THANK YOU FOR SUBSCRIBING
A featured contribution from Leadership Perspectives: a curated forum reserved for leaders nominated by our subscribers and vetted by our Pharma Tech Outlook APAC Advisory Board.



Contract development and manufacturing organizations(CDMOs)today use an array of computerized systems to manage a large volume of essential data generated throughout a single project.
These systems can be used to enhance security, reduce human error, and assist in making processes more efficient. More importantly, these systems can help implement technical controls for data integrity (DI) in support of CDMOs’ timely decisions based on quality and reliable data. Before any technology consideration, a thorough understanding, establishment of the intended use, and risk mitigation are needed to ensure robust DI controls.
In this article, Calvin Kim, Senior Director and Head of IT Quality Systems& Validation at Samsung Biologics will discuss the importance of understanding the fundamentals of DI. He conveys that the challenges associated with achieving DI are largely down to our critical thinking skills to tackle key questions, as opposed to challenges with technology.
The ongoing challenge of maintaining DI when generating an abundance of data
Advances in technology have enhanced and accelerated digitization of processes while highlighting the many complexities involved in safeguarding DI.
With many development and manufacturing processes throughout drug production relying on heavily automated equipment and computerized systems, an abundance of data iscreated. It is essential that DI is ensured - it should be complete, consistent, and accurate so that it can be used for informed decisions with a minimal or mitigated impact to product quality and patient safety.
Without safeguarding integrity of data throughout its lifecycle, data generated throughout drug development and manufacturing cannot be considered reliable. If this unreliable data is used to make decisions it could have disastrous consequences, including safety risks, recalls, and denied drug approvals.
The importance of DI and the potential risks involved in its absence have necessitated the introduction of regulations. These have been mandated by the FDA and have been consistently updated following their introduction in the early ‘60s. In particular, 21 CFR (Code of Federal Regulations) Part 11published by the FDA in 1997 provides regulatory requirements surrounding electronic records and electronic signatures (ERES), including DI controls and computerized system validation.
The FDA and other regulatory agencies have also outlined that complete, consistent, and accurate data needs to be ALCOA - standing for “Attributable, Legible, Contemporaneous, Original, and Accurate”. DI can be further assured by following the ALCOA+ principles, which have an additional emphasis on the attributes of being complete, consistent, enduring, and available. Understanding and implementation of the requirements of ALCOA+ principles in computerized systems continues to be a challenge to many CDMOs today.
A barrier to building robust DI controls: A lack of understanding
When implemented well, technologies that record, manage, and store data with robust DI controls to minimize human error will simplify conformance with the ALCOA+ principles. Consequently, digitalized solutions are often equated to enhanced or improved processes.
However, many manufacturing companies will adopt a “technology-first” approach. They will aim to solve a problem by introducing digitized solutions without understanding, defining, and optimizing the processes to establish the fundamental requirements needed for their digitalization. Without knowing the essential process requirements, the limitations, gaps, challenges, and potentials of a system, it cannot be analyzed before implementation. Consequently, it is easy to become dependent on a vendor and form an overreliance on an ineffective digitized solution that is difficult to escape from.
Both CDMOs that implement the digitized solutions and the solution providers themselves also may not know the necessary regulatory requirements on DI controls. Therefore, industry standards on regulatory requirements may not be adequately benchmarked and implemented into designs of digitalized solutions. This means that digitalized solutions can often generate more complexities than they solve.
A compliant approach is built on a foundation of understanding
The best approach to ensuring DI and data security is to build it from the top down.
It should be the responsibility of those in management roles to establish a robust governance program with appropriate organizational, procedural, and technical controls. In doing so, they will need to step back and assess how data is created, collected, reviewed, processed, archived, and finally destroyed at the end of the retention period. Throughout this process, they need to be asking several key questions:
1) What does it mean to be compliant with the regulatory DI requirements?
Establishing and maintaining an adequate understanding of current industry standards on meeting key elements of ERES regulatory requirements is necessary for compliance. This can be achieved by proactively benchmarking and implementing activities in digitized solutions while keeping system and data lifecycle in mind.
2) What is the critical data that needs to be protected and maintained?
Not all data is of equal importance. Those that have direct impact to patient safety and product quality are critical and must be prioritized in their DI controls.
3) How can the validated computerized system enhance product quality or reduce risk to product quality?
Establishing an efficient risk-based computerized system validation (CSV) and changing management processes to improve product quality requires:
• Adequately defining and maintaining the intended use of the computerized system
• Mitigating risk scenarios that may impact patient safety and product quality by both improving the technical design and reducing potential human errors
• Validating activity based on the user requirements, with full traceability throughout (from process to testing and release)
• Streamlining testing to verify the system design and risk mitigation measures
By answering questions like these, relevant procedures required for DI controls can be defined and introduced, while being built on a solid understanding of why they are needed.
However, it is not enough just to have these robust procedures in place. The company also needs to have a culture where identification, discussion, and remediation of the DI issues and potential risks are supported and encouraged by the senior management.
A key lesson surrounding DI
Decision-making throughout drug development and manufacturing is reliant on robust DI. Without this, decisions could be made that impact patient safety and product quality. CDMOs that do not fully understand the gaps in DI controls in their digitized solutions are more likely to place their trust in unreliable data. Ultimately, this could lead to mistakes being made and repercussions being faced following audits as regulations may not be adhered to. It is therefore essential to identify a CDMO partner that is aware of the DI regulatory requirements and has built proactive, robust processes with a data-centric mindset, in the implementation of the digitalized solutions.