Handover of Computerised Systems to the Operating Department
Excerpt from the GMP Compliance Adviser, Chapter 9.F, Operation of computerised systems
7 min. reading time | by Dennis Sandkühler, Director Quality & Compliance, Digital Life Sciences
Published in LOGFILE 16/2026
The GMP-compliant handover of computerised systems to operations is a critical step in the Computer System Validation (CSV) lifecycle. Beyond go-live and hypercare, clearly defined responsibilities, comprehensive documentation and well-trained personnel are essential to maintaining a validated state throughout routine operation.
Implementation and commissioning
The implementation and subsequent commissioning, or “go-live” of computerised systems require careful planning and continuous monitoring to ensure their integrity, security and up-time system availability. This section covers the key aspects of implementation and those tasks that need to be completed prior to go-live.

Figure 1 | Operation of computerised systems
The implementation of computerised systems involves several steps to ensure that the systems meet the requirements and are ready for productive operation. With regard to go-live of productive operation, however, preparatory activities should already be planned during the implementation phase of the project.
- Planning, specification and risk assessment: Before implementation, the system requirements must be specified and documented in detail. This includes functional and non-functional requirements, security requirements and regulatory requirements in accordance with the EU GMP Guidelines. An approach to continual risk assessment with regard to fulfilment of the requirements should be aligned in the planning phase. The designated operational support team should be involved in the planning in order to communicate requirements and risks to system operation at an early stage.
- System selection and development: The appropriate system is selected or developed based on the specifications. It is important to select a qualified software supplier and service provider. Attention must also be paid to the compatibility of the infrastructure (hardware and software) used in the regulated company (qualification of the infrastructure). The existing infrastructure, systems and monitoring services should be checked for compatibility to the design concept during system selection, and changes should be included in the implementation planning phase if necessary.
- Installation and configuration: The hardware and software should be installed in accordance with the supplier’s instructions and internal guidelines. The baseline configuration must be carefully documented to ensure a consistent and traceable system environment. In addition to the technical implementation, it is also important for the support team to classify the technical requirements with regard to the configuration. Members of the support team should therefore also be included in the project team.
- System acceptance testing: Comprehensive system acceptance tests must be carried out before going live. This includes functional tests, performance tests, safety tests and validation according to the requirements in accordance with Annex 11. All test results and validation documents should be carefully archived. The support team can take over tasks for setting up test users and test preparations during the test and validation phase. The support team can also support execution of functional and validation testing.
- Documentation: Documentation must be maintained in accordance with regulatory requirements. This ensures that all relevant information is available in the event of audits or inspections. The documentation should be protected against changes but should be accessible to all those involved in system operation. Operational issues and changes in operation must be documented. The support team must have access to all relevant validation documents. In particular, the support team must be informed of any issues during the project phase and the rollout.
- Staff training and responsibilities: The requirements for staff training and the definition of clear responsibilities for the operation and maintenance of the systems must be regulated during the establishment or upgrade of computerised systems. A training concept should be developed as part of the validation process and personnel should be trained prior to go-live.
The procedures for system operation must be developed already during the project phase and checked and adapted as warranted in the event of updates and changes. It is crucial that the core procedures are documented for the handover to operations and that these are further optimised by the project team and the supplier in the subsequent hypercare phase.
Go-live should be planned out in advance. As with all topics, the steps involved in go-live of the system are founded on a risk-based approach and must therefore be evaluated on a case-by-case basis.
Hypercare
Regardless of whether a new system is being implemented or an existing system is being updated, a hypercare phase should always be planned out in advance. This phase is utilised by the project team and the supplier to support the internal IT main support team in order to carry out support activities quickly and monitor the system. This support includes providing the planned assistance, e.g. performing support activities and monitoring the system, to ensure that any issues that arise are resolved quickly and effectively. The hypercare phase ends with the final transition to the operational phase.
The following topics and documents must be completed for the final handover:
- Validation report
- Data migration (as applicable)
- Configuration specification and inventory list
- Service Level Agreements (SLA) + Quality Assurance Agreements (QAA)
- Support process and tools
- Knowledge transfer of the new IT solution after update to the support team
The validation report must be completed and approved to confirm the validated status of the system. This report documents that the system meets the specified requirements and can be operated securely.
Data migration must be completed in full and confirmed by a migration report, as applicable. The migration report documents the successful transfer of all relevant data to the new system and ensures that no data has been lost or corrupted.
The configuration specifications and inventory lists must be updated and confirmed to be accurate. These documents contain detailed information about the system configuration and the components of the system. The configuration specification (baseline configuration) is the basis for future changes to the system.
All open issues and deviations must be documented and addressed through appropriate mechanisms such as Deviation Management (DM), Corrective and Preventive Actions (CAPA) or other Quality Management systems. These measures ensure that all potential issues are identified and tracked according to their criticality to system operation.
If necessary, the support process must be updated and the necessary administration and support tools must be provided to ensure that the support team can work effectively. Service Level Agreements (SLA) and Quality Assurance Agreements (QAA) must be reviewed and updated to meet the new requirements. These measures should be completed by the time of handover.
