Showing posts with label FDA. Show all posts
Showing posts with label FDA. Show all posts

Learn From FDA & MHRA GMP Inspection Observations

A comprehensive GMP intelligence program includes monitoring of enforcement actions, including FDA form 483s, warning letters, recalls, import alerts, consent decree agreements, EU reports of GMDP noncompliance, and inspection summaries published by selected European health authorities. This article presents the most recent GMP inspection data from CDER and MHRA (Medicines and Healthcare Products Regulatory Agency).  The CDER data and the MHRA data come from GMP inspections conducted in 2016.

The CDER drug inspection observations supplement the information we published in a previous article regarding CDER drug GMP warning letters from the same time interval.  The analysis herein includes data from the FY2016 form 483 observations and compares results with those from the three previous fiscal years. Raw data comes from the FDA website, though it is presented in a different manner. For example, I have combined the frequencies of all observations that cite 21 CFR 211.192 into a single value. In the FDA data, there are multiple line items for 211.192, each with a different frequency.  For example, in the FDA listing the most frequently cited item is 211.22(d), procedures not in writing, fully followed.  When you combine the full collection of times that 211.192 and 211.42(c) are cited, however, they become tied for No. 1, with 211.22(d) becoming the third most frequent citation.  FDA uses the term “frequency” which seems to be the number of times a given citation was identified in the form 483 collection supporting these data. 

Only form 483s that were issued through the Turbo EIR (Establishment Inspection Report) system are considered in this data, which provides a distinct limitation.  No form 483s issued to API manufacturers or issued outside of the Turbo EIR system are included. This becomes important to consider with FDA’s increased focus on API manufacturers, particularly outside the U.S.   MHRA data is similar and only includes deficiencies identified at dosage form manufacturers.  Note that the MHRA data includes only the 10 most frequently cited groups, whereas the data on the FDA website includes all observations. 

Here are some highlights of the analysis:

FDA:

The number of form 483s included in this analysis remains reasonably constant over the past four fiscal years even though it does not represent all drug inspections conducted by the FDA, particularly inspection of sites that manufacture APIs.

Deficiencies in investigations remains at the top of this list over the past four years.  We as an industry cannot seem to get this quite right.
In general, the regulations cited and their relative order has remained reasonably constant over the past four fiscal years.  Even though a few items have changed place, none of the numbers are striking.

MHRA:

MHRA issued 143 “critical” deficiencies, in a total of 324 inspections of which 82 inspections (25 percent) were overseas inspections and 242 inspections (75 percent) were conducted in the U.K.
The EU GMP Guide Chapters and Annexes that were cited in critical observations include, in order of their frequency: Chapter 1, Annex 1, Chapters 5, 8, Annex 15, Chapter 3, Annex 11, Chapter 2, Chapters 4 and 6.  
The MHRA cited a total of 4,588 deficiencies in the 10 areas that received the critical observations.  Critical deficiencies constituted 3 percent of the total.
The sections that follow include more detailed discussion of the observations.

FDA Form 483 Inspection Observations

The following data is based on inspections generated using the FDA Turbo-EIR system.  The number of form 483s remained quite similar over the four years in question, with FY2014 having the fewest.  Form 483s issued to API manufacturers or issued outside of the Turbo EIR system are not included.

Table 1 shows only the most frequent group of inspection observations; the tabulation on the FDA website shows all observations.  Table 1 is organized in the order of those observations with the highest to lowest frequency for 2016.  In several instances, though, the order of the observations did change in FY2016 from previous years; these are highlighted in gray. 

Table 1: Inspection Observations Issued Through Turbo-EIR System per Fiscal Year. (These are shown in the order of highest to lowest for FY2016.)


Figure 1 below shows the data from Table 1 graphed over four fiscal years, 2013–2016.  While there is some variation from year to year, the frequency with which specific regulations are identified remains generally constant.  Figure 2 shows additional detail of several of the areas where the frequency of the observation did show some variation between FY2015 and FY2016.


