The thesis. Every failed compliance programme in a regulated manufacturer fails the same way: each regime gets its own owner, its own spreadsheet, its own evidence request, and its own calendar. The same system owner is asked for the same user list five times a year in five formats, and quality degrades to whatever gets the auditor out of the room fastest.
The fix is not a single framework. It is a single control substrate — one set of controls, executed once — with an evidence package built to the strictest regime that touches it, and a mapping layer that lets any regime draw the evidence it needs without re-testing.
Build to GxP evidence discipline and SOX, ISO 27001, SOC 2 and GLBA come along free. Build to SOX and retrofit GxP, and you will rebuild. That single sequencing decision is worth more than any tooling choice in this document.
A control regime is defined by its assertion — the statement someone signs. Not by its control list. Two regimes can demand an identical quarterly access review and still be satisfied by completely different evidence, because they are proving different things to different audiences with different consequences for being wrong.
| Regime | Assertion signed | Harm prevented | Enforcer | Evidence bar |
|---|---|---|---|---|
| SOX §404 COSO 2013 / COBIT |
Internal control over financial reporting is effective as of fiscal year-end | Material misstatement of financial statements | External auditor, PCAOB, SEC | Sample-based test of operating effectiveness across the period, rolled forward to year-end |
| GxP 21 CFR 11 / 820→QMSR / Annex 11 / GAMP 5 2e |
Systems are validated for intended use; records are attributable, legible, contemporaneous, original, accurate (ALCOA+) | Patient harm from defective product or unreliable records | FDA (483, Warning Letter, consent decree), Notified Body, PMDA, NMPA | Highest in the stack. Full validation lifecycle documentation plus immutable audit trail. If it is not documented, it did not happen. |
| Product security FD&C §524B, IEC 81001-5-1, AAMI TIR57 |
The device is secure by design and maintainable across the total product lifecycle | Patient harm from an exploited device | FDA premarket review (refuse-to-accept hold), Notified Body under MDR | SBOM, threat model, architecture views, vulnerability management plan, CVD process, postmarket surveillance evidence |
| ISMS ISO 27001, SOC 2, NIST CSF 2.0 |
Stated security commitments are designed and operating effectively | Loss of confidentiality, integrity or availability; loss of customer trust | Certification body; service auditor; increasingly, customer procurement | Certificate plus Statement of Applicability; SOC 2 Type II opinion over a stated period |
| Privacy GDPR Art. 32, HIPAA Security Rule, US state laws |
Appropriate technical and organisational measures protect personal data | Harm to individuals from misuse or exposure of their data | Data protection authorities, HHS OCR, state attorneys general | Records of processing, DPIAs, risk analysis, transfer mechanisms, breach register |
| OT / plant IEC 62443, NIST 800-82r3, NIS2 |
The production environment is segmented, monitored and recoverable | Production stoppage, product quality deviation, safety event | Internally quality and operations; in the EU, NIS2 competent authorities | Zone and conduit model, complete asset inventory, target security level vs achieved security level per zone |
| GLBA 16 CFR 314 Safeguards Rule |
A written, risk-based programme protects customer non-public personal information — continuously | Consumer financial harm | FTC; banking regulators; SEC via Reg S-P | Qualified Individual's annual written report to the board; annual penetration test; semi-annual vulnerability assessment |
Usually not to a device manufacturer directly — but check three places before ruling it out: a captive finance or leasing subsidiary, an equipment financing programme offered to hospital customers, and any patient payment plan administered in-house. In the first two, you are a financial institution. In a partnership model you are typically a service provider under §314.4(f) and inherit the obligations contractually rather than by statute — which means they arrive through the master services agreement, not through your compliance calendar, and are therefore usually missed.
The three properties that drive every downstream design decision
- GxP has the strictest evidence bar. Approver identity, timestamp, meaning of signature, and tamper-evident audit trail are regulatory records in their own right — not artefacts describing a control. Design evidence to this bar and every other regime is satisfied by a subset.
- SOX has a point-in-time assertion; GLBA, GxP and ISMS do not. SOX opines on effectiveness at fiscal year-end. The others require a continuously operating programme with no snapshot to test to. This changes evidence architecture: period samples for SOX, continuous artefacts for everything else.
