GxP news - QFINITY
QFINITY · News · Insights & Events

What is driving the regulated quality of tomorrow.

Articles and analysis from our own work across GxP, pharma, quality management, GAMP and AI. They cover what is changing in the regulated environment, what it means in practice, and what is happening inside our company.

Latest articles

Events, case studies and insights.

IT-Qualitaetsmanagement und sichere Systemwiederherstellung - QFINITY

After a ransomware attack, a drug-discovery company had to recover GxP-relevant systems and data – fully documented. QFINITY guided the recovery from an IT quality management perspective: from forensically grounded quality planning through integrity-assured data migration to validated release.

Problem statement

The client is an international company in pharmaceutical active ingredient research. Its services include researching and developing new active ingredients and building software platforms for specialized methods in this environment. The company became the target of a ransomware attack that encrypted large parts of its infrastructure, systems, and data, making them inaccessible. Because some of these data and systems were GxP-relevant, the restoration of IT services and functions had to be closely overseen – and fully documented from an IT quality management perspective.

To achieve this objective, the client required:

  • Support in documenting and evaluating recovery activities for infrastructure, IT systems, and data
  • Coordination of activities with other departments, e.g. IT Security, Data Privacy, and IT Operations
  • Creation of quality reports for individual sub-areas of restored IT services and functionalities
  • Review and, if necessary, improvement of existing quality management processes to prevent future IT security risks

Project execution

At the start of the project, QFINITY recorded the recovery activities defined by the project team and evaluated their regulatory relevance. The results of the forensic analysis of the ransomware attack fed into this work, serving to review the effectiveness of existing quality management processes and optimize them where necessary. Based on this analysis, QFINITY developed a quality plan covering the following activities and areas:

  • Development of a procedural recovery framework by integrating forensic findings with the existing quality management framework
  • Restoration of a secure IT infrastructure by establishing a secure environment
  • Creation of regulatory documentation by fully documenting the restored IT infrastructure for compliance requirements
  • Reinstallation of IT systems as clean new installations to eliminate malicious code
  • Integrity-assured data migration through documented transfer of relevant data while maintaining consistency
  • Consolidation of data sets by synchronizing restored data with information newly generated since the attack
  • Comprehensive system validation through documented testing of restored systems and data prior to release
  • Timely quality reporting and release management for efficient approval of infrastructure and systems

Implementing this plan and the associated activities required intensive coordination with all departments to enable a fast, secure release of IT services and systems in full regulatory compliance.

In recovery, what matters is not speed but the complete traceability of every recovery activity.

Results and benefits

The project was completed successfully on schedule and within the planned budget because analysis, documentation, and release activities were appropriately scaled and efficiently coordinated. The restored IT systems and associated data fully meet all internal and regulatory requirements. Throughout the recovery, internal quality assurance continuously monitored the documentation in close coordination with the IT quality function, ensuring complete regulatory compliance and adherence to the highest internal quality standards. The resulting IT infrastructure meets the most stringent requirements for security, data integrity, and operational reliability.

Globales QMS-Konzept fuer Pharma - QFINITY

Grown through acquisitions, an international pharmaceutical company needed a harmonized global QMS. QFINITY designed and implemented it along GAMP 5 and ITIL – across infrastructure, software development, and computerized system validation – including a training concept and a worldwide rollout.

This case study focuses on the design and implementation of a global QMS concept for an international pharmaceutical company.

Problem Statement

The client is an international company in pharmaceutical active ingredient research. Its services range from researching and developing new pharmaceutical compounds to building software platforms for specialized methods in this domain.

After years of significant growth through acquisitions, the company needed to consolidate its various quality management approaches into a harmonized global Quality Management System (QMS).

To achieve this objective, the client required:

  • Development of a global QMS concept that integrates the requirements of existing QMS with relevant standards such as GAMP and ITIL while ensuring regulatory compliance
  • Evaluation of existing inconsistencies and development of appropriate solutions
  • Creation of policies, directives, SOPs, work instructions, and required templates for Infrastructure, Software Development, and Computerized System Validation, based on the developed QMS concept
  • Development of a training concept and training materials for the global QMS rollout
  • Execution of global QMS training sessions for relevant departments and stakeholders

Project Execution

In the initial phase, QFINITY analyzed the organization’s existing quality management systems and evaluated them against regulatory requirements and industry standards.

