Author: Brandon Miller

To learn more about quality control and data integrity, you need to understand what these terms mean and how they can affect your company.

 

What Is Quality Control and Data Integrity?

 

The Good Practices for Data Management and Integrity in Regulated GMP/GDP Environments document from PICS offers perhaps the most comprehensive explanation of what a quality culture is. According to that document, this type of culture is a work environment that is open and transparent, allowing team members to fully and openly communicate mistakes and failures. This open culture is also a work environment where there are processes and structures that allow information about mistakes and problems to flow between team members at different levels.

 

Why Quality Culture?

 

Quality culture and its importance to the World Health Organization, MHRA and PICS recognizes that data quality is reliant on type of workplace. An organization that punishes team members who come forward with mistakes or issues is likely to have fewer reportable issues and less transparency, which can mean less accurate data. By allowing team members to speak freely and permitting the information to flow to different tiers of the organization, you’ll ensure that data can be accurately collected and acted upon.

 

Improving Organizational Quality Culture and Data Integrity through Risk Management

 

If you would like to create a quality culture, your organization can take several steps, including:

  • Creating a quality risk management plan: A written quality risk management plan should include your potential risks and a detailed plan on how to address problems and mistakes. This plan should make it clear that every team member is part of the solution and can report problems without risk of retaliation.
  • Evaluating your risks: Run an organization-wide audit to evaluate which risks could negatively impact product quality. As you start to write your quality risk management plan, begin by evaluating the risks that could impact your product. Could a supplier issue compromise the product? What other problems have arisen in the past or affected others in your industry?
  • Having a remediation plan: Create a written plan on what to do if something happens. How will an issue be reported? Once an issue is reported, what will the next steps be? How can you begin the remediation process?
  • Maintaining your plans as living documents: The goal of a quality risk management plan isn’t to create a document that sits on a computer. Present the document to your team and use it every day. Add to the document as new challenges come to light, and encourage your team to abide by the plan.

 

How We Can Help

 

A quality culture will help you pave the way for success because you’ll be enjoying better data. When you need to submit to global regulatory agencies, having more robust data can also help.

 

While having data integrity and good metrics is a crucial factor for biologics, medical device, pharmaceutical, compounding pharmacy and other organizations, an open quality culture is also important. In addition, it will help you to notice issues and address them in a timely fashion as well as enable you to plan what to do when problems arise.

 

To begin the Regulatory Compliance Associates scoping process today, please enter your information in the blue form below and click the submit button at the bottom of the webpage. You may also email us at [email protected].

Amanda Pedersen, senior editor for MD+DI magazine, interviewed Susan Schniepp, Troy Fugate, and Steven Niedeleman to discuss “some of the craziest things FDA investigators hear during a US FDA inspection”. Below is an excerpt of her widely circulated column. 

 

One pearl of wisdom I often hear from regulatory and quality experts on the subject of managing FDA inspections is to answer the investigator’s questions and then zip it – do not offer more information than what is asked. For this reason alone, I would be a terrible “front room” person during an FDA inspection.

 

While I typically work best under pressure, uncomfortable silence is my kryptonite. I can easily see myself getting nervous and word-vomiting all over the investigator. There’s been a rash of medical device recalls and regulatory snafus in recent weeks, so it seems like a good time for some tried and true tips for interacting with FDA. 

 

1. “You don’t know what you’re talking about.”

 

It should go without saying, but never argue with the FDA investigator or insult their intelligence. It’s not going to lead anywhere good. If you do happen to find yourself in a disagreement during the inspection, do your best to de-escalate the situation. Whatever you do, don’t choose violence.

 

Troy Fugate, co-founder and vice president at Compliance Insight, recently shared a wild story from the field about an FDA inspection at a foreign site that went horribly wrong. The plant manager didn’t like that the investigator was finding problems and a heated argument ensued. The plant manager became so angry that he punched the investigator in the face.

 

2. “During the last inspection, the FDA investigator saw the same thing and did not put it on the Form 483.”