Figure 1: Frequency of observations


Figure 2: Selected observation frequency

In conclusion, there is little change in the overall frequency of inspection observations, as characterized by the regulation cited, between FY2013 and 2016. This may have been different if all inspected sites, including API sites, had been included in the metrics. The three most frequent observations in FY2016 cite 211.192 (investigations), 211.42(c) (design of facilities to prevent cross contamination), and 211.160(b) (scientifically sound specifications). While 211.192 was in first place for all four fiscal years, in 2016 it tied with 211.42(c), Requirement for adequate facilities to prevent contamination or mix-ups, moved up from third place, even though the actual number of those observations decreased from 2015. Citations against 211.160(b) Development of scientifically sound specifications went from second place to fourth place. Observations citing 211.113(b) Validation of aseptic processes including sterilization dropped from fifth place to sixth place in 2016, and the actual number decreased significantly, to FY2013 levels. Finally, observations identifying 211.25(a) Staff shall have training, education and experience to perform their jobs dropped from eighth place to 10th place in 2016. 

MHRA Inspection Deficiencies

I won’t reproduce the graphics from the MHRA slide deck, but I do recommend reading those because they contain a wealth of information at a granular level. The MHRA conducted a total of 324 inspections in 2016; 242 inspections were conducted in the U.K. and 82 inspections were conducted overseas. The MHRA inspections identified 143 total “critical” deficiencies in 2016, a dramatic increase from 2015 when 51 were identified. We cannot compare this with the U.S. FDA inspection observations because the FDA does not classify the criticality of observations. In the future, perhaps health authorities will adopt a common classification category for inspection observations.

MHRA identified critical deficiencies in only five areas in 2015, and increased this to 10 areas in 2016. Several categories saw significant increases, for example:

  • Sterility Assurance had no critical observations in 2015 and 34 in 2016
  • Personnel had no critical observations in 2015 and eight in 2016
  • Premises and Equipment had no critical observation in 2015 and nine in 2016
  • Computerized Systems had one critical observation in 2015 and nine in 2016.

Table 2 identifies the areas with critical deficiencies identified in 2016. The groups included seven Chapters and three Annexes. Figure 3 clearly shows that approximately two-thirds of the deficiencies are included within three groups: Quality Systems, Sterility Assurance, and Production.

Table 2: Chapters and Annexes Associated with MHRA Critical GMP Inspection Deficiencies in 2016



                          Figure 3: Distribution of these critical MHRA deficiencies


Conclusions:

It is difficult to directly compare areas identified by the MHRA with those identified by the FDA, as the FDA does not categorize the criticality of inspection observations as do the MHRA and other health authorities. We can, however, say that with FDA observations addressing “investigations” at the top of the list, “quality unit responsibilities” third on the list, and “staff training” at No. 10, quality systems is a high priority for the FDA. Similarly, Quality Systems is the area with the most critical deficiencies identified by the MHRA in 2016. Validation of aseptic processing (21 CFR 211.113(b)) was sixth on the FDA list but was second on the list for MHRA.

Computer system requirements are identified in Annex 11, Computerized Systems. Data integrity and data governance deficiencies are identified by MHRA by citing either Chapter 4 or Annex 11, both of which were associated with critical deficiencies in 2016. Similar FDA regulations are found in 21 CFR 11, Electronic Records; Electronic Signatures, and it is rarely, if ever, identified in either form 483s or warning letters. The FDA frequently associates these types of inspection observations with predicate rules including 21 CFR 211.68(b) and 21 CFR 194.


MHRA has always had a reputation as one of the most rigorous health authority inspectorates. It seemed to have upped its game in 2016, as demonstrated by an increase in the number of critical deficiencies, along with an increase in the total number of deficiencies identified for essentially the same number of inspections.

Both agencies will likely continue to focus on sterility assurance, investigations, quality systems, and data integrity/governance in 2017. It would be interesting to see if the number and types of observations identified during API inspections were similar for the two health authorities. And finally, the Mutual Recognition Agreement (MRA) between FDA and the European Medicines Agency will likely not impact the number of inspections for 2017, though it may be possible to see that happen in 2018. Time will tell how this impacts the number and locations of both EMA and FDA inspections.


