SlideShare a Scribd company logo
1 of 28
Download to read offline
How to Use Risk
Management
for PAT Implementation
Agenda

   Risk Analysis Background
   Various Protocols
       FTA, FMEA/FMECA, HACCP, GAMP 4, ISO
        14791, ISO 17799
   Risk Analysis and PAT
       Understanding & controlling variability
   Summary
Why Do Risk Analysis?

   For Regulatory Compliance….
        Measure and rank of compliance effort
        Regulatory submissions checklists (PMA and 510k) used
         by the FDA now call for inclusion of risk analysis
        FDA Requires risk analysis for software within medical
         devices
   Determine Extent of Validation
   ID Process Weaknesses Early to Reduce Cost
   Reduce Product Liability
        Identification of device design problems prior to
         distribution eliminates costs associated with recalls
   It is the Right Thing to Do!
Methodologies
Risk Management Protocols

 FTA    – Fault Tree Analysis
     Use first
 FMEA     – Failure Mode Effects Analysis
     What could go wrong
 FMECA-      Failure Mode Effects & Criticality Analysis
     Adds probability of occurrence and severity of failure to the FMEA
      process
 HACCP       – Hazard Analysis and Critical Control Points
     How to keep the ‘wrong’ from happening
 ISO 14971
 GAMP (appendix M3)
 BS/ISO 17799
Impact on
Risk Management is a Process                       Cost and
                                                 Compliance
Team & Defs             ID Processes


                 ID Use and Potential Misuse


                    ID Potential Hazards

 Develop         Quantify Consequences and
 Controls                Probabilities           Doc Eval
 for Risk
                                                 and
Reduction                                        Resulting
                    Determine Risk Index         Risk




                       Risk Acceptable?                Stop
            NO                             YES
Fault Tree Analysis Steps
                                  Process Fault Tree Analysis
   Top Down Approach to
    Risk Analysis
   Look at Hazards and Work
    Back to Failures that Cause
    Hazards
   List the Possible Hazards
   What Failures, or
    Combination of Failures,
    Will Lead to the Named
    Hazards?
   Diagram the Fault Tree
   Tool to Intercept or Design
    Out Unacceptable
    Consequences
FMECA or FMEA Approaches
   Bottom Up Approach to Risk Analysis
   Look at Hazards of System Components


Process Pre-Production    Possible Component Defects



                          Determine Undesired Events



                            Corrective Actions
FMEA
   There are Two Main Types of FMEA:
       Design FMEA which focuses on what could go
        wrong with a product in both manufacturing
        operation and in service as a result of a
        weakness in the design
       Process FMEA which concentrates on the
        reasons for potential failure during
        manufacturing and in service
           This is a result of non-compliance to specification
            and/or design intent
FMEA Protocol
   Define the Product Function(s)
   ID All Potential Failures
   Determine Failure Causes
   Determine Failure Effects
   Assign a Risk Index to Each Failure Type
   Develop Appropriate CAPA
   Ensure that the CAPA Has the Desired
    Effect
Format for FMEA Table
Function or Failure    Effect on   Possible   Risk    User        Acceptable
Component Mode         System      Hazard     Index   Detection   Controls
                                                      Means

Filter;     Plugge Dilute          Dirty    5         Alarm; Surge
T1          d Filter; water;       water;             Warnin Tank
                      Concentrat
Valve;      Short     e solute
                                   Contami            g Light;
Pump        circuit                nated              Flow
                                   product;           Meter
                                   Bad
                                   conc.
Hazard Analysis & Critical Control Points

   A Comprehensive, Methodical, Systematic
    Review
      from Design to Development, Manufacture and Use

        for Identifying, Evaluating and Controlling Hazards.
HACCP
   Based on the Following Seven Principles:
       Principle 1: Conduct a hazard analysis
       Principle 2: Determine the critical control points
        (CCPs)
       Principle 3: Establish critical limits
       Principle 4: Establish monitoring procedures
       Principle 5: Establish corrective actions
       Principle 6: Establish verification procedures
       Principle 7: Establish record-keeping and
        documentation procedures
Critical Control Points
   A Point, Step or Procedure at Which a Control Can
    be Applied to Eliminate or Reduce a Hazard to an
    Acceptable Level
   Set a Max/Min Value of Risk to Which a Safety
    Parameter Must Be Controlled at a CCP
   Established by:
        Regulatory standards
        Scientific publications
        Industry standards
        Experts
        Experimental studies
ISO 14971
   Defines Risk Management as a 13-Step Process:
       State intended use and ID characteristics of safety of product
       ID known foreseeable hazards
       Estimate the risks for each hazard
       Evaluate risk
       Analyze options
       Implement risk control measures
       Evaluate residual risk
       Analyze risk/benefit
       ID other generated hazards
       Complete risk evaluation
       Evaluate overall residual risk
       Complete risk management report
       Provide post-production data
GAMP 4 Functional Risk
     Assessment Methodology