- Product security is the only regime that can block revenue directly. A §524B deficiency produces a refuse-to-accept hold on a submission. Every other regime here produces a finding, a fine or an opinion — after the fact. Weight your remediation queue accordingly.
Below is the full control substrate for an organisation of this shape. Select one or more regimes to highlight the controls each one claims. The point of the exercise is what you will see immediately: the overlap is near-total, and the differences are almost entirely in evidence and scope, not in the control itself.
No regime selected — showing all 14 controls. Colour blocks on each card show which regimes claim it.
Scope is not a list of systems. It is a list of system-plus-regime pairs, each with a criticality tier. The same MES may be GxP-critical, SOX-relevant through inventory valuation, OT-adjacent through the historian, and out of scope for privacy entirely. One row per pair.
How to run the scoping exercise
- Pull the authoritative system inventory from three sources, not one. The CMDB, the finance application list used for the last SOX walkthrough, and the QA validated-systems register. They will disagree. The delta is your first finding.
- Run the six questions with the owners in the room. Finance answers the SOX question, QA answers the GxP question, product security answers §524B, privacy answers Art. 32, OT engineering answers the zone question, and legal answers GLBA. Do not let IT answer on their behalf — IT does not know which report the controller actually relies on.
- Tier by consequence, not by cost or user count. Tier 1 is anything where failure reaches product, patient, or the ledger. A twelve-user batch release system outranks a two-thousand-user collaboration platform.
- Record the rationale in one sentence per exclusion. "Excluded from SOX: outputs are used for operational reporting only; no interface to ERP; confirmed with Controller, [date]."
- Refresh annually and on trigger. Triggers below.
Assuming SOX scope covers everything. SOX pulls in ERP, consolidation, subledgers. It does not pull in the CRM, the complaint handling system, the LIMS, or the historian — all of which carry heavier obligations under other regimes.
Treating a validated system as automatically SOX-compliant. Validation proves fitness for intended use. It does not test segregation of duties in the financial workflow.
Leaving OT out because "it isn't IT." The historian feeds yield and scrap numbers into inventory valuation. That is a financially relevant data flow with an OT-resident source.
Site-level shadow systems. Every plant has a spreadsheet or an Access database doing something material. Find them during scoping, not during testing.
This is the working table. For each shared control, the middle columns state what each regime demands; the final column states the single design that satisfies all of them. Build the final column.
| Control | SOX wants | GxP wants | ISMS / privacy wants | OT reality | Build this |
|---|---|---|---|---|---|
| User access review | Quarterly, financially relevant apps, evidence of reviewer and action taken | Periodic, all GxP systems, QA approval of the review itself | Annual review of access rights; least privilege demonstrable | Shared HMI accounts; named accounts often technically impossible | Quarterly global process, one workflow. QA co-signs GxP scope. OT shared accounts documented as a compensating control with physical access log and shift roster. |
| Joiner / mover / leaver | Timely deprovisioning; transfers do not accumulate rights | Training completion gates access to GxP systems | Documented provisioning process, revocation SLA | Contractor and vendor remote access dominate the risk | HR-triggered automation with a hard SLA. Training status as a provisioning precondition. Vendor access time-boxed and brokered, never standing. |
| Privileged access | Restricted, monitored; firefighter access reviewed after use | Admin cannot alter records or audit trail without trace | PAM, MFA, session recording for critical systems | Engineering workstations with local admin as standard | PAM with checkout, justification, session capture. Database-level admin separated from application admin. Audit trail write access held by nobody. |
| Change management | Approval, testing, SoD in migration to production | Validation impact assessment; revalidation trigger; CAPA linkage | Documented, risk-assessed change process | Change windows constrained by production schedule and campaign | One CAB, one ticket type. GxP systems get an added impact-assessment gate before approval. OT changes carry a production-window field and a rollback plan. |
