{"id":5075,"date":"2024-11-25T20:06:43","date_gmt":"2024-11-25T20:06:43","guid":{"rendered":"https:\/\/complyguru.com\/en-ie\/?p=5075"},"modified":"2025-01-24T12:41:51","modified_gmt":"2025-01-24T12:41:51","slug":"as-per-iso-13485-is-spreadsheet-validation-required","status":"publish","type":"post","link":"https:\/\/complyguru.com\/en-ie\/as-per-iso-13485-is-spreadsheet-validation-required\/","title":{"rendered":"As per ISO 13485, is Spreadsheet Validation required?"},"content":{"rendered":"

Welcome to the first in a series of blogs where we will start to break down ISO 13485:2016 (ISO 13485). As someone who has both implemented and audited a Quality Management System (QMS) to the requirements of ISO 13485, the nuance and interpretation of the standards of the various users, from auditors to auditees and everyone in between, never ceases to amaze me.<\/p>\n

This past week, I posted a poll on LinkedIn asking:<\/p>\n

\u201cAs per ISO 13485, is it true or false that a medical device organization that uses spreadsheets is only required to validate spreadsheets that contain calculations?\u201d<\/strong><\/p>\n

The results were interesting where 17% believed the statement to be true, versus 83% believing the same statement to be false.\u00a0 A resounding voice from the \u201cfalse camp\u201d!<\/p>\n

So, what is the correct answer?<\/p>\n

Drum roll please\u2026. the requirement to validate spreadsheets extends beyond only spreadsheets that contain calculations.<\/p>\n

Spreadsheets that contain any quality related data, even those without calculations, will be subjected to some level of validation.<\/p>\n

The level of validation will depend on the type of quality data captured, and what the spreadsheet is intended to do with that quality data.<\/p>\n

But before I explain, let\u2019s explore the various standards, regulations and guidance documents that outline or define the requirements around software validation, and more specifically spreadsheet validation.<\/p>\n

ISO 13485<\/strong><\/h2>\n

The clauses captured throughout Clause 4 of ISO 13485<\/a> are related to the planning phase of the QMS.\u00a0 Clause 4.1.6 makes it a mandatory requirement that organizations have a procedure in place for software validation used in the quality management system.<\/p>\n

It is important to recognize that this clause is not only referring to software that are used directly in your QMS, but also any software that is used to support the management system, for example, spreadsheets.<\/p>\n

It is also important to know, that when the statement is made to validate spreadsheets, that does not mean to validate the excel software itself, but rather, the spreadsheet.<\/p>\n

In addition, clause 7.5.6 \u2013 Validation of processes for production and service provisions also requires organizations to document procedures for the validation of the application of software used in production and service provision.<\/p>\n

Importantly, both clause 4.1 6 and clause 7.5.6 specifies that the approach to the validation activities shall be proportionate to the risk associated with the use of the software.\u00a0 It is this risk that determines the level of validation that will be applied to the spreadsheets in use.<\/p>\n

FDA Regulations<\/strong><\/h2>\n

Our US based friends are not that different to their ISO 13485 counterparts.<\/p>\n

21 CFR 820.70(i) states that \u201cWhen computers or automated data processing systems are used as part of production or the quality system, the manufacturer shall validate computer software for its intended use according to an established protocol. All software changes shall be validated before approval and issuance. These validation activities and results shall be documented\u201d<\/em>.<\/p>\n

The FDA\u2019s guidance document \u2013 \u201cGeneral Principles of Software Validation\u201d advises that \u201cMany other commercial software applications, such as word processors, spreadsheets, databases, and flowcharting software are used to implement the quality system. All of these applications are subject to the requirement for software validation, but the validation approach used for each application can vary widely\u201d.<\/em><\/p>\n

Why Part 11 Compliance Matters for Spreadsheet Validation<\/strong><\/h3>\n

And what about \u201cPart 11\u201d compliance?\u00a0 Well, one should also consider what records need to comply with the FDA Electronic Records and Signature Regulation or 21 CFR Part 11.<\/p>\n

Part 11 applies to:<\/p>\n

    \n
  1. Records in electronic form that are created, modified, maintained, archived, retrieved, or transmitted, under any records requirements set forth in agency [FDA] regulations.<\/li>\n
  2. Electronic records submitted to the agency under requirements of the Federal Food, Drug, and Cosmetic Act and the Public Health Service Act, even if such records are not specifically identified in agency regulations.<\/li>\n<\/ol>\n

    But what does 21 CFR Part 11 say about software validation?<\/p>\n

    Key Requirements of 21 CFR Part 11 for Software Validation<\/strong><\/h3>\n

    Well, indulge me for but a moment while I break it down.<\/p>\n

    Firstly, 21 CFR 11.10 states that \u201cPersons who use closed systems to create, modify, maintain, or transmit electronic records shall employ procedures and controls designed to ensure the authenticity, integrity, and, when appropriate, the confidentiality of electronic records, and to ensure that the signer cannot readily repudiate the signed record as not genuine. Such procedures and controls shall include the following:<\/em><\/p>\n

    (a) Validation of systems to ensure accuracy, reliability, consistent intended performance, and the ability to discern invalid or altered records\u201d.<\/em><\/p>\n

    But what is a closed system I hear you ask.\u00a0 21 CFR Part 11 defines a closed system as \u201can environment in which system access is controlled by persons who are responsible for the content of electronic records that are on the system\u201d. <\/em><\/p>\n

