You are on page 1of 12

RETHINK RESHAPE RESTRUCTURE...

FOR BETTER PATIENT OUTCOMES

STRATEGIES FOR
LIFE SCIENCES COMPANIES
USING MICROSOFT
AZURE WITH GXP
SYSTEMS
ABOUT THIS
WHITEPAPER
This paper will help life sciences
companies to:
• Analyze the controls required to
leverage Microsoft Azure.
• Define how Microsoft Azure can
meet those controls.
• Define the levels of ownership and
INTRODUCTION participation from Life Sciences
The pressure on profit margins that life sciences companies face today companies when validating and
is well documented. Government control on drug expenditure and the maintaining GxP systems hosted
availability of generic options after the recent spate of patent expirations on Microsoft Azure.
are putting pressure on top and bottom line growth. In the short term,
many life sciences companies are focused on adjusting operating models We have divided this paper into
and trimming costs, including IT costs. eight sections:
1. Why Public Cloud for GxP
Organizations can only cut costs so far while retaining a thriving business. Applications discusses the business
So increasingly life sciences companies are looking to embrace digital benefits life sciences companies can
transformation as a core part of the strategy to sustainably restore profit realize if they invest in the public
margins and have a positive impact on revenue generation. This new focus cloud for GxP applications.
on digital transformation should see IT move from a cost center to a key
2. Key regulatory requirements for
enabler of business growth and revenue generation.
IT environments in life sciences
companies summarizes the key
For any organization, public cloud computing services are likely to form a
regulatory requirements that global
core technology component of digital transformation. The promise of near-
life sciences companies must adhere
unlimited computing; storage and networking resources at low cost; easy
to when adopting public cloud services.
access to new value-added services; rapid technology innovation; and financial
flexibility all combine to create a compelling value proposition for any 3. Security capabilities of Microsoft
organization looking to maximize the business value of their IT investments. Azure examines the steps that
Microsoft has taken to ensure the
However, fully embracing digital transformation, and particularly the shift to security of its cloud platform and
public cloud services, is not as easy for life sciences companies as in some how it meets the needs of life
other industries. These companies must balance the need for change against sciences companies.
the requirements of their highly regulated industry. They must continue to 4. Accenture’s assessment of
clearly identify and mitigate the risks that arise; be able to respond effectively Microsoft Azure for GxP Services
to audit requests and to changes in regulations when they occur. provides some detail on Accenture’s
assessment of Microsoft’s cloud
Today, many life sciences companies are beginning their public and hybrid platform for GxP applications.
cloud journeys. Although they are making some investments in the public 5. Qualifying the infrastructure
cloud, it is typically in parts of the business that are subject to less regulation. underlying Microsoft Azure
Currently their public cloud spend represents a small fraction of their overall demonstrates at a high level how
investment in IT. This is based on current portfolio management at top 10 an organization would go through
pharma companies. the qualification process, and
outlines the challenges a life
Accenture’s analysis of the infrastructure underlying Microsoft Azure shows sciences company may face.
that it can be maintained in a controlled state provided proper change 6. A strategic approach for adopting
management and automated testing controls and management tools are Microsoft Azure cloud services
in place. In this document we show how the key Food and Drug Administration provides guidance on how to examine
(FDA) regulations (CFR 21 Part 820 and CFR 21 Part 11) apply in a cloud the full portfolio of GxP applications
context, but also provide broader guidance that applies to other global for cloud suitability.
compliance requirements, and should also apply to future regulations as
they come into force.

