Case studyPharma & Life Sciences11 min read

Gunvatta QMS: replacing a pharma plant's paper quality system before the next inspection

A generic-drug manufacturer ran deviations, CAPAs, change controls and training records on paper binders and spreadsheets — and had an international regulatory inspection coming. We built Gunvatta QMS: an electronic quality management system with audit trails, e-signatures and linked records, validated for GMP use — 25 features delivered against a hard inspection deadline.

25
Features shipped
3
Apps & platforms
8
Team members
26
Weeks to rollout
Gunvatta QMS deviation record and quality dashboard
Gunvatta QMS: deviations, CAPAs, change control and training in one validated system.
01

Sixty binders and an inspection date

When we first visited Gunvatta's QA department, one wall was lined with binders — deviations, CAPAs, change controls, training records — each labelled by year and department. The head of quality could find almost anything, but it took time, and linking a deviation to its investigation, its CAPA and the training that followed meant opening four binders and trusting that nobody had misfiled a page.

The trigger for the project was an upcoming inspection by an overseas regulator. Previous inspections had raised observations about record retrieval and the traceability of changes. The quality head wanted a system that could answer any inspector's question in minutes, with a complete and tamper-proof history behind it.

“An inspector doesn't ask whether we fixed the problem. They ask us to prove it.”

— Gunvatta's head of quality
02

Writing requirements a validator would accept

Pharma software is different: it must be validated to show it does exactly what it claims, and every requirement must be traceable to a test. So instead of loose user stories, we wrote a user requirements specification with the QA team, clause by clause, and a traceability matrix that followed every requirement through design, build and testing.

The quality team walked us through their SOPs for each process. We discovered that the paper forms encoded years of lessons — fields added after previous audit observations — and we preserved every one of them in the electronic forms.

Non-negotiables from the QA team
  • Complete, uneditable audit trail of every change
  • Electronic signatures with meaning, identity and time
  • Records linked: deviation to investigation to CAPA to effectiveness check
  • Validation documentation the inspector could review
Technician working on detailed components
Every field on the paper forms had a reason. We kept them all.
03

Designing for linked records

The biggest improvement over paper was linkage. In Gunvatta QMS, a deviation opens an investigation, the investigation proposes CAPAs, each CAPA can trigger a change control and training assignments, and the effectiveness check closes the loop. Every record shows its parents and children, so an inspector's question can be followed end to end on one screen.

Shop-floor staff got a simplified tablet interface to raise deviations at the point they happen, with photos, instead of reporting them later from memory.

04

The team

Validation work is substantial, so the team included a dedicated validation and QA lead from the first week.

1
Engagement lead

Requirements workshops, inspection timeline and sign-offs.

1
Validation lead

Traceability matrix, IQ/OQ/PQ protocols and execution.

1
Product designer

Linked-record navigation and shop-floor tablet forms.

2
Backend engineers

Workflow engine, audit trail and e-signatures.

2
Frontend engineers

QMS web app, dashboards and tablet interface.

1
QA engineer

Test scripts mapped to every requirement.

8 people in total, working as one team.

05

Decisions made with QA and IT

Every decision here was documented in the design specification and reviewed by the head of quality.

01

Buy a packaged QMS or build?

  • Configure a packaged QMS
  • Build around the plant's own SOPs

Our call: Build around the plant's own SOPs. Packaged options required changing SOPs that had been refined through past inspections. A purpose-built system kept the plant's validated processes intact.

02

Where should it run?

  • Public cloud SaaS
  • On-premise in the plant's validated environment

Our call: On-premise in the plant's validated environment. The plant's IT and validation policies required GMP systems in its controlled infrastructure.

03

How should corrections work?

  • Edit records in place
  • Never overwrite; record every change with reason

Our call: Never overwrite; record every change with reason. Data integrity requires that original entries remain visible. Every change is appended with who, when and why.

04

Where should AI help?