 

That would be like telling a police officer that you’ve been pulled over before for the same violation, but you got off with a warning. Don’t expect the investigator to second-guess their FDA 483 observation just because you got away with the same issue in the past.

 

3. “The last investigator was crazy.” Or “The last investigator did not know what they were doing.”

 

Best case scenario, the FDA investigator agrees with you, but wonders if you’ll badmouth them during your next US FDA inspection. Worst case, you just insulted their favorite colleague.

 

4. “I told them not to do it this way…”

 

Don’t be that person. Present a united front as a company and simply acknowledge the issue and express a willingness to address it. Don’t throw your colleagues under the bus in front of FDA because you’re only going to make yourself look bad.

 

5. “The management of this firm is only concerned with profits and does not take quality seriously.”

 

Even if this is true, nothing good will come from sharing the company’s dirty laundry with FDA. If you have legitimate concerns about your firm’s quality assurance, there is surely a more appropriate time and place to bring it up than during an FDA inspection. If your concerns get brushed off, maybe consider going the whistleblower route.

 

6. “We don’t have enough people or time to review all those complaints…”

 

Manufacturers must prioritize their resources. Being a small or understaffed company is no excuse to turn a blind eye to quality complaints, especially in medtech where people’s lives may be at stake. Don’t waste time during an FDA inspection trying to justify poor handling of complaints.

 

7. “That is the way we have always done it.”

 

If I was an FDA investigator, this sad excuse for any FDA observation, however big or small, would make me wonder what other procedures the manufacturer has “always” done the wrong way.

 

8. “That’s not my fault. It was the previous person who did that…”

 

Don’t point fingers. It’s childish and annoying. The investigator doesn’t care whose fault something is, they just want it fixed.

 

9. Don’t lie to FDA … but that doesn’t mean you should have to put such a statement in writing anywhere that an FDA investigator might see it.

 

This one comes from an embarrassing story Susan Schniepp of Regulatory Compliance Associates shared with Medtech Insight a few years back. She had just started working as VP of a small company when FDA came knocking. The company’s director of quality handled the audit while Schniepp observed. The director proudly handed the investigator the company’s standard operating procedure (SOP) document on how the firm handled inspections. That seemed like a great first step until she saw the line on the SOP that read: Don’t lie to the FDA.

 

As Schniepp said, surely the FDA investigator wondered exactly what the firm is doing the rest of the time that it needs to remind its employees not to lie to FDA. So, she said, FDA inspections are all about perception and putting the company’s best foot forward, so to speak. Don’t write SOPs like you’re reading them, she advised, but like someone else is going to read them. But it wouldn’t be fair to point out all the ways manufacturers have screwed up during FDA audits without acknowledging that FDA inspectors are human too and have been known to act inappropriately and even downright creepy at inspection sites.

 

Click now to read the full article here.

 

To begin the Regulatory Compliance Associates scoping process today, please enter your information in the blue form below and click the submit button at the bottom of the webpage. You may also email us at [email protected].

The Food and Drug Administration (FDA) has released an updated draft for the life science industry regarding communicating directly with health care professionals. This FDA guidance draft will go to industry for comment and feedback with the long term goal of streamlining the FDA regulatory process.

 

A specific use case mentioned in the FDA guidance is how HCPs use scientific information about unapproved uses (SIUU) for approved/cleared medical products. From the pharmaceutical or medical device perspective, are life science companies providing this scientific information in the context of clinical decision making? For example, are there off label uses of the FDA approved treatment for patients that may be going under investigated for both efficacy or compliance?

 

Scientific Information on Unapproved Uses (SIUU)

 

Particularly, this FDA guidance targets life science firms and how companies are sharing specific approval drug communications for medical products. Further, the following types of communications with HCPs were specifically mentioned by the Food and Drug Administration:

 

  • Published scientific or medical journal articles (reprints)
  • Published clinical reference resources:
    • Clinical practice guidelines (CPGs)
    • Scientific or medical reference texts (reference texts)
    • Materials from independent clinical practice resources
  • Firm-generated presentations of scientific information from an accompanying published reprint

 

Clinical Drug Trials

 

The FDA guidance speaks consistently to the delivery and context of medical trials data. Further, scientific information from clinical trials for approved products should be truthful, non-misleading, factual, and unbiased. The clinical research center should be in good standing from an FDA compliance perspective as well. 