2 | Strategies for Life Sciences Companies Using Microsoft Azure with GxP Systems
7. Operational Models for GxP availability of nearly limitless using networks of compromised
validation in Microsoft Azure computing resources and rapid systems combined with sophisticated
examines how organizations can innovation in IT can do to transform malware to compromise organizations
execute effectively on maintaining their products, services, and and individuals hosting valuable
validated GxP applications. business operations. data. Protecting data integrity is
8. Using Accenture to support GxP increasingly a board-level issue for
validation shows how Accenture In the life sciences field, there is a life sciences companies. In a world
can assist life sciences companies real opportunity to use public cloud where threats morph every day,
looking to validate and maintain services to accelerate business and time is of the essence, it is very
GxP applications in the cloud. growth. For example: difficult for most internal IT security
• Core infrastructure services can departments to keep up. Public
This paper is aimed at business be combined with higher-level cloud companies invest significantly
decision makers and compliance capabilities in advanced analytics in protecting their customers from
professionals who are looking to and machine learning to effectively constantly evolving security threats,
establish the strategy for their GxP predict and improve outcomes. and lead the industry in rapid response.
applications. However, readers who These services can transform
are most interested in the results products and services for the The FDA Safety and Innovation Act
of the Accenture’s assessment of core business and for the was signed into law on July 9, 2012,
Microsoft Azure can skip straight to health consumer, by possibly but the challenges associated with
validating applications as technology

1
Section 4 (pg. 5). lowering hospitalization rates for
chronic diseases. evolves have been around for
decades. As an example, the
• The highly flexible application of
introduction of the first programmable
high-performance computing
ENSURING ACCESS TO capabilities allows them to be
logic controllers led to a rule that the
custom code for those controllers
HIGH-VALUE THERAPIES used in a much wider set of
should be treated as predicate rule
IN AN ERA OF HIGH- circumstances, lowering the
records for master production and
cost of failure in research and
PRICED DRUGS development, and facilitating the
control records. In many respects,
the current concern around public
Ever since the dawn of cloud developments of new categories
cloud computing is just a continuation
computing, enterprises have been of products and services.
of this pattern. Each time a new
wrestling with how to extract the
technology paradigm emerges,
most value from it. Over time, many Most life sciences companies have
there is an initial desire to document
have observed “born in the public just scratched the surface in terms
its inner workings rather than qualify
cloud” companies demonstrating of realizing the benefits of adopting
it as an underlying capability that
accelerated business growth, and public cloud services. This is in part
can be leveraged by the application.
wondered how to gain some of because most of the technology
these benefits for themselves without investments that yield maximum
Ironically, over time, cloud computing
jeopardizing existing operations. business value for life sciences
may come to be seen as key to
companies are subject to regulatory
speeding up the validation process.
Initially, much of the value proposition compliance considerations, and it
Organizations adopting public cloud
for cloud computing was centered has been unclear to date how to
computing are responsible for fewer
on potential cost savings, and in validate these types of applications
of the operational activities associated
particular around financial flexibility, on a public cloud platform.
with managing an application, when
with spend in IT growing or shrinking
compared to on premises deployments.
based on business conditions. But Another important consideration
The specific responsibilities of the
as the capabilities of the hyper-scale for life sciences companies is the
life sciences company will vary
cloud providers have increased, underlying security and privacy
according to the type of cloud
attention has shifted to the unique concerns that lead to high regulation
services used, with differences
ways public cloud offerings can in the industry. Today, cyber-attacks
between IaaS, PaaS and SaaS level
drive business growth and increase are increasingly frequent and more
services (for more information
profit margins. Businesses are damaging, with hacktivists, organized
seriously examining what the instant criminals and even nation states

3
on this see the section “Security FDA’s Title 21 CFR Part 11 also deals - Retention period is determined
Capabilities of Microsoft Azure”) with records in electronic form that by individual organizations. This
However, due to the standardized are created, modified, maintained, needs to be communicated to
nature of the cloud environment, archived, retrieved, or transmitted, computerized system solution
it should be possible to streamline under any records requirements set team as data residing in a storage
qualification over time. forth in agency regulations. This system needs to keep up with
part also applies to electronic technology changes
The business benefits associated records submitted to the agency - Backup and recovery
with public cloud capabilities, under requirements of the Federal - Disaster Management
combined with the medium term Food, Drug, and Cosmetic Act and
validation benefit of using a highly the Public Health Service Act, even The International Society for
standardized underlying platform if such records are not specifically Pharmaceutical Engineering (ISPE)
for regulated applications means identified in agency regulations. has published the Good Automated
that it is only a matter of time However, this part does not apply to Manufacturing Practices (GAMP)
before life sciences companies paper records that are, or have been, Guideline, Version 5. This guideline
more fully adopt the public cloud transmitted by electronic means [Ref: stresses the importance of risk