References:



Barbara Unger



Surveying The Current Regulatory Landscape regarding Data Integrity

Failures in data integrity break the essential trust that regulators have with manufactures of medicinal products. Regulatory authorities cannot review all the data that firms generate during the development and commercial lifecycle of every drug. Even during inspections, they review only a small fraction of the data generated. When regulators find that companies have falsified or manipulated electronic or paper data to achieve passing results — or have failed to document and investigate failing results — they lose confidence in all the data presented by the firm, a conclusion with devastating financial consequences.
Data integrity has been the subject of many recent industry trade group meetings involving speakers from the world’s major regulatory authorities, including FDA. The topic, however, is not new and has been the cited in FDA enforcement actions dating back to 1999. The Able Laboratories Form 483 in 2005 created a new level of awareness of data integrity within the industry. Shortly thereafter, the story of Ranbaxy Laboratories and its data integrity deficiencies became the subject of enforcement actions brought about by a whistle blower. And data integrity failures continue to be cited in form 483s and warning letters to this day — with increasing incidence. For companies in India and China, such failures often result in the firm being placed on import alert, which has significant financial ramifications.
In this article, we will review recent regulatory actions related to the highly visible topic of data integrity. First, we will look at data integrity deficiencies cited in FDA warning letters issued between FY 2013 and FY 2015, to sites both inside the U.S. and outside it. Second, we will move to the recently published FDA draft guidance on data integrity, which takes a markedly different approach from the MHRA and WHO guidances, even though FDA has been a leader in enforcement actions in this area for the last 15 years. Finally, we will address the finalized version of the WHO guidance on the topic.
The goal is to provide perspective on the current enforcement environment in the U.S. and abroad. The FDA, WHO, and the EMA have taken enforcement actions on a global basis. Unfortunately, the pharmaceutical industry does not seem to fully appreciate the seriousness with which regulators take these deficiencies, and it has not implemented the corrective and preventive actions necessary to correct these failures.
Data Integrity Deficiencies In FDA Warning Letters
Table 1 shows the number of warning letters issued to firms inside and outside the U.S. (OUS) over the last three FDA fiscal years, excluding those issued to compounding pharmacies. Data integrity deficiencies, including those cited in warning letters, identify the predicate rule(s) to which firms did not adhere — none cite 21 CFR Part 11. Note that even though the total number of warning letters decreased during the time period, the percent that addressed data integrity increased. Figure 1 provides a graphical representation of the data.
Table 1: Data Integrity Deficiencies in FDA Warning Letters (WLs), FY2013-2015
Most data integrity deficiencies addressed in the warning letters focused on the lack of controls over laboratory instrument associated computers/software or failure to contemporaneously record data. The warning letter issued to Sun Pharmaceuticals in early FY2016 (deficiency #6) focuses on manufacturing instrumentation-associated software and computer systems. While related deficiencies have occasionally been identified in past warning letters, the clarity of focus in this deficiency may represent an approach that inspectors will take in moving forward. Watch for more instances of this trend in FY2016, as FDA likely expands its scope to include additional manufacturing floor computer systems.
Several of the warning letters from FY2015 included requirements that approached consent decree-like requirements. Examples may be found in the warning letters issued to: Micro Labs Limited, Apotex Research Private Limited, Hospira Spa, Yunnan Hande Bio-Tech Ltd, and Cadila Healthcare Limited. (For more information on — and links to — these and other FY2013-2015 warning letters, see An Analysis Of Recent CDER Observation & Warning Letter Data.) This text has been refined over the past few years and increased in scope and granularity last year. Currently, the following text appears to be the boiler-plate requirements that FDA includes in instances where serious data integrity deficiencies are identified.
  1. A comprehensive investigation into the extent of the inaccuracies in data records and reporting. Your investigation should include:
    • A detailed investigation protocol and methodology; a summary of all laboratories, manufacturing operations, and systems to be covered by the assessment; and a justification for any part of your operation that you propose to exclude.
    • Interviews of current and former employees to identify the nature, scope, and root cause of data inaccuracies. We recommend that these interviews be conducted by a qualified third party.
