[{"data":1,"prerenderedAt":401},["ShallowReactive",2],{"blog-posts":3},[4],{"id":5,"title":6,"author":7,"body":8,"date":388,"description":389,"extension":390,"image":391,"meta":392,"navigation":393,"path":394,"seo":395,"stem":396,"tags":397,"__hash__":400},"blog\u002Fblog\u002Fbolted-on-compliance.md","Why Bolted-On Compliance Fails: A 21 CFR 820 Teardown","WELR Team",{"type":9,"value":10,"toc":364},"minimark",[11,15,18,21,24,29,32,35,48,55,58,60,64,67,70,87,90,92,96,101,104,122,126,129,132,138,142,145,159,162,164,168,172,175,186,190,193,204,210,213,215,219,223,226,237,240,244,247,258,269,271,275,281,284,287,289,293,296,299,325,327,331,337,343,346,349,351,355,358,361],[12,13,14],"p",{},"I spent years as a field service engineer on regulated medical imaging equipment. I have been on both sides of the audit table: the technician who had to reconstruct what happened six months ago from a PDF attachment and a handwritten note, and the engineer trying to convince a Quality auditor that yes, this procedure was actually followed, step by step, in the correct order.",[12,16,17],{},"The documentation existed. The intent was there. But the system could not prove it — because the system was not designed to enforce it. It was designed to store it.",[12,19,20],{},"That distinction is exactly where audit findings occur.",[22,23],"hr",{},[25,26,28],"h2",{"id":27},"the-core-problem","The Core Problem",[12,30,31],{},"Most service platforms claim to be \"compliant\" with 21 CFR Part 820.",[12,33,34],{},"What they actually mean is:",[36,37,38,42,45],"ul",{},[39,40,41],"li",{},"They can store documentation",[39,43,44],{},"They can attach PDFs to work orders",[39,46,47],{},"They can log that something happened",[12,49,50,51],{},"What they cannot do is enforce ",[52,53,54],"strong",{},"how work is executed, in what order, by whom, and under what constraints.",[12,56,57],{},"That gap is where exposure lives.",[22,59],{},[25,61,63],{"id":62},"what-21-cfr-820-actually-requires-in-practice","What 21 CFR 820 Actually Requires (In Practice)",[12,65,66],{},"At a system level, compliance is not about records — it is about controlled execution.",[12,68,69],{},"In practice, that means:",[36,71,72,75,78,81,84],{},[39,73,74],{},"Procedures must be followed exactly as defined",[39,76,77],{},"Steps must be completed in sequence",[39,79,80],{},"Critical actions must require verified approvals",[39,82,83],{},"Records must be attributable, contemporaneous, and immutable",[39,85,86],{},"Deviations must be detectable and reviewable",[12,88,89],{},"Most systems fail here because they treat procedures as documents, not executable systems.",[22,91],{},[25,93,95],{"id":94},"teardown-1-the-pdf-as-procedure-model","Teardown #1: The \"PDF-as-Procedure\" Model",[97,98,100],"h3",{"id":99},"how-legacy-systems-work","How Legacy Systems Work",[12,102,103],{},"Platforms like ServiceMax or Fiix typically structure work like this:",[105,106,107,110,113,116,119],"ol",{},[39,108,109],{},"Work Order created",[39,111,112],{},"PDF manual attached",[39,114,115],{},"Technician opens PDF",[39,117,118],{},"Technician performs steps manually",[39,120,121],{},"Technician marks work order \"complete\"",[97,123,125],{"id":124},"where-this-fails","Where This Fails",[12,127,128],{},"Consider a concrete scenario: a technician is performing a high-voltage subsystem service on an MRI linac. Step 14 requires measuring and logging the output voltage at three specific test points before proceeding. The PDF is open on a tablet in airplane mode. The measurement takes four minutes and requires moving a probe between cabinet sections. Under time pressure — a delayed flight, a hospital schedule, a system that needs to be back online for afternoon treatments — the technician skips step 14 and marks the procedure complete.",[12,130,131],{},"The system records: procedure completed, technician ID, timestamp. What it does not record: that step 14 was skipped, that no measurement was taken, that the safety constraint was bypassed.",[12,133,134,135],{},"From an audit perspective, ",[52,136,137],{},"the system can prove that a document existed — but not that it was followed.",[97,139,141],{"id":140},"the-audit-reality","The Audit Reality",[12,143,144],{},"The system has no visibility into execution:",[36,146,147,150,153,156],{},[39,148,149],{},"Did the technician skip steps?",[39,151,152],{},"Were steps performed out of order?",[39,154,155],{},"Were required measurements actually taken?",[39,157,158],{},"Was the correct revision of the procedure used?",[12,160,161],{},"Every one of these is an audit question. None of them has a defensible answer in a PDF-as-procedure model.",[22,163],{},[25,165,167],{"id":166},"teardown-2-the-self-approval-loophole","Teardown #2: The Self-Approval Loophole",[97,169,171],{"id":170},"what-happens-in-practice","What Happens in Practice",[12,173,174],{},"In many CMMS platforms:",[105,176,177,180,183],{},[39,178,179],{},"Technician completes work",[39,181,182],{},"Technician checks a box: \"Verified\"",[39,184,185],{},"Technician closes the work order",[97,187,189],{"id":188},"why-this-is-a-problem","Why This Is a Problem",[12,191,192],{},"This creates a hidden violation:",[36,194,195,198,201],{},[39,196,197],{},"No enforced separation of duties",[39,199,200],{},"No independent