计算机化系统验证要注意些什么?

2023-02-10 · 法默康

trends

计算机化系统验证要注意些什么?封面图

正文内容

计算机化系统验证方法遵循制药工程协会(ISPE)的良好自动化生产实践指南第五版(GAMP5)的V模型和美国FDA的21CRF Part11的要求。该模型是使系统在整个生命周期实现合规与符合预定用途的通用方法,其将验证过程分为规范阶段和验证阶段,构成V字,同时根据计算机化系统的分类,在规范阶段和验证阶段分别执行特定的验证活动。

The computerized system validation method follows the requirements of the V model of the fifth edition of the Institute of Pharmaceutical Engineering (ISPE) Good Automated Production Practice Guide (GAMP5) and the 21CRF Part 11 of the FDA. This model is a general method to enable the system to achieve compliance and meet the intended purpose in the whole life cycle. It divides the verification process into the specification stage and the verification stage, forming the V word. At the same time, according to the classification of computerized systems, specific verification activities are carried out in the specification stage and the verification stage respectively.

药品生产全程质量监控在线、实时技术平台属于可配置软件产品,根据GAMP指南,在规范阶段需按顺序建立用户需求规范、功能规范和配置(设计)规范,在验证阶段按顺序进行安装确认、运行确认和性能确认,分别用于验证对应的规范得到满足。该项目包含的验证活动的V模型见图1。

The online and real-time technology platform for the quality monitoring of the whole process of drug production is a configurable software product. According to the GAMP guidelines, user requirements specifications, functional specifications and configuration (design) specifications need to be established in sequence at the specification stage. Installation confirmation, operation confirmation and performance confirmation are carried out in sequence at the validation stage, which are respectively used to verify that the corresponding specifications are met. The V model of verification activities included in the project is shown in Figure 1.

风险评估

risk assessment 

指南提出了质量风险管理的概念,要求将风险穿于从系统设计至系统引退的整个计算计划系统的生命周期中。验证项目采取了基于风险的验证方法,其风险管理的活动包括以下几个步骤:

The guide puts forward the concept of quality risk management, and requires that risk be put into the whole life cycle of the calculation plan system from system design to system retirement. The verification project adopts a risk-based verification method, and its risk management activities include the following steps:

在制定验证项目计划前,实施风险评估,用于识别系统受监管的法规并确定验证范围。验证团队通过供应商审计和业务访谈的形式完成了初步风险评估。

Before formulating the validation project plan, risk assessment is carried out to identify the regulations that the system is subject to supervision and determine the scope of validation. The validation team completed the preliminary risk assessment in the form of supplier audit and business interview.

在建立功能规范后,实施功能性风险评估,从法规、业务、技术角度评估各项系统功能的风险水平。由验证团队和业务部门骨干通过风险评估问卷的形式共同完成功能性风险评估。

After establishing functional specifications, functional risk assessment is implemented to assess the risk level of various system functions from the perspective of regulations, business and technology. The functional risk assessment is jointly completed by the validation team and the backbone of the business department through the risk assessment questionnaire.

在验证阶段,根据各项系统功能的风险水平,采取相应的测试方法,从而将风险管理贯穿于整个验证过程。

In the verification stage, according to the risk level of each system function, corresponding test methods are adopted, so as to run risk management through the whole verification process.

执行规范阶段的验证活动

Perform validation activities in the specification phase

在规范阶段,需依次建立用户需求规范、功能需求规范和配置(设计)规范文档。为了识别系统的用户需求,验证团队先对系统支持的业务流程进行了梳理,编制了详细的业务流程图,并在业务流程图中标注由系统功能执行的步骤。在业务流程图的基础上,由业务部门的流程负责人对用户需求进行识别,可保证用户需求的完整性。识别用户需求时,必须同时考虑业务需求和法规需求。书面记录每一个识别出的用户需求形成用户需求规范。对每一个用户需求规范,由系统开发人员继续编写功能需求规范和配置(设计)需求规范,以记录系统功能和软件配置(设计)的规范要求,形成功能需求文档和配置(设计)需求规范文档。规范文档需在进入验证阶段前,依次由验证主管进行复核和审批。规范文档中记录的需求,将作为验证阶段编制验证测试脚本的依据,每一个识别出的需求,都将能够被追溯到特定的测试案例,同时,也是判断测试结果通过与否的衡量标准。表1是一个针对某系统功能的用户需求、功能需求和设计需求规范的完整实例。

