Guest Column | August 6, 2026

In Bioprocessing, Trusted Data Is A Process Variable

By Jason Herche, VP, Digital Validation Solutions, Pinnaql

cybersecurity, AI validation-GettyImages-2209954431

In bioprocessing, we are comfortable talking about critical process parameters, yield, contamination control, and batch variability. We are less likely to talk about data in the same practical way, even though data now influences nearly every release decision, deviation investigation, equipment qualification, and process improvement effort in the plant.

As digital systems become increasingly interconnected, digital validation is no longer just a regulatory requirement. It is the discipline that ensures the systems generating and managing critical GxP data remain accurate, consistent, and trustworthy throughout their life cycle.

A conductivity reading from a water for injection (WFI) loop, an alarm from a bioreactor control system, a dissolved oxygen trend during cell expansion, an audit trail entry showing a configuration change, or a temperature excursion captured in a stability chamber all shape decisions that can affect product quality. When that data is incomplete, poorly contextualized, or difficult to trust, the problem is not administrative. It is operational.

For bioprocess manufacturers, this is becoming one of the defining technical challenges of the current era. The industry has added more automation, more connected platforms, and more digital oversight, but many organizations are still working through the practical question of how to make all of that data consistently reliable.

More Systems, More Interfaces, More Risk

The typical bioprocess environment now includes far more than process equipment and paper records. A single operation may involve programmable logic controller (PLC) or distributed control system (DCS)-based controls, historians, supervisory control and data acquisition (SCADA) platforms, environmental monitoring systems, laboratory information management systems (LIMS), electronic batch record (EBR) platforms, computerized maintenance management system (CMMS) tools, and laboratory instruments with their own local software and user permissions.

On paper, that level of digital maturity looks like progress. In practice, it can create a patchwork of systems that were implemented at different times, by different teams, for different purposes.

Consider a common example in upstream manufacturing. A bioreactor may be operating under an automated control strategy, with process values transferring into a historian while sample results are recorded separately in a laboratory system. The batch record may then reference both sources during review. If timestamps do not align, if user roles are inconsistent between systems, or if one data stream is reviewed while the other is assumed to be correct, the risk is not theoretical. It affects how confidently the batch can be evaluated.

The same is true in laboratories supporting bioprocess operations. A chromatographic assay may depend on instrument software, network storage, manual review steps, and approved methods maintained elsewhere. Even when each component appears controlled on its own, the full life cycle of the data may still contain gaps.

This is where many organizations struggle. The issue is usually not one catastrophic system failure. It is the accumulation of smaller weaknesses across interfaces, user practices, legacy configurations, and incomplete governance.

Digital validation helps organizations identify and control those risks before they become compliance issues by validating not only individual systems but also the interfaces and data flows between them.

Data Integrity Has To Be Engineered

Digital validation provides the framework for demonstrating that these controls continue to function as intended throughout the system life cycle, even as software, integrations, and operational processes evolve.

In regulated environments, data integrity is often discussed through familiar principles like ALCOA+. Those principles remain essential, but they are not enough when treated only as training concepts or documentation expectations.

In my experience, the most sustainable approach is to treat data integrity as something that must be designed into the system. It has to be visible in equipment configuration, access management, validation strategy, review workflows, and change control.

That is especially important in facilities where systems have grown over time. A site may have one set of expectations for newer automation platforms and a completely different reality for older instruments or utilities that were never upgraded with the same level of governance.

A strong example is audit trail configuration. Many teams assume audit trails are either present or absent, but the more important question is whether they are meaningful and routinely reviewed. A system may technically retain user actions, but if entries are too broad, if critical events are not distinguishable, or if reviewers have no defined cadence for review, then the control is weaker than it appears.

Access management is another area where design matters. Shared accounts, excessive administrative privileges, or poorly structured user roles continue to create preventable risk. In a laboratory or manufacturing setting, those weaknesses can complicate investigations and make it harder to establish who did what, when, and why.

In a recent Pinnaql engagement, an enterprise-wide data integrity program covering more than 700 laboratory and manufacturing systems showed just how common these issues can be at scale. Standardizing access controls, audit trail expectations, and governance across those systems improved inspection readiness and created a more sustainable compliance model, not because one new tool solved the problem but because the organization treated data reliability as a system-level issue rather than an isolated quality task.

Validation Needs To Reflect How Systems Actually Work

Validation is still one of the clearest ways to build confidence in GxP systems, but it has to keep pace with how modern bioprocess operations are actually running.

Today's manufacturing and laboratory environments rely on interconnected digital ecosystems where automation platforms, laboratory software, historians, cloud applications, and manufacturing systems continuously exchange information. Digital validation is no longer simply about demonstrating that an individual application performs as intended. It is about validating the integrity of the data flowing between systems and ensuring that information remains accurate, complete, and consistent from creation through archiving.

When those digital connections are properly validated, organizations gain confidence that critical process data can support product release, investigations, trending, and regulatory decision-making. When they are not, even well-designed systems can produce uncertainty that increases compliance risk and slows operations.

