Platform

Built for the regulations you answer to.

Labeling is where regulatory exposure concentrates: it is the part of the product a regulator can inspect without opening anything, and the part a recall notice quotes.

The four controls that carry it.

Everything below is a property of the system rather than a procedure you have to remember to follow. That distinction is the whole point of buying a labeling system rather than writing an SOP.

Audit trail on every action.

Every action attributable, timestamped and reconstructable: who did what, when, and to which object. Not a log that can be pruned, but the record an inspector is entitled to see.

Electronic signature where it is required.

Which actions need signing is configuration, not a fixed list. A signature carries the signer, a reason code and a comment, is given with either a password or single sign-on, and stays visible on the record afterwards: evidence rather than an entry in a spreadsheet saying the approval happened.

Change reason captured at the change.

The reason is recorded when the change is made, and every object the change alters is linked to it. Reconstructing intent afterwards from a diff is the thing this removes.

Role-based access control.

Who may design, review, approve and print, enforced by the system. Signing authority is a permission, not a convention.

Approval routed, not chased.

Reviewers are grouped against a change, and the routing for a recurring change type is saved as a template rather than rebuilt each time. Every decision is kept with the change: who approved, who rejected, when, and the reason each gave.

Mapped clause by clause.

The controls are not asserted against Part 11 in general terms. RONOVA's requirements are individually assessed against the specific clauses they bear on: records being retrievable and readable, access being limited to authorised users, the system enforcing the permitted sequence of steps, signatures carrying their signer and meaning, and audit trails being generated by the system rather than kept by hand.

What this is measured against.

Public, checkable regulation rather than product claims. Always read the current text before relying on any of it: these instruments are amended, and this page is not the authority.

  • 21 CFR Part 11: US FDA rules for electronic records and electronic signatures
  • 21 CFR Part 820: the FDA Quality System Regulation, including device labeling controls
  • EU MDR 2017/745 and IVDR 2017/746: labeling, UDI and the technical documentation behind them
  • EU GMP Annex 11: computerised systems in medicinal-product manufacture
  • ANVISA RDC resolutions: Brazilian labeling and registration requirements
  • NMPA requirements: Chinese registration and labeling, including language obligations
  • GAMP 5 second edition: the risk-based approach most quality teams validate against
  • ISO 9001:2015: the standard Innovatum's own quality system is certified to

Why no vendor can sell you compliance.

Any vendor that tells you their software makes you compliant is describing something that is not for sale. 21 CFR Part 11 places obligations on the regulated company, not on a software product: it governs how you use a system to create and keep records. A system can make those obligations achievable or nearly impossible, but it cannot discharge them for you.

What a vendor can honestly supply is three things: controls that satisfy the technical requirements, evidence that the software does what it claims through IQ/OQ/PQ documentation and validation support, and a change process that does not silently invalidate that evidence. Innovatum supplies those three.

What remains yours is the procedural half: who is authorised to approve what, how you train and record training, how you handle deviations, and the periodic review that confirms the system is still doing what you validated it to do. Any vendor claiming otherwise is either being loose with language or has not been through an inspection.

The company behind those three things.

The controls, the validation evidence and the change process above come out of a quality system that an accredited body audits. That certificate covers Innovatum, not RONOVA: no certification of any kind makes a product compliant, which is the whole point of this page.

Questions people ask.

Does RONOVA support electronic signatures under 21 CFR Part 11?

Yes. Electronic signature is part of the control model, bound to the action being signed and to the signer, alongside an immutable audit trail and role-based access control. Which steps in your process require a signature is configuration, because it varies by company and by product class.

Can RONOVA satisfy EU, Brazilian and Chinese requirements as well as US ones?

The same controls (audit trail, electronic signature, change control with reason capture) address the equivalent expectations under EU MDR, ANVISA and NMPA oversight. What differs between those markets is label content rather than control, and content is handled by destination-driven labeling from a single product record rather than by maintaining a separate label set per market.

Can we require a signature on some actions but not others?

Yes. Signing is configured per action rather than applied uniformly, so the actions your procedures treat as significant require a signature and routine ones do not. Where a signature is required you can also require a reason code, a comment, or both, and users sign with either their password or their single sign-on identity.

How are label approvals routed to reviewers?

Reviewers are grouped against the change, and a routing you use repeatedly is saved as a template so a recurring change type does not have to be assembled by hand each time. The outcome is kept with the change rather than in someone's inbox: who approved, who rejected, when, and the reason given.

Who is responsible for compliance, us or Innovatum?

Both, and the split matters. Innovatum is responsible for the software's controls and for the validation evidence that the software does what it claims, including IQ/OQ/PQ documentation and validation support. You remain responsible for the procedural half: authorisation, training, deviation handling and periodic review. No software product can discharge a regulated company's own obligations.

Is Innovatum's quality system certified?

Yes, Innovatum holds ISO 9001:2015 certification covering its software development and support processes, and the certificate itself is published rather than merely claimed. Innovatum is also a member of RAPS, the Regulatory Affairs Professionals Society, and of AIM Global, both of which are independently checkable in those organisations' own supplier directories. Ask for the current certificate with its expiry date for your supplier file.

Cookie preferences