Control Architecture · Global Medical Device Manufacturer

One control substrate,
seven assertions

SOX, GxP, FDA product security, ISO 27001, privacy, GLBA and OT are not seven programmes. They are seven different things you must be able to prove about the same access reviews, the same change tickets, the same logs. This is how to build the substrate once, evidence it to the highest bar in the stack, and run it on a calendar that survives a global footprint.

SEC registrant FDA-regulated device Multi-site manufacturing EU / APAC presence OT + IT convergence

The thesis. Every failed compliance programme in a regulated manufacturer fails the same way: each regime gets its own owner, its own spreadsheet, its own evidence request, and its own calendar. The same system owner is asked for the same user list five times a year in five formats, and quality degrades to whatever gets the auditor out of the room fastest.

The fix is not a single framework. It is a single control substrate — one set of controls, executed once — with an evidence package built to the strictest regime that touches it, and a mapping layer that lets any regime draw the evidence it needs without re-testing.

Build to GxP evidence discipline and SOX, ISO 27001, SOC 2 and GLBA come along free. Build to SOX and retrofit GxP, and you will rebuild. That single sequencing decision is worth more than any tooling choice in this document.

Sections

A control regime is defined by its assertion — the statement someone signs. Not by its control list. Two regimes can demand an identical quarterly access review and still be satisfied by completely different evidence, because they are proving different things to different audiences with different consequences for being wrong.

Regime comparison — assertion, harm, enforcement, evidence bar
RegimeAssertion signedHarm preventedEnforcerEvidence bar
SOX §404
COSO 2013 / COBIT
Internal control over financial reporting is effective as of fiscal year-end Material misstatement of financial statements External auditor, PCAOB, SEC Sample-based test of operating effectiveness across the period, rolled forward to year-end
GxP
21 CFR 11 / 820→QMSR / Annex 11 / GAMP 5 2e
Systems are validated for intended use; records are attributable, legible, contemporaneous, original, accurate (ALCOA+) Patient harm from defective product or unreliable records FDA (483, Warning Letter, consent decree), Notified Body, PMDA, NMPA Highest in the stack. Full validation lifecycle documentation plus immutable audit trail. If it is not documented, it did not happen.
Product security
FD&C §524B, IEC 81001-5-1, AAMI TIR57
The device is secure by design and maintainable across the total product lifecycle Patient harm from an exploited device FDA premarket review (refuse-to-accept hold), Notified Body under MDR SBOM, threat model, architecture views, vulnerability management plan, CVD process, postmarket surveillance evidence
ISMS
ISO 27001, SOC 2, NIST CSF 2.0
Stated security commitments are designed and operating effectively Loss of confidentiality, integrity or availability; loss of customer trust Certification body; service auditor; increasingly, customer procurement Certificate plus Statement of Applicability; SOC 2 Type II opinion over a stated period
Privacy
GDPR Art. 32, HIPAA Security Rule, US state laws
Appropriate technical and organisational measures protect personal data Harm to individuals from misuse or exposure of their data Data protection authorities, HHS OCR, state attorneys general Records of processing, DPIAs, risk analysis, transfer mechanisms, breach register
OT / plant
IEC 62443, NIST 800-82r3, NIS2
The production environment is segmented, monitored and recoverable Production stoppage, product quality deviation, safety event Internally quality and operations; in the EU, NIS2 competent authorities Zone and conduit model, complete asset inventory, target security level vs achieved security level per zone
GLBA
16 CFR 314 Safeguards Rule
A written, risk-based programme protects customer non-public personal information — continuously Consumer financial harm FTC; banking regulators; SEC via Reg S-P Qualified Individual's annual written report to the board; annual penetration test; semi-annual vulnerability assessment
Does GLBA apply to you?

Usually not to a device manufacturer directly — but check three places before ruling it out: a captive finance or leasing subsidiary, an equipment financing programme offered to hospital customers, and any patient payment plan administered in-house. In the first two, you are a financial institution. In a partnership model you are typically a service provider under §314.4(f) and inherit the obligations contractually rather than by statute — which means they arrive through the master services agreement, not through your compliance calendar, and are therefore usually missed.

The three properties that drive every downstream design decision

  1. GxP has the strictest evidence bar. Approver identity, timestamp, meaning of signature, and tamper-evident audit trail are regulatory records in their own right — not artefacts describing a control. Design evidence to this bar and every other regime is satisfied by a subset.
  2. SOX has a point-in-time assertion; GLBA, GxP and ISMS do not. SOX opines on effectiveness at fiscal year-end. The others require a continuously operating programme with no snapshot to test to. This changes evidence architecture: period samples for SOX, continuous artefacts for everything else.
  3. Product security is the only regime that can block revenue directly. A §524B deficiency produces a refuse-to-accept hold on a submission. Every other regime here produces a finding, a fine or an opinion — after the fact. Weight your remediation queue accordingly.

