<!DOCTYPE article PUBLIC "-//NLM//DTD JATS (Z39.96) Journal Archiving and Interchange DTD v1.0 20120330//EN" "JATS-archivearticle1.dtd">
<article xmlns:xlink="http://www.w3.org/1999/xlink">
  <front>
    <journal-meta>
      <journal-title-group>
        <journal-title>Proceedings of the SQAMIA</journal-title>
      </journal-title-group>
      <issn pub-type="ppub">1613-0073</issn>
    </journal-meta>
    <article-meta>
      <title-group>
        <article-title>Pharmaceutical Software Quality Assurance System</article-title>
      </title-group>
      <contrib-group>
        <contrib contrib-type="editor">
          <string-name>General Terms: System Architecture</string-name>
        </contrib>
        <aff id="aff0">
          <label>0</label>
          <institution>BOJANA KOTESKA and ANASTAS MISHEV, University SS. Cyril and Methodius, Faculty of Computer Science and Engineering</institution>
          ,
          <addr-line>Skopje LJUPCO PEJOV</addr-line>
          ,
          <institution>University SS. Cyril and Methodius, Faculty of Natural Science and Mathematics</institution>
          ,
          <addr-line>Skopje</addr-line>
        </aff>
      </contrib-group>
      <pub-date>
        <year>2016</year>
      </pub-date>
      <volume>5</volume>
      <abstract>
        <p>The risk-based nature of the pharmaceutical computer software puts it in a critical software category which imposes a must quality assurance and careful testing. This paper presents the architecture and data model of a quality assurance system for computer software solutions in pharmaceutical industry. Its main goal is to provide an online cloud solution with increased storage capacity and full time authorized access for quality checking of the developed software functionalities. The system corresponds to the requirements of the existing standards and protocols for pharmaceutical software quality. This system aims to ease the process of pharmaceutical software quality assurance process and automate the document generation required for quality document evidence.</p>
      </abstract>
    </article-meta>
  </front>
  <body>
    <sec id="sec-1">
      <title>1. INTRODUCTION</title>
      <p>5:42
rules and good manufacturing practice (GMP) methods specified for drug software system design and quality. The
goal of the system is to provide a structured data environment and to automate the process of documents generation
required for quality document evidence. It is mainly based, but not limited on the quality requirements specified in Good
Automated Manufacturing Practice (GAMP) 5 risk based-approach to Compliant GxP Computerized Systems [GAMP
5]. The main idea is to ensure that pharmaceutical software is developed according to already accepted standards for
developing software in pharmaceutical industry, in this case, GAMP 5.</p>
      <p>The paper is organized as follows: in the next Section we give an overview of the existing computer software quality
validation methods in the pharmaceutical industry. In Section 3, we describe the system architecture in details. Section
4 provides the data model of our system. The benefits and drawbacks of the systems are provided in Section 5 and
conclusive remarks are given in the last Section.
2.</p>
    </sec>
    <sec id="sec-2">
      <title>RELATED WORK</title>
      <p>GAMP 5 [GAMP 5] is a cost effective framework of good practice which ensures that computerized systems are
ready to be used and compliant with applicable regulations. Its aim is to ensure patient safety, product quality, and data
integrity. This Guide can be used by regulated companies, suppliers, and regulators for software, hardware, equipment,
system integration services, and IT support services.</p>
      <p>In addition to GAMP 5, there are several more validation guiding specifications that are commonly used in validating
automation systems in pharmaceutical industry.</p>
      <p>The "Guidance for Industry: General Principles of Software Validation" [US Food and Drug Administration and
others 2002] describes the general validation principles that FDA proposes for the validation of software used to design,
develop, or manufacture medical devices. This guideline covers the integration of software life cycle management and
the risk management activities.</p>
      <p>The "CFR(Code of Federal Regulations) Title 21 - part 11" [US Food and Drug Administration and others 2012]
provides rules for the food and drug administration. It emphasizes the validation of systems in order to ensure accuracy,
reliability, consistent intended performance, and the ability to discern invalid or altered electronic records.</p>
      <p>The "CFR(Code of Federal Regulations) Title 21 - part 820" [Food and Drug Administration and others 1996]
sets the current good manufacturing practice (CGMP). The requirements in this part are oriented to the the design,
manufacture, packaging, labeling, storage, installation, and servicing of all finished devices intended for human use.
