GxP news - QFINITY
QFINITY · News · Insights & Events

Shaping the regulated quality of tomorrow.

Articles and analysis from our own work across GxP, pharma, quality management, GAMP and AI - what is changing in the regulated environment, what it means in practice, and what is happening inside our company.

Latest articles

Events, case studies and insights.

Live-Online-Training GxP Systems Digital Compliance - QFINITY

The live online training “GxP Systems & Digital Compliance Fundamentals” takes place on 8 May 2026. QFINITY CEO Oliver Herrmann will deliver the training together with Martin Heitmann. The focus is on AI compliance, GMP requirements, Annex 11, and the Annex 22 Draft. The session will also present practical approaches for using AI safely in regulated GxP environments.

Artificial intelligence is making its way into more and more GMP-relevant processes and systems. This creates new opportunities – and new requirements for validation, data integrity, governance, and inspection readiness. The training addresses exactly this interface. It covers fundamentals and current developments in computerized systems and digital compliance, along with the regulatory-compliant use of AI in the GMP environment.

Participants will get a structured overview of the current Annex 11 requirements. The session will also discuss the possible impact of the revised Annex 11 drafts and the new regulatory perspectives arising from the Annex 22 Draft, and will include the ISPE GAMP perspective on good practices for the quality of computerized systems. A particular focus is the effective, safe, and compliance-oriented use of AI in GxP environments.

Oliver Herrmann, CEO and Founder of QFINITY, and Martin Heitmann will deliver the training. Oliver Herrmann is an internationally recognized expert in validation, technology quality, data integrity, and system implementation. Martin Heitmann brings extensive expertise in GAMP AI and GxP compliance. Among other roles, he is Co-Lead of the ISPE GAMP Guide: Artificial Intelligence.

You can find further information about the training here. For more QFINITY events, see Meet QFINITY.

GxP-konforme Cloud-Nutzung - QFINITY

A CDMO wanted to use cloud services – including hosting GxP-relevant systems. QFINITY evolved the global quality management system so that Infrastructure as a Service, Infrastructure as Code, and cloud operation and monitoring are covered in a fully GxP-compliant way – on time and on budget.

Problem Statement

The customer is an international contract development and manufacturing organization (CDMO) in the pharmaceutical industry. Its services span comprehensive product development, from the early research phase through commercial-scale production. It also manufactures active pharmaceutical ingredients and finished medicinal products.

The company plans to expand its use of cloud services, particularly for infrastructure (IaC), and later use them to host GxP-relevant systems. To achieve this, the customer needed:

  • Analysis of the global quality management system’s suitability for managing cloud services across infrastructure, Infrastructure as Code (IaC), and system deployment and operation
  • Identification and assessment of potential gaps in the existing process framework, and development of practical, regulatory-compliant solutions for cloud environments
  • Creation and revision of policies, directives, SOPs, work instructions, and the required templates for infrastructure and computerized system validation to ensure a consistent and auditable approach

Project Execution

In the first phase, QFINITY analyzed the company’s existing quality management system for its suitability for cloud services and evaluated it against regulatory requirements and relevant industry standards. QFINITY then developed concrete change proposals for the affected processes and aligned them with the responsible departments. The customer approved the finalized documents in accordance with its own processes and implemented them within the company.

Cloud becomes GxP-compliant when the quality management system carries it – not the technology alone.

Results and Benefits

The project was completed successfully, on schedule and within the planned budget. This was possible because the analysis, creation, and approval activities were properly planned and precisely coordinated.

The revised processes of the global quality management system provide a clear, regulatory-compliant framework for the use of cloud services. In particular, they cover Infrastructure as a Service (IaaS), Infrastructure as Code (IaC), and the deployment and operation of computerized systems in cloud environments. They also define consistent requirements for planning, qualification, change and release management, monitoring, and incident and problem management in cloud contexts. These requirements ensure that all activities are documented consistently in a GxP-compliant manner.

IT-Qualitaetsmanagement und sichere Systemwiederherstellung - QFINITY

After a ransomware attack, a drug-discovery company had to recover GxP-relevant systems and data – fully documented. QFINITY guided the recovery from an IT quality management perspective: from forensically grounded quality planning through integrity-assured data migration to validated release.

Problem statement

The client is an international company in pharmaceutical active ingredient research. Its services include researching and developing new active ingredients and building software platforms for specialized methods in this environment. The company became the target of a ransomware attack that encrypted large parts of its infrastructure, systems, and data, making them inaccessible. Because some of these data and systems were GxP-relevant, the restoration of IT services and functions had to be closely overseen – and fully documented from an IT quality management perspective.

To achieve this objective, the client required:

  • Support in documenting and evaluating recovery activities for infrastructure, IT systems, and data
  • Coordination of activities with other departments, e.g. IT Security, Data Privacy, and IT Operations
  • Creation of quality reports for individual sub-areas of restored IT services and functionalities
  • Review and, if necessary, improvement of existing quality management processes to prevent future IT security risks

Project execution

At the start of the project, QFINITY recorded the recovery activities defined by the project team and evaluated their regulatory relevance. The results of the forensic analysis of the ransomware attack fed into this work, serving to review the effectiveness of existing quality management processes and optimize them where necessary. Based on this analysis, QFINITY developed a quality plan covering the following activities and areas:

  • Development of a procedural recovery framework by integrating forensic findings with the existing quality management framework
  • Restoration of a secure IT infrastructure by establishing a secure environment
  • Creation of regulatory documentation by fully documenting the restored IT infrastructure for compliance requirements
  • Reinstallation of IT systems as clean new installations to eliminate malicious code
  • Integrity-assured data migration through documented transfer of relevant data while maintaining consistency
  • Consolidation of data sets by synchronizing restored data with information newly generated since the attack
  • Comprehensive system validation through documented testing of restored systems and data prior to release
  • Timely quality reporting and release management for efficient approval of infrastructure and systems

Implementing this plan and the associated activities required intensive coordination with all departments to enable a fast, secure release of IT services and systems in full regulatory compliance.

In recovery, what matters is not speed but the complete traceability of every recovery activity.

Results and benefits

The project was completed successfully on schedule and within the planned budget because analysis, documentation, and release activities were appropriately scaled and efficiently coordinated. The restored IT systems and associated data fully meet all internal and regulatory requirements. Throughout the recovery, internal quality assurance continuously monitored the documentation in close coordination with the IT quality function, ensuring complete regulatory compliance and adherence to the highest internal quality standards. The resulting IT infrastructure meets the most stringent requirements for security, data integrity, and operational reliability.