コンテンツへスキップ

GxP: An Introduction

Fundamentals and Practice of Pharmaceutical Regulation

Good Practice Standards — A Comprehensive Guide

June 2026

Introduction: What Is GxP?

0.1 Definition of GxP

GxP (Good x Practice) is an umbrella term for the body of regulatory standards established to ensure the quality, safety, and efficacy of products in life sciences industries such as pharmaceuticals, medical devices, food, and cosmetics. The “x” is replaced by the type of activity involved (Manufacturing, Laboratory, Clinical, etc.), and each forms an independent set of guidelines.

The ultimate goals of GxP are “Patient Safety” and “Product Quality Assurance.” These are required throughout the entire lifecycle of a pharmaceutical product, from manufacturing through the post-marketing phase. Because violations of GxP can result in product recalls, suspension of manufacturing, and criminal penalties, GxP compliance is a top priority for pharmaceutical companies.

GxP Type Full English Name Primary Scope Application
GMP Good Manufacturing Practice Manufacturing and quality control Manufacturing of active pharmaceutical ingredients, drug products, and medical devices
GLP Good Laboratory Practice Nonclinical studies (safety studies) Toxicology and pharmacology studies using animals
GCP Good Clinical Practice Clinical trials Human clinical trials and clinical research
GDP Good Distribution Practice Distribution, storage, and transport Pharmaceutical wholesale, logistics, and cold chain
GVP Good Vigilance Practice Post-marketing safety management Adverse event reporting and risk management
GRP Good Regulatory Practice Regulatory affairs Regulatory submissions and maintenance of approvals
GAMP Good Automated Manufacturing Practice Computerized systems Validation of IT systems such as SAP

0.2 Fundamental Principles Required by GxP

While each individual GxP guideline covers a different area of operations, there are fundamental principles common to all of them. The data integrity principle known as ALCOA+ is a representative example.

ALCOA+ — Data Quality Principles Underlying All of GxP

A Attributable: It must be possible to identify who did what and when

L Legible: Records must be readable and permanently recorded

C Contemporaneous: Records must be made at the time the activity occurs

O Original: The first record (not a transcription or summary)

A Accurate: The record accurately reflects what was actually done

+C Complete: All records are present in full

+C Consistent: The record-keeping system is free of contradictions

+E Enduring: Records can be preserved and referenced over the long term

+A Available: Records can be accessed when needed

Computerized systems operating in a GxP environment

must be designed to satisfy this principle as a system function.

Chapter 1: GMP — Good Manufacturing Practice

1.1 What Is GMP?

GMP (Good Manufacturing Practice) is a standard for ensuring that pharmaceuticals are consistently manufactured to meet defined quality specifications. GMP is founded on the philosophy that “product quality is built into the manufacturing process” (Quality is Built In), and it covers manufacturing facilities, raw materials, manufacturing procedures, testing, documentation, and training and education.

Pharmaceutical companies that fail to meet GMP requirements face regulatory measures such as suspension of manufacturing licenses, product recalls, and import bans. Since 2022, GMP inspections by the FDA, EMA, and PMDA have expanded across the entire supply chain, including API manufacturers and contract manufacturers, increasing the difficulty of GMP compliance for globally operating companies.

1.2 Major GMP Regulations and Guidelines

Regulation / Guideline Issuing Body Region of Application Primary Scope
21 CFR Part 210/211 FDA (U.S. Food and Drug Administration) United States Manufacturing and control standards for pharmaceuticals
21 CFR Part 820 FDA United States QMS (Quality Management System) for medical devices
EU GMP Guidelines (Vol. 4) EMA (European Medicines Agency) EU / Europe Pharmaceutical GMP; the Annexes contain detailed requirements
ICH Q7 ICH (International Council for Harmonisation) Global GMP for active pharmaceutical ingredients (APIs)
ICH Q10 ICH Global Pharmaceutical Quality System (PQS)
WHO GMP WHO (World Health Organization) Primarily developing countries Basic GMP requirements
Act on Pharmaceuticals and Medical Devices / Ministerial Ordinances Ministry of Health, Labour and Welfare Japan Manufacturing control and quality control standards for pharmaceuticals, etc.
PIC/S GMP PIC/S 50+ countries Internationally harmonized GMP standards

1.3 Key GMP Management Requirements

① Document Control

Under GMP, all manufacturing and quality activities are managed according to the principle “if it’s not written down, it didn’t happen.” Manufacturing instructions, quality specifications, test records, deviation reports, and change control records are the principal controlled documents, each subject to requirements for version control, approval, and retention period.

② Deviation Management

All deviations from GMP (unplanned events) must be recorded, investigated, and addressed with corrective and preventive action (CAPA). Response requirements depend on the severity of the deviation (major or minor), and major deviations may trigger an obligation to report to regulatory authorities.