Below is the full control substrate for an organisation of this shape. Select one or more regimes to highlight the controls each one claims. The point of the exercise is what you will see immediately: the overlap is near-total, and the differences are almost entirely in evidence and scope, not in the control itself.

No regime selected — showing all 14 controls. Colour blocks on each card show which regimes claim it.

ASSERTION LAYER — SEVEN SIGNATURES, SEVEN AUDIENCES SOX §404ICFR effective GxPvalidated · ALCOA+ §524Bsecure by design ISO 27001commitments met PrivacyArt. 32 measures IEC 62443SL-A ≥ SL-T GLBAwritten programme CONTROL SUBSTRATE — EXECUTED ONCE Identity & access Change control Logging & audit trail Backup & recovery Third-party oversight Segregation of duties Encryption Vulnerability mgmt Incident response Asset inventory Segmentation Training & awareness EVIDENCE LAYER — BUILT TO THE HIGHEST BAR THAT TOUCHES THE CONTROL Approver identity · timestamp · meaning of signature · tamper-evident trail · defined retention · system-generated wherever possible
Read it top-down for scoping, bottom-up for building. Seven assertions draw from one substrate. The substrate draws from one evidence layer. If the evidence layer is built to GxP discipline, no regime above it needs a separate evidence pipeline — only a mapping and a scope filter.

Scope is not a list of systems. It is a list of system-plus-regime pairs, each with a criticality tier. The same MES may be GxP-critical, SOX-relevant through inventory valuation, OT-adjacent through the historian, and out of scope for privacy entirely. One row per pair.

System enters the estate Six questions, asked in this order SOX Feeds, calculates orstores data that hitsthe general ledger? GxP Creates or holds apredicate-rule record,or controls product? Product sec. Ships in, builds, orsigns the devicesoftware? Privacy Holds personal data,PHI, or clinicalsubject data? OT Sits in a plant zoneor connects to onethrough a conduit? GLBA Holds NPI from afinancing, leasing orpayment programme? Assign criticality tier: 1 (product / ledger / patient) · 2 (supporting) · 3 (peripheral) One row per system × regime × tier — this register is the programme
Answer all six every time, even when the answer is obviously no. The register of explicit "no" answers is what defends your scope when an auditor asks why a system was excluded. Undocumented exclusion is indistinguishable from oversight.

How to run the scoping exercise

  1. Pull the authoritative system inventory from three sources, not one. The CMDB, the finance application list used for the last SOX walkthrough, and the QA validated-systems register. They will disagree. The delta is your first finding.
  2. Run the six questions with the owners in the room. Finance answers the SOX question, QA answers the GxP question, product security answers §524B, privacy answers Art. 32, OT engineering answers the zone question, and legal answers GLBA. Do not let IT answer on their behalf — IT does not know which report the controller actually relies on.
  3. Tier by consequence, not by cost or user count. Tier 1 is anything where failure reaches product, patient, or the ledger. A twelve-user batch release system outranks a two-thousand-user collaboration platform.
  4. Record the rationale in one sentence per exclusion. "Excluded from SOX: outputs are used for operational reporting only; no interface to ERP; confirmed with Controller, [date]."
  5. Refresh annually and on trigger. Triggers below.
Scoping traps specific to this profile

Assuming SOX scope covers everything. SOX pulls in ERP, consolidation, subledgers. It does not pull in the CRM, the complaint handling system, the LIMS, or the historian — all of which carry heavier obligations under other regimes.

Treating a validated system as automatically SOX-compliant. Validation proves fitness for intended use. It does not test segregation of duties in the financial workflow.

Leaving OT out because "it isn't IT." The historian feeds yield and scrap numbers into inventory valuation. That is a financially relevant data flow with an OT-resident source.

Site-level shadow systems. Every plant has a spreadsheet or an Access database doing something material. Find them during scoping, not during testing.

This is the working table. For each shared control, the middle columns state what each regime demands; the final column states the single design that satisfies all of them. Build the final column.

