スキル一覧に戻る

conduct-gxp-audit

pjt222
更新日 Yesterday
5 閲覧
17
2
17
GitHubで表示
メタdata

について

このスキルは、開発者がコンピュータ化システムの包括的なGxP監査を実施できるようにするもので、計画と証拠収集から是正処置(CAPA)の生成および追跡検証に至る完全なライフサイクルを網羅します。内部監査、サプライヤー適格性評価、逸脱によって引き起こされる原因追及監査など、様々な監査タイプをサポートします。主な機能には、所見の分類(重大/主要/軽微)と、コンプライアンスレビューのための構造化レポート生成が含まれます。

クイックインストール

Claude Code

推奨
メイン
npx skills add pjt222/agent-almanac -a claude-code
プラグインコマンド代替
/plugin add https://github.com/pjt222/agent-almanac
Git クローン代替
git clone https://github.com/pjt222/agent-almanac.git ~/.claude/skills/conduct-gxp-audit

このコマンドをClaude Codeにコピー&ペーストしてスキルをインストールします

ドキュメント

Conduct GxP Audit

Plan and execute a GxP audit of computerized systems, data integrity practices, or regulated processes.

When to Use

  • Scheduled internal audit of a validated computerized system
  • Supplier/vendor qualification audit for GxP-relevant software
  • Pre-inspection readiness assessment before a regulatory audit
  • For-cause audit triggered by a deviation, complaint, or data integrity concern
  • Periodic review of a validated system's compliance posture

Inputs

  • Required: Audit scope (system, process, or site to audit)
  • Required: Applicable regulations (21 CFR Part 11, EU Annex 11, GMP, GLP, GCP)
  • Required: Previous audit reports and open CAPA items
  • Optional: System validation documentation (URS, VP, IQ/OQ/PQ, traceability matrix)
  • Optional: SOPs, training records, change control logs
  • Optional: Specific risk areas or concerns triggering the audit

Procedure

Step 1: Develop the Audit Plan

# Audit Plan
## Document ID: AP-[SYS]-[YYYY]-[NNN]

### 1. Objective
[State the purpose: scheduled, for-cause, supplier qualification, pre-inspection]

### 2. Scope
- **System/Process**: [Name and version]
- **Regulations**: [21 CFR Part 11, EU Annex 11, ICH Q7, etc.]
- **Period**: [Date range of records under review]
- **Exclusions**: [Any areas explicitly out of scope]

### 3. Audit Criteria
| Area | Regulatory Reference | Key Requirements |
|------|---------------------|------------------|
| Electronic records | 21 CFR 11.10 | Controls for closed systems |
| Audit trail | 21 CFR 11.10(e) | Secure, computer-generated, time-stamped |
| Electronic signatures | 21 CFR 11.50 | Manifestation, legally binding |
| Access controls | EU Annex 11, §12 | Role-based, documented |
| Data integrity | MHRA guidance | ALCOA+ principles |
| Change control | ICH Q10 | Documented, assessed, approved |

### 4. Schedule
| Date | Time | Activity | Participants |
|------|------|----------|-------------|
| Day 1 AM | 09:00 | Opening meeting | All |
| Day 1 AM | 10:00 | Document review | Auditor + QA |
| Day 1 PM | 13:00 | System walkthrough | Auditor + IT + System Owner |
| Day 2 AM | 09:00 | Interviews + evidence collection | Auditor + Users |
| Day 2 PM | 14:00 | Finding consolidation | Auditor |
| Day 2 PM | 16:00 | Closing meeting | All |

### 5. Audit Team
| Role | Name | Responsibility |
|------|------|---------------|
| Lead Auditor | [Name] | Plan, execute, report |
| Subject Matter Expert | [Name] | Technical assessment |
| Auditee Representative | [Name] | Facilitate access and information |

Got: Audit plan approved by quality management and communicated to auditee at least 2 weeks before the audit. If fail: Reschedule if auditee cannot provide required documentation or personnel.

Step 2: Conduct Opening Meeting

Agenda:

  1. Introduce audit team and roles
  2. Confirm scope, schedule, and logistics
  3. Explain finding classification system (critical/major/minor)
  4. Confirm confidentiality agreements
  5. Identify auditee escorts and document custodians
  6. Address questions

Got: Opening meeting documented with attendance record. If fail: If key personnel are unavailable, reschedule affected audit activities.

