
QFINITY · Updates
The latest from QFINITY and the field.
An overview of updates beyond events and projects: articles and publications, work in industry bodies and committees, awards, and our perspective on new regulations.
At a glance

An overview of updates beyond events and projects: articles and publications, work in industry bodies and committees, awards, and our perspective on new regulations.
The PIC/S Recommendation PI 006, Fourth Version: The Paradigm Shift in Qualification and Validation
PIC/S has rewritten its recommendations on qualification and validation: PI 006-4 replaces the 2007 version on October 1, 2026. The real change sits beneath the chapters: validation is no longer a completed event but a continuously demonstrated state. That is precisely what gives modern ways of working a regulatory foundation, from a scientifically justified number of batches in process validation to ongoing verification in operation. Reading the new text with the vocabulary of 2007 can take you down the wrong path: scope and terminology have shifted. Computerized systems are explicitly out of scope; they belong to a different set of rules.
PI 006-4 "Recommendations on Qualification and Validation" is the Pharmaceutical Inspection Co-operation Scheme’s (PIC/S) recommendation on qualification and validation in pharmaceutical manufacturing; its participating authorities include the European inspectorates and the U.S. FDA. It covers the qualification of facilities, equipment and supporting utilities, process and cleaning validation, the validation of test methods, and special topics such as the verification of transportation and the validation of packaging for solid dose products. It enters into force on October 1, 2026, replaces the 2007 version and describes what inspectorates expect beyond Annex 15. It is not a legal instrument; as a guidance and training resource for GMP inspectors and the pharmaceutical industry, however, it shapes inspection practice directly.
Why is PI 006-4 a paradigm shift?
Four narrowly scoped topics from 2007 have become a lifecycle guide. The language, however, deserves particular attention: the words have stayed the same while the meaning underneath them has moved. The longer your validation practice reaches back, the more familiar the terms sound; they no longer carry their 2007 meaning.
In addition, statistics moves from optional to expected: process capability indices, multivariate methods and predefined evaluation criteria belong in the protocols where risk warrants it, with subject matter experts and statisticians working side by side. Cleaning validation follows the same movement: the extent of the cleaning program is driven by a toxicological risk assessment, for example based on health-based exposure limits (HBEL); they make the actual hazard potential of an active substance the measure of how stringent cleaning needs to be.
Is periodic revalidation still written into your validation master plan?
Periodic revalidation gives way to Ongoing Process Verification, and its requirements are concrete. After the initial validation, once routine manufacturing begins, OPV runs until the process is discontinued. It monitors product quality and the critical parameters identified through risk assessment, and draws in quality system signals such as deviations and complaints; the trending should also be capable of detecting creeping change and special causes of variability. Results are reported regularly, normally at least once a year and, wherever possible, with objective statistical tools such as the process capability index Cpk, which measures how reliably the process stays within its specification limits; every report ends with a verdict: the process is in a state of control, or it is not. The effort scales with risk, and the reports may explicitly serve as a reference for the annual Product Quality Review. For most companies this means the data already exist. But what about the predefined criteria and the regular, documented verdict?
There is one question that lets you read PI 006-4 without stumbling: what exactly is demonstrated, and against what? Name the object and the reference point for every piece of evidence and you cannot take a wrong turn. Verifying the transport route then follows just as logically as the risk-based number of batches. Take only the familiar words with you, however, and verification turns into monitoring, the continuous demonstration of control turns into a calendar entry, and a conditional permission turns into a free choice. The same economy of thought runs through the document itself: evidence established once is referenced, not repeated.
What applies to computerized systems?
The two process worlds
Computerized systems are explicitly out of scope: their validation "is covered in the PIC/S GMP Guide Annex 11". That is a deliberate boundary between two process worlds. The Annex 15 process transforms material into product; it is tied to the plant, filed with the marketing authorization and changed through the variation procedure. The Annex 11 process originates in the business function and transforms information into records and decisions, from ERP processes to document control, QMS workflows or complaint handling. The tools of the production world do not transfer here: a deviation process has no batches and no process capability indices.
The difficulty starts where the two worlds overlap. An MES executes the filed manufacturing process; a LIMS manages testing against the approved methods. The system falls under Annex 11 while its content remains part of the marketing authorization world: the process world of Annex 15. Without that separation, you either test twice or leave a gap.
