Regulatory Open Forum

 View Only
  • 1.  SharePoint validation for Part 11 compliance

    Posted 07-Nov-2023 15:54

    Hello,

    We are a biotech company using SharePoint as our document management system. The system has security, audit trail and other features for compliance. However, we have not validated the system.

    1. Does anyone recommend that we validate the system to ensure part 11 compliance? 
    2. If yes, does anyone have experience validating SharePoint and if you could advice on things we should consider from a regulatory standpoint?

    Thank you.



    ------------------------------
    Divya Hariharan MS
    Reading MA
    United States
    ------------------------------


  • 2.  RE: SharePoint validation for Part 11 compliance

    Posted 08-Nov-2023 09:44

    Hi Divya,

    My opinion here is that yes you should validate the system for its intended use, including Part 11 compliance in that validation. This is not always a simple undertaking, so it requires a robust plan, a budget, subject matter experts, and management support to do it efficiently and effectively. If you use a Computer Software Assurance (CSA) approach in accordance with the FDA's guidance on the topic (Computer Software Assurance for Production and Quality System Software | FDA), this may simplify things for you. It is a risk-based approach that requires sound rationale for the way the validation is carried out (i.e., why are you only testing certain things and not others), so spend a good amount of time up front on the risk assessment otherwise you kind of lose the flexibility of this approach. Given that Sharepoint has broad applicability, you will want to scope the validation such that you cover the specific use cases for your organization as a document management system. This will require some procedures or work instructions about administration, security, access, use, change management, document workflows, etc. Other documents needed are typically the validation plan, user requirements, protocol(s) with test cases, traceability matrix, and summary report, to name some of the usual suspects. But each validation effort may have a different flavor depending on the approach taken (traditional vs. CSA noted earlier), company policies and risk tolerance, regulatory requirements in markets you serve, compliance history, etc.  

    Hope this is helpful - feel free to message me if you have specific questions. 

    Kind regards,

    Nathan



    ------------------------------
    Nathan Blazei
    Head of Quality & Regulatory Affairs
    Morrisville NC
    United States
    ------------------------------



  • 3.  RE: SharePoint validation for Part 11 compliance

    Posted 08-Nov-2023 11:41

    Agreed with Nathan.  My firm has also helped clients validate SharePoint to assure not only Part 11 compliance but also regarding the general intended use [e.g., in regards to medical devices 21 CFR 820.70(i)].



    ------------------------------
    Kevin Randall, ASQ CQA, RAC (U.S., Europe, Canada)
    Principal Consultant
    Ridgway, CO
    United States
    © Copyright 2023 by ComplianceAcuity, Inc. All rights reserved.
    ------------------------------



  • 4.  RE: SharePoint validation for Part 11 compliance

    Posted 08-Nov-2023 13:56

    Hi Divya,

    1. Yes, if the system is used to support compliance to part 11, and if it is being used to support regulatory requirements for example if your company is certified/audited to ISO 13485, ISO 9001. 
    2. Define test cases in a validation plan that walk through the process steps and identify potential risks. Through testing, document in a validation report that the risks are mitigated, and the tool is functioning as intended. 


    ------------------------------
    Julie Warren RAC
    Regulatory Affairs Professional
    Newark DE
    United States
    ------------------------------



  • 5.  RE: SharePoint validation for Part 11 compliance

    Posted 09-Nov-2023 07:56

    Be careful to not just read the regulation, but the current guidance which narrows the scope of 21 CFR 11.

    https://www.fda.gov/regulatory-information/search-fda-guidance-documents/part-11-electronic-records-electronic-signatures-scope-and-application 



    ------------------------------
    David Manalan
    Principal, INQC Consulting
    Acton MA
    United States
    ------------------------------