下载本文档
版权说明:本文档由用户提供并上传,收益归属内容提供方,若内容存在侵权,请进行举报或认领
文档简介
1、QAS/19.819GUIDELINE ON DATA INTEGRITY数据完整性指南(October 2019)2019 年10月1. INTRODUCTION AND BACKGROUND前言与背景1.1. Data governance and data integrity (DI) are important elements in ensuring the reliability of data and information obtained in production and control of pharmaceutical products. The data and in
2、formation should be complete as well as being attributable, legible, contemporaneous, original and accurate, commonly referred to as meeting“ALCO A principles.数据管理与数据完整性(DI)是确保药品生产和检测期间所获得的数据和信息可靠 性的重要要素。这些数据和信息应完整,同时具有可追溯性、清晰、同步、原始和 准确,一般称为符合“ ALCOA原则。1.2. In recent years, the number of observation
3、s made regarding the integrity of data, documentation and record management practices during inspections of good manufacturing practice (GMP), good clinical practice (GCP) and good laboratory practice (GLP) has been increasing. Possible causes for this may include (i) too much reliance on human prac
4、tices; (ii) the use of computerized systems that are not appropriately managed and validated;and (iii) failure to adequately review and manageoriginal data and records. 近年,在GMP GCP和GLP检查中,数据完整性、文件记录管理规范性方面的缺陷 数量大大上升。可能的原因大致包括(1)太过依赖人员操作,(2)使用了未进行 恰当管理和验证的计算机化系统,以及(3)未充分审核和管理原始数据与记录。1.3. Quality risk
5、 managementfQRM), control strategies and sound scientific principles are required to mitigate such risks.Examples of controls mayinclude, but are not limited to:降低此类风险需要有质量风险管理(QRM、控制策略和科学合理原则。控制实例可 包括但不仅限于:? the establishment and implementation of a DI policy;? 制订和实施DI 方针;? the establishment and im
6、plementation of procedures that will facilitate compliance with DI requirements and expectations;? 制订和实施有利于符合DI 要求和预期的程序;? adoption of a quality culture within the companythat encourages personnel to be transparent about failures which includes a reporting mechanism;? 在公司内推行质量文化,鼓励员工坦白失败,包括报告机制;? ap
7、plication of QRMwith identification of all areas of risk to DI through data integrity risk assessment (DIRA) and implementation of appropriatecontrols to eliminate or reduce risks to an acceptable level throughout the life cycle of the data;?应用QRM通过数据完整性风险评估(DIRA)识别所有领域的DI风险,在数据整个生命周期中实施适当控制消除或降低风险至
8、可接受水平;? ensuring sufficient resources to monitor compliance with DI policies and procedures and processes, and facilitate continuous improvement;? 确保有足够的资源监测DI 方针以及程序和流程遵守情况,促进持续改进;? provision of necessary training for personnel in, for example, good practices (GXP), computerized systems and DI;?为员工
9、提供必要的培训,如,优良规范( GXP、计算机化系统和 DI ;? implementation and validation of computerized systems appropriate for their intended use;? 根据其既定用途实施和验证计算机化系统;? definition and management of appropriate roles and responsibilities forquality agreements and contracts entered into by contract givers and contract accep
10、tors.? 作为合同委托方或接受方签署的质量协议和合同中适当角色与职责的定义和管 理。2. SCOPE范围2.1. This guideline provides information, guidance and recommendations to facilitate compliance with DI, GXP in documentation and record keeping requirements.本指南提供促进DI、GXP在文件和记录保存要求方面的合规性信息、指南和建议。2.2. The scope of this guideline is designated as
11、GXP . It does not, however, cover medical devices.本指南的范围规定为“ GXP 。但并不覆盖医疗器械。2.3. Where possible, this guideline has been harmonised with other published documents. The guideline should be read with other WHO GXP guidelines and publications.如可能,本指南已与其它已发布文件保持统一。本指南应与其它WHOGXP指南和出版物联合解读。2.4. In line wi
12、th the current approach in GMP, it recommends a risk-basedapproach over the life cycle of data.DIRA should be carried out in orderto identify and assess areas of risk.根据GMP中的当前方法,建议对数据生命周期采取基于风险的方法。应执行 DIRA 以识别和评估风险领域。2.5. The principles of this guideline apply to contract giversand contractacceptor
