[ HOW-TO GUIDE ]

How to Stand Up a Regulated Operating Model

Build the quality system a new regulated company actually needs — in the order that makes each next step possible.

What a how-to is not

A how-to is SPEQ’s practitioner method, not a procedure. It does not replace your own SOP, it is not a validated approach, and the judgement calls in it belong to your quality unit.

A new company in a regulated market has to become auditable before it becomes commercial, and most of the pain comes from doing that in the wrong order — buying an eQMS before anyone has decided who approves what, or writing SOPs for a process the company has not settled. This is the sequence that avoids rework: establish who decides, then what you make and to what standard, then the records that prove it, then the systems that hold them. It is a sequencing guide, not a compliance checklist, and no authority prescribes this order.

THE STEPS
  1. 1

    Decide what you are, before you decide what you need

    Your product type and your role in the value chain set everything downstream: a device company runs design controls, a drug manufacturer runs process validation, a CDMO inherits obligations from its clients through quality agreements, and a virtual sponsor holds accountability it has outsourced the execution of. Write down the product, the markets you intend to enter, and whether you manufacture, sponsor, or serve. Almost every later argument traces back to a team that never made this explicit.

  2. 2

    Establish decision rights before writing a single procedure

    Name who approves a release, who can stop one, and who owns the quality system — and make the quality decision independent of the commercial one. This is the structural point ICH Q10 turns on, and it is cheap now and expensive later: a procedure written before the decision rights exist has to name a role that does not yet exist, and gets rewritten the moment it does.

  3. 3

    Write the small number of procedures the others depend on

    Not the full SOP library. The ones that govern how you will write, change, and retire everything else: document control, change control, deviation and CAPA, and training. These four are the machinery the rest of the system runs on, and companies that write them late end up with an uncontrolled pile of documents they then have to bring under control retroactively.

  4. 4

    Define the records before choosing the system that holds them

    Decide what evidence each activity must produce and who reviews it, then choose software. Doing it the other way round lets a vendor configuration decide your quality system, and you inherit a record set shaped by what the tool does easily rather than by what you need to prove. Paper is an acceptable answer at this stage for a small operation, provided the controls are real.

  5. 5

    Qualify the people and the things that touch product

    Training records for the people, qualification for facilities and equipment, calibration for instruments whose measurements become evidence, and supplier qualification for anyone whose material or service you rely on. A record generated by an uncalibrated instrument or executed by an untrained person is not evidence, which is why this step gates the ones after it rather than running alongside them.

  6. 6

    Validate the computerised systems that create or approve records

    Scope the effort to risk and intended use rather than validating everything to the same depth. What matters is that the systems holding GxP records enforce attributable, contemporaneous, and unalterable-without-trace behaviour, and that you can demonstrate it. This is where 21 CFR Part 11 and EU GMP Annex 11 expectations land for a company keeping electronic records.

  7. 7

    Run the system long enough to have a record of running it

    Deviations raised and closed, changes assessed, a management review held, an internal audit completed. An operating model with no operating history is a set of documents, and the first external audit will ask for the history rather than the intent. Build in the time for this before any date that depends on being inspectable.

  8. 8

    Close the loop and let the system change itself

    Feed audit findings, deviation trends, and management review outputs back into the procedures and the risk picture. A quality system that cannot change itself in response to what it learns will drift away from how the company actually works, and the gap between the written system and the real one is what inspections find.

USE THE TEMPLATE
Regulated Operating Model Establishment Plan
Skip the blank page — start from SPEQ’s structured, regulator-aligned template for this procedure. Open the template →
COMMON PITFALLS
  • !Buying an eQMS first. The tool then defines the process, and you inherit a record set shaped by the software rather than by what you need to prove.
  • !Copying an SOP library from a previous employer. It describes a company with different products, scale, and decision rights, and the mismatch surfaces during the first audit rather than during the copy.
  • !Making quality report to the function whose deadlines it has to be able to stop. The independence is structural, not cultural, and no amount of good intent substitutes for it.
  • !Treating validation and qualification as one activity. Qualifying equipment and validating a process answer different questions, and collapsing them leaves one of the two unevidenced.
  • !Planning no time to actually run the system before an inspection or partner audit. There is no way to produce an operating history retrospectively.

How to Stand Up a Regulated Operating Model: frequently asked questions

Common questions on stand up a regulated operating model.

Is there a required order for standing up a quality system?

No. No regulation prescribes a sequence — they set expectations about what must be true, not the order in which you get there. The order here is SPEQ synthesis based on dependency: each step makes the next one possible, and the common failures are things done before the thing they depend on.

How small can a compliant quality system be?

Smaller than most new companies expect. Expectations scale with risk and complexity, not with headcount, and a small operation with a genuinely controlled document set, real decision rights, and honest records is in better shape than a large one with an elaborate system nobody follows. What does not scale down is independence of the quality decision.

Do we need an electronic quality management system to start?

Not necessarily. Paper or simple controlled files are acceptable for a small operation provided the controls are real — versions managed, approvals recorded, changes traceable. The trigger for electronic systems is usually volume and distribution, not compliance in itself, and choosing one before the records are defined tends to lock in the wrong shape.

When should a startup involve a regulatory consultant?

Most usefully at the first step, when the product classification, target markets, and role in the value chain are being decided, because those choices set every downstream obligation and are expensive to revisit. Bringing help in later to write procedures produces documents; bringing it in early changes what you have to build.

What does a first partner audit or inspection actually look for?

Evidence that the system runs, not that it exists. Expect questions about deviations you have raised and closed, changes you have assessed, training records for the people who did the work, and whether your written procedures match what people actually do. That is why running the system for a period is a step rather than an afterthought.

[ FOUR SHAPES ]

The same sequence lands differently depending on what you are

The steps above hold for any regulated startup. What changes is what each step is about. A generic checklist would tell a virtual sponsor to qualify equipment it does not own.

DimensionDevice startupClass II device entering first clinical use, with its own assembly spaceDiagnostics / lab startupClinical lab preparing to offer its own testVirtual early-stage sponsorFour people, everything contracted, entering preclinicalCDMO-dependent sponsorDrug sponsor with no manufacturing of its own
The regulated objectThe design, evidenced by the design history fileThe laboratory as an operation, evidenced by accreditationThe decision record, evidenced by who decided on what basisThe release decision, evidenced by oversight of others
First real gateDesign freeze and design transferAuthorisation to report clinical resultsTrial application readinessBatch release for clinical supply
What the startup owns physicallyAssembly and inspection space, AR-01 to AR-03One laboratory, AR-04Nothing at all, including storageNothing. The CDMO holds every area
Quality system scopeDesign plus in-house assemblyLaboratory processes onlyA quality plan, not yet a systemRelease, change, deviation and oversight only
Non-delegable roleQuality and regulatory leadLaboratory directorThe named accountable person, who is the chief executiveNamed releasing person
Largest outsourced riskSterilisation and packagingReagent supply and lot performanceStudy data the company did not generateEverything physical; oversight is the only control
Most common over-buildElectronic QMS before design transferPharmaceutical-scale QMS in a fourteen-person laboratoryA governance framework with committees of oneA hundred-page quality agreement negotiated for a year
Deferred longest, correctlyPost-market surveillance systemKit design controlsPharmacovigilance systemOwn manufacturing quality system
Where SPEQ helps firstApplicability of design controls versus facility controlsSeparating research use from reportable clinical useNaming what attaches now versus at first-in-humanDividing sponsor and CDMO obligation cleanly