   Mechanism for Assessing and Ranking the
    Risks Arising from Computerized Systems
   Links Degree of Validation to Overall
    System Vulnerability to Develop Risk-
    appropriate Validation Strategies
       First, ID the Functional Criticality of an
        Automated System
       Second, Analyze the System’s Vulnerability to
        Deficient Operation
       Third, Determine a Validation Strategy
           Validation must address any e-record/signature
            requirements
GAMP Risk Classifications
                                                                 Likelihood


                                              Low                  Med        High
Severity of Impact




                            High


                                                Infrastructure




                                                                              Software
                                                                              Custom
                                                                    COTS
                            Med



                            Low


                     Key:
                                   GAMP Risk Level 1 System
                                   GAMP Risk Level 2 System
                                   GAMP Risk Level 3 System
Risk and PAT
What is PAT?
   A System to…..
       Design, analyze, and control a process…..
       ….based on timely measurements of
       ….critical quality parameters and…
       ….performance attributes….
       ….of raw and in-process materials
   Processes to Assure End Product Quality
   “Analytical“ Includes:
       Chemical, physical, microbiological, mathematical
        and risk analysis….
       …..conducted in an integrated manner
PAT Approach: Quality by Design

   Focus on Process Understanding
   What Parameters are Critical to Product Quality?
   How Do We Assess these Parameters?
        Risk Assessment / Risk Management
   How Do We Control these Parameters Throughout
    the Process?
        Increased amount of in-process testing
        Verification and residual risk control
   Integrate Multi-variate Data
        ‘Reactive’ to ‘Proactive’
PAT = Process Understanding
   Process Understanding…..
       Inversely proportional to risk of poor product quality
       Facilitates risk-managed regulatory decisions and innovation
   A Process is Well Understood When:
       Identify all critical sources of variability
       Manage variability by the process
       Predict product quality attributes accurately and reliably


         Process Understanding  Controlling
        Variability → Less Restrictive Regulatory
             Approaches to Manage Change
PAT Guidance (September 29, 2004)

   Scientific Principles and Tools
    Supporting Innovation
        PAT Tools:
             Multivariate data acquisition
              & analysis tools
             Process analyzers
             Process control systems

        Process Understanding
        Risk-Based Approach
        Integrated Approach


   FDA Strategy for Innovation
        PAT Team approach to
         Review and Inspection
        Joint training/certification of
         staff
PAT: Risk-Managed Approach to
     Regulatory Scrutiny

   Use a Risk Management Protocol to Determine the
    PAT Implementation Points
   Use a Risk Management Protocol to Select a PAT
    Technology
   Use Risk Management to ID and Control
    Parameters that Impact Product Quality
   Well Understood Process  Less Restrictive
    Regulatory Approaches to Manage Change
   Process Understanding Facilitates Risk-managed
    Regulatory Decisions and Innovation
Tying It All Together
     PAT Elements                                     PAT Strategy
                                                          Strategy
      PAT Tools          Risk Management
                               Risk               Process
                                                        Process Process            Process
                           Management           Understanding
                                                     Understanding
                                                                 Analysis         Optimization

• Multivariate Data      • Provide Risk         • Identify Critical Attributes   • Implement
  Acqu & Anal Tools        Based Decisions                                         Test
                                                • ID Automation Attributes         Strategies
• Modern Process         • Rationale on
  Analyzers                Where to Apply       • Identify Monitoring &
                                                  Control Elements               • Optimize
                           Technology
                                                                                   Process
• Process & Endpoint                            • Obtain Knowledge of
  Monitoring & Control   • Framework to           Product & Process
                           Facilitate Process                                    • Implement
  Tools                                           Requirements
                           Understanding &                                         Optimization
                           Decision Making                                         Points
• Continuous                                    • Understand QS Interfaces
  Improvement & KM
                                                • Analyze Risk Process           • Apply
Process Understanding    • Provide                & QS Perspective                 Technology
                           Framework to
Risk-Based Approach        Execute Risk-        • Define Mitigation Strategy
Integrated Systems         Based Strategies
Approach
Real-Time
Real Time Release
PAT, cGMP, and the Critical Path
 Encourage Innovation       Critical Path
                             Initiative
  Process
                              Risk-Management
 Analytical
Technology
                             cGMP’s for the
  New Technologies            21st Century