2
for these applications. 21 CFR Part 11, section 11.1 (b)]. based validation/qualification of
systems. It also stresses the importance
EUDRALEX Annex 11 is a recognized of leveraging vendor-supplied
guideline to companies that produce facts and documents to aid in
KEY REGULATORY

3
therapeutic products for use in the validation/qualification.
REQUIREMENTS FOR European Union. This annex applies
IT ENVIRONMENTS IN LIFE to all forms of computerized systems
used as part of a GMP regulated SECURITY CAPABILITIES
SCIENCES COMPANIES activities. As per Annex 11, a
The FDA’s Title 21 CFR Part 820 is computerized system is a set of OF MICROSOFT
a set of regulations designed to software and hardware components Azure traditional data centers are
ensure that quality systems involved that together fulfill certain dedicated to a single organization,
in the manufacture of pharmaceutical functionalities. The application and perimeter hardware firewalls
products and medical devices are should be validated; IT infrastructure provide the organizational boundary.
adequate. These regulations are should be qualified. [Ref: EUDRALEX But any organization using a public
mandatory for all life science Annex 11, Principle]. cloud environment is embracing
companies that offer products some form of multitenancy, where
and services in the United States. The major goal for the FDA regulations services are shared with other
21 CFR Part 820 includes purchasing and Annex 11 guidelines on computer organizations using the same public
controls, and so the vendor relationship systems is to achieve product and cloud environment. This makes
with Microsoft should be considered patient safety by ensuring the following: traditional perimeter-based security
for any product or service produced • Data Integrity, achieved by two impractical for each tenant.
that involves Microsoft cloud services. methods at application level:
- By use of electronic signatures In the last few years there have also
The FDA’s Title 21 CFR Part 11, which been dramatic advances in the nature
- By usage of automated audit
is relevant to companies that produce of security threats. Attacks now come
trails and logs
therapeutic products for use in from sophisticated insider threats,
• Security, to safeguard systems
the United States, captures the organized criminals, even nation
against internal and external threats:
requirements for computer systems states. Like-minded individuals can
(including hardware and software), - Restricting access to authorized
form effective teams through social
controls, and attendant documentation personnel
networking, and they can use networks
maintained under this part shall be • Data Retention, to ensure data of compromised systems, combined
readily available for, and subject to, availability whenever required. with sophisticated malware to conduct
FDA inspection [Ref: 21 CFR Part 11, The data/documents generated their attacks. Threats evolve at an
section 11.1 (e)]. is auditable by FDA any time during ever-faster rate, and many enterprise
the life cycle of the therapeutic IT security organizations are struggling
product. The retention time to keep up.
requirement usually varies from
two to 15 years.

4 | Strategies for Life Sciences Companies Using Microsoft Azure with GxP Systems
Microsoft takes a multi-layered FIGURE 1 . Responsibilities for managing applications in on-premises and
approach to securing its public cloud models
cloud environment. They make sure
CLOUD SERVICE MODELS
that threats are tracked and combatted
in order to protect the data from RESPONSIBILITY On-Prem IaaS PaaS SaaS
unauthorized access, regardless Data classification and
of whether the attempted breach accountability
is from within or outside of the
organization. To ensure that its Client and end point protection
cloud environment is appropriately
protected, Microsoft has invested
heavily in threat modeling, prevention,
Identity and access
detection, forensics, remediation, management
and incident response capabilities.
Application level controls
Multiple boundaries are established
inside the Microsoft Azure environment
and movement is limited across
Network controls
those boundaries. They do this
by limiting privileges according
to context, and isolating logical
Host security
networks and identities. The cloud
infrastructure and applications in
the cloud environment become part
of the sensor network designed to Physical security
determine if an attack is underway.
Microsoft also uses its data analytics
Cloud customer Cloud provider
capabilities to understand how
threats are evolving over time.

