Industries / Pharma

Software for regulated pharma environments

Manufacturing systems under GMP. Clinical systems under GCP. Laboratory systems under GLP. Each has its own validation, change control and record retention requirements. At the same time, pharma teams are dealing with large research and clinical datasets and looking at ways to use AI without changing how those systems are controlled.

The environment

GMP, GCP and GLP across the same organisation

Manufacturing runs under GMP, clinical systems under GCP, and laboratory systems under GLP. In practice, a pharma company may be running all three across systems of very different ages. Those systems were usually built at different times, for different purposes, and still have to work together.

The records matter too. Plans, specifications, executed test scripts, summary reports, change control records and periodic reviews have to remain retained, retrievable and intact, often after the system that created them has been replaced. Where electronic records and signatures are involved, 21 CFR Part 11 applies to the system that stores them as well.

Research results, trial data, internal reports and laboratory output keep growing. Much of it sits in formats that were not designed for easy search or analysis. Teams want to use AI on that material, but the data still has to be handled within the controls around it.

Automated liquid handling in a pharmaceutical laboratory
LABORATORY AUTOMATION UNDER GLP
Where teams run into trouble

Validation as a bottleneck

Some systems took a year to validate and are still difficult to change. The common approach has been to make change expensive so the validated state stays intact. That stops working when the business needs a change. Release cycles stretch and the cost moves elsewhere. We put the testing and evidence into the delivery process, so each change comes with its own record. The test suite runs with the build, the result is tied to the version and requirement, and the evidence is there when the release is reviewed. GAMP 5 and the FDA's Computer Software Assurance guidance both support a risk based approach, with more effort spent on functions where a failure would matter.

Research data that is hard to use

The information a team needs is often already somewhere in the company, but spread across documents and systems. The first issue is finding it and making sure the person asking is allowed to see it. A retrieval layer can search the company's own documents and send the relevant passages to the model instead of putting the entire corpus into a prompt. Access control stays with the documents, so the answer is based only on material that reader is allowed to access.

Data platforms that have to be compliant everywhere

Cloud infrastructure has to respect the privacy and residency rules attached to the data, and still be usable by the teams working with it. That includes encryption in transit and at rest, including backups and logs, least privilege for people and services, network segmentation, and audit trails that can be followed later. Where data has to stay in a country or inside a building, the platform has to run there as well. That changes the design compared with a standard managed cloud deployment.

Genomics in regulated development

Biomarker driven trials and companion diagnostics move bioinformatics closer to regulated software. A pipeline that was acceptable for internal research has to produce the same result later, on different infrastructure, with the inputs and versions recorded. Tool versions are pinned in containers, stages define their inputs and outputs, reference samples are replayed after changes, and the raw inputs are kept so an output can be traced back to the file that produced it.

A gloved hand holding a microplate in a laboratory
REGULATED SYSTEMS IN THE LAB
Work we do
Validation and release testing

Test automation that records verification evidence, traceability from requirement to test to result, and a release process that does not turn every change into a full revalidation. Regression gives the best return because the same checks run on every release. Exploratory testing and user acceptance still need people, and the test strategy makes that distinction clear.

Platforms that hold regulated data

Cloud environments built around the controls the data requires, pipelines that bring laboratory and clinical data together, and the same platform running on premises or inside a closed network when the data cannot leave.

Document retrieval in practice

A retrieval layer over the organisation's own documents, deployed inside the client's environment rather than as a shared service, with access control applied at the document level.

Reproducible genomics

Pipelines with pinned versions, defined inputs and outputs, and reference samples replayed as the software changes, with validation running alongside the build.

Migration of regulated records

When validation documents have to move between systems, the migration is planned as a controlled activity. That includes field by field mapping, verification of what arrived against what left, and a report covering the result and any deviations.

WHAT APPLIES HERE
GMPGCPGLPGAMP 5Computer Software Assurance21 CFR Part 11ALCOA plus
How we get involved

We get involved at different points. A system may be heading into validation and the team wants the evidence produced during development. An existing validated system may have documentation that no longer matches what is running. In other cases, the first job is to bring data together and make it queryable.

Questions people ask

Can validation keep up with a modern release cycle?

Yes. The evidence needs to come out of the delivery process instead of being recreated later. The test suite runs with each change and the results stay linked to the requirement and version. Formal scripted testing can then focus on the higher risk functions.

Can we use AI on our research archive without a compliance problem?

The way the system is put together determines how this works. Retrieval limits what reaches the model, document level access control limits what each person can see, and the system can run inside your own environment.

Does a research pipeline have to be validated?

Not while it remains a research tool. Once it supports a regulated decision, a biomarker driven trial or a companion diagnostic, the pipeline needs the reproducibility and supporting evidence expected in that setting.

Working on a system that has to stay validated?

Tell us what the system does, what it has to satisfy, and where it is today.

Start a conversation