Ir al contenido principal
DocumentMS

Pharma & life sciences

GxP document management for life sciences

GxP document management is governed by FDA 21 CFR Part 11 and EU GMP Annex 11, which require validated systems, attributable and unalterable audit trails, controlled electronic signatures, and copies that remain readable for the record’s full retention period — commonly the product lifetime plus one year.

Why documents are difficult in pharma & life sciences

Life sciences is the sector with the strictest electronic records requirements of any we work with, and the one where a document system itself becomes an object of inspection. Under FDA 21 CFR Part 11 and EU GMP Annex 11, the system holding your batch records is not neutral infrastructure — it must be validated, its audit trail must be computer-generated and unalterable, and its electronic signatures must be provably linked to the records they apply to.

The practical consequence is that "we will configure it later" is not available. A GxP configuration has to be specified, tested and documented before it holds a regulated record, and changes to it are themselves controlled. That front-loads work most organisations prefer to defer, and it is the single biggest reason life sciences document projects run longer than the equivalent project in another sector.

Regulatory pressure

Three regulatory pressures that shape the configuration

These are inspection criteria, not guidance. Each one has produced observations in published warning letters.
  1. FDA 21 CFR Part 11 (electronic records; electronic signatures)

    What it requires. Validated systems, secure computer-generated time-stamped audit trails recording operator entries and actions that create, modify or delete records, retention of audit trails for at least as long as the records themselves, limited system access, and electronic signatures linked to their records so they cannot be excised, copied or transferred.

    What it means for a document system. The audit trail must be generated by the system rather than maintained by a person, must be unalterable, and must outlive the record. It also means signature and record are inseparable: a signed batch record whose signature could be detached and reapplied elsewhere fails the rule.

  2. EU GMP Annex 11 (computerised systems)

    What it requires. Risk-based validation, an up-to-date system description, supplier assessment, controls over data changes with reason recorded, and the ability to obtain readable printed copies of electronically stored data throughout the retention period.

    What it means for a document system. Supplier assessment makes the vendor part of your inspection scope, so the availability of validation documentation and a quality agreement is a procurement requirement rather than a nicety. "Reason for change" also has to be captured, which most general-purpose systems do not prompt for.

  3. ALCOA+ data integrity expectations

    What it requires. Records must be Attributable, Legible, Contemporaneous, Original and Accurate, with the additional expectations that they are Complete, Consistent, Enduring and Available.

    What it means for a document system. Attributable rules out shared accounts absolutely. Contemporaneous rules out batch data entry after the fact. Enduring and Available shape retention and export: a record you cannot render in fifteen years is not available, whatever your storage says.

Capability mapping

Five capabilities mapped to GxP requirements

What each module is relied on for in a validated configuration.
  • Computer-generated, unalterable audit trail

    Every action is recorded by the system with the operator, a server-side timestamp and the document version, in an append-only log that no role can edit. Part 11 §11.10(e) requires exactly this, and requires the trail to be retained at least as long as the record — which is why the trail outlives disposed documents.

  • Signatures bound to a specific version

    A signature applies to one version of one document and is filed with it, so it cannot be detached and reapplied. The signing history records the signer, the time and what was signed — the linkage Part 11 §11.70 demands.

  • Approval before issue for controlled SOPs

    Workflow enforces that only an approved version is current, marks superseded versions unambiguously, and records the approver and date. The failure this prevents — an operator working to a superseded SOP — is among the most commonly cited GMP observations.

  • Attributable access with no shared accounts

    Unique user identification with two-factor authentication enforceable per role, and OIDC single sign-on so identity is governed centrally. Attributability is not a permission feature; it is the precondition for every other Part 11 control.

  • Retention that outlasts the product

    Batch documentation retention is expressed relative to expiry or release rather than creation, and disposition raises a review rather than deleting. Legal holds suspend disposal where an investigation or claim is live.

Taxonomy

A starting folder taxonomy

Structured by GxP discipline, because that is how validation scope, permissions and inspection requests are all framed.

