Where the requirement comes from
- Annex 11 to the EAEU GMP Rules (EEC Council Decision No. 77) is the main document on computerized systems: it requires validation, risk management, an audit trail, access control and data protection throughout the entire retention period.
- The EAEU GDP Rules (EEC Council Decision No. 80) require that, before a computerized system is put into use, validation or verification demonstrate that it can achieve the intended results accurately, consistently and reproducibly.
- The storage rules of Order No. 260n permit an electronic log with archiving (clause 18) and require validation of any computerized system that replaces physical segregation of zones (clause 10).
- SanPiN 3.3686-21 requires, for the cold chain of immunobiological medicinal products, that the design of the data logger prevent data falsification and intermediate data loss, and that the data be kept for five years.
- Roszdravnadzor inspection checklists (Order No. 5803) include a set of questions on computerized systems.
- For reference: the GAMP 5 guide is not a regulation but a methodology that is convenient to rely on when planning the work; the US rule 21 CFR Part 11 does not apply in Russia and is taken into account only for export supplies.
GAMP 5 software categories
| Category | What it is | Scope of testing in a monitoring system |
|---|---|---|
| 1 — infrastructure software | OS, DBMS, network software | infrastructure qualification, documentation of versions |
| 3 — non-configured software | firmware of sensors and controllers | verification of operation within the system |
| 4 — configured software | SCADA platform with configuration of points, thresholds, reports and roles | verification of the configuration and critical functions |
| 5 — custom software | custom-developed modules, integrations | full lifecycle: specifications, code review, unit and integration tests |
The V-model and documentation
| Document | Contents |
|---|---|
| Validation plan | system boundaries, roles, software categories, approach, completion criteria |
| Risk assessment | functions that affect product quality and data integrity, and the depth of their testing |
| URS | user requirements: points, intervals, thresholds, alerts, reports, retention, access |
| FS and configuration specification | how the system meets the requirements: list of points, addressing, thresholds, roles, report templates |
| IQ protocol and report | installed according to specification: software versions, sensor serial numbers and verification, network, UPS, time |
| OQ protocol and report | functions work: measurement, archive, alarms, escalation, audit trail, backup |
| PQ protocol and report | the system works under real conditions: shifts, weekends, staff response |
| Traceability matrix | each requirement is linked to a test and its result |
| Validation report | summary, deviations and their closure, decision on release for operation |
Typical OQ tests
| Function | Test | Acceptance criterion |
|---|---|---|
| Channel accuracy | comparison of readings with a reference thermometer at an operating point | difference within the instrument’s accuracy |
| Recording interval | check of timestamps in the archive over 24 hours | interval matches the configuration, no gaps |
| High-limit alarm | heating the sensor above the threshold | event and alert within the set delay |
| Escalation | the alarm is not acknowledged | message sent to the second tier of recipients |
| Loss of connection | disconnecting a sensor or line | technical alarm; after recovery, the buffer is uploaded |
| Power failure | disconnecting 220 V in the control cabinet | operation on UPS, power event logged, no data lost |
| Audit trail | threshold change by an administrator | record: who, when, old and new value, reason |
| Data protection | attempt to change an archived value | not possible, the attempt is logged |
| Access rights | login with the operator role | administrator functions unavailable |
| Backup | restoring the archive on a test server | data match the original |
| Reports | generating a log for a period | values match the archive, deviations highlighted |
Data integrity: ALCOA+
| Principle | How it is verified |
|---|---|
| Attributable | each value is linked to a sensor, each action to a user |
| Legible | data are available in a readable form throughout the retention period |
| Contemporaneous | recorded at the time of measurement, with synchronized time |
| Original | raw values are stored, not recalculated ones |
| Accurate | verified sensors, tested conversions |
| + complete, consistent, enduring, available | no gaps, buffering, backups, export at the inspector’s request |
After go-live
- Change control. Adding points, changing thresholds and updating software are assessed for risk and, where necessary, followed by repeat testing.
- Periodic review. Once a year — analysis of incidents, changes, users and permissions, and backup results.
- Access management. Staff departures and role changes are reflected in the system immediately.
- Verification. Sensor replacements are recorded in the maintenance log with serial numbers.
Frequently asked questions
Does a pharmacy have to validate its monitoring system?
Order No. 259n does not impose a direct obligation on pharmacies, but the electronic log must be reliable and secure. For pharmacy chains with a centralized system, simplified verification of functions is good practice.
How long does validation take?
For a typical warehouse system — 2 to 6 weeks, depending on the number of points, integrations and the amount of custom software.
Does validation have to be repeated after a software update?
The change is assessed for risk: minor updates require regression testing of the affected functions, while significant ones require repeating part of the OQ tests.
What is 21 CFR Part 11?
The US Food and Drug Administration (FDA) requirements for electronic records and electronic signatures. They are not mandatory in Russia, but are applied by manufacturers who export and are often used as a benchmark.