GxP news - QFINITY
QFINITY · News · Insights & Events

Shaping the regulated quality of tomorrow.

Articles and analysis from our own work across GxP, pharma, quality management, GAMP and AI - what is changing in the regulated environment, what it means in practice, and what is happening inside our company.

Latest articles

Events, case studies and insights.

Beitragsaufruf ISPE Annual Meeting 2026 GAMP-Track - QFINITY

At the ISPE Europe Annual Conference 2026 in Copenhagen (April 20-22), Oliver Herrmann, Founder and CEO of QFINITY, served as Track Lead for the GAMP track „Digital Compliance by Design: GAMP, AI, data integrity and digital validation in a digitalized world“.

The life sciences industry is going through a profound digital transformation. Cloud platforms, AI-enabled tools and automation are changing how systems are built, validated and operated. These technologies open up opportunities; they also bring new risks and regulatory expectations.

At the heart of the track was the question of how „compliance by design“ works in practice: building conformity into processes, systems and technologies from the start, so that innovation can proceed without putting GxP compliance at risk. A particular focus was data integrity as the foundation for AI: without trustworthy, well-governed data, AI systems cannot perform reliably, least of all in regulated environments.

The track featured contributions on:

  • Compliance by design in practice: using AI, cloud and automation in line with GxP and regulatory requirements
  • Applying GAMP 5 Second Edition, the GAMP AI Guide and the Digital Validation Guide in digital initiatives
  • Annex 11 vs. Annex 15: where they differ and where they overlap for QA, IT and project teams
  • Data integrity in the digital age, particularly in the context of AI
  • Translating process requirements into risk-based, testable and GxP-compliant system requirements
  • Supplier qualification and continuous monitoring in outsourced or cloud environments
  • Business continuity and disaster recovery for regulated digital infrastructures

The sessions centered on case studies, lessons learned and forward-looking perspectives on emerging technologies and upcoming regulatory developments.

IT-Qualitaetsmanagement und sichere Systemwiederherstellung - QFINITY

After a ransomware attack, a drug-discovery company had to recover GxP-relevant systems and data – fully documented. QFINITY guided the recovery from an IT quality management perspective: from forensically grounded quality planning through integrity-assured data migration to validated release.

Problem statement

The client is an international company in pharmaceutical active ingredient research. Its services include researching and developing new active ingredients and building software platforms for specialized methods in this environment. The company became the target of a ransomware attack that encrypted large parts of its infrastructure, systems, and data, making them inaccessible. Because some of these data and systems were GxP-relevant, the restoration of IT services and functions had to be closely overseen – and fully documented from an IT quality management perspective.

To achieve this objective, the client required:

  • Support in documenting and evaluating recovery activities for infrastructure, IT systems, and data
  • Coordination of activities with other departments, e.g. IT Security, Data Privacy, and IT Operations
  • Creation of quality reports for individual sub-areas of restored IT services and functionalities
  • Review and, if necessary, improvement of existing quality management processes to prevent future IT security risks

Project execution

At the start of the project, QFINITY recorded the recovery activities defined by the project team and evaluated their regulatory relevance. The results of the forensic analysis of the ransomware attack fed into this work, serving to review the effectiveness of existing quality management processes and optimize them where necessary. Based on this analysis, QFINITY developed a quality plan covering the following activities and areas:

  • Development of a procedural recovery framework by integrating forensic findings with the existing quality management framework
  • Restoration of a secure IT infrastructure by establishing a secure environment
  • Creation of regulatory documentation by fully documenting the restored IT infrastructure for compliance requirements
  • Reinstallation of IT systems as clean new installations to eliminate malicious code
  • Integrity-assured data migration through documented transfer of relevant data while maintaining consistency
  • Consolidation of data sets by synchronizing restored data with information newly generated since the attack
  • Comprehensive system validation through documented testing of restored systems and data prior to release
  • Timely quality reporting and release management for efficient approval of infrastructure and systems

Implementing this plan and the associated activities required intensive coordination with all departments to enable a fast, secure release of IT services and systems in full regulatory compliance.

In recovery, what matters is not speed but the complete traceability of every recovery activity.

Results and benefits

The project was completed successfully on schedule and within the planned budget because analysis, documentation, and release activities were appropriately scaled and efficiently coordinated. The restored IT systems and associated data fully meet all internal and regulatory requirements. Throughout the recovery, internal quality assurance continuously monitored the documentation in close coordination with the IT quality function, ensuring complete regulatory compliance and adherence to the highest internal quality standards. The resulting IT infrastructure meets the most stringent requirements for security, data integrity, and operational reliability.

Globales QMS-Konzept fuer Pharma - QFINITY

Grown through acquisitions, an international pharmaceutical company needed a harmonized global QMS. QFINITY designed and implemented it along GAMP 5 and ITIL – across infrastructure, software development, and computerized system validation – including a training concept and a worldwide rollout.

This case study focuses on the design and implementation of a global QMS concept for an international pharmaceutical company.

Problem Statement

The client is an international company in pharmaceutical active ingredient research. Its services range from researching and developing new pharmaceutical compounds to building software platforms for specialized methods in this domain.

After years of significant growth through acquisitions, the company needed to consolidate its various quality management approaches into a harmonized global Quality Management System (QMS).

To achieve this objective, the client required:

  • Development of a global QMS concept that integrates the requirements of existing QMS with relevant standards such as GAMP and ITIL while ensuring regulatory compliance
  • Evaluation of existing inconsistencies and development of appropriate solutions
  • Creation of policies, directives, SOPs, work instructions, and required templates for Infrastructure, Software Development, and Computerized System Validation, based on the developed QMS concept
  • Development of a training concept and training materials for the global QMS rollout
  • Execution of global QMS training sessions for relevant departments and stakeholders

Project Execution

In the initial phase, QFINITY analyzed the organization’s existing quality management systems and evaluated them against regulatory requirements and industry standards.

QFINITY then developed a new QMS concept covering the following areas:

  • Infrastructure
    • IT Risk Management
    • IT Asset and Inventory Management
    • Monitoring and Capacity Management
    • Data Centre / Server Room Management
    • Infrastructure Qualification
    • Backup and Restore Management
    • Change and Patch Management
    • Service Request Management
    • (Major) Incident Management
    • Problem Management
  • Software Development
    • Software Development Planning
    • Software Requirements and Risk Assessment
    • Software Design and Architecture
    • Software Development
    • Software Quality Assurance
    • Software Release and Maintenance
  • Computerized System Validation
    • Project Phase
      • Validation and Implementation of GxP-regulated systems
      • Implementation of non-regulated systems
    • Operational Phase
    • Retirement Phase
    • Data Migration
    • Data Archiving

As part of the implementation, QFINITY developed all necessary policies, directives, SOPs, work instructions, and document templates. It also created training materials for all relevant areas and planned and ran training sessions for the respective employee groups and departments.

A global QMS thrives not on the rule book but on a shared understanding of quality across every site.

Results and Benefits

The project was completed successfully on time and within the planned budget. Appropriately scaling the analysis, development, and rollout activities – and coordinating them efficiently – made this possible. Potential bottlenecks were identified early and avoided, keeping the overall project timeline on track.

The implemented global QMS significantly improved both efficiency and compliance. Globally harmonized processes and approaches ensured consistent compliance with regulatory requirements across the entire organization. Process efficiency increased substantially, and the company established a unified global understanding of quality.

The company’s internal quality assurance function reviewed the QMS approach and related documentation, and any inconsistencies identified were resolved promptly before rollout.

For more information about QFINITY’s case studies, check out our Project News.