#49 – CORRECTING AND DETECTING CAPA HORRORS – PETER KNAUER

aaaNote:  The views expressed in this article are those of the author and do not necessarily represent those of his employer, GxP Lifeline, its editor or MasterControl Inc.

The long history of Corrective and Preventive Action (CAPA) requirements within the Food and Drug Administration’s (FDA) Quality System Regulations—and specifically 21 CRF 820.100 and ICH Q10—implies that most biomedical companies have evolved a certain level of mature thinking and a good understanding of the fundamental requirements for CAPA systems.  This, unfortunately, is not always the case.  I am currently spending a lot of time working with client companies in remediation mode; that is, after FDA has found enough flaws to issue a 483 or warning letter.  I would like to point out some common CAPA problems that can be proactively rectified to avoid citations in the first place. Continue reading

#49 – AUDITING RISK AUDITORS – UMBERTO TUNESI

Umberto Tunesi pixI’m quite a novice in risk audits, though I have twenty years experience in quality audits and fifteen in quality inspections.

I think that audits’ basics – or sound-track – are the same, be they quality, risk, financial audits: auditors are usually – and officially … welcome.  Auditors are treated like princes, as a colleague of mine once said, they’re told their work is most useful but – in the end – auditors and audits are a nuisance, even to the top management who might ask for them to investigate deep into the company’s business.  Fighting words?  Let’s look at risk auditing: Continue reading

#49 -PROCESS APPROACH IN C MAJOR – T. DAN NELSON

T. Dan NelsonIn the movie ‘Sincerely Yours,’ Liberace is playing a live show when he solicits the audience for a request.  Arguably the greatest pianist on Earth, supremely capable of dazzling the crowd with a jaw-dropping rendition of even the most intricate, demanding piano arrangement, he asks the audience for a request with the confidence of a magician saying, “Pick a card, any card.” Continue reading

#49 – IT APPLICATION DEVELOPMENT GUIDELINES – ED PERKINS

OLYMPUS DIGITAL CAMERAThe folks over at the NIST Information Technology Labs (ITL) have been busy. One complaint about the recently released Risk Management Framework (RMF) [1], developed in response the President’s Executive Order 13636 on Improving Critical Infrastructure Cybersecurity, was that it did not address application security (the coding practices that allow for SQL injection, buffer overflow, etc). [2]. Continue reading

#48 – PROACTIVE VS. REACTIVE RISK MANAGEMENT WITH ISO 31000 – GREG CARROLL

GregCarrollISO 31000 needs to address the understanding of the fundamental nature of risk if it hopes to advance the maturity of risk practices in business.

Risk Management is firmly entrenched in a world of re-active modelling and reporting that belies the goals of ISO 31000 and until there is an epiphany in the industry on understanding the nature of risk, it is unlikely that ISO 31000 will achieve anything more than a documentary role in corporate governance and business management.  Risk Management must add value, and this means add Shareholder Value, if it is to be accepted as a part the strategic management of business. Continue reading