spk-logo-white-text-short2
0%
1-888-310-4540 (main) / 1-888-707-6150 (support) info@spkaa.com
Select Page

PLM in the Cloud: Computer System Validation in FDA Regulated Industries

cloud for engineering image of buildings
Written by Mike Solinap
Published on July 29, 2013

Product lifecycle management (PLM) systems have evolved from being custom-built, on-premise applications to cloud-based, off-the-shelf solutions. As adoption for PLM in the cloud increases, system validation approaches in FDA/GXP regulated industries have had to adapt as well.

PLM Evolution

The FDA and Computer System Validation

Computer system validation is mandated by the Quality System regulation (FDA, 21 CFR Part 820) which requires that “when computers or automated data processing systems are used as part of production or the quality system, the manufacturer shall validate computer software for its intended use according to an established protocol.”

Furthermore, computer systems that implement part of a manufacturer’s production processes or quality system are subject to the Electronic Records and Signatures regulation (FDA, 21 CFR Part 11).

The  classical V-Model is typically applied for Software Verification and Validation for enterprise systems:

V-model

Applying the V-Model to Cloud Based Service Models

There are three basic service models in the cloud (source: David Chou, http://blogs.msdn.com/b/dachou/):

Cloud deployment models source - david chou

The V-Model may be applied to systems in the cloud as follows:

v model applied to the cloud

While the IQ, OQ responsibilities are shifted to the cloud service provider, as the regulated company you are still accountable for compliant quality systems. As the regulated company, you must verify that the service provider has appropriate controls in place.

Before you select a cloud service provider for your PLM solution:

  • Conduct  a supplier audit and perform a risk assessment
  • Document risks related to roles and responsibilities, processes controls and technology  used
  • Formally document the responsibilities of the cloud service provider

After going live with cloud based solution continue periodic performing periodic audits of the cloud service provider.

Next Steps:

Latest White Papers

How Creo Supports Sustainable Product Development

How Creo Supports Sustainable Product Development

Developing products can lead to environmental costs based on the materials used and how they are handled pre- and post-production. Let’s explore how Creo helps drive sustainable product development practices.What You Will Learn In this eBook, you will discover how to:...

Related Resources

An Executive’s Guide to Strengthening Software Supply Chain Security

An Executive’s Guide to Strengthening Software Supply Chain Security

Modern software is assembled from a complex web of components, contributors, and tools, both internal and external. While this modularity accelerates development, it also expands the attack surface. For executives, a single breach in the software supply chain can...

M&A Software Due Diligence Checklist

M&A Software Due Diligence Checklist

M&A transactions can pose risks, especially if you aren’t sure what to look for. Dive into this eBook to explore common security protocols as well as how Black Duck can help.What You Will Learn Explore the key areas of focus for software due diligence, including:...