| Audit logging | Detective control over privileged activity | The audit trail is itself a regulatory record — cannot be disabled, must be reviewed, retained for the record retention period | Log collection, protection, retention, monitoring | Historian integrity; limited logging capability on legacy PLCs | Design to GxP. Audit trail immutable and independently retained. Review documented per SOP. Legacy OT compensated by network-level capture at the conduit. |
| Backup & restore | Restore testing evidence | Record retention across the full statutory period, often ten years or more | Continuity objectives, RTO/RPO | Recipe and golden-image recovery; plant restart sequence | Common technology, differentiated retention schedules and restore-test evidence per regime. Test restores of GxP records annually with QA witness. |
| Segregation of duties | Prevents fraudulent transaction flows | Prevents self-approval of records and batch release | Least privilege | Operator versus engineer role split | One SoD ruleset with two rationale columns — financial and quality. Enforce in-system, not by policy statement. |
| Third-party oversight | SOC 1 Type II plus mapped complementary user entity controls | Supplier qualification, quality agreement, right to audit | SOC 2 Type II / ISO certificate; DPA and transfer mechanism | Vendor remote access to plant equipment | One TPRM intake, three evidence tracks and one criticality tier. Unmet CUECs raised as findings, not filed. |
| Incident response | Not directly asserted | Deviation and CAPA process; possible MDR reporting | IR plan; GDPR 72-hour notification; SEC 8-K Item 1.05 materiality clock | NIS2 24-hour early warning for in-scope EU sites | Build to the fastest clock in the stack, not the average. One intake, parallel regulatory assessment tracks running from the same triage. |
| Vulnerability management | Only where patching evidences change control | Patch requires impact assessment on validated state | Defined SLAs by severity; annual pen test | Patching often impossible; compensating controls are the answer | Risk-based SLA tiers. Validated systems get an assessment gate. OT gets virtual patching and segmentation with documented residual risk accepted by name. |
Broken ITGCs invalidate reliance on every automated control beneath them. If change management fails, the auditor cannot rely on a single automated calculation, tolerance check, or three-way match in the ERP — and the population reverts to full substantive testing. One ITGC deficiency can convert a clean automated-control strategy into thousands of hours of manual sampling. This is the argument that funds the programme.
The most common measurement error is a single 1–5 score per control. It hides the failure mode that actually hurts you: a control that is beautifully designed and cannot be proven. Score two axes independently.
| Level | Definition | Objective test — no judgement required |
|---|---|---|
| 0 · Absent | No control exists | — |
| 1 · Initial | Performed ad hoc, dependent on an individual | Someone does it; no written procedure exists |
| 2 · Repeatable | Documented, local scope only | An approved SOP exists at one site |
| 3 · Defined | Standardised globally, named owner, applies to all in-scope systems | Global SOP + RACI + scope register entry |
| 4 · Managed | Quantitatively measured with thresholds and escalation | A metric exists with a defined threshold and a named owner of the breach |
| 5 · Optimising | Automated, continuous, self-correcting with drift detection | Tooling enforces the control; exceptions route automatically |
| Level | Test | What an auditor experiences |
|---|---|---|
| 0 | No evidence retained | Finding on the spot |
| 1 | Evidence must be reconstructed on request | Two weeks of scrambling; reconstructed evidence is challenged |
| 2 | Retained per procedure, manual retrieval | Email threads and screenshots; IPE questions follow |
| 3 | Retained in a controlled repository with defined retention | Requests fulfilled in days |
| 4 | Generated as a by-product of the control; system-generated, IPE-validated | Requests fulfilled from the system, not from people |
| 5 | Continuously available, timestamped, tamper-evident | Read-only auditor access; sampling becomes negotiable |
Design 5 / Evidence 2 passes a management review and fails an FDA inspection. Design 2 / Evidence 4 passes SOX and fails ISO 27001 certification. Design 4 / Evidence 4 with a target of 4 is done — stop investing and move the money to the control scoring 2.
Score it here
Set design and evidence levels for the substrate controls. The readout weights by criticality tier — never take a flat average, or a tier-1 MES at 2.0 gets cancelled out by an HR system at 4.5.
Control scores
Readout
Reporting rule
Report the weighted score and the count of tier-1 controls below the floor. The second number is what a board acts on; the first is what makes the deck look tidy. A programme at 3.8 weighted with four tier-1 controls under 3 is in worse shape than one at 3.2 with none.
