investigator notification system - QFINITY
QFINITY · References · Case Study

Case Study: Investigator Notification System.

How we helped an international CRO build a bespoke solution for notifying investigators electronically - GxP-compliant, fully integrated and validated using a risk-based approach per GAMP 5.

The problem

Manual, error-prone - and no solution on the market.

Notifying investigators about safety-related issues such as SUSARs by hand, day after day, was resource-intensive and error-prone. With no commercial product on the market able to meet the requirements, a bespoke solution was the only way forward. The customer set out to achieve:

  • Robust, compliant processes for distributing safety information to investigators electronically
  • Process control through metrics and reports
  • Electronic signatures for key steps, such as investigators acknowledging receipt of the information
  • Integration of the solution into the customer's CTMS
  • Risk-based validation per GAMP 5 to meet international requirements
Project execution

From new processes to a validated solution.

We began by designing new data-entry and distribution processes that reflected pharmacovigilance and clinical-trial regulations alongside the customer's own expectations, then translated them into detailed requirements for development with an external partner. Throughout development and rollout, QFINITY's contribution centered on:

Supplier evaluation (audit) of the system development partner's QMS
Reviewing and reworking processes against ICH E6(R2), pharmacovigilance rules, 21 CFR Part 11 and GDPR
Risk-assessing the processes and system to keep the validation effort lean
Designing integrations that cut processing times and strengthened data integrity
System validation: requirements, strategy, IQ, configuration review (OQ) and UAT
Designing and validating reports and metrics in the CRO's BI platform
Result & benefit

A solution that makes compliance provable.

A key success factor was the close communication between the customer, the external development partner and the validation team. It made an end-to-end validation approach possible - one that ran from the business process all the way through to the development specifications.

Delivered successfully, with validation scaled appropriately to the risk
End-to-end approach spanning business process, user requirements and development specifications
Detailed compliance data and metrics to demonstrably meet the compliance expectations of customers and regulators
A first of its kind - thoroughly assessed and signed off with no major findings
Framing today.

The project ran under ICH E6(R2) and followed risk-based validation to GAMP 5 - the methodology that the QFINITY-co-authored ISPE GAMP eClinical Good Practice Guide (2nd edition, 2024) sets out for GCP-relevant systems. Under ICH E6(R3) and the EMA guideline on computerised systems, that is the framework we work in today.

Result

First of its kind - and assessed with no major findings.

An industry first, the bespoke solution was thoroughly assessed and released with no major findings - backed by solid compliance data for customers and regulators alike.

GCP 21 CFR Part 11 GDPR
More case studies

More from our project work.

Custom GxP systems, validated and inspection-ready.

You need a solution the market doesn't offer - from process design and supplier audit through to risk-based validation per GAMP 5. In a free intro call (about 30 minutes), we map out your requirements, the right validation depth, and the integration points your project needs.

Book an intro call