Step 3: Collect and Review Evidence

Review documentation and records against audit criteria:

3a. Validation Documentation Review

  • URS exists and is approved
  • Validation plan matches system category and risk
  • IQ/OQ/PQ protocols executed with results documented
  • Traceability matrix links requirements to test results
  • Deviations documented and resolved
  • Validation summary report approved

3b. Operational Controls Review

  • SOPs current and approved
  • Training records demonstrate competence for all users
  • Change control records complete (request, assessment, approval, verification)
  • Incident/deviation reports handled per SOP
  • Periodic review conducted on schedule

3c. Data Integrity Assessment

  • Audit trail enabled and not modifiable by users
  • Electronic signatures meet regulatory requirements
  • Backup and recovery procedures documented and tested
  • Access controls enforce role-based permissions
  • Data is attributable, legible, contemporaneous, original, accurate (ALCOA+)

3d. System Configuration Review

  • Production configuration matches validated state
  • User accounts reviewed — no shared accounts, inactive accounts disabled
  • System clocks synchronized and accurate
  • Security patches applied per approved change control

Got: Evidence collected as screenshots, document copies, interview notes with timestamps. If fail: Record "unable to verify" as an observation and note the reason.

Step 4: Classify Findings

Classify each finding by severity:

ClassificationDefinitionResponse Required
CriticalDirect impact on product quality, patient safety, or data integrity. Systematic failure of a key control.Immediate containment + CAPA within 15 business days
MajorSignificant departure from GxP requirements. Potential to impact data integrity if uncorrected.CAPA within 30 business days
MinorIsolated deviation from procedure. No direct impact on data integrity or product quality.Correction within 60 business days
ObservationOpportunity for improvement. Not a regulatory requirement.Optional — tracked for trend analysis

Document each finding:

## Finding F-[NNN]
**Classification:** [Critical / Major / Minor / Observation]
**Area:** [Audit trail / Access control / Change control / etc.]
**Reference:** [Regulatory clause, e.g., 21 CFR 11.10(e)]

**Observation:**
[Objective description of what was found]

**Evidence:**
[Document ID, screenshot reference, interview notes]

**Regulatory Expectation:**
[What the regulation requires]

**Risk:**
[Impact on data integrity, product quality, or patient safety]

Got: Every finding has classification, evidence, and regulatory reference. If fail: If classification is disputed, escalate to the audit program manager for adjudication.

Step 5: Conduct Closing Meeting

Agenda:

  1. Present findings summary (no new findings should be raised)
  2. Review finding classifications
  3. Discuss preliminary CAPA expectations and timelines
  4. Confirm next steps and report timeline
  5. Acknowledge auditee cooperation

Got: Closing meeting documented with attendance. Auditee acknowledges findings (acknowledgement ≠ agreement). If fail: If auditee disputes a finding, document the disagreement and escalate per SOP.

Step 6: Write Audit Report

# Audit Report
## Document ID: AR-[SYS]-[YYYY]-[NNN]

### 1. Executive Summary
An audit of [System/Process] was conducted on [dates] against [regulations].
[N] findings were identified: [n] critical, [n] major, [n] minor, [n] observations.

### 2. Scope and Methodology
[Summarize audit plan scope, criteria, and methods used]

### 3. Findings Summary
| Finding ID | Classification | Area | Brief Description |
|-----------|---------------|------|-------------------|
| F-001 | Major | Audit trail | Audit trail disabled for batch record module |
| F-002 | Minor | Training | Two users missing annual GxP training |
| F-003 | Observation | Documentation | SOP formatting inconsistencies |

### 4. Detailed Findings
[Include full finding details from Step 4 for each finding]

### 5. Positive Observations
[Document areas of good practice observed during the audit]

### 6. Conclusion
The overall compliance status is assessed as [Satisfactory / Needs Improvement / Unsatisfactory].

### 7. Distribution
| Recipient | Role |
|-----------|------|
| [Name] | System Owner |
| [Name] | QA Director |
| [Name] | IT Manager |

### Approval
| Role | Name | Signature | Date |
|------|------|-----------|------|
| Lead Auditor | | | |
| QA Director | | | |

Got: Report issued within 15 business days of the closing meeting. If fail: If delayed beyond 15 days, notify stakeholders and document the reason.

