MCP HubMCP Hub
스킬 목록으로 돌아가기

conduct-gxp-audit

pjt222
업데이트됨 2 days ago
2 조회
17
2
17
GitHub에서 보기
메타data

정보

이 Claude Skill은 컴퓨터화된 시스템에 대한 GxP 적합성 감사를 자동화하며, 계획부터 후속 조치까지 감사 전 주기를 처리합니다. 발견 사항을 분류하고, CAPA를 생성하며, 내부, 공급자 또는 원인별 감사에 대한 보고서를 작성합니다. 개발자들은 이를 통해 검사 전 준비 및 검증된 시스템의 적합성 검토에 활용할 수 있습니다.

빠른 설치

Claude Code

추천
기본
npx skills add pjt222/agent-almanac -a claude-code
플러그인 명령대체
/plugin add https://github.com/pjt222/agent-almanac
Git 클론대체
git clone https://github.com/pjt222/agent-almanac.git ~/.claude/skills/conduct-gxp-audit

Claude Code에서 이 명령을 복사하여 붙여넣어 스킬을 설치하세요

문서

Conduct GxP Audit

Plan + execute GxP audit of computerized systems, data integrity practices, or regulated procs.

Use When

  • Scheduled internal audit of validated computerized system
  • Supplier/vendor qualification audit for GxP-relevant software
  • Pre-inspection readiness assessment before regulatory audit
  • For-cause audit triggered by deviation, complaint, or data integrity concern
  • Periodic review of validated system's compliance posture

In

  • Required: Audit scope (system, proc, or site to audit)
  • Required: Applicable regs (21 CFR Part 11, EU Annex 11, GMP, GLP, GCP)
  • Required: Prev audit reports + open CAPA items
  • Optional: System valid. docs (URS, VP, IQ/OQ/PQ, traceability matrix)
  • Optional: SOPs, training records, change control logs
  • Optional: Specific risk areas / concerns triggering audit

Do

Step 1: Develop Audit Plan

# Audit Plan
## Document ID: AP-[SYS]-[YYYY]-[NNN]

### 1. Objective
[State the purpose: scheduled, for-cause, supplier qualification, pre-inspection]

### 2. Scope
- **System/Process**: [Name and version]
- **Regulations**: [21 CFR Part 11, EU Annex 11, ICH Q7, etc.]
- **Period**: [Date range of records under review]
- **Exclusions**: [Any areas explicitly out of scope]

### 3. Audit Criteria
| Area | Regulatory Reference | Key Requirements |
|------|---------------------|------------------|
| Electronic records | 21 CFR 11.10 | Controls for closed systems |
| Audit trail | 21 CFR 11.10(e) | Secure, computer-generated, time-stamped |
| Electronic signatures | 21 CFR 11.50 | Manifestation, legally binding |
| Access controls | EU Annex 11, §12 | Role-based, documented |
| Data integrity | MHRA guidance | ALCOA+ principles |
| Change control | ICH Q10 | Documented, assessed, approved |

### 4. Schedule
| Date | Time | Activity | Participants |
|------|------|----------|-------------|
| Day 1 AM | 09:00 | Opening meeting | All |
| Day 1 AM | 10:00 | Document review | Auditor + QA |
| Day 1 PM | 13:00 | System walkthrough | Auditor + IT + System Owner |
| Day 2 AM | 09:00 | Interviews + evidence collection | Auditor + Users |
| Day 2 PM | 14:00 | Finding consolidation | Auditor |
| Day 2 PM | 16:00 | Closing meeting | All |

### 5. Audit Team
| Role | Name | Responsibility |
|------|------|---------------|
| Lead Auditor | [Name] | Plan, execute, report |
| Subject Matter Expert | [Name] | Technical assessment |
| Auditee Representative | [Name] | Facilitate access and information |

Audit plan approved by QA mgmt + communicated to auditee ≥ 2 weeks before audit. If err: Reschedule if auditee can't provide req'd docs or personnel.

Step 2: Conduct Opening Meeting

Agenda:

  1. Introduce audit team + roles
  2. Confirm scope, schedule, logistics
  3. Explain finding classification (critical/major/minor)
  4. Confirm confidentiality
  5. ID auditee escorts + doc custodians
  6. Address questions

Opening meeting doc'd w/ attendance record. If err: Key personnel unavail → reschedule affected audit activities.

