Ga naar hoofdinhoud

Compliance Radar

It is the second Tuesday of the quarter at the Leuven API manufacturing facility. The Quality Director opens ProBeya's Compliance Radar and reviews the dashboard before the Management Review meeting. The radar shows 247 tracked requirements across four frameworks: EU GMP Annex 11 (78 requirements), FDA 21 CFR Part 11 (52), ICH Q10 (68), and EU GMP Annex 15 (49). Of these, 221 are compliant, 8 have gaps identified, 14 have remediation in progress, and 4 are non-compliant. The 4 non-compliant items are all high-risk — and all four have linked corrective actions with due dates within the next 30 days.

She filters by "next assessment overdue" and finds 12 requirements that have not been reassessed in over 12 months. She assigns assessors and schedules the reviews. In 20 minutes, she has a complete picture of the organization's regulatory posture, evidence of management oversight, and a prioritized remediation plan — exactly what the upcoming EMA inspection team will ask for.

Why Compliance Radar Exists​

Regulated organizations face hundreds of compliance requirements across multiple frameworks. In pharma manufacturing, these requirements are not academic — non-compliance can result in warning letters, consent decrees, import alerts, or facility closures. The 2023 FDA Warning Letter to a major CDMO cited "failure to maintain a system for tracking and remediating compliance gaps" as a primary finding.

The challenge is not knowing the requirements. Every quality professional knows EU GMP and 21 CFR Part 11. The challenge is tracking the current state of each requirement across time: Which requirements are met? Which have gaps? Which are overdue for reassessment? Who owns what? Where is the evidence?

Spreadsheets fail at this for three reasons: they lack an audit trail, they have no concept of assessment history, and they cannot aggregate across frameworks to give leadership a unified view.

Compliance Radar solves these problems by treating each regulatory requirement as a tracked, assessed, risk-classified entity with full history.

For Quality Directors

Compliance Radar is not a replacement for your quality management system (QMS). It is the management layer that sits above your QMS and gives you — and your executive team — real-time visibility into the organization's compliance posture. Use it to prepare for inspections, drive management reviews, and prioritize remediation resources.

Registering Compliance Requirements​

Each requirement represents a single clause or control from a regulatory framework.

Creating a Requirement​

  1. Navigate to the Compliance Radar section
  2. Click New Requirement
  3. Fill in the requirement details:
FieldDescriptionExample
FrameworkRegulatory framework name"EU GMP Annex 11"
ClauseSpecific section reference"12.4"
TitleShort description"Segregation of duties for data review"
CategoryGrouping label"data integrity"
ApplicabilityWhether it applies to this organizationApplicable / Not Applicable / Partial
StatusCurrent compliance stateCompliant / Non-Compliant / Gap Identified / Remediation in Progress
Risk LevelImpact classification for non-complianceLow / Medium / High / Critical
OwnerPerson responsible for maintaining complianceQA Manager
EvidenceSupporting documentation (JSONB)Links to SOPs, validation reports, screenshots
Next Assessment DueScheduled date for periodic review2026-07-15

Applicability Assessment​

Not every requirement applies to every organization. A facility that does not use electronic signatures may mark FDA 21 CFR Part 11 Section 11.200 (electronic signatures) as "Not Applicable" — but must document the rationale. The applicability field captures this decision.

ApplicabilityMeaning
ApplicableRequirement applies and must be assessed
Not ApplicableRequirement does not apply — document rationale
PartialRequirement partially applies — document scope
Bulk Import by Framework

When onboarding a new regulatory framework, create requirements from the official clause list rather than cherry-picking. This ensures complete coverage from day one. It is far better to mark 30 requirements as "Not Applicable" with documented rationale than to discover during an inspection that you missed a requirement entirely.

Compliance Statuses​

StatusMeaningAction Required
CompliantRequirement fully met with documented evidenceSchedule periodic reassessment
Non-CompliantRequirement not metImmediate remediation — create corrective action
Gap IdentifiedAssessment revealed a gap that needs investigationInvestigate scope and plan remediation
Remediation in ProgressCorrective actions are underwayMonitor progress, track due dates

Risk Classification​

LevelDescriptionInspection ImpactResponse Time
LowMinor finding, limited regulatory impactObservationPlan within 90 days
MediumModerate risk, requires planned remediation483 observation likelyPlan within 30 days
HighSignificant risk, priority remediation needed483 observation + Warning Letter riskRemediate within 15 days
CriticalImmediate regulatory exposureWarning Letter / Consent Decree riskRemediate immediately
Risk-Based Prioritization

Focus remediation on Critical and High risk non-compliant items first. The risk-level dashboard view helps leadership allocate scarce QA resources where they matter most. A site with 200 compliant items and 4 critical non-compliant items is in worse shape than a site with 180 compliant items and 20 low-risk gaps — and the dashboard makes this visible.