These requirements ensure that finished devices will be safe and effective.</p>
      <p>The "PDA Technical Report 18, (TR 18) Validation of Computer-Related Systems" [PDA Committee on Validation
of Computer-Related Systems 1995] elaborates the steps to be taken in selecting, installing, and validating computer
systems used in pharmaceutical GMP (Good Manufacturing Practice) functions. It provides information about practical
documentation that can be used to validate the proper performance of the computer systems.</p>
      <p>According to the "1012-2004 - IEEE Standard for Software Verification and Validation" [148 2005] the term
software also includes firmware, microcode, and documentation. This standard specifies the software verification and
validation life cycle process requirements. It includes software-based systems, computer software, hardware, and
interfaces and it can be applied for software being developed, reused or maintained.</p>
      <p>In [Wingate 2016], the authors provide practical advices and guidance on how to achieve quality when developing
pharmaceutical software. Various processes utilized to automate QA (quality assurance) within CRM systems within
the pharmaceutical and biotech industry and to define current QA requirements are presented in [Simmons et al. 2014].</p>
      <p>Compared to the researches that have been made so far, no system for automatic quality assurance based on GAMP
5 has been proposed yet in the pharmaceutical industry. The system we propose should provide cloud based solution
for pharmaceutical software management and automatic document generation based on GAMP 5.</p>
    </sec>
    <sec id="sec-3">
      <title>3. SYSTEM ARCHITECTURE</title>
      <p>Fig. 1 shows the architecture of our pharmaceutical software quality assurance system. Pharmacists from different
pharmaceutical laboratories access the quality assurance system solution hosted in the Cloud by using a web browser.
Each user in the pharmaceutical laboratory has login credentials which allow him to log in to the system and to
manage data for the computer software being tested. A user from the pharmaceutical laboratory 1 has permissions
only to manage data for software solutions developed in his laboratory. Also, a pharmacist with provided credentials
has a possibility to access the cloud solution outside the laboratory by using any electronic device that is connected to
Internet and supports web browsing. The primary method for the authentication will be weblogin. Users are authorized
to access only the data for the projects they participate in.</p>
      <p>After the successful login, the user has a possibility to chose a software project from the list of the project being
developed in his laboratory. According to example forms proposed by GAMP 5 [GAMP 5], the system must provide
generation of the following documents:
—Risk assessment form;
—Source code review form;
—Forms to assist with testing;
—Forms to assist with the process of managing a change;
—Forms to assist with document management;
—Format for a traceability matrix;
—Forms to support validation reporting;
—Forms to support backup and restore;
—Forms to support performance monitoring.
5:44</p>
      <p>The main idea of our quality assurance system is the automatic generation of the required document forms. The
system should provide a preview of the missing documents by checking the inserted data for a selected software
solution.</p>
      <p>The manual document filling is replaced by importing the data from the database. User is only responsible for
inserting the data for the software solution by using the web interface. For example, if a user inserted the names of the
software functions once, they will be used for the generation of all documents that contains records for the software
functions names. When a change for an inserted function is required or a new test should be added, the user only
selects the function from the lists of provided functions and change the required data. There is also an option for
autofill of certain fields provided in the web interface such as: today’s date, user name, project name, function auto
increase number, test status, etc.</p>
      <p>The details about the required data for successful generation of all quality documents (listed above) is given in the
data model, described in the next Section. The benefits of using cloud solution for our quality assurance system is
described in the Section 5.</p>
    </sec>
    <sec id="sec-4">
      <title>4. SYSTEM DATA MODEL</title>
      <p>The data model of our pharmaceutical software quality assurance system is shown in Fig. 2. Each user has an
opportunity to access multiple projects that is authorized for. Projects must have at least one user. A project is composed of
many functions which are divided into subfunctions. The entity "Document" is intended for storing the each generated
document specified in GAMP 5, as listed in Section 3.</p>
      <p>The risk assessment form can be generated by using the "RiskAssesment" entity where each row represents one
row from the risk assessment document. Each row of the "RiskAssessment" entity is aimed for a specific system
subfunction. A given subfucntion can have multiple risk assessment row records.</p>
      <p>The entity "SourceCodeReview" is designed for the creation of the Source Code Review Report document.
Similarly, each row from this entity represents a row in the Source Code Review Report and it is dedicated to a specific
system subfucntion.</p>
      <p>Test Results Sheet is created for a system subfunction by using the entity "Test" and for each test a new document is
generated. A Test Incident Sheet must be connected to the specific test. There might be more test incidents for a given
test.</p>
      <p>Change Request is a document for proposing project changes. Each change request can have multiple change notes
as shown in our data model. The "ChangeRequest" and "ChangeNote" entities are used for this purpose.</p>
      <p>The system backup is documented in the Data Backup document. In our data model this entity is named "DataBackup".
