MedTech Expert Explains Quality Management Systems | Pressure Tested
What is a Quality Management System (QMS), and why does every medical device laboratory need one?
How do audits, ISO 17025, GLP, and quality culture all work together to ensure reliable testing and regulatory compliance?
Toni Carlton, Head of Quality and Compliance at Test Labs, explains what it really takes to build and maintain an effective Quality Management System in a regulated laboratory.
She explores what happens behind the scenes every day to keep quality on track, how audits support continual improvement, and why documentation, traceability, and culture matter just as much as procedures. Toni also discusses ISO 17025, GLP, supplier onboarding, customer complaints, and the common misconceptions around quality assurance – showing how a strong QMS helps laboratories deliver consistent results, meet regulatory expectations, and build trust with clients.
#qms #iso17025 #glp
Video Transcript
What is a quality management system?
A quality management system is a system that companies can put into place. This covers your procedures, your calibration of equipment, whatever that might be, depending on the industry that you’re in. Obviously, what that means to you and what that means to your clients is, at the end of the day, what you’re doing, there is the quality aspect of it. No matter whether that is testing, you’re in neuroscience, or whatever that might be. Whatever your product that you’re selling or the service that you’re selling, the client at the end of the day is getting that quality aspect, and the confidence that they need in whatever you do.
Can you run a laboratory without QMS?
So, to answer the question, technically you can, but I wouldn’t advise it, and I don’t know who would want to go to a laboratory who doesn’t have something like that in place. I know a lot of our suppliers ask for different things around the management systems that we have in place to even get you as a supplier onto their system. So yeah, I wouldn’t recommend.
What happens on a daily basis when running a QMS at a laboratory?
On a daily basis, this can vary. Obviously, you’ve got your audit schedule, so making sure that there are the facility audits, study-specific audits, and process-based audits that are taking place. These are to ensure that the processes that are implemented are being performed as they should be. And then on the other side of that, obviously you’ve got your nonconformance and CAPAs. So, if anything is raised throughout the day and the procedures aren’t being followed, making sure that there’s the investigations performed to ensure that you’ve determined the root cause and the impact of those, and also the corrective actions to make sure that they don’t happen again. On top of that, you’ve got your continual improvement. So, every quality management system that’s in place, one of your big things is your continual improvement. No matter what business that you’re in, whether you’re a big business or a small one, there is always improvement to be made, and that is something that obviously you need to focus on, on a day-to-day basis.
What is a technical procedure?
So, a technical procedure is an SOP of sorts. These ones are normally specific for testing standards, so it’s something that the laboratory can follow. It has the equipment that you should use, the method you should follow, any controls that are in place, and as well as how you interpret that data. As I said, it’s something that your staff should be able to follow, you should be able to audit against it, and it should normally follow a standard or a verified method that you’ve got in place.
What is a testing protocol?
Okay, so a testing protocol, sometimes referred to as a study plan, especially within the GLP guidance. And this covers the method that your client is looking for. It covers the test item that is going to be tested, the introduction and purpose, so why that study is being performed, and then it goes on to the actual method itself. This includes your testing criteria, it includes your acceptance criteria, and usually, depending on the laboratory, you’d then send that to the client, make sure that they’re happy with it, and then get everyone’s sign-off.
What are the forms for the lab?
Okay, so I presume this is from the client perspective. So, the first one we usually send out is the new customer form, obviously, if it’s a new customer. This is to put them onto our system and make sure that we have everything regarding the actual company itself. You then have anything that is required for the actual testing itself. So, you have things like the sample submission form. This is to ensure that, one, we have the details correct when it comes to the company name and the location of them. But, and then it goes into the actual testing item itself. So, what we require on there is the exact name of what you want to put on the report for your test item that you’re testing, the batch number or serial number. It then comes into some more specifics around how it’s manufactured and expiry dates. And then lastly on there, usually we put on what testing you actually want to do. The reason we ask for this information is so that when we get those test items on-site, we can verify that. So, we can verify the batch number is the correct one, and then obviously question it if it’s something slightly different. And then when it comes to the method, obviously, yes, we’ve signed all the contract and everything like that. We’ve had all those conversations to make sure the fact of we’re going to be testing it to what you want, but at the end of the day, we need to have something that we compare to, to then obviously do our contract review and all of our other internal things that we need to have in place. At the end of the day, it’s the traceability from start to finish that we need, and that is the first point of call.
