50 likes | 198 Views
CSV-View from a Vendor. Glyn Williams VP Product Delivery. IDBS. Provider of Data Management solutions worldwide COTS generic software Extended under contract for interfaces ( eg LIMS, CDS etc) Held ISO 9001 and TickIT certification since January 2004
E N D
CSV-View from a Vendor Glyn Williams VP Product Delivery
IDBS • Provider of Data Management solutions worldwide • COTS generic software • Extended under contract for interfaces (eg LIMS, CDS etc) • Held ISO 9001 and TickIT certification since January 2004 • GxP Implementations in the US, EU and Japan • GLP, GMP, now touching on GCP and HIPAA • Actively engaged in supporting CSV through services • Audited by regulated customers on-site or “electronically” each 2 months over 3 years
Current Situation • High cost on both sides • ‘The more the vendor does the less we have to do’ • Variable quality of audits • Adversarial – not all but some • Team variations • Focus on Process (SDLC) and QMS • Some very “paper-based”/evidence – some very focused on competence, some balanced • Contradictory messages from auditors on the risk based approach • Quality of the auditor –the samples they choose • Recommendations can be very prescriptive
Future Vision • Why are we being audited? • Because we have to • Meet Regulatory Requirements • Issues with Quality • What does the vendor have in place? • ISO 9001? CMM, nothing • Quality Questionnaire? • Security • Separate audit? • ISO27001 or 2700 or both • Supply Chain • Liability • Data Protection
How do we get there • Open findings of audits • Independent audit • Standard guidelines: • Objective based • Focus on deliverables not the process • Handle multiple regulations • Methodology is the ISV problem • An audit is only as good as the auditor