Skip to main content Skip to search Skip to main navigation

Handover of Computerised Systems to the Operating Department

Excerpt from the GMP Compliance Adviser, Chapter 9.F, Operation of computerised systems

7 min. reading time | by Dennis Sandkühler, Director Quality & Compliance, Digital Life Sciences
Published in LOGFILE 16/2026 

The GMP-compliant handover of computerised systems to operations is a critical step in the Computer System Validation (CSV) lifecycle. Beyond go-live and hypercare, clearly defined responsibilities, comprehensive documentation and well-trained personnel are essential to maintaining a validated state throughout routine operation.


Implementation and commissioning

The implementation and subsequent commissioning, or “go-live” of computerised systems require careful planning and continuous monitoring to ensure their integrity, security and up-time system availability. This section covers the key aspects of implementation and those tasks that need to be completed prior to go-live.

Figure 1 | Operation of computerised systems

The implementation of computerised systems involves several steps to ensure that the systems meet the requirements and are ready for productive operation. With regard to go-live of productive operation, however, preparatory activities should already be planned during the implementation phase of the project.

  • Planning, specification and risk assessment: Before implementation, the system requirements must be specified and documented in detail. This includes functional and non-functional requirements, security requirements and regulatory requirements in accordance with the EU GMP Guidelines. An approach to continual risk assessment with regard to fulfilment of the requirements should be aligned in the planning phase. The designated operational support team should be involved in the planning in order to communicate requirements and risks to system operation at an early stage.
  • System selection and development: The appropriate system is selected or developed based on the specifications. It is important to select a qualified software supplier and service provider. Attention must also be paid to the compatibility of the infrastructure (hardware and software) used in the regulated company (qualification of the infrastructure). The existing infrastructure, systems and monitoring services should be checked for compatibility to the design concept during system selection, and changes should be included in the implementation planning phase if necessary.
  • Installation and configuration: The hardware and software should be installed in accordance with the supplier’s instructions and internal guidelines. The baseline configuration must be carefully documented to ensure a consistent and traceable system environment. In addition to the technical implementation, it is also important for the support team to classify the technical requirements with regard to the configuration. Members of the support team should therefore also be included in the project team. 
  • System acceptance testing: Comprehensive system acceptance tests must be carried out before going live. This includes functional tests, performance tests, safety tests and validation according to the requirements in accordance with Annex 11. All test results and validation documents should be carefully archived. The support team can take over tasks for setting up test users and test preparations during the test and validation phase. The support team can also support execution of functional and validation testing. 
  • Documentation: Documentation must be maintained in accordance with regulatory requirements. This ensures that all relevant information is available in the event of audits or inspections. The documentation should be protected against changes but should be accessible to all those involved in system operation. Operational issues and changes in operation must be documented. The support team must have access to all relevant validation documents. In particular, the support team must be informed of any issues during the project phase and the rollout.
  • Staff training and responsibilities: The requirements for staff training and the definition of clear responsibilities for the operation and maintenance of the systems must be regulated during the establishment or upgrade of computerised systems. A training concept should be developed as part of the validation process and personnel should be trained prior to go-live. 

The procedures for system operation must be developed already during the project phase and checked and adapted as warranted in the event of updates and changes. It is crucial that the core procedures are documented for the handover to operations and that these are further optimised by the project team and the supplier in the subsequent hypercare phase. 

Go-live should be planned out in advance. As with all topics, the steps involved in go-live of the system are founded on a risk-based approach and must therefore be evaluated on a case-by-case basis. 


Hypercare 

Regardless of whether a new system is being implemented or an existing system is being updated, a hypercare phase should always be planned out in advance. This phase is utilised by the project team and the supplier to support the internal IT main support team in order to carry out support activities quickly and monitor the system. This support includes providing the planned assistance, e.g. performing support activities and monitoring the system, to ensure that any issues that arise are resolved quickly and effectively. The hypercare phase ends with the final transition to the operational phase. 

