54- Compliance, Enforcement, and Audit Mechanisms (S21E5)

From Concept to Medicine - A Comprehensive Drug Development Journey

Details and explains the enforcement mechanisms that regulatory agencies employ to make sure cGCP compliance. Also explained is the role that audit procedures, risk-based inspections, and corrective actions have.

This includes the ways that all of the previous measures drive continuous improvement and to safe guard participant safety in clinical research. Discussions on good documentation practices will take place, the types of audits are performed, and the role they take in maintaining GCP compliance. Validation practices tie into many aspects of CGMP, and will be discussed in full detail.

2025-06-02 17 min Transcript

Available Results

Generated results are saved to the knowledge database for reuse and search.

No generated results are available for this episode yet.

Extract Knowledge

Pick what you want extracted first. Model, scope, and chapter options appear after a template is selected.

Generated results for public episodes are saved to the knowledge database so they can be reused and searched later.

Transcript

Alright, so today we're getting into something
pretty fundamental. You know, when we think about
all these clinical trials happening for new drugs
and medical devices, how can we be sure they're
actually being done right? I mean... safely and
producing results we can actually trust. That's
what we're diving into today. The whole world
of compliance and enforcement and these really
crucial audit mechanisms. All the stuff that
underpins the FDA's good clinical practice regulations
or GCT as everyone calls it. Yeah, it's kind
of like looking under the hood, right? Like understanding
the nuts and bolts of how we get these new treatments
and make sure they're actually safe and effective
before they're available to patients. This is
something that really matters for everyone. even
if you're not directly involved in clinical research.
Absolutely. Whether you're a researcher, a health
care provider, or just someone who relies on
medications, understanding this whole oversight
process gives you a better sense of how we can
be confident in those medical treatments. So
our mission today is to dig deep into how these
trials are actually overseen and what happens
when things go wrong, when those standards aren't
met. We're going to pull from regulatory documents
and expert insights to try to give you the clearest
picture possible. OK, so when we're talking about
oversight, one of the first things that comes
to mind is the FDA's Bioresearch Monitoring Program,
BIMO. BIMO, right. This program is really the
cornerstone of the FDA's effort to monitor all
these clinical trials that are going on. We're
talking about inspections of actual trial sites
and in -depth audits of all the data that's collected.
And the scale of this program is huge. Think
over 1 ,500 inspections every single year, both
here in the US and internationally. Wow. 1 ,500
inspections a year. That's a lot. So who exactly
is responsible for managing this whole program?
Right. So within the FDA, the Office of Scientific
Investigations, or OSI, that's who coordinates
DIMO. They've got a very specific structure in
place to make sure that GCP compliance is happening
across the board. So we've been using the term
inspections. Can you break down what an inspection
actually looks like? What are they? focusing
on when they go into a trial site? Sure. So you've
got your GCP inspections. These are a big focus,
especially those tied to NDAs and BLAs. Those
are the applications you need to get a new drug
approved. But the BiMO program is pretty wide
-ranging. It also includes inspections for good
laboratory practice or GLP. That covers the non
-clinical lab studies that need to be done before
you even start testing on humans. And then there
are inspections for bioavailability, bioequivalent
studies, institutional review. or IRB inspections,
which look at the ethics boards that oversee
trials, and even inspections related to paid
clinical investigators and RMS, which are safety
plans for specific medications. So it sounds
like a really comprehensive system covering all
the crucial steps in drug development, but...
Going back to OSI, you mentioned the structure
dedicated to GCP compliance. Can you unpack that
a bit more? Yeah. So within OSI, you've got the
Division of Enforcement and Post -Marketing Safety.
This division handles issues that arise after
a product is already on the market. Then there's
the Division of Clinical Compliance Evaluation,
which is all about the actual clinical trials.
And under that you've got branches like the GCP
Compliance Oversight Branch, which deals with
complaints and IRB surveillance, and the GCP
Assessment Branch. They're really focused on
the inspections that happen as part of the NDA
and BLA review process. So that GCP assessment
branch is really on the front lines when it comes
to making sure the data supporting those drug
approvals is solid. Now let's talk about GCP
