Best Practices in Preparation for an FDA Computer System Audit

Carolyn Troiano Instructor:
Carolyn Troiano 
Tuesday, December 9, 2025
11:00 AM PST | 02:00 PM EST
90 Minutes
Webinar ID: 503326

More Trainings by this Expert

Price Details
Live Webinar
$149 One Attendee
$299 Corporate Live
Recorded Webinar
$199 One Attendee
$399 Corporate Recorded
Combo Offers
Live + Recorded
$299 $348 Live + Recorded
Corporate (Live + Recorded)
$599 $698 Corporate
(Live + Recorded)

Live: One Dial-in One Attendee

Corporate Live: Any number of participants

Recorded: Access recorded version, only for one participant unlimited viewing for 6 months ( Access information will be emailed 24 hours after the completion of live webinar)

Corporate Recorded: Access recorded version, Any number of participants unlimited viewing for 6 months ( Access information will be emailed 24 hours after the completion of live webinar)

Overview:

In particular, industry citations have increased as they relate to areas of Part 11 and data integrity.

At the heart of these, is the ability to ensure that no original record is obscured, or is destroyed before the retention period has ended. The best way to preserve database records, those that are uniformly structured, is to place an audit trail on the file. The audit trail will create a new record every time a record is updated, including the old value, new value, date, time, person who authentically performed the modification to the record, and the reason for the change.

Companies are not aligning well with the Part 11 and data integrity requirements, and while many use audit trails, these are not always managed appropriately. In some cases, FDA has found that the audit trail was deactivated for a period of time, but this was not documented, or it was modified or deleted. Without this protection, it’s virtually impossible to follow the life cycle for any record from creation to disposition at the end of the retention period.

In some cases, audit trails exist, but do not require the user to enter a reason for a change to a record. This is a challenge when trying to reconstruct what happened, and not having the reason brings into question the validity of the record.

Some legacy stand-alone systems that include software loaded onto a local device, instrument, or piece of equipment do not have audit trail capability. This is not a valid reason for ignoring Part 11 and data integrity requirements. If no technical control is available, such as an audit trail, then a procedural control must be in place. In the case of a stand-alone system, the user would have to maintain a log of all changes made, and this could be done using a bound laboratory notebook or log book, or using Excel or some other means of tracking this information.

Not only do these companies risk being out of compliance, but they are not able to perform analysis and trending on the records to identify the reason behind changes. If it's a consistent reason, it may be due to a training deficiency or have some other cause that should receive action.

We will explore the best practices and strategic approach for evaluating computer systems used in the conduct FDA-regulated activities and determining the level of potential risk, should they fail, on data integrity, process and product quality, and consumer/patient safety. We will walk through the System Development Life Cycle (SDLC) approach to validation, based on risk assessment, and will also discuss 21 CFR Part 11 and data integrity, and the importance of managing electronic records and signatures appropriately.

We will also walk through the entire set of essential policies and procedures, as well as other supporting documentation and activities that must be developed and followed to ensure compliance. We will provide an overview of practices to prepare for an FDA inspection, and will also touch on the importance of auditing vendors of computer system hardware, software, tools and utilities, and services.

Why should you Attend: FDA requires that all computer systems that handle data regulated by the Agency to be validated in accordance with their guidance on computerized systems. This guidance was first issued in 1983, and the main points of focus remain consistent today, despite the number of years that have passed and the technology changes that have taken place.

In 1997, the 21 CFR Part 11 Guidance was issued to address electronic records and signatures, as many FDA-regulated organizations began seeking ways to move into a paperless environment. This guidance has been clarified over the years to make it more palatable to industry, and this includes discretionary FDA enforcement measures. The intent was to avoid creating a huge regulatory compliance cost to industry that was initially preventing companies from embracing the technology.

Additional guidance was provided in late 2018 on Data Integrity to address an increasing trend in industry findings. We will cover best practices in industry to address these issues and ensure inspection readiness.