    Phew, don\u2019t worry this will all become clearer now that we have squared away where the standards and regulations define the requirements of software validation.<\/p>\n

    It is not lost on me that I have strayed beyond ISO 13485 specifically, but it is also stated at Clause 4.1.1 that organizations not only need to maintain effectiveness of their QMS as per the standard, but also those pesky regulatory requirements.<\/p>\n

    So why not throw you some additional information eh?<\/p>\n

    We are sound like that at Comply Guru! To be fair, most Quality Manuals I see include 21 CFR 820<\/a> in the scope of their QMS certified to ISO 13485.<\/p>\n

    So, lets acknowledge one thing at this point.\u00a0 Nowhere in any of the standards or regulations mentioned does it state that validation is restricted only to software\u2019s that perform calculations or indeed spreadsheets that perform calculation.\u00a0 Now, shall we get down with the good stuff?\u00a0 I think so!<\/p>\n

    Which spreadsheets need validation?\u00a0 Well, ask yourself these questions; Could the spreadsheet impact on patient health, public safety and\/or product quality?\u00a0 Now ask yourself, could the spreadsheet impact on the integrity of the data and records associated with any of those three?<\/p>\n

    And the final, and potentially, most important question \u2013 will the spreadsheet be used as an electronic record or a record as it is controlled as per the requirements of Clause 4.2.5 of ISO 13485.\u00a0 Don\u2019t forget, Clause 4.2.5 has its own requirements related to control of records.<\/p>\n

    Organizations are mandated by ISO 13485 to establish and implement a procedure detailing the controls needed \u201cfor the identification, storage, security and integrity, retrieval, retention time and disposition of records\u201d <\/em>That word INTEGRITY is the key in this requirement.\u00a0 Additionally, changes to records need to be identifiable.<\/p>\n

    Now, the building blocks around spreadsheet validation are starting to form, and any reader of this should now be registering the importance of all spreadsheets and not just those that perform calculations.\u00a0 How many organizations use spreadsheets to track confidential health information?\u00a0 Spreadsheets are easy to navigate and filter out specific information when set up correctly.<\/p>\n

    Guess what, Clause 4.2.5 also mandates that organizations \u201cshall define and implement methods for protecting confidential health information contained in records in accordance with the applicable regulatory requirements\u201d. <\/em>Hmmm, sounds like a job for spreadsheet validation! A validated spreadsheet will ensure all these requirements are met, if the validation is correctly performed.<\/p>\n

    Essential Spreadsheets That Demand Validation and Compliance<\/strong><\/h3>\n

    What are examples of spreadsheets that require spreadsheet validation and in some cases part 11 compliance, well, here we go:<\/p>\n

      \n
    1. Spreadsheets that compute the potency of the raw material<\/li>\n
    2. Product Complaint tracking spreadsheet<\/li>\n
    3. Spreadsheets that track which donors are (and are not) eligible to donate plasma<\/li>\n
    4. An accounting spreadsheet that also tracks the quality status of each lot<\/li>\n
    5. Spreadsheets that calculate how long to dry a batch of active ingredient<\/li>\n
    6. Spreadsheet of training on QA SOPs<\/li>\n
    7. Spreadsheet of lab test results<\/li>\n
    8. Spreadsheets of manufacturing schedules<\/li>\n
    9. Spreadsheets used to calculate lab results<\/li>\n<\/ol>\n

      What next?\u00a0 We know the types of spreadsheets that require validation, but how is validation of all these different types of spreadsheets, with varying levels of risk and criticality performed?<\/p>\n

      I could tell you, but\u2026\u2026\u2026. you know the rest!<\/p>\n

      Come back next week for Part 2, where I will delve into criticality classification and the steps involved in performing spreadsheet validation and the documentation requirements associated with the validation activities.<\/p>\n

      Keep an eye on the Comply Guru LinkedIn page<\/a>, where we will drop the link to part 2 when it is available.<\/p>\n

      In the meantime, have a great week and Happy QARAing!<\/p>\n","protected":false},"excerpt":{"rendered":"

      As per ISO 13485, is it true or false that a medical device organization that uses spreadsheets is only required to validate spreadsheets that contain calculations?<\/p>\n","protected":false},"author":1,"featured_media":5076,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"_acf_changed":false,"footnotes":""},"categories":[86,24,87,57],"tags":[84,85],"class_list":["post-5075","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-fda-regulations","category-iso-13485","category-medical-devices","category-medtech","tag-iso-13485","tag-spreadsheet-validation"],"acf":[],"aioseo_notices":[],"_links":{"self":[{"href":"https:\/\/complyguru.com\/en-ie\/wp-json\/wp\/v2\/posts\/5075","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/complyguru.com\/en-ie\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/complyguru.com\/en-ie\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/complyguru.com\/en-ie\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/complyguru.com\/en-ie\/wp-json\/wp\/v2\/comments?post=5075"}],"version-history":[{"count":0,"href":"https:\/\/complyguru.com\/en-ie\/wp-json\/wp\/v2\/posts\/5075\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/complyguru.com\/en-ie\/wp-json\/wp\/v2\/media\/5076"}],"wp:attachment":[{"href":"https:\/\/complyguru.com\/en-ie\/wp-json\/wp\/v2\/media?parent=5075"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/complyguru.com\/en-ie\/wp-json\/wp\/v2\/categories?post=5075"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/complyguru.com\/en-ie\/wp-json\/wp\/v2\/tags?post=5075"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}