 

Finally, there is a legal responsibility for industry employees to communicate information that is generally regarded as safe. Those who communicate unapproved indications or create medical labeling should not be associated with different types of unresearched clinical outcomes.

 

Medical Manufacturers

 

The FDA guidance makes it a point to note the types of life science firms and industry employees who can be held legally responsible. Medical labeling and the labeling of medical products can include:

 

  • Applicants
  • Sponsors
  • Requestors
  • Manufacturers
  • Packers
  • Distributors
  • Licensees
  • Any person communicating on behalf of these entities.

 

Clinical Evaluation

 

There has been some clinical research concerns across the healthcare industry about data integrity and organizations or publications that have issued clinical studies. The FDA guidance describes what it considers a source publication for legitimacy as:

 

  • The clinical problem is scientifically sound
  • The clinical study provides relevant information
  • Clinical data is relevant to HCPs who make clinical decisions
  • Clinical treatment must be relevant to the the care of a patient

 

The FDA guidance is written so industry employees focus towards:

 

  • Interpreting strengths and weaknesses of clinical research
  • Interpreting validity and utility of the therapeutic information

 

Healthcare Providers (HCPs)

 

The FDA guidance goes on to elaborate about professionals who are engaged with clinical decision making during patient treatment. Additionally, special focus is given to individuals licensed or authorized by law to prescribe, order, administer, or use medical products during their daily job.

 

Regulatory Compliance

 

The FDA goes on to comment that medical product regulation has progressed over time and is shaped via real world clinical evidence. Additionally, there can be significant hazards to society when uses of medical products do not follow the clinical process for regulatory approval.

 

FDA’s premarket review process decides if a medical product is safe and effective for the specified use(s) in an recognized patient profile. Yet, after the premarket review process is complete and a product is approved/cleared, questions may arise.

 

Intended Use

 

These questions can be investigated during clinical use of the medical product for the intended patient. Specifically, FDA premarket review for medical products includes:

 

  • Safety and effectiveness for each intended use needs to be appropriately studied by firms
  • Independently evaluated by FDA before a medical product is introduced into interstate commerce
  • Evidence that demonstrates effectiveness and safety for one product does not guarantee the clinical effectiveness or safety for additional uses

 

To begin the Regulatory Compliance Associates scoping process today, please enter your information in the blue form below and click the submit button at the bottom of the webpage. You may also email us at [email protected].

 

 

The application date of May 26, 2022, is coming up for the EU In-Vitro Diagnostic Medical Devices Regulation (2017/746) (IVDR) has created a huge challenge for IVD medical device firms planning to introduce or continue to market their IVD products to any of the European Union Member States. 

 

One of the biggest changes from IVDD to IVDR is the move from list-based IVD device classifications to a rule-based IVD medical device classification resulting in 4 new device classes: class A (lowest risk) to class D (highest risk), where class B, C, and D would require Notified Body involvement.

 


Need help with your transition to the EU IVDR? Contact Us Now →


 

The EU Commission has recommended that the application date be extended due to the bottleneck within the EU notified bodies caused by the pandemic.

 

  • General EU MDR Class 1 Low-risk devices that are non-measuring, non-sterile, non-reusable, non-surgical, and that do not require review from a notified body will still go into effect in 2022.
  • Non-sterile Class A and B Devices (low risk) – May 26, 2022
  • Class D (Highest Risk) – May 26, 2025
  • Class C (Medium Risk) – May 26, 2026
  • Sterile Class A and B Devices (low risk) – May 26, 2027

 

Companies need to learn from their experience with EU MDR and start transitioning sooner than later to avoid not being able to sell their products in the EU.

