Chemical SOP
Microbiology SOP
Warehouse SOP
Manufacturing SOP
Information technology SOP

DESKTOP POLICY FOR ANALYTICAL INSTRUMENT SOFTWARE’S

Brief Description

This SOP establishes a controlled desktop security policy for computers used with Quality Control analytical instruments such as HPLC and FTIR. Its objective is to protect instrument computers, regulated data, software, and network resources from unauthorized access, alteration, loss, or misuse. The procedure assigns responsibility to IT personnel for implementation and administration and to the QC Manager for effective control within applicable QC areas. The SOP defines key security controls including password protection, local network control, domain logon, control-panel restrictions, antivirus protection, and controlled user privileges. It further restricts domain users from accessing the Task Manager, changing system date and time, or using USB/media devices without authorization. The procedure also requires data backup and restoration controls and limits creation, deletion, or modification of domain users to the domain administrator. An annexure provides a controlled format for user ID creation/deletion requests, with QC approval, IT execution, and QA verification.

Skip to PDF content

1. Flow Diagram:

The flow diagram illustrates the systematic implementation of the Desktop Policy for Analytical Instrument Software used on Quality Control instrument computers such as HPLC and FTIR systems. The process begins with identification of the applicable QC instrument computer, followed by implementation of essential desktop security controls. These controls include password protection, local network control, domain logon, control-panel restrictions, antivirus protection, and controlled user privileges to protect analytical data and prevent unauthorized system changes.

User privileges are restricted for sensitive functions such as Task Manager, system date and time, USB access, backup/restore activities, and user-account management. When creation or deletion of a user ID is required, an authorized request is submitted, reviewed by QC, executed by the IT administrator, and verified by QA. The process concludes with continued monitoring of access control, antivirus status, data protection, and overall compliance to ensure the security and integrity of QC analytical computer systems.

2. Brainstorming for SOP Failure:

The brainstorming diagram identifies the major possible causes that can lead to SOP failure in a pharmaceutical manufacturing area. The central issue, “SOP Failure in MFG Area,” is surrounded by contributing factors such as inadequate training, non-availability or outdated SOPs, high workload and production pressure, poor supervision, equipment or facility problems, communication gaps, inadequate documentation, human factors, and weak compliance monitoring.

The diagram also highlights behavioral causes such as carelessness, complacency, intentional bypassing of procedures, insufficient awareness of quality consequences, and poor workplace conditions. These factors may result in product quality risks, regulatory non-compliance, batch rejection, increased cost, production delays, potential patient-safety concerns, and damage to company reputation. Overall, the brainstorming exercise is intended to help cross-functional teams identify potential root causes of SOP non-compliance, prioritize areas requiring investigation, and develop appropriate corrective and preventive actions to strengthen SOP implementation and GMP compliance.

3. 5-Why Analysis for SOP Failure:

The 5-Why analysis identifies the underlying reasons for failure to follow an SOP in the manufacturing area. The investigation begins with the observation that the required procedure was not followed by operators. The first level points to inadequate awareness or poor understanding of the SOP, while the second identifies ineffective or insufficient training as a contributing factor.

Further analysis shows that training may not be effective because there is no proper system for training effectiveness evaluation, refresher training, or routine compliance monitoring. The next level highlights inadequate supervision, production pressure, and weak accountability, which can result in SOP steps being ignored or bypassed. The final root cause is linked to a weak quality culture, insufficient management oversight, unclear accountability, and inadequate resources for GMP compliance. Appropriate CAPA should therefore focus on effective training, stronger supervision, periodic monitoring, management review, and reinforcement of a quality-first culture to prevent recurrence.

4. Fishbone Analysis for SOP Failure:

The Fishbone Analysis identifies the major categories of causes that can lead to SOP failure in a pharmaceutical manufacturing area. The central problem is linked to factors under Man, Machine, Method, Material, Environment, Measurement, and Management.

Personnel-related causes include inadequate training, poor awareness, carelessness, complacency, and intentional bypassing of procedures. Equipment-related causes include breakdowns, poor maintenance, inadequate calibration, and unclear operating instructions. Method-related issues include unavailable, outdated, complex, or impractical SOPs. Material-related factors include mix-ups, poor labeling, shortages, and inadequate in-process controls. Environmental contributors may include poor lighting, unsuitable temperature or humidity, noise, dust, inadequate HVAC, and workplace distractions. Monitoring and management causes include weak supervision, insufficient compliance checks, ineffective CAPA, production pressure, poor communication, lack of accountability, and weak quality culture. Overall, the analysis helps systematically identify potential root causes of SOP non-compliance and supports development of effective corrective and preventive actions to improve product quality, GMP compliance, and patient safety.

5. Fault Tree Analysis for SOP Failure:

The Fault Tree Analysis (FTA) diagram identifies the possible combinations of failures that can result in SOP non-compliance in the manufacturing area. The top event is defined as “SOP Failure in Manufacturing Area – Procedure Not Followed.” This failure can arise from several major branches, including personnel not following the SOP, SOP unavailability or ineffectiveness, inadequate monitoring and supervision, and intentional bypassing of the procedure.

