08.09.2026 aktualisiert


100 % verfügbar
Founder & CEO, QA4Tech | AI Governance, CSV, Data Integrity & Vendor Quality in GxP | MBA, CISA
Ludwigsfelde, Deutschland
Weltweit
MBA (GPA 4.0), Illinois Institute of Technology; Engineer's Degree (MSc eq.), Mendeleev UniversityÜber mich
Founder & CEO of QA4Tech: AI, technology and quality advisory, assurance and interim leadership for regulated industries. 25+ years in IT, the last 13 in pharma and clinical research. Formerly Head of Vendor QA at ICON and Technology QA Manager at Parexel. 100+ audits led. MBA, CISA. Berlin area.
Skills
ISO 27001Six SigmaAuditsCloud ComputingSoftware QualityQualitätsauditComplianceDatenvalidierungData GovernanceITILInformation GovernanceAuditing (Informationstechnik)Lean Six SigmaSoftware QualitätssicherungVendor Relationship Management
Independent consultant and CISA-certified auditor. Through QA4Tech, my founder-led firm: AI, technology and quality advisory, assurance and interim leadership for regulated industries.
AI Governance & Assurance
Enterprise AI governance policy and process development using ISO/IEC 42001; AI use-case inventory, intended-use and risk classification; risk-based validation of AI-enabled systems; third-party AI assurance; agentic AI assessment; EU AI Act and EMA/FDA AI expectations. Member of an enterprise AI Screening Committee; conference speaker on validating AI-based systems in clinical trials.
Computer System Validation (CSV) & CSA
CSV with a CSA mindset to GAMP 5 (2nd ed.), EU GMP Annex 11 and 21 CFR Part 11: GxP applicability and validation-approach assessment, SDLC and validation documentation, qualification package review, periodic review programs, gap analysis and risk-based remediation across 100+ GxP systems - DCT, eCOA, EDC, IRT/RTSM, CTMS, eTMF, LIMS, imaging and eSource.
Data Integrity, Electronic Records & Audit Trail Review
Data integrity to ALCOA++, electronic records and signatures, audit trail review (ATR), data migration. Authored an enterprise Data Integrity Policy and led development of an ATR approach in line with the EMA guideline on computerized systems in clinical trials.
Independent Assurance, Audits & Inspections
100+ audits personally planned, led and reported since 2013 - supplier qualification, routine, for-cause, internal, and technology/quality due diligence. Domains: AI-enabled suppliers, CSV, cybersecurity, SDLC, infrastructure, cloud and SaaS, BCP/DR, data integrity. Represented global CROs in FDA, EMA, MHRA, Health Canada, PMDA, Swissmedic, MFDS and HSA inspections.
Vendor & Supplier Quality
Led a Vendor QA department owning qualification and oversight of ~1,500 regulated vendors and 150-300 audits per year with a team of seven: risk-based vendor tiering, oversight plans and governance, quality provisions in vendor MSAs, third-party risk management, quality events, CAPA, requalification. ICH E6(R3) service-provider oversight.
Information Security, Privacy & Technology Risk
ISO 27001 (Certified ISO 27001 Implementer, PwC) and internal ISO 27001 audit programs contributing to certification; SOC 1/SOC 2 attestation review; cloud/SaaS and cybersecurity vendor oversight; privileged access; GDPR in technology and vendor oversight.
Quality Management & Inspection Readiness
ISO 9001-based QMS development (quality manual, policies, SOPs, records); quality investigations, root cause analysis and CAPA; quality risk management (ICH Q9/Q10); audit and inspection readiness, hosting and response management.
Leadership, Transformation & Interim Roles
Agile, LEAN and Six Sigma (Europe-wide LEAN/GDF program at IBM, six countries, ~50 people); M&A integration and separation workstreams; interim and fractional quality/technology leadership and named officer functions.
Sprachen
DeutschverhandlungssicherEnglischMutterspracheRussischMuttersprache
Projekthistorie
Founded and lead QA4Tech, an independent advisory firm for AI, technology and quality in GxP-regulated industries.
Service scope: AI governance and assurance; computerized systems validation and assurance (CSV/CSA); data integrity and electronic records; vendor quality and oversight; QMS, remediation and inspection readiness; audits and independent assurance (supplier qualification, routine, surveillance, for-cause, thematic and internal technology audits); privacy, cybersecurity and technology risk; management and organizational consulting; interim and functional leadership and named officer functions; training, workshops and expert advisory.
Clients addressed: pharmaceutical, biotechnology, medical technology and health technology organizations, CROs, software, cloud and clinical-technology providers, start-ups entering regulated markets, and investors needing technology and quality due diligence.
Applicable criteria: GAMP 5 (2nd ed.), EU GMP Annex 11, 21 CFR Part 11, ALCOA++, ISO 9001, ISO 27001 and ISO/IEC 42001.
Delivery: principal consultant and auditor, personally delivering engagements; remote, on-site and hybrid agreed per engagement.
Completed: designed and implemented the firm's internal QMS in alignment with ISO 9001 - quality manual, quality policies, SOPs and records - signed and effective.
Led the Vendor Quality Assurance department as a second-line manager: owned Vendor QA strategy, policies, procedures and KPIs, managing and developing a team of seven QA professionals.
Developed AI governance policies and processes at enterprise level and within Vendor QA, and implemented risk management practices for AI system validation and oversight. Reviewed AI and technology initiatives as a member of the enterprise AI Screening Committee, including agentic AI solutions; strategic advisor for AI compliance. Led integration of AI technologies into vendor QA processes and delivered AI training.
Owned qualification and quality oversight of approximately 1,500 regulated vendors and the annual vendor audit program of 150-300 audits per year, with risk-based vendor tiering, escalation pathways and executive reporting; qualified and oversaw the third-party auditors executing part of the schedule.
Global process owner for vendor qualification and oversight procedures; owned the quality provisions of vendor Master Service Agreements. Contributed to ICH E6(R3) implementation for sponsor and CRO oversight of service providers.
Escalation point for significant vendor quality events (50-100 per year), driving investigation, CAPA and effectiveness verification. Represented the vendor management process area in sponsor and client audits and regulatory inspections.
QA leadership for technology and information compliance across a global CRO, leading a Technology QA team of four. Oversight portfolio of 100+ GxP computerized systems - clinical platforms (DCT, eCOA, EDC, IRT), CTMS, eTMF and other enterprise GxP systems - plus supporting datacenters, cloud and networks.
Authored and implemented the enterprise Data Integrity Policy and delivered advanced data integrity training. Led development of the audit trail review approach in line with the EMA guideline on computerized systems and electronic data in clinical trials.
Reviewed and approved validation and qualification deliverables for computerized systems and technology changes, including SaaS and cloud solutions (20-30 per year); owned GxP applicability assessments; oversaw the periodic review program; reviewed data migration strategies and verification evidence.
Established an Agile Auditing framework for internal technology audits; personally planned, led and reported 5-10 internal and vendor audits per year across CSV, cybersecurity, infrastructure and cloud (team output 30-50 per year). Defined quality expectations for cloud and SaaS providers, including SOC 1/SOC 2 and ISO 27001 attestation review.
Started the AI advisory track: assessed AI and ML-enabled initiatives and advised on risk, validation and compliance. Subject-matter expert on decentralized clinical trials. Contributed to the post-acquisition integration of PRA Health Sciences.