    • An assessment of the extent of data integrity deficiencies at your facility. Identify omissions, alterations, deletions, record destruction, non-contemporaneous record completion, and other deficiencies. Describe all parts of your facility’s operations in which you discovered data integrity lapses.
    • A comprehensive retrospective evaluation of the nature of all data integrity deficiencies. We recommend that a qualified third party with specific expertise in the area where potential batches were identified should evaluate all data integrity lapses.
  2. A current risk assessment of the potential effects of the observed failures on the quality of your drugs. Your assessment should include of the risks to patients caused by the release of drugs affected by a lapse of data integrity, and risks posed by ongoing operations.
  3. A management strategy for your firm that includes the details of your global corrective action and preventive action plan. Your strategy should include:
    • A detailed corrective action plan that describes how you intend to ensure the reliability and completeness of all of the data you generate, including analytical data, manufacturing records, and all data submitted to FDA.
    • A comprehensive description of the root causes of your data integrity lapses, including evidence that the scope and depth of the current action plan is commensurate with the findings of the investigation and risk assessment. Indicate whether individuals responsible for data integrity lapses remain able to influence CGMP-related or drug application data at your firm.
    • Interim measures describing the actions you have taken or will take to protect patients and to ensure the quality of your drugs, such as notifying your customers, recalling product, conducting additional testing, adding lots to your stability programs to assure stability, drug application actions, and enhanced complaint monitoring.
    • Long-term measures describing any remediation efforts and enhancements to procedures, processes, methods, controls, systems, management oversight, and human resources (e.g., training, staffing improvements) designed to ensure the integrity of your company’s data.
    • A status report for any of the above activities that are already underway or completed.
Completion of these activities will not happen quickly and will take a concerted effort on the part of the firms involved.
FDA Draft Guidance on Data Integrity
In April 2016, the Federal Register announced availability of the long-awaited 10-page FDA draft guidance on Data Integrity and Compliance with CGMP for comment. For comparison, you can review MHRA GMP Data Integrity Definitions and Guidance for Industry (March 2015) and WHO'sAnnex 5: Guidance on Good Data and Record Management Practices (May 2016), the latter of which I will explore in more detail below.
The FDA draft guidance is structured in a Q&A format with a total of 18 questions. It focuses heavily on identifying and citing the predicate rules as they apply to electronic records and data integrity, and for this it is an excellent reference. However, it provides little insight into FDA’s intent and actual expectations in this area.
We all read guidance documents to identify regulators’ expectations and actions we might take to ensure compliance. This one, in particular, was anticipated for over two years and addresses FDA’s leadership in enforcement actions over the past 10+ years. Perhaps I had unrealistic expectations, but requirements and expectations in this area can be more easily discerned from a careful reading of warning letter deficiencies and form 483 observations than from reading this draft guidance.
Following are some the areas that I hope are addressed as part of the comment process and revised in the final guidance:
  • The guidance fails to address the concept of lifecycle for either computer systems or data. In fact, the term “lifecycle” is not found in the document, even though it is a concept central to the FDA’s guidance on process validation and is also central to associated ICH quality guidelines.
  • The guidance does not address an expectation for a risk based data governance process andperiodic evaluations of effectiveness of the program to prevent, detect, and remediate data integrity issues. Frequently, FDA warning letters that identify data integrity failures require development of a management strategy to investigate the scope of the shortcoming, including impact on product quality and patient safety, and to address how such failures will be prevented, identified, and remediated in the future. In short, the firm that receives a warning letter must describe a data governance program and a data integrity plan. An example of this requirement is provided at the end of the warning letter recently issued to Emcure Pharmaceuticals.
  • Question 16 states that personnel should be trained to detect data integrity issues. While it seems appropriate that all staff should be trained on the concepts and importance of data integrity to ensure product quality and patient safety, it seems excessive and impractical that ALL personnel should be trained to detect data integrity issues. Data reviewers, particularly those that review electronic data, and audit staff should receive special training in the area of detecting data integrity shortcomings. Training for each functional area needs to reflect the roles and responsibilities performed by the staff.
