← Drug Development Suite Quality Assurance · Vitalis Therapeutics Inc.

GxP Compliance Plan

Download Word

Vitalis Therapeutics Inc. — GxP compliance across the VitaFlow (VTX-401) program: which practice applies where, the ALCOA+ data integrity principles, the quality management system, 21 CFR Part 11 obligations, and the audit program including the for-cause audit triggered by I-02.

5
GxP practices in scope
11
Audits completed
3
CAPA open
0
CAPA overdue
Contents
  1. GxP Is Not a Quality Target
  2. The GxP Family
  3. Data Integrity — ALCOA+
  4. The Quality Management System
  5. Electronic Records — 21 CFR Part 11
  6. Audit Program
  7. What Happens When GxP Is Breached
  8. Responsibilities

1. GxP Is Not a Quality Target

Most standards in a program are targets with tolerance. Budget carries ±5%. Gates are held within four weeks. Enrolment tracks against a curve. Each has an acceptable variance because each is a plan, and plans are estimates.

GxP is not that. It is the regulatory floor below which the work is not lawful.

Constraint C-01, from the RAID Log: Good Laboratory Practice for nonclinical safety, Good Clinical Practice for clinical conduct, and current Good Manufacturing Practice for material dosed in humans are regulatory obligations, not quality targets the program may trade against cost or schedule. A gate cannot authorize a deviation from any of them.

The Development Committee Charter §9 names GxP as one of four matters outside Committee authority. There is no vote available. A committee facing a choice between a filing date and a GMP obligation has not been given a choice.

For a program manager the practical implication is narrow and important: compliance is never a lever. When schedule pressure arrives, the options are more money, more people, more time, or reduced scope. Compliance is not on that list, and a program that treats it as negotiable will discover the fact at inspection rather than in a meeting.

2. The GxP Family

Full nameApplies toReferenceIn this program
GLPGood Laboratory PracticeNonclinical safety studies21 CFR Part 58Applied to the IND-enabling toxicology package. Complete.
GCPGood Clinical PracticeAll clinical conductICH E6(R2), 21 CFR 50/54/56/312Applies to every site, the CRO, and the sponsor. The largest surface area in this program.
GMPcurrent Good Manufacturing PracticeAny material dosed in humans21 CFR Parts 210/211Applies to clinical supply and to commercial manufacture at Aldergate.
GDPGood Distribution PracticeStorage and shipping of productCold-chain integrity from depot to site, and post-approval to wholesalers.
GVPGood Pharmacovigilance PracticeSafety data collection and reporting21 CFR 312.32Governs the obligations in the Safety Reporting Plan.
Note how the scope shifts across the program. GLP applied intensely during nonclinical and is now complete — those studies are finished and their reports are in the IND. GCP applies right now across 231 sites, a CRO and the sponsor, which is why it has the largest surface area. GMP applied to clinical supply from the beginning and is increasing in importance as the program approaches commercial manufacture and the pre-approval inspection.

A program that resources quality against yesterday's profile is under-resourcing the part that is about to be inspected.

3. Data Integrity — ALCOA+

Regulators assess records against nine principles, known collectively as ALCOA+. They apply identically to a paper laboratory notebook and to an electronic data capture system.

PrincipleMeansWhat it looks like in practice
AttributableWho recorded it, and whenUnique logins, no shared accounts, no recording on behalf of someone else.
LegibleReadable and permanentNo pencil, no correction fluid, no overwriting. A correction strikes through, initials and dates — the original value stays visible.
ContemporaneousRecorded when it happenedNot written up later from memory or from a scrap of paper. The most commonly cited failure at inspection.
OriginalThe first record, or a certified true copyA transcription is not the original unless the copy process is verified.
AccurateCorrect, and consistent with realityErrors happen; concealing them is a different category of problem entirely.
CompleteNothing omitted, including failuresRepeat tests are recorded with the original result. Testing into compliance is fraud.
ConsistentSequenced and dated coherentlyTimestamps that contradict each other.
EnduringPreserved for the required retention periodLegible media, readable format.
AvailableRetrievable on request throughout retentionIncluding the ability to read data from superseded systems.
Contemporaneous is the one most commonly cited, and it is worth understanding why. Writing something up two days later from notes is not fraud, is usually accurate, and feels harmless. It is also unverifiable — the record no longer demonstrates what was actually observed at the time, only what someone later recalled observing.

The regulatory concern is not honesty. It is that a non-contemporaneous record cannot be distinguished from a reconstructed one, and a system that permits reconstruction permits convenient reconstruction.
“Complete” carries the sharpest edge. Records must include failures, repeat tests, and results that were not wanted. Testing into compliance — running a sample repeatedly until a passing result appears, and reporting only that one — is not a documentation lapse. It is fraud, it is prosecuted, and it has ended companies.

The corresponding discipline is unglamorous: an out-of-specification result triggers an investigation, and the original result stands in the record whatever the investigation concludes.

4. The Quality Management System

ElementStandardNote
Standard operating proceduresCurrent, controlled, version-managedWork is performed to written procedure; a procedure nobody follows is a finding.
Training and qualificationDocumented per person per procedureTraining records are among the first things an inspector requests.
Deviation managementRecorded, investigated, closedEvery departure from procedure, planned or otherwise.
CAPACorrective and preventive actionCorrective fixes this instance; preventive addresses the cause. Both required.
Change controlAssessed before implementationAny change to a validated process, system or method.
Audit programInternal, vendor, and for-causeIndependent of the function being audited.
Document controlIssue, revision, retirement, retentionIncluding the ability to show which version was in force on a given date.
Supplier qualificationAssessed before use, re-assessed periodicallyAldergate, Meridian and Kestrel are all qualified suppliers under this element.
Deviations and CAPA are the pair that reveals whether a quality system is real. A deviation is any departure from written procedure. Recording one is not an admission of failure — it is the system working. What matters is the investigation: a root cause that survives scrutiny, a corrective action that fixes this instance, and a preventive action that addresses why it could happen at all.

