White Paper - Complying with Electronic Records and Electronic Signatures Regulations in the Life Sciences Industry
SAP for Life Sciences
Complying with electronic
records and electronic
signatures regulations in the
life sciences industry
Complying with electronic
records and electronic
signatures regulations in the
life sciences industry
2 | 54
Disclaimer
SAP SE’s compliance analysis with respect to SAP software performance based on U.S. FDA 21 CFR Part 11, EU Annex 11 to GMP
Guideline Commission Directive 2003/94/EC for Medicinal Products for human use and Directive 91/412/EEC for veterinary use,
Annex 11 to PIC/S Guide to Good Manufacturing Practice for Medicinal Products, as part of Guide to Good Manufacturing Practice
for Medicinal Products Annexes, ICH Q7A Guideline, and further mentioned international ERES regulations: (i) in no way expresses
the recognition, consent, or certification of SAP software by the United States Food and Drug Administration or European or other
international regulatory authorities; and (ii) applies to certain components of SAP S/4HANA and SAP S/4HANA Cloud, private edition
only as stated herein. The customer is solely responsible for compliance with all applicable regulations, and SAP SE and its affiliated
companies (“SAP Group”) have no liability or responsibility in this regard.
Table
of contents
8 Know the rules
11 ERES regulations and
SAP S/4HANA
28 SAP software quality
38 Why Choose SAP solutions
for ERES compliance
40 Appendixes
About the author
Dr. Christoph Roller is global life sciences
solution manager in the global industry
business unit for life sciences at SAP.
Disclaimer
SAP SE’s compliance analysis with respect to SAP software performance based on U.S. FDA 21 CFR Part 11, EU Annex 11 to GMP
Guideline Commission Directive 2003/94/EC for Medicinal Products for human use and Directive 91/412/EEC for veterinary use,
Annex 11 to PIC/S Guide to Good Manufacturing Practice for Medicinal Products, as part of Guide to Good Manufacturing Practice
for Medicinal Products Annexes, ICH Q7A Guideline, and further mentioned international ERES regulations: (i) in no way expresses
the recognition, consent, or certification of SAP software by the United States Food and Drug Administration or European or other
international regulatory authorities; and (ii) applies to certain components of SAP S/4HANA and SAP S/4HANA Cloud, private edition
only as stated herein. The customer is solely responsible for compliance with all applicable regulations, and SAP SE and its affiliated
companies (“SAP Group”) have no liability or responsibility in this regard.
Table
of contents
8 Know the rules
11 ERES regulations and
SAP S/4HANA
28 SAP software quality
38 Why Choose SAP solutions
for ERES compliance
40 Appendixes
About the author
Dr. Christoph Roller is global life sciences
solution manager in the global industry
business unit for life sciences at SAP.
3 | 54
By complying with global regulations, your
life sciences company can enjoy the
benefits of increased overall efficiency and
reduced costs for handling and storing
traditional paper records. No matter the
type of life sciences business you conduct,
there is even more that you can do. With
the SAP for Life Sciences solution portfolio,
you can comply with key electronic
signature regulations and limit the
costs involved in compliance.
3 | 54
By complying with global regulations, your
life sciences company can enjoy the
benefits of increased overall efficiency and
reduced costs for handling and storing
traditional paper records. No matter the
type of life sciences business you conduct,
there is even more that you can do. With
the SAP for Life Sciences solution portfolio,
you can comply with key electronic
signature regulations and limit the
costs involved in compliance.
3 | 54
4 | 54
Today’s approach to compliance
To compete in this market, your life sciences com-
pany needs to comply with various regulations
depending on which markets you do business in.
These regulations include those of the U.S. Food
and Drug Administration (FDA), such as 21 CFR Part
11 Electronic Records; Electronic Signatures; the
European Commission’s Annex 11 Computerized
Systems; and the International Conference on
Harmonization (ICH) guideline Q7A. Regulatory
authorities across the globe have acknowledged
the importance of computerized systems and
records within the life sciences industry. These
regulations all share the same intent of ensuring the
integrity and security of electronic data and records.
However, applying these requirements to the
numerous computerized systems within your life
sciences company can translate into millions of
dollars in project costs to validate these systems.
Also, maintaining these systems in a “validated
state” for their productive lifetime requires signifi-
cant annual costs.
Systems-based inspection approach
More and more, regulatory authorities globally
are taking a risk-based approach to determine
which computer systems are the most critical.
They then follow a systems-based approach that
aims at conducting and evaluating inspections
with regard to specific systems to evaluate risks.
For example, a global regulatory agency program
such as the FDA’s inspection compliance program
consists of six major systems, which are similar to
other agency inspection programs. They include:
• Quality system
• Facilities and equipment system
• Materials system
• Production system
• Packaging and labeling system
• Laboratory control system
These systems are not considered discrete enti-
ties but instead are part of an integrated system
model. The idea underlying this approach is that
deficiencies in one system will affect all other
systems. The integrated systems-based inspec-
tion approach recognizes the widespread use of
computers to support each company’s quality
initiatives. Therefore, regulatory agencies review
the qualification, validation, and security of
integrated computer solutions much more
closely than that of stand-alone systems during
inspection.
4 | 54
Today’s approach to compliance
To compete in this market, your life sciences com-
pany needs to comply with various regulations
depending on which markets you do business in.
