Compliance Radar
It is the second Tuesday of the quarter at the Leuven API manufacturing facility. The Quality Director opens ProBeya's Compliance Radar and reviews the dashboard before the Management Review meeting. The radar shows 247 tracked requirements across four frameworks: EU GMP Annex 11 (78 requirements), FDA 21 CFR Part 11 (52), ICH Q10 (68), and EU GMP Annex 15 (49). Of these, 221 are compliant, 8 have gaps identified, 14 have remediation in progress, and 4 are non-compliant. The 4 non-compliant items are all high-risk — and all four have linked corrective actions with due dates within the next 30 days.
She filters by "next assessment overdue" and finds 12 requirements that have not been reassessed in over 12 months. She assigns assessors and schedules the reviews. In 20 minutes, she has a complete picture of the organization's regulatory posture, evidence of management oversight, and a prioritized remediation plan — exactly what the upcoming EMA inspection team will ask for.
Why Compliance Radar Exists
Regulated organizations face hundreds of compliance requirements across multiple frameworks. In pharma manufacturing, these requirements are not academic — non-compliance can result in warning letters, consent decrees, import alerts, or facility closures. The 2023 FDA Warning Letter to a major CDMO cited "failure to maintain a system for tracking and remediating compliance gaps" as a primary finding.
The challenge is not knowing the requirements. Every quality professional knows EU GMP and 21 CFR Part 11. The challenge is tracking the current state of each requirement across time: Which requirements are met? Which have gaps? Which are overdue for reassessment? Who owns what? Where is the evidence?
Spreadsheets fail at this for three reasons: they lack an audit trail, they have no concept of assessment history, and they cannot aggregate across frameworks to give leadership a unified view.
Compliance Radar solves these problems by treating each regulatory requirement as a tracked, assessed, risk-classified entity with full history.
Compliance Radar is not a replacement for your quality management system (QMS). It is the management layer that sits above your QMS and gives you — and your executive team — real-time visibility into the organization's compliance posture. Use it to prepare for inspections, drive management reviews, and prioritize remediation resources.
Registering Compliance Requirements
Each requirement represents a single clause or control from a regulatory framework.
Creating a Requirement
- Navigate to the Compliance Radar section
- Click New Requirement
- Fill in the requirement details:
| Field | Description | Example |
|---|---|---|
| Framework | Regulatory framework name | "EU GMP Annex 11" |
| Clause | Specific section reference | "12.4" |
| Title | Short description | "Segregation of duties for data review" |
| Category | Grouping label | "data integrity" |
| Applicability | Whether it applies to this organization | Applicable / Not Applicable / Partial |
| Status | Current compliance state | Compliant / Non-Compliant / Gap Identified / Remediation in Progress |
| Risk Level | Impact classification for non-compliance | Low / Medium / High / Critical |
| Owner | Person responsible for maintaining compliance | QA Manager |
| Evidence | Supporting documentation (JSONB) | Links to SOPs, validation reports, screenshots |
| Next Assessment Due | Scheduled date for periodic review | 2026-07-15 |
Applicability Assessment
Not every requirement applies to every organization. A facility that does not use electronic signatures may mark FDA 21 CFR Part 11 Section 11.200 (electronic signatures) as "Not Applicable" — but must document the rationale. The applicability field captures this decision.
| Applicability | Meaning |
|---|---|
| Applicable | Requirement applies and must be assessed |
| Not Applicable | Requirement does not apply — document rationale |
| Partial | Requirement partially applies — document scope |
When onboarding a new regulatory framework, create requirements from the official clause list rather than cherry-picking. This ensures complete coverage from day one. It is far better to mark 30 requirements as "Not Applicable" with documented rationale than to discover during an inspection that you missed a requirement entirely.
Compliance Statuses
| Status | Meaning | Action Required |
|---|---|---|
| Compliant | Requirement fully met with documented evidence | Schedule periodic reassessment |
| Non-Compliant | Requirement not met | Immediate remediation — create corrective action |
| Gap Identified | Assessment revealed a gap that needs investigation | Investigate scope and plan remediation |
| Remediation in Progress | Corrective actions are underway | Monitor progress, track due dates |
Risk Classification
| Level | Description | Inspection Impact | Response Time |
|---|---|---|---|
| Low | Minor finding, limited regulatory impact | Observation | Plan within 90 days |
| Medium | Moderate risk, requires planned remediation | 483 observation likely | Plan within 30 days |
| High | Significant risk, priority remediation needed | 483 observation + Warning Letter risk | Remediate within 15 days |
| Critical | Immediate regulatory exposure | Warning Letter / Consent Decree risk | Remediate immediately |
Focus remediation on Critical and High risk non-compliant items first. The risk-level dashboard view helps leadership allocate scarce QA resources where they matter most. A site with 200 compliant items and 4 critical non-compliant items is in worse shape than a site with 180 compliant items and 20 low-risk gaps — and the dashboard makes this visible.
