Controls that work and controls that drag
Every organization has controls protecting against risks that were engineered out years ago. Telling them apart from the ones holding the business up is the job.
Book a demoENGINEER
Controls that work, and controls that drag
Telling real regulatory constraints apart from inherited habit.
There’s a conversation I’ve had in some form with almost every regulated customer I’ve worked with. It starts with somebody saying: we can’t change that, it’s a compliance requirement.
Sometimes that’s completely true, and the conversation should stop there. Often it turns out to be a control somebody introduced fifteen years ago for a sensible local reason, which has since acquired the status of regulation because nobody currently employed knows why it exists.
The Engineer phase of PURE has to be able to tell those apart. Get it wrong in one direction and you create regulatory risk. Get it wrong in the other and you carry decades of unnecessary work because nobody was willing to ask.
Preventive and detective
The most useful distinction I know in this area is between controls built into the flow of work and controls bolted on afterwards.
A detective control catches problems after they’ve happened, if somebody looks. An approved supplier list that people are supposed to check is a detective control. So is a monthly reconciliation, a spot audit, or a report someone reviews.
A preventive control makes the wrong outcome impossible. A system that only offers approved suppliers and materials is preventive: you can’t order outside it, so there’s nothing to catch afterwards.
Preventive controls are usually less work than detective ones, not more.
The intuition runs the other way, tightening control feels like adding effort, but a control embedded in the flow costs nothing per transaction, while a detective control costs somebody’s time on every cycle, forever, and still lets the error happen first.
When I’m looking at a process, the ratio of detective to preventive controls tells me a great deal about how much invisible work is going on. A process held together by checking is a process that was never designed.
Which constraints are real
In a GxP environment, some constraints are genuinely immovable.
EU GMP Chapter 5, applied in the UK through the MHRA’s guidance, requires that the selection, qualification, approval and maintenance of starting material suppliers is documented within the pharmaceutical quality system, and that materials are purchased directly from the manufacturer where possible. It also requires audits of API manufacturers and distributors, and formal traceability through the supply chain. ICH Q10 sets equivalent expectations for the management of outsourced activities and purchased materials, and ICH Q7 covers materials management for active ingredients.
These aren’t bureaucratic preferences. They exist because the consequences of getting materials wrong in a regulated product are severe, and any process redesign has to work within them.
The cost of change in this environment is also real, and larger than people outside it assume. The FDA’s 2019 analysis of drug shortages gives a sense of the scale: changing an API supplier generally requires additional regulatory approval, expanding or modernizing a multi-product facility takes more than a year and can cost over $100 million, and in one documented case an aseptic equipment upgrade on a globally marketed product took around seven years from planning to approval across all health authorities.
So when a CDMO tells you the cost of change is high, they aren’t being obstructive. They’re being accurate.
And which are habit
But notice what those requirements actually say. They govern supplier qualification, traceability and documented control. They don’t specify that the qualification evidence must live in a shared drive, that approval must be sought by email, that the same data must be entered into three systems, or that a person must manually check a list before every order.
That’s the space where redesign is available, and it’s usually much larger than the team believes.
The test I apply to any control is four questions:
- What specific risk does this control address?
- Does that risk still exist, in that form, today?
- Is this control mandated by regulation, by a customer agreement, or by internal decision, and can we point to the document?
- Could the same risk be addressed preventively, inside the flow, rather than by inspection afterwards?
If nobody can answer the first question, you’ve found something worth examining. If the answer to the third is an internal decision whose author left in 2016, you’ve found something worth changing.
Single source is a control decision too
A validated single source is the lowest-friction option in a regulated environment: no requalification, no change control, no customer notification. It’s also a concentration of risk. The FDA’s shortage work found that around 40% of generic drug markets were supplied by a single manufacturer, with a median of two, and supply disruption is precisely what that structure produces.
Qualifying a second source costs real money and real time. Not qualifying one costs nothing until the day it costs everything. That’s a genuine strategic trade-off, and the organizations that handle it well are the ones that have made it consciously rather than by default. Nobody can do all of it. The question is whether you chose what to leave, or whether it chose itself.
Audit readiness is a design outcome
One of the better diagnostics for whether controls are working is to ask how long an audit takes to prepare for.
If preparing means several people spending days assembling documentation, that effort isn’t the cost of being audited. It’s the cost of a process that doesn’t record itself. The documentation was always going to be needed; the only question was whether it accumulated as a by-product of the work or had to be reconstructed afterwards.
A well-designed process produces its own evidence. Audit preparation becomes retrieval rather than reconstruction, and the improvement isn’t marginal, it’s the difference between a fortnight and an afternoon.
This is why I push back when people describe regulation as an obstacle to process improvement. In my experience the quality management system is one of the most helpful frameworks you can have, because it forces exactly the discipline the methodology asks for: define the purpose, document the reality, control the change, evidence the outcome. The organizations that struggle aren’t the ones with the most regulation. They’re the ones that implemented regulation as a layer of manual checking on top of an undesigned process. Undesigned compliance is expensive. That’s a different problem, and it’s one you can actually fix.
See where the drag is in your own lab
Talk to MyAmici about applying the PURE methodology to your procurement and inventory processes.
Book a demo