Step 3: Collect + Review Evidence

Review docs + records vs. audit criteria:

3a. Validation Documentation Review

  • URS exists + approved
  • Valid. plan matches system category + risk
  • IQ/OQ/PQ protocols executed w/ results doc'd
  • Traceability matrix links req's to test results
  • Deviations doc'd + resolved
  • Valid. summary report approved

3b. Operational Controls Review

  • SOPs current + approved
  • Training records show competence all users
  • Change control records complete (req, assessment, approval, valid.)
  • Incident/deviation reports handled per SOP
  • Periodic review conducted on schedule

3c. Data Integrity Assessment

  • Audit trail enabled + not user-modifiable
  • Electronic sigs meet reg req's
  • Backup + recovery docs'd + tested
  • Access controls enforce role-based perms
  • Data: attributable, legible, contemporaneous, original, accurate (ALCOA+)

3d. System Configuration Review

  • Prod config matches validated state
  • User accounts reviewed — no shared accounts, inactive disabled
  • System clocks sync'd + accurate
  • Security patches applied per approved change control

Evidence collected as screenshots, doc copies, interview notes w/ timestamps. If err: Can't verify → record "unable to verify" as observation + reason.

Step 4: Classify Findings

Classify each finding by severity:

ClassificationDefinitionResponse Required
CriticalDirect impact on product quality, patient safety, or data integrity. Systematic failure of a key control.Immediate containment + CAPA within 15 business days
MajorSignificant departure from GxP requirements. Potential to impact data integrity if uncorrected.CAPA within 30 business days
MinorIsolated deviation from procedure. No direct impact on data integrity or product quality.Correction within 60 business days
ObservationOpportunity for improvement. Not a regulatory requirement.Optional — tracked for trend analysis

Doc each finding:

## Finding F-[NNN]
**Classification:** [Critical / Major / Minor / Observation]
**Area:** [Audit trail / Access control / Change control / etc.]
**Reference:** [Regulatory clause, e.g., 21 CFR 11.10(e)]

**Observation:**
[Objective description of what was found]

**Evidence:**
[Document ID, screenshot reference, interview notes]

**Regulatory Expectation:**
[What the regulation requires]

**Risk:**
[Impact on data integrity, product quality, or patient safety]

Every finding has classification, evidence, reg ref. If err: Classification disputed → escalate to audit program manager for adjudication.

Step 5: Conduct Closing Meeting

Agenda:

  1. Present findings summary (no new findings should be raised)
  2. Review finding classifications
  3. Discuss prelim CAPA expectations + timelines
  4. Confirm next steps + report timeline
  5. Acknowledge auditee cooperation

Closing meeting doc'd w/ attendance. Auditee acknowledges findings (acknowledgement ≠ agreement). If err: Auditee disputes finding → doc disagreement + escalate per SOP.

Step 6: Write Audit Report

# Audit Report
## Document ID: AR-[SYS]-[YYYY]-[NNN]

### 1. Executive Summary
An audit of [System/Process] was conducted on [dates] against [regulations].
[N] findings were identified: [n] critical, [n] major, [n] minor, [n] observations.

### 2. Scope and Methodology
[Summarize audit plan scope, criteria, and methods used]

### 3. Findings Summary
| Finding ID | Classification | Area | Brief Description |
|-----------|---------------|------|-------------------|
| F-001 | Major | Audit trail | Audit trail disabled for batch record module |
| F-002 | Minor | Training | Two users missing annual GxP training |
| F-003 | Observation | Documentation | SOP formatting inconsistencies |

### 4. Detailed Findings
[Include full finding details from Step 4 for each finding]

### 5. Positive Observations
[Document areas of good practice observed during the audit]

### 6. Conclusion
The overall compliance status is assessed as [Satisfactory / Needs Improvement / Unsatisfactory].

### 7. Distribution
| Recipient | Role |
|-----------|------|
| [Name] | System Owner |
| [Name] | QA Director |
| [Name] | IT Manager |

### Approval
| Role | Name | Signature | Date |
|------|------|-----------|------|
| Lead Auditor | | | |
| QA Director | | | |

Report issued within 15 business days of closing meeting. If err: Delayed beyond 15 days → notify stakeholders + doc reason.