Reconciliation — one control, multiple demands, one design
ControlSOX wantsGxP wantsISMS / privacy wantsOT realityBuild this
User access review Quarterly, financially relevant apps, evidence of reviewer and action taken Periodic, all GxP systems, QA approval of the review itself Annual review of access rights; least privilege demonstrable Shared HMI accounts; named accounts often technically impossible Quarterly global process, one workflow. QA co-signs GxP scope. OT shared accounts documented as a compensating control with physical access log and shift roster.
Joiner / mover / leaver Timely deprovisioning; transfers do not accumulate rights Training completion gates access to GxP systems Documented provisioning process, revocation SLA Contractor and vendor remote access dominate the risk HR-triggered automation with a hard SLA. Training status as a provisioning precondition. Vendor access time-boxed and brokered, never standing.
Privileged access Restricted, monitored; firefighter access reviewed after use Admin cannot alter records or audit trail without trace PAM, MFA, session recording for critical systems Engineering workstations with local admin as standard PAM with checkout, justification, session capture. Database-level admin separated from application admin. Audit trail write access held by nobody.
Change management Approval, testing, SoD in migration to production Validation impact assessment; revalidation trigger; CAPA linkage Documented, risk-assessed change process Change windows constrained by production schedule and campaign One CAB, one ticket type. GxP systems get an added impact-assessment gate before approval. OT changes carry a production-window field and a rollback plan.
Audit logging Detective control over privileged activity The audit trail is itself a regulatory record — cannot be disabled, must be reviewed, retained for the record retention period Log collection, protection, retention, monitoring Historian integrity; limited logging capability on legacy PLCs Design to GxP. Audit trail immutable and independently retained. Review documented per SOP. Legacy OT compensated by network-level capture at the conduit.
Backup & restore Restore testing evidence Record retention across the full statutory period, often ten years or more Continuity objectives, RTO/RPO Recipe and golden-image recovery; plant restart sequence Common technology, differentiated retention schedules and restore-test evidence per regime. Test restores of GxP records annually with QA witness.
Segregation of duties Prevents fraudulent transaction flows Prevents self-approval of records and batch release Least privilege Operator versus engineer role split One SoD ruleset with two rationale columns — financial and quality. Enforce in-system, not by policy statement.
Third-party oversight SOC 1 Type II plus mapped complementary user entity controls Supplier qualification, quality agreement, right to audit SOC 2 Type II / ISO certificate; DPA and transfer mechanism Vendor remote access to plant equipment One TPRM intake, three evidence tracks and one criticality tier. Unmet CUECs raised as findings, not filed.
Incident response Not directly asserted Deviation and CAPA process; possible MDR reporting IR plan; GDPR 72-hour notification; SEC 8-K Item 1.05 materiality clock NIS2 24-hour early warning for in-scope EU sites Build to the fastest clock in the stack, not the average. One intake, parallel regulatory assessment tracks running from the same triage.
Vulnerability management Only where patching evidences change control Patch requires impact assessment on validated state Defined SLAs by severity; annual pen test Patching often impossible; compensating controls are the answer Risk-based SLA tiers. Validated systems get an assessment gate. OT gets virtual patching and segmentation with documented residual risk accepted by name.
The dependency nobody diagrams

Broken ITGCs invalidate reliance on every automated control beneath them. If change management fails, the auditor cannot rely on a single automated calculation, tolerance check, or three-way match in the ERP — and the population reverts to full substantive testing. One ITGC deficiency can convert a clean automated-control strategy into thousands of hours of manual sampling. This is the argument that funds the programme.

The most common measurement error is a single 1–5 score per control. It hides the failure mode that actually hurts you: a control that is beautifully designed and cannot be proven. Score two axes independently.

Axis 1 — design maturity
LevelDefinitionObjective test — no judgement required
0 · AbsentNo control exists
1 · InitialPerformed ad hoc, dependent on an individualSomeone does it; no written procedure exists
2 · RepeatableDocumented, local scope onlyAn approved SOP exists at one site
3 · DefinedStandardised globally, named owner, applies to all in-scope systemsGlobal SOP + RACI + scope register entry
4 · ManagedQuantitatively measured with thresholds and escalationA metric exists with a defined threshold and a named owner of the breach
5 · OptimisingAutomated, continuous, self-correcting with drift detectionTooling enforces the control; exceptions route automatically
Axis 2 — evidence maturity: can it be proven without a fire drill?
LevelTestWhat an auditor experiences
0No evidence retainedFinding on the spot
1Evidence must be reconstructed on requestTwo weeks of scrambling; reconstructed evidence is challenged
2Retained per procedure, manual retrievalEmail threads and screenshots; IPE questions follow
3Retained in a controlled repository with defined retentionRequests fulfilled in days
4Generated as a by-product of the control; system-generated, IPE-validatedRequests fulfilled from the system, not from people
5Continuously available, timestamped, tamper-evidentRead-only auditor access; sampling becomes negotiable
How to read the pair

Design 5 / Evidence 2 passes a management review and fails an FDA inspection. Design 2 / Evidence 4 passes SOX and fails ISO 27001 certification. Design 4 / Evidence 4 with a target of 4 is done — stop investing and move the money to the control scoring 2.