Setting targets
Do not target 5 everywhere — it is not economically defensible and it signals to auditors that you cannot prioritise. Practical targets for this profile:
- Tier 1 (GxP-critical, financially relevant, device-connected): design 4, evidence 4.
- Tier 2: design 3, evidence 3.
- Tier 3: design 3, evidence 2 — with the honest acknowledgement that this is a conscious risk acceptance, recorded with a name against it.
- Hard floor of 3 on both axes for access, change and audit trail on any system touching product or the ledger, regardless of tier.
| Activity | Owner | J | F | M | A | M | J | J | A | S | O | N | D |
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| Config drift & access monitoring | Security Ops | · | · | · | · | · | · | · | · | · | · | · | · |
| Privileged access recert | IAM + system owner | · | · | · | · | · | · | · | · | · | · | · | · |
| GxP audit trail review | Process owner + QA | · | · | · | · | · | · | · | · | · | · | · | · |
| Standard user access review | System owner, QA co-sign | Q | Q | Q | Q | ||||||||
| Control self-assessment (rotating families) | Site IT lead | Q | Q | Q | Q | ||||||||
| Maturity assessment — enterprise | IT Compliance | A | A | ||||||||||
| Maturity re-assessment — sites below target | IT Compliance | S | |||||||||||
| SOX scoping refresh | Finance + IT | A | |||||||||||
| SOX interim testing | Internal Audit | A | A | A | |||||||||
| SOX roll-forward & year-end | Internal Audit + external | A | A | ||||||||||
| Vulnerability assessment | Security | S | S | ||||||||||
| Penetration test | Security + external | A | |||||||||||
| Periodic review of validated systems | System owner + QA | A | A | A | A | ||||||||
| OT plant assessment — tier 1 sites | OT Security | A | A | ||||||||||
| Third-party SOC 1 / SOC 2 review + CUEC mapping | TPRM | A | A | ||||||||||
| DR / BCP exercise | IT Ops | A | |||||||||||
| Product security postmarket reporting | PSIRT | Q | Q | Q | Q | ||||||||
| Risk assessment refresh (all regimes, harmonised) | Respective owners | A | |||||||||||
| Audit committee reporting | CFO / CISO / CQO | Q | Q | Q | Q |
The two sequencing decisions that make or break the year
- Run the enterprise maturity assessment in Q2, ahead of SOX interim testing in Q3. Remediation needs a full quarter to land and to generate a testable population before the auditor arrives. Assessing in Q4 tells you what you already know and gives you nowhere to put the answer.
- Stagger site assessments regionally; never assess all sites in one quarter. A simultaneous global assessment guarantees shallow evidence, burns out site IT, and produces a scorecard nobody believes. Three regional waves across the year, same instrument, same scorer discipline.
ERP or MES implementation · site acquisition or divestiture · cloud migration of an in-scope system · receipt of a 483 or Warning Letter · identification of a significant deficiency · material change in a critical vendor · entry into a new regulatory jurisdiction · a device recall with a software root cause.
NIS2 requires a 24-hour early warning for in-scope EU sites. GDPR gives 72 hours. The SEC materiality determination must be made without unreasonable delay. FDA MDR timelines run separately. GLBA, where applicable, requires FTC notification within 30 days at 500+ consumers. One intake, one triage, parallel assessment tracks — and the process designed against 24 hours, not against the average of all of them.
Phase 1 · Months 1–4 — Establish
- Build the scope register: one row per system × regime × tier, with rationale for every exclusion.
- Consolidate to a single control set with one control ID per control, mapped outward to COBIT, NIST 800-53 Rev 5, NIST 800-171, ISO 27001 Annex A, CIS v8, IEC 62443 and the SOC 2 trust services criteria. One ID, many mappings — never many IDs for one control.
- Name a single accountable owner per control family and a single evidence owner per system. Two names, not a committee.
- Agree the harmonised risk assessment calendar with Finance, QA, Privacy and Security in one meeting. This is a governance act, not an IT task.