③ Change Control

Changes to manufacturing processes, equipment, test methods, raw materials, and the like must go through a process of prior evaluation, approval, and post-implementation verification. The impact of a change on regulatory filings (e.g., major or minor variation) must also be assessed.

④ Calibration & Validation

Equipment, facilities, processes, and computerized systems used in manufacturing and testing require qualification or validation. This is one of the legal bases for CSV (Computerized System Validation).

⑤ Training

Everyone engaged in GMP-related work must receive training appropriate to their duties, and that training must be documented. Training records serve as important evidence during inspections.

GMP Management Requirement Content Representative Regulatory Reference
Quality system Organization, accountability structure, QMS (Quality Management System) ICH Q10 / EU GMP Part I Ch. 1
Personnel Requirements for GMP personnel, the Quality Assurance head, and the Manufacturing Control head 21 CFR 211.68 / Enforcement Regulations of the Act on Pharmaceuticals and Medical Devices
Premises and equipment Design, cleanliness, and maintenance of manufacturing and testing areas 21 CFR 211.42-68
Manufacturing control Manufacturing instructions, process control, labeling, and packaging 21 CFR 211.100-188
Quality control Testing, specifications, stability, and retention samples 21 CFR 211.160-194
Document control Creation, retention, revision, and disposal of records EU GMP Annex 11 / 21 CFR 211.68
Deviations and CAPA Recording deviations, investigating causes, and implementing corrective actions ICH Q10 Section 3.2
Change control Evaluation, approval, implementation, and notification of changes ICH Q10 Section 3.1 / 21 CFR 314.70
Outsourcing management Management of CMOs and contract testing laboratories; quality agreements EU GMP Chapter 7
Annual Product Review (APR/PQR) Annual product quality review ICH Q10 / 21 CFR 211.180(e)

Chapter 2: GLP — Good Laboratory Practice

2.1 What Is GLP?

GLP (Good Laboratory Practice) is a standard ensuring that nonclinical studies evaluating the safety of pharmaceuticals, agrochemicals, and other chemicals (toxicology and pharmacology studies using animals, etc.) are planned, conducted, recorded, and reported in a reliable manner. The purpose of GLP is the “reliability of study results,” and it is a prerequisite for regulatory authorities to accept safety data as part of a submission.

Whereas GMP assures the quality of a product, GLP assures the reliability of safety data (study data). Only data generated in a GLP-compliant test facility is internationally recognized as valid safety evidence in pharmaceutical approval applications.

GLP Requirement Content
Test facility organization A clear accountability structure with facility management, a Study Director (SD), and a Quality Assurance Unit (QAU)
Standard Operating Procedures (SOPs) All study procedures are documented and approved as SOPs
Study protocol Study design, methods, and evaluation criteria documented before the study begins
Test substance control Characterization, storage, and handling records for test and reference substances
Test system management Records of the acquisition, husbandry, observation, and treatment of test systems such as animals and cells
Raw data management Original records and archiving of all observations and measurements
Quality assurance audits Study audits and facility audits conducted and recorded by the QAU
Study report Complete reporting of study results, signed by the Study Director
Differences Between GLP-Compliant and Non-Compliant Test Facilities

GLP-compliant facilities:

・Facilities confirmed to meet the GLP standards established by regulatory authorities (FDA, OECD, PMDA, etc.)

・Study data generated at such facilities can be used in regulatory submissions

 as data whose reliability has been confirmed

・Facility compliance is confirmed through periodic regulatory inspection or external audit

Non-GLP studies:

・GLP compliance may not be required for exploratory research, early-stage screening,

 and other studies not intended for use in regulatory submissions

・However, careful judgment is required to determine which studies are subject to GLP

・Mistakenly using non-GLP study data in a submission constitutes a regulatory violation

Chapter 3: GCP — Good Clinical Practice

3.1 What Is GCP?

GCP (Good Clinical Practice) is an international standard governing the design, conduct, monitoring, auditing, recording, analysis, and reporting of clinical trials involving human subjects. The fundamental purpose of GCP is to achieve both the “protection of the rights, safety, and welfare of trial subjects” and the “assurance of the reliability of clinical trial data.”

ICH E6(R2) (revised in 2016) is the leading international GCP standard, and in Japan it has been codified as the “Ministerial Ordinance on Standards for the Conduct of Clinical Trials of Pharmaceuticals” (the GCP Ordinance). In 2023, a draft of ICH E6(R3) was published, strengthening its support for risk-based approaches and decentralized clinical trials (DCTs).