Score it here

Set design and evidence levels for the substrate controls. The readout weights by criticality tier — never take a flat average, or a tier-1 MES at 2.0 gets cancelled out by an HR system at 4.5.

Control scores

Control & tier weightDesignEvid.

Readout

Weighted designtarget 4.0 for tier 1
Weighted evidencetarget 4.0 for tier 1
Provability gapdesign minus evidence
Below floorcontrols scoring under 3
Set scores to see the readout.

Reporting rule

Report the weighted score and the count of tier-1 controls below the floor. The second number is what a board acts on; the first is what makes the deck look tidy. A programme at 3.8 weighted with four tier-1 controls under 3 is in worse shape than one at 3.2 with none.

Setting targets

Do not target 5 everywhere — it is not economically defensible and it signals to auditors that you cannot prioritise. Practical targets for this profile:

  • Tier 1 (GxP-critical, financially relevant, device-connected): design 4, evidence 4.
  • Tier 2: design 3, evidence 3.
  • Tier 3: design 3, evidence 2 — with the honest acknowledgement that this is a conscious risk acceptance, recorded with a name against it.
  • Hard floor of 3 on both axes for access, change and audit trail on any system touching product or the ledger, regardless of tier.
C Continuous / monthly Q Quarterly S Semi-annual A Annual
Annual operating calendar — assumes a December fiscal year-end
ActivityOwner JFMAMJ JASOND
Config drift & access monitoringSecurity Ops ············
Privileged access recertIAM + system owner ············
GxP audit trail reviewProcess owner + QA ············
Standard user access reviewSystem owner, QA co-sign QQQQ
Control self-assessment (rotating families)Site IT lead QQQQ
Maturity assessment — enterpriseIT Compliance AA
Maturity re-assessment — sites below targetIT Compliance S
SOX scoping refreshFinance + IT A
SOX interim testingInternal Audit AAA
SOX roll-forward & year-endInternal Audit + external AA
Vulnerability assessmentSecurity SS
Penetration testSecurity + external A
Periodic review of validated systemsSystem owner + QA AAAA
OT plant assessment — tier 1 sitesOT Security AA
Third-party SOC 1 / SOC 2 review + CUEC mappingTPRM AA
DR / BCP exerciseIT Ops A
Product security postmarket reportingPSIRT QQQQ
Risk assessment refresh (all regimes, harmonised)Respective owners A
Audit committee reportingCFO / CISO / CQO QQQQ

The two sequencing decisions that make or break the year

  1. Run the enterprise maturity assessment in Q2, ahead of SOX interim testing in Q3. Remediation needs a full quarter to land and to generate a testable population before the auditor arrives. Assessing in Q4 tells you what you already know and gives you nowhere to put the answer.
  2. Stagger site assessments regionally; never assess all sites in one quarter. A simultaneous global assessment guarantees shallow evidence, burns out site IT, and produces a scorecard nobody believes. Three regional waves across the year, same instrument, same scorer discipline.
Event triggers that override the calendar

ERP or MES implementation · site acquisition or divestiture · cloud migration of an in-scope system · receipt of a 483 or Warning Letter · identification of a significant deficiency · material change in a critical vendor · entry into a new regulatory jurisdiction · a device recall with a software root cause.

Build the incident clock to the fastest hand

NIS2 requires a 24-hour early warning for in-scope EU sites. GDPR gives 72 hours. The SEC materiality determination must be made without unreasonable delay. FDA MDR timelines run separately. GLBA, where applicable, requires FTC notification within 30 days at 500+ consumers. One intake, one triage, parallel assessment tracks — and the process designed against 24 hours, not against the average of all of them.

Q1Q2Q3 Q4Q5Q6 Establish Scope register · unified control set · RACI Baseline Dual-axis maturity assessment, all sites Evidence Evidence layer to GxP bar · IPE remediation · repository Access IAM consolidation · PAM · quarterly recert live Change Single CAB · GxP impact gate · SoD ruleset in-system OT Asset inventory · zone & conduit model · segmentation Automate Continuous control monitoring · auditor read-only access Assure External attestation cycle
Evidence before automation, always. Automating a control whose evidence is not yet trustworthy produces trustworthy-looking untrustworthy evidence at scale — the single most expensive failure mode in this programme.

