0% found this document useful (0 votes)
113 views

Computer Validation: Questionnaire For Auditing of IT Service Providers

This document provides a questionnaire for auditing IT service providers. It contains questions in the following categories: general, personnel, service level agreements, life cycle, and data management. The questionnaire can be used to analyze a service provider's change management procedures, documentation, quality assurance systems, and compliance with service agreements. Conducting regular audits of service providers demonstrates a company's preparedness for regulatory audits and ensures tasks are performed according to requirements.

Uploaded by

sudheer
Copyright
© © All Rights Reserved
We take content rights seriously. If you suspect this is your content, claim it here.
Available Formats
Download as PDF, TXT or read online on Scribd
0% found this document useful (0 votes)
113 views

Computer Validation: Questionnaire For Auditing of IT Service Providers

This document provides a questionnaire for auditing IT service providers. It contains questions in the following categories: general, personnel, service level agreements, life cycle, and data management. The questionnaire can be used to analyze a service provider's change management procedures, documentation, quality assurance systems, and compliance with service agreements. Conducting regular audits of service providers demonstrates a company's preparedness for regulatory audits and ensures tasks are performed according to requirements.

Uploaded by

sudheer
Copyright
© © All Rights Reserved
We take content rights seriously. If you suspect this is your content, claim it here.
Available Formats
Download as PDF, TXT or read online on Scribd
You are on page 1/ 3

Newsletter LOGFILE N° 3 - May 2009 Maas & Peither AG, www.gmp-publishing.

com

Computer Validation: ment activities in accordance with the V


model.
Questionnaire for Auditing
of IT Service Providers ¬ Review quality assurance systems

Another important issue to consider is the sup-


plier’s error investigation and resolution
process. Companies should analyze reported
errors from existing system users and the sup-
plier should inform customers when a global
error has been detected.

Written by The focus of a service provider audit is to ana-


Peter Bosshard, Ph.D., lyze change management procedures, report-
F. Hoffmann La-Roche ing, and documentation and to ensure that the
Ltd, Basel, Switzerland service provider is performing all tasks in ac-
cordance with the service level agreement.
Conducting regular service provider audits de-
When starting a business relationship with an monstrates a company’s preparedness to un-
IT service provider the following steps should dergo an audit by the authorities if the need
be taken: should arise.
The following question catalog offers a practic-
¬ Conduct a formal supplier assessment. al and helpful supplement to the question cata-
log in the PIC/S guidance (PIC/S Guidance
¬ Conduct a supplier audit to ensure the Good Practices for Computerized Systems in
supplier correctly performs all develop- Regulated “GXP” Environments)

Question Supplier Service Intern


Provider

General
Is there an inventory of all systems? X X
Are the systems uniquely identified, versioned and classified? X X X
Is there a validation of all systems? X

Personnel
Does staff have sufficient experience and training? X X X
Are there sufficient personnel available to complete the transferred tasks? X X
Do job descriptions exist? Partially X X
Do organizational charts exist? X X X
Are new systems developed with assistance from its end users? X X
Are any quality assurance aspects from the previous system lost in the new X
system?
Are users trained before using a new system? X
Are maintenance and repair personnel in the computerized systems pro- Partially Partially
duction environment trained in the relevant hygiene and zone instructions?
Are advanced training options available for computerized systems and Partially X
applications?
Are the training courses documented? X X

Maas & Peither AG, Himmelreichsstr. 5, D-79650 Schopfheim www.gmp-publishing.com


Maas & Peither America Inc. Philadelphia, USA Phone +1 610 337-9548 [email protected] 1
Newsletter LOGFILE N° 3 - May 2009 Maas & Peither AG, www.gmp-publishing.com

Question Supplier Service Intern


Provider

Service level agreements


Do service level agreements exist? X Partially
Do these contracts include quality assurance measures? X Partially
Do contracts restrict the transfer of tasks or data to third parties? X X
Do the contracts permit audits and inspections? X X X

