A typical NetSuite implementation proposal might include discovery, design, build, testing, training, and go-live support. This range is sufficient for most industries. But that's not true for regulated life sciences and healthcare organizations.
Standard proposals often don’t include the deliverables that will determine if an implementation is compliant with regulators. This is not because implementing firms want to keep these out of the proposal, but because firms without experience in regulated industries don’t know to include them.
In this article we look at what great implementation services look like for regulated organizations and how to tell if a proposal will actually meet those requirements.
A standard proposal will usually contain the following information:
A typical mid-market NetSuite implementation proposal includes the following components:
Project Kickoff and Discovery: This phase of the project includes business requirements.
Design: This phase includes fit-gap analysis and solution design documentation.
Build: This phase includes configuration and development.
Testing: This phase consists of functional and user acceptance testing.
Training: This phase includes end-user training sessions.
Go-Live and Cutover: This phase consists of go-live support.
All of these phases are necessary. No one of them is enough for a regulated life sciences or healthcare organization with additional provisions for compliance requirements.
What regulated organizations need that is often missing
Mapping of compliance needs. Prior to design initiation, all relevant regulatory structures should be mapped to system design requirements. For a pharmaceutical manufacturer, this includes 21 CFR part 11 audit trail requirements, cGMP traceability requirements, and validation documentation standards. For a healthcare organization it includes HIPAA access control requirements, ASC 606 revenue recognition requirements, and SOX controls for applicable companies. This mapping should be a documented deliverable to inform design decisions.
Documentation package from validation. Systems used for regulated activities in life sciences have to be validated. The implementation should result in an Installation Qualification confirming the system is installed and configured as intended, an Operational Qualification confirming that workflows operate as designed and a Performance Qualification confirming that the system performs as needed in the real operational environment. These documents are not optional add-ons – they are requirements for validated operation of the system.
Data migration validation. One of the validation events in regulated environments is the migration of historical data from legacy systems to the new ERP. Migration approach, mapping logic and verification process to be documented and tested. The output will be a data migration summary report confirming the completeness and accuracy of migrated records.
Configuration design aware of compliance. The system design documentation should clearly describe the means by which each compliance requirement is satisfied by the configuration. This is not a standalone report of compliance. It is an integrated part of design documentation.
The deliverables that define excellent quality in implementation services
The quality implementation services for regulated entities have concrete outputs beyond the standard deliverables that showcase real compliance expertise.
A log of configuration decisions. Implementation projects make hundreds of decisions about configuration. High-quality services keep a decision log, which includes the options considered, the decision made and the rationale behind it. This log will be very useful for post go-live support and understanding context behind existing configuration.
Audit trail configuration documentation. A specific document that confirms the audit trail settings for each type of record subject to regulatory requirements, the elements captured and the retention period configured.
Access management and segregation of duties documentation. A complete map of user roles and permissions and segregation of duties enforcement that confirms the access control design meets the applicable framework requirements.
Architecture documentation for integration. For each interconnected system, documentation should include the design of the integration, flow of data, mapping logic and approach to error handling to support ongoing maintenance and regulatory review.
Cutover plan continuity of audit trail. The cutover plan should describe how the continuity of the audit trail is maintained during the transition from the legacy system to the new ERP, where the historical records are maintained and how they are accessible during and after the transition.
Evaluating an Implementation Services Proposal
When reviewing a NetSuite implementation proposal from a Life Sciences or Healthcare perspective, check to see if compliance requirements mapping is in scope and if validation deliverables are listed and described, whether data migration is scoped with validation methodology, and whether training is described as role-specific and based on actual configured workflows.
If they don’t include these items in the proposal, ask for them. If the firm cannot articulate how they provide these elements – or they do not know why they are needed – that is a clear sign of generalist experience.
What post go-live services to include
A full implementation engagement for a regulated organization should identify the post-go-live services available through ongoing engagement in the base scope. At a minimum this includes hypercare support in the 30 days following go-live, access to the configuration decision log and technical documentation, and a defined escalation path for compliance-related support requests.
The relationship with the implementation partner post go-live provides valuable continuity of institutional knowledge for the life of the system. Organizations that drift away from the team that built their system – as the engagement quickly ends at go-live with no ongoing relationship – have to go back to the drawing board every time they need system support.