Adrta Quality & Compliance Team
•8 min read

Bridging the critical gap between paper compliance and real-time execution across your enterprise quality operations.
Most pharmaceutical companies do not fail their ICH Q10 audits because they lack a policy. They fail because the policy does not match what actually happens on the floor, in the lab, or in the inbox of the person responsible for tracking a CAPA that closed six weeks late.
ICH Q10 has been in place since 2008. Every midsize and large pharma company can point to a quality manual that references it. Yet in most audits, the same pattern appears: a documented pharmaceutical quality system (PQS) that looks complete on paper but falls apart the moment an inspector asks to see how a single deviation actually moved through the system, from start to finish.
"That gap, between what is written and what is connected, is where most quality risk actually resides."
ICH Q10 defines a PQS around four core elements:
Are trends actively monitored, or is data simply collected and filed?
Does an identified problem reliably trigger a fix, or does resolution depend on someone remembering to follow up?
When a process, supplier, or specification changes, does that change automatically propagate through training, documentation, and validation, or does it require someone to manually notify every affected owner?
Does leadership see current, accurate quality signals, or a quarterly summary reconstructed after the fact from memory and spreadsheets?
None of these requirements are new. What has changed is regulator expectations around how compliance is demonstrated. Inspectors increasingly expect to see live traceability: not a binder confirming that a process exists, but a system that proves the process ran, consistently, for every record.
A common pattern recurs across pharmaceutical quality operations.
A deviation is logged in one system. A CAPA is opened in a separate tracker, often a spreadsheet or an email thread. If the fix requires a training update, a different department is notified separately to update the training matrix. If it also requires a document revision, that follows its own approval chain, on yet another platform.
Each individual step is technically compliant. A record exists for the deviation, the CAPA, and the training update. But no single thread connects them; no system can demonstrate, in one view, that a given deviation triggered a specific CAPA, which triggered a procedure revision, which in turn triggered a training requirement completed by every affected employee before the revised procedure took effect.
That thread is precisely what auditors increasingly request. Reconstructing it after the fact, by pulling logs from several disconnected tools in the days before an inspection, is what turns a routine audit into a finding.
This is also why the FDA's shift toward Computer Software Assurance (CSA) is significant. CSA moves quality teams away from checkbox style validation and toward demonstrating that a system's underlying risk logic holds up under scrutiny. A disconnected PQS cannot demonstrate this convincingly. A connected one can, because the logic is embedded in how records flow rather than added afterward.
A connected PQS does not require more documentation. It typically requires less, because the same event is no longer recorded separately across five different tools.
In practice, this looks like:
A deviation, its associated CAPA, any resulting change control, and the related training or document updates exist within one structure that references each other automatically.
When a procedure changes, the system automatically identifies every employee whose training record requires updating, rather than relying on a QA manager's memory.
Management review draws on current data: open CAPAs, overdue trainings, and trending deviation categories, rather than a report assembled manually.
Traceability from identification through closure that an inspector can follow seamlessly without needing multiple system cross-checks.
Two developments have shifted this landscape.
First, regulators, including the FDA and EMA, have moved decisively toward expecting real-time visibility rather than periodic reporting. A PQS capable of proving compliance only retroactively, through documentation reconstruction, is increasingly misaligned with current inspection expectations.
Second, the tools required to build a connected PQS have matured and become accessible well below the scale of large pharmaceutical enterprises. A decade ago, a connected quality system implied a significant, enterprise-scale investment. That is no longer the case. Cloud-based, validated QMS platforms now make real-time connectivity achievable for midsize manufacturers, CDMOs, and specialty BioTechs. Companies still managing quality through spreadsheets and shared drives are no longer constrained by cost. The remaining barrier is organizational inertia.
The following questions offer a practical starting point for evaluating your current infrastructure:
If a deviation is logged today, can every downstream action it triggered, along with current status, be shown in a single view?
When a procedure changes, does the system automatically identify which employees require retraining, or does this depend on manual tracking?
Can an accurate, current CAPA aging report be produced immediately, without requiring someone to compile it first?
If an inspector requested a trace of one deviation from identification to closure, how many people and systems would be required to answer?
If the honest answer to any of these involves assembling information across several sources over an extended period, the PQS is compliant on paper but disconnected in practice. Closing that gap is the underlying intent of ICH Q10.
Adrata Technologies builds the Zentixs suite for life sciences companies managing exactly this kind of complexity, including Zentixs QMS, designed around the principle that quality data should move automatically rather than manually. Organizations evaluating what a connected PQS should look like for their operations are welcome to reach out.