Verification vs Validation, and Grandfather Rights
The beautifully complex world of validation. Installation qualification (IQ), operational qualification (OQ), performance qualification (PQ), process validation, system validation - What about Verification? What does it all mean?
Overwhelming, right?
Verification - Is an examination with objective means so that specific (product) properties are fulfilled. These (product) properties or characteristics can be found, for example, in a System Requirements Specification (SRS). An example is that a tension is supposed to be x and you verify that through your user interface.
An example of when you couldn’t verify is Sterilisation, this could be done, however, it would require destructive testing and you wouldn’t have any product left 🤷🏽♂️
Enter validation…
Validation - Is a series of activities that utilises protocols to ensure that processes within a Quality Management System (QMS) are capable of consistently and repeatedly producing results.
Sterilisation example - Since destructive testing is not possible in your sterilisation process, validation must be used to ensure that the process consistently and satisfactorily sterilises product.
How to validate?
Identify critical processes
Define what can be verified or validated
Write a Master Validation Plan - A master validation plan should detail all of the processes requiring validation as well as a schedule for doing this.
Create a validation matrix - this details all key equipment, systems, processes etc., and enables you to understand the interrelationships. See our example below as a guide.
Get protocol writing - This is where you develop your methods of how you are going to validate
Check out the additional information section for the Global Harmonisation Task Force (GHTF) guidance, this is the most recognised guidance on validation around.
➕ Additional Information: GHTF guidance
Grandfather Rights
Summary
This may be called alternatives, such as legacy or historic.
What we’re referring to is when a Quality system is implemented with new supplier or employee controls such as additional audits or training etc., there is retrospective activity required but a method exists and we call this grandfather rights.
Let’s use an example to go through Grandfather rights.
Organisation A produce Product B and have done for many years. A main supplier they are using is Supplier C.
Under their new quality system, all suppliers shall have certain levels of quality system certification etc., all that good stuff.
However, Supplier C do not have any of this and nor do they have any intention of doing so. Do Organisation A have to exit? Absolutely not.
Providing they are able to demonstrate that Supplier C has historically had a low level of issues, or that they have a level of control in place i.e. quality agreements, regular audits etc., in place with them to ensure product quality does not falter, they can put a Note to File (NTF) against Supplier Cs profile exempting them from the new supplier management protocols.
This cannot be a blanket approach, and as an auditor this is something we look out for. If you are using grandfather rights all over your system, without any logical rational or risk based thinking as a basis for doing so, you are opening yourself up to some severe scrutiny.
➕ Additional Information: Put a clause in the relevant procedure around grandfather rights and link it to the profile of whoever or whatever you are claiming exemption from.