              Broad Cooperation:
            Industry, Academia, FDA
Summary

   Develop an SOP for Risk Assessment
   Risk Management as Part of Quality System
   PAT Implementation Requires Deep Process
    Understanding
   ‘RM’ and PAT Assures Quality
   Use ‘RM’ and ‘PU’ to Develop Meaningful
    Specifications
   Use RM and PAT to Replace Existing Methods
    with Predictive / Proactive Ones
References
   GAMP 4 (2001) Appendix M3- Guideline for Risk Assessment
   ISO 14971 – Application of Risk Management to Medical Devices
   ISO 17799 (BS 7799) – Guide to Risk Assessment and Risk
    Management
   ISPE White Paper – www.ispe.org
   February 2003, FDA Draft Guidance for Industry: Part 11, ERES –
    Scope and Application”
   GAMP Forum (2003), “Risk Assessment for Use of Automated
    Systems Supporting Manufacturing”, Part 1&2, Pharmaceutical
    Engineering
   Computer Systems Validation: Quality Assurance, Risk Management
    & Regulatory Compliance, CRC Press (2003)
   FDA Concept Paper – Draft Pre-marketing Risk Assessment (3/3/03)
   NIST Computer Security Document
Thank You For Your Attention!




  Questions……………………?

More Related Content

What's hot

Using Risk Management for Validation
Using Risk Management for ValidationUsing Risk Management for Validation
Using Risk Management for ValidationRobert Sturm
 
Qrm presentation
Qrm presentationQrm presentation
Qrm presentationGeetha Svcp
 
Quality Risk Management Dr.A. Amsavel
Quality Risk Management   Dr.A. AmsavelQuality Risk Management   Dr.A. Amsavel
Quality Risk Management Dr.A. AmsavelDr. Amsavel A
 
LOPA | Layer Of Protection Analysis | Gaurav Singh Rajput
LOPA | Layer Of Protection Analysis | Gaurav Singh RajputLOPA | Layer Of Protection Analysis | Gaurav Singh Rajput
LOPA | Layer Of Protection Analysis | Gaurav Singh RajputGaurav Singh Rajput
 
Supply chain risks
Supply chain risksSupply chain risks
Supply chain risksNeik Lee
 
Amergamalpres1 130129172315-phpapp01
Amergamalpres1 130129172315-phpapp01Amergamalpres1 130129172315-phpapp01
Amergamalpres1 130129172315-phpapp01Fasika Alemu
 
Risk Management in QMS and New Products Design (NPD)
Risk Management in QMS and New Products Design (NPD)Risk Management in QMS and New Products Design (NPD)
Risk Management in QMS and New Products Design (NPD)Sanjay Dhal , MS, MBA
 
Ich guidelines on risk assessment and risk mangment
Ich guidelines on risk assessment and risk mangmentIch guidelines on risk assessment and risk mangment
Ich guidelines on risk assessment and risk mangmentAshvin Bhoge
 
How auditable is your disaster recovery program
How auditable is your disaster recovery programHow auditable is your disaster recovery program
How auditable is your disaster recovery programgeekmodeboy
 
Anomalies, complaints and non-compliances
Anomalies, complaints and non-compliancesAnomalies, complaints and non-compliances
Anomalies, complaints and non-compliancesTim Sandle, Ph.D.
 
Presentation Risk Based Approach to Inspection Frequency
Presentation Risk Based Approach to Inspection FrequencyPresentation Risk Based Approach to Inspection Frequency
Presentation Risk Based Approach to Inspection FrequencyTGA Australia
 
Layer of protection analysis
Layer of protection analysisLayer of protection analysis
Layer of protection analysisSandip Sonawane
 
FDA/EC/WHO Expectations for Computer System Validation
FDA/EC/WHO Expectations for Computer System Validation FDA/EC/WHO Expectations for Computer System Validation
FDA/EC/WHO Expectations for Computer System Validation Muhammad Luqman Ikram
 
A Framework for Developing and Operationalizing Security Use Cases
A Framework for Developing and Operationalizing Security Use CasesA Framework for Developing and Operationalizing Security Use Cases
A Framework for Developing and Operationalizing Security Use CasesRyan Faircloth
 

What's hot (20)

Using Risk Management for Validation
Using Risk Management for ValidationUsing Risk Management for Validation
Using Risk Management for Validation
 
Quality Risk management Application of FMEA
Quality Risk management  Application of FMEAQuality Risk management  Application of FMEA
Quality Risk management Application of FMEA
 
Quality risk management sop
Quality risk management sopQuality risk management sop
Quality risk management sop
 