For that reason, one of the most valuable starting points is data life cycle mapping. Before teams determine how to validate a system, they need to understand how data is created, processed, transferred, reviewed, retained, and archived across the entire digital ecosystem. That visibility often reveals hidden assumptions and integration risks that traditional validation approaches may overlook.

Risk-based digital validation allows organizations to focus effort where it matters most, prioritizing systems based on patient impact, product quality, and data criticality. The result is more than regulatory compliance. It creates trusted digital systems that deliver reliable data, consistent execution, and greater confidence in every quality and manufacturing decision.

Specific Examples From The Floor

The value of trusted data becomes obvious when we look at day-to-day operations.

One example is environmental control. In a cleanroom or classified manufacturing area, pressure differentials, particle counts, and temperature and humidity readings are often reviewed routinely, but problems arise when sites assume that monitoring data is inherently trustworthy. If a sensor drift issue goes undetected or a calibration status is unclear, trend reports may look normal while the underlying measurement system is compromised. In that case, the weakness is not in the trend itself. It is in the confidence we place in it.

The same principle applies at the laboratory level. At a recent Pinnaql engagement at a biologics development site, an embedded life cycle support model helped manage more than 420 systems, including analytical instruments, chambers, and software platforms. The measurable value came not just from keeping equipment qualified but from standardizing onboarding, change control, requalification, and documentation practices across a very mixed instrument population. That kind of consistency matters because laboratory data often feeds directly into major product and process decisions.

Utilities infrastructure tells a similar story. If a WFI control system is upgraded to improve reliability or address data integrity concerns, the project is not just a controls exercise. It affects qualification, alarm handling, user access, historical records, and how deviations are investigated later. When these upgrades are handled well, the result is not merely compliance on paper. It is a utility system that operators and quality teams can trust during real production conditions.

These examples are not dramatic, but that is the point. In bioprocessing, trusted data is built through hundreds of routine design and maintenance decisions that often go unnoticed until something goes wrong.

Continuous Improvement Has To Include Data Governance

Most life sciences teams are familiar with continuous improvement in manufacturing and quality systems. The same discipline should be applied to data governance.

The plan-do-check-act (PDCA) cycle offers a simple but useful framework here: define the control strategy, implement it, assess whether it is working, and adjust based on evidence. In the context of digital systems, that may mean reviewing audit trail practices, reassessing user roles, identifying recurring documentation gaps, or evaluating whether a review process is actually catching what it was designed to catch.

This is especially important after implementation. Sites often put significant effort into qualification and go-live readiness, then give much less attention to what happens six months later. Over time, staff changes, software patches, workarounds, and process drift can all erode the original control strategy.

The organizations that manage this best usually have a few habits in common. They revisit system risk periodically. They treat deviations as sources of learning, not just events to close. They involve engineering, quality, IT, and users in the same conversation. And they understand that a validated state is something to maintain, not simply something to achieve once.

The Human Factor Is Still Central

There is a tendency to frame digital maturity as a technology issue, but people remain at the center of system reliability.

An operator deciding whether to acknowledge an alarm, a scientist reviewing an integration result, an engineer implementing a control change, or a quality reviewer assessing a trend all influence whether the data is interpreted correctly. Even well-designed systems can fail when workflows are confusing, expectations are vague, or ownership is fragmented.

That is why training needs to go beyond procedural recall. People need to understand why the control exists, what risk it addresses, and what a meaningful exception looks like in practice.

Cross-functional collaboration also matters more than many teams expect. Engineering may understand the system configuration. Quality may understand the compliance expectation. Operations may understand what actually happens on night shift. If those perspectives are not combined, blind spots remain.

Looking Forward

Bioprocessing is moving toward more advanced analytics, more connected manufacturing, and more AI-supported decision making. Those changes will create major opportunities, especially in process monitoring, predictive maintenance, and deviation reduction.

But none of that progress will matter much if the underlying data cannot be trusted.

Before the industry asks systems to do more, it has to make sure the foundation is strong enough to support that next step. That means designing for integrity, applying risk-based digital validation that reflects actual system use, and maintaining controls after implementation, not just during it.

In the end, trusted data is not an IT objective or a compliance slogan. It is a process variable in its own right. It shapes decisions, influences risk, and supports the consistency that bioprocess manufacturing depends on.

As life sciences organizations continue their digital transformation, trusted data will increasingly become a competitive advantage. Digital validation plays a critical role in making that possible by ensuring that the systems generating and managing GxP data remain reliable, compliant, and fit for purpose throughout their life cycle.

When organizations validate their digital ecosystems with the same rigor they apply to their manufacturing processes, they build more than compliance. They create confidence in their data, consistency in their operations, and a stronger foundation for innovation.

About The Author:

Jason Herche is VP of Digital Validation Solutions at Pinnaql. He has more than two decades of experience helping life sciences organizations solve complex engineering, quality, and compliance challenges. A graduate of Purdue University with a bachelor's degree in electrical engineering, he works closely with pharmaceutical and biotechnology companies to develop practical, compliant solutions that improve operational performance and support the successful delivery of therapies to patients.