Updated eQMS
eQMS IT Requirements: SSO, Backups, Versioning, Confidentiality
IT and quality questions for eQMS buyers: SSO, offline backups, version history, and confidentiality controls that survive review.
By Obsevia editorial · Mid-market chemical, pharma, and medtech compliance operations
eQMS IT requirements that matter in selection are not only CAPA workflow screenshots. Quality engineers and IT share a shortlist: single sign-on (SSO), backups and recoverability, complete version histories, and confidentiality controls that survive both security review and inspection. An IVD or device company that picks on UI polish alone often rediscovers identity gaps, export dead-ends, and weak audit trails during the first real customer audit.
This article is a buyer’s checklist for mid-market life sciences and related regulated manufacturers. It pairs IT non-functionals with quality-system expectations so procurement does not split into two incompatible scorecards.
Why are eQMS IT non-functionals quality issues?
Controlled documents, training records, deviations, CAPAs, and technical file links are GxP-relevant records when used as the system of record. If access control fails, the wrong person changes an SOP. If restore fails, you lose investigation history. If versioning is incomplete, you cannot prove which procedure was effective on the batch date.
US electronic records and signatures expectations are framed in 21 CFR Part 11 (eCFR). Part 11 is not “only e-signatures.” It points to controls around systems that create, modify, maintain, or transmit electronic records—access, audit trails, operational controls, and device/system checks as applicable to your use. Device manufacturers also operate under quality system expectations described in FDA’s Quality System (QS) regulation / medical device GMP.
What SSO and identity controls should an eQMS support?
Single sign-on reduces shared passwords and simplifies offboarding when someone leaves. Ask vendors and implementers:
- Which protocols are supported (SAML, OIDC) and with which IdPs you already run?
- How do roles map from IdP groups to eQMS permissions (QA approver, author, read-only auditor, external supplier)?
- What happens when SSO is down? Is there a break-glass admin path, who controls it, and is it audited?
- Do e-signatures still meet your Part 11 procedure when identity is federated (re-authentication rules, meaning of signature components)?
- Session timeout and concurrent session policies—configurable per risk?
- SCIM or automated provisioning for joiner-mover-leaver, or only manual accounts?
- External users (suppliers, consultants): separate IdP, invited accounts, or VPN-only—and how is their access scoped?
SSO that dumps everyone into a single “user” role is identity theater. Demand a role matrix demo with least privilege for document approval versus view.
Related process context once identity works: eQMS document management from draft to training.
Backups and recoverability
“We back up nightly” is not a recoverability story. Ask:
| Topic | Questions to force a clear answer | | --- | --- | | RPO / RTO | What recovery point and time objectives are contractual vs aspirational? | | Restore tests | How often are restores tested, and can you see evidence? | | Your export | Can you export records and files if you leave the vendor? | | Geo redundancy | Where is data stored, and what happens to a region outage? | | Ransomware posture | Immutable backups, separation of duties, offline or logically air-gapped copies? | | Customer-controlled backup | Can you pull periodic exports into your own retention store? |
Do you need offline backups if the vendor is SaaS?
You need a recovery story you trust: vendor backups plus your export and retention plan. Offline or customer-held copies may be required by IT policy even when the primary system is SaaS. “The cloud is backed up” without export drills is hope, not control.
Test a restore or export before go-live and on a schedule after. A backup never restored is an unverified claim.
What versioning survives inspection?
Version history must be complete for controlled documents and quality events:
- Who changed what, when, and why (change description)
- Prior content or file retrieval for effective-dated comparisons
- Approval records bound to the version, not a floating signature image
- Training effectiveness tied to the version people were trained on—not only “latest”
- Ability to show the effective document at a historical date (batch review, complaint, audit)
Weak systems overwrite blobs, keep only the last PDF, or lose draft history after publish. That breaks investigations that need the procedure in force on a specific day.
Pair versioning discipline with controlled documents vs working copies. Working copies on desktops are how versioning dies in practice even when the eQMS is capable.
Confidentiality and access control
Confidentiality means more than a padlock icon on a marketing page:
- Role-based access to document classes (HR, pricing, full technical files, open CAPAs)
- Encryption in transit and at rest with documented standards
- Admin audit logs for permission changes and exports
- Field- or folder-level restrictions for multi-tenant or multi-site orgs
- Supplier portal isolation so vendor A never sees vendor B
- Data processing terms aligned with your privacy and contract requirements
- Support access — when vendor staff can open your tenant, with whose approval, and logged how?
Technical files, ASMF/DMF-style content, and complaint files are high-value targets. Align eQMS confidentiality with how sensitive your portfolio actually is—not with a generic SMB SaaS default.
For AI features bolted onto eQMS platforms, demand the same access boundaries and audit trails discussed in audit trails for regulatory AI agents in 21 CFR Part 11 contexts.
Integration, time, and environment controls
IT will also ask:
- API and SSO logging for SIEM ingestion
- Time synchronization expectations (accurate timestamps on records)
- Non-production environments for validation and training without cloning production secrets carelessly
- IP allow lists / private connectivity options if policy requires
- Mobile offline behavior—does offline create conflicting versions?
Quality will ask whether integrations to LMS, ERP, or LIMS can create uncontrolled document copies. Integration is not free; every pipe needs an owner.
Validation and shared responsibility
Clarify the shared responsibility model in writing:
- Vendor: product validation evidence, infrastructure controls, change notifications
- Customer: configuration qualification, procedural controls, user training, periodic review
- Both: incident communication, security patches, feature flags that change GxP behavior
Ask how the vendor notifies you of changes that may require retesting. Silent UI changes to approval flows are a quality risk.
Scoring vendors without theater
Weight IT and quality non-functionals explicitly in the RFP:
- SSO + role model demo on your IdP
- Export/restore drill with a sample dataset
- Historical effective-version retrieval for a mock batch date
- Confidentiality demo with two external users isolated
- Audit trail sample for document approve and permission change
- Written RPO/RTO and data residency statements
- Part 11 / Annex 11 (if EU) procedure fit—not only a certificate PDF
Price and CAPA Kanban boards come after those gates for regulated buyers.
Common failure modes in mid-market rollouts
- Shared local accounts “just for the audit week”
- No export test until contract non-renewal
- Versioning on files but not on forms (CAPA text edits without history)
- Over-broad admin roles because role design was deferred
- Supplier users created as full internal authors
- Backup success emails mistaken for restore capability
Fix role design and export drills early; they are cheaper than remediation after inspection.
FAQ
Is Part 11 only about e-signatures?
No. Electronic signatures are one piece. Audit trails, access control, and operational controls in your procedure matter as much as a checkbox on a vendor datasheet. Read the control expectations in 21 CFR Part 11 against your intended use.
Do we need offline backups if the vendor is SaaS?
You need a recovery story you trust—vendor backups plus your export and retention plan. Offline or customer-held copies may be required by IT policy even when the primary system is SaaS. Prove export and restore paths with drills.
How long should we retain eQMS records?
Follow your regulatory retention schedule and product lifecycle (often years beyond last distribution for many device and drug records). The eQMS must support retention without silent deletion; confirm legal hold and archive behavior before go-live.
What is the minimum SSO setup for a small company?
At least: enforce IdP login for internal users, disable shared passwords, map three to five roles with least privilege, document break-glass access, and log admin changes. Complexity can grow with sites and suppliers; emptiness of controls should not.