In the specification stage, the user requirement specification, functional requirement specification and configuration (design) specification documents need to be established in sequence. In order to identify the user needs of the system, the validation team first sorted out the business processes supported by the system, prepared a detailed business flow chart, and marked the steps executed by the system functions in the business flow chart. On the basis of the business flow chart, the process leader of the business department identifies the user requirements, which can ensure the integrity of the user requirements. When identifying user needs, business needs and regulatory needs must be considered at the same time. Write down each identified user requirement to form a user requirement specification. For each user requirement specification, the system developer will continue to write the functional requirement specification and configuration (design) requirement specification to record the specification requirements of the system function and software configuration (design), and form the functional requirement document and configuration (design) requirement specification document. The specification documents shall be reviewed and approved by the validation supervisor in turn before entering the validation stage. The requirements recorded in the specification document will be used as the basis for preparing the verification test script in the verification stage. Each identified requirement will be traceable to a specific test case, and it is also a measure to judge whether the test result is passed or not. Table 1 is a complete example of user requirements, functional requirements and design requirements specifications for a system function.

执行验证阶段的验证活动

Perform validation activities in the validation phase

验证阶段的验证活动分为依次执行的安装确认、运行确认和性能确认。安装确认的目的是证明系统是按照书面的、预先已批准的规范进行安装的。验证内容包括软、硬件的安装和配置。运行确认的目的是证明系统在规定的运行范围内,是按照书面的、预先已批准的规范运行的。性能确认的目的是证明系统在业务流程和运行环境范围内,能够按照书面的、预先已批准的规范正确执行所要求的流程活动。

The verification activities in the verification stage are divided into installation qualification, operation qualification and performance qualification. The purpose of IQ is to prove that the system is installed according to the written and pre-approved specifications. The verification includes the installation and configuration of software and hardware. The purpose of OQ is to prove that the system operates in accordance with the written and pre-approved specifications within the specified operating range. The purpose of performance qualification is to prove that the system can correctly perform the required process activities according to the written and pre-approved specifications within the scope of business process and operation environment.

对于每项确认都包括:

For each confirmation, it includes:

编写确认协议,在确认协议中定义测试范围,测试流程(包括测试偏差处理的流程),参与测试人员的职责。由验证主管批准确认协议。

Prepare the confirmation protocol, define the test scope, test process (including test deviation handling process), and the responsibilities of the test personnel in the confirmation protocol. The validation director approves the validation agreement.

编写测试实例,根据在规范阶段识别的需求及其风险水平编写测试实例和测试脚本。由验证主管批准测试实例和脚本。

Write test cases and test scripts according to the requirements identified in the specification stage and their risk level. The validation supervisor approves the test cases and scripts.

执行测试,记录测试结果,对于发生的测试偏差进行记录,分析,确定处理解决方案(比如变更系统和重新测试)。由验证主管批准测试结果。

Execute the test, record the test results, record and analyze the test deviation, and determine the solution (such as system change and retest). The validation supervisor approves the test results.

4)对测试文档进行归档,编写确认报告。由验证主管批准确认报告。

4) Archive the test documents and prepare the confirmation report. The validation supervisor approves the validation report.

验证阶段的活动完成后,验证团队对所有的验证文档进行整理归档,并编制验证总结报告。验证总结报告需陈述所有验证活动的执行情况和执行结果,记录系统存在的缺陷和限制,并提供计算机化系统验证的结论。

After the activities in the validation stage are completed, the validation team will sort out and file all the validation documents and prepare the validation summary report. The validation summary report shall state the implementation and results of all validation activities, record the defects and limitations of the system, and provide the conclusion of computerized system validation.