  • FDA invites individuals to report suspected data integrity issues…” and provides an email address to which such communications should be sent. It seems most unusual for FDA to directly solicit what is effectively whistleblower activity in a guidance document. I am not saying this is inappropriate, just that it's unusual.
  • With regard to definitions, the guidance does not differentiate between the terms ”back-up” and ”archive” as they relates to electronic records. It would also be ideal if the definitions were harmonized with the two existing guidances.
For now, we await industry and trade group comments, and look forward to the final guidance.
WHO Final Guidance on Good Data and Record Management Practices (Annex 5)
Annex 5 was published as part of the publication of the WHO Technical Report Series No. 996 in May 2016, and represents a finalization of a draft document published for comment in September 2015. WHO initiated work in this area during a meeting in Geneva in April 2014.
Changes from the draft of September 2015 are primarily in reorganization of content and the addition of Appendix I, titled Expectations and examples of special risk management considerations for the implementation of ALCOA (-plus) principles in paper-based and electronic systems. The annex includes the tabulation of information on electronic and paper records, and examples of special risk management considerations that previously were included in a tabulation within the draft guidance. Content has also been expanded in both the appendix and in the document overall, increasing the length of Annex 5 by 10 pages over the 2015 draft.
Following are the changes between the 2015 draft guidance and the finalized 2016 Annex 5. This does not include minor changes in wording or reorganization of the same information. I think it’s impressive that this few changes were made to a document that is 46 pages long.
  • Section 2.3 in Aims and Objectives of the Guidance is new.
  • The ALCOA-plus entry in the glossary is new.
  • The archivist entry in the glossary is new.
  • The audit trail entry in the glossary is expanded.
  • The control strategy entry in the glossary is new.
  • The corrective and preventive action entry in the glossary is new.
  • The good data and record management practices entry in the glossary is new and reflects the new term for good documentation practice.
  • The quality metrics entry in the glossary is new.
  • Section 4.6 Management Governance is expanded.
  • Section 4.7 Quality Culture is expanded.
  • Section 4.12, providing examples of record keeping methodologies and systems, is expanded.
  • Section 4.13, describing durability of data and record media, is new.
  • Section 6.4 under Management Governance and Quality Audits is expanded.
  • Section 7.2 under Contracted Organizations, Suppliers and Service Providers is expanded.
  • Section 7.6 under Contracted Organizations, Suppliers and Service Providers is new. This section addresses expectations where data and document retention is contracted to a third party.
  • Sections 11.7 and 11.8 on Data Processing are new.
  • Sections 11.15 and 16 on Data Retention and Retrieval are new.
Conclusion
The use of computerized systems in our industry provides great advantages in efficiency and ease of documentation. Failure to correctly configure and validate the systems — along with a small number of firms who have purposefully manipulated the data — has ensured that FDA and other regulatory authorities will continue to focus on this area. It is interesting that the same deficiencies continue to be cited, year after year; industry does not seem to have gotten the message yet. But thanks to specialized meetings held by trade groups like PDA and ISPE, the industry may finally start to gain a better understanding of how essential data integrity is to the manufacture of safe and efficacious products. We need to reach a state where regulators can have confidence in the validity and accuracy of the data on which drugs are approved and released for commercial distribution. In this effort, every member of every pharmaceutical company has an important role to play.
About The Author
Barbara Unger formed Unger Consulting, Inc. in December 2014 to provide GMP auditing and regulatory intelligence services to the pharmaceutical industry. She has extensive expertise in this area having developed, implemented, and maintained the GMP regulatory intelligence program for eight years at Amgen Inc. This included surveillance, analysis, and communication of GMP related legislation, regulations, guidance, and industry compliance enforcement trends. Barbara was the first chairperson of the Rx-360 Monitoring and Reporting work group (2009 to 2014) that summarized and published relevant GMP and supply chain related laws, regulations, and guidance. She also served as the chairperson of the Midwest Discussion Group GMP-Intelligence sub-group from 2010 to 2014.
Before Amgen, Barbara worked for the consulting firm Don Hill and Associates, providing regulatory and quality services to the pharmaceutical industry, and for Eli Lilly and Company in quality and CMC regulatory affairs positions. She began her career in the pharmaceutical / device industry with Hybritech Inc. and received a bachelor's degree in chemistry from the University of Illinois at Urbana-Champaign.

