IT infrastructure qualification: a controlled data center opening to the cloud - QFINITY
QFINITY · Service Areas · IT Infrastructure

IT Infrastructure Qualification - From Data Center to Cloud.

IT infrastructure qualification demonstrates that the infrastructure beneath your GxP systems is built to specification and under control - from your own data center to the cloud. The evidence is not a protocol signed on a given day, but a controlled state: established according to risk, maintained through tools and monitoring.

IT Infrastructure

The foundation beneath every GxP system.

EU GMP Annex 11 puts the principle plainly - "The application should be validated; IT infrastructure should be qualified." How deeply is not prescribed: the scope follows the risk of the GxP processes the infrastructure supports - from hardware and networks through virtual environments to operating systems and databases.

A paper record with a date on it

A paper-based record confirms the state of a single day - it says little about ongoing operation.

A controlled state in operation

The qualified state is maintained within the IT quality management system: service management, automation, and monitoring carry the evidence. Build reports, the configuration management database, and monitoring logs are the records - governed by data integrity per ALCOA++.

GxP Risk-based EU GMP Annex 11 Configuration control Monitoring ALCOA++ Data integrity
Applications come and go - the infrastructure carries them all. Every GxP system is only as reliable as the foundation it runs on.
Qualification Path

Risk-based from need to controlled state.

Instead of a rigid phase model, every step derives from the risk of the supported GxP processes - evidence is deepened where it contributes most to safety.

  1. 1

    Planning & risk assessment

    Assessing the risk of the supported GxP processes and deriving the scope and depth of qualification - the risk-based starting point that sets the effort per component.

  2. 2

    Requirements & specification

    Capturing and documenting the infrastructure requirements, and confirming that the planned design fulfills them.

  3. 3

    Build & verification

    Documented evidence that hardware, virtual infrastructure, and infrastructure software are installed and configured to specification - automated build reports and Infrastructure as Code (IaC) deliver it reproducibly, with supplier documentation leveraged according to risk.

  4. 4

    Acceptance & release

    Functional evidence at the risk-based scope, the qualification report, and release of the infrastructure for GxP use.

  5. 5

    Controlled state in operation

    Change, configuration, and security management, patching, and periodic review maintain the state - the configuration management database (CMDB) and monitoring logs carry the evidence forward continuously.

Cloud

How do you qualify what you don't own - a moving target?

Cloud infrastructure belongs to the provider and changes constantly: capacity breathes with demand, patches arrive on the provider's schedule. A point-in-time record misses the mark twice over - the answer lies in demonstrable control on three levels:

  • Qualifying the provider

    The depth scales with the provider: for large cloud providers it rests on their certifications and audit reports, for small and mid-sized providers it extends to a direct audit - our service IT supplier audits.

  • Service and quality agreements

    Contract, SLA, and quality agreement define risk-based what the provider delivers. Activities can be delegated, accountability cannot - it stays with the regulated company.

  • Continuous monitoring

    Ongoing monitoring of service quality carries the evidence forward over time and surfaces deviations before they reach GxP processes.

Two service models carry outsourced infrastructure - Infrastructure as a Service (IaaS) and Platform as a Service (PaaS); they differ in how far the provider's responsibility extends:

ModelThe provider carriesYour evidence focus
IaaSData center, hardware, and virtualization - operated as a controlled service, without insight into the physical environmentQualify your own layer (operating systems, databases, middleware); verify delivered instances against the order - the provider's build reports serve as evidence
PaaSAdditionally operating systems, middleware, database services, and the development environment - the full application life cycleAssess the provider's controls; keep your own applications and deployments on the platform under control

Software as a Service is deliberately outside this picture: a rented application directly fulfills business processes and belongs to the validation of the computerized system as a whole - in its process, against its intended use.

The provider is not GxP-regulated - and does not need to be

Operating infrastructure is the core competency of the major providers; their controls are often more mature than in-house operation. What is demonstrated is controlled operation: through supplier qualification, service and quality agreements, and continuous monitoring.

Add to this compute: training and scaling modern AI models exceed company-owned data centers, and the demand arrives in bursts. Elastic compute from the cloud is what makes AI applications in the GxP environment operable in the first place - demonstrate controlled use of the cloud, and the path is open.

