Requirement to Evidence
An inspector rarely asks whether you know the regulation. They ask what you do about it, and what shows that you did. This is that chain, made explicit: a clause-level obligation, the control that discharges it, the process that performs it, the risk it reduces, and the record it produces.
The quality processes that carry the controls
A control does not float. It is performed inside a process, on named system classes, by people with a procedure. These are the 9 processes SPEQ’s mapped controls belong to.
User access management
Granting, changing and withdrawing access to regulated systems so that authority always matches the person’s current role.
Computerised system validation
Establishing and documenting that a system performs as intended for its regulated use, at a depth justified by risk.
- Validate the system for its intended use
- Assess system risk and scale the effort to it
- Enable and lock the audit trail
- Enforce operational sequencing in the system
- Check the validity of the data source
- Verify data crossing a system boundary
- Check critical manually entered data
- Manifest the signature in readable form
- Bind the signature to its record
- Add open-system controls where access is not controlled
Change and configuration control
Assessing, approving, implementing and verifying changes to regulated systems so the validated state is never lost silently.
Periodic system review
Re-evaluating at defined intervals whether a system remains fit for its regulated purpose and in its validated state.
Data backup, retention and archiving
Protecting regulated data against loss and keeping it retrievable and readable for the whole retention period.
Supplier and service-provider management
Assessing, contracting and periodically re-evaluating the vendors, hosts and integrators that regulated systems depend on, and holding each to defined quality obligations.
Training and qualification management
Ensuring every person performing a regulated task has, and can evidence, the education, training and experience it requires.
Incident and deviation management
Detecting, assessing, investigating and closing out system failures and data anomalies, including their impact on product and records.
Batch certification and release
Certifying and releasing batches through an authorised person, with the record showing who released what and on what basis.
The requirement statements are faithful restatements of the regulations they cite, each carrying its clause and source. The controls, risks, evidence types and processes — and every line drawn from an obligation to a control — are SPEQ synthesis: a practitioner’s reading of how an obligation is customarily discharged. No regulator publishes this mapping. 21 CFR 11.10(d) requires that system access be limited to authorised individuals; it does not say “run a quarterly access review”. That inference is what SPEQ adds, and it is labelled rather than presented in a regulator’s voice.