Three levels, one pattern
The boundary does not mean the systems world is spared the paradigm shift. It is ahead of it. Annex 11 requires computerized systems to be validated across the lifecycle and periodically evaluated in operation; the 2025 draft revision expands precisely that operational phase: reviews at risk-based intervals verify that the system remains in a validated state, and reveal when a system in motion drifts out of its defined parameters. The upcoming AI Annex 22 (2025 draft) takes it further: predefined metrics and acceptance criteria before testing, then regular performance monitoring of the model in operation and drift monitoring of the input data space. And the draft of the new Chapter 4 (Documentation, 2025) draws the same line at the data level: a data governance system should cover the entire data lifecycle, from creation through processing and archiving to destruction. PI 006-4 itself states that data governance should be considered in all aspects of qualification and validation.
The movement is transatlantic, too, down to the authorship: the PIC/S working group behind the revision was most recently jointly chaired by Ireland’s HPRA and the U.S. FDA. The FDA anchored the lifecycle view in its Process Validation guidance back in 2011; Stage 3 is called Continued Process Verification there, and the 2015 revision of Annex 15 adopted that view. On the systems side, the FDA guidance on Computer Software Assurance shifts the effort from documentation to effective assurance; formally it covers the production and QMS software of medical device manufacturers, yet its approach draws attention well beyond that scope. Five documents in two years point in the same direction: the EMA and PIC/S Concept Paper on the Annex 15 revision, PI 006-4, the Annex 11 draft revision, the AI Annex 22 and the Chapter 4 draft. Production level, system level and data level converge on one pattern: quality is no longer proven at a point in time; it is demonstrated continuously.
And your computerized systems: under which set of rules do you validate?
QFINITY advises on both worlds and on the transition between them. Many of our clients work with the established methods today: classic validation campaigns, document-based evidence, the three-batch logic. We continue to advise on these paths without reservation; they remain acceptable under GMP, and which path fits is a question of maturity. Increasingly, and with the same conviction, we offer the continuous approaches: ongoing verification in operation, agile software development with a robust evidence trail and a risk-based number of batches. The first inquiries are already coming in. The deciding factor is where the organization stands: QFINITY covers past, current and emerging quality strategies and draws the line for every piece of evidence at its object. What is demonstrated, and against what? The answer determines whether the production rules apply (Annex 15; at the FDA, 21 CFR 211 with the process validation lifecycle) or the system rules (Annex 11; at the FDA, 21 CFR Part 11 and 211.68, and in the medical device world the CSA guidance), what depth of scrutiny is appropriate and what evidence your inspection requires. That evidence is what we deliver, and it is defensible.
PIC/S PI 006-4: Recommendations on Qualification and Validation→Concept Paper on the Revision of Annex 15 (EMA and PIC/S, 2026)→
QFINITY at the ISPE AI Summit 2026: Advancing Practical AI Applications in GxP
The first ISPE AI in Life Sciences Summit – Powered by GAMP put one question at its centre, a question QFINITY has worked on for years: how do you move AI in GxP environments from experiment to validated, responsible use? QFINITY was on site and helped shape the content – among other things with a workshop on working with AI suppliers.
The Summit turned on a core question for regulated life sciences: what changes when AI enters the picture – and what does not? Collaboration between the regulated user and the supplier was always demanding: different vocabularies, quality brought in too late, short-notice changes in SaaS services. AI sharpens these familiar challenges and adds new ones – dynamic models, model drift, a higher relevance of data, ongoing performance monitoring.
The answer, however, is not a new discipline: it is the proven GAMP 5 key principles, critical thinking and a risk-based approach – the right mix of flexibility and rigor.
Four blind spots in AI supplier relationships
How concrete this gets became clear in the workshop, drawing on real gaps that recur in AI supplier relationships:
The decisive question behind every gap: what would you put in front of an inspector to justify your validation strategy?
The regulatory framework for this is taking shape right now: the draft EU GMP Annex 22 requires the regulated user to review the documentation – regardless of whether the model is trained in-house or by a supplier. Methodological orientation comes from the ISPE GAMP Guide: Artificial Intelligence (2025), and the EU AI Act draws a further line with its distinction between provider and deployer. Specific guidance on AI supplier management is still rare – and this is where QFINITY works at the leading edge.