The following topics and documents must be completed for the final handover:

  • Validation report
  • Data migration (as applicable)
  • Configuration specification and inventory list
  • Service Level Agreements (SLA) + Quality Assurance Agreements (QAA)
  • Support process and tools
  • Knowledge transfer of the new IT solution after update to the support team 

The validation report must be completed and approved to confirm the validated status of the system. This report documents that the system meets the specified requirements and can be operated securely. 

Data migration must be completed in full and confirmed by a migration report, as applicable. The migration report documents the successful transfer of all relevant data to the new system and ensures that no data has been lost or corrupted.

The configuration specifications and inventory lists must be updated and confirmed to be accurate. These documents contain detailed information about the system configuration and the components of the system. The configuration specification (baseline configuration) is the basis for future changes to the system.

All open issues and deviations must be documented and addressed through appropriate mechanisms such as Deviation Management (DM), Corrective and Preventive Actions (CAPA) or other Quality Management systems. These measures ensure that all potential issues are identified and tracked according to their criticality to system operation.

If necessary, the support process must be updated and the necessary administration and support tools must be provided to ensure that the support team can work effectively. Service Level Agreements (SLA) and Quality Assurance Agreements (QAA) must be reviewed and updated to meet the new requirements. These measures should be completed by the time of handover.

A comprehensive transfer of knowledge covering the new IT solution or the system update must be provided to the users and in particular to the support team. This includes training and documentation to ensure that the support team is able to effectively support and maintain system operation. Infrastructural and organisational changes should also be communicated to the support team. 


Training courses

Training of employees who work with computerised systems is performed in accordance with the EU GMP Guidelines and the ISPE GAMP® 5, 2nd Edition guide. A differentiated training concept that addresses specific needs and responsibilities is advantageous for efficient operation. In this context, both software application training and training on IT security and data integrity are key topics in order to ensure secure and compliant use of the systems. 


Role-based training 

A distinction should at least be made between the roles of key users, users of the system and administrators as part of defining training requirements. Further differentiation, for example between readers and authors in document management systems, can be helpful. Here is a brief explanation for a better understanding of the roles. 

Key users are employees who act as an interface between users and the IT department and have in-depth knowledge of the system and work processes. The training for key users goes beyond basic use and covers specific functional, security and compliance-relevant aspects. 

Users are the employees who work with the system on a daily basis and use certain functions to perform their tasks efficiently and in accordance with the rules. User training is geared towards the basic use and safe handling of the application(s). 

Administrators are the knowledgeable specialists responsible for the configuration, maintenance and technical support of the system. Administrator training includes advanced application knowledge and specific training on IT security and data integrity to ensure that the system is operated securely and in compliance with regulations. It is generally advantageous to provide both specialist administrators for configuration and specialist compliance as well as IT administrators for maintenance and technical system operation.

Application training provides the involved parties with the necessary knowledge to carry out their specific tasks in the system securely and in compliance with regulations. IT security and data integrity training ensures that all employees recognise potential risks, act securely and fulfill data integrity and compliance requirements. This ensures that users for all roles are competent and act in a compliant manner and that the high standards of security, compliance and data integrity in the pharmaceutical industry are guaranteed. 


Role
Focus of the application training
Focus of the training on IT security and data integrity
Key userSystem configuration and process control: 
Key users receive in-depth application training that enables them to understand how complex processes are mapped in the system. This includes knowledge of internal system settings, the configuration of workflows and the configuration of reports and dashboards to the needs of the respective business processes. 

Training the trainer: 
Key users are often multipliers who prepare and conduct training courses for users. They learn how to create training materials and instruct their colleagues in the use of the system. The application training therefore contains methods and techniques for imparting knowledge to other employees.
Data integrity and audit trails: 
As key users often access GMP-relevant data, training on the subject of data integrity is essential. They learn how to ensure that all entries are accurate, complete and traceable. The training also covers the handling of audit trails and the traceability of changes required for inspections. 

Security awareness: 
Key users are trained to recognise and report potential security risks when handling data and user access authorisations. They learn how to protect their personal user account and ensure that unauthorised access is prevented. There is also an extended focus on cybersecurity.
UsersBasic knowledge and standard operating procedures: 
Users receive training in the system functions relevant to their tasks. They learn how to operate the system in accordance with the defined work instructions (SOPs) to ensure that all activities are traceable and compliant. 