Key GCP Requirements Description
IRB/EC approval Approval by an Institutional Review Board (IRB) or ethics committee is required before a trial begins
Informed Consent (IC) Adequate explanation to subjects and freely given consent; must be recorded and retained
Clinical trial protocol The trial’s objectives, design, methodology, and statistical analysis plan are documented in advance
Principal Investigator (PI) requirements A physician with appropriate qualifications, experience, and facilities must lead and oversee the trial
Monitoring A CRA (Clinical Research Associate) engaged by the sponsor periodically confirms the proper conduct of the trial
Electronic Case Report Forms (eCRF) Requirements applicable when electronic systems are used to collect and manage subject data
Serious Adverse Event (SAE) reporting Obligation to report SAEs to regulatory authorities and the IRB within a prescribed period
Raw data management Retention of source documents and access to data throughout the GCP retention period

3.2 Risk-Based Monitoring (RBM) and DCT

Since ICH E6(R2), there has been a shift away from traditional monitoring that confirms every case and every data field through on-site visits, toward “risk-based monitoring (RBM)” that prioritizes based on risk. By focusing on high-risk data items and combining this with central monitoring (remote data review), both efficiency and quality can be improved simultaneously. In addition, the spread of decentralized clinical trials (DCTs) has made it possible for subjects to participate in trials from home and for data to be collected via wearable devices, making GCP’s adaptation to digital tools an important theme.

Chapter 4: GDP — Good Distribution Practice

4.1 What Is GDP?

GDP (Good Distribution Practice) is a standard for ensuring that pharmaceutical quality is maintained throughout the distribution, storage, and transport processes as products move from manufacturer to patient. The EU GDP Guidelines (revised in 2013) serve as the leading international reference, and in Japan GDP has been introduced as the “Guideline on Proper Distribution of Pharmaceuticals (GDP)” (Ministry of Health, Labour and Welfare, 2018).

The importance of GDP has increased significantly in recent years, driven by the growth of products requiring cold chain management—such as biologics, cell therapy products, and mRNA vaccines—the increasing complexity of global supply chains, and the growing risk of counterfeit medicines entering distribution.

GDP Management Requirement Primary Content
Temperature control Continuous monitoring and recording of temperature and humidity that affect product quality; management of temperature excursions for refrigerated (2–8°C) and frozen (below -15°C) products
Transport management Validated transport means that minimize the effects of temperature, shock, and light exposure during transit
Warehouse management Design, cleaning, pest control, and access restriction of warehouses in accordance with GMP
Traceability Records of receipt, storage, and movement history at the batch level for pharmaceuticals
Prevention of counterfeit medicines Authentication of pharmaceuticals and serialization compliance (EU FMD; the Act on Pharmaceuticals and Medical Devices in Japan)
Outsourcing management Confirmation of GDP compliance for logistics contractors and 3PLs; conclusion of quality agreements
Quality Technical Agreement (QTA) An agreement documenting the division of GDP responsibilities between the manufacturer and the distributor

Chapter 5: GVP — Good Vigilance Practice

5.1 What Is GVP?

GVP (Good Vigilance Practice, or Good Pharmacovigilance Practice: GPvP) is a standard for collecting, evaluating, and managing safety information after a pharmaceutical is marketed, in order to minimize risk. In Japan, it is regulated under the “Act on Securing Quality, Efficacy and Safety of Pharmaceuticals, Medical Devices and Other Products” (the PMD Act) through the “Risk Management Plan (RMP)” and the “GVP Ministerial Ordinance.”

Not all safety information about a pharmaceutical is known at the time of approval. The core of GVP is to continuously monitor for adverse reactions, drug interactions, and risks to specific patient populations that only become apparent after marketing, and to take measures such as revising the package insert, alerting healthcare providers, or issuing a voluntary recall as necessary.

GVP Requirement Content Example Reporting Deadline
Adverse event reporting (ICSR) Collection, evaluation, and reporting to regulatory authorities of Individual Case Safety Reports Serious, unexpected adverse reactions: within 15 days; domestic reports: within 30 days
Periodic safety reports (PSUR/PBRER) Periodic evaluation and reporting of the safety benefit-risk balance Annually for the first year after approval, then every three years thereafter in the EU
Risk Management Plan (RMP) Monitoring and minimization measures for identified and potential risks Submitted at the time of the approval application and updated periodically
Signal detection and evaluation Early detection of safety signals through database analysis Ongoing monitoring
Package insert management Timely revision of the package insert based on safety information Promptly after new information is obtained