These regulations include those of the U.S. Food
and Drug Administration (FDA), such as 21 CFR Part
11 Electronic Records; Electronic Signatures; the
European Commission’s Annex 11 Computerized
Systems; and the International Conference on
Harmonization (ICH) guideline Q7A. Regulatory
authorities across the globe have acknowledged
the importance of computerized systems and
records within the life sciences industry. These
regulations all share the same intent of ensuring the
integrity and security of electronic data and records.
However, applying these requirements to the
numerous computerized systems within your life
sciences company can translate into millions of
dollars in project costs to validate these systems.
Also, maintaining these systems in a “validated
state” for their productive lifetime requires signifi-
cant annual costs.
Systems-based inspection approach
More and more, regulatory authorities globally
are taking a risk-based approach to determine
which computer systems are the most critical.
They then follow a systems-based approach that
aims at conducting and evaluating inspections
with regard to specific systems to evaluate risks.
For example, a global regulatory agency program
such as the FDA’s inspection compliance program
consists of six major systems, which are similar to
other agency inspection programs. They include:
• Quality system
• Facilities and equipment system
• Materials system
• Production system
• Packaging and labeling system
• Laboratory control system
These systems are not considered discrete enti-
ties but instead are part of an integrated system
model. The idea underlying this approach is that
deficiencies in one system will affect all other
systems. The integrated systems-based inspec-
tion approach recognizes the widespread use of
computers to support each company’s quality
initiatives. Therefore, regulatory agencies review
the qualification, validation, and security of
integrated computer solutions much more
closely than that of stand-alone systems during
inspection.
4 | 54
Cost of compliance
Figures 1 and 2 illustrate the cost of compliance
and noncompliance.
On the basis of global regulations for electronic
records and electronic signatures, companies
that fail to establish adequate control of their
computerized systems face sanctions for any
other significant noncompliance of good
practices.
Figure 1 shows two opposing exponential
curves depicting the cost of noncompliance
and compliance. The cost of noncompliance
is determined to be a function of regulatory
agencies’ enforcement actions – including
warning letters, import detention, and consent
decree – and the time and resources required
to remediate regulatory bodies’ observations.
The cost of compliance is determined to be a
function of time and resources. The graph also
shows that the state of compliance is not
dichotomous. Rather, compliance is a state of
operation determined by a company’s inter-
pretation of pertinent global regulations and
the corporate culture applied to the various
business processes within the quality system.
The three levels of compliance are therefore
subjective, as depicted by the range for each
level.
Figure 2 illustrates the beneficial movement of
the cost of compliance curve manifested by
process optimization and other internal cost
reductions, including the consolidation of IT
systems. Therefore, companies can choose
to improve their level of compliance to
significantly reduce costs.
5 | 54
Figure 1: Model of compliance costs
Optimal
area to
balance
risk versus
benefit
NC$ > C$ C$ > NC$
Sum of both exponential
curves (total $)
Cost of noncompliance
(NC$)
Cost of compliance
(C$)
The goal is
to operate
in this area.
Compliance
CompliantNot compliant Overcompliant
Cost
Cost
Figure 2: Model of compliance costs reduced through process
optimization
NC$ > C$ C$ > NC$
Sum of both exponential
curves (total $)
Cost of noncompliance
(NC$)
Cost of compliance
(C$)
Compliance
CompliantNot compliant Overcompliant
Vigilance and maturity
to manifest this
beneficial movement
Maintenance of same
level of compliance
with reduced cost
Cost of compliance
curve enhanced
through process
optimization and
standardization
Figures 1 and 2 illustrate the cost of compliance
and noncompliance.
On the basis of global regulations for electronic
records and electronic signatures, companies
that fail to establish adequate control of their
computerized systems face sanctions for any
other significant noncompliance of good
practices.
Figure 1 shows two opposing exponential
curves depicting the cost of noncompliance
and compliance. The cost of noncompliance
is determined to be a function of regulatory
agencies’ enforcement actions – including
warning letters, import detention, and consent
decree – and the time and resources required
to remediate regulatory bodies’ observations.
The cost of compliance is determined to be a
function of time and resources. The graph also
shows that the state of compliance is not
dichotomous. Rather, compliance is a state of
operation determined by a company’s inter-
pretation of pertinent global regulations and
the corporate culture applied to the various
business processes within the quality system.
The three levels of compliance are therefore
subjective, as depicted by the range for each
level.
Figure 2 illustrates the beneficial movement of
the cost of compliance curve manifested by
process optimization and other internal cost
reductions, including the consolidation of IT
systems. Therefore, companies can choose
to improve their level of compliance to
significantly reduce costs.
5 | 54
Figure 1: Model of compliance costs
Optimal
area to
balance
risk versus
benefit
NC$ > C$ C$ > NC$
Sum of both exponential
curves (total $)
Cost of noncompliance
(NC$)
Cost of compliance
(C$)
The goal is
to operate
in this area.
Compliance
CompliantNot compliant Overcompliant
Cost
Cost
Figure 2: Model of compliance costs reduced through process
optimization
NC$ > C$ C$ > NC$
Sum of both exponential
curves (total $)
Cost of noncompliance
(NC$)
Cost of compliance
(C$)
Compliance
CompliantNot compliant Overcompliant
Vigilance and maturity
to manifest this
beneficial movement
Maintenance of same
level of compliance
with reduced cost
Cost of compliance
curve enhanced
through process
optimization and
standardization