The lower-level causes include lack of knowledge, inadequate or refresher training, carelessness, distraction, high workload, production pressure, outdated or inaccessible SOPs, unclear instructions, weak supervision, lack of compliance checks, ineffective CAPA, and poor quality culture. The diagram also highlights the potential consequences of SOP failure, such as product quality defects, batch rejection, regulatory non-compliance, increased cost, supply delays, risk to patient safety, and loss of company reputation. Overall, the FTA helps identify critical failure pathways so that appropriate corrective and preventive actions can be implemented to break the chain of SOP failure.

Questions & Answers – Desktop Policy for Analytical Instrument Software

Question 1: What is the objective of this SOP?
Answer:
The objective is to establish a procedure for maintaining the desktop policy for analytical instrument software used in the Quality Control department.

Question 2: What is the scope of this SOP?
Answer:
This SOP applies to computers used for operating QC analytical instruments such as HPLC and FTIR.

Question 3: Who is responsible for implementing this procedure?
Answer:
The Assistant IT/Executive IT is responsible for effective implementation and management, while the Manager-QC is responsible for implementation and control in applicable QC areas.

Question 4: What are the main desktop security controls defined in the SOP?
Answer:
The SOP covers password protection, local network control, domain logon, control-panel restriction, antivirus protection, and user privilege control.

Question 5: How is password change controlled?
Answer:
When a password change is required, the user must submit a request to the IT administrator as specified in Annexure-I.

Question 6: Who is authorized to modify local network settings?
Answer:
IT networking and administrator personnel have authorized access to read and modify the local network, while domain users are restricted from making such changes.

Question 7: How is the Control Panel protected?
Answer:
The IT Administrator locks the Control Panel and Run command on QC analytical instrument computers.

Question 8: Why are user privileges restricted?
Answer:
User privileges are restricted to minimize risks to regulated data, equipment, and organizational resources while allowing users to perform their assigned job functions.

Question 9: Can a domain user access Task Manager?
Answer:
No. Task Manager access is denied to domain users to prevent unauthorized shutdown, cancellation, or interference with analytical instrument software.

Question 10: Can a domain user change the system date and time?
Answer:
No. Access to change the date and time is denied to domain users.

Question 11: Is USB access allowed to domain users?
Answer:
No. USB and other media access is denied to domain users to prevent unauthorized loading or unloading of data from the computer system.

Question 12: Why is data backup required?
Answer:
Data backup is required to protect analytical instrument data from loss and to allow recovery in case of equipment failure or intentional destruction of data.

Question 13: Who can create, delete, or change a domain user?
Answer:
Only the domain administrator can create new users, delete users, or change passwords.

Question 14: Who provides training on this SOP?
Answer:
Training is provided by Executive IT to Quality Control personnel for a duration of approximately one and a half hours.

Question 15: What is the purpose of Annexure-I?
Answer:
Annexure-I is used for User ID Creation/Deletion Requisition. It records user details, reason for the request, QC approval, IT activity, and QA verification.

Reference Guidelines:

  1. Revised Schedule M, Drugs Rules, 1945 – India
    Computerised systems should have controls against unauthorized access or data changes, maintain records of changes, have written operating/maintenance procedures, control system changes, and provide backup/data protection. (CDSCO)
    CDSCO Drugs Rules / Schedule M
  2. EU GMP Annex 11 – Computerised Systems
    Applicable to GMP computerized systems and relevant to system validation, security, user access, data storage, backup, change control, periodic evaluation, and electronic records. (Public Health)
    European Commission – EudraLex Volume 4
  3. US FDA – 21 CFR Part 11, Electronic Records; Electronic Signatures
    Requires controls for trustworthy electronic records, including system validation, authorized access, record protection, authority checks, and secure time-stamped audit trails. (eCFR)
    21 CFR Part 11 – eCFR
  4. US FDA – Data Integrity and Compliance With Drug CGMP: Questions and Answers
    Provides FDA expectations concerning the completeness, consistency, accuracy, reliability, and integrity of GMP electronic data. (U.S. Food and Drug Administration)
    FDA Data Integrity Guidance
  5. WHO TRS 1033, Annex 4 – Guideline on Data Integrity
    Requires computerized systems used for GxP data to be suitable, validated for intended use, appropriately configured, maintained in a validated state, and controlled throughout the data lifecycle. (World Health Organization)
    WHO Guideline on Data Integrity
  6. PIC/S PI 041-1 – Good Practices for Data Management and Integrity in Regulated GMP/GDP Environments
    Provides regulatory expectations for data governance, access controls, computerized systems, audit trails, user privileges, and protection of electronic GMP records. (PIC/S)
    PIC/S PI 041-1 Information
  7. MHRA – GxP Data Integrity Guidance and Definitions
    Provides guidance on core elements of a compliant data-governance system across pharmaceutical GxP operations. (GOV.UK)
    MHRA GxP Data Integrity Guidance

error: Content is protected !!

This is the Premium Content

You can access this page after paying the subscription fees of 21 ₹ /month only.