A CAPA whose preventive action is “retrain the operator” is almost always a CAPA that has not found the root cause. People do not spontaneously forget procedures; procedures are unclear, systems permit error, or workload makes compliance impractical.

5. Electronic Records — 21 CFR Part 11

Every GxP system holding regulated records is subject to Part 11 (Constraint C-02).

RequirementStandardScope
Validated systemsEach GxP system validated for intended useEDC, safety database, document management, manufacturing execution.
Audit trailsAutomatic, unalterable, independently reviewableWho changed what, when, and why. Reviewed, not merely enabled.
Electronic signaturesUnique to one individual, never reassigned
Access controlRole-based, reviewed periodicallyLeavers removed promptly — a common audit finding.
Copy and retentionTrue copies producible for the retention period
Audit trails must be reviewed, not merely enabled. Turning on an audit trail satisfies the technical requirement and none of the intent. The obligation is that someone examines it — that unusual patterns of change, out-of-hours edits, or repeated modifications to the same field are actually looked at by a person with the standing to ask about them.

“The system captures it” is an answer that invites the next question, which is “show me who reviewed it and when.”

6. Audit Program

Audit typePosition
Internal audits6 of 8 planned complete
Vendor audits4 of 5 planned complete
For-cause audits1
CAPA open3
CAPA overdue0

The for-cause audit is the one worth reading. Triggered by I-02. Audit of Aldergate analytical laboratory following the method transfer failure. Two observations, both closed.

That audit is the quality system responding correctly to I-02. A method transfer failed first-pass acceptance. The commercial response would have been to fix it and move on. The quality response was to ask whether the failure indicated something about the laboratory rather than something about the method — which is a different question, and one clinical operations was not positioned to ask because it was busy solving the immediate problem.

Two observations were raised and closed. Neither was serious. But the audit existing at all is what separates a program that recovered from an incident from one that learned from it.

Audits are conducted by Quality Assurance, independent of the function being audited, and QA's right of access to vendors is unconditional and requires no notice (see the CRO Oversight Plan §4).

Zero overdue CAPAs is the metric worth watching here. Open CAPAs are normal and healthy. Overdue CAPAs indicate a quality system that raises issues faster than it resolves them, which is the pattern that precedes an inspection finding.

What Happens When GxP Is Breached

The consequence gradient is rarely written down, which is why compliance can feel abstract until it is not. Each step is a different kind of event, not a more serious version of the last.

LevelWhat it isConsequence
Internal deviationRecorded and investigated by the site or functionNo external consequence. The system working.
Internal audit findingCAPA raised, owner and date assignedNo external consequence, provided it closes.
Form 483 observationInspector's written observations at the end of an inspectionResponded to within 15 working days. Not a finding of violation.
Warning LetterAgency letter alleging significant violationsPublic. Can delay approvals across the company, not only the product inspected.
Import alert / detentionProduct refused entry or detainedSupply interruption. Applies to specific facilities.
Consent decreeCourt-enforced agreement, often with an independent monitorExistential. Can suspend manufacturing at a site indefinitely.
The first two levels are the quality system working, not failing. A recorded deviation with a sound investigation is evidence of control. As §6 notes, a site with no recorded deviations is not reassuring — it is a site whose recording practices should be examined.

The break in the ladder is between a Form 483 observation and a Warning Letter. A 483 lists an inspector's observations and is not a finding of violation; it is answered, and most are closed. A Warning Letter alleges significant violations, is public, and can delay approvals across a company's entire portfolio — not only the product whose facility was inspected.
That cross-portfolio effect is why GxP cannot be traded against a single program's schedule. A Program Director weighing compliance effort against a filing date is not weighing it against their filing date. They are weighing it against every filing date in the company, including programs that do not yet exist.

It is also why the escalation ladder ends where it does. A consent decree is court-enforced, often with an independent monitor installed, and can suspend manufacturing at a site indefinitely. No program schedule survives that, and no program-level decision should be able to reach it.

Self-reporting

Where a significant breach is identified internally, the sponsor may report it to the agency before an inspection finds it. That is uncomfortable and generally correct: a self-reported issue with a completed investigation and effective corrective action demonstrates a functioning quality system, while the same issue found by an inspector demonstrates the opposite.

7. Responsibilities

AccountabilityHolder
Quality system ownershipDr. I. Solberg, Chief Quality Officer
GCP compliance at sitesSites and Meridian, verified by Vitalis QA
GMP compliance in manufactureAldergate, verified by Vitalis QA
Data integrity in clinical systemsData Management, audited by QA
Part 11 system validationEach system owner, verified by QA
Audit programQuality Assurance, independent of all of the above
Inspection responseRetained by Vitalis — not delegable
The Chief Quality Officer sits on the Development Committee as an observer without a vote (see the Development Committee Charter §2). That is deliberate and follows directly from §1 of this document: a vote implies a position that four other votes could outweigh, and GxP compliance cannot be outvoted. Giving the CQO a vote would mischaracterize the nature of the obligation.

Full access, full speaking rights, a standing entry in the minutes — and no vote, because the matters the CQO speaks to are not the kind that get decided by majority.