4
These defenses are combined with
an “assume breach” mindset, and
with consistent efforts to test the Building secure cloud services is ACCENTURE’S
effectiveness of security measures. considered to be a dual responsibility
To provide maximum protection, of Microsoft and its customers.
ASSESSMENT OF
Microsoft employs a dedicated Microsoft provides the security MICROSOFT AZURE
team that models emerging threats controls to protect data and FOR GXP SERVICES
and uses blended threats to attempt applications, and the customers
own their data, identities, and After a careful technical review of
to compromise Microsoft’s services,
responsibility for protecting them. Microsoft Azure and its Quality
alongside a defensive team designed
The exact nature of the responsibilities Management System (QMS), our
to thwart them. This allows the
depends on the cloud model used, Compliance Team found that all
company to enumerate risks, and
as shown in the Figure 1. essential procedural controls were
justify the resources necessary to
in place at Microsoft. The following
combat them.
Any company looking to use public table on pg. 6 outlines the key areas
cloud services should consider very that need to be considered for cloud
carefully the security capabilities service providers that equip an
of a cloud service provider, but our infrastructure for GxP compliant
assessment reveals that the tools and applications, and demonstrates how
security capabilities of Microsoft Microsoft meets these requirements.
Azure are comprehensive, and in many
cases will more than match those of
internal IT security departments in
life sciences companies.

5
KEY AREA REQUIREMENTS FOR HOW MICROSOFT MEETS REQUIREMENT IN
SERVICE PROVIDER MICROSOFT AZURE
Security • Manage access through physical • Supported through Microsoft Azure’s standard security
security for datacenter and logical measures and Service Level Agreements (SLAs).
access controls for underlying • Data integrity is ensured by proper client security at the file,
systems. database, and application design level.
• Provide network isolation and • Microsoft Cloud Infrastructure and Operations is responsible
encryption in case of multitenancy. for physical security of the Microsoft Azure datacenters,
• Prove capability of the physical data protection, physical hardware asset management, and
systems to support the hosted network services.
applications by way of qualified • These datacenters are managed, monitored, and operated
infrastructure. by Microsoft operations staff delivering online services with
• Ensure that systems used to ceaseless continuity. In addition to datacenter, network and
manage and control the physical personnel security practices, Microsoft Azure incorporates
infrastructure and related security practices at the application and platform layers to
underlying components work enhance security for developers and service administrators.
according to defined processes. Microsoft Azure contracts allow data to be retrieved
• Demonstrate controls are in place whenever required.
to support data integrity. Note:
• Retain and record data ownership. • Requirements for physical systems do not apply, as public cloud does not
• Support requirements for data provide direct access to physical systems for the customer.
retention. • Depending on the criticality of data and the systems to be hosted on
public cloud, life sciences companies should use their due diligence
• Allow data to be retrieved
in incorporating additional controls/mitigations to ensure business
whenever required. continuity and audit readiness.
Incident • Have robust disaster recovery in Microsoft Azure’s datacenter and data replication models provide
Management place for both datacenter and underlying resiliency. It maintains three copies of data in the
service. datacenter, and can be configured to store additional copies.
• Establish contracts for Recovery Microsoft Azure Backup Service and Microsoft Azure Site
Time Objective (RTO) and Recovery Recovery meet RTO and RPO requirements.
Point Objective (RPO).
People Have adequate processes in place for Microsoft hiring managers define job requirements prior to
Management people training and management. recruiting, interviewing, and hiring. Job requirements include
the primary responsibilities and tasks, background skills, and
personal qualifications desired. Once the requirements are
determined, managers create a job description, and use it
to identify potential candidates. When viable candidates are
identified, the interview process begins to evaluate candidates
and make an appropriate hiring decision. Ongoing training
curriculum/training records ensures that employees have the
skills needed to support the cloud environment.
Solution Provide a robust solution Solutions are developed according to the security development
Development development process. lifecycle, consisting of training, requirements gathering, design,
implementation, verification, release and response phases.
Note: While the current documentation practices in place are comprehensive
in general, some life sciences specific expectations (qualification plans and
summaries), reviews and approvals, etc. may need to be incorporated.
Quality • Create a Quality Management Quality Management System is in place, and defined processes
Management System. are followed for change management, incident management,
• Demonstrate control on underlying problem management, patch management, service requests,
physical and software systems and capacity management.
including change management, Note: While the current documentation practices in place are comprehensive
incident management, problem in general, some life sciences specific expectations (documentation of
management, patch management, changes, evaluation and approvals of changes prior to implementation in
service requests, capacity production systems, maintaining documents for baseline and changes) may
need to be incorporated.
management, etc.
Datacenter of Design a datacenter following an Standardized design for datacenters across all geographies,
Public Cloud approved standard/certifiable meeting global requirements for datacenter design, build
process. and operations.

