{"id":461,"date":"2016-08-29T19:16:31","date_gmt":"2016-08-29T09:16:31","guid":{"rendered":"http:\/\/paulyeatman.net.au\/?p=461"},"modified":"2020-07-29T14:37:38","modified_gmt":"2020-07-29T03:37:38","slug":"notes-on-the-fda-draft-data-integrity-and-compliance-with-cgmp-guidance-for-industry","status":"publish","type":"post","link":"https:\/\/paulyeatman.net.au\/index.php\/2016\/08\/29\/notes-on-the-fda-draft-data-integrity-and-compliance-with-cgmp-guidance-for-industry\/","title":{"rendered":"Notes on the FDA&#8217;s Draft Data Integrity and Compliance With CGMP Guidance for Industry"},"content":{"rendered":"<p>Having worked in the pharmaceutical industry where I&#8217;ve dealt with electronic systems, paper based systems, programmed my own access databases and Excel spreadsheet\u00a0 and been on projects such as LIMS system validation, I figured I&#8217;d make notes on the FDA&#8217;s 2016 guidance for industry document regarding <span style=\"text-decoration: underline;\">Data Integrity and Compliance With CGMP<\/span>.\u00a0 This draft is for currently open for comment and the guidance addresses data integrity in:<\/p>\n<ul>\n<li>drug manufacture<\/li>\n<li>finished pharmaceuticals<\/li>\n<li>positron emission tomography drugs<\/li>\n<\/ul>\n<p><!--more--><\/p>\n<p>Knowing about the data integrity requirements (and more importantly, keeping your data intact), will reduce the likelihood of the FDA (or other Government regulatory body) citing you on deficiencies.\u00a0 Personally knowing about this should help resume my scientific career and it&#8217;ll definitely add to my knowledge.\u00a0 One should note that data is<em> ALL<\/em> data, both physical <em>AND<\/em> electronic.<\/p>\n<p>Sections of the non binding, not for implementation Draft Guidance<\/p>\n<ul>\n<li>Introduction<\/li>\n<li>Background<\/li>\n<li>Questions and answers<\/li>\n<\/ul>\n<p>With the nature of the document being draft and not for implementation, the content is still a very good guide on what is expected of manufacturers working to the cGMP.<\/p>\n<h3>Introduction<\/h3>\n<ul>\n<li>21 CFR parts 210, 211 and 212 detail cGMP for drugs as follows:\n<ul>\n<li>210: Current Good Manufacturing Practice in Manufacturing, Processing, Packing or Holding of Drugs, general<\/li>\n<li>211: Current Good Manufacturing Practice for Finished Pharmaceuticals<\/li>\n<li>212: Current Good Manufacturing Practice for Positron Emission Tomography Drugs<\/li>\n<\/ul>\n<\/li>\n<\/ul>\n<p>Dara should be reliable and accurate.\u00a0 Risk based strategies can be used to detect data integrity issues. Management strategies should be meaningful and effective.\u00a0 <em>Things get a little hazy here as these strategies are based upon the manufacturer\u2019s process understanding and knowledge management of technologies and business models \u2013 you need to employ people who know your tech and operating practices and who are adequately training in such.\u00a0 I find most people have a pretty tenuous grasp of technology once it surpasses the purely mechanical.<\/em><\/p>\n<p><em>In guidance speak, \u201cshould\u201d is a recommended or suggested action.\u00a0 In reality, if you do not do it, you need to justify why not (which should not be too hard as your processes will be documented and validated to regulatory requirements).<\/em><\/p>\n<h3>Background<\/h3>\n<p>The guide has been created as the number of cGMP data integrity violations has been going up.\u00a0 This troubles the FDA (and it should you to) as data integrity\u2019s a key component to ensuring the products you make are unadulterated and your end-user is safe from harm (when your product is used correctly).<\/p>\n<p>CFR\u2019s 210 \u2013 212 set out the minimum requirements.