Quality Risk Management
Quality Risk ManagementQuality Risk Management
Quality Risk Management
 
Apply Risk Management to Computerized and Automated Systems
Apply Risk Management to Computerized and Automated SystemsApply Risk Management to Computerized and Automated Systems
Apply Risk Management to Computerized and Automated Systems
 
Qrm presentation
Qrm presentationQrm presentation
Qrm presentation
 
ICH Q9 Quality Risk Management
ICH Q9 Quality Risk ManagementICH Q9 Quality Risk Management
ICH Q9 Quality Risk Management
 
Quality Risk Management Dr.A. Amsavel
Quality Risk Management   Dr.A. AmsavelQuality Risk Management   Dr.A. Amsavel
Quality Risk Management Dr.A. Amsavel
 
LOPA | Layer Of Protection Analysis | Gaurav Singh Rajput
LOPA | Layer Of Protection Analysis | Gaurav Singh RajputLOPA | Layer Of Protection Analysis | Gaurav Singh Rajput
LOPA | Layer Of Protection Analysis | Gaurav Singh Rajput
 
Supply chain risks
Supply chain risksSupply chain risks
Supply chain risks
 
Amergamalpres1 130129172315-phpapp01
Amergamalpres1 130129172315-phpapp01Amergamalpres1 130129172315-phpapp01
Amergamalpres1 130129172315-phpapp01
 
Risk Management in QMS and New Products Design (NPD)
Risk Management in QMS and New Products Design (NPD)Risk Management in QMS and New Products Design (NPD)
Risk Management in QMS and New Products Design (NPD)
 
Ich guidelines on risk assessment and risk mangment
Ich guidelines on risk assessment and risk mangmentIch guidelines on risk assessment and risk mangment
Ich guidelines on risk assessment and risk mangment
 
How auditable is your disaster recovery program
How auditable is your disaster recovery programHow auditable is your disaster recovery program
How auditable is your disaster recovery program
 
Anomalies, complaints and non-compliances
Anomalies, complaints and non-compliancesAnomalies, complaints and non-compliances
Anomalies, complaints and non-compliances
 
Presentation Risk Based Approach to Inspection Frequency
Presentation Risk Based Approach to Inspection FrequencyPresentation Risk Based Approach to Inspection Frequency
Presentation Risk Based Approach to Inspection Frequency
 
Layer of protection analysis
Layer of protection analysisLayer of protection analysis
Layer of protection analysis
 
FDA/EC/WHO Expectations for Computer System Validation
FDA/EC/WHO Expectations for Computer System Validation FDA/EC/WHO Expectations for Computer System Validation
FDA/EC/WHO Expectations for Computer System Validation
 
Gamp5 new
Gamp5 newGamp5 new
Gamp5 new
 
A Framework for Developing and Operationalizing Security Use Cases
A Framework for Developing and Operationalizing Security Use CasesA Framework for Developing and Operationalizing Security Use Cases
A Framework for Developing and Operationalizing Security Use Cases
 

Viewers also liked

ISS - Exposure Control Validation
ISS - Exposure Control ValidationISS - Exposure Control Validation
ISS - Exposure Control ValidationAbhinav Asthana
 
2011 ISPE Presentation-Supply Chain Improvements w Case Study Examples
2011 ISPE Presentation-Supply Chain Improvements w Case Study Examples2011 ISPE Presentation-Supply Chain Improvements w Case Study Examples
2011 ISPE Presentation-Supply Chain Improvements w Case Study ExamplesCharles Trammell
 
Process Validation & Verification (V&V) for Medical Devices
Process Validation & Verification (V&V) for Medical DevicesProcess Validation & Verification (V&V) for Medical Devices
Process Validation & Verification (V&V) for Medical DevicesRina Nir
 
Effective medical device validation introduction manual advance
Effective medical device validation introduction   manual advanceEffective medical device validation introduction   manual advance
Effective medical device validation introduction manual advanceguest2d7d1cac
 
Codex validation Group presentation
Codex validation Group presentationCodex validation Group presentation
Codex validation Group presentationWalter Acevedo
 
Components of computer system and input-output devices and storage devices
Components of computer system and input-output devices and storage devicesComponents of computer system and input-output devices and storage devices
Components of computer system and input-output devices and storage devicesSaiFul IsLam
 
Best Practices for Managing a Large-Scale SAP System Consolidation Project
Best Practices for Managing a Large-Scale SAP System Consolidation ProjectBest Practices for Managing a Large-Scale SAP System Consolidation Project
Best Practices for Managing a Large-Scale SAP System Consolidation ProjectSAPinsider Events
 