itself for a minute. We keep using the term,
but what exactly does good clinical practice
involve? GCP is essentially a set of international
standards that ensure the quality and reliability
of clinical trial data, while also protecting
the rights and well -being of the people who
volunteer for those trials. It dictates how trials
should be planned, conducted, recorded, overseen,
analyzed, and reported, all of it. These are
the gold standard principles in the draft ICH
E6R3 guideline. OK, that makes sense. So. If
the FDA decides to inspect a trial site to see
if those GCP standards are being met, what triggers
that inspection? It can't be every single trial,
right? Right. There are specific triggers. A
major one is when a company submits an NDA or
BLA for a new drug. They want to independently
verify the data in that application to make sure
it's solid. Other triggers might include complaints
about a trial site or even information that comes
up during routine IRB surveillance. So it's a
mix of routine checks and reacting to potential
issues. Now, I've heard the term risk -based
inspections. What does that mean in the context
of GCP? How does the FDA decide what to focus
on? That's a great question. So with risk -based
inspections, the FDA doesn't examine everything
with the same level of detail. Instead, they
prioritize what are called critical to quality
factors. These are things that are absolutely
essential for protecting the participants in
the trial and ensuring the data is reliable.
It's all about focusing on the areas where problems
would have the biggest impact. This approach
is also a key part of ICH Q9, the guideline on
quality risk management. So what kind of things
would fall under that critical to quality umbrella?
What are some examples? Sure. We're talking about
things like the key data points in the study,
the primary end points, for example. We're also
talking about the core elements of the study's
design that make it scientifically valid. And
of course, we're talking about really important
study processes and procedures. How informed
consent is obtained, how the investigational
product is handled and administered, those kinds
of things. For example, in a trial for a new
diabetes drug, getting accurate blood glucose
measurements would be a critical data point.
If those measurements are off, it could throw
off the whole study. Sponsors and investigators
need to do their own risk assessments to figure
out what those critical factors are. So it's
not about looking at every single detail, but
rather zeroing in on the areas that really matter
the most. Okay, so let's say an inspection is
actually triggered. What happens when the FDA
shows up at a clinical trial site? What's that
process look like? Well, typically the FDA will
notify the sponsor of the study that a clinical
investigator or CI inspection is going to happen
at a specific site. Interestingly, the FDA doesn't
have a set rule about whether the sponsor can
be there during the inspection. Usually that's
up to the sponsor and the investigator to work
out. Interesting. So the FDA arrives at the site.
What are the next steps? They'll usually have
an opening meeting with the investigator and
the site staff. They'll lay out the scope of
the inspection, what they'll be looking at, and
then the inspection itself might take several
days. Often they'll have daily closing discussions,
kind of updating the investigator on what they've
found so far, any immediate questions they have.
And finally, there's a closeout meeting. Okay.
And at that closeout meeting, do the investigators
share their initial findings or concerns? Yeah.
If they see any potential violations, they might
issue what's called a Form FDA 483 or inspectional
observations. This is a written list of the specific
things they found that don't seem to be in line
with the regulations. But it's important to remember
that this form is just a factual record. It doesn't
tell the investigator how to fix things. It just
flags the issues. So the investigator gets this
list of observations. Then what? Are they just
expected to fix the problems? Exactly. The investigator
or the trial site has 15 business days to send
a written response to the FDA. And this response
is super important. It's a chance to address
each observation on the 4E3, say whether they
agree or disagree, and most importantly, explain
how they're going to fix things. So it's more
than just saying, we'll take care of it. What
should be included in a strong response? For
each observation, they need to lay out a corrective
and preventive action plan, a capillet plan.
This outlines how they'll correct the specific
issue and, crucially, how they'll prevent it
from happening again. We've talked about KPA
before. Can you remind our listeners what a good
KPA plan looks like? Sure. A good KPA plan will
be very detailed. It'll say what's already been
done to correct the issue, when it was done,
and what's still planned. It will include timelines
for completing those actions and how they'll
