Regulatory compliance in pharma is often associated with inspections, validation and regulatory submissions. But what if compliance needs to start much earlier, at the point where a product, process, facility or technology is first being designed?
In this conversation, we speak with Dr. Srikanth Reddy Sokkula to explore how regulatory thinking can be embedded across the pharmaceutical lifecycle.
With extensive experience across Regulatory Affairs, GMP, clinical and pharmacovigilance, regulatory submissions, audits and pharmaceutical operations, Dr. Srikanth brings a practical perspective to the discussion.
We talk about the decisions made during facility and technology design that can have long-term compliance implications, why technology transfer needs to transfer process knowledge rather than just documentation, and how manufacturers can balance speed with regulatory expectations.
The conversation also looks at greenfield versus brownfield facilities, data integrity, digital manufacturing, AI, contamination control and the capabilities pharmaceutical organisations will need to remain inspection-ready over the next decade.
Ultimately, the discussion moves beyond the traditional idea of validation as a point-in-time activity and towards a broader question: How do we build and maintain a state of control throughout the entire lifecycle?
We often associate regulatory compliance with inspections or product approvals. In your experience, how early should regulatory thinking begin, and which decisions made during process, facility, or technology design have the greatest long-term impact on compliance?
Regulatory thinking should begin at the concept and target product profile stage, rather than being introduced immediately before qualification, validation, or regulatory submission. From a regulatory-science perspective, compliance is most effective when it is designed into the product and manufacturing system through a science- and risk-based lifecycle approach.
During development, the organisation should establish a clear understanding of the Critical Quality Attributes (CQAs), Critical Material Attributes (CMAs), Critical Process Parameters (CPPs), quality risks, process capability and the overall control strategy. These elements should then drive equipment selection, facility design, automation, analytical strategy, utilities, cleaning processes and validation requirements.
Some of the most consequential decisions are made before the first equipment is installed. These include facility and personnel/material flows, segregation strategy, HVAC zoning and pressure cascades, environmental control, contamination and cross-contamination prevention, equipment geometry and cleanability, single-use versus fixed systems, utility architecture, automation philosophy, and the design of GMP-relevant computerized systems.
From a regulatory perspective, particular attention should be given to decisions that become difficult, costly or disruptive to modify later. Examples include equipment design, facility zoning, process train configuration, sampling locations, automation architecture, data models and system interfaces.
The objective should be to establish Quality by Design (QbD) principles and a scientifically justified control strategy early enough that subsequent qualification and validation demonstrate a system that is already inherently capable of maintaining the required state of control.
In practical terms, I would summarise the principle as: validation should confirm a well-designed system; it should not be used to compensate for inadequate design or insufficient process understanding.
Looking back at regulatory inspections and manufacturing programmes you’ve supported, what are the most common compliance issues that could have been prevented through better planning during development or technology transfer?
A significant proportion of inspection findings can be traced back to weaknesses that existed much earlier in the product or process lifecycle. In my experience, recurring problems typically involve insufficient process understanding, incomplete technology transfer, weak control strategies, inadequate facility or equipment design, ineffective contamination controls, and poorly designed data systems.
One of the most important regulatory expectations is that technology transfer should not be treated as the physical transfer of a batch record, SOPs and equipment specifications. A scientifically robust transfer should transfer the process knowledge and rationale behind the manufacturing process.
The receiving site should understand the relationship between material attributes, process parameters and CQAs; scale-dependent behaviour; equipment differences; mixing, heat-transfer and mass-transfer characteristics; hold times; sampling strategy; analytical variability; known failure modes; process capability; cleaning requirements; and the established control strategy.
For example, simply transferring a validated CPP range from one site to another without demonstrating comparability of equipment capability, scale, mixing dynamics, automation and measurement systems can create significant regulatory risk.
The same principle applies to facility and equipment design. Deficiencies in drainability, equipment cleanability, dead legs, material/personnel flows, HVAC performance, utility quality, or sampling accessibility can create problems that later appear as deviations, environmental excursions, cleaning failures or repeated validation issues.
