  {"id":69425,"date":"2023-02-16T00:13:51","date_gmt":"2023-02-15T23:13:51","guid":{"rendered":"https:\/\/www.veeva.com\/eu\/?page_id=69425"},"modified":"2026-02-21T00:07:12","modified_gmt":"2026-02-20T23:07:12","slug":"endo-pharmaceuticals-simplifies-validation-with-a-risk-based-approach","status":"publish","type":"customer-stories","link":"https:\/\/www.veeva.com\/eu\/customer-stories\/endo-pharmaceuticals-simplifies-validation-with-a-risk-based-approach\/","title":{"rendered":"Endo Pharmaceuticals"},"content":{"rendered":"<p>\nEven for biopharmas with strong processes and a quality mindset,<br \/>\nvalidation can be fraught with risk and inefficiency. Scope creep can<br \/>\nhappen when teams don\u2019t establish clear expectations at the beginning<br \/>\nof a new project. Testing and documentation can become cumbersome,<br \/>\ntrapping teams in an endless cycle of validation that stifles new<br \/>\nfeatures and innovation.\n<\/p>\n<p>\nThe IT team at Endo Pharmaceuticals Inc. (Endo) knows this firsthand. After their<br \/>\nfirst ³Ô¹Ï±¬ÁÏ implementation, Gregory Rosen, executive director<br \/>\nof IT, and Joanna Ollendorff, associate director, computer systems<br \/>\nvalidation, saw an opportunity to make the validation process simpler<br \/>\nand more efficient.\n<\/p>\n<p>\n\u201cWe tested everything. Like many other companies, we didn\u2019t have an expert understanding of the system and<br \/>\nwe were duplicating efforts that ³Ô¹Ï±¬ÁÏ had already done,\u201d said Ollendorff. \u201cWe didn\u2019t identify what was Endo-specific configuration and what was base functionality from ³Ô¹Ï±¬ÁÏ.\u201d\n<\/p>\n<p>\nRosen described the level of effort at that time as immense and unsustainable. \u201cEvery time we had a release,<br \/>\nwe\u2019d have to go through an exhaustive exercise to ensure that the release maintained our defined validated state<br \/>\nof the application. Which essentially meant we would never be able to take advantage of the new features ³Ô¹Ï±¬ÁÏ<br \/>\nwas introducing.\u201d\n<\/p>\n<p>\nThe team was determined to make a change.\n<\/p>\n<h2>Establishing a 3-step approach to validation<\/h2>\n<p>\nAt its core, Ollendorff describes Endo\u2019s strategy as a risk-based approach to validation modeled on<br \/>\nGAMP 5. But, some simple changes in mindset have reduced the impact on IT resources and the<br \/>\nbusiness as a whole. Endo\u2019s strategy centers on leveraging the validation work that ³Ô¹Ï±¬ÁÏ already does to<br \/>\nreduce the overall testing burden and speed the adoption of new capabilities.<\/p>\n<p><h3>1. Implementation validation: building trust with the vendor<\/h3>\n<p>\nA thorough quality assessment of the vendor is the first \u2013 and perhaps most critical \u2013 step in the validation<br \/>\nprocess. Defining expectations up front and leveraging ³Ô¹Ï±¬ÁÏ\u2019s documentation helps Endo reduce time<br \/>\nspent and get to value more quickly.\n<\/p>\n<p>\nEndo accomplishes this by using ³Ô¹Ï±¬ÁÏ\u2019s classified levels of validation risk as a guidepost for running test<br \/>\nscripts during implementation. For out-of-the-box or low-risk functionality, no testing may be required at all.<br \/>\nWhen testing is necessary, the Endo team works closely with the ³Ô¹Ï±¬ÁÏ team to execute the test scripts in a<br \/>\nsandbox environment until they are approved. This methodology limits testing to only Endo-specific<br \/>\nconfigurations with a certain risk profile, eliminating redundancy and creating more value for the company.\n<\/p>\n<p>\n\u201cWe are not duplicating efforts, we\u2019re not retesting what ³Ô¹Ï±¬ÁÏ has already tested,\u201d said Ollendorff. \u201cWe\u2019ve<br \/>\nmitigated the risk of doing that: we audited ³Ô¹Ï±¬ÁÏ\u2019s company and quality systems structure, we performed<br \/>\nan IT security assessment, we looked at ³Ô¹Ï±¬ÁÏ\u2019s CSV practices, and through those actions, we were able to<br \/>\nmitigate the risk down to an acceptable level for the business.\u201d\n<\/p>\n<p>\n\u201cIn the world of cloud-based GxP tools there has to be a comfort level that people get to, and it all starts with<br \/>\nthe vendor assessment,\u201d added Rosen. \u201cHaving the mindset to look at ³Ô¹Ï±¬ÁÏ as a GxP supplier has helped,<br \/>\nthat\u2019s the real advancement in our thinking.\u201d\n<\/p>\n<h3>2. Managing updates: classifying the level of impact<\/h3>\n<p>\nOnce implementation is complete, Endo adopted a similar mindset for managing updates: create efficiency<br \/>\nby leveraging what has already been tested. For ³Ô¹Ï±¬ÁÏ\u2019s major releases, which happen three times a year,<br \/>\nEndo takes a three-step approach:\n<\/p>\n<p>\nDuring this process, Endo reviews ³Ô¹Ï±¬ÁÏ\u2019s release impact assessment and compares it to its own<br \/>\nenvironment. While something in a general release might be a high risk for general use, if it\u2019s not a feature<br \/>\nEndo has in its configuration the team rates it as not applicable, or low impact. Doing so saves unnecessary<br \/>\ntesting and validation efforts, and is a key differentiator in Endo\u2019s overall approach.