Handling data and documentation:
The application training course teaches users how to enter, edit and store data correctly to ensure the quality and integrity of data. They learn how to avoid input errors and how to use system functions such as plausibility checks correctly.
Secure use and password management: 
Users are trained in basic security principles, including the secure management of passwords and the need to keep their access authorisation confidential. They learn how to avoid potentially risky behaviour. 

Awareness of data integrity:
The data integrity training course teaches users what steps they need to take to ensure the accuracy and completeness of the data. They learn how to record and store data correctly so that each entry and change is traceable.
AdministratorsSystem architecture and configuration: 
Administrators receive comprehensive training in the system architecture, including the technical configurations and interfaces to other systems. This enables them to maintain and configure the system and operate the various components safely and effectively.

Patch and update management:
The application training also covers patch and update management, as administrators must ensure that all security-relevant updates are applied without affecting validation. They will learn how to check patches in a test environment and test the updates for system compatibility.
Security policies and user management: 
Administrators receive comprehensive training in the company's security guidelines and user management requirements. They learn how to create user accounts, manage access rights and maintain access logs to ensure traceability and data integrity. 

Backups and recovery: 
Administrators are also trained in the backup and recovery process to ensure data availability in the event of an emergency. They learn how to perform regular backups and how to react quickly in the event of a system failure. 

Compliance and documentation: 
As administrators play a central role in ensuring system compliance, they are trained in how to document changes, updates and configuration changes and how to execute them in a compliant manner.

Training documentation and follow-up

In accordance with the EU GMP Guidelines, companies are obliged to ensure that all employees who work with GMP-relevant computerised systems are appropriately trained and qualified. The EU GMP Guidelines require that all employees concerned have the necessary knowledge and skills to operate and maintain the systems properly. This is accompanied by the requirement to maintain comprehensive and comprehensible documentation of proof of qualification, including the training measures taken. 

Training documentation and tracking for computerised systems must always be up-to-date, complete and accessible to meet both internal and external requirements. A clear structure of training documents, regular reviews and updates as well as centralised management of qualification certificates are necessary. This enables proof of GMP compliance to be provided efficiently during inspections. This also ensures the safe and compliant use of the systems and the associated processes.


Do you have any questions or suggestions? Please contact us at: redaktion@gmp-verlag.de

Dr. Dennis Sandkühler
Dr. Dennis Sandkühler

You may also be interested in the following articles:

How is the Effectiveness of CAPAs Verified?

How is the Effectiveness of CAPAs Verified?

Here's the answer:
Read more
Handover of Computerised Systems to the Operating Department

Handover of Computerised Systems to the Operating Department

The GMP-compliant handover of computerised systems to operations is a critical step in the Computer System Validation (CSV) lifecycle. Beyond go-live and hypercare, clearly defined responsibilities, comprehensive documentation and well-trained personnel are essential to maintaining a validated state throughout routine operation.
Read more
APIC: Publishes Updated “How to Do” Document for GDP for Active Pharmaceutical Ingredients

APIC: Publishes Updated “How to Do” Document for GDP for Active Pharmaceutical Ingredients

The Active Pharmaceutical Ingredients Committee (APIC) has published Version 3 of the document “GDP for APIs: How to Do” (June 2026) on its website. The document provides practical guidance on implementing Good Distribution Practice for active pharmaceutical ingredients.

Read more
TGA: Seeks Feedback on Planned Adoption of 11 International Scientific Guidelines

TGA: Seeks Feedback on Planned Adoption of 11 International Scientific Guidelines

Australia's regulatory authority, the TGA (Therapeutic Goods Administration), pursues a strategy of aligning its regulatory approaches as closely as possible with comparable international standards. These include the regulatory requirements of the EU, the FDA and the ICH. In this context, around 370 international scientific guidelines have already been adopted.