Chapter 6: National Regulatory Authorities and the GxP Framework

6.1 Comparison of the Three Major Regulatory Authorities (FDA, EMA, PMDA)

Item FDA (United States) EMA (Europe) PMDA (Japan)
Year established 1906 1995 2004
Primary role Regulation of pharmaceuticals, food, and medical devices Evaluation and monitoring of pharmaceuticals within the EU Review of approvals, safety measures, and GMP compliance inspections in Japan
GMP legal basis 21 CFR Part 210/211 EU Directive 2001/83/EC / GMP Vol. 4 Article 14-2 of the Act on Pharmaceuticals and Medical Devices / GMP Ministerial Ordinance
Inspection authority Direct on-site inspection of domestic and overseas facilities by FDA inspectors Inspection by the competent authority of each EU member state (EMA plays a coordinating role) On-site inspection by PMDA (of facilities within Japan and overseas contractors)
GCP 21 CFR Part 312; based on ICH E6 EU Clinical Trials Regulation; based on ICH E6 Act on Pharmaceuticals and Medical Devices / GCP Ministerial Ordinance; based on ICH E6
Electronic records 21 CFR Part 11 EU Annex 11 PMDA CSV Management Guideline
Notable features DSCSA (Drug Supply Chain Security Act); mandatory serialization EU FMD (Falsified Medicines Directive); revision of Annex 11 under consideration 2022 amendment to the Act on Pharmaceuticals and Medical Devices; introduction of GDP guideline

6.2 ICH and Global Regulatory Harmonization

ICH (International Council for Harmonisation of Technical Requirements for Pharmaceuticals for Human Use) is an organization in which regulatory authorities (FDA, EMA, PMDA, and others) and pharmaceutical industry associations participate to promote international harmonization of technical requirements relating to the quality, safety, and efficacy of pharmaceuticals. ICH guidelines function as a common standard for global regulatory submissions and are among the most important reference documents for GxP.

ICH Category Major Guidelines Content
Q Series (Quality) Q7: API GMP; Q8: Pharmaceutical Development; Q9: Quality Risk Management; Q10: Pharmaceutical Quality System Internationally harmonized standards for manufacturing and quality
S Series (Safety) S1–S9: Various toxicology study guidelines Standards for conducting nonclinical safety studies
E Series (Efficacy) E6(R2): GCP; E8: General Considerations for Clinical Trials; E14: QTc Prolongation Standards for clinical trials and efficacy evaluation
M Series (Multidisciplinary) M4: CTD (Common Technical Document); M7: Mutagenicity; M9: Biowaivers Technical requirements spanning multiple disciplines

Chapter 7: Organizational and Process Requirements for GxP Compliance

7.1 Quality Management System (QMS)

To maintain GxP compliance on an organizational level, it is necessary to build a Pharmaceutical Quality System (PQS) as defined by ICH Q10. A PQS is not merely document management; it is a management system that continuously improves quality across the entire product lifecycle.

QMS Element Relationship to GxP Requirements
Quality manual Documents the company-wide GxP policy, quality objectives, and organizational accountability structure
SOP management Lifecycle management of the creation, approval, revision, and retirement of SOPs for all GxP operations
Deviation and CAPA management Recording GMP deviations, GCP critical findings, etc., followed by root cause analysis and implementation of corrective and preventive actions
Change control Evaluation, approval, implementation, and effectiveness verification of all changes affecting manufacturing or quality
Product Quality Review (PQR/APR) Annual review of product quality status and continuous improvement
Self-inspection (internal audit) Periodic internal audits to self-verify GxP compliance status
Training management Planning, execution, recording, and effectiveness verification of training for GxP personnel
Complaint handling Recording and investigating market complaints, and determining whether a recall is necessary

7.2 Vendor Management and Supply Chain GxP

As global supply chains grow more complex, managing the GxP compliance of contract partners (CMOs, CROs, 3PLs) has become an important challenge for pharmaceutical companies. Even if a company itself satisfies GxP, if its contract partners do not, regulatory responsibility still falls on the outsourcing company.

The Three Pillars of GxP Management for Contract Partners

① Qualification / Audit

・Confirming GxP compliance through a document review or on-site audit before beginning a contract relationship

・Periodic reconfirmation (typically every two to three years)

・Additional confirmation when a significant change occurs

② Quality Technical Agreement (QTA)

・A documented agreement on the division of responsibilities for manufacturing, testing, and distribution

・Specifying obligations to comply with GxP requirements, to notify of deviations, and change control procedures

・A contract relationship without a QTA risks being judged a GMP violation

③ Ongoing monitoring

・Periodic review of the contract partner’s KPIs (number of deviations, CAPA completion rate, quality pass rate)

・Prompt information sharing and response when issues arise

・Annual review to assess whether the contract relationship should continue

Chapter 8: Digitalization and GxP — Application to Computerized Systems

8.1 Managing Computerized Systems in a GxP Environment

As pharmaceutical and life sciences companies advance digitalization, how GxP requirements are met by IT systems has become one of the most critical themes. Many systems—ERP (such as SAP), LIMS (Laboratory Information Management System), EDC (Electronic Data Capture), DMS (Document Management System), MES (Manufacturing Execution System), and others—operate within a GxP environment.

