63 - Audit Readiness and Continuous Improvement in Clinical Quality Systems (S23E4)
From Concept to Medicine - A Comprehensive Drug Development Journey
This episode offers listeners a chance to become more knowledgeable on how they can audit preparedness, by using internal audits. We will discuss corrective action processes and share strategies for ensuring ongoing quality improvement.
Our goal is to help empower these organization with information on how to maintain compliance and risk management. The ultimate intention is to show how this can ensure that clinical operations stay strong, aligned with the most current cGCP regulations, transparent, and robust.
This episode will use FDA regulations, ICH guidelines, and GMP, quality, and management handbooks to help illuminate this information. We will look at creating a culture that isn't based on cramming, but more of a culture that supports building quality. This helps promote the idea of a culture shift, meaning to create a culture where quality doesn't only come from one department but more of an all-encompassing idea.
Available Results
Generated results are saved to the knowledge database for reuse and search.
Extract Knowledge
Pick what you want extracted first. Model, scope, and chapter options appear after a template is selected.
Transcript
Welcome to another deep dive. We're going deep today on audit readiness and making those clinical quality systems better all the time. Yeah, it's a big one. We're talking about making sure medical products are safe and effective, and that's kind of important, right? It is. We want you guys to know what's going on without getting too lost in the weeds. Exactly. We're basically pulling out those golden nuggets of best practices. That's right. We want to show you how to stay ahead of the game when it comes to quality management. You know, we always go all in on the research for these deep dives. We dug through tons of FDA regulations, like seriously, a whole bunch of parts of the code of federal regulations. From like manufacturing all the way to clinical trials, everything. Then there's the ICH guidelines, those global standards everyone follows for quality, safety, and efficacy, really important stuff. Absolutely. And we didn't stop there. Nope. We went through GMP and quality management handbooks and even listened to hours of FDA training sessions and industry webinars. Like getting the inside scoop straight from the experts. And just to round things out, we threw in some other relevant texts. You know, just to cover all the bases. So let's jump in. How do organizations make sure they're always ready for an audit? Okay, so the first thing is to understand that it's not about cramming at the last minute, right? It's about creating a culture where audit readiness is just built into your quality systems Okay, that makes sense. But how does an organization actually start building that kind of culture? I mean, where do they begin? Well, one of the things we saw a lot in the materials was the importance of self -assessment It's like taking a good hard look in the mirror. Okay. And internal audits are really key for this. Leonard Steinborn had a lot to say about this in one of the books we read. He calls internal audits a vital self -assessment tool. So it's like checking your own work before turning it in. Exactly. Companies can use these audits to really scrutinize their processes, you know, really dig in and find those spots that might be weak. Or areas that don't quite line up with the regulations. Yeah. Or even they're on internal standards. And here's the thing. It's not just about checking boxes and making sure you're compliant. Internal audits are a chance to find ways to make your processes even better. So it's a chance to go above and beyond, not just meet the minimum requirements. Precisely. Now, to take self -assessment to the next level, we have mock audits. It's like a practice run. Makes sense. They're like simulated inspections, you know, like stepping into the shoes of a regulator. I see. And the whole point is to find any gaps before the real inspection happens. And how are these mock audits different from just reading through procedures? Well, they're much more hands -on. They're designed to test the actual implementation of your systems and how robust they are in real -world scenarios. OK, so it's not just theoretical. It's very practical. Absolutely. And some of the webinars even talked about including mark recalls as part of these exercises. Oh, wow. That's next level. Yeah. So you're not just identifying a problem. You're actually practicing the whole response process. So investigating and taking corrective action. and managing that potential recall like it's really happening. That's intense, but I guess it really helps to expose any weaknesses in your system. For sure. So let's say these internal and mock audits uncover some issues. What happens then? How do companies address those findings? That's where the corrective action and preventive action CAPA system comes in. Right, I've heard of that. It's really the heart of continuous improvement in a quality system. And KPA is all about taking action, right? Exactly. It's how organizations fix problems that are found during audits. And crucially, it's how they make sure those problems don't happen again. So it's all about learning from mistakes and then putting safeguards in place. Yeah, that's a good way to put it. There was a great point made in a season six episode with Godwin. He said that when the FDA issues you a Form 