Pharmaceuticals
FDA 21 CFR Part 11, GxP, and clinical trial compliance
Pharmaceutical companies operate under FDA regulations governing electronic records, clinical trials, and manufacturing. Thalorin supports pharma compliance with 21 CFR Part 11, GxP requirements, and the cybersecurity controls required for protecting valuable research and manufacturing data.
Pharmaceutical compliance runs on validation, and validation is where the regulatory expectation shifted. FDA's Computer Software Assurance guidance moved the emphasis from exhaustive documentation toward risk-based, critical-thinking-led assurance — testing proportionate to the risk the software actually presents to product quality and patient safety. Organisations still producing identical validation packages for a spreadsheet and a manufacturing execution system are spending effort the guidance was written to redirect.
The underlying rules did not relax. 21 CFR Part 11 still governs electronic records and electronic signatures, requiring audit trails, system validation, record retention, and signature controls. GxP expectations apply across good manufacturing, laboratory, and clinical practice, and EU Annex 11 imposes parallel requirements for computerised systems in the European market.
Supply chain traceability under the Drug Supply Chain Security Act adds a different obligation shape: interoperable, electronic, package-level product tracing across trading partners, which is a data interoperability problem as much as a compliance one.
Thalorin holds validation state, audit trail evidence, and change control as one connected record, so a change to a GxP system surfaces its revalidation impact rather than being discovered at inspection.
Healthcare faces mounting cybersecurity challenges
Validation effort misallocated to low-risk systems
Computer Software Assurance directs assurance effort toward risk. Programmes still applying uniform validation rigour spend disproportionately on low-risk tools while under-testing the systems that matter.
Audit trail completeness under Part 11
Part 11 requires secure, computer-generated, time-stamped audit trails. Systems that permit modification without an attributable trail, or where the trail can be disabled, fail on inspection regardless of surrounding controls.
Change control drives revalidation
A change to a validated system can invalidate its qualified state. Without a link between change records and validation status, systems drift out of validation silently between inspections.
DSCSA interoperability across partners
Package-level electronic tracing depends on trading partners exchanging data in compatible form. Readiness is partly determined by counterparties.
How Thalorin helps
21 CFR Part 11 compliance
Apply risk-based Computer Software Assurance, scaling validation effort to the risk a system presents to product quality and patient safety.
GxP computer system validation
Evidence 21 CFR Part 11 controls including audit trails, signature manifestations, and record retention.
Clinical trial data integrity
Link change control records to validation status so a change surfaces its revalidation impact.
Manufacturing system security
Carry EU Annex 11 obligations alongside Part 11 where products reach the European market.
Regulatory submission support
Track DSCSA traceability obligations and trading partner data exchange readiness.
Supplier qualification
Maintain inspection readiness from live system state rather than through pre-inspection reconstruction.
Pharmaceuticals: common questions
What changed with Computer Software Assurance?
The emphasis, not the requirements. CSA directs organisations to apply critical thinking and risk-based assurance — concentrating testing and documentation on software whose failure would affect product quality or patient safety, and using lighter approaches such as unscripted or ad hoc testing where risk is low. Part 11 and GxP obligations are unchanged; what changes is how effort is allocated against them.
Does Part 11 apply to every system we use?
It applies to electronic records required by predicate rules and to electronic signatures used in their place. Systems holding records that no predicate rule requires generally fall outside it. Scoping this properly matters, because applying full Part 11 rigour to every system in the estate is a common and expensive misreading.
What makes an audit trail acceptable?
It must be secure, computer-generated, time-stamped, and record operator entries and actions that create, modify, or delete electronic records, without obscuring previously recorded information. It must be retained for at least as long as the record itself and be available for review and copying. Trails that can be disabled by users, or that overwrite prior values, are recurring inspection findings.
How does DSCSA interoperability work in practice?
It requires trading partners to exchange package-level transaction information electronically and in an interoperable form, enabling tracing of individual packages through the supply chain. The practical difficulty is that compliance depends on counterparties' systems as well as your own, so readiness assessments have to cover the partner network rather than the internal estate alone.
Do we revalidate after every change?
No — the extent of revalidation should be proportionate to the change's risk and impact on the validated state. A configuration change to a non-GxP-impacting field is not equivalent to a change in calculation logic. What matters is that the assessment is made deliberately, documented, and linked to the change record, rather than the system drifting without anyone deciding.
Regulatory state described as of August 2026. Requirements change; verify against the current rule before relying on any date above.
Talk to us about Pharmaceuticals.
See how one evidence artifact satisfies Pharmaceuticals requirements alongside every other framework you carry.