Quality management system

  • Standard operating procedures (controlled)
  • Work instructions and forms
  • Quality manual and policies
  • Change controls
  • Deviations and CAPA

Manufacturing (GMP)

  • Master batch records
  • Executed batch records
  • Equipment logs and calibration
  • Cleaning validation
  • Environmental monitoring

Laboratory (GLP)

  • Analytical methods and validation
  • Certificates of analysis
  • Stability study data
  • Out-of-specification investigations

Clinical (GCP)

  • Trial master file sections
  • Protocols and amendments
  • Informed consent forms
  • Investigator site files

Regulatory and validation

  • Submissions and correspondence
  • Computerised system validation packages
  • Supplier assessments and quality agreements
  • Training records and competency

Keeping computerised system validation in its own branch matters because it is the documentation an inspector asks for about the document system itself — including the validation of the DocumentMS configuration you are using to hold everything else.

Worked example

A worked workflow: controlled SOP revision under change control

The most inspected document workflow in the sector, and the one where evidence of who approved which version is the whole point.
  1. Step 1: Raise change control

    A change control record captures the reason for the change and its assessed impact. Annex 11 expects the reason to be recorded, so it is a mandatory field rather than a free-text note.

  2. Step 2: Draft and review

    The author produces a new version. It routes to the technical reviewer and Quality Assurance, each approving in their own authenticated session with 2FA where the role requires it.

  3. Step 3: Approve, train, effective date

    QA approval locks the version and sets an effective date. Affected operators receive a training and acknowledgement task, and the SOP does not become effective until training is recorded.

  4. Step 4: Supersede and retain

    The previous version is marked superseded and retained — never deleted — and the retention rule attaches. The audit trail evidences which version was effective on any given date.

Retention

Retention expectations

GxP retention periods are usually expressed relative to product expiry or trial completion rather than to document creation, which is the detail most often misconfigured.
Pharma & life sciences retention expectations — starting points, not a schedule
Record classCommonly applied periodWhat starts the clockSource
Executed batch records (EU GMP)1 year after batch expiry, or 5 years after certification — whichever is longerBatch expiry or QP certificationEU GMP Part I, Chapter 4
Batch records (US)1 year after batch expiry, or 3 years after distributionBatch expiry or distribution21 CFR §211.180
Audit trailsAt least as long as the records they describeFollows the underlying record21 CFR §11.10(e)
Trial master file / clinical trial documentation25 years (EU CTR); at least 2 years after last approval (ICH GCP baseline)Trial completion or last marketing approvalEU Regulation 536/2014; ICH E6(R2) §4.9.5
Validation documentation for computerised systemsLife of the system plus a defined period after decommissioningSystem decommissioningAnnex 11 / organisational validation policy
Training recordsDuration of employment plus a defined periodEnd of employmentGMP expectation; period set by organisational policy

These periods are indicative and must be confirmed against the specific regulations, product types and territories you operate under before you rely on them. GxP retention differs between GMP, GCP and GLP, between the EU and US, and by product class. Nothing here is regulatory advice.

FAQ

Pharma & life sciences document management: common questions

What compliance, IT and operations teams in this sector ask us first.
Is DocumentMS validated for 21 CFR Part 11?

A product cannot be validated on your behalf — validation applies to your configuration, in your process, for your intended use. What we supply is the documentation that makes your validation feasible: a system description, a completed supplier assessment questionnaire, functional specifications and platform test evidence, all released under NDA on request. Ask for the pack early in an evaluation rather than late; its absence is a hard blocker for a GxP buyer, and finding out during qualification is an expensive way to discover it.

Does the audit trail meet Part 11 §11.10(e)?

It is computer-generated, time-stamped from the server, records the operator and the affected document version, cannot be edited or deleted by any role including administrators, and is retained after the underlying document is disposed of. That is the shape the rule requires. Whether your implementation satisfies an inspector is a validation question, not a feature question.

Are the electronic signatures Part 11 compliant?

Signatures are applied in an authenticated session, bound to one version of one document, and filed with it so they cannot be excised or transferred — the §11.70 linkage requirement. The signature manifestation carries all three elements §11.50 requires: the signer’s printed name, the date and time of signing, and the meaning of the signature — approved, reviewed, authored — selected by the signer at the point of signing rather than inferred from the workflow step.

Can we record a reason for change?

Yes, and for GxP configurations it should be mandatory rather than optional. Annex 11 expects the reason for a change to be recorded, and a free-text field that people can skip produces exactly the observation you were trying to avoid.

How do you prevent an operator using a superseded SOP?

Only the approved version is marked current, superseded versions are labelled unambiguously and cannot be presented as current, and the effective date is set on approval. The audit trail then evidences which version was effective on any given date — which is the question an investigation actually turns on.

A 30-minute session using the taxonomy, workflow and retention rules on this page, adapted to how your organisation actually works.