Gate: the scope register is signed by Finance, QA and Security, and no system appears in it without a named owner.
Phase 2 · Months 3–8 — Baseline and evidence
- Run the dual-axis assessment across all sites in three regional waves with one instrument and one calibration session per wave.
- Stand up the evidence repository with retention schedules driven by the longest applicable requirement per record type.
- Remediate IPE first. Every report used in the operation of a control needs documented completeness and accuracy validation, plus parameter capture at run time. This is the highest-volume deficiency area in every programme of this shape.
- Inventory end-user computing. Lock, version, and validate every spreadsheet feeding the close or a quality decision — or eliminate it.
Gate: every tier-1 control has evidence at level 3 or above, and no tier-1 control depends on an unvalidated spreadsheet.
Phase 3 · Months 7–14 — Access, change, OT
- Consolidate identity, deploy PAM for tier-1 systems, run the first two quarterly recertification cycles to completion including remediation of exceptions.
- Move to one CAB and one ticket type with a conditional GxP impact-assessment gate. Enforce SoD in-system with a single ruleset carrying financial and quality rationale columns.
- Complete OT asset inventory per site, define zones and conduits, set target security levels, and segment. Accept residual risk explicitly with a named accepter where patching is impossible.
Gate: deprovisioning SLA met for two consecutive quarters; zero standing vendor access; every tier-1 plant has a documented zone model.
Phase 4 · Months 13–18 — Automate and assure
- Deploy continuous control monitoring where the control is deterministic — configuration, access drift, log integrity, backup success.
- Provide read-only auditor access to the evidence repository. This is the moment sampling becomes negotiable and the annual burden drops.
- Run the external attestation cycle: SOC 2 Type II, ISO 27001 certification or surveillance, SOX opinion, and any regulatory inspection readiness review.
Gate: the weighted maturity score meets target, no tier-1 control sits below the floor, and evidence for any control can be produced in under one business day without a person reconstructing it.
Leading indicators worth tracking
| Metric | Why it leads | Threshold to escalate |
|---|---|---|
| Deprovisioning SLA (termination → access revoked, hours) | Predicts the most common access finding across every regime | Any tier-1 system beyond 24 hours |
| Privileged accounts with a named human owner (%) | Orphaned privilege is where both fraud and audit trail tampering live | Below 100% on tier 1 |
| Emergency changes as % of total changes | A rising rate means the standard process is being bypassed, not that emergencies increased | Above 5% |
| Audit trail review backlog (days) | The GxP finding that turns into a Warning Letter observation | Beyond the SOP interval |
| Controls with system-generated evidence (%) | Direct proxy for next year's audit cost | Below 60% on tier 1 |
| OT asset inventory completeness by site (%) | You cannot segment or patch what is not inventoried | Below 95% at a tier-1 plant |
| Mean time to close audit and inspection observations (days) | Repeat findings are treated far more severely than new ones | Beyond commitment date |
| Unmapped CUECs from critical vendor reports (count) | Inherited deficiencies surface at year-end when nothing can be done | Any, on a critical vendor |
Failure modes, in order of how often they appear
- IPE. Reports used to operate controls, never validated for completeness and accuracy, parameters not captured. Highest-volume deficiency in every programme of this shape.
- End-user computing. Unlocked, unversioned spreadsheets feeding the close or a batch release decision.
- Evidence built to the wrong bar. SOX-grade evidence presented at an FDA inspection. Rework is total, not incremental.
- Scope drift. A cloud migration or ERP module go-live that never re-entered the scope register.
- Segregation of duties enforced by policy rather than by system. A stated rule with technical capability to violate it is not a control.
- Vendor reports filed rather than read. Qualified opinions and unmet CUECs discovered in Q4.
- Flat-averaged maturity scoring. A tidy 3.9 hiding four tier-1 controls at 2.
- Site assessment fatigue. All sites assessed in one quarter, producing a scorecard the sites themselves do not believe and will not act on.
Scope once by system × regime × tier, control once against a single control set, evidence once at the strictest bar that touches the control, assess on two axes weighted by tier, and sequence the calendar so remediation lands before testing rather than after it.