That QFINITY helps shape this development is no coincidence: as chair of the GAMP Global Steering Committee, Frank Henrichmann, Senior Executive Consultant at QFINITY, is close to where these guidelines take form. The real value, however, is created where QFINITY translates this still-young framework into robust practice – from AI experiment to validated, audit-ready use.
QFINITY’s Senior Executive Consultant was interviewed by the Clinical Leader
The Clinical Leader interviewed Frank Henrichmann, Senior Executive Consultant at QFINITY and Co-Chair of the GAMP Global Steering Committee, on the occasion of the second edition of the ISPE GAMP Good Practice Guide for computerized GCP systems. The conversation explores how clinical trials are changing and the role of validated computer systems.
Mr. Henrichmann works as a Senior Executive Consultant at Q-FINITY Quality Management. He is an expert in quality management, computer system validation, and compliance, particularly in the context of clinical trials and pharmacovigilance. Over the course of more than 22 years, he has gained extensive experience with strategies, projects, and measures for GxP-regulated environments, both at a CRO and at a major pharmaceutical company. In his current role, he assists life sciences companies and supports technology providers in finding innovative solutions to quality and validation challenges. He is a qualified ISPE trainer, a member of the ISPE Clinical Systems Special Interest Group (SIG), and a co-author of the ISPE GAMP Good Practice Guide: Validation and Compliance of Computerized GCP Systems and Data. He has been a member of ISPE since 2001 and currently serves as co-chair of the GAMP Global Steering Committee.
Frank Henrichmann is one of the lead authors of the ISPE GAMP Good Practice Guide: Validation and Compliance of Computerized GCP Systems and Data – Good eClinical Practice (Second Edition). To mark the occasion, he was invited by Clinical Leader to participate in an interview. In this interview, Henrichmann provides insights into the challenges and changes in the field of clinical trials. The interview highlights the importance of computer systems in clinical trials. Read the full interview at Clinical Leader↗
The Interview
The second edition of the “GAMP Good Practice Guide: Computerized GCP Systems & Data” has been published. Why is now the right time for an update?
Frank Henrichmann: The way we design, plan, and conduct clinical trials today differs from how we conducted them 15, 10, or even five years ago. The pharmaceutical products being developed in clinical trials have changed significantly and now include more innovative cell and gene therapies (CGTs). This requires a completely different approach to clinical trial design, and the tools we use must adequately support these new designs and meet the new requirements.
The challenges posed by the COVID-19 pandemic required the industry to rethink its approach to data collection and management. Pandemic-related lockdowns limited study participants’ ability to visit clinical facilities for treatments and examinations, leading to an accelerated shift toward decentralized data collection via participants’ homes, mobile clinics, wearables, sensors, and telemedicine. This brought additional challenges for data integrity and data management. While participants in traditional systems were typically identified by an anonymous number, these new systems collect and process personally identifiable information to ensure the delivery of devices or investigational products and to enable telemedicine. These are just a few examples of what has changed in recent years since the publication of the first edition of our guide. Of course, regulatory authorities have also responded to these changes and issued guidelines to address these new elements and challenges.
What are some of the new topics covered in the second issue?
The comprehensive new guide covers more topics than the first edition. While the structure of the first edition has remained the same, the content has been expanded to include topics such as decentralized trials, the evolution of data management toward data science using AI-enabled solutions, and guidelines for generating real-world evidence (RWE) from real-world data (RWD) available from electronic health records (EHRs), patient registries, and other non-regulated data sources.
In addition, the guidance document now also covers oversight activities such as audits and assessments and includes practical guidance and questions to consider when evaluating computer systems in clinical settings. The guidance document also includes guidance on data protection in the context of clinical trials. And while the validation of AI/ML-based systems is addressed in other ISPE guidelines, the considerations regarding AI-enabled systems used in clinical trials are specific to this comprehensive guideline.
Today, an increasing number of users are becoming involved in clinical trial processes – from pharmaceutical companies, CROs, technology service providers, and clinical research organizations to trial participants. How does this new issue take this growing number of end users into account and address their needs?
As more and more stakeholders interact with the systems and data during the collection and processing of clinical trial data, greater challenges arise for data integrity. For example, in decentralized clinical trials (DCTs), sensors and wearables are often used to collect data directly from participants. This data must be securely and accurately transferred to the systems that manage data from all trial participants, such as an EDC system.