Equipment validation of fbd
Equipment validation of fbdEquipment validation of fbd
Equipment validation of fbdpriyanka odela
 
Testing of Safety Valves
Testing of Safety ValvesTesting of Safety Valves
Testing of Safety ValvesCarl Stevens
 
Computer System Validation
Computer System ValidationComputer System Validation
Computer System ValidationEric Silva
 
Input, Output and Storage Devices
Input, Output and Storage DevicesInput, Output and Storage Devices
Input, Output and Storage Devicesguest30320a
 
Concept of URS,DQ,IQ,OQ,PQ
Concept of URS,DQ,IQ,OQ,PQConcept of URS,DQ,IQ,OQ,PQ
Concept of URS,DQ,IQ,OQ,PQdhavalrock24
 
Components of a computer system
Components of a computer systemComponents of a computer system
Components of a computer systemlistergc
 
Types and components of computer system
Types and components of computer systemTypes and components of computer system
Types and components of computer systemmkhisalg
 

Viewers also liked (17)

ISS - Exposure Control Validation
ISS - Exposure Control ValidationISS - Exposure Control Validation
ISS - Exposure Control Validation
 
Tp addition
Tp additionTp addition
Tp addition
 
2011 ISPE Presentation-Supply Chain Improvements w Case Study Examples
2011 ISPE Presentation-Supply Chain Improvements w Case Study Examples2011 ISPE Presentation-Supply Chain Improvements w Case Study Examples
2011 ISPE Presentation-Supply Chain Improvements w Case Study Examples
 
Software testing day1
Software testing day1Software testing day1
Software testing day1
 
Gd test kieu_test
Gd test kieu_testGd test kieu_test
Gd test kieu_test
 
Process Validation & Verification (V&V) for Medical Devices
Process Validation & Verification (V&V) for Medical DevicesProcess Validation & Verification (V&V) for Medical Devices
Process Validation & Verification (V&V) for Medical Devices
 
Effective medical device validation introduction manual advance
Effective medical device validation introduction   manual advanceEffective medical device validation introduction   manual advance
Effective medical device validation introduction manual advance
 
Codex validation Group presentation
Codex validation Group presentationCodex validation Group presentation
Codex validation Group presentation
 
Components of computer system and input-output devices and storage devices
Components of computer system and input-output devices and storage devicesComponents of computer system and input-output devices and storage devices
Components of computer system and input-output devices and storage devices
 
Best Practices for Managing a Large-Scale SAP System Consolidation Project
Best Practices for Managing a Large-Scale SAP System Consolidation ProjectBest Practices for Managing a Large-Scale SAP System Consolidation Project
Best Practices for Managing a Large-Scale SAP System Consolidation Project
 
Equipment validation of fbd
Equipment validation of fbdEquipment validation of fbd
Equipment validation of fbd
 
Testing of Safety Valves
Testing of Safety ValvesTesting of Safety Valves
Testing of Safety Valves
 
Computer System Validation
Computer System ValidationComputer System Validation
Computer System Validation
 
Input, Output and Storage Devices
Input, Output and Storage DevicesInput, Output and Storage Devices
Input, Output and Storage Devices
 
Concept of URS,DQ,IQ,OQ,PQ
Concept of URS,DQ,IQ,OQ,PQConcept of URS,DQ,IQ,OQ,PQ
Concept of URS,DQ,IQ,OQ,PQ
 
Components of a computer system
Components of a computer systemComponents of a computer system
Components of a computer system
 
Types and components of computer system
Types and components of computer systemTypes and components of computer system
Types and components of computer system
 

Similar to Risk Analysis Pat New

ICH Q9 QUALITY RISK MANAGEMENT(QRM)
ICH Q9 QUALITY RISK MANAGEMENT(QRM)ICH Q9 QUALITY RISK MANAGEMENT(QRM)
ICH Q9 QUALITY RISK MANAGEMENT(QRM)saimsoleja
 
Quality risk management
Quality risk managementQuality risk management
Quality risk managementpraveen dubey
 
Risk management in development of life critical systems
Risk management in development of life critical systemsRisk management in development of life critical systems
Risk management in development of life critical systemsScott Althouse
 
Quality risk management
Quality risk managementQuality risk management
Quality risk managementimran bakshi
 
Quality risk management
Quality risk managementQuality risk management
Quality risk managementKarunaMane1
 
Pharmaceutical Quality Risk Assessment
Pharmaceutical Quality Risk Assessment Pharmaceutical Quality Risk Assessment
Pharmaceutical Quality Risk Assessment Pharmaceutical
 
Quality risk management -Technology development and transfer
Quality risk management -Technology  development and transferQuality risk management -Technology  development and transfer
Quality risk management -Technology development and transfersneha_pharmacist
 
Risk management in pharmaceutical Industry
Risk management in pharmaceutical IndustryRisk management in pharmaceutical Industry
Risk management in pharmaceutical IndustryMahesh shinde
 
Risk management and environmental monitoring
Risk management and environmental monitoringRisk management and environmental monitoring
Risk management and environmental monitoringTim Sandle, Ph.D.
 