Major Systems Operating in a GxP Environment GxP Type Primary Regulatory Requirement
ERP (e.g., SAP S/4HANA) GMP, GDP GMP Ministerial Ordinance, 21 CFR Part 11; subject to CSV (Computerized System Validation)
LIMS (Laboratory Information Management System) GMP, GLP 21 CFR Part 11, OECD GLP; electronic records, electronic signatures, and audit trails are mandatory
EDC (Electronic Case Report Forms) GCP 21 CFR Part 11, ICH E6(R2); data integrity and protection of subject identity
DMS (Document Management System) All GxP Version control, approval workflow, retirement management; electronic management of SOPs
MES (Manufacturing Execution System) GMP Integration with manufacturing instructions, performance recording, electronic batch records
WMS (Warehouse Management System) GMP, GDP Temperature zone control, traceability, FEFO management
Regulatory submission support system GRP Preparation of the CTD (Common Technical Document); electronic submissions

8.2 Data Integrity and GxP

Since 2016, findings related to data integrity (DI) issued by the FDA, MHRA, and PMDA have increased sharply. Falsification, deletion, or overwriting of GxP records is a regulatory violation, and there have been cases resulting in suspension of manufacturing licenses, product recalls, and criminal prosecution. Issues such as “paper records that disappeared,” “computer configuration files that were overwritten,” and “audit trails that had been disabled” are frequently cited during inspections.

System Requirements for Ensuring Data Integrity

Functions required of computerized systems in a GxP environment:

1. Audit Trail

The system automatically records who did what, when, and to which data,

and users cannot delete or modify that record

2. Access Control

Permission management by user. Segregation of Duties is implemented,

separating “view only,” “input,” and “approval” permissions

3. Backup and Restore

Periodic backups and records of restore testing are required

4. Electronic Signature

Approval of GxP records must use an electronic signature on the system (compliant with 21 CFR Part 11)

A scanned image of a handwritten signature is not an electronic signature

5. Change Control

Configuration changes and program changes to the system must go through a change control process

Unapproved changes may constitute a GMP violation

8.3 GxP Considerations for Cloud and SaaS Migration

When cloud services such as SAP S/4HANA Cloud (RISE with SAP), Salesforce, and Microsoft Azure are used in a GxP environment, a management approach different from traditional on-premises systems is required. A validation strategy based on a “Shared Responsibility Model” is needed, one that clearly separates the scope of responsibility of the cloud provider (infrastructure, OS, middleware) from that of the pharmaceutical company (application configuration, data, processes).

Key Points for GxP-Compliant Cloud Adoption

① Cloud provider qualification (Supplier Qualification)

Confirm third-party certifications such as ISO 27001, SOC 2 Type II, and ISAE 3402

Confirm whether a compliance program tailored to pharmaceutical customers exists

(e.g., the AWS GxP whitepaper, Microsoft’s pharma compliance offerings)

② Documenting the boundary of responsibility (Responsibility Matrix)

The portion managed by the cloud vendor (Infrastructure Software: roughly GAMP Category 1)

The portion provided by the SaaS vendor (Configured Product: roughly GAMP Category 4)

The portion configured and managed by the pharmaceutical company (business processes and data)

Organize how these three layers are addressed in validation using a “responsibility allocation matrix”

③ Confirming data residency and data sovereignty

Which country’s servers store the GxP data

Whether regulatory authorities in each country can access the data when needed

④ Data retention at service termination or migration

Technical and contractual measures must be in place to guarantee GxP record retention periods

(for GMP, batch records must be retained for at least the product’s shelf life plus one year)

even after a cloud service is discontinued

End

Chapter 9: EU GMP Annex 1 (2022 Revision) — New Requirements for Sterile Manufacturing

9.1 Background and Significance of the Annex 1 Revision

EU GMP Annex 1, “Manufacture of Sterile Medicinal Products,” was comprehensively revised in August 2022, with full application beginning in August 2023. This is the first major revision since the original version in 1971, and it is one of the regulatory changes that has drawn the most attention from the pharmaceutical industry. At the heart of the revision is the introduction of the “Contamination Control Strategy (CCS)” and adaptation to modern sterile manufacturing technologies such as barrier systems and robotics.