A new document is created for each performed system backup. Data Restoration Form is aimed to be generated from
data stored in one row in the "DataRestoration" entity table.</p>
      <p>Monitoring Plan Form is consisted of records for different Monitored Parameters. These data are stored in the
"MonitoredParameter" entity table. Each row of this table represents a data row in the document.</p>
      <p>The Test Progress Sheet, Change Request Index, all forms to assist with document management (Document
Circulation Register, Document History, Master Document Index, Review Report, Review Summary), Traceability Matrix
Form, forms to support validation reporting are summary documents and they are generated with querying the data
model by joining the required entity tables.</p>
    </sec>
    <sec id="sec-5">
      <title>5. PROS AND CONS OF THE SYSTEM IMPLEMENTATION</title>
      <p>The proposed quality assurance system has both advantages and disadvantages. It can be beneficial in terms of:
—Centralized solution accessible from everywhere;
—Automatic generation of quality assurance documents;
—Records for functions and subfunctions are used in multiple document creation;
—Summary reports are generated from the existing data, no need to insert additional data;</p>
      <sec id="sec-5-1">
        <title>MonitoredParameter</title>
        <p>PK mpID
warningLimit
frequencyObservation
monitoringTool
notificationMechanism
resultsLocation
retentionPeriod</p>
      </sec>
      <sec id="sec-5-2">
        <title>DataRestoration</title>
        <p>PK drID
files
reason
1
M
1
1 M</p>
      </sec>
      <sec id="sec-5-3">
        <title>ChangeNote</title>
        <p>PK cnID
details</p>
        <p>M
1
1
1</p>
      </sec>
      <sec id="sec-5-4">
        <title>DataBackup</title>
        <p>PK dbID
type
interval
behaviorIfFailure
remarks
backupMedia
storage
backupTool
call
—Name unification of system components (functions, subfunctions);
—Easy accessible interface;
—Allowing parallel data insertion;
—Reduced number of errors in documents;
—Cloud provides elasticity, scalability and multi-tenancy;
—Only pay for the options you want in the Cloud;
—Cloud provides easy backup of the data at regular intervals, minimizing the data loss;
—No need of an investment in hardware and infrastructure.</p>
        <p>As a main possible disadvantage is the Internet connection factor. We cannot rely on an Internet connection to
access the data if Internet goes down on user side or on the cloud provider’s side. Also, the users do not have
physical control over the servers.
6.</p>
      </sec>
    </sec>
    <sec id="sec-6">
      <title>CONCLUSION</title>
      <p>In this paper we propose an architecture and data model for pharmaceutical software quality assurance system hosted
on the Cloud. We made a brief review of the existing guidelines and standards for developing quality software in
pharmaceutical industry. The proposed architecture shows the easy system accessibility from any electronic device
connected to Internet. We also provide data model showing the organization and structure of the data used in the
system. There are many advantages for developing such a system and we describe each of them. In the future, we plan
to implement and use this system in practice and to found any inconsistencies that can be improved in the next system
versions.</p>
    </sec>
    <sec id="sec-7">
      <title>Acknowledgement</title>
      <p>This work is supported by the project Advanced Scientific Computing Infrastructure and Implementations, financed
by the Faculty of computer science and engineering, UKIM.</p>
    </sec>
  </body>
  <back>
    <ref-list>
      <ref id="ref1">
        <mixed-citation>
          2005.
          <article-title>IEEE Standard for Software Verification and Validation</article-title>
          . IEEE Std 1012
          <article-title>-2004 (Revision of IEEE Std 1012-</article-title>
          <year>1998</year>
          ) (
          <year>June 2005</year>
          ),
          <fpage>1</fpage>
          -
          <lpage>110</lpage>
          . DOI:http://dx.doi.org/10.1109/IEEESTD.
          <year>2005</year>
          .96278
        </mixed-citation>
      </ref>
      <ref id="ref2">
        <mixed-citation>
          <source>US FDA</source>
          .
          <year>2011</year>
          .
          <article-title>Guidance for Industry-Process Validation: General Principles and Practices</article-title>
          .
          <source>US Department of Health and Human Services</source>
          , Rockville,
          <string-name>
            <surname>MD</surname>
          </string-name>
          , USA
          <volume>1</volume>
          (
          <year>2011</year>
          ),
          <fpage>1</fpage>
          -
          <lpage>22</lpage>
          .
