We've updated our Privacy Policy to make it clearer how we use your personal data. We use cookies to provide you with a better experience. You can read our Cookie Policy here.
Monika has over a decade of experience in formulating and executing strategies for data integrity and data governance assessments and remediation, risk management and computerized system validation within the pharmaceutical sector.
Laura Lansdowne is the managing editor at Technology Networks, she holds a first-class honors degree in biology. Before her move into scientific publishing, Laura worked at the Wellcome Sanger Institute and GW Pharma.
Sartorius' ambition is to simplify medical progress, from the first idea of a new medication to its production. They support their customers with innovative technologies that make the development and manufacture of new therapeutics faster and more efficient, so that more people have access to better medicine.
Small gaps in data management can quickly become compliance issues, affecting data integrity, operational efficiency, and regulatory readiness.
In regulated laboratories, poorly defined requirements, supplier overreliance, infrastructure limitations, weak governance, and inadequate oversight often create downstream risks that are costly to correct.
This guide explores six common sources of data noncompliance and provides practical strategies to strengthen data lifecycle management.
Download this guide to discover:
How to identify and address the root causes of data integrity and compliance failures before they escalate.
Strategies to improve system selection, supplier oversight, data governance, and infrastructure planning.
Practical approaches to developing data literacy and reducing compliance risk across the data lifecycle.
1
Dodging the Data Noncompliance
Domino Effect
Monika Andraos, ASQ CQE
Is the state of your data’s noncompliance really a series of unfortunate events or a series of avoidable
practices? Data is the foundation of decision-making and regulatory trust, and thus, small inconsistencies
or trivial negligence can quickly trigger a domino effect of noncompliance.
In a regulated lab, compliance is as meticulously designed as a carefully arranged series of dominoes. Managing
data throughout its lifecycle requires both a bird’s-eye view of the overall process and a worm’s-eye
view of the finer details involved in designing, acquiring, processing, reporting, and retaining data. As with
dominoes, preventing an accidental trigger is more effective (and cheaper in the long run) than correcting it,
as its impact has already set off a downstream chain reaction that also requires remediation.
In this guide, we address the root cause of six common issues seen in the lab to stop and reverse the
noncompliance domino chain reaction and instead build trustworthy data where compliance is a natural
by-product of process understanding and control.
Domino 1: Blurred vision, incomplete requirements
Before a single domino is placed, there needs to be a master plan for the sequencing and mapping of kinetic
energy; what is the potential, impact, and risk? Similarly, an effective lab strategy requires a carefully
considered vision when selecting a system, one that aligns with the user (organizational) requirements
and its intended use. System requirements form the foundation of the entire vision, underpinning system
selection, risk management, validation, and traceability; yet they are often overlooked and receive the
least investment.
We see the first domino begin to tip most often during the end-of-year slush-fund scramble, which pushes
departments to spend their surplus budgets on a new system before they lose them in the new fiscal
year. Requirement specifications are quickly actioned to satisfy the paperwork quota, but are neither
complete, accurate, nor correct due to incomplete visions and rushed timelines. Requirements may be incomplete,
copied and pasted from outdated documents containing stagnant requirements, poorly elicited,
or copied verbatim from standards and regulations without consideration of their specific context.
The result? A poorly selected system that requires workarounds for integration, configuration, operation,
and additional resources. In the worst cases, it becomes "shelfware"—an expensive system left collecting
dust because it doesn't have adequate technical controls to ensure data integrity, doesn’t fit the actual
workflow, and/or generates data that cannot be leveraged effectively for integration or analytics.
How To Guide
HOW TO DODGE THE DATA NONCOMPLIANCE DOMINO EFFECT 2
While lab SMEs cannot predict and prevent every unexpected system breakdown, they can reduce the
downstream “domino” effect by maintaining living system requirements (more commonly referred to
as user requirements). So, when a new or similar system is needed quickly, a strong foundation already
exists, reducing the time and effort needed to implement a sustainable solution.
The recovery strategy:
• Engage IT, QA, procurement, and management early to ensure the vision addresses the full data
lifecycle.
• Eliminate workflows that require manual transcription, duplication, paper records, or spreadsheet-
based calculations, as these can introduce data integrity risks.
• Implement controlled electronic workflows with e-signatures to preserve data integrity and
traceability.
• Evaluate the supplier beyond their product offering; their responsiveness, technical expertise, timeliness,
and general integrity are important indicators for future partnership success.
Top tip: Don’t design the requirements, architecture, workflows, and configurations from scratch
every time. Review the previous 12-24 months of relevant QMS events and IT tickets to identify
recurring issues. New requirements should explicitly "design out" these previous failures to
prevent repeat noncompliance events.
Domino 2: Outsourced accountability
A poorly and hastily selected system inevitably leads to an overreliance on the supplier and their standard
validation package. When an organization simply "copies and pastes" supplier documentation and training
materials, it has already tipped the second domino.