Periodic Assessments​

Compliance is not a one-time event. Requirements must be reassessed periodically to ensure ongoing compliance. ProBeya captures assessments as point-in-time evaluations.

Recording an Assessment​

Each assessment captures:

FieldDescription
AssessorAuthenticated user conducting the assessment
Previous StatusCaptured automatically from the requirement
New StatusUpdated compliance state after assessment
FindingsDetailed text describing assessment results
EvidenceLinks to supporting documents, screenshots, system outputs
Recommended ActionsNext steps if gaps were identified

When an assessment is created, the parent requirement's status and lastAssessedAt timestamp are automatically updated.

Worked Example: EU GMP Annex 11 Section 12.4 Assessment​

Requirement: "Electronic records must include a clear indication of who performed the review and when."

Annual assessment by QA Manager:

  • Previous Status: Compliant
  • Findings: "Reviewed the MES audit trail configuration. All batch record review activities log the reviewer's user ID and timestamp. However, the new LIMS module (installed Q3 2025) does not capture reviewer identity for OOS result reviews. Gap identified."
  • New Status: Gap Identified
  • Risk Level: Updated from Low to High (data integrity impact)
  • Evidence: Screenshots of MES audit trail (compliant) and LIMS audit trail (gap)
  • Recommended Actions: "LIMS vendor to implement reviewer tracking in next release (Q2 2026). Interim manual procedure SOP-QC-089 implemented."

This assessment creates a dated, attributed record showing that the organization actively monitors compliance and responds to gaps — exactly the evidence that regulators want to see.

The Dashboard​

The compliance dashboard provides the aggregated view that leadership needs:

Status Distribution​

StatusCountPercentage
Compliant22189.5%
Gap Identified83.2%
Remediation in Progress145.7%
Non-Compliant41.6%

Risk Distribution​

Visual breakdown of non-compliant and gap items by risk level — highlights where the organization is most exposed.

Framework Breakdown​

Compliance posture by regulatory framework — useful for preparing for framework-specific inspections (e.g., an upcoming FDA pre-approval inspection focuses on 21 CFR Part 11 items).

Overdue Assessments​

Requirements where nextAssessmentDue has passed without a new assessment — these are the items that auditors will flag during an inspection as evidence of inadequate self-inspection programs.

Regulatory Framework Reference​

Compliance Radar is designed to track requirements from any regulatory framework. Common frameworks used in pharma manufacturing:

FrameworkScopeTypical Requirement Count
EU GMP Annex 11Computerized systems70-90
FDA 21 CFR Part 11Electronic records and signatures40-60
ICH Q10Pharmaceutical quality system60-80
EU GMP Annex 15Qualification and validation40-60
EU GMP Annex 1Sterile manufacturing100-150
ISO 13485:2016Medical device quality management50-80
PIC/S PE 009GMP inspection guidance80-120
Preparing for an Inspection

Two weeks before a regulatory inspection, filter Compliance Radar by the relevant framework. Ensure all requirements are assessed within the last 12 months, all non-compliant items have active remediation plans with evidence, and the dashboard can be presented to inspectors as evidence of your self-inspection program. This preparation alone can shift an inspection from adversarial to collaborative.

Integration with the Quality System​

Compliance Radar connects to the broader ProBeya ecosystem:

  • Action Log: Create corrective actions directly from non-compliant requirements — tracked with the same TIER-based escalation as all other actions
  • KPI Boards: Track compliance KPIs (e.g., "% requirements compliant", "overdue assessments count") on your Quality SQCDP board
  • Inspections Module: Run mock inspections against your requirement baseline to test audit readiness
  • TIER Meetings: Review critical compliance items during TIER 3 monthly steering meetings

Permissions​

ActionRequired Role
Create/edit requirementsCompliance manager or admin
Record assessmentsCompliance assessor or admin
View requirements and dashboardAny organization member
Assign ownersCompliance manager or admin
  • Inspections — Run simulated inspections to prepare for regulatory audits
  • IFQHC Framework — Competency assessments aligned with compliance requirements
  • Action Log — Create and track actions for remediation of compliance gaps
  • KPI Boards — Track compliance KPIs (% compliant, overdue assessments, remediation velocity)