Data integrity is another area where inadequate planning creates long-term problems. If audit trails, user privileges, interfaces, time synchronisation, electronic signatures and data retention are not designed appropriately from the beginning, organisations may later discover that historical GMP data cannot be reconstructed with sufficient confidence.
Therefore, the objective of technology transfer should be transfer of demonstrated process capability and scientific understanding—not merely transfer of documentation. A successful transfer should enable the receiving site to operate the process in a state of control from the outset rather than learning fundamental process behaviour through commercial deviations.
The pressure to accelerate product development and commercialisation has never been greater. How can manufacturers balance speed with regulatory expectations without creating technical or compliance debt that surfaces later?
The regulatory objective should not be to choose between speed and compliance. The objective is to increase development velocity while maintaining scientific and regulatory integrity.
A useful distinction is between accelerating work and deferring critical work. Acceleration can be achieved through concurrent engineering, risk-based prioritisation, digital workflows, platform technologies, standardised design solutions, integrated project teams and early regulatory engagement. Deferral, on the other hand, occurs when critical process knowledge, validation strategy, data-integrity requirements or quality-risk assessments are postponed with the assumption that they can be reconstructed later.
That approach frequently generates what I would describe as regulatory and technical debt. It may allow a programme to meet an immediate milestone, but the organisation subsequently pays for it through deviations, investigations, CAPAs, requalification, supplemental studies, manufacturing delays or regulatory questions.
A robust programme should establish the target product profile, CQAs, process understanding, quality-risk priorities, control strategy, analytical strategy, validation strategy and data-governance requirements early in development.
The activities can then proceed in parallel. For example, process development, equipment engineering, automation development, analytical method development, facility design and quality-risk management do not necessarily need to occur sequentially if their interfaces and decision criteria are clearly defined.
The most efficient organisations also use risk-based lifecycle gates. High-risk decisions receive deeper technical assessment, while low-risk activities are handled through standardised approaches. This prevents resources from being consumed equally across issues that have very different potential impacts on product quality and patient safety.
From a regulatory perspective, speed is sustainable only when it is achieved through better decision-making, earlier risk identification and reduced rework, rather than by reducing the scientific evidence required to demonstrate control.
Greenfield facilities allow organisations to design compliance into their operations, while brownfield sites must evolve around existing infrastructure. What regulatory and engineering trade-offs deserve the most attention in each scenario?
The fundamental regulatory principle is the same for both environments: the facility must be fit for intended use and capable of consistently maintaining the required state of control. However, the engineering and regulatory risk profile is very different.
Greenfield facilities
For a greenfield facility, the major opportunity is to establish GMP control through design rather than subsequent remediation.
The design should integrate:
- Personnel and material flows
- Segregation and containment strategy
- HVAC zoning and pressure cascades
- Temperature, humidity and environmental control
- Contamination and cross-contamination prevention
- Equipment cleanability and drainability
- Hygienic utility design
- Water and clean-steam systems
- Equipment maintainability
- Sampling accessibility
- Automation and control-system architecture
- Electronic data architecture
- Alarm and interlock philosophy
- Cleaning and disinfection strategy
- Preventive maintenance and calibration requirements
A scientifically sound Contamination Control Strategy (CCS) should connect these individual controls rather than treating them as independent systems.
However, greenfield does not automatically mean compliant. A technically sophisticated facility can still be deficient if the design lacks a scientifically justified control strategy or if the facility’s operating envelope has not been demonstrated.
Brownfield facilities
Brownfield projects are more challenging because the intended GMP process must operate within the constraints of an existing physical and technological environment.
The first step should therefore be a structured gap and risk assessment covering utilities, HVAC, equipment capability, material and personnel flows, cleaning, containment, environmental controls, automation, computerized systems, data integrity, maintenance and qualification status.
The key regulatory question is not simply, “Is the existing equipment qualified?” It is:
“Can the existing system, in its current configuration or after justified modification, consistently perform its intended function and maintain the required state of control?”
Legacy systems can create particular challenges around obsolete PLCs, unsupported software, inadequate audit trails, uncontrolled interfaces, manual data transcription and limited cybersecurity capabilities.