Major Changes in the Annex 1 Revision Content Practical Impact
Mandatory Contamination Control Strategy (CCS) Preparation of a strategy document (CCS) that comprehensively manages contamination risk across the entire manufacturing plant is now mandatory Microbial, particulate, and foreign matter risks across the entire plant must be documented, and the effectiveness of control measures must be demonstrated
Clarification of cleanroom grades Environmental monitoring standards for Grades A/B/C/D have been detailed further; Grade A in particular corresponds to ISO 5 Environmental monitoring frequency and sampling points during manufacturing are now clearly specified; validation of the monitoring system is required
Recommendation of RABS and isolators Use of Restricted Access Barrier Systems (RABS) and isolators is now strongly recommended Relying solely on an open cleanroom to maintain Grade A control may become difficult going forward; capital investment should be considered
Strengthened bioburden control Requirements for controlling microbial contamination of raw materials, primary packaging materials, and manufacturing processes have been detailed further Microbial specifications required of suppliers and incoming testing and monitoring methods need to be reviewed
Media fill testing Detailed requirements for the design, frequency, and acceptance criteria of media fill tests are now specified At least annual execution, execution under worst-case conditions, and documentation of simulation conditions are required

9.2 Implementing a Contamination Control Strategy (CCS)

The CCS is a living document that identifies all contamination risks (microbial, particulate, foreign matter, and chemical contamination) at a manufacturing facility and defines the control measures for each risk. “Living document” means a document that is periodically reviewed and updated to reflect process changes, deviations, and environmental monitoring trends.

Key Elements to Include in a CCS

1. Facility and equipment design

Cleanroom layout, airflow design, differential pressure control, material selection

Design rationale and monitoring of the HVAC system

2. Personnel management

Entry and exit procedures for the cleanroom, gowning procedures, behavioral restrictions

Content, frequency, and qualification criteria for aseptic technique training

Personnel monitoring (microbial testing of gloves and garments)

3. Control of raw materials, containers, and closures

Incoming bioburden testing, decontamination processes, storage conditions

4. Control of manufacturing equipment and instruments

Cleaning and sterilization validation, microbial testing before and after use

5. Environmental monitoring program

Sampling points, frequency, sampling methods, acceptance criteria,

trend analysis, and action plans when limits are exceeded

6. Sterilization processes

Validation, monitoring, and periodic revalidation of autoclave, dry heat,

filter sterilization, and gamma irradiation processes

7. Process simulation (media fill testing)

Confirmation of aseptic technique proficiency for all operators and of the sterility of the manufacturing process

Chapter 10: ICH Q9(R1) — Implementing Quality Risk Management

10.1 Overview of ICH Q9(R1)

ICH Q9 (Quality Risk Management: QRM) was issued in 2005, and the R1 revision was published in 2023. At the heart of the R1 revision is the prevention of risk-based approaches becoming a mere formality. It is no longer sufficient to have a record stating “a risk assessment was performed”; evidence is now required that “the results of the assessment were actually used in decision-making.” QRM is expected to be applied in an integrated manner across all GxP activities (GMP, GCP, GLP, GDP, and CSV).

Major QRM Tools Overview Examples of Application in GxP
FMEA (Failure Mode and Effects Analysis) Identifies how each process or function could fail (failure mode) and calculates a Risk Priority Number (RPN) from Severity, Occurrence, and Detection Identification of critical process parameters in manufacturing; risk assessment for CSV validation; evaluation of the impact of changes after validation
HACCP (Hazard Analysis and Critical Control Points) A method for identifying and continuously monitoring critical control points (CCPs) in food safety and pharmaceutical manufacturing Identification of critical control points in sterile manufacturing; design of incoming inspection processes for raw materials; cold chain management
Fault Tree Analysis (FTA) A top-down method that logically traces back and comprehensively enumerates the causes of a specific “undesired event” (top event) Root cause analysis of major deviations; impact analysis in the event of system failure; basis for risk reports
Fishbone diagram (cause-and-effect diagram) A simple method for organizing the causes of a problem into the 6 Ms: Man, Machine, Method, Material, Measurement, and Environment Cause investigation when a deviation occurs; root cause analysis for CAPA
Risk ranking and filtering A method for scoring and prioritizing multiple risks; similar in concept to the RPN used in FMEA but more flexible Supplier risk assessment; determining priority for monitoring quality indicators

10.2 Integrating QRM and CSV

GAMP 5 Second Edition strengthens alignment with ICH Q9 and recommends that risk assessments in CSV be carried out within the QRM framework. In a system risk assessment using FMEA, each function’s failure mode (what could go wrong), impact (what is the effect on GxP), likelihood of occurrence, and detectability are evaluated, and the depth of validation is determined according to the resulting RPN score.