check to make sure the problem's really fixed.
It's about both fixing the immediate problem
and making sure it doesn't come back. Okay, so
it's like putting out a fire and then installing
a smoke detector. What else makes a good 483
response? Supporting documentation can really
help. Things like updated training records for
staff, revised standard operating procedures,
SOPs, maybe even evidence that contradicts the
FDA's observation if the investigator disagrees
with it. And if there are similar observations,
they can be grouped together with one overall
KP plan. It also helps to have a statement from
leadership showing they're taking it seriously.
A really well -organized, easy to understand,
and comprehensive response is key, especially
if it's submitted on time. Got it. A good response
is all about being thorough and timely. So what
happens to that response once it's sent to the
FDA? What do they do with it? The FDA investigator
will take the 483, if there was one, along with
the site's response and any other documents,
and will use all of that to write up a big report
called an Establishment Inspection Report, or
ER. This EIR then gets sent to the relevant FDA
center for their review. And what does that review
tell us? What's the outcome? The FDA wants to
give an official classification within 90 days
of the inspection. Usually there are three classifications,
no action indicated, and AI, meaning everything
looks good. voluntary action indicated, VAI,
which means there were some minor issues that
the site should voluntarily fix, and official
action indicated, OAI, which means more serious
problems were found and some kind of regulatory
action is probably needed. If it's NAI or VAI,
the company will usually get a letter from the
FDA and maybe a redacted copy of the EIR, but
these reports aren't usually made public. So
the company sees the report, but not the public.
What if the company doesn't get an EIR within
90 days? In that case, they should reach out
to the contact person on the 483 or to the investigator
to ask for a Stennis update. Okay. So let's say
the FDA finds serious issues leading to that
OAI classification. We've talked about the 483
and the EIR, but what are the real consequences
of noncompliance? What can happen? The 483 is
really just the first step. If the response isn't
good enough or if the violations are really bad,
the FDA might issue a warning letter. And even
if the response is late, they'll still look at
it, although it might not be mentioned in the
warning letter. This warning letter means the
FDA is serious and the company needs to address
those issues right away. What kind of impact
can a warning letter have? What happens if they
ignore it? A warning letter is a big deal. If
a company doesn't respond properly, they could
face even more serious actions from the FDA.
One consequence is that data from the trial could
be rejected. So, if they're trying to get a drug
approved and the FDA doesn't trust the data because
of GCP violations, that drug might not get approved.
We saw this in an OSI workshop case study where
problems with documentation and informed consent
raised serious concerns about the entire study's
data. Wow. So it can actually prevent a new drug
from coming to market. What are some of the other
broader impacts of noncompliance? What are the
bigger picture consequences? Well, noncompliance
can put public health at risk. We could see things
like substandard medical products hitting the
market, leading to people getting sick. It could
contribute to drug shortages if manufacturing
has to stop and due to compliance issues. And
of course, it can damage public trust in the
whole system. And those impacts go beyond just
the trial sites and the drug companies, right?
What about all the other players involved in
drug development and manufacturing? Right. Think
about contract development and manufacturing
organizations or CDMOs. For them, a bad track
record with compliance can be really damaging.
They could lose contracts, and their operations
could be disrupted. And then you have the labs
that do the non -clinical safety studies under
GLP regulations. If they have serious violations,
they could be disqualified. And that means the
data they produced might not be considered acceptable,
which could delay or even prevent a drug from
being approved. So non -compliance can really
have a ripple effect across the entire industry.
And ultimately, patients might not get the treatments
they need. It could even lead to drugs being
pulled off the market if there are safety concerns.
Exactly. And we have seen drugs being withdrawn.
as outlined in regulations like 21 CFR parts
216 and 330, because of problems that often stem
from issues during the development or manufacturing
process. This really highlights why sticking
to these GCP and CGMP regulations is so important.
Right. Following those regulations is crucial.
So we've talked about how the FDA enforces compliance.
But what about the companies themselves? What
are they doing proactively to make sure they're