What is an audit?
Okay, so an audit internally, anyway, is something that we put in place to ensure that procedures that we have in place are being followed correctly. So, throughout the year, we have an audit schedule in place. This covers all our management systems so that we can integrate and ensure that everything is covered within our certification cycle. As part of the audit, obviously, we have our scope and criteria that we are auditing against. So, whether that is a technical procedure, whether it is a management procedure, or even a study-specific thing. So, there might be a critical area of a specific test that we’re performing that we need to ensure is audited, as it’s completely different to anything else that we might do. Once you then get into the audit, obviously you have other people involved, whether that’s the laboratory scientists, or whether that is your sales team, depending obviously on the scope of that audit. Then it’s a question of asking why. Why is that in place? That is a question what you might be asking to whoever you’re auditing. Or it might be: Why are you doing that? What are you following? So it’s kind of those five ‘w’ questions that you’d usually ask. And as I said, the aim of the audit is to ensure that whatever procedures are in place and you’re auditing, is being followed correctly.
Do you get audited by your clients?
Yes. Yes, we do. We can be audited by them, and there might be a few different reasons why they might want to audit us. It might be the actual procedure itself. So once it’s been agreed with them, they might want to come and have a look at how their test item is actually being tested. Or it might actually be so that we can actually get put onto their supplier system, and then they would start to have a look at the actual processes that we have in place and what is behind our systems in the sense of our QMS.
What do clients ask when completing supplier onboarding forms?
Okay, so they vary. Some of them are very basic, and some of them are expansive. But usually, what they’re asking for is obviously company details, and then also the management systems that you have in place. So, do you have a quality management system? Do you have an environmental management system? And so forth. They then ask for your policies and your certificates, and obviously, the main thing that they’re looking for is the scope that is on those certificates. So, is that appropriate to what they are looking for?
How long does it take to establish an ISO 17025 quality management system?
Oh, well, that’s a very broad topic, and it definitely depends on what status the laboratory is already at. Obviously, we came from nothing, and we implemented it, and we had our certificate within a year. But that doesn’t mean everyone can do that. Obviously, it depends on the mindset that you have, as well as if you’re already established. Which, to me, can sometimes be harder to then implement a new system, because then you’ve got the aspects of changing people’s mindset and implementing new procedures that might not necessarily go down very well.
GLP or 17025, which is better?
Well, I think to answer that, you kind of need to know what they are. So GLP, that’s a framework that was implemented to ensure that laboratories who are doing non-clinical safety and environmental testing have something in place to ensure that there’s the traceability and transparency of the testing that is performed to make sure that the results, at the end of the day, and what you’re submitting to a regulatory body is reliable. On the other hand, you’ve got ISO 17025. So this is specifically for testing and calibration laboratories, and it does look at those things, but also it looks at the technical competence and other aspects that there are overlap between the two. So, which one is better? I think it depends on, one, where in the world that you are. So 17025 is very European based usually, whereas GLP is very heavy in America. So it depends on where your client is based and where you’re trying to put your product onto the market. I wouldn’t necessarily say that one is better than the other. I think they both have their places and their pros and cons. So I think it is up to the person themselves to decide which one they require.
Why is there a GLP fee for a study?
Well, I’m not on the business aspect side in that sense, but what I can tell you is what is more involved with a GLP study. So on your general sort of non-GLP study, you’ve obviously got all the quality checking and everything like that, that is still in place. But when it comes to GLP, because of the extra requirements that you need, this is where QA gets involved. So it’s that extra resource that’s required which kind of carries that fee. This includes us ensuring that the study plan includes everything that meets the requirements, having the extra audits throughout the test. So we look at the critical aspects of each study that goes through the laboratory to ensure that the study is audited to a high enough level to ensure that it meets the requirements. You’ve then got the report itself. So once that’s drafted by the study director, we then have to look through the entirety of the raw data. So whether that is the media prep forms, whether that is your logbook with all your study data, and the report itself. So there’s a lot more involvement that is in place when it comes to a GLP study.
Why do GLP studies take more time?