\u00a0 Examples are:<\/p>\n<ul>\n<li>68 Backups are complete and unalterable<\/li>\n<li>110(b) Data to be stored to prevent deterioration or loss<\/li>\n<li>100 &amp; 211.160 Document as it happens and use scientifically sound lab controls<\/li>\n<li>180 Retained data to be classified as original, true copies or some other term that indicates the data is a true reproduction (not representation) of the original records<\/li>\n<li>188, 211.194 &amp; 212.60(g) ALL data needs to be recorded. <em>Complete gets written a lot.<\/em><\/li>\n<\/ul>\n<p>21 CFR 11 <em>Guidance for Industry, Part 11, Electronic Records; Electronic Signatures \u2013 Scope and Application<\/em>, \u00a0which I\u2019ve had loads of exposure, having been on a LIMS validation project, sets out the requirements for electronic signatures and record keeping.<\/p>\n<h3>Questions and answers<\/h3>\n<p><strong>Q1a: What is \u201cdata integrity?\u201d<\/strong><\/p>\n<p>A: According to this guidance, complete, consistent, accurate data.\u00a0 Attributable, legible, contemporaneously recorded original (or true copy) and accurate.\u00a0 <em>NOTE, accurate is used twice.\u00a0 Acronym of ALCOA used.<\/em><\/p>\n<p><strong>Q1b: What is \u201cmeta data?\u201d<\/strong><\/p>\n<p>A: Contextual information required to understand data.\u00a0 Structured information that describes, explains or makes easy to retrieve, use or manage data.\u00a0 <em>Basically a good filing system, database or LIMS setup.<\/em> Example of metadata for a given data point include time stamp, user ID, instrument ID, audit trails etc.<\/p>\n<p><strong>Q1c: What is \u201caudit trail?\u201d<\/strong><\/p>\n<p>A: For guidance purposes, this means a secure, computer generated, time stamped electronic record that allows for reconstruction of the course of events relating to the creation, modification, or deletion of an electronic record.\u00a0 It details who, what, when and why.<\/p>\n<p>As well as recording the creation, modification or deletion, the audit trail also should show attempts to access the system and file rename or deletion attempts.<\/p>\n<p>cGMP compliant record keeping prevents (<em>I\u2019d say reduces the likelihood of<\/em>) data from being lost or obscured.<\/p>\n<p><strong>Q1d: How do \u201cstatic and dynamic relate to record formats?\u201d<\/strong><\/p>\n<p>A: \u201cStatic\u201d: fixed-data document.\u00a0 Eg paper record, electronic image. \u201cDynamic\u201d: the record format allows interaction between user and the record content.\u00a0 <em>Eg, tweaking coding on a spreadsheet that calculates antibiotic potency could skew the results.\u00a0 Such formulas should be locked down.\u00a0 NOTE: electronic images can be manipulated quite easily if you know what you are doing.\u00a0 Here you\u2019d want to make sure modification time stamps are recorded as part of the audit trail (perhaps as a red flag if the file\u2019s modified\/accessed outside of the viewing program).<\/em><\/p>\n<p><strong>Q1e: What is \u201cbackup 211.68(b)?\u201d<\/strong><\/p>\n<p>A: A true copy of the original data that is maintained securely for the record retention period.\u00a0 The backup should contain meta data (so the data makes sense\/can be retrieved) and in its original format or compatible with original format.<em>\u00a0 So if paper, needs to be a photocopy or would a scanned document that can be printed suffice?\u00a0 Most likely paper, as conversion to electronic data would require audit trails and that might impose an unacceptable dollar penalty\/overhead.<\/em><\/p>\n<p>Different to routine systems backup of data as they tend to be temporary and not archived.<\/p>\n<p><strong>Q1f: What are the \u201csystems\u201d in \u201ccomputer or related systems\u201d in 211.68?<\/strong><\/p>\n<p>A: With reference to the American National Standards Institute:<\/p>\n<ul>\n<li>Systems: people, machines and methods organised to accomplish a set of specific instructions.<\/li>\n<li>Computer or related systems: computer hardware, software, peripherals, networks, off site networked infrastructure (cloud), operators, associated documents such as manuals, SOPs etc.<\/li>\n<\/ul>\n<p><strong>Q2: When is it permissible to exclude cGMP data from decision making?