Step 7: Track CAPA + Verify Effectiveness

Each finding requiring CAPA:

## CAPA Tracking
| Finding ID | CAPA ID | Root Cause | Corrective Action | Due Date | Status | Effectiveness Check |
|-----------|---------|------------|-------------------|----------|--------|-------------------|
| F-001 | CAPA-2025-042 | Configuration oversight during upgrade | Enable audit trail, verify all modules | 2025-04-15 | Open | Scheduled 2025-07-15 |
| F-002 | CAPA-2025-043 | Training matrix not updated | Complete training, update tracking | 2025-05-01 | Open | Scheduled 2025-08-01 |

CAPAs assigned, tracked, effectiveness verified per defined timeline. If err: Unresolved CAPAs escalate to QA mgmt + flag in next audit cycle.

Check

  • Audit plan approved + communicated pre-audit
  • Opening + closing meetings doc'd w/ attendance
  • Evidence collected w/ timestamps + source refs
  • Every finding has classification, evidence, reg ref
  • Audit report issued within 15 business days
  • CAPAs assigned w/ due dates for all critical + major findings
  • Prev audit CAPAs verified for closure effectiveness

Traps

  • Scope creep: Expanding scope during exec w/o formal agreement → incomplete coverage + disputes.
  • Opinion-based findings: Findings must ref specific reg req's, not personal preferences.
  • Adversarial tone: Audits = collaborative quality improvement, not interrogations.
  • Ignore positives: Reporting only findings w/o acknowledging good practices undermines trust.
  • No effectiveness check: Closing CAPA w/o verifying fix actually works = recurring regulatory citation.

  • perform-csv-assessment — full CSV lifecycle assessment (URS through validation summary)
  • setup-gxp-r-project — project structure for validated R environments
  • implement-audit-trail — audit trail impl for electronic records
  • write-validation-documentation — IQ/OQ/PQ protocol + report writing
  • security-audit-codebase — security-focused code audit (complementary perspective)

GitHub 저장소

pjt222/agent-almanac
경로: i18n/caveman-ultra/skills/conduct-gxp-audit
0
agentsagentskillsai-assisted-developmentclaude-codeskillsteams

연관 스킬

content-collections

메타

이 스킬은 콘텐츠 콜렉션(Content Collections)을 위한 프로덕션 검증된 설정을 제공합니다. 콘텐츠 콜렉션은 Markdown/MDX 파일을 Zod 검증이 포함된 타입 안전한 데이터 콜렉션으로 변환해주는 TypeScript 최우선 도구입니다. 블로그, 문서 사이트 또는 콘텐츠 중심의 Vite + React 애플리케이션을 구축할 때 타입 안전성과 자동 콘텐츠 검증을 보장하기 위해 사용하세요. Vite 플러그인 구성과 MDX 컴파일부터 배포 최적화 및 스키마 검증에 이르기까지 모든 것을 다룹니다.

스킬 보기

polymarket

메타

이 스킬은 개발자들이 Polymarket 예측 시장 플랫폼을 활용한 애플리케이션을 구축할 수 있도록 지원하며, 거래 및 시장 데이터를 위한 API 통합 기능을 포함합니다. 또한 WebSocket을 통한 실시간 데이터 스트리밍을 제공하여 실시간 거래와 시장 활동을 모니터링할 수 있습니다. 이를 통해 거래 전략을 구현하거나 실시간 시장 업데이트를 처리하는 도구를 생성하는 데 활용할 수 있습니다.

스킬 보기

creating-opencode-plugins

메타

이 스킬은 개발자들이 명령어, 파일, LSP 작업 등 25개 이상의 이벤트 유형에 연결되는 OpenCode 플러그인을 만들 수 있도록 돕습니다. JavaScript/TypeScript 모듈을 위한 플러그인 구조, 이벤트 API 명세, 구현 패턴을 제공합니다. OpenCode AI 어시스턴트의 라이프사이클을 사용자 정의 이벤트 기반 로직으로 가로채거나, 모니터링하거나, 확장해야 할 때 사용하세요.

스킬 보기

sglang

메타

SGLang은 RadixAttention 프리픽스 캐싱을 활용하여 JSON, 정규식, 에이전트 워크플로우를 위한 고속 구조화 생성에 특화된 고성능 LLM 서빙 프레임워크입니다. 특히 반복되는 프리픽스가 있는 작업에서 상당히 빠른 추론 속도를 제공하여 복잡한 구조화 출력 및 다중 턴 대화에 이상적입니다. 제약 디코딩이 필요하거나 광범위한 프리픽스 공유가 있는 애플리케이션을 구축할 때는 vLLM과 같은 대안보다 SGLang을 선택하십시오.

스킬 보기