483, you absolutely need a solid KPA plan to address it. OK. So when you're putting together a KPA plan, what are some of the key things to keep in mind? Well, the FDA is very clear about this. They say each observation on that Form 483 needs its own response. You can't lump them all together. Right. And you got to be upfront about whether you agree or disagree with the FDA's findings. I see. And if you agree, that's where the KPA plan comes in. You've got to lay out exactly how you're going to fix the problem. I'm guessing just saying, we'll fix it. isn't enough. No, not even close. You need realistic timelines, and you need to be specific about how you'll prove that your actions were effective. Okay, so you have to show that you're not just taking action, but that the action is actually making a difference. Exactly. And there's another really important piece. You can't just fix the symptom. You have to dig deep and figure out the root cause of the problem. I remember reading something about that. Yeah, Rodriguez Perez wrote a lot about this in his work on KPA. Okay. He said that effective root cause analysis is absolutely essential. There are a bunch of tools you can use for this, like the five why's technique. Oh, I've heard of that. It's where you keep asking why until you get to the bottom of the issue. Exactly. It's about asking what, where, when, how, and of course why. You got to get to the heart of the matter. Okay, and once you've identified that root cause. The KPA plan itself has to be pretty detailed, right? Oh, yeah, for sure. Rodriguez Perez stressed that you need to outline every single action you're going to take. And not only that, but you need to explain how each of those actions will prevent the problem from happening again. Right. And then you have to lay out how you're going to validate or verify that those actions are working. proving it with data exactly and of course you need realistic timelines for when you're going to implement everything so it's a whole project plan basically it is and here's something that might surprise you yeah you also need to consider whether the root cause of this problem could be affecting other parts of the organization wow so it's not just about fixing one isolated issue it's about looking at the big picture. Exactly. It's about systemic improvement, not just spot fixes. That makes a lot of sense. Now it seems like even small deviations from procedures can be opportunities for learning. Absolutely. You know, in season two, we talked about how important it is to investigate deviations any time something unexpected happens or there's a departure from the approved way of doing things. Well, these investigations are not just about fixing the immediate problem, they're a gold mine of information for continuous improvement. OK, I see. By figuring out what went wrong and all the factors that contributed to it, you can proactively make your processes better and prevent similar deviations from happening again. It's all about being proactive. Yeah. And you know, in season seven, they made a really good point about this. OK. They said that any time you have a discrepancy that you can't explain or something fails to meet specifications, you need to launch a full investigation. So even if it seems small, it's worth looking into. Yeah, because sometimes those small issues are actually symptoms of bigger problems that are lurking beneath the surface. Got it. So we've talked about a lot of specific processes and tools, but what about the overall mindset? Right. So one of the biggest takeaways from our research is that organizations need to always be prepared for an FDA inspection. Like always be ready. Always. Godwin from the FDA, she really emphasized this in one of the webinars. She said that maintaining that state of constant readiness is the best way to handle an FDA inspection. Makes sense. She also pointed out that the whole point of these inspections is to make sure that companies are following the regulations and adhering to good clinical practice or GCP. Okay, so it's about ensuring patient safety and data integrity. Exactly. It's not about trying to catch companies doing something wrong. It's about verifying that they're meeting the established standards. I've also learned something interesting about those clinical investigator regulatory assessments, or RAs, that are initiated by CDER. They're usually voluntary, right? Right. Unless the FDA specifically says otherwise. Yeah, that's right. Alaro talked about this in the FDA CITC Day 3 transcript. He said that if an RA is mandatory, the FDA will be very clear about it. They'll let you know exactly what authority they're using, but for voluntary RAs, they'll usually ask for your consent to participate. I guess this is a little different from a traditional on -site inspection. Yeah. Another interesting thing Alaro pointed out is that the FDA doesn't issue a Form 482 at the start of a Remote Regulatory Assessment, or RRA. That's different. Right. Now, let's say the FDA inspectors do show up at your door. What's the best way to handle that? I'd imagine honesty is the best policy. You got it. Transparency and clear communication are super important during an inspection. Makes sense. You know, back in Season 7, we learned that trying to hide things from the FDA will only make things worse. It erodes trust. Yeah, I can see that. The goal is to show the FDA that your organization is committed to quality and compliance. And the best way to do that is to be open and honest. Great. So we've covered