How to Stand Up a Regulated Operating Model
Build the quality system a new regulated company actually needs — in the order that makes each next step possible.
What a how-to is not
A how-to is SPEQ’s practitioner method, not a procedure. It does not replace your own SOP, it is not a validated approach, and the judgement calls in it belong to your quality unit.
A new company in a regulated market has to become auditable before it becomes commercial, and most of the pain comes from doing that in the wrong order — buying an eQMS before anyone has decided who approves what, or writing SOPs for a process the company has not settled. This is the sequence that avoids rework: establish who decides, then what you make and to what standard, then the records that prove it, then the systems that hold them. It is a sequencing guide, not a compliance checklist, and no authority prescribes this order.
- 1
Decide what you are, before you decide what you need
Your product type and your role in the value chain set everything downstream: a device company runs design controls, a drug manufacturer runs process validation, a CDMO inherits obligations from its clients through quality agreements, and a virtual sponsor holds accountability it has outsourced the execution of. Write down the product, the markets you intend to enter, and whether you manufacture, sponsor, or serve. Almost every later argument traces back to a team that never made this explicit.
- 2
Establish decision rights before writing a single procedure
Name who approves a release, who can stop one, and who owns the quality system — and make the quality decision independent of the commercial one. This is the structural point ICH Q10 turns on, and it is cheap now and expensive later: a procedure written before the decision rights exist has to name a role that does not yet exist, and gets rewritten the moment it does.
- 3
Write the small number of procedures the others depend on
Not the full SOP library. The ones that govern how you will write, change, and retire everything else: document control, change control, deviation and CAPA, and training. These four are the machinery the rest of the system runs on, and companies that write them late end up with an uncontrolled pile of documents they then have to bring under control retroactively.
- 4
Define the records before choosing the system that holds them
Decide what evidence each activity must produce and who reviews it, then choose software. Doing it the other way round lets a vendor configuration decide your quality system, and you inherit a record set shaped by what the tool does easily rather than by what you need to prove. Paper is an acceptable answer at this stage for a small operation, provided the controls are real.
- 5
Qualify the people and the things that touch product
Training records for the people, qualification for facilities and equipment, calibration for instruments whose measurements become evidence, and supplier qualification for anyone whose material or service you rely on. A record generated by an uncalibrated instrument or executed by an untrained person is not evidence, which is why this step gates the ones after it rather than running alongside them.
- 6
Validate the computerised systems that create or approve records
Scope the effort to risk and intended use rather than validating everything to the same depth. What matters is that the systems holding GxP records enforce attributable, contemporaneous, and unalterable-without-trace behaviour, and that you can demonstrate it. This is where 21 CFR Part 11 and EU GMP Annex 11 expectations land for a company keeping electronic records.
- 7
Run the system long enough to have a record of running it
Deviations raised and closed, changes assessed, a management review held, an internal audit completed. An operating model with no operating history is a set of documents, and the first external audit will ask for the history rather than the intent. Build in the time for this before any date that depends on being inspectable.
- 8
Close the loop and let the system change itself
Feed audit findings, deviation trends, and management review outputs back into the procedures and the risk picture. A quality system that cannot change itself in response to what it learns will drift away from how the company actually works, and the gap between the written system and the real one is what inspections find.
- !Buying an eQMS first. The tool then defines the process, and you inherit a record set shaped by the software rather than by what you need to prove.
- !Copying an SOP library from a previous employer. It describes a company with different products, scale, and decision rights, and the mismatch surfaces during the first audit rather than during the copy.
- !Making quality report to the function whose deadlines it has to be able to stop. The independence is structural, not cultural, and no amount of good intent substitutes for it.
- !Treating validation and qualification as one activity. Qualifying equipment and validating a process answer different questions, and collapsing them leaves one of the two unevidenced.
- !Planning no time to actually run the system before an inspection or partner audit. There is no way to produce an operating history retrospectively.
How to Stand Up a Regulated Operating Model: frequently asked questions
Common questions on stand up a regulated operating model.
Is there a required order for standing up a quality system?
No. No regulation prescribes a sequence — they set expectations about what must be true, not the order in which you get there. The order here is SPEQ synthesis based on dependency: each step makes the next one possible, and the common failures are things done before the thing they depend on.
How small can a compliant quality system be?
Smaller than most new companies expect. Expectations scale with risk and complexity, not with headcount, and a small operation with a genuinely controlled document set, real decision rights, and honest records is in better shape than a large one with an elaborate system nobody follows. What does not scale down is independence of the quality decision.
Do we need an electronic quality management system to start?
Not necessarily. Paper or simple controlled files are acceptable for a small operation provided the controls are real — versions managed, approvals recorded, changes traceable. The trigger for electronic systems is usually volume and distribution, not compliance in itself, and choosing one before the records are defined tends to lock in the wrong shape.
When should a startup involve a regulatory consultant?
Most usefully at the first step, when the product classification, target markets, and role in the value chain are being decided, because those choices set every downstream obligation and are expensive to revisit. Bringing help in later to write procedures produces documents; bringing it in early changes what you have to build.
What does a first partner audit or inspection actually look for?
Evidence that the system runs, not that it exists. Expect questions about deviations you have raised and closed, changes you have assessed, training records for the people who did the work, and whether your written procedures match what people actually do. That is why running the system for a period is a step rather than an afterthought.
The same sequence lands differently depending on what you are
The steps above hold for any regulated startup. What changes is what each step is about. A generic checklist would tell a virtual sponsor to qualify equipment it does not own.
| Dimension | Device startupClass II device entering first clinical use, with its own assembly space | Diagnostics / lab startupClinical lab preparing to offer its own test | Virtual early-stage sponsorFour people, everything contracted, entering preclinical | CDMO-dependent sponsorDrug sponsor with no manufacturing of its own |
|---|---|---|---|---|
| The regulated object | The design, evidenced by the design history file | The laboratory as an operation, evidenced by accreditation | The decision record, evidenced by who decided on what basis | The release decision, evidenced by oversight of others |
| First real gate | Design freeze and design transfer | Authorisation to report clinical results | Trial application readiness | Batch release for clinical supply |
| What the startup owns physically | Assembly and inspection space, AR-01 to AR-03 | One laboratory, AR-04 | Nothing at all, including storage | Nothing. The CDMO holds every area |
| Quality system scope | Design plus in-house assembly | Laboratory processes only | A quality plan, not yet a system | Release, change, deviation and oversight only |
| Non-delegable role | Quality and regulatory lead | Laboratory director | The named accountable person, who is the chief executive | Named releasing person |
| Largest outsourced risk | Sterilisation and packaging | Reagent supply and lot performance | Study data the company did not generate | Everything physical; oversight is the only control |
| Most common over-build | Electronic QMS before design transfer | Pharmaceutical-scale QMS in a fourteen-person laboratory | A governance framework with committees of one | A hundred-page quality agreement negotiated for a year |
| Deferred longest, correctly | Post-market surveillance system | Kit design controls | Pharmacovigilance system | Own manufacturing quality system |
| Where SPEQ helps first | Applicability of design controls versus facility controls | Separating research use from reportable clinical use | Naming what attaches now versus at first-in-human | Dividing sponsor and CDMO obligation cleanly |