONTENTS. List of Tables List of Figures

Pharma CloudAdoption. and Qualification Trends

This interpretation of the revised Annex

Testing Automated Manufacturing Processes

Using the ISPE s GAMP Methodology to Validate Environmental Monitoring System Software

Installation and Operational Qualification Protocol (Reference: SOP )

Computer System Validation - It s More Than Just Testing

Business Management System Manual. Context, Scope and Responsibilities

Computer System Configuration Management and Change Control

Qualification Guideline

GAMP5 - a lifecycle management framework for customized bioprocess solutions

LOW RISK APPROACH TO ACHIEVE PART 11 COMPLIANCE WITH SOLABS QM AND MS SHAREPOINT

Cloud Computing in a GxP Environment: The Promise, the Reality and the Path to Clarity

Computer System Configuration Management and Change Control

Welcome. Panel. Cloud Computing New Challenges in Data Integrity and Security 13 November 2014

ServiceNow Authorized Training Partner. Program Guide

Lab Service, Asset Management and Extending the Life of Your Lab Equipment. Scott Greenwood Director, Services

Cloud Computing: What needs to Be Validated and Qualified. Ivan Soto

Clinical database/ecrf validation: effective processes and procedures

INTRODUCTION. This book offers a systematic, ten-step approach, from the decision to validate to

Complete Document & Process Management for Life Sciences on SharePoint 2010

Saba Cloud Validated Environment Managed Services (VEMS)

QUESTIONS FOR YOUR SOFTWARE VENDOR: TO ASK BEFORE YOUR AUDIT

Assuring E Data Integrity and Part 11 Compliance for Empower How to Configure an Empower Enterprise

A Pragmatic Approach to the Testing of Excel Spreadsheets

ComplianceWire COMPREHENSIVE TRAINING SOLUTIONS FOR OPERATIONALLY EXCELLENT ORGANIZATIONS

What is the correct title of this publication? What is the current status of understanding and implementation?

How To Manage A Service Transition

Monitoring the autoclaving process in the pharmaceutical industry

Cloud Computing in GxP Environment

Overview of how to test a. Business Continuity Plan

Library Guide: Pharmaceutical GMPs

Monitoring manufacturing, production and storage environments in the pharmaceutical industry

SOLUTION BRIEF: CA IT ASSET MANAGER. How can I reduce IT asset costs to address my organization s budget pressures?

Regulated Mobile Applications

Custom Course Development Services


Project Prism - Kyle Hochenberger Johnson & Johnson SAP IT Service Management David Birkenbach SAP Session 1603

SaaS Adoption Lifecycle in Life-Sciences Companies

Overview of STS Consulting s IV&V Methodology

This is a training module for Maximo Asset Management V7.1. In this module, you learn to use the E-Signature user authentication feature.

Binary Tree Support. Comprehensive User Guide

Software Testing Lifecycle

Leveraging Rational Team Concert's build capabilities for Continuous Integration

A CRO's Dilemma - The CDMS Validation Package that Failed Client Audits 19.OCT Disclaimer

Validating Enterprise Systems: A Practical Guide

Introduction to SOA governance and service lifecycle management.

Training Course Computerized System Validation in the Pharmaceutical Industry Istanbul, January Change Control

PAS X. Competence. Implementation. Support. Services Overview. PAS-X Services. Global Service Centres

Library Guide: HIPAA

Designing a CDS Landscape that Ensures You Address the Latest Challenges of the Regulatory Bodies with Ease and Confidence

Clinical Training Management

Review and Approve Results in Empower Data, Meta Data and Audit Trails

Electronic Signatures in Contract Management

Complying with Global ERES Regulations in the Life Sciences Industry

GUIDELINES ON VALIDATION APPENDIX 5 VALIDATION OF COMPUTERIZED SYSTEMS

Altiris Asset Management Suite 7.1 from Symantec

TIBCO Spotfire and S+ Product Family

ALS Configuration Management Plan. Nuclear Safety Related

PeopleSoft HelpDesk. Maximized Operational Efficiency. Usability and Role-Based Access

Making SOP Training More Effective

International GMP Requirements for Quality Control Laboratories and Recomendations for Implementation

Altiris Asset Management Suite 7.0

Developing a Risk-Based Cloud Strategy

How CMOs are Turning Their Training Programs into Market Differentiators

Optimizing Quality Control / Quality Assurance Agents of a Global Sourcing / Procurement Strategy

QA Engagement Models. Managed / Integrated Test Center A Case Study

Using SharePoint 2013 for Managing Regulated Content in the Life Sciences. Presented by Paul Fenton President and CEO, Montrium

Transcription:

Validation Best Practice for a SaaS UL and the UL logo are trademarks of UL LLC 2012

Validation Best Practice for SaaS Validation Definition: Establishing documented evidence which provides a high degree of assurance that a specific computerized process or operation will consistently produce a quality result meeting its predetermined specifications. Source: GAMP 5-A Risk-Based Approach to Compliant GxP Computerized Systems, pg 335, appendix G2 2

Validation Best Practice for SaaS 2.1.5 Leveraging Supplier Involvement Regulated companies should seek to maximize supplier involvement throughout the system life cycle in order to leverage knowledge, experience, and documentation, subject to satisfactory supplier assessment. Source: GAMP 5-A Risk-Based Approach to Compliant GxP Computerized Systems, pg 21 3

Validation Best Practice for SaaS 2.1.5 Leveraging Supplier Involvement (cont d) Planning should determine how best to use supplier documentation, including existing test documentation, to avoid wasted effort and duplication. Justification for the use of supplier documentation should be provided by the satisfactory outcome of supplier assessments, which may include supplier audits. Vendor documentation should be assessed for suitability, accuracy, and completeness. There should be flexibility regarding acceptable format, structure, and documentation practices. Source: GAMP 5-A Risk-Based Approach to Compliant GxP Computerized Systems, pg 21 4