6 | Strategies for Life Sciences Companies Using Microsoft Azure with GxP Systems
Qualifying the It is worth noting that while there precedents are established for use
may be some differences to how of the public cloud in the life sciences
infrastructure underlying a life sciences company qualifies industry, we expect significantly
Microsoft Azure the infrastructure underlying public higher adoption for GxP applications.
Life sciences companies that are cloud services, application validation Another significant challenge for life
looking to validate applications on does not change. Applications should sciences companies is the lack of
Microsoft Azure first need to ensure go through the normal system familiarity with cloud technologies
that the underlying infrastructure development life cycle, across inside many life sciences compliance
(servers, storage, network components, development, testing, quality and teams. Most life sciences companies
firewalls, CPU, memory, anti-virus, production environments, with some traditionally rely on GAMP guidelines.
etc.) is secure, documented, and or all of the environments residing in Accenture believes that GAMP 5
maintained in a controlled state. In the public cloud. However, by using has not fully addressed qualification
life sciences, this state is commonly Microsoft Azure for all of these of cloud solutions, and has not put
referred to as “qualified.” environments, one can ensure forth any guidance in the past seven
consistency throughout the years for public cloud providers.
Qualification is traditionally achieved development life cycle. Fortunately, there are efforts already
by following two processes— underway by ISPE to develop
Installation Qualification (IQ) and Maintaining the environment in more adequate guidelines on the
Operational Qualification (OQ), but Microsoft Azure relies upon an adoption of cloud systems by
now a life sciences company can underlying set of capabilities provided pharmaceutical companies.
achieve this with automated testing by Microsoft and the client or third
and configuration management party provider, but also on appropriate The following steps will help life
tools. Once the requirements are change control and risk management sciences companies become