Life cycle
Have the systems been developed according to a life cycle? X Partially
Does a life cycle model or a project procedure model exist? X X
Is there a project plan and a corresponding SOP? X X
Is there a project concept and a corresponding SOP created? X X
Is there a quality protocol and a corresponding SOP? X
Are application specifications compiled and, if applicable, are these signed X X
by the user?
Is a risk analysis carried out and is there a corresponding SOP? X X
Is development of system components (hardware and software) docu- X
mented?
Compilation of user instructions manuals. X
Installation and start-up/SOP X X
Acceptance test planning and execution X Partially X
Release/SOP X
Change control/SOP X X X
System monitoring and maintenance/SOP X X
Error handling/SOP X X X
Planning of tests and reviews/SOP X X X
Are there plans or SOP for the retirement of systems? X X
Is the retention period of data and documentation regulated and does it X X
comply with regulatory requirements?
Retrospective validation: Does an experience report exist? X
Completeness of the documentation X X X
Risk analysis X X X
Quality protocol X X
Is authorized access regulated? X X X
Are user lists up-to-date? X X x
Are the authorizations appropriate, or are all users authorized as adminis- X X X
trators?
Is system access protected by timeout or shutting down? X X X
Are passwords protected using a suitable method and are they secure? X X X
Are entries subject to plausibility checks so that they remain within prede- X X
fined limits?

Maas & Peither AG, Himmelreichsstr. 5, D-79650 Schopfheim www.gmp-publishing.com


Maas & Peither America Inc. Philadelphia, USA Phone +1 610 337-9548 [email protected] 2
Newsletter LOGFILE N° 3 - May 2009 Maas & Peither AG, www.gmp-publishing.com

Question Supplier Service Intern


Provider
Is critical data reviewed? X X
Is a data archiving process performed using a long-text format (PDF, TXT)? X X X
Is later retrieval of data guaranteed?

Is data archived on long-term media? (Magnetic media should be rewritten X X


every two to three years, since magnetic information becomes lost over
time)
Are full backups performed on a regular basis? Partially X
Are two generations of full backups available? Partially X
Have the backups been checked for completeness and recovery ability? Partially X
Are daily incremental backups performed? Partially X
Are alternative systems available in the event of a failure? Partially X
Are procedures for restarting a failed system clearly defined and approved? X X

(Article based on GMP MANUAL, chapter 9 Computer validation; www.gmp-manual.com )

Author:
Peter Bosshard, Ph.D. GMP MANUAL
Global Quality Assurance Good Manufacturing Practice
F. Hoffmann La-Roche Ltd. & Implementation
Basel, Switzerland
E-Mail: [email protected]

References:
GMP MANUAL
Good Manufacturing
Practice & Implementation
www.gmp-manual-now.com The most dependable reference tool
in the world!
PIC/S PI 011-3
Good Practices for Computerized Systems in Available as
“GxP” Environments
http://www.picscheme.org/publis/recommandatio ¬ Loose leaf book + CD ROM
ns/PI%20011- 695 € / 995 US$
3%20Recommendation%20on%20Computerise
d%20Systems.pdf ¬ Online version:
o Corporate license:
GAMP 5 For all employees of a company
Good Automated 2,100 € / 3,000 US$
Manufacturing Practice Guide,
ISPE (International Society for Life Sciences) o Named User license
http://www.ispe.org/cs/gamp_publications_sectio For one single person
n/gamp_publications_overview 595 € / 850 US$

Free trial at www.gmp-manual.com


By completing a brief registration you can use
the trial version with full content and functions.

For more information and order visit


www.gmp-manual-now.com

Maas & Peither AG, Himmelreichsstr. 5, D-79650 Schopfheim www.gmp-publishing.com


Maas & Peither America Inc. Philadelphia, USA Phone +1 610 337-9548 [email protected] 3

You might also like