Quality risk management for regulated manufacturing — pharma, med-device, food and automotive — with native SAP QM integration. When a QualityNotification lands in SAP, RiskGuard opens the investigation cockpit automatically: the affected finished goods, the qualified supplier, and the traceability chain already resolved.
BUILT FOR REGULATED MANUFACTURING
A single walkthrough: SAP QM incident → BOM cascade → hazard cockpit → AIAG-VDA FMEA → e-signed approval → tamper-evident audit trail.
HOW IT WORKS
Suppliers, materials, and bills of material sync from SAP over OData on a scheduled pull. Qualification status, audit dates, certifications, criticality and material class — kept in sync from SAP. Every hazard, incident, and FMEA reads from the same source of truth.
Med-device and pharma get IMDRF Annex A/E/F terminology and the ISO 14971 structure built in. Automotive gets AIAG-VDA seven-step FMEA, CC/SC special characteristics and 8D. Food gets Codex HACCP with critical control points. An industry profile switches the surface to match — the methods and terms your inspector expects, not free text a reviewer has to interpret.
Every action is logged with user, timestamp, IP, and a cryptographic hash of the previous entry. Break a row, break the chain. One-click Verify Chain Integrity walks the full audit trail and hands your inspector the chain-head hash and a verification timestamp.
CAPABILITIES
SAP QualityNotifications land in RiskGuard as PMS incidents with Q1/Q2/Q3/F1 type, priority-mapped severity, linked material, batch, and supplier — no re-typing.
When a raw-material incident opens, RiskGuard resolves the BOM upward and shows the finished goods that consume it. The chain SAP holds but never surfaced.
Hazards linked to a supplier or material show the supplier's qualification status, last audit, certifications, and the material's classification and hazard class — read live from the master-data store.
Live search across IMDRF Annex A (Device Problems) and Annex E/F (Health Effects). Hazards stored with codes an auditor recognises, not free text.
Process Flow, Structure Tree, Worksheet (RPN + Action Priority), Control Plan — the modern AIAG-VDA method, not the old MIL-STD-1629 spreadsheet regulators are pushing back on.
Containment, structured root cause (5-Why · Ishikawa · 8D) with the automotive 3-legged view — why it happened, why it escaped, why the system allowed it. A D7 gate blocks closure until the FMEA / control plan that failed is updated, with the revised line linked as evidence.
Every closed CAPA gets a monitoring window. If the same defect returns on the same material or supplier, the CAPA is auto-flagged “effectiveness questioned” and comes back to you — instead of resurfacing months later as a repeat audit finding.
Configurable S/O/D scales with your own criteria and a recorded rationale per rating, a choice of trigger (Action Priority · RPN · S×O · S×D), and APQP Control Plans with CC/SC special characteristics — switched on by industry profile, alongside pharma and med-device.
A secure, single-use link lets a supplier answer a non-conformity directly: a message thread, file attachments, and an affected-stock containment declaration — all landing in the incident. The link is consumed on send, and only your reverse proxy exposes it.
FMEA, PHA, FTA, HAZOP, HACCP — same submit/review/approve state machine, same electronic-signature discipline, same audit trail. One platform, five methodologies.
Reviewer and approver sign with their password. The backend refuses to let the same person review and approve. Separation of duties as a permission check at the endpoint, not policy on paper — and configurable per install: toggle the author≠approver rule and assign who submits, reviews and approves.
Each audit row carries a hash of the previous row. Verify Chain Integrity walks the whole chain in seconds — hands you the head hash, row count, and the first break if any.
When SAP marks a supplier's qualification as expired, a re-review alert opens on every hazard and incident that references that supplier. RiskGuard even separates an expired qualification (audit lapsed) from a never-qualified supplier — catching the case where the ERP still reads “Approved.” No manual scan, no missed exposures.
One-click ISO 14971:2019 risk management report with the exact structure your notified body expects. Plus a 12-month hazard trend chart and a supplier heat map.
Every hazard, FMEA, and report is scoped by plant. Quality leads see what they own — not everyone else's noise. Enterprise multi-tenant, single audit chain.
Ships as Docker containers. PostgreSQL 15, Redis 7, no external SaaS dependency. GDPR-native by design.
STANDARDS-NATIVE
RiskGuard replaces it with a system regulators recognise — signed, chained, and provable.