Operational Ownership
FocusedWhat Should a GxP Organisation Be Able to Produce Within Hours When an Inspector Requests Evidence for a Specific Veeva Vault Change?
LIB-010 already sets out what a scheduled, proactive periodic review should cover, and LIB-025 sets out how to assess validated-state impact after a production incident. Both assume the organisation is initiating the review on its own timetable. Inspection response is different in a way that matters operationally: the inspector chooses which change to ask about, chooses when to ask, and the organisation's only real control is how quickly and completely it can respond once asked.
Define the retrieval scope before you are asked
Decide in advance, not during the inspection, what "evidence for a change" means in retrievable terms. For any named Veeva Vault configuration or code change, the organisation should be able to locate, quickly, the original change request and its impact assessment, the approval showing who authorised it and on what basis, the test evidence that supported deployment, confirmation of the current configuration state showing the change is genuinely in effect in the system being inspected, and the audit trail entry recording who deployed it and when. MHRA's GxP data integrity guidance frames data integrity expectations as applying to records irrespective of the medium holding them, and treats their availability, not merely their existence, as part of what data integrity means in practice. A change record that exists somewhere in an email archive or an individual's local files does not meet that expectation if nobody can locate it quickly when asked.
Retrievability is an operational capability, not a document property
A record can be complete, accurate and fully approved and still fail an inspection-readiness test if nobody can find it inside the response window an inspector is willing to wait for. This is why retrievability has to be treated as its own capability, distinct from whether the underlying record is good. Know, specifically, where each of the five evidence categories above actually lives for a Veeva Vault change: inside Vault itself as a workflow or object record, in a separate change-management or ticketing system, or in a document management area outside Vault entirely. Where evidence for one change is scattered across more than one system, know the retrieval path across all of them, not just the primary one.
Rehearse retrieval against a real historical change
The only reliable way to know whether retrieval actually works is to try it before an inspector does. Periodically select a real, already-deployed change, not a hypothetical one, and time how long it genuinely takes to assemble the complete evidence set defined above. Treat any gap this rehearsal surfaces, a document that cannot be found, an approval recorded in a place nobody checked, as a finding in its own right, worth fixing before it is discovered during an actual inspection rather than after. PIC/S guidance for inspectors auditing computerised systems in regulated GXP environments treats the operational and procedural controls surrounding a system as part of what is actually inspected, not only the system's technical configuration; retrieval rehearsal is one of the more direct ways to test that operational control before someone else does.
Understand what a retrieval failure actually signals
An inspector who asks for evidence and receives it slowly, or incompletely, or from an unexpected source, does not only note the delay. A slow or fragmented response to one specific request reasonably raises the question of whether records generally are under adequate control, because a records-management system that works reliably for one named change is normally expected to work reliably for others. EU GMP Annex 11 sets an expectation that a system remain in a valid, GMP-compliant state on an ongoing basis, evidenced through the organisation's own controls; an organisation that cannot promptly demonstrate that a specific past change is still correctly reflected in the current configuration state is, in effect, unable to demonstrate that ongoing compliance for the change in question, whatever the change record itself actually says.
Sources
- UK Medicines and Healthcare products Regulatory Agency, 'GxP' Data Integrity Guidance and Definitions.
- Pharmaceutical Inspection Co-operation Scheme, Good Practices for Computerised Systems in Regulated GXP Environments.
- European Commission, EudraLex Volume 4, Annex 11: Computerised Systems.