Instead of having selected a system to support your process, you are now forced to change the process to
accommodate a poorly selected system. Often, generic, vendor-supplied training sessions fails to address
specific system configurations or newly modified workflows. While suppliers may be experts in the system’s
code, you are the expert when it comes to the process and operational context.
For example, a lab may only realize after go-live that the system database is configured to automatically
overwrite the oldest data once it reaches a size limit; a feature that was never mentioned in passing or
during training. Suddenly, the "time-saving" vendor package has created a massive compliance deficit,
requiring immediate emergency controls, retrieval, testing, deviations, additional resources, and manual
monitoring to secure past, current, and future critical data.
Regulators are clear: the responsibility of intimately knowing the system, including its uses, functions,
validation, data management, vulnerabilities, and risks, lies solely with the regulated user. This means
adequate control, ownership, and training.
How To Guide
HOW TO DODGE THE DATA NONCOMPLIANCE DOMINO EFFECT 3
The recovery strategy:
• Examine technical documents, rather than whitepapers and marketing materials: Read manuals and
specifications before purchase, and challenge features that may impact current processes and/or
data handling.
• Challenge the demo: Request specific "stress-test" demos of features that could introduce compliance
risks (e.g., deletions, overwrites).
• Use supplier documentation as a supplement to your testing, not a substitute. Adapt these documents
and training materials to reflect your specific requirements, processes, and nuances.
Domino 3: Infrastructure gap
An over-reliance on the supplier can lead to a superficial understanding of the newly acquired system.
When a vendor’s validation is copied over without adequate review, you inherit assumptions that may not
account for your specific facility constraints, workflows, or user behaviors.
We see the third domino quickly topple when the system is compliant on paper but operationally broken.
The supplier’s expertise cannot expand out to deliver data integrity and quality within the boundaries of
the implementing company—we know trustworthy and reliable data requires behavioral and procedural
controls, not just technical ones.
For example, a company purchases seven identical units designed to integrate simultaneously via a secure
network. However, during installation, they discover the specific areas lack secure Wi-Fi connections,
meaning they cannot be integrated into the network in the immediate short term.
Treating each system individually, as a workaround, creates isolated data silos that increase compliance
risk. Instead of managing one integrated environment, data must be manually transferred and synchronized
across seven systems, each requiring its own configuration, security, maintenance, troubleshooting,
user management, time synchronization, backups, and data governance. All of this is in addition to the
integration work that will likely be required in the future. The company will now be executing and paying
for two separate implementations. The dominoes are reaching terminal velocity now as resources and
compliance risk increase tenfold.
Top Tip: Leverage vendor expertise to identify potential risks before purchase. If vulnerabilities
are found, collaborate with them to see if the system can be modified to meet your requirements
before moving forward. A strong relationship can help suppliers improve their products while
ensuring it is fit for purpose.
How To Guide
HOW TO DODGE THE DATA NONCOMPLIANCE DOMINO EFFECT 4
The recovery strategy:
• Before finalizing a purchase, walk the physical area with the vendor, IT, and engineering at a minimum.
Map the data flow and trace the path a data point takes from the source (i.e., the instrument) to the
server. Identify physical "dead zones" or security risks (e.g., lack of ports, Wi-Fi, or access space) that
would force an SME to use a workaround.
Domino 4: Knowledge atrophy
Whether a system much like the one in the previous example was inherited or inadvertently implemented,
it quickly becomes a landmine of manual data handling.
The domino tipping continues to accelerate when it comes to the data governance side of process control.
Workarounds introduced at the beginning of the data lifecycle during design and planning continue to
adversely affect the subsequent stages—from data creation and processing, to review, reporting, storage,
and archival. The resources involved in maintaining this delicate and complicated data make it difficult to
clarify data ownership, especially if the supplier is still perceived as the go-to expert; internal staff never
acquire the deep, personalized confidence required to steward the data or defend it during an audit. This
is compounded by any personnel departures and onboarding of new staff.
The result is a decline in knowledge management and data literacy, limiting the ability of lab SMEs to spot
noncompliance, identify discrepancies and trends, or effectively troubleshoot issues. This level of analysis
requires a thorough understanding of the system within its current processes.
For example, a lab using a cloud-based SaaS chromatography data system (CDS) might start approving
all software updates automatically without first performing internal impact assessments. Over time,
SMEs lose the technical fluency and data literacy needed to recognize when even a minor software patch
may cause unintended variation.
The recovery strategy:
• Transition the team from system "users" to business process "owners”. Map the data lineage and flow
to identify where governance is unclear or missing.
Top Tip: Leverage the supplier for their technical expertise, but ensure an internal SME is
always accountable for the data strategy, quality, and oversight. This is especially critical for
SaaS or cloud solutions, where the physical data seems secure, but the regulatory justification
remains yours.
Top Tip: Make the best behavior the easiest behavior. With a multidisciplinary team, review the
workflows for extra or tedious steps to sync, secure, or process data that may trigger behavioral
shortcuts. Design the process that makes it harder to be non-compliant than it is to be compliant.