13、s. Contract givers are ultimatelyresponsible for the integrity of data provided to them by contract acceptors. Contract givers should therefore ensure that contract acceptors comply with the principles contained in this guideline.本指南的原则适用于合同委托方和合同接受方。合同委托方最终对合同接受方提交给他们的数据的完整性负责。委托方因此应确保合同接受方符合本指南所含原
14、则。2.6. Efficient risk-based controls and review of data and documents shouldThe effectiveness of the controls shouldbe identified and implemented. be verified.应识别并实施对数据和记录的基于风险的有效控制与审核。控制的有效性应进行验 证。3. GLOSSARY(Note: This section will be updated)(注:本部分将进行更新)The definitions given below apply to the te
15、rms used in these guidelines. They may have different meanings in other contexts.以下定义适用于本指南所述术语。可能与其它语境含义有所不同。ALCOA.A commonly used acronym for “ attributable, legible, contemporaneous, original and accurate ” . 常用术语,代表“可追溯性、清晰、同步、原始和准确”。ALCOA+.A commonly used acronym for “ attributable, legible, co
16、ntemporaneous, original and accurate ” which puts additional emphasis on the attributes of being complete, consistent, enduring and available- implicit basic ALCOAprinciples.常用术语,代表可追溯性、清晰、同步、原始和准确”,加上对完整性、一致性、持久性和可及性等明确的 ALCOA基本原则的补充强调。archiving, archival. 归档Archiving is the process of storage and
17、protecting records from the possibility of being accessed, further altered or deleted, and storing these records under the control of independent data management personnel throughout the required retention period. Archived records should include, for example, associated metadata and electronic signa
18、tures.归档是存放和保护记录不被访问、进一步修改或删除,以及在所需保存周期内由独 立的数据管理人员存贮和控制这些记录的过程。归档记录应包括例如相关元数据和 电子签名。archivist. 档案保管员An independent individual designated in GLP who has been authorized by managementto be responsible for the managementof the archive, i.e. for the operations and procedures for archiving.在 GLP 内指定的独立个
19、人,由管理人员批准负责档案管理,即归档操作和程序。audit trail. 审计追踪The audit trail is a form of metadata containing information associated with actions that relate to the creation, modification or deletion of GXPrecords. An audit trail provides for secure recording of life cycle details such as creation, additions, deletion
20、s or alterations of information in a record, either paper or electronic, without obscuring or overwriting the original record. An audit trail facilitates the reconstruction of the history of such events relating to the record regardless of its medium, including the “ who, what, when and why ” of the
21、 action.审计追踪是含有GMP 记录创建、修改或删除相关动作信息的元数据表。审计追踪提供生命周期详细情况的安全记录,如电子或纸质记录中信息的创建、增加、删除或 修改,而不会妨碍或改写原始记录。审计追踪有利于重建此类与记录(无论使用何 种介质)有关事件的历史,包括动作的“何人何事何时及因何”。data governance. 数据管理The arrangements to ensure that data, irrespective of the format in which they are generated, are recorded, processed, retained an
22、d used to ensure the record throughout the data life cycle.确保数据(无论其以何种格式生成)在生命周期中被记录、处理、保存和使用的所 有安排。data life cycle. 数据生命周期All phases of the process by which data are created, recorded, processed, modified, transmitted, reviewed, reported, used, approved, archived and restored until destruction.数据被创
23、建、记录、处理、修改、传输、审核、报告、使用、批准、归档和恢复直 到销毁的所有阶段。electronic signatures. 电子签名A signature in digital form (bio-metric or non-biometric) that represents the signatory. This should be equivalent in legal terms to the handwritten signature of the signatory.代表签名人的数字形式签名(生物识别或非生物识别)。电子签名在法律上与手书 签名具有同等效力。good prac
24、tices (GXP). 优良规范(GXP)Acronym for the group of good practice guides governing the preclinical, clinical, manufacturing, testing, storage, distribution and post-market activities for regulated pharmaceuticals, biologicals and medical devices, such as GLP, GCP, GMP, good pharmacovigilance practices (G
