Questions and Answers on Cloud Computing in a GxP Environment – Part 5

   

GMP/GDP – On Demand Online Training

You can book the desired online training from our extensive database at any time. Click below for more information.

   

Stay informed with the GMP Newsletters from ECA

The ECA offers various free of charge GMP newsletters  for which you can subscribe to according to your needs.

The trend in the pharmaceutical industry is also moving towards cloud computing. Financial but also organizational advantages speak for the cloud. At the same time, however, potential dangers and regulatory restrictions should also be taken into account. Nine experts from the pharmaceutical industry and regulatory authorities answer a comprehensive catalog of questions from the following GxP-relevant topics:

  • Basics of Cloud Computing Technology
  • Regulations and Expectations of Inspectors
  • Customer-Supplier-Relationship
  • Requirements for Cloud Service Providers (CSP)
  • Requirements for Supplier Evaluation and Supplier Audits
  • Requirements for Qualifcation / Validation

The experts:
Frank Behnisch, CSL Behring GmbH, Marburg
Klaus Feuerhelm, Local GMP Inspectorate/Regierungspräsidium Tübingen
Oliver Herrmann, Q-FINITY Quality Management, Dillingen
Eberhard Kwiatkowski, PharmAdvantageIT GmbH, Neuschoo
Stefan Münch, Körber Pharma Consulting, Karlsruhe
Yves Samson, Kereon AG, Basel
Dr. Wolfgang Schumacher, formerly F. Hoffmann-La Roche AG, Basel
Dr. Arno Terhechte, Local GMP Inspectorate / Bezirksregierung Münster
Sieghard Wagner, Chemgineering Germany GmbH, Stuttgart

26. Requirements for qualification and validation
Can we operate without evidence for qualification of IT infrastructure for large CSP?

No. Regulations do not distinguish between "large" and "small" providers, between new and established companies, between cheap and costly offerings.

The statements in our answer to question 15 (GMP Journal Nᵒ 39) also apply to large CSPs. However: A robust and safe operation of all its cloud services and solutions is the core aspect of the CSP's business model. This is true for all CSPs but even more for large ones. Often, the regulated company can benefit from higher standards and more rigor (though it should not exercise blind faith!).

While performing a supplier assessment by an on-site audit is difficult to impossible (typically, the willingness to cooperate is reciprocally proportional to the company size), the risk is generally lower and many procedures (incl. results and deliverables) are often provided on demand or already published as white papers, certificates, or reports (e.g. Amazons "Whitepaper: Building a solid foundation for GxP-regulated workloads on AWS", Microsoft's SOC Reports or Microsoft's Compliance Reports).

Computerised System Validation: Legacy Systems + Maintaining Compliance during Operation - Live Online Training

Recommendation

29 September - 2 October 2026

Computerised System Validation: Legacy Systems + Maintaining Compliance during Operation - Live Online Training

27. Requirements for qualification and validation
How can CSPs achieve the Annex 11 requirement of qualified infrastructure, considering short product cycles? Which evidence / documentation is expected?

Annex 11 of July 2011, defining the EU GMP rules for computerised systems, does not mention "cloud computing" at all. However, it defines "IT Infrastructure" in its glossary and includes this fundamental and unambiguous statement in its introduction ("Principle"): "The application should be validated; IT infrastructure should be qualified."

On the other hand, GAMP® 5 Second Edition addresses the cloud as a (potential) component of IT infrastructure. For example, appendix M11 on IT Infrastructure starts the second paragraph with "A controlled IT infrastructure is a prerequisite for ensuring that GxP applications are managed in a state of control."

This applies to cloud services and solutions, too. However, while the regulated company is still accountable, some practical and operational elements are performed by the cloud service provider (CSP) - details depend on the type of service, e.g. IaaS, PaaS, or SaaS. It is important to note that basic requirements on IT security, backup and restore, change and configuration management etc. do not change, though they are often implemented differently ("Principles remain, practices change").

Therefore, CSPs should ensure installation and operation of a qualified infrastructure with often short release cycles by commensurate process models (e.g. agile and iterative changes, virtualisation, DevOps), a high degree of automation ("development pipeline"), and complementary QA controls. This includes risk assessments and implementation of safeguards and controls for protection and detection - measures that should be self-evident for CSPs with good IT practices.

As most components used for cloud computing are highly standardized, the risk for changing and extending the configuration is typically low and simple to control, and practices can easily be transferred to other projects ("Qualify once, implement several times"). Professional, high-class CSPs meet most requirements for a qualified IT infrastructure anyway by implementing IT standards, procedures, and guidelines (e.g. based on ITIL®), even when not specialized in or focusing on GxP.

Thus, the remaining challenge for regulated companies is to sign an agreement with a CSP ensuring adherence to these requirements and regulations, and to review and verify it following the identified risks. This can be achieved through various measures like a supplier assessment and signing individual agreements for operation, availability, monitoring etc. Information provided by the CSP - whether provided individually or published in public (e.g. white papers, certificates, or reports) - support this assessment that may be supplemented by a supplier audit.

28. Qualification/Validation requirements
Does a SaaS provider have to qualify the IT infrastructure used to provide services in the same way that a drug manufacturer or pharmaceutical company would have to?

Generally speaking, the requirements of the EU GMP guidelines and its annexes apply to the qualification of infrastructure in the GMP environment. Annex 11: The software should be validated and the IT infrastructure should be qualified. However, essential guidance can in particular be found in the AIM of EFG 11 (Aide-Mémoire of EFG 11 - supervision of computerised systems) and in Votum V1100202 - Requirements for the storage of electronic data. According to ZLG, a "Votum" is an opinion issued by an expert working group on a matter that is open to interpretation or requires clarification.