 

Partner With RCA to Transition from IVDD to IVDR

 

At Regulatory Compliance Associates® Inc. (RCA), we have subject matter experts who start with a gap analysis of the quality system and the technical documentation per IVDR requirements to identify the compliance gaps and develop an execution plan to help you become IVDR compliant. 

 

We can help with your device classification according to the classification rules, update of your quality system to address and remediate any gaps. Including but not limited to:

 

  • Post-Market Surveillance (PMS)
  • Performance Evaluation
  • Post-Market Performance Follow-Up (PMPF). 

 

We can also help you with your technical documentation for the PMS Plan, PMS Report, PMPF Plan, PMPF Report, or help you remediate any other technical documentation gap(s).

 

To begin the Regulatory Compliance Associates scoping process today, please enter your information in the blue form below and click the submit button at the bottom of the webpage. You may also email us at [email protected].

Click now to watch Regulatory Compliance Associates® Dr. Stephen Coulter explain how design controls and risk management play an intricate role in the Waterfall methodology:

 

 

The Waterfall methodology incorporates the usage of FDA design controls into the medical device design process. It serves as the primary connection between quality system requirements (QSR) and current good manufacturing practices (CGMP).

 

Waterfall Method

 

Conceptually, the FDA Waterfall model is designed to provide engineers with the flexibility to mitigate product risk, meet regulatory compliance and satisfy customer needs. It is a sequential process based on the quality assurance and medical device engineering principles listed in 21 CFR 820. The methodology itself is conceptualized in the image below from the Medical Device Bureau of Health Canada. 

 

Waterfall Development

 

To increase risk mitigation during the Waterfall methodology, both risk management & design controls are considered. They often become integrated processes during Waterfall product development. Many unique tools that medical device engineers use to define requirements & meet user needs are shared across these processes, even though each is based on a separate standard.

 

While design controls for FDA approval are referred to in 21 CFR 820, medical device risk management is internationally associated with ISO 14971. Three critical elements of risk mitigation strategies clearly focus on avoiding risk during product development:

 

  • Evaluating an associated risk
  • Controlling an evaluated risk
  • Monitoring risk control effectiveness overall

 

Input Requirements

 

The success of the Waterfall development method depends on early research & assessments conducted about input requirements that include strategic risk. Further, spending time documenting the inputs of user interface, user stories and product epics can help increase positive outcomes and reduce requirement risk overall.  Finally, any inconsistencies during the waterfall methodology between the proposed design & input requirements can be corrected across stages. This aligns with one of the primary motivations behind FDA originally developing 21 CFR 820 (e.g. helping medical device manufacturers find design deficiencies earlier in the process).

 

Risk Management

 

By starting the Waterfall process with this end state in mind, design inputs are more likely to pass failure testing & become a manufacturing output. This risk management strategy during a Waterfall project can begin with identifying the publicly known risks of competitive products. Second, the team is challenged to investigate if similar hazards could be associated with your medical device. When working with a Regulatory Compliance Associates risk management consultant, our clients are reassured that Waterfall development should detail how hazards can impact user needs & potential customers.

 

For example, design inputs should consider current regulations and global standards early in the waterfall process. This helps incorporate a risk management perspective even before verification and validation testing begins. Intended uses should consider predicate devices and if any causes for recalls are related to design, materials, or software. 

 

Waterfall Approach

 

So, does this mean risk management & design controls are connected in the waterfall approach? And if they are, how important is one over the other when leading to marketing approval or regulatory compliance? This process is often measured against a combination of factors, including:

 

  • Regulations & standards for clinical approval
  • Risk class of medical device being manufactured
  • Regulatory body reviewing the marketing submission

 

Enterprise risk management would consider all three of these factors individually and in combination when considering how to eliminate systemic risk. The Waterfall project management team can also use various tools and techniques while developing the risk management plan. These risk identification tools include conducting a risk analysis, performing an FMEA, and charting risk tolerance. 