QFINITY then developed a new QMS concept covering the following areas:

  • Infrastructure
    • IT Risk Management
    • IT Asset and Inventory Management
    • Monitoring and Capacity Management
    • Data Centre / Server Room Management
    • Infrastructure Qualification
    • Backup and Restore Management
    • Change and Patch Management
    • Service Request Management
    • (Major) Incident Management
    • Problem Management
  • Software Development
    • Software Development Planning
    • Software Requirements and Risk Assessment
    • Software Design and Architecture
    • Software Development
    • Software Quality Assurance
    • Software Release and Maintenance
  • Computerized System Validation
    • Project Phase
      • Validation and Implementation of GxP-regulated systems
      • Implementation of non-regulated systems
    • Operational Phase
    • Retirement Phase
    • Data Migration
    • Data Archiving

As part of the implementation, QFINITY developed all necessary policies, directives, SOPs, work instructions, and document templates. It also created training materials for all relevant areas and planned and ran training sessions for the respective employee groups and departments.

A global QMS thrives not on the rule book but on a shared understanding of quality across every site.

Results and Benefits

The project was completed successfully on time and within the planned budget. Appropriately scaling the analysis, development, and rollout activities – and coordinating them efficiently – made this possible. Potential bottlenecks were identified early and avoided, keeping the overall project timeline on track.

The implemented global QMS significantly improved both efficiency and compliance. Globally harmonized processes and approaches ensured consistent compliance with regulatory requirements across the entire organization. Process efficiency increased substantially, and the company established a unified global understanding of quality.

The company’s internal quality assurance function reviewed the QMS approach and related documentation, and any inconsistencies identified were resolved promptly before rollout.

For more information about QFINITY’s case studies, check out our Project News.

Veranstaltungsbanner: ISPE EU Jahreskonferenz | 20-22. April 2026

Meet QFINITY on site at the ISPE EU Annual Conference 2026 in Copenhagen and learn how to bring digital compliance, AI, and GxP requirements together in a safe, future-proof, and practical way.

  • Event: ISPE EU Annual Conference 2026
  • Location: Copenhagen, Denmark, and virtual
  • Date: April 20-22, 2026
  • Organizer: International Society for Pharmaceutical Engineering
  • QFINITY Role: Program Team & Track Lead Digital Compliance

QFINITY’s Contribution to ISPE Europe 2026

The digital transformation of the pharmaceutical industry is progressing rapidly. Artificial intelligence, cloud technologies, and data-driven automation are now integral to GxP-critical processes. At the same time, regulatory requirements for data integrity, transparency, and patient safety remain uncompromising.

Oliver Herrmann, CEO of QFINITY, is a member of the event’s Program Team. He also serves as Track Lead for the Digital Compliance track, together with Josef Trapl and Niels de Blende. In this role, he is responsible for the track’s structure, technical depth, and overall content direction.

Content Focus: Digital Compliance

The Digital Compliance track addresses one central question:

How do you ensure lasting GxP compliance in AI-enabled, cloud-based, and continuously evolving system landscapes?

1. GxP Principles in the Age of AI

  • Risk-based application of GAMP principles to AI systems
  • Compliance-by-design for automation and cloud architectures
  • Clear accountability for automated decisions

2. From Document-Based to Data-Driven Validation

  • Digital, record-based validation approaches
  • Inspection-ready, data-centric evidence
  • Scalable Validation 4.0 models

3. Data Integrity, Trust, and Decision-Making

  • Practical data integrity concepts
  • Audit trail design and review in complex GxP landscapes
  • Traceable models for AI-supported review by exception

4. Next Generation Digital Compliance

  • End-to-end validation of AI systems
  • Intelligent agents and embedded compliance
  • Explainability as the foundation of regulatory trust

For more information about the event and to register for the ISPE EU Annual Conference, please visit the ISPE website.