Read more
EU: Strengthened Cooperation with WHO on Pandemic Preparedness

EU: Strengthened Cooperation with WHO on Pandemic Preparedness

“Today public health faces a new kind of challenge: speed. Diseases move faster and are more unpredictable than ever, racing across borders and continents.”, said Hadja Lahbib, Commissioner for Equality, Preparedness and Crisis Management, upon signing an EU4Health contribution agreement worth over 4 million euros with the World Health Organisation’s (WHO) Hub for Pandemic and Epidemic Intelligence in Berlin on 24 July 2026.

Read more
PIC/S: Revised Recommendations on Qualification and Validation

PIC/S: Revised Recommendations on Qualification and Validation

PIC/S has published a fundamentally revised version of its “Recommendations on Qualification and Validation” (PI 006-4). The new document was issued on 30 July 2026, will enter into force on 1 October 2026, and replaces the 2007 edition. The revised document has been expanded from 26 to 49 pages.
Read more
Previous
Next

Related Products

Skip product gallery
GMP Compliance Adviser

GMP Compliance Adviser

The GMP Compliance Adviser is an online publication that covers all aspects of Good Manufacturing Practice (GMP) in one source.In the GMP Compliance Adviser you’ll find: GMP in Practice This part contains 21 chapters with GMP expert knowledge to base your decisions upon. It provides practical assistance with checklists, templates and SOP examples. It is written by more than 80 authors with hands-on experience directly linked to the industry. The individual chapters describe the different aspects of GMP in clear language. Technical, organizational and procedural aspects are covered.More than 700 checklists, templates and examples of standard operation procedures taken directly out of practice help you in understanding the GMP requirements.GMP RegulationsThese chapters cover the most important GMP regulations from Europe and the United States (CFR and FDA), but also PIC/S, ICH, WHO and many more.  Sample Documents In addition, the GMP Compliance Adviser contains many sample documents and practical examples that you can use.

delivery time appr. 2-5 workdays after receipt of payment
€597.00 net excl. VAT
GMP:KnowHow Pharma Logistics (GDP)

GMP:KnowHow Pharma Logistics (GDP)

Your knowledge base about GDP-compliant handling of your pharmaceutical logistics. It is important that you as a logistics service provider, but also as a client in the pharmaceutical industry, adhere precisely to the regulatory requirements. The GMP:KnowHow knowledge portal guides you through the regulatory jungle of the pharmaceutical and logistical supply chain! The knowledge portal gives you an easy-to-understand overview of all the important topics. Using graphics, you can easily navigate through all the areas covered by the EU GDP Guidelines (2013/C 343/01). You also have the relevant passages of the regulations directly at hand for each topic. This allows you to compare the requirements directly and saves you a lot of time on time-consuming searches and research!One thing is certain: the knowledge portal answers your questions about the supply chain of medicinal products, active pharmaceutical ingredients and medical devices. You don't have to be an expert. Yet.You will find answers to your questions in the GMP:KnowHow Pharma Logistics (GDP). Where does GDP begin, where does GMP end? What does GDP-compliant mean? When do I also have to take GMP requirements into account? What permits do I need for certain activities? What requirements do I have to fulfil? What is the current legal basis? How am I covered? What authorizations do I have for my work, e.g. from my employer? Who is responsible — the client or the contractor? And many more What is the difference to the GMP Compliance Adviser? The GMP:KnowHow Pharma Logistics (GDP) is your guideline for Good Distribution Practice. It is a product that is independent of the GMP Compliance Adviser and concentrates on content that is essential for carriers of medicinal products, active pharmaceutical ingredients and medical devices as well as for logistics clients. The focus is on practical knowledge and how to apply it in your daily business. If necessary, the relevant regulations can be called up immediately alongside the practical knowledge, and you can see the relevant paragraphs at a glance. In addition, sample documents are available to help you make immediate progress. AuthorSimone Ferrante – now Director Quality at Fisher Clinical Services – was previously Head of Quality Control and Responsible Person according to GDP (VP) for the entire Grieshaber Group. She is also a long-standing author and GDP expert at GMP-Verlag.

delivery time appr. 2-5 workdays after receipt of payment
€460.00 net excl. VAT