The appropriate strategy is neither automatic acceptance nor automatic replacement. Decisions should be based on documented risk, engineering capability, GMP impact, lifecycle status and objective performance evidence.
In both greenfield and brownfield projects, the final design should be traceable from user requirements through functional/design specifications, risk assessments, commissioning, qualification, process validation and continued verification.
As manufacturing becomes increasingly digital through MES, automation, AI, and electronic records, how should companies rethink their approach to data integrity and inspection readiness from the very beginning of a project?
Data integrity should be regarded as a fundamental component of the pharmaceutical control strategy, not as a documentation issue or simply a computerized-system validation requirement.
The regulatory expectation is fundamentally concerned with whether GMP data remain attributable, legible, contemporaneous, original or true copies, accurate, complete, consistent, enduring and available throughout their required lifecycle.
Therefore, data integrity should be addressed at the architecture stage.
A project should first identify critical GMP data flows from generation through processing, calculation, review, approval, transmission, storage, archival and eventual destruction. Interfaces between instruments, PLCs, SCADA, DCS, historians, MES, LIMS, ERP and other systems require particular attention because data can be altered, lost, duplicated or disconnected from metadata at system boundaries.
Controls should include appropriate:
- User access and role-based privileges
- Segregation of duties
- Audit trails
- Electronic signatures
- Time synchronisation
- Backup and disaster recovery
- Data migration controls
- Interface validation
- Record retention and archival
- Cybersecurity controls
- Periodic review
- Change management
- Business continuity
Inspection readiness should also extend beyond the application itself. Inspectors increasingly need to understand the underlying data lifecycle, including raw data, metadata, audit trails, system configuration, calculations and interfaces.
AI introduces an additional layer of regulatory complexity. Organisations need governance covering data provenance, training-data quality, model validation, intended use, model version control, performance monitoring, bias assessment where relevant, model drift, change control and human oversight.
For me, true digital inspection readiness means that an organisation can take any critical GMP result and reconstruct the complete chain:
Who generated the data → using which instrument/system → under what configuration → from which source data → what processing occurred → who reviewed it → what changes were made → what decision was taken → and whether the complete evidence remains available and trustworthy.
That is the standard that digital pharmaceutical manufacturing should ultimately be designed to meet.
Regulatory compliance is often viewed as the responsibility of Quality or Regulatory Affairs. In practice, how can engineering, manufacturing, validation, and quality functions collaborate more effectively to embed compliance throughout the product lifecycle?
Compliance should be managed as a cross-functional lifecycle responsibility, while maintaining clear functional independence and accountability.
Engineering should ensure that facilities, equipment, utilities and automation are designed to be robust, maintainable, controllable and suitable for their intended GMP application.
Process Development should establish the scientific relationship between CMAs, CPPs and CQAs, define process understanding and develop the appropriate control strategy.
Manufacturing should ensure that the process is operationally executable and that human factors, operator interactions, procedural controls, material handling and routine variability are adequately considered.
Validation should provide objective evidence that facilities, utilities, equipment, processes and computerized systems are fit for intended use and remain in a state of control. This should include appropriate lifecycle approaches rather than treating validation as a one-time event.
Quality should provide independent governance, quality-risk oversight, deviation/CAPA management, change control and assurance that decisions remain consistent with the pharmaceutical quality system.
Regulatory Affairs should ensure alignment with the registered process, regulatory commitments, applicable regional requirements and post-approval change strategy.
The strongest model is therefore not a sequence in which Engineering completes its work, then Validation validates it, and finally Quality approves it. It is an integrated lifecycle in which critical decisions are challenged and agreed at defined stages.
I would establish formal quality and regulatory gates at:
Concept → User Requirements → Process/Facility Design → Design Qualification → Commissioning/Qualification → Process Validation → PPQ/Commercial Operation → Continued Process Verification → Change Management → Lifecycle/Decommissioning.
At each gate, the team should explicitly assess whether the design intent, process understanding, risk controls and objective evidence remain aligned.
This approach also prevents Quality from becoming the final “compliance department” responsible for correcting problems that were actually created during engineering or development.