FDA's First Draft Guidance Under DSCSA

On June 10th, the long-awaited first draft guidance under the DSCSA was released by the FDA. For those holding high expectations that the guidance would offer specific direction on how to handle suspect/illegitimate products internally, you may come away feeling a little shortchanged. However, in the past, the FDA has come under scrutiny for using guidance to replace rule making, since this requires legislative involvement, so the lack of detail in the draft may be an effort to make room for flexibility that industry felt they weren’t getting before.

Whatever the intent, the draft guidance does provide some learning opportunities and also a very subtle call to action. I recently spoke with David Colombo and Dawn Wang with KPMG Life Sciences Advisory to find out what can be learned from this draft and where we go from here.

What We Can Learn:

As stated on page four of the Draft Guidance for Industry: Drug Supply Chain Security Act Implementation: Identification of Suspect Product and Notification, the document is “intended to aid trading partners (manufacturers, repackagers, wholesale distributors, or dispensers) in identifying a suspect product and terminating notifications regarding illegitimate product.” Since these terms and their definitions were already defined in the legislation, it would seem that the other piece to be provided would be how a company would investigate and handle them. This is a major area where the draft falls short. There is no detail around what these internal processes should look like; however, this is where Colombo and Wang say this room for interpretation should encourage action on behalf of all trading partners.


Dave Colombo, KPMG Life Sciences Advisory

In most organizations, the quality group will already have standard operating procedures (SOPs) outlining the internal processes around product investigations, complaints, “suspect” or “illegitimate” products, as well as corrective and preventative action (CAPA) responses. Matching terms used in these existing processes with those used in the regulation allows a company to then assess which definitions need edited in order to align with the FDA’s terms and definitions. “If an organization hasn’t formally established terms that align with the definitions provided under the DSCSA, then those need to be addressed. In the case that terms have been established, they will need to be reviewed to ensure that any overlaps or conflicts in the interpretation can be addressed,” says Colombo.

“As an example, in the past, an organization may use different SOPs to respond to stolen versus counterfeit products. Under the DSCSA, the definition of suspect and illegitimate can apply in cases identified across various SOPs and will now require standard ways of quarantining, reporting, and dispositioning of the product,” adds Wang about the draft and the process it outlines for reporting illegitimate products through the new Form 3911, which must occur no later than 48 hours after determining that a product is indeed illegitimate. “Fortunately, the guidance provides some clarity to the piece on notifying and reporting to authorities, if not to the piece on the coordination with trading partners. The nature of relationships with trading partners, though, is quite different than that with authorities, so it may be good to keep the definition of business relationship processes out of scope of the guidance. Organizations are starting with baseline SOPs to build off of and will just need to examine the elements of the law and guidance to make sure they are all tied in.” Part of updating these procedures includes making sure that outdated pedigree legislation is not mentioned in any existing SOPs. This would include state laws that were preempted by the passing of the DQSA, or soon-to-be-outdated legislation, such as the Prescription Drug Marketing Act (PDMA), which is going to be sunsetted as of January 1st, 2015.

Not only is it important to identify the definition of a “suspect” and “illegitimate” products (which is done in the legislation itself), but it’s also important to be aware of situations when there is a heightened risk for a suspect product to enter the pharmaceutical supply chain. While it is stated it is not an exhausted list, the draft guidance does offer possible scenarios industry should be aware of when: engaging with trading partners and product sourcing that put the product at risk; dealing with a product that is vulnerable based on its supply, demand, history, and value, and/or a product that has suspicious form or packaging.

What We Still Need To Know:

As indicated in the legislation, the suspect product must be put in quarantine to prevent it from being shipped. Once this is done, the first step is to make sure the expiration date on the product and the relevant transaction data, which is the transaction associated with the lot number, have the right association. As previously stated, the company must provide these materials within 24 hours or a maximum of 48 (if the notification of verification request occurred over the weekend) and then complete an investigation and report the results to the FDA. If you’ve determined the product does not actually seem to be suspect, when can the quarantine end and shipping resume? While this is not clearly identified in the draft, Wang says having the lot-level data at your fingertips will allow for a quicker investigation, which should reduce the amount of time any product is under quarantine. “The intent of the requirements on product verification within the law is to make lot-level product date more readily available in order to aid stakeholders to identify or clear suspect and illegitimate product. With this data, stakeholders should be able to more accurately define the impact of the suspect or illegitimate product, and reduce the amount of time a product sits in quarantine.”

Also, many questions still swarm around what should happen if an illegitimate product is found. Does the entire lot have to go back to the manufacturer, does it all have to be destroyed, or does a company just continue what they would do in the situation of a theft or a counterfeit? Like any draft guidance, the FDA is soliciting comments from interested stakeholders for 60 days from the date of publication. It is through these comments where good discussions and thoughts may drive an industry standard, even if the FDA doesn’t necessarily do something tangible with those that are submitted. Additionally, keeping an eye on information coming from organizations, such as the Healthcare Distribution Management Association (HDMA) or the Pharmaceutical Distribution Security Alliance (PDSA), may prove beneficial if the FDA coordinates behind the scenes efforts with these organizations to fill in the gaps through suggested best practices. “Most stakeholders understand that the FDA, industry associations, and standards organizations have different roles and areas of expertise when it comes to defining requirements versus issuing technical guidance or implementation methods. Industry stakeholders will apply the requirements to specific scenarios that are applicable to them. One example of this is that HDMA is planning to release its interpretation of the types of transaction scenarios that occur in the distribution chain, and what data elements are required to be sent and received in each of those cases,” explains Wang.