<\/strong><\/p>\n<p>A: <em>I\u2019d be inclined to say never!\u00a0 The guidance agrees.<\/em>\u00a0 As per usual, if one was to exclude data, there must be a valid, documented, scientific justification for its exclusion<em>.\u00a0 In reality, the data is not excluded, your OOS procedure will take the data into account and a risk based approach will determine how likely such data is to impact negatively on product quality and ultimately the end user.<\/em><\/p>\n<p><strong>Q3: Does each workflow on our computer system need to be validated.<\/strong><\/p>\n<p>A: <em>I am REALLY surprised this needs to be asked. You need to document everything.\u00a0 <a href=\"http:\/\/paulyeatman.net.au\/index.php\/2016\/08\/11\/notes-on-pics-guide-for-good-manufacturing-practice-for-medicinal-products-2009\/\" target=\"_blank\" rel=\"noopener\">See my notes on the PIC\/s Guide to GMP <\/a>.\u00a0 You need to validate everything.\u00a0 IF IT IS NOT DOCUMENTED IT NEVER HAPPENED.\u00a0 <\/em>(This is not to say if you do not document a stuff up, it never happened.\u00a0 It did and it\u2019ll most likely be revealed by way of audit or customer complaint\/adverse reaction).<\/p>\n<p><em>For computer systems.\u00a0 URS.\u00a0 IQ.\u00a0 OQ.\u00a0 PQ.<\/em><\/p>\n<p><strong>Q4: \u00a0How should access to cGMP computer systems be restricted?<\/strong><\/p>\n<p>A: For electronic systems, user access with appropriate permissions.\u00a0 It is suggested the system\u2019s admin not be a member of the data recording team<em>.\u00a0 Eg, for a microbiology or chemistry lab, the admin should not be working for the lab.\u00a0 It might make things tedious at times, but it improves the integrity of your data.<\/em><\/p>\n<p>Maintain the list of authorised individuals along with access rights for each cGMP system.<\/p>\n<p>If the site is small as roles of admin and user cannot be split, it is suggested a second person review the settings and content.\u00a0 If that is not possible, the sole user should recheck settings and their work before pressing the commit\/enter\/submit button.<\/p>\n<p><strong>Q5: What is FDA concerned with the use of shared login accounts for computer systems?<\/strong><\/p>\n<p>A: <em>For the same reason anyone concerned about IT security is!\u00a0 So only authorised users can enter or modify or access data.\u00a0 Recall that the user ID forms part of the meta data.\u00a0 Sharing logins means your data is not cGMP compliant and thus your product is adulterated.<\/em><\/p>\n<p><strong>Q6: How should blank forms be controlled?<\/strong><\/p>\n<p>A: <em>This one\u2019s interesting as I worked at a site that moved from printed out\/photocopied forms to electronically issued blank forms. The electronically issued worksheets were issue number and date stamped and included an electronic record of who printed the sheet.\u00a0 This still does not prevent an operator from photocopying the newly printed sheet if they were inclined to. A check of bins and desk would reveal such a practice pretty quickly.<\/em><\/p>\n<p>Incomplete or erroneous forms should be kept as part of the original data.\u00a0 A book of numbered forms could be kept (and reconciled), or page numbered workbooks with document control group use approval stamps could be used (<em>this is to prevent cooking the books)<\/em>.<\/p>\n<p><strong>Q7: How often should audit trails be reviewed?<\/strong><\/p>\n<p>A: They should be reviewed along with the batch record before final approval.<\/p>\n<p><strong>Q8: Who should review the audit trails?<\/strong><\/p>\n<p>A: For all production and quality records, the quality unit (CFR 211.192)<\/p>\n<p><strong>Q9: Can electronic copies be used as accurate reproductions of paper or electronic records?<\/strong><\/p>\n<p>A:<em> I surmised something about this in Q1e, though the FDA\u2019s clearly not expecting anyone to run around photoshopping scanned in documents or modifying them in Indesign.