Validation Best Practice for SaaS One of the appeals of the SaaS application is that a company can shift some of the validation effort to the SaaS vendor. This enables the company s validation team to focus initially on an audit of the vendor s data center, as well as the vendor s QA and validation methodology, to ensure these activities are performed at the same standard as would be performed by the client s own QA and validation teams. Typically, the time spent auditing the SaaS vendor can dramatically reduce the time spent validating the system. 5

Validation Best Practice for SaaS Vendor Quality Process should include: - SDLC Methodology - Project Planning - Personnel Qualifications - Documentation Standards & Procedures - Methods for review & approval - Design Standards - Programming Standards - Configuration Management - Testing Standards & Procedures - Separation of Development, Test and Production Environments 6

Validation Best Practice for SaaS Vendor Quality Process should include: - Move to Production Process - Clearly defined responsibilities - Involvement of: Customer/User Quality Assurance professionals Technology Professionals Change Management Training process Process for continuous evaluation, incident monitoring, error correction Processes and procedures for physical & logical security of system and data 7

Validation Best Practice for SaaS Audit results may then be incorporated into a risk assessment to leverage vendor supplied documentation. In many cases, following an audit of the data center and software development lifecycle (SDLC) methodology, a client s audit and validation team will then develop only the core validation documents: - Validation Plan - User Requirements Specification - User Acceptance Test Scripts (including testing for customizations, integrations) - Validation Report - System Governance 8

System Governance Best Practice for SaaS Define Your Governance Model (System) Standardize Nomenclature and Other Meta Data Create Role Based Training Curricula Create Targeted Security Roles Define Integrations with other systems (HRIS, EDMS) Train Your Administrators and End Users Decentralize System Administration Appropriately Monitor the System Through Standard Reporting Practice Continuous Improvement 9

System Governance Best Practice for SaaS Define Your Governance Model (Procedures) - Use and Operation Procedures, including general Use and Operations for Users and User esignature certification - System Administration Procedures, including security roles, system admin roles and responsibilities, maintenance (including system releases), configuration changes requiring change control - Computer System Change Control, including standard operation procedures for system configuration changes, addition of new functionality, handling system releases 10

System Release UL and the UL logo are trademarks of UL LLC 2012

System Release Notifications Notification to System Admin- 30 Days prior to System Release Platform Release Notes: Enhancement List System Availability Regression Test Script Access Information Preview Testing Details Standard Enhancement Demos Notification to System Admin- 21 Days prior to System Release: Platform Release Guide Enhancement Details Elective Enhancement Demos Notification to System Admin- 14 Days prior to System Release: Final Release Details Premium Enhancement Demos 12

System Release-Enhancement Categories Standard Enhancements A platform impacting enhancement that affects ComplianceWire functionality for all Clients. Does not result in additional cost to existing ComplianceWire Clients. Changes to the ComplianceWire platform that are considered Standard are not configurable for individual instances and cannot be turned off. Documentation of changes and impacts will be provided with Release Communication. 13

System Release-Enhancement Categories Elective Enhancements A change to ComplianceWire platform functionality that is not defaulted to be enabled for all Clients and is available without additional cost. In many cases, this functionality can be enabled with a request to the Client Services Team at UL EduNeering who will modify a Client s ComplianceWire configuration. Details related to the operability, impact and activation instructions will be provided for Elective Enhancements in Release Communications. 14

System Release-Enhancement Categories Premium Enhancements A change to ComplianceWire functionality or tools that require additional cost or subscription. These changes will be documented on a high level in Release Communication. In many cases, the implementation of such enhancements requires further analysis of a Client s instance of ComplianceWire with additional implementation and application support. Clients who are interested are encouraged to contact their Account Director for more details and pricing. 15

System Release-Enhancement Categories Consultative Enhancements Functionality or tools that are being built and may have some components introduced to the infrastructure of ComplianceWire, but are not yet available or purchase. The changes will be documented on a high level in the Release Communication. In many cases, the implementation of Consultative Enhancements will require further analysis of a Client s instance of ComplianceWire. It may be necessary to customize changes, reconfigure or require professional services. Clients who are interested are encouraged to contact their Account Director for more details and pricing 16

System Release Example Process Overview Organizational administrator reviews the system release notes with appropriate business users, system owner, QA and IT to decide if any non standard enhancements will be utilized. Organizational administrator reviews the regression test scripts received for completeness for testing for standard enhancements and non standard enhancements being utilized. Organizational administrator completes an impact assessment form and coordinates with QA, IT and System owner to evaluate the impact and identify procedure changes that may require change control (i.e. New system feature being used) and any additional testing required. Note- most clients choose to use the UL EduNeering regression test scripts that are part of the release to save time and resources. 17

System Release Example Impact Assessment Example 18

System Release Example Impact Assessment Example Completed 19

System Release Example Impact Assessment Example Completed 20

System Release Example Impact Assessment Example Completed 21

Best Practice Tips Minimize validation- do an initial audit of vendor to determine if their validation processes are sufficient Audit at least every 2-3 years to ensure vendor is still in compliance with your standards Share validation responsibility with Vendor, QA, IT, Business owner, Administrators - Vendor audit of functional requirements should be referenced in your validation plan to justify why you didn t do full validation (IQ, OQ, SDS, Backup/restore etc) - QA review and approves documentation - IT review and approves documentation, sets up user PC environment - Business Owner- authors documentation - Administrators- Runs any test scripts 22