Risk minor major critical
Risk minor major criticalRisk minor major critical
Risk minor major criticalyasser mekky
 
Quality Risk Management 2 brief note
Quality  Risk Management 2 brief noteQuality  Risk Management 2 brief note
Quality Risk Management 2 brief noteRathodBhavansinh
 
Failure Mode & Effect Analysis
Failure Mode & Effect AnalysisFailure Mode & Effect Analysis
Failure Mode & Effect AnalysisECC International
 
Quality Management System.pptx
Quality Management System.pptxQuality Management System.pptx
Quality Management System.pptxDipansiTembharne
 
Keeping up with ICH E6(R2): Risk-Based Monitoring (RBM) Redefined
Keeping up with ICH E6(R2): Risk-Based Monitoring (RBM) RedefinedKeeping up with ICH E6(R2): Risk-Based Monitoring (RBM) Redefined
Keeping up with ICH E6(R2): Risk-Based Monitoring (RBM) RedefinedLife Sciences Network marcus evans
 
11. faliure mode & effect analysis
11. faliure mode & effect analysis11. faliure mode & effect analysis
11. faliure mode & effect analysisHakeem-Ur- Rehman
 

Similar to Risk Analysis Pat New (20)

ICH Q9 QUALITY RISK MANAGEMENT(QRM)
ICH Q9 QUALITY RISK MANAGEMENT(QRM)ICH Q9 QUALITY RISK MANAGEMENT(QRM)
ICH Q9 QUALITY RISK MANAGEMENT(QRM)
 
Quality risk management
Quality risk managementQuality risk management
Quality risk management
 
Risk Assessment and Management
Risk Assessment and ManagementRisk Assessment and Management
Risk Assessment and Management
 
Quality risk management
Quality risk managementQuality risk management
Quality risk management
 
Risk management in development of life critical systems
Risk management in development of life critical systemsRisk management in development of life critical systems
Risk management in development of life critical systems
 
Quality risk management
Quality risk managementQuality risk management
Quality risk management
 
Quality risk management
Quality risk managementQuality risk management
Quality risk management
 
Pharmaceutical Quality Risk Assessment
Pharmaceutical Quality Risk Assessment Pharmaceutical Quality Risk Assessment
Pharmaceutical Quality Risk Assessment
 
Quality risk management -Technology development and transfer
Quality risk management -Technology  development and transferQuality risk management -Technology  development and transfer
Quality risk management -Technology development and transfer
 
Risk management in pharmaceutical Industry
Risk management in pharmaceutical IndustryRisk management in pharmaceutical Industry
Risk management in pharmaceutical Industry
 
Risk management and environmental monitoring
Risk management and environmental monitoringRisk management and environmental monitoring
Risk management and environmental monitoring
 
Risk minor major critical
Risk minor major criticalRisk minor major critical
Risk minor major critical
 
Failure mode and effect analysis
Failure mode and effect analysisFailure mode and effect analysis
Failure mode and effect analysis
 
Quality Risk Management 2 brief note
Quality  Risk Management 2 brief noteQuality  Risk Management 2 brief note
Quality Risk Management 2 brief note
 
Failure Mode & Effect Analysis
Failure Mode & Effect AnalysisFailure Mode & Effect Analysis
Failure Mode & Effect Analysis
 
Quality Management System.pptx
Quality Management System.pptxQuality Management System.pptx
Quality Management System.pptx
 
Keeping up with ICH E6(R2): Risk-Based Monitoring (RBM) Redefined
Keeping up with ICH E6(R2): Risk-Based Monitoring (RBM) RedefinedKeeping up with ICH E6(R2): Risk-Based Monitoring (RBM) Redefined
Keeping up with ICH E6(R2): Risk-Based Monitoring (RBM) Redefined
 
FMEA.pptx
FMEA.pptxFMEA.pptx
FMEA.pptx
 
11. faliure mode & effect analysis
11. faliure mode & effect analysis11. faliure mode & effect analysis
11. faliure mode & effect analysis
 