<\/em>\u00a0 The answer is yes, provided the copies preserve the content and meaning of the original data, including associated metadata and the static or dynamic nature of the original records.<\/p>\n<p><strong>Q10: Is it acceptable to retain paper printouts or static records instead of original 260 electronic records from stand-alone computerized laboratory instruments, 261 such as an FT-IR instrument?<\/strong><\/p>\n<p>A: If it is a complete copy of the original record.\u00a0 Some equipment is read out only (scales, pH meters etc), so some other way or recording the displayed data is needed.<\/p>\n<p>In the case of dynamic records printouts do no preserve the dynamic format of the data.\u00a0 Eg electronic data can be reprocessed, where are a printout of what you see on screen cannot.<\/p>\n<p>Control strategies such as second person review of original paper and electronic records is recommended as per 211.194(a)(8) to ensure all results are appropriately recorded.<\/p>\n<p>For PET drugs, see guidance for industry PET Drugs \u2014 Current Good Manufacturing 282 Practice (CGMP),<\/p>\n<p><strong>Q11: Can electronic signatures be used instead of handwritten signatures for master production and control records?<\/strong><\/p>\n<p>A: Yes.\u00a0 The intent of a signature (written or otherwise) is to identify who\u2019s signed off on the data.\u00a0 As usual, your procedures on controlling electronic signatures needs to be documented.<\/p>\n<p><strong>Q12: When does electronic data become a CGMP record?<\/strong><\/p>\n<p>A: <em>As soon as it is created.\u00a0 Lots of waffle here for what is a cut and dry answer.<\/em><\/p>\n<p><strong>Q13: Why has the FDA cited use of actual samples during \u201csystem suitability\u201d or test, prep, or equilibration runs in warning letters?<\/strong><\/p>\n<p>A: Testing into compliance is frowned upon.\u00a0 The FDA considers (in some situations) using an actual sample in test, prep or equilibration runs a violative practice as it is a means of disguising testing into compliance.\u00a0 <em>I\u2019m a bit fuzzy on this as a microbiologist.\u00a0 You have a sample.\u00a0 You test it.\u00a0 You get a result.\u00a0 \u00a0Perhaps they mean use negative and positive controls.\u00a0 Though, when testing antibiotics, you could test three samples from the one batch where the average result would be within spec.\u00a0 That was not something we allowed.<\/em><\/p>\n<p>We are pointed towards ICH guidance for industry <em>Q2(R1) Validation of \u00a0Analytical Procedures: Text and Methodology <\/em>(a 1994 document) for more information.<\/p>\n<p><strong>Q14: Is it acceptable to only save the final results from reprocessed laboratory chromatography?<\/strong><\/p>\n<p>A: No!\u00a0 Reprocessed results are not original data.\u00a0 You need to show the original result <em>and<\/em> the reprocessed result.<\/p>\n<p><strong>Q15: Can an internal tip regarding a quality issue, such as potential data falsification, be handled informally outside of the documented CGMP quality system?<\/strong><\/p>\n<p>A: Here, any tip must be treated as legitimate and a documented investigation carried out in case product quality\/patient safety is affected.\u00a0 <em>For both, CAPA should prevent (reduce likelihood) of future (fraudulent) modification, thus reducing likelihood of suspicion as with appropriate checks and balances, alteration at the very least should not be possible without appropriate permission for electronic records.<\/em><\/p>\n<p>Details of how to tip off the FDA are provided.<\/p>\n<p><strong>Q16: Should personnel be trained in detecting data integrity issues as part of a routine CGMP training program?<\/strong><\/p>\n<p>A: In so far as it suits their role as personnel must have the education, training and experience required to perform their assigned duties.<\/p>\n<p>Q17: Is the FDA investigator allowed to look at my electronic records?<\/p>\n<p>A: All data associated with batch records and process\/plant validation, training etc is subject to regulatory inspection and audit.