[ TRACEABILITY ]

Requirement to Evidence

An inspector rarely asks whether you know the regulation. They ask what you do about it, and what shows that you did. This is that chain, made explicit: a clause-level obligation, the control that discharges it, the process that performs it, the risk it reduces, and the record it produces.

34
REQUIREMENTS
33
CONTROLS
13
RISKS
23
EVIDENCE TYPES
9
PROCESSES

The quality processes that carry the controls

A control does not float. It is performed inside a process, on named system classes, by people with a procedure. These are the 9 processes SPEQ’s mapped controls belong to.

PRC-USER-ACCESS-MANAGEMENT

User access management

Granting, changing and withdrawing access to regulated systems so that authority always matches the person’s current role.

CONTROLS PERFORMED HERE
PRC-COMPUTERIZED-SYSTEM-VALIDATION

Computerised system validation

Establishing and documenting that a system performs as intended for its regulated use, at a depth justified by risk.

CONTROLS PERFORMED HERE
PRC-CHANGE-CONTROL

Change and configuration control

Assessing, approving, implementing and verifying changes to regulated systems so the validated state is never lost silently.

CONTROLS PERFORMED HERE
PRC-PERIODIC-REVIEW

Periodic system review

Re-evaluating at defined intervals whether a system remains fit for its regulated purpose and in its validated state.

CONTROLS PERFORMED HERE
PRC-DATA-BACKUP-AND-ARCHIVE

Data backup, retention and archiving

Protecting regulated data against loss and keeping it retrievable and readable for the whole retention period.

CONTROLS PERFORMED HERE
PRC-SUPPLIER-MANAGEMENT

Supplier and service-provider management

Assessing, contracting and periodically re-evaluating the vendors, hosts and integrators that regulated systems depend on, and holding each to defined quality obligations.

CONTROLS PERFORMED HERE
PRC-TRAINING-MANAGEMENT

Training and qualification management

Ensuring every person performing a regulated task has, and can evidence, the education, training and experience it requires.

CONTROLS PERFORMED HERE
PRC-INCIDENT-MANAGEMENT

Incident and deviation management

Detecting, assessing, investigating and closing out system failures and data anomalies, including their impact on product and records.

CONTROLS PERFORMED HERE
PRC-BATCH-RELEASE

Batch certification and release

Certifying and releasing batches through an authorised person, with the record showing who released what and on what basis.

CONTROLS PERFORMED HERE
WHAT IS FACT AND WHAT IS SPEQ’S READING

The requirement statements are faithful restatements of the regulations they cite, each carrying its clause and source. The controls, risks, evidence types and processes — and every line drawn from an obligation to a control — are SPEQ synthesis: a practitioner’s reading of how an obligation is customarily discharged. No regulator publishes this mapping. 21 CFR 11.10(d) requires that system access be limited to authorised individuals; it does not say “run a quarterly access review”. That inference is what SPEQ adds, and it is labelled rather than presented in a regulator’s voice.