Although the ambiguity of the guidance leaves many unanswered questions, the fact that the FDA is allowing stakeholders to develop their own processes should be embraced as something positive. A trust is building between the industry and the regulators that has resulted in some level of independence, and it’ll be interesting to see how this develops as the remaining milestones in the DQSA play out over the next 9 ½ years. Not just domestically but internationally, we are attempting to take back the supply chain from the vulnerability it’s been exposed to for so long and protect the patients who trust us to do. The commitment from the FDA to release the guidance this month as promised (even if it is a little late) shows that the effort is well underway.

FDA Guidance :Contract Manufacturing Arrangements for Drugs: Quality Agreements

Last year, FDA published its draft guidance, officially titled “Contract Manufacturing Arrangements for Drugs: Quality Agreements”. Here are some of the highlights.

First, a Quality Agreement between a Sponsor and Contract Manufacturer has never been, nor is it now, explicitly required by FDA regulations. However, responsibilities and procedures of the each company’s respective Quality Units are required to be documented, so a Quality Agreement that outlines the responsibilities of each company is a logical next step. Note that “Contract Manufacturer” refers to any Contracted Facility that provides some or all manufacturing services, including processing, packing, labeling, holding, or testing.

In Europe, Sponsors (or, in the vernacular of the draft guidance, “Owners”) can outsource the final product release/rejection of finished goods for distribution. In the US, sponsors always assume this responsibility and cannot delegate or outsource it.

Because Contracted Facilities often provide services to multiple Sponsors, FDA advises that special consideration be given to reporting information about objectionable conditions.  Sponsors may wish to require that their Contracted Facilities make them aware of manufacturing deficiencies that may impact their products, even if the deficiencies were observed during an inspection of another Sponsor’s product.  (Note, our consultants also suggest that the Quality Agreement require that a Contracted Facility notify its Sponsor whenever the FDA inspects the facility.  The name of the inspected product and its Sponsor would be kept confidential, but this reporting of inspections tells a Sponsor how often FDA visits the site.)

FDA acknowledges that processes can change at both Sponsor and Contracted Facility companies for a variety of legitimate reasons, so communicating changes between the two companies should be discussed in the Quality Agreement. Examples include additional products brought into the line/facility, changes to key personnel and suppliers, and changes resulting from stability studies, process improvement projects, investigations into manufacturing deviations, out-of-specification results, customer complaints, recalls, or adverse event reports.

Finally, a Quality Agreement does not exempt Contracted Facilities from CGMP compliance. Regardless of the allocation of responsibilities in the Quality Agreement, the Contracted Facility cannot essentially agree to manufacture under non-CGMP conditions. Both companies could be held responsible – the Contract Manufacturer for the non-compliance, and the Sponsor for lack of oversight. FDA provided a few examples:
The Contracted Facility receives a Warning Letter for deficient maintenance of facilities and equipment. The Quality Agreement specifies the Sponsor is responsible for this, yet the Owner has failed to provide the requisite resources or carry out the necessary upgrades and maintenance, and the Contracted Facility has continued to operate under non-CGMP conditions. (Possible course of action: the Contracted Facility could bear the costs of modifying operations in order to maintain CGMP compliance, and then seek redress from the Sponsor later.)

Batch records do not match the manufacturing process of adding reclaimed powder, but the Contracted Facility claims that this is just as the Sponsor specified. (Possible course of action: the Contracted Facility could refuse to carry out the additional manufacturing step without including it in the batch record).
The draft guidance concludes by noting that “Owners and Contracted Facilities can draw on quality management principles to carry out the complicated process of contract drug manufacturing by defining, establishing, and documenting the responsibilities of all parties involved in drug manufacturing, testing, or other support operations.”

By Laurie Meehan, Polaris Compliance Consultants, Inc.