Local time

01Offer · Deliver

IT projectsin regulatedenvironments.

An IT, Digital, Quality or Compliance decision-maker needs an answer to one simple question: will this project be delivered, validated and defensible in an inspection?

01Deliver

AI & GxP Solutions Architect

That is the role I hold today at a Belgian biopharmaceutical group: connecting technology, quality and users. Concretely, I translate business and regulatory requirements into validated technical solutions, organise the documentation (URS, specifications, IQ/OQ/PQ, traceability matrix) and coordinate IT, OT, Quality and supplier teams up to go-live.

Twenty years of IT projects, including several in regulated pharmaceutical environments, taught me one thing: a system is only useful if it is reliable, documented and understood by the people who use it.

02Deliver

CSV validation, GxP and data integrity

Computer system validation (CSV) demonstrates, with evidence, that a system does what it should, reproducibly. I structure the approach along GAMP 5, scaling the effort to the risk: user requirements, risk assessment, qualification protocols and reports, change management.

21 CFR Part 11 requirements (electronic records and signatures) and data integrity principles (ALCOA+) are built in from the design stage: audit trails, access control, time-stamping, backups, periodic review. The goal is not paperwork, it is a file you can defend in an inspection.

03Deliver

IT/OT integration and document governance

On an industrial site, information systems meet production systems: PLCs, SCADA, MES, LIMS, historians. This IT/OT convergence creates specific risks (security, continuity, data integrity) that I address with the relevant frameworks, ISA/IEC 62443 for industrial cybersecurity and GAMP 5 for validation.

Document governance ties it together: procedures, versions, approvals, archiving. I set up simple systems and rules so that the right version of the right document is always the one in use.

04Deliver

AI in regulated environments

Artificial intelligence is entering plants and laboratories, and it must enter with governance: a justified use case, controlled data, validation proportionate to risk, traceable decisions. I help define that framework (AI governance, AI compliance) and deliver first useful use cases, such as document assistance, deviation analysis or report summarisation, without compromising compliance.

The digital transformation of an industrial site is not decreed: it is built project after project, with users, and with a quality file that keeps up.

02Frequently asked questions

What is 21 CFR Part 11?

21 CFR Part 11 is the US FDA regulation that sets the conditions under which electronic records and electronic signatures are considered trustworthy and equivalent to paper. It requires, among other things, audit trails, access control, electronic signatures linked to their record, and validated systems. Its European counterpart is EU GMP Annex 11.

What is data integrity in pharma?

Data integrity means data is complete, consistent and accurate throughout its life cycle. Regulators summarise it with the ALCOA+ acronym: attributable, legible, contemporaneous, original, accurate, plus complete, consistent, enduring and available. In practice it translates into audit trails, time-stamps, named access and regular reviews.

What is IT/OT convergence?

IT/OT convergence is the coming together of information systems (IT: servers, networks, applications) and production systems (OT: PLCs, SCADA, sensors, MES). It lets production data flow up to the business and enables more automation, but it exposes industrial equipment to new cyber risks, hence frameworks such as ISA/IEC 62443.