Components & Risk Classification

Risk-based scope by infrastructure component.

The qualification scope scales with component type and risk: standard components are demonstrated leanly, while configured and outsourced building blocks receive the depth of control their risk demands.

Infrastructure componentClassificationQualification focus (risk-based)
Operating systems, databases, infrastructure softwarestandard infrastructure softwareInventory, version, and configuration - recorded in the tooling, deliberately lean where risk is low
Hardware, network, serversphysical infrastructureAcceptance against the specification; functional evidence goes as deep as the risk demands
Virtual infrastructure, Infrastructure as Code (IaC)configuredThe code is the specification: verified once, it provisions identically - every run documents itself in the build report
Cloud services (IaaS, PaaS)outsourced operationControl over the provider: qualification, service and quality agreements, ongoing service monitoring
Backup & restore, disaster recoveryprocess on the infrastructureWhat matters is the rehearsed recovery under real operating conditions
Change, configuration & security managementoperational processThe operational processes carry the evidence forward - they maintain the qualified state in day-to-day operation
IT/OT

Does qualification end at the edge of the shop floor?

No - it follows the data. The production level (operational technology, OT) was long a world of its own: process control systems and sensors, strictly hierarchical, separated from the corporate network. That separation is dissolving:

  • Convergence opens the pyramid

    Smart sensors deliver condition data through edge devices to the cloud; maintenance and calibration are becoming data-driven.

  • IT controls reach through

    Network segmentation, access and patch management, and life cycle control extend all the way to the shop floor.

  • Intended use sets the depth

    A condition signal for predictive maintenance needs different controls than a process value that feeds into batch release.

Our Service

Qualification, implemented risk-based.

From strategy to report - and beyond: we maintain the qualified state in operation.

Consulting, planning, and implementation of risk-based qualification strategies
Risk assessment of the infrastructure against the business processes it supports
Capturing and documenting infrastructure requirements, test strategy, and documentation concept
Qualification of cloud and infrastructure providers, including allocation of shared responsibilities
Controls for Infrastructure as Code, automation, and monitoring - with the tools' records as evidence
Establishing the operational processes: change, configuration, and security management, backup & restore, disaster recovery, business continuity
Delineating and risk-classifying IT and OT in the production environment
Tracking all qualification activities, the qualification report, and CAPA management
First-Hand

We know the guide for this path - we helped write it.

QFINITY contributed to the GAMP Good Practice Guide "Enabling Innovation" - the guide that describes how the qualified state of modern IT infrastructure is maintained through tools, automation, and monitoring, from the company data center to IaaS and PaaS.

GAMP 5 Second Edition, which QFINITY helped shape as part of the Core Team, carries the same line: risk-based control instead of blanket documentation. Infrastructure cannot be partitioned into GxP and non-GxP - it is controlled as a whole, with uniform IT practices and evidence drawn from the tools.

GAMP 5 Second Edition Enabling Innovation IT QMS CMDB IaC Monitoring
FAQ

Frequently asked questions on IT infrastructure in the GxP environment.

Yes. No regulation prohibits cloud operation; what is required is demonstrable control. Accountability stays with the regulated company - demonstrated through provider assessment, service and quality agreements, and continuous monitoring. Operated this way, the cloud is open to GxP-critical applications as well.

No. The DQ/IQ/OQ/PQ phase model comes from qualifying stable equipment. IT infrastructure is qualified risk-based: standard components leanly, configured building blocks more deeply - and the qualified state is maintained in operation rather than confirmed on a given date. The tools carry the evidence: build reports, the configuration management database, monitoring logs.

Not necessarily. The qualification follows the risk: from certificates and standard reports through postal audits up to on-site or shared audits where risk is high. Just as important are the service and quality agreements and ongoing monitoring of performance - an audit captures a moment, while control has to hold permanently.

No - such a partition is neither practicable nor required. The same infrastructure carries regulated and non-regulated applications alike; it is controlled as a whole, with uniform IT practices. The differentiation happens above it: the intended use of the supported processes and data determines how deeply individual components are demonstrated.

Controlled infrastructure - the foundation that holds.

In an initial consultation, we classify your infrastructure by risk - from your own data center to the cloud - and identify where responsibilities and evidence have gaps today. Free of charge, about 30 minutes.

Schedule a consultation