A comprehensive transfer of knowledge covering the new IT solution or the system update must be provided to the users and in particular to the support team. This includes training and documentation to ensure that the support team is able to effectively support and maintain system operation. Infrastructural and organisational changes should also be communicated to the support team.
Training courses
Training of employees who work with computerised systems is performed in accordance with the EU GMP Guidelines and the ISPE GAMP® 5, 2nd Edition guide. A differentiated training concept that addresses specific needs and responsibilities is advantageous for efficient operation. In this context, both software application training and training on IT security and data integrity are key topics in order to ensure secure and compliant use of the systems.
Role-based training
A distinction should at least be made between the roles of key users, users of the system and administrators as part of defining training requirements. Further differentiation, for example between readers and authors in document management systems, can be helpful. Here is a brief explanation for a better understanding of the roles.
Key users are employees who act as an interface between users and the IT department and have in-depth knowledge of the system and work processes. The training for key users goes beyond basic use and covers specific functional, security and compliance-relevant aspects.
Users are the employees who work with the system on a daily basis and use certain functions to perform their tasks efficiently and in accordance with the rules. User training is geared towards the basic use and safe handling of the application(s).
Administrators are the knowledgeable specialists responsible for the configuration, maintenance and technical support of the system. Administrator training includes advanced application knowledge and specific training on IT security and data integrity to ensure that the system is operated securely and in compliance with regulations. It is generally advantageous to provide both specialist administrators for configuration and specialist compliance as well as IT administrators for maintenance and technical system operation.
Application training provides the involved parties with the necessary knowledge to carry out their specific tasks in the system securely and in compliance with regulations. IT security and data integrity training ensures that all employees recognise potential risks, act securely and fulfill data integrity and compliance requirements. This ensures that users for all roles are competent and act in a compliant manner and that the high standards of security, compliance and data integrity in the pharmaceutical industry are guaranteed.
| Role | Focus of the application training | Focus of the training on IT security and data integrity |
| Key user | System configuration and process control: Key users receive in-depth application training that enables them to understand how complex processes are mapped in the system. This includes knowledge of internal system settings, the configuration of workflows and the configuration of reports and dashboards to the needs of the respective business processes. Training the trainer: Key users are often multipliers who prepare and conduct training courses for users. They learn how to create training materials and instruct their colleagues in the use of the system. The application training therefore contains methods and techniques for imparting knowledge to other employees. | Data integrity and audit trails: As key users often access GMP-relevant data, training on the subject of data integrity is essential. They learn how to ensure that all entries are accurate, complete and traceable. The training also covers the handling of audit trails and the traceability of changes required for inspections. Security awareness: Key users are trained to recognise and report potential security risks when handling data and user access authorisations. They learn how to protect their personal user account and ensure that unauthorised access is prevented. There is also an extended focus on cybersecurity. |
| Users | Basic knowledge and standard operating procedures: Users receive training in the system functions relevant to their tasks. They learn how to operate the system in accordance with the defined work instructions (SOPs) to ensure that all activities are traceable and compliant. Handling data and documentation: The application training course teaches users how to enter, edit and store data correctly to ensure the quality and integrity of data. They learn how to avoid input errors and how to use system functions such as plausibility checks correctly. | Secure use and password management: Users are trained in basic security principles, including the secure management of passwords and the need to keep their access authorisation confidential. They learn how to avoid potentially risky behaviour. Awareness of data integrity: The data integrity training course teaches users what steps they need to take to ensure the accuracy and completeness of the data. They learn how to record and store data correctly so that each entry and change is traceable. |
| Administrators | System architecture and configuration: Administrators receive comprehensive training in the system architecture, including the technical configurations and interfaces to other systems. This enables them to maintain and configure the system and operate the various components safely and effectively. Patch and update management: The application training also covers patch and update management, as administrators must ensure that all security-relevant updates are applied without affecting validation. They will learn how to check patches in a test environment and test the updates for system compatibility. | Security policies and user management: Administrators receive comprehensive training in the company's security guidelines and user management requirements. They learn how to create user accounts, manage access rights and maintain access logs to ensure traceability and data integrity. Backups and recovery: Administrators are also trained in the backup and recovery process to ensure data availability in the event of an emergency. They learn how to perform regular backups and how to react quickly in the event of a system failure. Compliance and documentation: As administrators play a central role in ensuring system compliance, they are trained in how to document changes, updates and configuration changes and how to execute them in a compliant manner. |
Training documentation and follow-up
In accordance with the EU GMP Guidelines, companies are obliged to ensure that all employees who work with GMP-relevant computerised systems are appropriately trained and qualified. The EU GMP Guidelines require that all employees concerned have the necessary knowledge and skills to operate and maintain the systems properly. This is accompanied by the requirement to maintain comprehensive and comprehensible documentation of proof of qualification, including the training measures taken.
Training documentation and tracking for computerised systems must always be up-to-date, complete and accessible to meet both internal and external requirements. A clear structure of training documents, regular reviews and updates as well as centralised management of qualification certificates are necessary. This enables proof of GMP compliance to be provided efficiently during inspections. This also ensures the safe and compliant use of the systems and the associated processes.
Do you have any questions or suggestions? Please contact us at: redaktion@gmp-verlag.de