Processes: Quality Management System
No processes match the current filters.
CSV Change Assessment and Release Planning
Quality Management System
ID: P017
The CSV Change Advisory Board assesses internal improvement proposals and external regulatory changes, then the Change Coordination Board selects proposals for implementation and creates a detailed release plan with resource estimates. Defined in document 10201920 as activities A1 and A2 of the CSV
Source Documents (1)
Mapped Citations (10)
Roles (5)
CSV Feedback Collection and Management
Quality Management System
ID: P019
During CSV release maintenance mode, the CSV Process Owner Team maintains formal feedback channels, manages incoming feedback from all employees, provides formal responses, and feeds improvement opportunities back into the improvement proposals list. Defined in document 10201920 as activity A5 of th
Source Documents (1)
Artifacts (1)
CSV Release Communications and Training Rollout
Quality Management System
ID: P022
Following release approval, the CSV Process Owner Team sends targeted communications to all employees about the new release and coordinates training needs identification and fulfillment before the release becomes effective. Defined in document 10201920 as activity A4 of the CSV Governance Model.
Source Documents (1)
CSV Release Formal Approval
Quality Management System
ID: P023
CSV Approvers formally review new CSV release documentation, verify organizational readiness against the implementation plan, and provide formal approval or feedback for escalation. Defined in document 10201920 as activity A3 of the CSV Governance Model.
Source Documents (1)
Mapped Citations (2)
Data Integrity Assessment
Quality Management System
ID: P034
A structured GxP compliance assessment workflow defined in SRD-0139481 for identifying data integrity risks and gaps across data, systems, and processes. The assessment evaluates adherence to ALCOA++ principles for computerized systems, procedures, and quality systems, resulting in documented correc
Source Documents (1)
Mapped Citations (44)
- 3.1 Establish and Maintain a Data Management Process
- 3.12 Segment Data Processing and Storage Based on Sensitivit...
- 3.14 Log Sensitive Data Access
- 3.2 Establish and Maintain a Data Inventory
- 3.7 Establish and Maintain a Data Classification Scheme
- 3.8 Document Data Flows
- 8.1 Establish and Maintain an Audit Log Management Process
- 8.2 Collect Audit Logs
- 8.5 Collect Detailed Audit Logs
- Acceptable use of information and other associated assets
- Activate audit logging
- Audit Trail
- CT.DM-P8
- CT.PO-P4
- Classification of information
- DL-2.B.1
- Electronic Records (Audit trail in human readable format)
- Electronic Records (Audit trail)
- Electronic Records (Data Integrity)
- Electronic Records (Data Review)
- Electronic Records (Data availbility in human readable forma...
- Enable Detailed Logging
- Encrypt All Sensitive Information in Transit
- Encrypt Sensitive Information at Rest
- Enforce Detail Logging for Access or Changes to Sensitive Da...
- GRC-07 Information System Regulatory Mapping
- GV.OC-03
- ID.AM-07
- ID.IM-P8
- Legal, statutory, regulatory and contractual requirements
- Maintain an Inventory of Sensitive Information
- Maintenance, Monitoring and Analysis of Audit Logs
- OS-1.C
- Open System Controls
- PR.DS-01
- PR.DS-02
- PR.DS-10
- Privacy and protection Of personal identifiable information ...
- SS.164.306.a1
- Signature/Record Linking
- TS.164.312.b
- TS.164.312.c1
- TS.164.312.c2
- Time-stamped Audit Trails
Roles (2)
Artifacts (1)
Health Authority Inspection Support
Quality Management System
ID: P045
Coordinated process for supporting Health Authority inspections of GxP computerised systems, covering preparation, during-inspection activities, and post-inspection follow-up between Contract Giver (PT) and Contract Acceptor (IT). Defined in AGR-0304935 with specific notification timelines and respo
Source Documents (2)
Mapped Citations (4)
Roles (7)
IT Self Inspection Management
Quality Management System
ID: P049
A structured review process defined in SOP-0302802 that monitors and evaluates key IT processes against defined metrics and objectives. The process covers two levels — Quality Oversight and Process Owner — and follows a mandatory eight-step lifecycle from scope definition to final reporting.
Source Documents (1)
Mapped Citations (31)
- 7.5 Perform Automated Vulnerability Scans of Internal Enterp...
- A&A-01 Audit and Assurance Policy and Procedures
- A&A-02 Independent Assessments
- A&A-03 Risk Based Planning Assessment
- A&A-05 Audit Management Process
- A&A-06 Remediation
- AS.164.308.a1-ii-d
- AS.164.308.a8
- Audit Log Completeness
- CEK-09 Encryption and Key Management Audit
- Collection Of evidence
- Compliance With policies, rules and standards for informatio...
- GV.MT-P3
- GV.OV-01
- GV.OV-02
- GV.OV-03
- GV.RM-07
- GV.RR-03
- ID.IM-02
- ID.IM-03
- Independent review Of information security
- PR.PO-P5
- PR.PO-P6
- Penetration Tests and Red Team Exercises
- Perform Periodic Red Team Exercises
- Protection of information systems during audit testing
- SEF-05 Incident Response Metrics
- STA-11 Internal Compliance Testing
- TS.164.312.b
- TVM-09 Vulnerability Management Reporting
- Use Vulnerability Scanning and Penetration Testing Tools in ...
Quality Management Review
Quality Management System
ID: P063
A structured periodic review process defined in POL-0300118 for evaluating the health and effectiveness of the IT QMS across Roche Informatics. The process combines Quality Oversight reviews, Process Owner reviews, data integrity validation, compliance assessment, and management review to ensure adh
Source Documents (1)
Mapped Citations (27)
- A&A-01 Audit and Assurance Policy and Procedures
- A&A-02 Independent Assessments
- A&A-04 Requirements Compliance
- AIS-03 Application Security Metrics
- AS.164.308.a1-i
- Compliance With policies, rules and standards for informatio...
- GRC-01 Governance Program Policy and Procedures
- GRC-03 Organizational Policy Reviews
- GV.MT-P3
- GV.MT-P4
- GV.OC-01
- GV.OV-01
- GV.OV-02
- GV.OV-03
- GV.RM-03
- GV.RR-01
- ID.IM-01
- ID.IM-04
- Independent review Of information security
- Management responsibilities
- PP.164.316.a
- PP.164.316.b1
- PR.PO-P5
- PR.PO-P6
- Policies for information security
- Quality Management System (in house)
- STA-11 Internal Compliance Testing
Roles (3)
Artifacts (1)