FMEA
FMEAFMEA
FMEA
 

Risk Analysis Pat New

  • 1. How to Use Risk Management for PAT Implementation
  • 2. Agenda  Risk Analysis Background  Various Protocols  FTA, FMEA/FMECA, HACCP, GAMP 4, ISO 14791, ISO 17799  Risk Analysis and PAT  Understanding & controlling variability  Summary
  • 3. Why Do Risk Analysis?  For Regulatory Compliance….  Measure and rank of compliance effort  Regulatory submissions checklists (PMA and 510k) used by the FDA now call for inclusion of risk analysis  FDA Requires risk analysis for software within medical devices  Determine Extent of Validation  ID Process Weaknesses Early to Reduce Cost  Reduce Product Liability  Identification of device design problems prior to distribution eliminates costs associated with recalls  It is the Right Thing to Do!
  • 5. Risk Management Protocols  FTA – Fault Tree Analysis  Use first  FMEA – Failure Mode Effects Analysis  What could go wrong  FMECA- Failure Mode Effects & Criticality Analysis  Adds probability of occurrence and severity of failure to the FMEA process  HACCP – Hazard Analysis and Critical Control Points  How to keep the ‘wrong’ from happening  ISO 14971  GAMP (appendix M3)  BS/ISO 17799
  • 6. Impact on Risk Management is a Process Cost and Compliance Team & Defs ID Processes ID Use and Potential Misuse ID Potential Hazards Develop Quantify Consequences and Controls Probabilities Doc Eval for Risk and Reduction Resulting Determine Risk Index Risk Risk Acceptable? Stop NO YES
  • 7. Fault Tree Analysis Steps Process Fault Tree Analysis  Top Down Approach to Risk Analysis  Look at Hazards and Work Back to Failures that Cause Hazards  List the Possible Hazards  What Failures, or Combination of Failures, Will Lead to the Named Hazards?  Diagram the Fault Tree  Tool to Intercept or Design Out Unacceptable Consequences
  • 8. FMECA or FMEA Approaches  Bottom Up Approach to Risk Analysis  Look at Hazards of System Components Process Pre-Production Possible Component Defects Determine Undesired Events Corrective Actions
  • 9. FMEA  There are Two Main Types of FMEA:  Design FMEA which focuses on what could go wrong with a product in both manufacturing operation and in service as a result of a weakness in the design  Process FMEA which concentrates on the reasons for potential failure during manufacturing and in service  This is a result of non-compliance to specification and/or design intent
  • 10. FMEA Protocol  Define the Product Function(s)  ID All Potential Failures  Determine Failure Causes  Determine Failure Effects  Assign a Risk Index to Each Failure Type  Develop Appropriate CAPA  Ensure that the CAPA Has the Desired Effect
  • 11. Format for FMEA Table Function or Failure Effect on Possible Risk User Acceptable Component Mode System Hazard Index Detection Controls Means Filter; Plugge Dilute Dirty 5 Alarm; Surge T1 d Filter; water; water; Warnin Tank Concentrat Valve; Short e solute Contami g Light; Pump circuit nated Flow product; Meter Bad conc.
  • 12. Hazard Analysis & Critical Control Points  A Comprehensive, Methodical, Systematic Review from Design to Development, Manufacture and Use for Identifying, Evaluating and Controlling Hazards.
  • 13. HACCP  Based on the Following Seven Principles:  Principle 1: Conduct a hazard analysis  Principle 2: Determine the critical control points (CCPs)  Principle 3: Establish critical limits  Principle 4: Establish monitoring procedures  Principle 5: Establish corrective actions  Principle 6: Establish verification procedures  Principle 7: Establish record-keeping and documentation procedures
  • 14. Critical Control Points  A Point, Step or Procedure at Which a Control Can be Applied to Eliminate or Reduce a Hazard to an Acceptable Level  Set a Max/Min Value of Risk to Which a Safety Parameter Must Be Controlled at a CCP  Established by:  Regulatory standards  Scientific publications  Industry standards  Experts  Experimental studies
  • 15. ISO 14971  Defines Risk Management as a 13-Step Process:  State intended use and ID characteristics of safety of product  ID known foreseeable hazards  Estimate the risks for each hazard  Evaluate risk  Analyze options  Implement risk control measures  Evaluate residual risk  Analyze risk/benefit  ID other generated hazards  Complete risk evaluation  Evaluate overall residual risk  Complete risk management report  Provide post-production data
  • 16. GAMP 4 Functional Risk Assessment Methodology  Mechanism for Assessing and Ranking the Risks Arising from Computerized Systems  Links Degree of Validation to Overall System Vulnerability to Develop Risk- appropriate Validation Strategies  First, ID the Functional Criticality of an Automated System  Second, Analyze the System’s Vulnerability to Deficient Operation  Third, Determine a Validation Strategy  Validation must address any e-record/signature requirements