  • AI decides root cause
  • AI suggests similar past deviations for investigators

Our call: AI suggests similar past deviations for investigators. Root cause must be determined by qualified investigators. Surfacing similar historical deviations helps them spot recurring issues faster.

06

The 25 features

Everything in the validated first release, organised by quality process.

Deviations and investigations
From the shop floor to root cause.
  • 01Point-of-event deviation reporting

    Raise deviations on tablets with photos where they happen.

  • 02Risk classification

    Critical, major and minor classification with guided criteria.

  • 03Investigation workflow

    Structured root-cause investigation with tools and approvals.

  • 04Similar deviation search

    AI-suggested historical deviations with related causes.

  • 05Batch impact assessment

    Link deviations to affected batches and products.

CAPA and change control
Closing the loop.
  • 06CAPA management

    Corrective and preventive actions with owners and due dates.

  • 07Effectiveness checks

    Scheduled verification that CAPAs worked.

  • 08Change control

    Impact assessment, approvals and implementation tracking.

  • 09Linked record view

    Every related record visible end to end.

  • 10Overdue escalation

    Automatic escalation of overdue actions.

Training and documents
People and procedures.
  • 11Training matrix

    Required training by role, with completion status.

  • 12Training triggered by change

    SOP revisions assign retraining automatically.

  • 13SOP document control

    Versioned SOPs with review and approval workflow.

  • 14Training compliance reports

    Compliance by department and individual.

Data integrity
What inspectors check first.
  • 15Immutable audit trail

    Every change with user, time, old value, new value and reason.

  • 16Electronic signatures

    Signatures with meaning, identity verification and timestamp.

  • 17Role-based access

    Permissions aligned with QA responsibilities.

  • 18Record retention

    Retention rules per record type.

  • 19Validated migration

    Paper records migrated with verification and sign-off.

Oversight
Quality at a glance.
  • 20Quality dashboard

    Open items, overdue actions and trends.

  • 21Inspection readiness view

    Fast retrieval of linked records during audits.

  • 22Trend analysis

    Deviations by area, product and cause over time.

  • 23Management review reports

    Periodic quality review packs generated automatically.

  • 24Validation document set

    Requirements, traceability and qualification records.

  • 25Notification centre

    Tasks and approvals delivered to each user.

Gunvatta QMS linked record view from deviation to CAPA
Linked records: from a deviation to its investigation, CAPAs, change control and training.
07

Validation and go-live

We executed installation, operational and performance qualification protocols with the QA team, recording every test result and every deviation from expected behaviour. Open paper records were migrated with verification: each migrated record was checked against its paper original and signed off.

The system went live several weeks before the inspection, giving the team time to use it for real. During the inspection, QA staff retrieved linked records on screen as questions were asked.

  1. Weeks 1–4
    Requirements

    SOP walkthroughs, user requirements and traceability matrix.

  2. Weeks 5–7
    Design specification

    Workflows, forms and linkage designed and approved.

  3. Weeks 8–17
    Build

    Five modules with audit trail and e-signatures.

  4. Weeks 18–23
    Validation

    IQ, OQ and PQ executed with the QA team.

  5. Weeks 24–26
    Migration and go-live

    Open records migrated and verified; live before inspection.

08

What we learned

In regulated software, documentation is a deliverable, not overhead. The traceability matrix made validation smoother and gave the QA team confidence in the system.

Respect the paper. The existing forms held years of institutional learning; migrating that knowledge faithfully mattered as much as the software.

Built with
  • Next.js
  • Java / Spring Boot
  • PostgreSQL
  • Electronic signatures
  • Immutable audit trail
  • On-premise deployment
  • Validation documentation (IQ/OQ/PQ)
CTA Background

Building something like Gunvatta QMS?

Bring the problem as it actually is, constraints included. You will get a straight answer on whether we are the right team.

View Our Work
AI-First Engineering
Secure & Scalable
Built to Deliver Impact
More case studies