how to be audit ready. Let's shift gears now and talk about the second big piece. Continuous quality improvement. Yeah, this is all about how organizations can proactively make their quality systems better and better. Right. And we've already touched on a few things that contribute to this. We have. Like we talked about how investigating deviations isn't just about fixing the immediate problem. It's also a valuable source of data for identifying trends and figuring out where you can make improvements. And those mock audits we talked about, they also provide a lot of feedback that can drive proactive changes. Absolutely. It's like getting a free consultation from an expert. It seems like the FDA actually encourages this kind of proactive approach to quality. Oh, they definitely do. There's this FDA initiative called the Pharmaceutical CGMP for the 21st century, and it really pushes for innovation and using risk management principles in pharmaceutical manufacturing. They want companies to constantly be looking for ways to improve. That sounds a lot like the concept of quality by design or QBD. It is Dirvaj, he's a big name in this field, and he describes QBD as a philosophy where you're building quality into the product and the process from the very beginning. Interesting. The idea is that if you really understand the science and how your process works, you can anticipate potential problems and design them out. Okay, so you're preventing problems before they even happen. Exactly. And if you can show the FDA that you have this level of knowledge and control, you might be able to justify a more streamlined regulatory oversight process. So less red tape. Potentially, yes. And this ties in with another important concept. Pharmaceutical development is a learning process. ICH Q8 actually emphasizes this. I see. It's all about continuous improvement. So speaking of proactive strategies, risk management seems to be really important for continuous improvement. It's huge. Quality risk management or QRM is a systematic approach to identifying, assessing, and controlling risks to the quality of a medicine. You know, in the description for our season three, episode six, we talked about how systematic risk assessments are super important for making good decisions, improving processes, and meeting those regulatory requirements. So it's about being proactive and thinking about risks all the time. Trying to prevent those problems before they even have a chance to happen. Exactly. Godwin, she's been a great source. of information on this topic. She said that risk management should be part of every single decision made in pharmaceutical manufacturing. And patient safety and product quality, those should always be the top priorities. Now, when it comes to risk management, the FDA really looks to ICHQ -9 for guidance. It's the key guideline for how to manage risks. So what are the basic steps involved in this QRM process? It's pretty straightforward. First, you have risk assessment. This involves identifying potential hazards, like asking yourself, what could possibly go wrong? Then you analyze those hazards, figure out how likely they are to happen and how severe the consequences would be. And then you evaluate the risk, which means you compare the estimated risk to some predetermined criteria to see if it's acceptable. After that, you move on to risk control. This is where you decide how to reduce the risk or whether you can just accept it. So it's all about making informed decisions. And then the final step is risk review. It's the ongoing process of monitoring and evaluating your risk management strategies to make sure they're actually working. It's like a continuous feedback loop. Exactly. Rodriguez Perez, in his book, he gives a really good overview of all these steps based on ICH Q9. And he talks about hazard identification. He does. He emphasizes that it's all about systematically using information to find those potential hazards. So it's about being proactive and looking for those risks before they turn into problems. Exactly. And all of this talk about quality systems and risk management, it points to something bigger. What's that? It takes a specific kind of culture to pull this off. You need an organization where everyone is committed to quality. from the top down. Right. It can't just be one department's responsibility. Exactly. Back in season two, we talked about how a culture of quality starts with strong leadership. Yeah. The leaders have to set the tone. They do. They have to make it clear that adhering to regulations and quality standards is not optional. It's the foundation of everything they do. Right. And it's not just about the leaders. You have to empower every employee to feel responsible for quality. Given the sense of ownership. Exactly. Make them feel comfortable speaking up if they see something that's not right. Create a culture where everyone is looking out for quality. That's the goal. And you know, training is a really important part of this. Yes. Back in season six, They emphasized how effective training can lead to much more thorough data review and just overall stronger quality systems. Procedures are like the blueprint. They tell you what to do. But training is what brings those procedures to life. It bridges the gap between theory and practice. And we talked about this in season seven as well. Even something as basic as hygiene practices in manufacturing, you need good training to make sure everyone understands why it's important and how to do it right. Right. And then you