The adoption of public cloud infrastructures in the healthcare sector has accelerated significantly in recent years. Pharmaceutical, biotechnology, and medical device companies are increasingly turning to platforms like Microsoft Azure, Amazon Web Services, or Google Cloud Platform to host GxP critical systems, attracted by their scalability, availability, security, and operational flexibility.
However, using public cloud in regulated environments presents specific challenges regarding infrastructure qualification, vendor auditing, and regulatory compliance. In this article, we analyze these challenges and share the key elements you need to know to successfully manage GxP systems in the cloud.
The myth of “GMP certified cloud”
One of the most relevant and often misunderstood aspects is the belief that public cloud providers offer "GMP certified" services. In practice, these providers hold widely recognized international certifications, such as ISO 27001 or SOC reports, which evidence the robustness of their security controls, availability, and business continuity.
However, these certifications:
- Do not replace GxP requirements
- Do not guarantee regulatory compliance
- Do not exempt regulated companies from their responsibilities before health authorities
GxP compliance is not automatically "inherited" simply by using a top-tier cloud provider.
The shared responsibility model: a key concept
This point is best understood through the cloud shared responsibility model.
While the cloud provider is responsible for the physical infrastructure, data centers, hardware, networking, and virtualization layer, regulatory responsibility continues to rest entirely with the regulated user.
The company contracting the cloud service is responsible for:
- Correct system configuration
- Validation of supported processes
- Data integrity, security, and traceability
- Access and role management
- Compliance with regulations such as EU GMP Annex 11 and 21 CFR Part 11
Regulatory responsibility is never delegated, regardless of where the infrastructure is hosted.
Cloud infrastructure qualification: risk-based approach
From a cloud infrastructure qualification perspective, GxP systems deployed in the cloud must be evaluated using a risk-based approach, similar to the one applied in on-premise environments, but adapted to the specificities of the cloud model.
Providers make multiple technical capabilities available, such as:
- Access control and segregation of duties
- Audit trails
- Data encryption
- Security backups
- High availability and disaster recovery
However, it is the regulated user who must decide how these capabilities are configured, document those configurations, and demonstrate that they are suitable for the system's intended use.
Cloud vendor auditing: a different approach
The auditing of public cloud providers also presents differential characteristics. Unlike traditional vendors, major cloud providers do not allow customized on-site audits. Instead, they provide extensive documentation packages that include:
- Third-party audit reports
- International certifications
- Detailed description of controls
- Specific guides for the life sciences sector
Therefore, companies must adopt a documentary audit approach, focused on the specific service contracted and its GxP impact, evaluating whether the controls offered are sufficient to comply with applicable regulatory requirements.
Critical GxP requirements in cloud environments
In relation to EU GMP Annex 11 and 21 CFR Part 11, using the cloud does not eliminate regulatory requirements; it simply introduces new layers of technical complexity. The following aspects require special attention:
- Data integrity (ALCOA+ principles)
- Traceability of user actions
- Access and privilege management
- Segregation of duties
- Change management
- System availability
- Business continuity
All these elements must be managed in a structured manner within the organization's quality system.
Key activities to maintain a state of control
The management of cloud infrastructures in regulated environments must include:
- Formal qualification activities (IQ, OQ and, where applicable, PQ adapted to the cloud model)
- Proper management of critical technology vendors
- Operational and security procedures
- Training of involved personnel
- Periodic reviews of the state of control
All of this must be coherently integrated into the Quality Management System and aligned with the expectations of regulatory authorities, both in face-to-face and remote inspections.
Conclusion: the cloud is not GxP “by default”
The public cloud represents a clear opportunity to improve efficiency and operational agility in the healthcare sector. However, it cannot be considered a GxP environment by default.
The cloud does not eliminate the need to qualify, validate, and audit; it simply changes the way it is done. Organizations that understand this reality and properly manage the qualification and auditing of their cloud providers are better prepared to leverage its advantages without compromising regulatory compliance.
How to ensure regulatory compliance?
At Ambit Iberia, we support companies in the healthcare sector with cloud infrastructure qualification, technology vendor auditing, and GxP system validation, helping them implement secure, efficient cloud solutions aligned with current regulatory requirements. If you need support, click here and we will be delighted to help you.
For over 20 years, we have been experts in developing IT strategies and solutions. We help the pharmaceutical, medical device, and IVD (in vitro diagnostics) sectors comply with regulations throughout the entire product lifecycle. We design and implement innovative infrastructures leveraging a global service offering as a key driver for digital transformation.
Cuéntanos tu opinión