5
determined for any system, one can procedures for the application itself. comfortable with qualifying the
use automated testing to verify that infrastructure that underpins
their minimum-security baseline Microsoft Azure:
is met for the underlying cloud CHALLENGES IN • Establish how to meet regulatory
infrastructure. When an environment requirements with limited physical
is spun up for a particular application
QUALIFYING THE access to the data centers and
or client, a report can be generated INFRASTRUCTURE physical systems. The current
listing out all of the specifications, UNDERLYING data centers utilized by Azure
and this can be maintained via proper are physically secure and under
change control. This actually increases MICROSOFT AZURE constant guard.
the quality of the infrastructure The biggest challenge that life science • Establish how to rely on Microsoft
documentation and allows one to companies have with validating Azure documentation to support
do hundreds of tests/verifications cloud applications is in translating qualification and validation.
in minutes versus manually the requirements of the regulations - An example would be to leverage
over months. to the services offered by public cloud MSFT’s procedures and change
providers. Once the requirements management records
When an application is deployed in are clearly defined for the public
• Determine procedures for responding
Microsoft Azure, the life sciences cloud, it becomes easier to document
to an audit from a regulator,
company (or its IT partner) maintains how regulatory requirements are
including gaining access to
the validated application, but met appropriately.
necessary documentation from
Microsoft maintains the underlying
Microsoft.
infrastructure, using automated In a public cloud environment,
• Gain an understanding how Microsoft
testing, proper configuration and the FDA still holds individual life
performs the following functions
change management. sciences companies responsible
for Microsoft Azure:
for compliance to its regulations.
This has led pharmaceutical - Service management
companies to be risk averse due - Change management
to the very nature of business they - Audit trail requirements and
operate. However, once more management

7
- User access control on base mitigating. It is very important to However, which applications fit into
systems and storage of access identify applications that may fall which quadrant can be somewhat
logs under GxP regulations early in more challenging, particularly once
- Incident management and the design phase, as design the obvious candidates have been
Corrective Action and Preventative considerations may affect the identified. When examining the
Action (CAPA) ease of the validation process. portfolio of GxP applications one
- Problem management For example, there is currently more should consider the following
- Configuration management precedent of applications that use factors, comparing the new
- Training of employees infrastructure services being validated environment to the old:
- Data Segregation than those using higher-level platform • Financial costs and benefits,
- Data Privacy services. Note that this not a reflection including the cost of migration
of the underlying suitability of
• Usability
Currently, Microsoft Azure is certified infrastructure as a service (IaaS)
• Performance
by ISO 22301, ISO/IEC 27001 and or platform as a service (PaaS) for
GxP applications, rather it is more an • Functionality
ISO 27017, ISO/IEC 27018, FedRAMP,
SOC 1, SOC 2, SOC 3, NIST 800-171, indication of the time in market for • Scalability
DOD, and various other regulatory some of these higher-level services. • Geographical reach
bodies which demonstrate Microsoft’s Organizations that are looking to • Operational maintenance
control and rigor with respect to develop new GxP applications should • Security (Confidentiality, Integrity
compliance in general. balance the benefits provided by and Availability)
platform services with the risks • Flexibility
Accenture’s experience and expertise associated with being a first mover
• Strategic alignment to business
in the field can help life sciences on validation.
and technology strategy
companies gain a more detailed
understanding of these areas, and For existing applications, life sciences
As IT portfolio management is a
thus prepare them to adopt Microsoft companies should assess the portfolio

6
specialized field, many organizations
Azure for GxP applications. to determine which applications are
will find it helpful to work with a
the best candidates to move in part
partner such as Accenture to analyze
or in full to the public cloud. On the
their portfolio of GxP applications,
surface, this is a fairly simple exercise
A STRATEGIC APPROACH in balancing benefits or rewards
and determine which ones to move
FOR ADOPTING against risks and complexity (see
first, based on overall suitability and
on the likely complexity of validation
MICROSOFT Figure 2).
in the new environment.
AZURE SERVICES
Life sciences companies that have FIGURE 2 . Evaluating the best GxP applications to move to the cloud
made the decision to adopt Microsoft
Azure for their GxP regulated
MORE

New Mission Critical


applications now face the question Functionally Accessing
New Non-Mission
Critical Functionally
as to how to go about it in a strategic Private Data

way. After all, for most life sciences


REWARD/BENEFITS

companies, these applications Scale Existing Virtualized Legacy


represent a significant part of the Workloads Functionally

overall investment in IT, and are tied


directly to the business value the
technology provides. Private, Data
Intense Functionally Refactoring Existing
Functionality
New applications are frequently the
Migration of
easiest way to start, as there is no Existing Functionally
cost of change. For these applications,
LESS

it is simply a matter of working


with the regulators to address their
concerns and identifying and MORE COMPLEXITY/RISK LESS

