2020 FDA 483s around change

The yearly database of 483s has been updated by the FDA. Lots will be written on themes as we end the year, so I decided to give a few of my immediate observations.

I find that over time what I focus in on changes, as my jobs evolve and change, and the interests I have shift. However, some things never change, so let us talk change.

Reference NumberShort DescriptionLong Description2020 Frequency2019 Frequency2018 Frequency
21 CFR 211.100(a)Changes to Procedures Not Reviewed, ApprovedChanges to written procedures are  not [drafted, reviewed and approved by the appropriate organizational unit] [reviewed and approved by the quality control unit].  Specifically, ***8139
21 CFR 211.160(a)Lab controls established, including changesThe establishment of [specifications] [standards] [sampling plans] [test procedures] [laboratory control mechanisms] including any changes thereto, are not [drafted by the appropriate organizational unit] [reviewed and approved by the quality control unit].  Specifically, ***41817
21 CFR 212.20(c)Adverse effects of changes madeYou did not demonstrate that any change does not adversely affect the [identity] [strength] [quality] [purity] of your PET drug. Specifically,***111
483s related to changes

I think its fair to say the decreases as a result of the pandemic and the reduced inspections.

Over on the device side of things we see:

Reference NumberShort DescriptionLong DescriptionFrequency
21 CFR 820.30(i)Design changes – Lack of or Inadequate ProceduresProcedures for design change have not been [adequately] established.  Specifically,***26
21 CFR 820.40(b)Document change records, maintained.Records of changes to documents were not [adequately] maintained.  Specifically, ***6
21 CFR 820.70(b)Production and Process Change Procedures, lack of or Inad.Procedures for changes to a [specification] [method] [process] [procedure] have not been [adequately] established.  Specifically, *** 5
21 CFR 820.75(c)Process changes – review, evaluation and revalidationA validated process was not [reviewed and evaluated] [revalidated] when changes or process deviations occurred. Specifically, ***5
21 CFR 820.40(b)Change records, contentRecords of changes did not include [a description of the change] [identification of the affected documents] [the signature of the approving official(s)] [the approval date] [when the change became effective].  Specifically, ***



3
21 CFR 820.50(b)Supplier notification of changesThere is no agreement with [suppliers] [contractors] [consultants] to notify you of changes in the product or service.  Specifically, ***3
21 CFR 820.75(c)Documentation – review in response to changes or deviationsThere is no documentation of the [review and evaluation of a process] [revalidation of a process] performed in response to changes or process deviations.  Specifically, ***1
Device 473s around change

I’m a firm believer that pharma should always pay attention to the medical device side for 483s. A lot of us are combination products now (or will be) and there is always good trends to be aware of.

My key takeaways:

  1. Think change management and not just change control and document control
  2. Computer change controls need to be holistic and system orientated
  3. Have a process that ensures changes are appropriately reviewed and approved
  4. Risk based and evaluate validation
  5. A robust supplier management program is critical, plan for change

Here’s a more detailed checklist to help you evaluate your change system.

Mental Health and Culture

I’ve been thinking a lot today of this article by McKinsey by Jeffrey Pfeffer and Leanne Williams “Mental health in the workplace: The coming revolution.” It is a fascinating read, not just because we are in the midst of this pandemic which has certainly caused a lot of mental health issues, including depression, in many people. I know I’ve certainly been wrestling with it myself. I’m hopeful this issue remains on the agenda as I think it will provide long term benefits to culture.

I’ve written on how we need to build processes to support our employees in issues like burnout. Mental health is definitely a wicked problem, and will require systematic efforts to address. I am glad that the senior leaders I work with are thinking about this, and I look forward to deepening the conversation.

Embarrassing Photos

This photo is on the embarrassing side.

Messy Moderna binders from https://hbr.org/podcast/2020/11/remote-feedback

If I stumbled across this on a gemba walk there would be coaching on proper storage techniques of documents. My only hope is some corporate communications person made it this way on purpose and the poor person in the photo was muttering under their breath the entire time.

There is an opportunity here on connecting with communications team on best ways to showcase GxP activities. I recommend writing a good policy on the subject and ensuring it is appropriately bought into.

Happy Birthday to Franz Kafka

“I usually solve problems by letting them devour me.”

Franz Kafka, Letter to Max Brod

This blog is named after a great short story by Franz Kafka, a writer who should be read by every Quality professional.

Franz Kafka’s work has huge relevance for management and organization. The characteristics of bureaucracy that we find in Kafka’s fiction are widespread in the real world bureaucracies we find ourselves in, particularly the ambiguity of rules, the existence of informal networks within organizations, and systemic corruption. Reading Kafka has greatly influenced my ideas of organizational sense-making and has shaped many of my ideas on ethical issues and conflicts that arise within organizations. It is no exaggeration to say that Kafka’s name is as closely linked to the notion of bureaucracy as Weber’s, and deserves a central place in all organizational studies. Quite frankly, Quality as a practice and a profession would do well to read Kafka thoroughly.

The Value of Vulnerability

I’ve been thinking of the role vulnerability a lot in light of the current pandemic situation, and so I went back and re-read Professor Brené Brown’s Dare To Lead. In this book she lays out a framework for vulnerability, as a resource in leadership and within the workplace, which can impact the entire culture and creativity of a team.

Professor Brown defines vulnerability as uncertainty, risk and emotional exposure and lays out how vulnerability is essential to enabling collaboration. Leaders need to be transparent about their own challenges and encourage others to share their challenges with the group. Sharing vulnerability creates group cohesion.

At the same time I’m reading this book, I also started a new job and I’ve been in a lot of conversations about how we get folks comfortable with sharing their difficulties in their implementation around quality 4.0 initiatives.

Here’s the thing I want to stress, we can make vulnerability an organizational habit by instituting standard processes like after-action reviews and lessons learned. Building these processes into project lifecycle and our very culture provides a clear, designated space for sharing and vulnerability. By ensuring consistent application of lessons earned we can build this habit honesty, vulnerability, openness, and sharing of information. And through that we can help drive a culture of excellence.

Vulnerability can create space for “productive failure”, as Professor Brown terms it. A tricky thing for people to buy into but a way of thinking and working that turns failure into an opportunity to learn. When you know productive failure is a possibility you may be more inclined to be courageous and try and create something bigger and better despite the risks. When a workforce sees vulnerability named and shared by their leaders, and where they also acknowledge risks of failure but see it as an opportunity for learning they are likely to believe they can mirror some of that themselves.

There are a lot of reasons why organizations are bad at doing lessons learned, but I think at the core there is this unmovable idea that vulnerability is a weakness. It is probably for this reason that we see folks very willing to share their successes in case studies and at conferences, but not so willing to shares misses and failures. Even though we have a lot to learn from that vulnerability.

I’m curious. How is vulnerability expressed in your organization?