Example of an FMEA for CSV (SAP QM Module)

Function: Pass/fail determination of an inspection lot

Failure Mode ①: Incorrect specification setting

→ Impact: A nonconforming product could be judged as passing and shipped

→ Severity (S): 9 (direct impact on patient safety and product quality)

→ Occurrence (O): 3 (low if a double-check is performed at the time of setup)

→ Detection (D): 2 (detectable in UAT and confirmed through periodic review)

→ RPN: 9 × 3 × 2 = 54 ★ High risk → detailed OQ testing required

Failure Mode ②: Transcription error in test results (LIMS → SAP interface)

→ Impact: Test results are not correctly reflected in SAP, leading to an incorrect determination

→ Severity (S): 8

→ Occurrence (O): 4 (the interface is complex)

→ Detection (D): 3 (discrepancies are usually noticed quickly)

→ RPN: 8 × 4 × 3 = 96 ★ Highest risk → prioritize interface testing

RPN of 80 or higher: detailed test case creation and dedicated review

RPN of 40–79: standard OQ testing

RPN below 40: addressed by leveraging supplier test evidence

Chapter 11: Regulatory Inspections — Preparation, Response, and Remediation

11.1 Types and Characteristics of Inspections

To confirm the state of GxP compliance, regulatory authorities conduct inspections of manufacturing facilities, testing facilities, and clinical trial sites, either periodically or in connection with a submission. Responding to inspections is one of the most critical compliance activities for a pharmaceutical company. In well-run GxP organizations, there is a shared understanding that “an inspection is not something to fear” but rather “an opportunity to confirm that day-to-day GxP activities are being carried out properly.”

Inspection Type Conducting Body Trigger Primary Focus
Routine GMP inspection FDA, EMA member state authorities, PMDA Routine monitoring of manufacturing facilities (typically every 2–5 years) Manufacturing processes, quality control, document control, deviations, CAPA, and change control overall
Pre-Approval Inspection (PAI) FDA During review of a new drug approval application (NDA/BLA) Confirming that the submitted data is consistent with the actual manufacturing and testing performed
For-cause inspection Regulatory authorities Triggered by a product recall, major deviation, whistleblower complaint, etc. An in-depth investigation focused on a specific issue
GCP inspection FDA, EMA, PMDA At the time of a clinical trial application, before approval, or post-marketing Conduct of the trial, subject protection, and reliability of data
Overseas supplier inspection FDA (OAI/CFR inspections), EMA (overseas GMP inspections) Oversight of global supply facilities Direct on-site inspection by foreign authorities of manufacturing facilities in Japan and other parts of Asia

11.2 FDA Form 483 Observations and Warning Letters

The results of an FDA inspection are documented in “Form 483 Observations” and “Warning Letters.” Form 483 observations are “observed issues” presented verbally and in writing at the conclusion of the inspection; they are not a failing judgment but rather a request for improvement. A Warning Letter reflects a more serious situation, is issued as a public document, and can lead to measures such as an import ban.

Practical Response: Procedure for Responding to Form 483 Observations

【During the inspection】

・Answer the inspector’s questions accurately and concisely (do not volunteer extra information)

・If you cannot answer immediately, say “I will confirm and respond shortly”

・Accurately transcribe all records of the observations

・If an issue the inspector points out can be corrected during the inspection, address it immediately

 and report “This has been corrected” (this makes a significant difference in impression)

【After receiving Form 483 observations (a response within 15 business days is recommended)】

① Conduct a root cause analysis (CAPA) for each observation

② Provide a specific corrective action plan and target completion date

③ Attach evidence (records, photographs, etc.) of any corrections already made

④ Answer honestly as to “why this problem occurred”

 (an attitude of confronting the root cause directly, rather than making excuses, is essential)

【After receiving a Warning Letter】

⑤ A formal response (a public document) within 30 days

⑥ A comprehensive corrective action plan that includes commitment from senior leadership (e.g., the president)

⑦ Proposing independent verification by a third party (an external consultant) can be effective

Since 2015, Warning Letters and inspection findings related to data integrity (DI) issued by the FDA, MHRA, and PMDA have increased sharply. Findings are especially common at API manufacturing facilities in Asia, making this an important issue for supplier management by Japanese pharmaceutical companies as well.

Representative DI-Related Inspection Findings The Underlying Problem
Deletion or concealment of failed test data (known as “OOS concealment”) Deleting out-of-specification (OOS) test results and recording only the passing results from a retest → a major GMP violation; some cases have resulted in criminal prosecution
Unauthorized access to or modification of electronic raw data Insufficient user management in LIMS or HPLC control software, allowing anyone to modify raw data
Disabled audit trails The audit trail function is intentionally turned off, or is enabled but never reviewed
Backdoor accounts (shared accounts) Everyone uses the same password, making it impossible to identify “who” performed an action
Retroactive alteration of paper records The act of “rewriting” test records later to make them look clean; only the original is discarded and a scan is retained

Chapter 12: Recent Trends in GCP — Decentralized Clinical Trials and ICH E6(R3)

12.1 Overview of ICH E6(R3)

The final draft of ICH E6(R3) was published in 2023, and implementation is proceeding in various countries from 2024 through 2025. The main changes from R2 (2016) are the full adoption of a “Risk Proportionate Approach (RPA)” and support for “decentralized clinical trials (DCTs).” In R3, requirements for clinical trial data management, IT systems, and digital tools have been substantially expanded.