Because these sensors and wearables take frequent measurements, the amount of data collected has increased exponentially. In a traditional study, for example, blood glucose levels or an ECG were measured only during clinic visits. With wearables and sensors, these measurements can be recorded with high accuracy at much shorter intervals – almost continuously. The massive increase in data volume has led to traditional data management evolving into a data science activity, in which specialized tools – previously used primarily for analyzing big data – are now being used to analyze study data in order to identify patterns or discrepancies. Today, the industry is rapidly adopting AI-enabled solutions to manage and analyze these large volumes of data more quickly, so that patient safety and well-being can be better protected and critical decisions can be made faster based on reliable and trustworthy data.
Clinical data often comes from systems owned and operated by a healthcare facility. These may include instruments and devices used in the daily care of patients, as well as electronic health records in hospitals. If data generated or processed by these systems is to be used in a clinical trial, the sponsor must verify the suitability of these systems in advance. This requirement presents several challenges, given that clinical trials often involve hundreds of sites around the globe. Efficient yet reliable methods and processes must be implemented to ensure the necessary control and monitoring while avoiding overburdening the limited resources of the trial sites. The guidance document provides practical guidance and a list of factors to consider when evaluating such systems at clinical sites to ensure the necessary control.
With regard to the overlap between these systems and those of pharmaceutical manufacturers and laboratories – which generally comply with GMP and GLP, respectively – how does this guide assist users working in these related fields?
We have tried not to reinvent the wheel and have focused on the systems directly related to the conduct of the clinical trial. However, there is an overlap with drug manufacturing, as investigational products must also be manufactured in appropriate, albeit small, quantities. The manufacture of the investigational product must comply with established GMP guidelines and expectations and has not been covered in detail in this guide, as this topic is already addressed in other ISPE guides. However, the investigational product may need to be packaged and labeled differently from marketed drugs in order to establish and maintain the blinding of a clinical trial. This is a critical aspect in many clinical trials, as it ensures that neither the participant nor the investigator can determine which participant is receiving the new investigational product, the standard of care, or a placebo. In our guideline, we have described the systems involved in this randomization process, explained the key risks associated with the process and the supporting systems, and presented possible validation approaches.
Similarly, we addressed the interface with the laboratories that analyze the samples collected from participants. The validation of the systems used within the laboratory itself was not covered in our guidance, as it has already been addressed in other ISPE guidance documents. However, the specific requirements for data transfer and the management of this laboratory data in a GCP system, while ensuring data integrity, were described in the section on good clinical laboratory practice in the guideline.
New in this issue is a focus on “ensuring compliance with applicable regulations, with a particular emphasis on data integrity and data flows, taking into account challenges posed by outsourcing services and technology.” What is the reason for including this additional objective?
GCP systems have a broader user base than most other regulatory systems, including sponsors, clinical service providers such as CROs, clinical sites, and trial participants. Because of this broad user base, it has become standard practice to outsource nearly all computer systems required for the collection and management of clinical trial data. Specialized technology service providers have developed web-based, zero-footprint systems that all authorized users can easily access, regardless of local infrastructure or device. All collected data is analyzed and processed by clinical research service providers such as CROs and, of course, the sponsor. These data transfers and activities must be assessed for potential risks to data integrity. This is important because the data must be collected and analyzed accurately and in a timely manner to identify possible adverse events or a lack of efficacy. Furthermore, this data often forms the basis for regulatory submissions to regulatory authorities. The quality and integrity of the data therefore have potential implications for the health and well-being of future users of the drug.
And finally, when and where will the second edition be available?
After 18 months of intensive work by a team of nearly 50 industry experts from sponsors, CROs, technology providers, and consultants, the guidance was published by ISPE on July 31, 2024. However, this is not the end of our team’s activities. We are currently planning a series of webinars on specific topics covered in the guidance document. These will be posted at ISPE.org/webinars as soon as they become available, such as decentralized trials and AI-enabled solutions in data management. In addition, there will be presentations on similar topics at various ISPE conferences and events around the world. As this field continues to evolve, we will cover new developments in future articles for ISPE’s Pharmaceutical Engineering Magazine or other ISPE publications.
Frank Henrichmann was pleased to have been invited to this interview.
Related ISPE webinars
The webinar series on the 2nd edition has since taken place. The recordings are available to ISPE members (sign-in required).
Webinar: Introduction to the 2nd Edition of the GAMP GPG on GCP Systems (ISPE members)↗
Webinar: Audit and Oversight Challenges in GCP Systems (ISPE members)↗