Phase 1 · Months 1–4 — Establish

  • Build the scope register: one row per system × regime × tier, with rationale for every exclusion.
  • Consolidate to a single control set with one control ID per control, mapped outward to COBIT, NIST 800-53 Rev 5, NIST 800-171, ISO 27001 Annex A, CIS v8, IEC 62443 and the SOC 2 trust services criteria. One ID, many mappings — never many IDs for one control.
  • Name a single accountable owner per control family and a single evidence owner per system. Two names, not a committee.
  • Agree the harmonised risk assessment calendar with Finance, QA, Privacy and Security in one meeting. This is a governance act, not an IT task.

Gate: the scope register is signed by Finance, QA and Security, and no system appears in it without a named owner.

Phase 2 · Months 3–8 — Baseline and evidence

  • Run the dual-axis assessment across all sites in three regional waves with one instrument and one calibration session per wave.
  • Stand up the evidence repository with retention schedules driven by the longest applicable requirement per record type.
  • Remediate IPE first. Every report used in the operation of a control needs documented completeness and accuracy validation, plus parameter capture at run time. This is the highest-volume deficiency area in every programme of this shape.
  • Inventory end-user computing. Lock, version, and validate every spreadsheet feeding the close or a quality decision — or eliminate it.

Gate: every tier-1 control has evidence at level 3 or above, and no tier-1 control depends on an unvalidated spreadsheet.

Phase 3 · Months 7–14 — Access, change, OT

  • Consolidate identity, deploy PAM for tier-1 systems, run the first two quarterly recertification cycles to completion including remediation of exceptions.
  • Move to one CAB and one ticket type with a conditional GxP impact-assessment gate. Enforce SoD in-system with a single ruleset carrying financial and quality rationale columns.
  • Complete OT asset inventory per site, define zones and conduits, set target security levels, and segment. Accept residual risk explicitly with a named accepter where patching is impossible.

Gate: deprovisioning SLA met for two consecutive quarters; zero standing vendor access; every tier-1 plant has a documented zone model.

Phase 4 · Months 13–18 — Automate and assure

  • Deploy continuous control monitoring where the control is deterministic — configuration, access drift, log integrity, backup success.
  • Provide read-only auditor access to the evidence repository. This is the moment sampling becomes negotiable and the annual burden drops.
  • Run the external attestation cycle: SOC 2 Type II, ISO 27001 certification or surveillance, SOX opinion, and any regulatory inspection readiness review.

Gate: the weighted maturity score meets target, no tier-1 control sits below the floor, and evidence for any control can be produced in under one business day without a person reconstructing it.

Leading indicators worth tracking

Metric set — leading, not lagging
MetricWhy it leadsThreshold to escalate
Deprovisioning SLA (termination → access revoked, hours)Predicts the most common access finding across every regimeAny tier-1 system beyond 24 hours
Privileged accounts with a named human owner (%)Orphaned privilege is where both fraud and audit trail tampering liveBelow 100% on tier 1
Emergency changes as % of total changesA rising rate means the standard process is being bypassed, not that emergencies increasedAbove 5%
Audit trail review backlog (days)The GxP finding that turns into a Warning Letter observationBeyond the SOP interval
Controls with system-generated evidence (%)Direct proxy for next year's audit costBelow 60% on tier 1
OT asset inventory completeness by site (%)You cannot segment or patch what is not inventoriedBelow 95% at a tier-1 plant
Mean time to close audit and inspection observations (days)Repeat findings are treated far more severely than new onesBeyond commitment date
Unmapped CUECs from critical vendor reports (count)Inherited deficiencies surface at year-end when nothing can be doneAny, on a critical vendor

Failure modes, in order of how often they appear

  1. IPE. Reports used to operate controls, never validated for completeness and accuracy, parameters not captured. Highest-volume deficiency in every programme of this shape.
  2. End-user computing. Unlocked, unversioned spreadsheets feeding the close or a batch release decision.
  3. Evidence built to the wrong bar. SOX-grade evidence presented at an FDA inspection. Rework is total, not incremental.
  4. Scope drift. A cloud migration or ERP module go-live that never re-entered the scope register.
  5. Segregation of duties enforced by policy rather than by system. A stated rule with technical capability to violate it is not a control.
  6. Vendor reports filed rather than read. Qualified opinions and unmet CUECs discovered in Q4.
  7. Flat-averaged maturity scoring. A tidy 3.9 hiding four tier-1 controls at 2.
  8. Site assessment fatigue. All sites assessed in one quarter, producing a scorecard the sites themselves do not believe and will not act on.
The one-sentence version

Scope once by system × regime × tier, control once against a single control set, evidence once at the strictest bar that touches the control, assess on two axes weighted by tier, and sequence the calendar so remediation lands before testing rather than after it.