Major Changes in ICH E6(R3) Content
Risk Proportionate Approach (RPA) Formal adoption of an approach centered on central monitoring based on risk, rather than on-site monitoring of every case and every data field
Support for decentralized clinical trials (DCT) Provisions formally recognizing alternatives to in-person visits for subjects—such as home nursing visits, wearable devices, and remote consultations
Clarified requirements for digital tools Specific quality and validation requirements for ePRO (electronic Patient-Reported Outcomes), eCOA, and eConsent (electronic informed consent)
Alignment with CDISC standards Strengthened language recommending compliance with CDISC standard data models such as CDASH and SDTM
Clarified responsibilities of the sponsor and investigational site A more clearly defined division of responsibility for monitoring, auditing, and record management

12.2 CSV Requirements for Decentralized Clinical Trials (DCT)

In a DCT (Decentralized Clinical Trial), subjects participate in the trial from home or elsewhere rather than visiting a medical institution. Digital tools such as wearable devices, smartphone apps, and telemedicine are used, and all of these are systems subject to GCP and CSV. Even “an ePRO app installed on a subject’s smartphone” must be managed as a GxP system.

Chapter 13: A Closer Look at GDP — Temperature Mapping and Serialization

13.1 Temperature Control Validation (Temperature Mapping)

The storage and transport temperature of pharmaceuticals has a direct effect on product quality. For refrigerated products (2–8°C), room-temperature products (15–25°C), frozen products (below -20°C), and ultra-low-temperature products (below -70°C, such as mRNA vaccines), it must be demonstrated through validation (temperature mapping) that the temperature of storage facilities and transport containers is maintained within the specified range.

Temperature Mapping Requirements Content
Mapping targets Warehouses, cold rooms, freezers, and transport containers (validated shippers)
Sensor placement To confirm uniform temperature distribution, the space is divided into a grid, with sensors concentrated at points where the highest and lowest temperatures are expected
Test conditions Empty and full load conditions, door-opening conditions, power-failure simulation, and testing under extreme summer and winter ambient temperatures
Monitoring period A minimum of 72–96 continuous hours; conducted in both summer and winter to account for seasonal variation
Acceptance criteria All sensors must remain within the specified temperature range; evaluation of excursion duration and MKT under worst-case conditions
Periodic revalidation Typically every two to three years; also performed after any major facility change

13.2 Pharmaceutical Serialization (EU FMD and Japan’s PMD Act)

To prevent the distribution of counterfeit medicines, the assignment of serial numbers to individual packages (serialization) is mandatory. In the EU this is required under the FMD (Falsified Medicines Directive), and in Japan, following the 2021 amendment to the Act on Pharmaceuticals and Medical Devices, prescription drugs must carry a two-dimensional (DataMatrix) code on individual packaging along with authentication verification. A serialization system is a computerized system subject to GMP and therefore requires CSV.

Chapter 14: A Closer Look at GVP — Risk Management Plan (RMP) and PSUR

14.1 Structure of the Risk Management Plan (RMP)

The RMP (Risk Management Plan) is a comprehensive safety risk management plan submitted at the time of a pharmaceutical’s approval application and continuously updated after marketing. The EU RMP (based on ICH E2E) has a structure of Modules I through VII and functions as a roadmap for post-marketing safety activities.

Major RMP Modules Content
Module I: Product Overview Summary of the product’s indications, pharmacology, pharmacokinetics, and clinical profile
Module II: Safety Specification Definition of identified risks, potential risks, and missing information (important identified risks, important potential risks, and important missing information)
Module III: Pharmacovigilance Plan Plan covering routine pharmacovigilance activities (adverse event reporting, PSUR, etc.) and additional pharmacovigilance activities (registries, drug use surveys, etc.)
Module V: Risk Minimization Measures Routine measures (package insert, packaging) and additional measures (educational materials, restricted prescribing programs, etc.)

14.2 Periodic Safety Update Report (PSUR/PBRER)

The PSUR (Periodic Safety Update Report) / PBRER (Periodic Benefit-Risk Evaluation Report) is a document that periodically (every one to three years after approval) evaluates and reports on the post-marketing safety profile of a pharmaceutical. It is a report compliant with ICH E2C that consolidates worldwide safety information and evaluates the benefit-risk balance.

End

About the author — Shimizu (Healthcare & Life Sciences)

Specializes in GxP compliance for pharma and medical devices, supporting regulated system implementation and process design.

Have a question about this article?

Ask the author directly — no sales pitch, just an answer.

Ask about this article →