8 | Strategies for Life Sciences Companies Using Microsoft Azure with GxP Systems
Hybrid computing FIGURE 3 . Hybrid application deployment models

models—a useful
alternative
Applications are no longer monolithic
in nature, and frequently components
of an application may be distributed
across a variety of underlying
infrastructures. Microsoft has
invested heavily in this area, looking
to support customers who not only
span their applications and data
across on-premises environments,
hosted private clouds and public
clouds, but also complex individual
application deployment scenarios,
as illustrated in Figure 3.

In some cases, it may not be desirable


to move an entire application to the
public cloud, but components of
the application may still be good
candidates for a shift. Just by moving
one part of the application, one may
increase the usability, flexibility,
scalability or geographical reach of
that application, and make validating In the second model, the life sciences Traditionally for new applications,

7
that application significantly easier. company retains the business technology providers consider
aspects but engages a technology infrastructure qualification along
partner such as Accenture to assist with the validation of the application
OPERATING MODELS in validating GxP applications itself. The underlying infrastructure
using the company’s own Quality qualification for Microsoft Azure
FOR GXP VALIDATION Management System. Working with services should only have to happen
Life sciences companies can choose the technology partner, the client once, after which the focus would
from three operating models for would identify candidates for be on application validation—driven
GxP validation. migration. The technology partner primarily by the client’s standards.
would then use its management
In the first model, the life sciences tools to create a “logical” factory The third operating model is where a
company takes responsibility for in which planning, coordination, client engages a technology provider
both business (functional) and disposition (VMs within Microsoft that assumes both business and
technical aspects of migrating and Azure), and actual execution steps technical aspects of migrating
validating GxP applications. The are developed and validated to workloads and validating new GxP
overall governing control is the migrate application and databases application using the partner’s Quality
Quality Management System of the including GxP from the client’s Management System by installing
life sciences company. locations into Microsoft Azure. and managing another technology
layer on top of the existing Microsoft
Azure infrastructure.

9
In this type of model, the life sciences and medical device companies. In
company and the service provider can addition, Accenture has partnered
agree to the level of their support with Microsoft to assist clients as
and maintenance functions. It is they migrate legacy systems to the
important to note that the traditional Microsoft Azure platform and to
support processes may need to be implement new GxP systems in the
updated within the life sciences cloud. The combination of Accenture
company itself when they contract consulting services and the Microsoft
with cloud service providers for any Azure platform will allow life
service. Cloud service providers assist sciences companies to validate
based on specific contract details cloud applications.
that may be difficult to change. A
typical agreement with a service Accenture is strategically placed
provider covers the following support to guide/coach clients through the
and maintenance functions: transformation of delivering software
1. Service management in a repeatable stream. As part of
our process, we split the software
2. Change management
development from its validation
3. User access control and logging activities with quality oversight
4. Incident management and CAPA applied to software development
5. Problem management and professional validation engineers.
6. Configuration management We use the outputs of that software
7. Data retention, backup and development to create the necessary
archiving regulatory documentation to provide
8. Disaster recovery a high degree of assurances that the
GxP application meets its intended
9. Service termination and service
use. This model uses the strength of
transfer
the organization to deliver functioning/
10. Employee training for those
validated software.
handling the above processes
11. Periodic review of the above to Accenture has successfully migrated
process adherence thousands of GxP and non-GxP
12. Support to life sciences companies applications and databases to

8
during external audits the cloud, while ensuring that the
application is still working and
maintained in a validated state.
This process minimizes downtime
USING ACCENTURE
and risk to the business by ensuring
TO SUPPORT that various tests (both manual
GXP VALIDATION and automated) are done prior to
migration and post migration. This
Most cloud providers do not have
process uses qualified tools and
a dedicated staff to support the
processes to test the underlying
validation and quality services, which
infrastructure as well as the application.
are currently provided by internal
groups within a life sciences company.
Accenture provides validation, quality,
and implementation services for
a number of top pharmaceutical