In September 2022, FDA issued a draft guidance for Computer Software Assurance (CSA), which unlike the document-driven CSV, or traditional approach to validation, is based on critical thinking and risk assessment. We will cover how CSA aligns with the most recent version of GAMP®5, 2nd Edition, published in July 2022, both of which include critical thinking and open the door to following one of many non-linear forms of software development, testing, and release, similar to agile. They also offer more streamlined approaches to validation and compliance.

We will talk about cloud-based services, Software-as-a-Service (SaaS) solutions, automated testing, and how to effectively and efficiently validate these types of systems and infrastructure, and how to perform a vendor audit remotely.

This session will provide some insight into current trends in compliance and enforcement. Some are based on technology changes, and these will continue to have an impact as new innovations and technology come into use in the industry. Again, we will help you position your company in a state of inspection readiness.

Areas Covered in the Session:

  • Learn how to identify "GxP" Systems
  • Discuss the Computer System Validation (CSV) approach based on FDA requirements
  • Understand Computer Software Assurance (CSA), the latest draft guidance from FDA on validation
  • Learn how CSA aligns with GAMP®5, 2nd Edition, both in using critical thinking and following simplified approaches for documenting validation activities
  • Learn about the System Development Life Cycle (SDLC) approach to validation
  • Learn about the importance of audit trails in assuring Part 11 and data integrity compliance
  • Discuss the best practices for documenting computer system validation efforts, including requirements, design, development, testing and operational maintenance procedures
  • Understand how to maintain a system in a validated state through the system's entire life cycle
  • Learn how to assure the integrity of data that supports GxP work
  • Discuss the importance of "GxP" documentation that complies with FDA requirements
  • Understand the rationale for including an audit trail in a system, along with the downside of not doing so
  • Understand how procedural controls may be used in place of technical controls, where the capability is lacking and not feasible
  • Learn about the policies and procedures needed to support your validation process and ongoing maintenance of your systems in a validated state
  • Understand the key components of 21 CFR Part 11 compliance for electronic records and signatures
  • Know the regulatory influences that lead to FDA’s current thinking at any given time
  • Understand the need to include an assessment of a computer system’s size, complexity, business criticality, GAMP®5 category and risk, should it fail, to develop a cohesive and comprehensive validation rationale
  • Learn how to best prepare for an FDA inspection or audit of a GxP computer system
  • Understand the importance of performing a thorough vendor audit to ensure oversight to the products and services they deliver
  • Finally, understand the industry best practices that will enable you to optimize your approach to validation and compliance, based on risk assessment, to ensure data integrity is maintained throughout the entire data life cycle
  • Q&A

Who Will Benefit:
  • Information Technology (IT) Analysts
  • IT Developers
  • IT Support Staff
  • IT Security Staff
  • QC/QA Managers and Analysts
  • Production Managers and Supervisors
  • Supply Chain Managers and Supervisors
  • Clinical Data Managers and Scientists
  • Compliance Managers and Auditors
  • Lab Managers and Analysts
  • Computer System Validation Specialists
  • GMP, GLP, GCP Training Specialists
  • Business Stakeholders using Computer Systems regulated by FDA
  • Regulatory Affairs Personnel
  • Consultants in the Life Sciences and Tobacco Industries
  • Interns working at the companies listed above
  • College students attending schools and studying computer system validation, regulatory affairs/matters (related to FDA) or any other discipline that involves adherence to FDA regulatory requirements


Speaker Profile
Carolyn (McKillop) Troiano has more than 35 years of experience in the tobacco, pharmaceutical, medical device and other FDA-regulated industries. She has worked directly, or on a consulting basis, for many of the larger pharmaceutical and tobacco companies in the US and Europe, developing and executing compliance strategies and programs. Carolyn is currently active in the Association of Information Technology Professionals (AITP), and Project Management Institute (PMI) chapters in the Richmond, VA area.

During her career, Carolyn worked directly, or on a consulting basis, for many of the larger pharmaceutical companies in the US and Europe. She developed validation programs and strategies back in the mid-1980s, when the first FDA guidebook was published on the subject, and collaborated with FDA and other industry representatives on 21 CFR Part 11, the FDA's electronic record/electronic signature regulation.


You Recently Viewed

Subscribe to our Newsletter

Subscribe for Compliance Alerts Research Reports Absolutely Free