25、PP) and good distribution practices (GDP).指导受法规管制药品、生物制品和医疗器械临床前、临床、生产、检测、存贮、运输和上市后活动管理的优良规范,如GLP、GCP GMP优良药物预警规范(GPP和优良运输规范(GDP)。metadata. 元数据Metadata are data that describe the attributes of other data and provide context and meaning and form an integral part of original records. An audit trail re
26、cord is an example of metadata.元数据是描述其它数据属性的数据,它提供语境和含义,形成原始记录不可分割的一部分。审计追踪记录就是元数据例子。raw data (source data). 原始数据(源数据)The original record (data) which can be described as the first-capture of information, whether recorded on paper or electronically.原始记录(数据)可描述为首次捕获的信息,可以是以纸质或电子记录的。routinedata review
27、. 日常数据审核Routine data review is a process where the raw data and metadata are reviewed for their integrity in an individual data set.日常数据审核是审核单个数据系列中原始数据和元数据完整性的过程。periodic data review. 定期数据审核Periodic data review is a process where an audit of the data generated isdone, on a periodic basis (e.g. mont
28、hly), where data are selected on a random basis to verify the effectiveness of existing control measures and identification of the possibility of unauthorised activity at all interfaces 定期数据审核是定期(例如每月)审计该周期中所生成的数据的过程,其中随机选择数据验证现有控制措施的有效性,找出所有界面下未授权活动的可能性。4. PRINCIPLES OF DATA INTEGRITY AND GOOD DOCU
29、MENTATION PRACTICES 整性原则与优良文件规范4.1. There should be a written DI policy.应制订书面DI 方针。4.2. Senior management is responsible for the establishment and implementation of an effective quality system and a data governance system. This applies to paper and electronic generated data.高级管理层有义务建立和实施有效的质量体系和数据管理
30、体系。该要求适用于纸质 和电子生成的数据。4.3. Data should be Attributable, Legible, Contemporaneous, Original, and Accurate (ALCOA) and be Complete, Consistent, Enduring, and Available (+).This is generally referred to as ALCOA+. (There is no difference in expectations regardless of which acronym is used).数据应可追溯、清晰、同步、
31、原始和准确(ALCOA并且完整、一致、持久和可获得 (+)。通常称为ALCOA+ (无论使用何术语,要求没有差别)4.4. The quality system, including documentation such as procedures and formats for recording data, should be appropriately designed and implemented to provide assurance that records and data meet the principles contained in this guideline.质量体
32、系,包括文件记录如记录数据的方法和格式,均应适当设计和实施,以保障记录和数据符合本指南所含原则。4.5. Data governance should address data ownership and accountability throughout the life cycle and consider the design, operation and monitoring of processes/systems to comply with the principles of DI, including control over intentional and unintenti
33、onal changes to data.数据管理应说明数据在其整个生命周期中的所有权和职责,要考虑使流程/系统的设计、运行和监测符合 DI原则,包括控制有意和无意的数据更改。4.6. Data governance systems should include:数据管理系统应包括: training in the importance of DI principles; DI原则的重要性培训; the creation of an appropriate working environment; and 创造适当的工作环境;以及 active encouragement of the rep
34、orting of errors, omissions and undesirable results. 主动鼓励报告失误、遗漏和不合意结果。4.7. Senior management should be accountable for the implementation of systems and procedures in order to minimise the potential risk to DI, and to identify the residual risk using risk management techniques such as the principle
35、s of the International Conference on Harmonisation (ICH) Q9.高级管理人员应对系统和程序实施承担责任,以尽可能降低潜在DI风险,使用风险管理技术如ICH Q9中的原则识别出残留风险。4.8. The data governance programme should include policies and procedures addressing data management. Elements of effective management governance should include:数据管理程序应包括方针和程序用于解决数
36、据管理问题。有效管理的要素应包括:? management oversight and commitment;?管理监督和承诺;? application of QRM;?应用QRM? good data management principles;?优良数据管理原则;? quality metrics and performance indicators;?质量量度和绩效指标;? validation;?验证;? change management;?变更管理;? security and access control;? 安保和访问控制;? configuration control;?
