Odoo and GxP compliance

July 11, 2024 by
Odoo and GxP compliance
Idealis Consulting, Pierrick Fichefet


Understanding GMP and GxP


GMP Meaning

GMP stands for Good Manufacturing Practices. It is a set of guidelines and regulations governing how drugs and other therapeutics are produced, particularly in the biotech industry. These practices ensure that the manufacturing process is controlled, reproducible, and meets established quality standards.

GxP vs. GMP

GxP refers to a collection of quality guidelines and regulations that apply to various industries and sectors, where "x" can stand for different fields:

  • GMP: Good Manufacturing Practices
  • GDP: Good Distribution Practices

GxP encompasses all these practices, ensuring that products are consistently produced and controlled according to quality standards.

Regulatory Guidelines

The specific guidelines and regulations for GxP practices depend on the country or region:

  • In the United States, the Food and Drug Administration (FDA) sets the standards to ensure the safety, efficacy, and security of human and veterinary drugs.  (FDA).
  • In Europe, the European Medicines Agency (EMA) is responsible for these regulations. EMA

GxP Compliant Software

A GxP compliant software ensures adherence to good practices and is subject to regulatory requirements. Examples of such software include:

  • LIMS (Laboratory Information Management System)
  • ERP (Enterprise Resource Planning)
  • MES (Manufacturing Execution System)


Key Features for Compliance


  1. Data Integrity: Data must be collected, accessed, and maintained securely. Key principles include secure data collection, access, and maintenance. For more information about data integrity.
  2. Responsibilities: Clearly defined roles and access controls to ensure only authorized personnel can attest to the quality of products.
  3. Criticality and Risks: Identifying, analyzing, and mitigating risks affecting data integrity and trial results.
  4. Data Capture: Specifying the data to be collected and the process for capturing it.
  5. Electronic Signature: Ensuring the authenticity, non-repudiation, and secure linking of electronic records with signatures.
  6. Data Protection: Protecting data, particularly personal data of trial participants, from unauthorized access.
  7. Unique Identification: Ensuring all users accessing data are uniquely identified to track who can access, modify, or delete data.

For detailed guidelines, refer to the EMA's requirements les exigences de l'EMA.


Is Odoo GxP Compliant?  

Odoo is not GxP compliant out of the box. However, with proper configuration, it can meet most requirements:


Data Integrity, Data Protection, and Unique Identification

  • Odoo records data with timestamps and user information.
  • Access to data is secured through user authentication and access rights.
  • Hosting Odoo behind a VPN on a non-public server adds an extra layer of security.

Authentication Methods

  • Login and password
  • Login, password, and two-factor authentication
  • Single sign-on

Missing Features

  • Difficulty in tracking who deleted a record.
  • Limited information on changes made to records.

Responsibilities

  • Odoo allows configuring access rights to determine user access.
  • Users can be assigned roles with specific permissions.
  • Odoo Studio enables fine-grained control over field-level access.

Electronic Signature

  • Odoo's Sign app provides valid electronic signatures in the EU and the US.
  • The Sign app is ideal for static documents but not for dynamic documents.
  • Re-authentication during signing can improve security.

Audit Trail and Data Governance

To enhance GMP compliance, additional solutions like the Smart Governance module can be installed on Odoo:

  • Customizable audit trails to log specific changes.
  • Data policies and data policy officers ensure data accuracy and governance.

GxP Certification of Software

Software cannot be certified as GxP compliant out of the box. Certification applies to both the software and its usage within an organization. A software can be certifiable, meaning it has the necessary features to support compliance. However, internal processes might need to be established to cover any gaps.


Certification Process  

Achieving certification involves time, expertise, organization, documentation, and financial investment. It is advisable to seek guidance from experts in the certification process.


Smart Biotech 

At Idealis Consulting, we have developed a solution named Smart Biotech. This solution aim to bridge the gap between Odoo and a fully certifiable GxP software. Smart Biotech

Advantages of Smart Biotech

  • Cost Efficiency: By using our solution, you can share the development costs with all users of Smart Biotech, making it more affordable than customized development.
  • Continuous Improvement: Our solution is continuously updated, with new releases two to three times per year. You have control over when and if you want to install the new releases.

Collaborative Development  

We believe in co-constructing our roadmap with our customers. This ensures that the product evolves according to your needs, with a priority on features that advance towards full GxP compliance.


Want to Learn More?

Votre snippet dynamique sera affiché ici... Ce message est affiché parce que vous n'avez pas défini le filtre et le modèle à utiliser.

Pour en savoir plus sur Smart Biotech, visitez notre site web. Vous pouvez également vous inscrire à l'une de nos sessions de découverte gratuites.


If you have any questions do not hesitate to contact us our team will be glad to give you more information.