Page 4 GAMP Good Practice Guide: A Risk-Based Approach to Compliant Electronic Records and Signatures Table of Contents 1 Introduction ..................................................................................................... 6 1.1 Overview .................................................................................................. 6 1.2 Purpose .................................................................................................... 6 1.3 Scope ...................................................................................................... 7 1.4 Benefits ................................................................................................... 8 1.5 Objectives ................................................................................................ 8 1.6 Structure of this Guide ................................................................................. 9 1.7 Key Concepts ............................................................................................. 9 1.8 Current Regulatory Situation ......................................................................... 11 2 Risk Management Process ................................................................................... 11 2.1 Overview of Process .................................................................................... 11 2.1.1 Current Risk Management Practices ........................................................ 11 2.1.2 Managing Risks to Electronic Records ...................................................... 12 2.1.3 Risk Management Based on the Impact of Records ....................................... 14 2.2 Step 1: Identify Regulated Electronic Records and Signatures .................................. 15 2.3 Step 2: Assess Impact of Electronic Records ....................................................... 16 2.4 Step 3: Assess Risks to Electronic Records Based on Impact ..................................... 20 2.4.1 Approach for Records Identified as Low Impact .......................................... 20 2.4.2 Approach for Records Identified as Medium Impact ..................................... 20 2.4.3 Approach for Records Identified as High Impact .......................................... 21 2.4.4 Hazards .......................................................................................... 21 2.5 Step 4: Implement Controls to Manage Identified Risks .......................................... 23 2.6 Step 5: Monitor Effectiveness of Controls .......................................................... 23 2.7 Points to Consider ...................................................................................... 24 3 Applying the Risk Management Process .................................................................. 25 3.1 Corporate Level Activities ............................................................................. 28 3.2 Applying the Process to New Systems ............................................................... 30 3.3 Applying the Process to Existing Systems ........................................................... 31 3.4 Systems Previously Assessed Against 21 CFR Part 11 .............................................. 32 4 Controls ......................................................................................................... 34 4.1 Record Controls ......................................................................................... 34 4.1.1 Implementation of Controls .................................................................. 34 4.1.2 Rigor of Controls ............................................................................... 39 4.2 Signature Controls ...................................................................................... 39 4.3 Managing Hybrid Records .............................................................................. 41 4.4 User/Supplier Responsibilities ........................................................................ 42 4.4.1 Procedural Requirements (responsibility of user) ........................................ 42 4.4.2 Technical Requirements (largely the responsibility of supplier) ....................... 43 ISPE GAMP GPG: ER&S – TOC ©2005 ISPE. All rights reserved. www.ISPE.org GAMP Good Practice Guide: A Risk-Based Approach to Compliant Electronic Records and Signatures Page 5 Table of Appendices Appendix 1 Validation Appendix 2 Audit Trail and Data Security Appendix 3 Record Retention, Archiving, and Migration Appendix 4 Copies of Records Appendix 5 21 CFR Part 11 Legacy Systems Appendix 6 Examples of Records and Signatures Required by GxP Regulations Appendix 7 Case Studies Appendix 8 Copy of GAMP 4, Appendix M3 Appendix 9 Example Template Form for Risk Assessment and Identification of Controls Appendix 10 Form for Previously Assessed 21 CFR Part 11 Systems Appendix 11 Current Regulatory Situation Appendix 12 Glossary Appendix 13 References ISPE GAMP GPG: ER&S – TOC ©2005 ISPE. All rights reserved. www.ISPE.org