<\/p>\n<p><strong>Q18: How does FDA recommend data integrity problems identified during inspections, in warning letters, or in other regulatory actions be addressed?<\/strong><\/p>\n<p>A: It looks like here, the FDA has no confidence in you internal systems and knowledge and suggest you hire a third party auditor to determine the scope of the issue and implement CAPA.\u00a0 If individuals responsible for data integrity issues are identified, remove them from cGMP positions. At the very least, retrain them unless the issue is chronic.<\/p>\n<p>The FDA\u2019s expectations mirror those in a 1991 <a href=\"http:\/\/www.fda.gov\/ICECI\/EnforcementActions\/ApplicationIntegrityPolicy\/ucm134744.htm\" target=\"_blank\" rel=\"noopener\">document available here<\/a>.<\/p>\n<h3>Additional links and references<\/h3>\n<p><a href=\"http:\/\/paulyeatman.net.au\/wp-content\/uploads\/2016\/08\/FDA-Guidance-for-industry-Draft-Data-Integrity.pdf\">FDA Guidance for industry &#8211; PDF<\/a><\/p>\n<p>Most importantly for Australian manufacture, here is a link to <a href=\"http:\/\/paulyeatman.net.au\/wp-content\/uploads\/2016\/08\/tga-presentation-give-pda-conference-july-2015.pdf\">the TGA&#8217;s Data Integrity expectations<\/a> dated July 2015.<\/p>\n<p>Here is a presentation given by the TGA in 2005 regarding the <a href=\"http:\/\/paulyeatman.net.au\/wp-content\/uploads\/2016\/08\/TGA-auditing-of-computerised-systems-for-pharmaceutical-and-medical-devices.pdf\">Auditing of Computerised Systems for Pharmaceuticals and Medical Devices.<\/a><\/p>\n<p><strong>Did you find this informative or useful? Please consider a small donation so I can expand and improve on what I deliver.<\/strong><\/p>\n<p><input title=\"PayPal - The safer, easier way to pay online!\" alt=\"Donate with PayPal button\" name=\"submit\" src=\"https:\/\/www.paypalobjects.com\/en_AU\/i\/btn\/btn_donateCC_LG.gif\" type=\"image\" \/><img loading=\"lazy\" decoding=\"async\" src=\"https:\/\/www.paypal.com\/en_AU\/i\/scr\/pixel.gif\" alt=\"\" width=\"1\" height=\"1\" border=\"0\" \/><\/p>\n","protected":false},"excerpt":{"rendered":"<p>Having worked in the pharmaceutical industry where I&#8217;ve dealt with electronic systems, paper based systems, programmed my own access databases and Excel spreadsheet\u00a0 and been on projects such as LIMS system validation, I figured I&#8217;d make notes on the FDA&#8217;s 2016 guidance for industry document regarding Data Integrity and Compliance With CGMP.\u00a0 This draft is [&hellip;]<\/p>\n","protected":false},"author":1,"featured_media":0,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[7,5,2],"tags":[30,37,12],"class_list":["post-461","post","type-post","status-publish","format-standard","hentry","category-commentary","category-documentation","category-the-regs","tag-data","tag-fda","tag-guidelines"],"_links":{"self":[{"href":"https:\/\/paulyeatman.net.au\/index.php\/wp-json\/wp\/v2\/posts\/461","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/paulyeatman.net.au\/index.php\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/paulyeatman.net.au\/index.php\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/paulyeatman.net.au\/index.php\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/paulyeatman.net.au\/index.php\/wp-json\/wp\/v2\/comments?post=461"}],"version-history":[{"count":11,"href":"https:\/\/paulyeatman.net.au\/index.php\/wp-json\/wp\/v2\/posts\/461\/revisions"}],"predecessor-version":[{"id":1214,"href":"https:\/\/paulyeatman.net.au\/index.php\/wp-json\/wp\/v2\/posts\/461\/revisions\/1214"}],"wp:attachment":[{"href":"https:\/\/paulyeatman.net.au\/index.php\/wp-json\/wp\/v2\/media?parent=461"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/paulyeatman.net.au\/index.php\/wp-json\/wp\/v2\/categories?post=461"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/paulyeatman.net.au\/index.php\/wp-json\/wp\/v2\/tags?post=461"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}