The most mature organisations therefore make compliance a design attribute and management-system responsibility, rather than an inspection-preparation activity.
Looking ahead, which shifts in global regulatory expectations do you believe pharmaceutical manufacturers are still underestimating, and what capabilities should organisations begin building today to remain inspection-ready over the next decade?
I believe the pharmaceutical industry is moving toward a regulatory model in which inspectors increasingly evaluate the organisation’s ability to maintain sustained control across the entire product and technology lifecycle, rather than simply verifying whether individual validation documents exist.
Several areas deserve particular attention.
1. Lifecycle process validation and continued process verification
Organisations need stronger capabilities in statistical process monitoring, process capability analysis, trend evaluation, multivariate analysis where appropriate, continued process verification and scientifically justified alert/action limits.
The question is increasingly not simply whether PPQ was successful, but whether the process continues to operate predictably over commercial experience.
2. Contamination Control Strategy
For sterile and contamination-sensitive manufacturing, contamination control should become an integrated scientific discipline encompassing facility design, personnel behaviour, HVAC, utilities, cleaning/disinfection, environmental monitoring, material flows, interventions, barrier technologies and microbial control.
The organisation should be able to demonstrate how these controls collectively reduce contamination risk rather than relying on environmental monitoring as the primary evidence of control.
3. Data governance and digital transformation
Companies need enterprise-level governance for GMP data, extending beyond individual CSV/CSA projects. Data ownership, criticality, metadata, interfaces, retention, cybersecurity, archival and lifecycle management need to be addressed systematically.
4. AI and advanced analytics
AI should not be adopted merely as an IT capability. Where AI influences GMP decisions, organisations need a controlled framework for model qualification/validation, intended-use definition, data provenance, change control, performance monitoring and human accountability.
5. Advanced manufacturing
Continuous manufacturing, process analytical technology, real-time monitoring, advanced control systems and other emerging technologies require regulators and manufacturers to evaluate control strategy differently from traditional batch manufacturing.
The industry therefore needs stronger capabilities in process dynamics, real-time release concepts, PAT, multivariate data analysis, automation and control theory.
6. Outsourced and distributed technology ecosystems
As manufacturing becomes more dependent on CMOs/CDMOs, cloud systems, software vendors, contract laboratories and specialised technology providers, companies must maintain adequate supplier qualification, technical agreements, oversight, data governance and knowledge ownership.
Outsourcing an activity does not outsource the marketing authorisation holder’s ultimate responsibility for product quality.
7. Knowledge management and regulatory intelligence
One of the most underestimated capabilities is the ability to preserve and continuously update process knowledge. Organisations should be able to demonstrate why their control strategy remains scientifically justified as equipment, suppliers, processes, analytical methods and manufacturing sites evolve.
Ultimately, the future-ready pharmaceutical organisation will move from a document-centric compliance model to an evidence-based lifecycle control model.
The critical question will increasingly be:
Can the company demonstrate, with reliable scientific and data-driven evidence, that its processes, facilities, equipment, computerized systems and quality systems remain in a validated and controlled state throughout their lifecycle.
About the guest – Dr. Srikanth Reddy Sokkula
A pharmaceutical executive and Regulatory Affairs professional with over 20 years of experience across regulatory strategy, compliance, product development, and international market access.
His expertise includes Regulatory Affairs, GMP audits for APIs and finished products, Pharmacovigilance, Clinical Research, and Product Lifecycle Management, with experience in regulatory submissions and market authorizations across Europe, Australia, Canada, South Africa, Brazil, and emerging markets.
Currently serving as Head of Regulatory Affairs at Jodas Expoium, he leads global regulatory operations and cross-functional teams covering Regulatory Affairs and GMP Compliance, with a focus on regulatory strategy, compliance, risk management, and international expansion.
His technical experience spans Parenteral Preparations, Oral Solid Dosage Forms, and advanced drug delivery systems, including Long-Acting Release injections, suspensions, liposomal, nano, micro, and macro delivery systems.
He is also a regular speaker, moderator, and panelist at pharmaceutical conferences and CPHI events, and contributes to academic development through guest lectures at pharmaceutical institutions.