 

Risk Analysis

 

Existing regulations & standards offer various types of risk tools that can be incorporated into design controls. This can include identifying risk levels and creating severity charts during the user needs & design inputs stages. Additionally, each new product will have different hazards and risk tolerance levels associated with the target patient. Being able to analyze the problem, control the problem, and mitigate the risk is essential to define in your risk analysis. Challenge yourself to reduce and identify hazards by analyzing the known data as much as possible.

 

FMEA

 

Failure Mode and Effects Analysis (FMEA) is a controlled technique to detect & concentrate on budding trouble. Each failure is commonly assigned a rating based on the negative effect it may cause. The Waterfall process would then take each rating and project how the marketplace, healthcare systems, or patients can be impacted. FMEAs are one of many risk mitigation tools that can help your team identify the hazards of your severity chart. Each charted hazard is established based on the severe nature of the hazard to the user and project requirements for design control.

 

Risk Tolerance

 

Further, after the severity is defined, all known or projected hazards can be developed into a risk tolerance chart. The risk tolerance chart can then be shared cross-functionally across the team to help everyone understand which design steps can increase user risk. One of the benefits of a risk tolerance chart is being able to show data visualization. The design team should consider how design controls and user needs can reduce the hazard’s impact. Finally, a waterfall chart could also project the negative consequences of adverse events and what the estimated cumulative impact might be during a product crisis scenario.

 

Risk Management Summary

 

Finally, once your team has evaluated the risks and decided on precautions, a risk management summary is developed. It may include involves multiple failure mode analysis types (e.g. product, process, etc.) and risk ratings. These initial ratings are typically based on the types of failures and the severity of the failure itself. Ranges can also be given to determine the risk management strategy and what is the acceptable level of product risk (e.g. high, medium, low).

 

To begin the Regulatory Compliance Associates scoping process today, please enter your information in the blue form below and click the submit button at the bottom of the webpage. You may also email us at [email protected].

MoCRA

The US Food and Drug Administration (FDA) recently published finalized guidance for regulatory approval in the Cosmetics industry. This latest agency publication introduces new methodologies for good manufacturing practices that can increase both patient safety and product quality.

 

What is MoCRA?

 

The term MoCRA was first introduced as an acronym for FDA’s Modernization of Cosmetics Regulation Act (2022). The updated FDA guidance is based originally from the existing, previous legislation (e.g. the Consolidated Appropriates Act) which served as the regulatory framework for FDA approval. MoCRA now includes additional provisions for facility registration, adverse events and product labeling that are designed to improve patient safety.

 

How does MoCRA impact cosmetic manufacturers?

 

An FDA inspector can access certain types of records and information during a facility inspection. Additionally, one specific inspection request from FDA auditors appears to be more common than others. Cosmetic industry employees have reported that FDA pre approval inspection teams are proactively asking for documentation about known cosmetic ingredients the FDA believes could be a consumer safety threat.

 

How does MoCRA impact cosmetic vigilance?

 

The updated regulatory process now requires cosmetic manufacturers to report consumer adverse events to the FDA within 15 days (via Form 3500A). An adverse report would then trigger an FDA inspection where both manufacturing and supplier documentation is inspected very carefully.

Specific documentation used in adverse reporting must be stored in a quality management system. Ideally, the manufacturer and agency should collaborate to clearly define the consumer problem (e.g. dermatitis, pigmentation, etc.) and be able to connect the batch record information from the product manufacturing team.

 

How does MoCRA impact FDA inspections?

 

Data documentation from the manufacturing process an FDA inspector may want to review should be shared quickly upon request. Specifically, common areas of FDA interest often include data on retail packaging, a copy of the product’s label, and regulatory compliance documentation. Finally, a cosmetic manufacturer must submit a corrective action and preventive action (CAPA) plan based on FDA inspection findings for how they will prevent adverse effects in the future and return to FDA compliance.

 

To begin the Regulatory Compliance Associates scoping process today, please enter your information in the blue form below and click the submit button at the bottom of the webpage. You may also email us at [email protected].