GCP process compliance for clinical trials: QFINITY
QFINITY · Service Areas · GCP / Clinical Trials

GCP process compliance and quality assurance for clinical trials.

We advise sponsors, CROs and service providers in clinical research on compliance management and on optimizing their GCP processes. Our work ranges from audits and setting up or adapting quality management systems to process-analysis workshops that prepare you for inspections.

GCP Compliance

Data quality and integrity through defined processes.

GCP process compliance is the demonstrable conformance of a clinical trial's processes with Good Clinical Practice, for sponsors, CROs, service providers and trial sites alike. The safety of study participants and the quality and integrity of the data depend on appropriate processes. The sponsor regularly checks whether those processes are followed. Whether a sponsor or trial site passes a regulatory inspection depends on compliant and efficient processes, and on qualified people and service providers.

We assess the supporting IT systems in the same pass as the processes. The comparison below shows what that means for effort and data integrity.

Process and system, one framework.

The EMA guideline on computerized systems and ICH E6(R3) set the regulatory bar; the methodology for the system level is laid down in the ISPE GAMP eClinical Good Practice Guide, co-authored by QFINITY. How we validate the systems behind these processes is covered in Data Integrity of GCP-Relevant Systems.

GCPGCLPICH E6(R3)EMA guidelineALCOA++
Tasks can be delegated. Responsibility for quality and data integrity cannot. An inspection is passed only on your own evidence.
Our Service

How is GCP compliance reviewed?

Every audit calls for specialist knowledge. An auditor from data management sees different aspects of a clinical system than someone who works at a trial site. Anyone who stays within their own specialty, however, misses the interfaces where deficiencies arise. Our auditors therefore bring expertise from more than one of these areas and check the handover points between them at the same time.

  • Vendor / supplier qualification audits

    Assessing CROs, laboratories and software service providers, both before and after contracting.

  • GCP audits at clinical trial sites

    Reviewing trial sites for process adherence and GCP compliance.

  • GCLP audits at clinical laboratories

    Reviewing clinical laboratories against the requirements of Good Clinical Laboratory Practice.

  • Mock audits

    A simulated regulatory inspection ahead of the real date, with a list of deficiencies and an action plan.

  • Internal audits

    Quality assurance from within: reviewing your own GCP processes and systems.

  • System audits

    A single process, reviewed across multiple studies and indications. The focus is not the study itself but the system behind it.

  • For-cause audits

    A targeted review prompted by a signal such as a cluster of deviations, a suspicion or a complaint, not by the routine schedule.

  • Workshops for process analysis

    Analyzing GCP processes in support of continuous improvement and greater efficiency.

Process and IT from one team

One audit instead of two.

In clinical research, data quality and inspection readiness rest on the GCP processes and on the computerized systems that support them. We assess both together rather than in separate audits.

  • One audit report covering processes and the IT systems behind them
  • An assessment of data integrity at the process/system interface
  • Prioritized actions for inspection preparation
GCP audit at the trial site: one audit path from the processes into the IT system, one audit instead of two
AspectSeparate auditsQFINITY audit
Scope of reviewprocess and IT system audited separatelyprocess and IT system audited together
Efforttwo audits, two reports, duplicate preparationone audit, one report, one preparation
Data integritygaps at the process/IT interfaceassessed against ALCOA++
Inspection readinessdeficiencies at the interface often go undetecteddeficiencies assigned to each interface, actions prioritized by inspection risk
GCP Audits

Inspection-ready before the inspection arrives.

With process compliance and quality assurance, trial sites, laboratories and sponsors have the evidence an inspection demands at hand. This is backed by more than 17 years of auditing experience with over 100 audits in total, of which more than 70 have been conducted in the GCP environment since 2014, including GCP-related pharmacovigilance audits under GVP, at a rate of two to three per year. Our case study on the Investigator Notification System shows how this holds up in practice. It describes a vendor audit and the end-to-end validation of the computerized system in its process context. The system was released with no major deficiencies.

Mock auditInternal auditProcess analysisQMS build-out
FAQ

Frequently asked questions about GCP compliance and quality assurance.

ICH E6(R3) allows a sponsor to delegate tasks to a CRO. Responsibility for quality and data integrity, however, stays with the sponsor. We put that into practice through risk-based oversight. It includes a vendor/supplier qualification audit before contracting and targeted audits of the critical processes and the systems behind them. This is how a sponsor oversees a CRO without retracing its work step by step.

Data integrity is created at the interface between process and IT: eCRF, eTMF and systems for randomization and trial supply management (IRT/RTSM) carry the GCP-relevant data. We assess these systems in the same pass as the processes. That way, deficiencies at the interface do not go undetected. How computerized systems are validated in their process context is covered in Data Integrity of GCP-Relevant Systems.

A GCP audit reviews trial sites and sponsor processes for process adherence and compliance with Good Clinical Practice. A GCLP audit focuses on the clinical laboratories that analyze study samples, reviewing those laboratories against Good Clinical Laboratory Practice. GCLP is the bridging standard between GCP and GLP for data quality in the lab. Both can be part of the same audit program.

A mock audit simulates the regulatory inspection that is actually coming up and prepares the trial site or sponsor specifically for it. An internal audit is a routine quality assurance activity within your own QMS. It reviews your GCP processes and systems on a regular cycle, whether or not an inspection is scheduled.

Last updated:

More from our Service Areas

Compliance needs a foundation.

Ready for the next regulatory inspection.

We plan the right audit program with you. That includes vendor qualification, GCP or GCLP audits, mock audits and QMS build-out. We review processes and IT systems in a single pass. The first call is free and takes about 30 minutes.

Book an intro call