verification",[39,202,203],{},"No structural prevention of self-approval",[12,205,206,207],{},"Even if SOPs say otherwise, the system ",[52,208,209],{},"does not prevent the behavior — it merely hopes users comply.",[12,211,212],{},"That is not compliance. That is policy without enforcement.",[22,214],{},[25,216,218],{"id":217},"teardown-3-after-the-fact-audit-trails","Teardown #3: \"After-the-Fact\" Audit Trails",[97,220,222],{"id":221},"the-illusion","The Illusion",[12,224,225],{},"Most systems provide:",[36,227,228,231,234],{},[39,229,230],{},"Timestamps",[39,232,233],{},"Activity logs",[39,235,236],{},"Edit histories",[12,238,239],{},"This creates the impression of traceability.",[97,241,243],{"id":242},"the-reality","The Reality",[12,245,246],{},"These logs are:",[36,248,249,252,255],{},[39,250,251],{},"Not tied to step-level execution",[39,253,254],{},"Not constrained by workflow logic",[39,256,257],{},"Often editable or reconstructable",[12,259,260,261,265,266],{},"So while you can see that ",[262,263,264],"em",{},"something"," happened, ",[52,267,268],{},"you cannot prove it happened correctly.",[22,270],{},[25,272,274],{"id":273},"the-root-cause-compliance-is-not-a-feature","The Root Cause: Compliance Is Not a Feature",[12,276,277,278],{},"All of these failures stem from a single architectural issue: ",[52,279,280],{},"compliance is treated as a layer on top of the system, not a property of the system itself.",[12,282,283],{},"Legacy platforms were designed to track work, manage tickets, and store data. They were not designed to enforce regulated execution.",[12,285,286],{},"So compliance gets \"added\" via SOPs, training, QA review, and manual audits. But the system itself remains permissive.",[22,288],{},[25,290,292],{"id":291},"what-structural-compliance-actually-looks-like","What Structural Compliance Actually Looks Like",[12,294,295],{},"A compliant system does not just record work — it constrains it.",[12,297,298],{},"In a structurally compliant model:",[105,300,301,307,313,319],{},[39,302,303,306],{},[52,304,305],{},"Procedures Are Executable"," — Each step is discrete and required. Execution order is enforced. Skipping steps is impossible without deviation logging.",[39,308,309,312],{},[52,310,311],{},"Actions Are Attributable at the Step Level"," — Every action is tied to a user, a timestamp, and a specific step.",[39,314,315,318],{},[52,316,317],{},"Approvals Are Enforced by Design"," — Critical steps require separate roles. Self-approval is structurally blocked. Signature events are cryptographically bound.",[39,320,321,324],{},[52,322,323],{},"Records Are Generated, Not Assembled"," — The audit trail is created as work happens, not reconstructed after completion.",[22,326],{},[25,328,330],{"id":329},"why-this-matters-in-an-audit","Why This Matters in an Audit",[12,332,333,334],{},"During an audit, the question is never: ",[262,335,336],{},"\"Do you have procedures?\"",[12,338,339,340],{},"The real question is: ",[262,341,342],{},"\"How do you ensure those procedures were actually followed?\"",[12,344,345],{},"If your answer depends on trusting technicians, reviewing PDFs, or sampling records, you have exposure.",[12,347,348],{},"If your system enforces execution order, required inputs, and role separation, then compliance becomes a property of the system — not a result of inspection.",[22,350],{},[25,352,354],{"id":353},"the-design-decision","The Design Decision",[12,356,357],{},"When we started building WELR, we had a choice: build a flexible service management tool and add compliance features later, or design the execution model around compliance constraints from the beginning.",[12,359,360],{},"We chose the second path — not because it is easier, but because the first path is what created the problem we are trying to solve. Separation of duties is enforced at the API layer, not just documented in a policy. Procedures are executable workflows, not attached PDFs. The audit trail is generated as work happens, because a trail assembled afterward is an argument, not evidence.",[12,362,363],{},"That is the architecture we chose. And it is the reason compliance in WELR is a structural property, not a setting.",{"title":365,"searchDepth":366,"depth":366,"links":367},"",2,[368,369,370,376,380,384,385,386,387],{"id":27,"depth":366,"text":28},{"id":62,"depth":366,"text":63},{"id":94,"depth":366,"text":95,"children":371},[372,374,375],{"id":99,"depth":373,"text":100},3,{"id":124,"depth":373,"text":125},{"id":140,"depth":373,"text":141},{"id":166,"depth":366,"text":167,"children":377},[378,379],{"id":170,"depth":373,"text":171},{"id":188,"depth":373,"text":189},{"id":217,"depth":366,"text":218,"children":381},[382,383],{"id":221,"depth":373,"text":222},{"id":242,"depth":373,"text":243},{"id":273,"depth":366,"text":274},{"id":291,"depth":366,"text":292},{"id":329,"depth":366,"text":330},{"id":353,"depth":366,"text":354},"2026-04-25","Most service platforms claim to be compliant with 21 CFR Part 820. Here is what that claim actually means — and where it breaks down under audit pressure.","md",null,{},true,"\u002Fblog\u002Fbolted-on-compliance",{"title":6,"description":389},"blog\u002Fbolted-on-compliance",[398,399],"compliance","architecture","Zucw5wATe__PBuLf1J50ACcNiR79ZAclp2Hhfk-HE9A",1787540976901]