AIM of EFG 11: The qualification of IT infrastructure is a clearly stated requirement of Annex 11. Responsibility for this lies with the system owners (usually IT departments). Where cloud service providers (CSPs) or other service providers supply the infrastructure, this does not affect the requirement itself. Whether the CSP has qualified its infrastructure and whether the qualification process is described in its quality management system must be verified as part of the qualification of the service provider and the ongoing monitoring by the RU.*

The SaaS provider must therefore qualify its infrastructure in accordance with EU GMP Annex 11 and Annex 15.

29. Basic regulatory principles and expectations of inspectors
Do the authorities accept that using cloud services entails a loss of control compared with on-premises operations?

In their GMP inspections, the health authorities take the position that the so-called 'regulated user' (employee of the pharmaceutical industry) must not have any loss of control when using a cloud service. This statement applies to all services offered by service providers (IaaS, PaaS, SaaS) that are used in place of an on-premise infrastructure/platform/application in the controlled area. SaaS is viewed particularly critical in this context, as GxP data is hosted by the service provider in validated applications.

Inspectors expect pharmaceutical companies to regularly check and audit their various service providers. It is often noticed that the service provider has commissioned further subcontractors to provide services, which must of course also meet the requirements of the regulated industry. Many SaaS providers use infrastructure services from Amazon Web Service (AWS), Microsoft (Azure) or Google, which do not usually allow audits.

Computerised System Validation: Legacy Systems - Live Online Training

Recommendation

Tuesday, 29 September 2026 9 .00 - 17.30 h

Computerised System Validation: Legacy Systems - Live Online Training

30. Regulatory foundations and inspectors' expectations
Is it permissible - and if so, under what conditions is it possible - to store data physically outside the EU?

No references to the physical place of storage of electronic data can be found in EU-GMP. If one looks at the AMWHV, the following note appears:
Section 20 Storage of documentation
(1) All records relating to acquisition, manufacture including release, testing, storage, movement into or out of the scope of the Medicinal Products Act, import or export, placing on the market including distribution, as well as records on animal husbandry and records of the "Stufenplanbeauftragter" or the person appointed in accordance with Section 19 (7), first sentence, must be kept in full for at least one year after the expiry date, but for no less than five years. Storage must take place in a suitable area within the premises covered by the authorisation pursuant to Section 13, Section 72 or Section 72c (4) of the Medicinal Products Act.*

The second sentence now raises major problems with regard to the physical storage of electronic data. It must first be interpreted to mean that storage outside the company site is virtually impossible. This problem was recognised by EFG 11 and assessed in a Votum:

Votum V1100202 - Requirements for the storage of electronic data
According to ZLG, a "Votum" is an opinion issued by an expert working group on a matter that is open to interpretation or requires clarification.

The decisive point is the conclusion formulated by EFG 11. Section 3, "Conclusion", stating:
In the case of electronic documentation, the requirement for storage of e-records/documents in premises covered by the authorisation pursuant to Section 13, Section 72 or Section 72c (4) of the Medicinal Products Act is deemed to be fulfilled if at least one terminal device (e.g. terminal or PC together with printer) is available within the premises covered by the authorisation, such that access to the entirety of data and metadata is possible and legible printouts and copies on data media can be generated.

The Votum then also formulates further requirements for the external service provider (CSP). In particular, the following point must be observed: in principle, the same requirements apply to a CSP as to a regulated user.

However, no references are provided to the geographical or political situation of the external CSP. The question therefore remains to what extent the statement made by EFG 11 in the Votum also applies to locations outside the EU. Here, the AIM of EFG 11 (Aide-Mémoire of EFG 11 - supervision of computerised systems 07121202) provides further guidance. A key indication can be found there. In section 17, Archiving, the following question is posed:
17-7 Can data be archived at an establishment other than that of the authorisation holder?

EFG 11's answer is:
The data may, with the consent of the competent authority, be archived at an external facility within the EU. The GMP requirements in respect of service provider qualification, audits, etc. apply. The archived data must be capable of being made accessible to the competent authority within a reasonable period of time (see Votum V11002).*

31. Customer-supplier relationship
Is it acceptable for a service provider to refuse access to subcontractor documents (e.g. IaaS) on the justification that they are subject to confidentiality (specifically: training certificates)?

During an audit of a service provider, all information relating to the operation of an application in the regulated area must be disclosed. This includes the IT infrastructure, which is often operated in a subcontractor's data center. The staff of this company must, of course, also be made familiar with the applicable GMP rules (good documentation practice, data integrity, etc.) in training courses, as these employees also perform GxP services on behalf of the company.

It is therefore advisable to insist on interviewing some of the subcontractor's employees during the audit of the service provider and to request evidence of their training. There is generally no confidentiality obligation with regard to training certificates in the area of good manufacturing practice, as GxP training does not contain any confidential / personally sensible information. Such certificates do not belong to the category of personal data according to the General Data Protection Regulation (GDPR) in Europe.

Please also see parts 1-4 of the Q&As in previous issues of the GMP Journal.

 

About the Author
Dr Andreas Mangel organises and conducts courses and conferences for the ECA Academy in the areas of sterile production and computer validation.

*Unofficial translations by the editorial team

References
1 Amazon Whitepaper: https://aws.amazon.com/de/blogs/industries/whitepaper-building-a-solid-foundation-for-gxp-regulated-workloads-on-aws/
2 Microsoft SOC Report: https://servicetrust.microsoft.com/viewpage/SOC
3 Microsoft Compliance Reports: https://servicetrust.microsoft.com/Documents/ComplianceReports


 

Go back

To-Top
To-Bottom