Well, they don’t need to, but the involvement with the different areas within the business, that’s usually where it comes from. So usually with GLP studies, QA get involved as well as the other areas. So what takes the time is all the audits that are in place. So there’s a lot more study-specific audits that you have to do with GLP. So where you would normally just create your study plan, get the approval, start your study, and then once you’ve finished it, you would do the report and send that to the client. You’ve got QA at multiple different aspects within that. So we have to audit the study plan to make sure that it includes everything that GLP requires. You’ve then got your inspections within that study. And then again, at the end, when you’ve got the report, you’ve got all the raw data that needs to look at to make sure that whatever is in that report accurately reflects what actually happened in that study. And there’s where your little roadblocks are. So QA don’t want to be those roadblocks, but obviously, if we don’t have the time to do those and the planning isn’t there, then that’s where the delays can come in.
Is ISO 9001 applicable to a laboratory? Why do you have it if you’ve got ISO 17025 and GLP?
It’s a good question. Why do we have multiple different quality management systems? But ISO 9001 is the backbone of the system in place. So it was the first one that was implemented, and we’ve just built from there. Obviously, different areas and different businesses have their different requirements. So that’s why we have the different ones. Obviously, 17025, we have a very specific scope. That’s what UCAS require, and you can’t do- The testing if it’s not on that scope. GLP also has its very specific scope, so if it’s not a non-clinical, safety, or environmental study that is for a regulatory submission, then it can’t be done under GLP either. So, where does all the other studies come in? We want to make sure that, basically, if our client has a difficult question they want to answer, we want to be able to do it, and we want to be able to do it under a management system. So, this is where 9001 comes in.
27001, what’s that all about?
Well, I’m presuming you’re meaning our information security management system, and it’s probably one of the most important ones, if not the most annoying. But basically, what it is, is to ensure that we’ve got things in place that we need to ensure the security of our systems, whether that is our intruder alarms that we have to make sure if there’s anyone that’s coming on site when we’re closed up. It’s our access control, so making sure that unauthorized personnel can’t go into the laboratory. It’s our access to all our systems. We have cloud-based systems, and we need to ensure that they’re backed up correctly. They are tested to ensure that if we lose anything, that we can recover that. And if we don’t have any of that, then that’s our business continuity out the window. If something was to happen tomorrow, then would we actually recover? And that’s where ISO 27001 comes in.
Who do you deal with? Which regulators?
Well, regulators per se, obviously, the relationship that we have are not just regulators. It’s accreditation bodies, certification bodies, as well as the likes of HSE and so forth. Obviously, we deal with MHRA when it comes to our GLP certification. We deal with UKAS for our ISO 17025. And for the rest of the management systems, we deal with BSI. Obviously, these are usually through audits, but the relationship that we need to build with them is something that we need to do, not just when the audit’s coming up. It’s something that we need to do throughout the entire year. The reason for that is obviously, we need to ensure that any changes that are happening or any updates in the standards that we’re using or regulations, we need to ensure that these are communicated with them as well. And then you’ve obviously got the likes of the FDA. We have our US clients, and we need to ensure that we’re also meeting the requirements that they need for their submissions within the US as well.
Certification, accreditation. Tomato, tomato.
Well, this is one that really bugs me when it’s used wrong, which sounds really stupid because they probably sound the same. So, certification is that you are certified to something. So, you have a certification body, you have your scope, and then you are certified against that scope. Whereas your accreditation is a lot more in-depth. So again, you’ve got an accreditation body. So, they accredit you against something. So yes, you’ve got a scope, but it’s a lot more specific. So yes, I understand why they probably get used incorrectly sometimes, but if you talk to anyone in the quality department, they’ll probably be just as bugged out as I am when they’re used incorrectly. But the main point is, obviously, the body that is either certifying you or accrediting you. I think that’s probably the easiest route to know which one to use.
What are the key three things that you would look at when establishing your QMS system?