Step 7: Track CAPA and Verify Effectiveness

For each finding requiring a CAPA:

## CAPA Tracking
| Finding ID | CAPA ID | Root Cause | Corrective Action | Due Date | Status | Effectiveness Check |
|-----------|---------|------------|-------------------|----------|--------|-------------------|
| F-001 | CAPA-2025-042 | Configuration oversight during upgrade | Enable audit trail, verify all modules | 2025-04-15 | Open | Scheduled 2025-07-15 |
| F-002 | CAPA-2025-043 | Training matrix not updated | Complete training, update tracking | 2025-05-01 | Open | Scheduled 2025-08-01 |

Got: CAPAs assigned, tracked, and effectiveness verified per defined timeline. If fail: Unresolved CAPAs escalate to QA management and are flagged in the next audit cycle.

Validation

  • Audit plan approved and communicated before audit
  • Opening and closing meetings documented with attendance
  • Evidence collected with timestamps and source references
  • Every finding has classification, evidence, and regulatory reference
  • Audit report issued within 15 business days
  • CAPAs assigned with due dates for all critical and major findings
  • Previous audit CAPAs verified for closure effectiveness

Pitfalls

  • Scope creep: Expanding the audit scope during execution without formal agreement leads to incomplete coverage and disputes.
  • Opinion-based findings: Findings must reference specific regulatory requirements, not personal preferences.
  • Adversarial tone: Audits are collaborative quality improvement exercises, not interrogations.
  • Ignoring positives: Reporting only findings without acknowledging good practices undermines trust.
  • No effectiveness check: Closing a CAPA without verifying the fix actually works is a recurring regulatory citation.

Related Skills

  • perform-csv-assessment — full CSV lifecycle assessment (URS through validation summary)
  • setup-gxp-r-project — project structure for validated R environments
  • implement-audit-trail — audit trail implementation for electronic records
  • write-validation-documentation — IQ/OQ/PQ protocol and report writing
  • security-audit-codebase — security-focused code audit (complementary perspective)

GitHub リポジトリ

pjt222/agent-almanac
パス: i18n/caveman-lite/skills/conduct-gxp-audit
0
agentsagentskillsai-assisted-developmentclaude-codeskillsteams

関連スキル

content-collections

メタ

このスキルは、Content Collections(Markdown/MDXファイルを型安全なデータコレクションに変換するTypeScriptファーストのツール)の本番環境でテストされた設定を提供します。Zodバリデーションによる型安全性を実現し、ブログ、ドキュメントサイト、コンテンツ重視のVite + Reactアプリケーション構築時にご利用ください。Viteプラグインの設定、MDXコンパイルから、デプロイ最適化、スキーマバリデーションまで、すべてを網羅しています。

スキルを見る

polymarket

メタ

このスキルは、開発者がPolymarket予測市場プラットフォームを活用したアプリケーション構築を可能にします。API統合による取引や市場データの取得に加え、WebSocketを介したリアルタイムデータストリーミングにより、ライブ取引や市場活動を監視できます。取引戦略の実装や、ライブ市場更新を処理するツールの作成にご利用ください。

スキルを見る

creating-opencode-plugins

メタ

このスキルは、開発者がコマンド、ファイル、LSP操作など25種類以上のイベントタイプにフックするOpenCodeプラグインを作成することを支援します。JavaScript/TypeScriptモジュール向けに、プラグイン構造、イベントAPI仕様、および実装パターンを提供します。カスタムイベント駆動ロジックでOpenCode AIアシスタントのライフサイクルをインターセプト、監視、または拡張する必要がある場合にご利用ください。

スキルを見る

sglang

メタ

SGLangは、高性能なLLMサービングフレームワークであり、RadixAttentionプレフィックスキャッシュを活用したJSON、正規表現、エージェントワークフロー向けの高速で構造化された生成を特長とします。特にプレフィックスが繰り返されるタスクにおいて、大幅に高速な推論を実現し、複雑な構造化出力やマルチターン対話に最適です。制約付きデコードが必要な場合や、広範なプレフィックス共有を伴うアプリケーションを構築する場合は、vLLMなどの代替案ではなくSGLangを選択してください。

スキルを見る