37、参数设置控制;? prevention of commercial, political, financial and other organizational pressures;? 预防商业、政治、经济和其它组织压力;? prevention of incentives that may adversely affect the quality and integrity of work;? 预防可能对工作质量和完整性产生不良影响的激励;? adequate resources, systems;? 充足的资源、系统;? workload and facilities to facilit
38、ate the right environment that supports DI and effective controls;? 工作量和设施有利于正确的环境,可支持DI 和有效控制;? monitoring;? 监测;? record keeping;? 记录保存;? training; and? 培训;以及? awareness of the importance of DI, product quality and patient safety.? 明白 DI 、产品质量和患者安全的重要性。4.9. There should be a system for the regular
39、review of documents and data to identify any DI failures. This includes paper records and electronic records in day-to-day work, system and facility audits and self-inspections.应制订一个体系对文件和数据进行常规审核,以发现任何DI 问题。其中包括日常工作的纸质和电子记录、系统和设施审订以及自检。4.10. The effort and resources applied to assure the integrity
40、of the data should be commensurate with the risk and impact of a DI failure.为确保数据完整性所付出的努力和资源应与DI 失败的风险和影响相称。4.11. Where DI weaknesses are identified, appropriate corrective and preventive actions (CAPA) should be implemented across all relevant activities and systems and not in isolation.如果发现DI弱点,应
41、在所有相关活动和系统中实施适当的CAPA而不是独立处理。4.12. Significant DI lapses identified should be reported to the national medicine regulatory authority.发现严重的DI 问题时应向国家药监机构报告。4.13. Changing from automated or computerised systems to paper-based manual systems or vice-versa will not in itself remove the need for appropria
42、te DI controls.从自动化或计算机化系统改为纸质人工系统或逆向改变时,改变本身并不能消除对适当 DI 控制的需求。4.14. Good documentation practices should be followed to ensure that all records are complete.应遵守优良文件规范以确保所有记录是完整的。4.15. Records (paper and electronic) should be kept in a manner that ensures compliance with the principles of this guidel
43、ine.These include, but arenot limited to:记录(纸质和电子)保存方式应确保符合本指南的原则。其中包括但不仅限于:? restricting the ability to change dates and times for recording events;? 限制对记录事件的日期和时间修改能力;? using controlled documents and forms for recording GXP data;? 使用受控文件和表格记录GXP 数据;? controlling the issuance of blank paper templat
44、es for data recording of GXP activities, with reconciliation;? 控制发放用于记录GXP 活动数据的空白纸张模板;? defining access and privilege rights to automated systems;? 规定自动化系统的访问与权限;? enabling audit trails;? 激活审计追踪;? having automated data capture systems and printers connected to equipment and instruments in productio
45、n and quality control where possible;? 尽可能配备自动化数据采集系统和打印机,连接至生产和质量控制用设备与仪器;? ensuring proximity of printers to sites of relevant activities; and? 确保打印机邻近相关活动场所;以及? ensuring access to original electronic data for personn el responsible for reviewing and checking data.? 确保负责审核和检查数据的人员可访问原始电子数据。4.16. D
46、ata and recorded media should be durable. Ink should be indelible. Temperature- sensitive or photosensitive inks and other erasable inks should not be used, or other means should be identified to ensure traceability of the data over their life cycle.数据和记录介质应可持久。墨水应为不可擦除的。不应使用热敏或光敏墨水和其它可擦写墨水。应识别其它方法,
47、以确保可数据在其生命周期的可追溯性。4.17. Paper should not be temperature-sensitive, photosensitive or easily oxidizable. If this is not feasible or limited, then true or certified copies should be available.纸张不应为热敏、光敏或易于氧化。如果不现实或受到限制,则应获得其真实副本 或认证副本。4.18. Systems, procedures and methodology used to record and store
48、data should be periodically reviewed for effectiveness and updated, as necessary, in relation to new technology.应定期审核用于记录和存贮数据的系统、程序和方法学的有效性并在必要时采用新 技术进行更新。5. QUALITY RISK MANAGEMENT!风险管理5.1. The DIRA should be documented. This should cover systems and processes that produce data or, where data are
49、obtained, data criticality and inherent risks.应记录DIRA。其中应包括生成数据(如得到数据)的系统和流程、数据关键程度和 内在风险。5.2. The risk assessment should include, for example, computerised systems, supporting personnel, training and quality systems.风险评估应包括例如计算机化系统、支持性人员、培训以及质量体系。5.3. Record and DI risks should be assessed, mitigat