meeting those standards? The CGMP, or current
good manufacturing practice regulations, are
a big part of it. They really stress the importance
of strong quality systems and controls that's
spelled out in several parts of the code of federal
regulations, like parts 111 and 211, and in guidelines
like ICH Q7. These systems are meant to build
quality into every single step, not just test
for it at the end. And audits are a key part
of any good quality system, right? We hear about
internal audits, external audits, supplier audits.
Can you explain the role those different types
of audits play in maintaining GCP compliance?
Absolutely. Audits are like regular checkups
for the quality system. Internal audits are done
by the company itself to make sure things are
running smoothly. External audits might be done
by a third party or by the sponsor of a trial
to check up on their partners, like contract
research organizations, CROs, or the trial sites.
And supplier audits focus on the quality of everything
coming into the company, like raw materials,
components, and any outsourced services. This
is highlighted in the ICH Q11 Q &A guidance.
So they're all about catching problems early
on. What does a typical audit process involve?
What are the steps? Well, whether it's internal,
external, or a supplier audit, the process is
pretty similar. It starts with planning, figuring
out what the audit will cover, then they'll actually
conduct the audit, looking at documents, observing
processes, and interviewing people. All the findings
are documented and then reported to the relevant
folks. It's really about seeing if things are
being done according to plan and if those plans
are actually effective. The goal is to find any
areas where things aren't quite right and could
be improved. And once they find those problems,
it's not enough just to identify them. They need
to be addressed. That's where the corrective
and preventive action or Calabi system comes
in, right? You got it. Calabi is essential, both
for audits and for inspections. When a problem
is found, the company needs to figure out why
it happened, fix it, and then prevent it from
happening again. A strong Calabi system is really
the foundation for continuous improvement. And
of course, we've talked a lot about the importance
of documentation. How does good record keeping
support all of this? Documentation is everything.
If it's not documented, it's like it never happened.
Everything needs to be accurate, legible, contemporaneous,
original, complete, consistent, enduring, and
available. Those are the LLCOA plus principles
we've discussed before. Good documentation is
required by regulations like 21 CFR Part 211
Subpart J. It's proof that procedures are being
followed and it's essential for internal audits,
external audits, inspections, and KPA investigations.
Makes sense. And finally, we've touched on validation
before. How does process validation tie into
all of this? Process validation ensures that
manufacturing processes consistently produce
high quality products. This includes things like
design qualification DQ, installation qualification
IQ, operational qualification OQ, and performance
qualification PQ. We've mentioned that framework
before and it's outlined in resources like the
21 CFR 111 YouTube video. It's all about proving
that a specific process will reliably create
a product that meets all the required standards.
And it's not just about the initial validation.
Continuous monitoring and reassessment, especially
of those critical to quality factors, are essential
throughout the entire process. That's something
that's often discussed in FDA conferences. So
it's this constant cycle of regulations, industry
efforts, audits, inspections, enforcement, and
always striving to do things better. It's complex,
but ultimately it's all about making sure those
medical products are safe and effective. Exactly.
We have this whole system of checks and balances
to make sure good clinical practice is being
followed. Inspections, audits, KPA, it all works
together to protect people participating in trials
and ensure that the data we use to make decisions
about new treatments is reliable. It is a complex
landscape, but incredibly important. And with
clinical research becoming increasingly global,
how do we strengthen international collaboration
to make sure those standards are consistent all
over the world? And what about the impact of
new technologies? They offer great potential
but could also create new challenges for compliance.
Those are really important questions. As the
world and technology continue to change, we need
to adapt and make sure those basic principles
of GCP and CGMP remain strong and effective in
protecting public health. It's definitely something
to think about. Absolutely. It's an evolving
landscape and we need to keep learning and adapting
to ensure patient safety remains at the forefront.
Well said. And that's a wrap for our deep dive
today. Until next time. See you.

Chapters

No chapters available.