That’s a good question. So for me, your first one is customers. So, what I mean by that is not just their satisfaction, but their actual requirements. So, whether that is legislation, whether that is a standard. So, do they need to go into a market in Europe or US? Does that decide which management system that you need to put it under? Is there a specific standard that they need to do testing against and is that applicable? Is it the latest version of it? And being able to pinpoint to a client, be like, “Oh, no, that’s an old one. There’s a new one.” I think that’s something that clients really appreciate. So yeah, it’s not just their satisfaction, but I think everything that goes into their satisfaction is the first key point. I think secondly to that is probably the perception and the culture that you have within the team. You can have as many processes you want in place, but that doesn’t mean someone’s going to follow them. I think having that culture around the team to know that whatever they’re doing, whether that is the smallest lab piece of work or whether that’s your business development team that are getting those clients in, it’s having that culture, knowing that everything goes into what comes out at the end of the day. And ensuring that whatever they do, there is always input into the outcome. Lastly, probably a bit more specific, it’s actually around the method and the equipment. So, is what you’re doing the actual thing that you need to do? So yes, you’ve got your procedures in place that kind of go into that, but is your equipment calibrated at the right points? Is your method that you’re using appropriate? And then obviously, you’ve got all the traceability behind that. So, what you need to ensure is having from start to finish, you could repeat that in 10, 20, 30 years’ time, when no one who was involved within that study was about, and that’s probably the last point I would probably say.
How do you deal with a customer complaint?
So, lucky enough, we don’t get them quite often, but obviously there is that procedure in place. And also, we want to make sure that we’re learning from them. So obviously, acknowledging that complaint, whatever that might be, whether that is coming from a low score on a customer satisfaction survey or an email just saying, “Oh, I thought you were going to do this, but you’ve done that.” We take them as complaints. Obviously, we do ask whether they want to submit it as an official one or whether we want to just look at it in the background to see how we can help that client. Obviously, once we’ve acknowledged that, we then decide based on the risk factors involved, whether we do a formal investigation on it. So, something that we can deal with the client straight up and deal with that, we may not do an investigation. But something that may impact other clients’ work or procedures that we have in place, then obviously we would. That investigation is obviously always done by someone who is independent. So, you’ve got none of that sort of impartiality when it comes to whatever is the outcome of that investigation. That can include communication. It can include looking at raw data. Obviously, that all depends on what the actual complaint actually is. And then you get the outcome. So, whether that means repeating work or whether that means going back through other clients’ work and making sure the fact that nothing else is involved, or it might be just updating a procedure or anything like that. So obviously, what we want to do is make sure that whoever has complained in the first place is happy with whatever the outcome is and whatever we intend to implement.
Deviations and amendments… What’s the stress there?
So, this is one that should never be something that should cause stress, but when they’re done incorrectly or someone doesn’t know the difference between them, then that can cause that stress level. So obviously, you’ve got something that is a deviation. This is where something has happened where you have not followed the process. And then obviously, the outcome of that is whoever is responsible for that study needs to ensure that they do an impact statement and root cause, and at the end of the day, find out a corrective action to prevent it from happening again. When this occurs, obviously we need to make sure that it’s very transparent, and so that means including this within the report that is issued, as well as make sure that it is fully documented from start to finish. Whereas an amendment, this is something that’s agreed beforehand. So, something as simple as you’re going past the date that you agreed that the study was going to be completed in. You know that’s going to happen beforehand. Let’s just do a quick amendment to the protocol, get it signed off again, and that’s as simple as that. Obviously, you need to make sure that it is still documented correctly, but it’s been agreed beforehand. You get the sign-off by the client, the study director is obviously privy to it, and then you can make sure that all your laboratory personnel are as well. I worked in a lab and I dreaded QA.
Why is everyone at odds with the QA department?
Well, I think that I can completely understand that, and I get that feeling every time I step into the laboratory and I’m looking at a bit of paperwork and everyone’s like, “Should I be worried?” Well, I think the answer to that question is around the fact of obviously everyone feels like they should be under pressure when anyone from QA steps inside. The reason for that is they’re being checked on, and they have someone looking over their shoulder to make sure the fact that they’re doing what they should. And a lot of quality departments, they have KPIs of how many non-conformances they raise, which to me isn’t necessarily the best KPI to have there, because I think that’s what adds to this pressure that staff have. What I would like to have, and the relationship that I would have with the team, is the fact of we want to work together, see. We want to make sure that we continually improve, and that’s where we come in place. We want to find those gaps and see how we can rectify those.
So that’s me pressure tested. I think it definitely made me think, something that normally I just do on a day-to-day basis, really having to think about what other people would ask about. But yeah, thank you for watching, and hope you enjoyed.
Up Next
Get It Done, With Certainty.
Contact us about your testing requirements, we aim to respond the same day.
Get resources & industry updates direct to your inbox
We’ll email you 1-2 times a week at the maximum and never share your information