\n<\/p>\n<p>\n\u201cA lot of companies say they take a risk-based approach, but they end up testing everything, even if it\u2019s<br \/>\nlow-risk or has no impact,\u201d said Ollendorff. \u201cIt becomes very cumbersome if you\u2019re not relying on what ³Ô¹Ï±¬ÁÏ<br \/>\nhas already tested, and you could end up rerunning those scripts as part of regression testing every time<br \/>\nthere\u2019s an update.\u201d\n<\/p>\n<h3>3. Making changes: managing configuration enhancements<\/h3>\n<p>\nThe last piece of Endo\u2019s risk-based validation strategy is managing enhancement requests to existing<br \/>\nfunctionality, for example, turning a required field on or off, or something more involved, like adding new<br \/>\npieces of functionality.\n<\/p>\n<p>\nFor these changes, Endo uses a governance process that catalogs and categorizes every enhancement<br \/>\nrequest and assigns each one a score based on the expected level of effort and IT complexity. Low-effort<br \/>\nitems, like cosmetic changes, score one point, medium items such as changing a configuration setting<br \/>\n(already tested by ³Ô¹Ï±¬ÁÏ) score three, and high-effort items, for example, additions that necessitate a test<br \/>\nscript, score seven points. For each bundled release, the Endo team ensures that the total score of requested<br \/>\nenhancements does not exceed 13 points. By using this methodology, Endo can cap the impact on the<br \/>\nvalidation process and manage updates more effectively.\n<\/p>\n<p>\nDuring this phase, the Endo team continues to rely on ³Ô¹Ï±¬ÁÏ\u2019s documentation to assess whether a<br \/>\nnew feature or functionality truly needs to be tested or can simply be verified with existing documentation.<br \/>\n\u201cWe are a lean team,\u201d said Rosen. \u201cWe don\u2019t have a huge department, so we need to work smarter.<br \/>\nThis approach helps us compartmentalize the impact and still be compliant.\u201d\n<\/p>\n<h2>Maintaining compliance while improving speed and value<\/h2>\n<p>\nWith this three-step strategy in place, Endo has been able to achieve gains in both speed and efficiency<br \/>\n\u201cHaving a risk-based approach to validation enabled us to launch three additional Vault products in six months.<br \/>\nBenchmarking revealed that for many companies the same effort would take 36 months, with one of the biggest<br \/>\nfactors being the validation efforts,\u201d said Rosen.\n<\/p>\n<p>\nOllendorff credits a lot of the improvement to how the team changed their mindset from a traditional, on-premise,<br \/>\ntest-everything mentality, to embracing a risk-based approach and leveraging the partnership with ³Ô¹Ï±¬ÁÏ. \u201cAll of<br \/>\nour requirements are being met, it\u2019s just being done in a different way.\u201d said Ollendorff.\n<\/p>\n<p>\nFor Endo, reducing the impact of the validation processes has yielded clear benefits to the business. \u201cWe\u2019re still<br \/>\nmaintaining a high compliance profile and have achieved a significant level of bandwidth giving us the ability to<br \/>\nexplore, adopt, and introduce the new capabilities that ³Ô¹Ï±¬ÁÏ is providing without being in a constant state of<br \/>\nvalidation,\u201d said Rosen.\n<\/p>\n<p>\nLearn more about <a href=\"https:\/\/www.veeva.com\/blog\/best-practices-for-release-management-in-a-multi-vault-environment\/\">best practices for release management<\/a>.\n<\/p>\n<p><footnotes><\/p>\n<hr>\n<p>The opinions stated herein are those of the writers, and not necessarily the opinion of Endo Pharmaceuticals Inc. or its affiliates.<br \/>\n<\/footnotes><\/p>\n","protected":false},"excerpt":{"rendered":"<p>Endo Pharmaceuticals establishes a three-step approach to software validation that improves speed and value while maintaining compliance.<\/p>\n","protected":false},"featured_media":69440,"parent":0,"template":"","product-link-list":[1395,1411,1418,1440,1451],"class_list":["post-69425","customer-stories","type-customer-stories","status-publish","has-post-thumbnail","hentry","product-link-list-veeva-commercial-cloud","product-link-list-veeva-ctms","product-link-list-veeva-etmf","product-link-list-veeva-qualitydocs","product-link-list-veeva-submissions"],"aioseo_notices":[],"_links":{"self":[{"href":"https:\/\/www.veeva.com\/eu\/wp-json\/wp\/v2\/customer-stories\/69425"}],"collection":[{"href":"https:\/\/www.veeva.com\/eu\/wp-json\/wp\/v2\/customer-stories"}],"about":[{"href":"https:\/\/www.veeva.com\/eu\/wp-json\/wp\/v2\/types\/customer-stories"}],"version-history":[{"count":7,"href":"https:\/\/www.veeva.com\/eu\/wp-json\/wp\/v2\/customer-stories\/69425\/revisions"}],"predecessor-version":[{"id":69745,"href":"https:\/\/www.veeva.com\/eu\/wp-json\/wp\/v2\/customer-stories\/69425\/revisions\/69745"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/www.veeva.com\/eu\/wp-json\/wp\/v2\/media\/69440"}],"wp:attachment":[{"href":"https:\/\/www.veeva.com\/eu\/wp-json\/wp\/v2\/media?parent=69425"}],"wp:term":[{"taxonomy":"product-link-list","embeddable":true,"href":"https:\/\/www.veeva.com\/eu\/wp-json\/wp\/v2\/product-link-list?post=69425"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}