50、ed, communicated and reviewed throughout the document and data life cycle.应在记录和数据生命周期中对记录和DI 风险进行评估、缓解、沟通和审核。5.4. Where the DIRA has highlighted areas for remediation, prioritisation of actions (including acceptance of an appropriate level of residual risk) and controls should be documented and comm
51、unicated. Where long-term remediation actions are identified, risk-reducing short-term measures should be implemented to provide acceptable data governance in the interim.如果 DIRA 显示出需要补救的领域,应记录和沟通措施(包括残留风险的可接受水平)与控制的优先等级。如果需要采取长期补救措施,则应实施短期降低风险的措施临时提供可接受的数据管理。5.5. Controls identified may include org
52、anizational and functional controls such as procedures, processes, equipment, instruments and other systems to both prevent and detect situations that may impact on DI. (Examples include appropriate content and design of procedures, formats for recording, access control, the use of computerized syst
53、ems and other means).所识别的控制可能包括组织和功能控制,如程序、工艺、设备、仪器和其它系统用于预防和发现可能影响DI 的情形。(例子包括对在程序中包含适当的内容及进行适当设计、记录格式、访问控制、计算机化系统的使用及其它方式)5.6. Controls should cover risks to data. Risks include deletion of, changes to, and excluding data and results from data sets without written authorisation and detection of th
54、ose activities and events.控制应覆盖数据风险。风险包括未经书面授权从数据系列中删除、修改、排除数据和结果,以及发现这些活动和事件。6. MANAGEMENT REVIEW 评审6.1. Compliance with DI policy and procedures should be reported in the periodic management review meetings.应在定期管理评审会议中报告DI 方针和程序符合情况。6.2. The effectiveness of the controls implemented should be meas
55、ured against the quality metrics and performance indicators.These shouldinclude for example:所实施措施的有效性应采用质量量度和绩效指标进行测量。其中包括例如:? The tracking and trending of data;? 数据追踪与趋势分析;? lapse in DI rates;? DI 问题频次;? review of audit trails in, for example, production, quality control, GLP, case report forms and
56、 data processing;?审核审计追踪,如生产、质量控制、GLP事件报告表和数据处理;? routine audits and/or self-inspections including DI and computerized systems; and? 日常审计和/ 或自检,包括DI 和计算机化系统;以及? DI lapses at outsourced facilities (contract acceptors).? 外包设施内DI 问题(受托方)7. OUTSOURCING 包月艮务7.1. Outsourcing of activities and responsibili
57、ties of each party (contract giver and contract accepter) should be clearly described in written agreements. Specific attention should be given to ensuring compliance with DI requirements.应在书面协议中清楚说明委外活动及各方职责(委托方和合同接受方)。特别要注意确保符合DI 要求。7.2. Compliance with the principles and responsibilities should b
58、e verified during periodic site audits. This should include the review of procedures and data (including raw data and metadata, paper records, electronic data, audit trails and other related data) held by the contracted organization that are relevant to the contract giver s product or services.在定期现场审计中应核查是否符合原则要求和职责规定。其中应包括审核程序和受托方持有的与委托方产品或服务有关的数据(包括原始数据和元数据、纸质记
温馨提示
- 1. 本站所有资源如无特殊说明,都需要本地电脑安装OFFICE2007和PDF阅读器。图纸软件为CAD,CAXA,PROE,UG,SolidWorks等.压缩文件请下载最新的WinRAR软件解压。
- 2. 本站的文档不包含任何第三方提供的附件图纸等,如果需要附件,请联系上传者。文件的所有权益归上传用户所有。
- 3. 本站RAR压缩包中若带图纸,网页内容里面会有图纸预览,若没有图纸预览就没有图纸。
- 4. 未经权益所有人同意不得将文件中的内容挪作商业或盈利用途。
- 5. 人人文库网仅提供信息存储空间,仅对用户上传内容的表现方式做保护处理,对用户上传分享的文档内容本身不做任何修改或编辑,并不能对任何下载内容负责。
- 6. 下载文件中如有侵权或不适当内容,请与我们联系,我们立即纠正。
- 7. 本站不保证下载资源的准确性、安全性和完整性, 同时也不承担用户因使用这些下载资源对自己和他人造成任何形式的伤害或损失。
最新文档
- 2026年服装行业跨境物流成本分析
- 新课标人教A版高中数学选修1-2第二章《2.1.1合情推理》(第1课时)获奖教学设计
- 2026年四川省广汉市《行测》考试笔试题库含答案详解(综合卷)
- 音乐小屋(教案)人音版(2012)音乐二年级下册
- 2025年四川省崇州市《行测》考试备考题库及参考答案详解(新)
- 三年级下册道德与法治教学设计-4我创造我快乐 第一课时 教科版
- 银行数字化科技岗位招聘笔试模拟试题完整版及答案2026年
- 企业网络安全全员培训考试题库(2026年版)
- 核医学技师培训考核试卷(2026年版)
- 活动1 智能生活新奇多教学设计初中信息技术安徽版八年级下册-安徽版2018
- 2026年企业财务管理与审计方案
- 肌间静脉血栓抗凝治疗
- GB/T 10810.5-2025眼镜镜片第5部分:表面耐磨试验方法
- 《复杂系统理论》课件
- 外出参加护理会议后汇报
- T-CTSS 3-2024 茶艺职业技能竞赛技术规程
- 2023年教育部高中技术课程标准
- CJT 340-2016 绿化种植土壤
- 高标准农田改造提升建设项目投标方案(技术标)
- 光学成像技术1-课件
- 实验诊断 第五章 常用肾脏功能实验室检测(2学时)
评论
0/150
提交评论