        </mixed-citation>
      </ref>
      <ref id="ref3">
        <mixed-citation>
          <string-name>
            <surname>Food</surname>
            ,
            <given-names>Drug</given-names>
          </string-name>
          <string-name>
            <surname>Administration</surname>
          </string-name>
          , and others.
          <source>1985</source>
          .
          <article-title>Guideline on general principles of process validation</article-title>
          .
          <source>Scrip Bookshop.</source>
        </mixed-citation>
      </ref>
      <ref id="ref4">
        <mixed-citation>
          <string-name>
            <surname>Food</surname>
            and
            <given-names>Drug</given-names>
          </string-name>
          <string-name>
            <surname>Administration</surname>
          </string-name>
          and others.
          <source>1996. Code of Federal Regulations Title 21 Part 820 Quality System Regulation. Federal Register</source>
          <volume>61</volume>
          ,
          <issue>195</issue>
          (
          <year>1996</year>
          ).
        </mixed-citation>
      </ref>
      <ref id="ref5">
        <mixed-citation>
          <string-name>
            <given-names>R</given-names>
            <surname>GAMP.</surname>
          </string-name>
          <article-title>5</article-title>
          .
          <string-name>
            <given-names>Good</given-names>
            <surname>Automated Manufacturing Practice (GAMP R)</surname>
          </string-name>
          <article-title>Guide for a Risk-Based Approach to Compliant GxP Computerized Systems</article-title>
          , 5th edn (
          <year>2008</year>
          ),
          <article-title>International Society for Pharmaceutical Engineering (ISPE), Tampa</article-title>
          , FL.
          <source>Technical Report. ISBN 1-931879-61-3</source>
          , www. ispe. org.
        </mixed-citation>
      </ref>
      <ref id="ref6">
        <mixed-citation>
          <source>PDA Committee on Validation of Computer-Related Systems. 1995. PDA Technical Report No.18</source>
          ,
          <string-name>
            <surname>Validation of</surname>
          </string-name>
          Computer-Related
          <string-name>
            <surname>Systems</surname>
          </string-name>
          .
          <source>J. of Pharmaceutical Science and Technology</source>
          <volume>1</volume>
          (
          <year>1995</year>
          ).
        </mixed-citation>
      </ref>
      <ref id="ref7">
        <mixed-citation>
          <string-name>
            <given-names>K</given-names>
            <surname>Simmons</surname>
          </string-name>
          ,
          <string-name>
            <given-names>C</given-names>
            <surname>Marsh</surname>
          </string-name>
          ,
          <string-name>
            <given-names>S</given-names>
            <surname>Wiejowski</surname>
          </string-name>
          , and
          <string-name>
            <given-names>L</given-names>
            <surname>Ashworth</surname>
          </string-name>
          .
          <year>2014</year>
          .
          <article-title>Assessment of Implementation Requirements for an Automated Quality Assurance Program for a Medical Information Customer Response Management System</article-title>
          .
          <source>J Health Med Informat</source>
          <volume>5</volume>
          ,
          <issue>149</issue>
          (
          <year>2014</year>
          ),
          <fpage>2</fpage>
          .
        </mixed-citation>
      </ref>
      <ref id="ref8">
        <mixed-citation>
          <string-name>
            <given-names>US</given-names>
            <surname>Food</surname>
          </string-name>
          and
          <article-title>Drug Administration and others</article-title>
          .
          <source>2002</source>
          .
          <article-title>Guidance for Industry, General Principles of Software Validation</article-title>
          .
          <article-title>Center for Devices and Radiological Health (</article-title>
          <year>2002</year>
          ).
        </mixed-citation>
      </ref>
      <ref id="ref9">
        <mixed-citation>
          <string-name>
            <given-names>US</given-names>
            <surname>Food</surname>
          </string-name>
          and
          <article-title>Drug Administration and others</article-title>
          .
          <source>2012</source>
          .
          <article-title>Code of federal regulations title 21: part 11âA˘Tˇelectronic records; electronic signatures</article-title>
          . (
          <year>2012</year>
          ).
        </mixed-citation>
      </ref>
      <ref id="ref10">
        <mixed-citation>
          <string-name>
            <given-names>Guy</given-names>
            <surname>Wingate</surname>
          </string-name>
          .
          <year>2016</year>
          .
          <article-title>Pharmaceutical Computer Systems Validation: Quality Assurance, Risk Management and Regulatory Compliance</article-title>
          . CRC Press.
        </mixed-citation>
      </ref>
    </ref-list>
  </back>
</article>