Electronic Quality Management System for Pharmaceutical Operations
How we built an electronic QMS for PT Otsuka Indonesia's pharmaceutical factory — a learning management system with cryptographic electronic signatures and a suite of quality modules aligned to FDA 21 CFR Part 11.
Complexity Snapshot
About the Client
PT Otsuka Indonesia is a pharmaceutical company operating in Indonesia, with its manufacturing site located in Lawang, Malang, East Java. As part of the global Otsuka Group, the site produces pharmaceutical products under strict Good Manufacturing Practice (GMP) guidelines.
For a pharmaceutical factory, quality is not only operational — it is regulatory. Every procedure, training record, and quality event must be documented, controlled, and auditable. Records and signatures made electronically must meet the same integrity and accountability standards as paper records.
The Operational Challenge
Documenting and training on pharmaceutical procedures had to satisfy both operational needs and regulatory expectations:
- Standard operating procedures (SOPs) and quality documents required structured authoring, version control, and controlled revision.
- Approvals moved through a defined hierarchy — from section head through unit, department, and QA — with no gaps in accountability.
- Electronic records and signatures needed to meet FDA 21 CFR Part 11 requirements: unique signatures, audit trails, and security controls.
- Training had to be assigned based on document roles, completed, and verified — including quiz-based testing where required.
- Quality events such as deviations, complaints, CAPAs, and changes needed controlled workflows with cross-references.
Paper and email-based processes could not provide the control, traceability, and audit readiness the operation required.
Why This Was More Than a Training Portal
e-QMS was not just a way to distribute documents and track who had read them. It had to coordinate a defined approval hierarchy, enforce document and quiz requirements, bind every signature cryptographically to the signed record, and preserve an audit history that could withstand regulatory review.
- 1 Document authoring and revision
- 2 QA review and hierarchical approval
- 3 Release and electronic signing (X.509, signed PDF)
- 4 Training assignment, completion, and quiz verification
- 5 Quality events (CAPA, deviations, complaints, changes) with audit trail
Our Solution
We designed and built e-QMS — an electronic Quality Management System for the factory — centered on a Learning Management System (LMS) with electronic signing, plus a suite of quality modules:
- Document authoring and revision: SOPs and quality documents with structured fields, attachments, version history, and revision control. Releasing a revision deactivates the previous one.
- Controlled approval workflow: Documents move through the approval hierarchy — QA review, section head, unit head, department head, QA manager — with role-based skipping and full progress logging. A document’s lifecycle runs through defined statuses: draft → pending QA → waiting section head → waiting unit head → waiting department head → waiting QA manager → released.
- Electronic signatures (FDA 21 CFR Part 11): Each signer holds an X.509 certificate; signatures are cryptographically bound to the document with a SHA-256 signature hash, and the final PDF is digitally signed with P12 certificates. A public verification page allows signature validation.
- Training assignment and completion: Documents are assigned to employees based on their roles, with completion tracking, deadlines, and quiz-based testing where required. Completion requires downloading the document and passing the quiz; assignment expands role definitions into the concrete employees who must train.
- Quality modules: CAPA, Change Control, Deviation, Complaint, Investigation, Risk Assessment, and Evaluation — each with its own controlled workflow, role separation, and audit trail.
- Tamper-proof audit logging: Every action is recorded in a hash-chained audit log, with write-once triggers and integrity verification.
- Notifications and interconnections: Status changes trigger notifications, and quality records can be linked across modules with follow-ups and a shared timeline.
Quality modules and their workflows
Each quality module defines its own approval chain, so the system controls the exact path a record must follow:
| Module | Workflow statuses |
|---|---|
| CAPA | draft → auditee filling → pending verification → QA approval → open → closed |
| Deviation | draft → pending department approval → pending QA evaluation → pending QA approval → completed |
| Complaint | draft → section approval → unit approval → department approval → subdivision approval → QA approval → completed |
| Investigation | draft → section/unit/department/subdivision approval → QA approval → released/completed |
| Risk Assessment | draft → team review → QA approval → QMS approval → mitigating → released |
| Evaluation | draft → superior approval → department approval → QA verification → QA department approval → completed |
| Change Control | draft with required-document tracking |
Outcomes and Evidence
The system brings pharmaceutical document control and training into one controlled, auditable platform:
| Before | After |
|---|---|
| Procedures and training tracked on paper and email | Document release, training, and signatures managed in one system |
| Approvals coordinated manually through the hierarchy | Approval moved through defined digital stages with progress logging |
| Signatures had no cryptographic binding | Electronic signatures bound to the record and signed PDFs |
| Training completion hard to verify | Assignment, completion, and quiz results tracked per employee |
| Quality events handled in separate workflows | CAPA, deviations, complaints, and changes share one controlled framework |
| History scattered and hard to audit | Every action recorded in a tamper-proof, hash-chained audit log |
Evolution and Partnership
The platform is delivered in phases. The current phase covers the Learning Management System with electronic signing plus the quality modules, and the system is designed as a structured foundation that can support continued development as the factory’s quality processes evolve.
Technology
PHP · MariaDB · Fuwafuwa Framework (F3) · Tailwind CSS · Alpine.js
Interested In Our Services?
Whether you have a question about features, pricing, or anything else of relevance, our team is ready to answer all your questions.
Discuss Your Project