How To Guide
HOW TO DODGE THE DATA NONCOMPLIANCE DOMINO EFFECT 5
Domino 5: Firefighting instead of governing
When data governance is weak, ongoing data monitoring and trend analysis inevitably follow suit. At this
point, a lab is no longer looking for problems; it’s waiting to react to consequences. During an inspection,
regulators expect more than a "pass/fail" outcome. They require evidence that the regulated user understands
how data moves through the system, where risks arise, and how control is maintained through its
entire lifecycle.
Curiosity, fueled by accumulated experience, helps organizations monitor the systems, data, trends, and
trajectory to avoid issues before they occur. The difference between a reactive and a proactive organization
can easily be identified by the two statements:
1. "I print out the PDF and make sure the value is within the parameters stipulated in the procedure."
2. "I’ve noticed when the value is consistently in the upper range of the parameter, it’s acceptable, but
this indicates the instrument should be scheduled for preventative maintenance soon before performance
deteriorates."
The difference between a data pusher (the first statement) and a data steward (the second statement)
is a knowledgeable and empowered SME who understands the system well enough to recognize subtle
sources of variation before they become problematic. Compliance becomes a natural byproduct as data
and metadata provide precious information and analytics about the process as a whole and shape any
decisions made. This is especially critical if you want to adopt artificial intelligence, as these systems
require constant vigilance and lifecycle-based monitoring to detect drift that could impact compliance and
process control.
The recovery strategy:
• Empower SMEs to trust their technical intuition. Don’t tolerate software that is simply delivered; actively
work with suppliers to tailor solutions that ensure data can be explored, understood, and transformed
to be used to communicate and convince others with the information and knowledge behind it
to make sound decisions.
Domino 6: Need-it-yesterday management
Is management steadying the dominos or the force that sets them in motion? Management focused
primarily on costs and profits often avoids continual improvement initiatives due to a perceived delay in
ROI and slightly longer timelines. This short-term focus may limit investment in quality risk management,
hinder the development of a strong data culture and good digital hygiene. While it's notable that CGMPs
don't explicitly mention any management responsibility, the US Food and Drug Administration (FDA) has
sent warning letters for data integrity violations to companies like Stason Pharmaceuticals and Tender
Corporation, for failure to control their computerized systems with a comprehensive remediation plan
Top Tip: Encourage curiosity within teams by moving away from fear-based compliance, towards
a learning-based culture that is not afraid of identifying mistakes. This is not an innate quality; it
is a learned behavior that constantly looks for answers around the “why” rather than looking for
blame to assign “right” or “wrong”.
How To Guide
HOW TO DODGE THE DATA NONCOMPLIANCE DOMINO EFFECT 6
requiring management to have knowledge of computerized systems. In reality, the failure points of the
earlier dominoes directly stem from the management deficiencies illustrated by these two cases.
The recovery strategy:
• Management must be actively involved in end-to-end implementation as well as ongoing use of computerized
systems. Gemba walks are essential—not only to reinforce the importance of quality, but also to
listen to feedback, helping uncover issues and bottlenecks. This provides a clearer understanding of the
timelines and governance resources needed to protect data, products, and investment.
Summary
This guide highlights the key contributing factors encountered by laboratories that lead to a domino effect
of data noncompliance. It is not a series of unfortunate ad-hoc events or isolated decisions. Rather, it is a
predictable chain reaction triggered by systemic blind spots in design, supplier overreliance, infrastructure
gaps, knowledge mismanagement, weak governance, and shortsighted executive prioritization.
The beauty of the domino effect is that the chain reaction can be interrupted at any single domino. Laboratories
can permanently stabilize their foundations by performing an honest assessment of their current
state and investing in technical curiosity, robust data literacy, and a proactive senior leadership that
cultivates an open quality culture.
Sponsored by
Acknowledgements
Special thanks to Bob McDowall for his time and effort in the review of this guide.
About the Author
Monika Andraos has over a decade of experience in formulating and executing strategies for data integrity and data governance
assessments and remediation, risk management and computerized system validation within the pharmaceutical sector. She has
worked within Quality, Technical Operations, Automation and Regulatory Affairs to execute and deliver compliant system solutions
in regulated GXP environments.
Top Tip: People follow leadership behaviors and tone, not posters on a wall. Ensure leadership
reviews and reinforces the incentives and recognition that encourage continuous learning,
curiosity, transparency, problem-solving, accountability, and engagement.
How To Guide
Sponsored by
SartoriusSartorius' ambition is to simplify medical progress, from the first idea of a new medication to its production. They support their customers with innovative technologies that make the development and manufacture of new therapeutics faster and more efficient, so that more people have access to better medicine.
Information you provide will be shared with the sponsors for this content. Technology Networks or its sponsors may contact you to offer you content or products based on your interest in this topic. You may opt-out at any time.