  • 17. GAMP Risk Classifications Likelihood Low Med High Severity of Impact High Infrastructure Software Custom COTS Med Low Key: GAMP Risk Level 1 System GAMP Risk Level 2 System GAMP Risk Level 3 System
  • 19. What is PAT?  A System to…..  Design, analyze, and control a process…..  ….based on timely measurements of  ….critical quality parameters and…  ….performance attributes….  ….of raw and in-process materials  Processes to Assure End Product Quality  “Analytical“ Includes:  Chemical, physical, microbiological, mathematical and risk analysis….  …..conducted in an integrated manner
  • 20. PAT Approach: Quality by Design  Focus on Process Understanding  What Parameters are Critical to Product Quality?  How Do We Assess these Parameters?  Risk Assessment / Risk Management  How Do We Control these Parameters Throughout the Process?  Increased amount of in-process testing  Verification and residual risk control  Integrate Multi-variate Data  ‘Reactive’ to ‘Proactive’
  • 21. PAT = Process Understanding  Process Understanding…..  Inversely proportional to risk of poor product quality  Facilitates risk-managed regulatory decisions and innovation  A Process is Well Understood When:  Identify all critical sources of variability  Manage variability by the process  Predict product quality attributes accurately and reliably Process Understanding  Controlling Variability → Less Restrictive Regulatory Approaches to Manage Change
  • 22. PAT Guidance (September 29, 2004)  Scientific Principles and Tools Supporting Innovation  PAT Tools:  Multivariate data acquisition & analysis tools  Process analyzers  Process control systems  Process Understanding  Risk-Based Approach  Integrated Approach  FDA Strategy for Innovation  PAT Team approach to Review and Inspection  Joint training/certification of staff
  • 23. PAT: Risk-Managed Approach to Regulatory Scrutiny  Use a Risk Management Protocol to Determine the PAT Implementation Points  Use a Risk Management Protocol to Select a PAT Technology  Use Risk Management to ID and Control Parameters that Impact Product Quality  Well Understood Process  Less Restrictive Regulatory Approaches to Manage Change  Process Understanding Facilitates Risk-managed Regulatory Decisions and Innovation
  • 24. Tying It All Together PAT Elements PAT Strategy Strategy PAT Tools Risk Management Risk Process Process Process Process Management Understanding Understanding Analysis Optimization • Multivariate Data • Provide Risk • Identify Critical Attributes • Implement Acqu & Anal Tools Based Decisions Test • ID Automation Attributes Strategies • Modern Process • Rationale on Analyzers Where to Apply • Identify Monitoring & Control Elements • Optimize Technology Process • Process & Endpoint • Obtain Knowledge of Monitoring & Control • Framework to Product & Process Facilitate Process • Implement Tools Requirements Understanding & Optimization Decision Making Points • Continuous • Understand QS Interfaces Improvement & KM • Analyze Risk Process • Apply Process Understanding • Provide & QS Perspective Technology Framework to Risk-Based Approach Execute Risk- • Define Mitigation Strategy Integrated Systems Based Strategies Approach Real-Time Real Time Release
  • 25. PAT, cGMP, and the Critical Path Encourage Innovation Critical Path Initiative Process Risk-Management Analytical Technology cGMP’s for the New Technologies 21st Century Broad Cooperation: Industry, Academia, FDA
  • 26. Summary  Develop an SOP for Risk Assessment  Risk Management as Part of Quality System  PAT Implementation Requires Deep Process Understanding  ‘RM’ and PAT Assures Quality  Use ‘RM’ and ‘PU’ to Develop Meaningful Specifications  Use RM and PAT to Replace Existing Methods with Predictive / Proactive Ones
  • 27. References  GAMP 4 (2001) Appendix M3- Guideline for Risk Assessment  ISO 14971 – Application of Risk Management to Medical Devices  ISO 17799 (BS 7799) – Guide to Risk Assessment and Risk Management  ISPE White Paper – www.ispe.org  February 2003, FDA Draft Guidance for Industry: Part 11, ERES – Scope and Application”  GAMP Forum (2003), “Risk Assessment for Use of Automated Systems Supporting Manufacturing”, Part 1&2, Pharmaceutical Engineering  Computer Systems Validation: Quality Assurance, Risk Management & Regulatory Compliance, CRC Press (2003)  FDA Concept Paper – Draft Pre-marketing Risk Assessment (3/3/03)  NIST Computer Security Document
  • 28. Thank You For Your Attention! Questions……………………?