need to document everything and observe people regularly to make sure those practices are being followed. So training and documentation go hand in hand. They do. And speaking of clinical quality systems, let's talk specifically about good clinical practice, or CGCP. OK, so how do those CGCP requirements fit into this whole picture of audit readiness and continuous improvement? Well, CGCP is all about setting the standards for clinical trials. It covers everything from designing and conducting the trials to recording and reporting the results. Right. It's all about ethics and scientific quality. And the FDA is obviously very focused on this. They are. Godwin, in the FDA CITC Day 3 transcript, She talked about how the FDA inspects clinical investigators to make sure they're following CGCP. And Jeba, who is also part of that series, he added that these GCP regulations apply to all clinical trials. It doesn't matter how they're designed or what kind of innovative methods they use. And then there are the bioresearch monitoring or BIMO inspections. Jeba explained that these are specifically designed to look at practices that could affect the reliability of the data and the safety of the participants in the trial. Got it. So if you want to be audit ready in a clinical setting, you got to make sure you're following CGCP. For sure. And one thing that keeps coming up over and over again is the importance of documentation. Yeah. It's like the foundation of a strong quality system. Whether you're talking about hygiene and manufacturing, which we discussed in season two, or GLP environments, which we covered in season five, documentation is crucial. Right. If it's not documented, it's like it never happened. Especially in a GLP setting. Exactly. And we're not just talking about major procedures. Any deviation from standard procedures needs to be thoroughly documented and investigated. So no matter how small the deviation, write it down. Absolutely. And we also learned in season two that you need to document all complaints, whether they come from patients or investigators. That creates an audit trail that can be really helpful for identifying patterns or systemic issues. And then in season six, we talked about change control. Any changes to equipment or processes have to go through a formal process that relies heavily on documentation. It all comes back to documentation. It does. And now that we're living in a digital world, electronic records and signatures are becoming super important. Yeah, they are. And the FDA has specific regulations for this 21 CFR Part 11. And those regulations basically tell you how to make sure electronic records and signatures are trustworthy and reliable. Exactly. Like equivalent to paper records and handwritten signatures. OK. Part 11 lays out the requirements for electronic signatures, so they're legally binding. I see. And it also says that electronic records can be used instead of paper records unless there's a regulation that specifically says you can't. So it's about making sure those electronic systems are just as good as the old paper -based systems. Exactly. And, you know, we watched a video on good documentation practices and it highlighted some really important things to keep in mind when you're managing electronic data. OK, like what? Well, first of all, you need secure systems for storing that data and those systems have to be validated. Right. And then you need audit trails, those time stamped records that show every change that's been made to the data. And don't forget backups. You got to make sure your data is backed up regularly and stored in a safe place, preferably off site. Right. And then you need to think about environmental controls to protect your data from things like power outages or extreme temperatures. So you're protecting against data loss or corruption. Right. And finally, you need to have clear procedures for restoring archive data if you ever need it. And you need to test those procedures regularly. OK. So it's not just about having the data, but making sure you can access it when you need it. Well, I think we've covered a lot of ground today. Audit readiness and continuous improvement, two sides of the same coin. There really are. It's not just about passing an inspection. It's about building a culture of quality where everyone is always striving to make things better. And it all starts with a commitment from the top. Absolutely. And then it's about giving everyone in the organization the tools and the training they need to contribute to that culture of quality. And of course, you have to have those robust processes in place like CPA and risk management. Right. Those are essential. So for our listeners out there, we hope this deep dive has given you a better understanding of how audit readiness and continuous improvement work together to ensure the safety and effectiveness of medical products. And as you think about how complex clinical research is becoming and how those regulations are constantly evolving, it begs the question, how can you and your organization become even more proactive and adaptable? How can you stay ahead of the curve when it comes to audit readiness and continuous improvement? It's a question worth pondering. And if any of the topics we discussed today sparked your interest, we encourage you to dig deeper. Check out those FDA regulations, the ICH guidelines, and all the other resources we mentioned. And remember, staying informed is a journey, not a destination. Well said. Thanks for joining us on this deep dive.