Periodic Assessments
Compliance is not a one-time event. Requirements must be reassessed periodically to ensure ongoing compliance. ProBeya captures assessments as point-in-time evaluations.
Recording an Assessment
Each assessment captures:
| Field | Description |
|---|---|
| Assessor | Authenticated user conducting the assessment |
| Previous Status | Captured automatically from the requirement |
| New Status | Updated compliance state after assessment |
| Findings | Detailed text describing assessment results |
| Evidence | Links to supporting documents, screenshots, system outputs |
| Recommended Actions | Next steps if gaps were identified |
When an assessment is created, the parent requirement's status and lastAssessedAt timestamp are automatically updated.
Worked Example: EU GMP Annex 11 Section 12.4 Assessment
Requirement: "Electronic records must include a clear indication of who performed the review and when."
Annual assessment by QA Manager:
- Previous Status: Compliant
- Findings: "Reviewed the MES audit trail configuration. All batch record review activities log the reviewer's user ID and timestamp. However, the new LIMS module (installed Q3 2025) does not capture reviewer identity for OOS result reviews. Gap identified."
- New Status: Gap Identified
- Risk Level: Updated from Low to High (data integrity impact)
- Evidence: Screenshots of MES audit trail (compliant) and LIMS audit trail (gap)
- Recommended Actions: "LIMS vendor to implement reviewer tracking in next release (Q2 2026). Interim manual procedure SOP-QC-089 implemented."
This assessment creates a dated, attributed record showing that the organization actively monitors compliance and responds to gaps — exactly the evidence that regulators want to see.
The Dashboard
The compliance dashboard provides the aggregated view that leadership needs:
Status Distribution
| Status | Count | Percentage |
|---|---|---|
| Compliant | 221 | 89.5% |
| Gap Identified | 8 | 3.2% |
| Remediation in Progress | 14 | 5.7% |
| Non-Compliant | 4 | 1.6% |
Risk Distribution
Visual breakdown of non-compliant and gap items by risk level — highlights where the organization is most exposed.
Framework Breakdown
Compliance posture by regulatory framework — useful for preparing for framework-specific inspections (e.g., an upcoming FDA pre-approval inspection focuses on 21 CFR Part 11 items).
Overdue Assessments
Requirements where nextAssessmentDue has passed without a new assessment — these are the items that auditors will flag during an inspection as evidence of inadequate self-inspection programs.
Regulatory Framework Reference
Compliance Radar is designed to track requirements from any regulatory framework. Common frameworks used in pharma manufacturing:
| Framework | Scope | Typical Requirement Count |
|---|---|---|
| EU GMP Annex 11 | Computerized systems | 70-90 |
| FDA 21 CFR Part 11 | Electronic records and signatures | 40-60 |
| ICH Q10 | Pharmaceutical quality system | 60-80 |
| EU GMP Annex 15 | Qualification and validation | 40-60 |
| EU GMP Annex 1 | Sterile manufacturing | 100-150 |
| ISO 13485:2016 | Medical device quality management | 50-80 |
| PIC/S PE 009 | GMP inspection guidance | 80-120 |
Two weeks before a regulatory inspection, filter Compliance Radar by the relevant framework. Ensure all requirements are assessed within the last 12 months, all non-compliant items have active remediation plans with evidence, and the dashboard can be presented to inspectors as evidence of your self-inspection program. This preparation alone can shift an inspection from adversarial to collaborative.
Integration with the Quality System
Compliance Radar connects to the broader ProBeya ecosystem:
- Action Log: Create corrective actions directly from non-compliant requirements — tracked with the same TIER-based escalation as all other actions
- KPI Boards: Track compliance KPIs (e.g., "% requirements compliant", "overdue assessments count") on your Quality SQCDP board
- Inspections Module: Run mock inspections against your requirement baseline to test audit readiness
- TIER Meetings: Review critical compliance items during TIER 3 monthly steering meetings
Permissions
| Action | Required Role |
|---|---|
| Create/edit requirements | Compliance manager or admin |
| Record assessments | Compliance assessor or admin |
| View requirements and dashboard | Any organization member |
| Assign owners | Compliance manager or admin |
Related Features
- Inspections — Run simulated inspections to prepare for regulatory audits
- IFQHC Framework — Competency assessments aligned with compliance requirements
- Action Log — Create and track actions for remediation of compliance gaps
- KPI Boards — Track compliance KPIs (% compliant, overdue assessments, remediation velocity)