Compliance, Mapped to Your Cloud

Assess your AWS, Azure, and Google Cloud environments against the industry frameworks and regulations your auditors expect.

56
Frameworks Supported
18
Standards Families
3
Cloud Providers
5 min
To First Results
ASecureCloud compliance report preview
AWS logo

GxP EU Annex 11

15 controls
54 checks mapped

GxP compliance frameworks map cloud safeguards to regulated computerized-system expectations for validated, controlled, and auditable environments.

Controls assessed

1 Risk Management3

Risk management should be applied throughout the lifecycle of the computerised system taking into account patient safety, data integrity and product quality. As part of a risk management system, decisions on the extent of validation and data integrity controls should be based on a justified and documented risk assessment of the computerised system.

5 Data18

Computerised systems exchanging data electronically with other systems should include appropriate built-in checks for the correct and secure entry and processing of data, in order to minimize the risks.

7.1 Data Storage - Damage Protection38

Data should be secured by both physical and electronic means against damage. Stored data should be checked for accessibility, readability and accuracy. Access to data should be ensured throughout the retention period.

7.2 Data Storage - Backups18

Regular back-ups of all relevant data should be done. Integrity and accuracy of backup data and the ability to restore the data should be checked during validation and monitored periodically.

8.2 Printouts - Data Changes2

For records supporting batch release it should be possible to generate printouts indicating if any of the data has been changed since the original entry.

9 Audit Trails2

Consideration should be given, based on a risk assessment, to building into the system the creation of a record of all GMP-relevant changes and deletions (a system generated 'audit trail'). For change or deletion of GMP-relevant data the reason should be documented. Audit trails need to be available and convertible to a generally intelligible form and regularly reviewed.

10 Change and Configuration Management1

Any changes to a computerised system including system configurations should only be made in a controlled manner in accordance with a defined procedure.

12.4 Security - Audit Trail2

Management systems for data and for documents should be designed to record the identity of operators entering, changing, confirming or deleting data including date and time.

13 Incident Management5

All incidents, not only system failures and data errors, should be reported and assessed. The root cause of a critical incident should be identified and should form the basis of corrective and preventive actions.

16 Business Continuity19

For the availability of computerised systems supporting critical processes, provisions should be made to ensure continuity of support for those processes in the event of a system breakdown (e.g. a manual or alternative system). The time required to bring the alternative arrangements into use should be based on risk and appropriate for a particular system and the business process it supports. These arrangements should be adequately documented and tested.

17 Archiving18

Data may be archived. This data should be checked for accessibility, readability and integrity. If relevant changes are to be made to the system (e.g. computer equipment or programs), then the ability to retrieve the data should be ensured and tested.

4.2 Validation - Documentation Change Control1

Validation documentation should include change control records (if applicable) and reports on any deviations observed during the validation process.

4.5 Validation - Development Quality1

The regulated user should take all reasonable steps, to ensure that the system has been developed in accordance with an appropriate quality management system. The supplier should be assessed appropriately.

4.6 Validation - Quality and Performance1

For the validation of bespoke or customised computerised systems there should be a process in place that ensures the formal assessment and reporting of quality and performance measures for all the life-cycle stages of the system.

4.8 Validation - Data Transfer19

If data are transferred to another data format or system, validation should include checks that data are not altered in value and/or meaning during this migration process.

See where you stand against any framework

Connect an account and get a full compliance breakdown with mapped findings and remediation guidance — free to start.