10 | Strategies for Life Sciences Companies Using Microsoft Azure with GxP Systems
CONCLUSION
Our comprehensive review of the suitability of Microsoft Azure
for GxP applications reveals that the security design, procedural
controls, and tools of Microsoft Azure meet the standards of
the life sciences industry. We believe companies can realize
significant business benefits moving GxP applications to Microsoft
Azure and most certainly in developing new GxP applications
using Microsoft Azure as the base infrastructure.

Life sciences companies looking to take advantage of the


capabilities offered by Microsoft Azure should examine the
portfolio for the best candidates. Partners such as Accenture
can be very helpful in identifying the right applications, in
helping organizations with validation challenges, and with
recommendations associated with application migration.

Over time, the process of qualifying the public cloud infrastructure


should continue to simplify as more tools and capabilities emerge.
However, it is perfectly possible to run GxP applications in a
compliant state in Microsoft Azure today, and organizations
looking to do so now have an opportunity to gain strategic
advantage over their competitors, and improve patient outcomes
with new categories of products and services.

11
STAY CONNECTED ABOUT THE AUTHOR ABOUT ACCENTURE
linkedin.com/company/ Adrian Perry is an Executive and LIFE SCIENCES
accenture_life_sciences Global Supply Chain Compliance Accenture’s Life Sciences group is
expert for Life Sciences working out dedicated to helping companies
@AccentureLifSci
of the Accenture New York Office. rethink, reshape or restructure their
He has over 20 years of experience businesses to deliver better patient
working across strategy and operations, outcomes and drive shareholder
and with his teams has validated
VISIT OUR BLOG returns. We provide end-to-end
over 3500 GxP systems across capabilities within or across strategy,
www.accenture.com/lifesciencesblog Manufacturing, R&D, and Enterprise consulting, digital, technology
Systems such as SAP. He has and operations around the globe
also worked on programs across in all strategic and functional areas—
over 25 manufacturing sites for with a strong focus on R&D, Patient
Biopharmaceuticals / Medical Device Services, Commercial and the
in Europe, Asia, and North America. Supply Chain.

We would like to also thank David We have decades of experience


Evans for contributing to this paper. working hand-in-hand with our
clients to improve their performance
David Evans is a senior technology across the entire life sciences value
and clinical research executive with chain. Accenture’s Life Sciences
over 35 years of experience in the group connects more than 15,000
clinical research, regulatory and skilled professionals in over 50
healthcare industries. Mr. Evans has countries who are personally
extraordinary experience in corporate committed to helping our clients
development, clinical information achieve their business objectives
management, clinical trial and deliver better health outcomes
management, complex clinical for people around the world.
data warehousing, regulatory data
analysis, automated data capture,
regulatory information standards,
regulatory quality management and ABOUT ACCENTURE
compliance, and clinical business
process engineering. He is recognized Accenture is a leading global
industry-wide as a leading technology professional services company,
visionary for developing and providing a broad range of services
implementing complex process and solutions in strategy, consulting,
and system solutions. He serves as digital, technology and operations.
the Head of Quality Governance and Combining unmatched experience
Regulatory Compliance for Accenture and specialized skills across more
R&D Services. than 40 industries and all business
functions—underpinned by the
world’s largest delivery network—
Accenture works at the intersection
of business and technology to help
clients improve their performance
and create sustainable value for their
stakeholders. With approximately
401,000 people serving clients in
more than 120 countries, Accenture
drives innovation to improve the way
Copyright © 2017 Accenture the world works and lives. Visit us at
All rights reserved.
www.accenture.com.
Accenture, its logo, and
High Performance Delivered
are trademarks of Accenture.

You might also like