Document Control (Metadata)

Field Value
Effective Date03/01/2026
StatusImplemented
Document IDQMS-FP-IT
Versionv1.0
OwnerQuality Unit (QU)
ApproverQuality Unit Director
Controlled System of RecordGitHub
Change ControlQMS-????
Last Review Date03/01/2026
Next Review Date03/01/2027

INFORMATION QMS FAMILY PACK

Table of Contents

Quality Unit Authority, Electronic Systems Control Framework, & Governance Inheritance

This Information Technology (IT) Family Pack operates under the authority of the Sawgrass Nutra Labs Quality Management System (QMS) and the Quality Unit (QU).

In accordance with 21 CFR Part 11 and 21 CFR Part 111, the Quality Unit (QU) retains final, non-delegable authority over all GMP-impacting computerized systems, electronic records, and electronic signature controls, including:

IT operates as a GMP-Enabling Control Domain. IT executes defined controls for system access management, electronic signature configuration, audit trail preservation, backup integrity, cybersecurity protections, and system validation lifecycle management. IT does not independently authorize release of product, deviation closure, CAPA approval, or final quality disposition decisions.

The Electronic Systems Control Framework represents the governance structure established under QU authority, including: validation requirements, access control rules, audit trail expectations, segregation of duties, backup verification, and data integrity safeguards. IT implements and maintains this framework but does not supersede Quality Unit authority.

System validation gaps, unauthorized access events, audit trail anomalies, data integrity concerns, cybersecurity incidents, or backup failures shall be escalated through the QA-owned QMS workflow (e.g., WIN-QA-EXCEPTION-ESCALATION) prior to continued GMP reliance where required.

In the event of any conflict between operational system management and Quality Unit authority, Quality Unit authority prevails.


Section 1 - Family Summary

This Family inherits enterprise governance requirements defined in the L0 Unified Governance Document (L0-QMS-UGD), including the Quality Manual, Risk Management Program (RMP), Internal Audit Program (IAP), and QA-administered escalation controls. All IT responsibilities and WINs operate fully within these L0 authorities.

The Information Technology (IT) Process Family defines WHAT-level controls ensuring that computerized systems used within the Quality Management System (QMS) remain secure, validated, reliable, and compliant. IT establishes governance controls necessary to maintain system integrity, electronic record authenticity, access security, data protection, and validated system performance.

IT governance includes controls for:

As a GMP-Enabling Control Domain, IT ensures that:

IT controls support compliance with:

Risk Tier Classification: HIGH. Failures in IT controls can compromise electronic data integrity, record authenticity, system availability, and enterprise-wide regulatory compliance. Because computerized systems support all Process Families, IT control failures create cross-functional compliance exposure.

Section 2 — Purpose, Scope & Regulatory Anchors

SOP ID SOP Title Purpose Scope Regulatory Anchors
SOP-IT-ACCESS System Access Control Establishes WHAT-level controls for provisioning... Applies to all computerized systems... 21 CFR...
SOP-IT-ESIG Electronic Signatures Defines WHAT-level controls governing creation... Applies to all electronic systems... 21 CFR...
SOP-IT-BACKUP Backup Management Establishes WHAT-level controls for backup... Applies to all validated systems... 21 CFR...
SOP-IT-VALIDATE Computer System Validation Defines WHAT-level controls to ensure systems are validated... Applies to all GMP-impacting systems... 21 CFR...

Section 5 — Required AAs & Traceability Matrix

# SOP WIN AA Doc ID Type Frequency Description
System Access Control
1 SOP-IT-ACCESS WIN-IT-ACCESS AA-IT-ACCESS-CHK CHK Per Access Event Verify documented approval...
2 SOP-IT-ACCESS WIN-IT-ACCESS AA-IT-ACCESS-LOG LOG Continuous Maintain lifecycle record...
Electronic Signature Governance
3 SOP-IT-ESIG WIN-IT-ESIG AA-IT-ESIG-AUTH FRM Per Authorization Document QA-approved authorization...
4 SOP-IT-ESIG WIN-IT-ESIG AA-IT-ESIG-AUDIT REC Event-Driven Provide audit evidence...
Backup & Restoration Controls
5 SOP-IT-BACKUP WIN-IT-BACKUP AA-IT-BACKUP-LOG LOG Per Scheduled Backup Document execution...
6 SOP-IT-BACKUP WIN-IT-BACKUP AA-IT-RESTORE-REC REC Periodic Document restore testing...
Computer System Validation
7 SOP-IT-VALIDATE WIN-IT-VALIDATE AA-IT-VAL-APPROVAL FRM Per Validation Document QA approval...
8 SOP-IT-VALIDATE WIN-IT-VALIDATE AA-IT-VAL-SUMMARY REC Lifecycle Confirm validated state...

Section 6 — AA Deliverables

AA-IT-ACCESS-CHK

Access approval verification record...

AA-IT-ACCESS-LOG

Access lifecycle log...

AA-IT-ESIG-AUTH

Signature authorization record...

AA-IT-ESIG-AUDIT

Signature audit evidence...

AA-IT-BACKUP-LOG

Backup execution log...

AA-IT-RESTORE-REC

Restore verification record...

AA-IT-VAL-APPROVAL

Validation approval record...

AA-IT-VAL-SUMMARY

Validation summary record...

Section 7 — Execution (WIN)

WIN-IT-ACCESS

Trigger Event: Access request or personnel change...

WIN-IT-ESIG

Trigger Event: Signature authorization...

WIN-IT-BACKUP

Trigger Event: Scheduled backup...

WIN-IT-VALIDATE

Trigger Event: Validation lifecycle...

Section 8 - Governance Inheritance

This Family Pack inherits all enterprise-level governance defined in the L0 Unified Governance Document (L0-QMS-UGD), which serves as the authoritative source for quality management, documentation control, data integrity, electronic systems governance, and enterprise-wide control architecture.

All SOPs, WINs, and Auditable Artifacts (AAs) within this Family shall be created, maintained, executed, and periodically reviewed in full alignment with L0 governance requirements, including:

Quality Unit Authority

The Quality Unit (QU) retains final, non-delegable authority over quality-related decisions affecting compliance, authorization, system controls, and escalation pathways.

Governance Supremacy Clause

L0 governance requirements apply uniformly and supersede all Family-level content. This Family Pack does not replace, dilute, or modify enterprise governance and operates fully within the enterprise-wide QMS architecture.