Organised around the ACT model — Auditing, Consulting and Training — each available as a permanent advisory retainer, temporary project support, or a freelance contract, whichever fits how your organisation resources compliance work.
On-site or remote audits against GxP, pharmacovigilance and clinical-quality frameworks, delivered with findings your team can act on immediately.
A full assessment of your quality systems — current Good Manufacturing Practice (GMP/cGMP), Good Clinical Practice (GCP/cGCP), Good Distribution Practice (GDP/cGDP), Good Pharmacovigilance Practice (GVP/cGVP), Good Laboratory Practice (GLP/cGLP) and Good Documentation Practice (GDocP) — measured against what regulatory authorities expect to see, not just what the standard says on paper.
Engagements typically combine an on-paper gap analysis with structured interviews and, where useful, a mock inspection, so findings translate directly into a CAPA plan your team can execute.
Typical timeline: 1–2 weeks planning & document review → 2–5 days on-site/remote audit → 1 week draft findings & CAPA plan.
Ask about GxP auditing →ISO 7101:2023, the first international standard dedicated to quality management in healthcare organisations, is still largely unavailable through training and audit providers. We're closing that gap.
Typical timeline: 1 week readiness scoping → 2–3 weeks gap assessment → certification audit scheduled separately with the certification body.
Ask about ISO 7101:2023 →Advisory work that goes beyond a findings report — helping your team design, document and operate the management systems a future audit will actually be checked against.
For organisations deploying or procuring AI in a regulated context, we assess where current governance stands against ISO/IEC 42001 and build the management-system documentation and controls needed to close the gap.
Because ISO/IEC 42001, the EU AI Act and the NIST AI RMF overlap significantly in practice, this work also flags where a given AI system is likely to sit under the Act's risk tiers — useful input for legal and product teams working the same question from a different angle.
Typical timeline: 1 week scoping → 2–3 weeks gap assessment → 1 week roadmap & report.
Ask about AI governance →Data protection work scoped specifically for health data: digital health platforms, clinical data flows, medical devices and AI-enabled tools that process patient information, where the stakes and the special-category rules are higher than in general-purpose data protection work.
The output is practical, not just a report: updated records of processing, a completed DPIA where one is required, and a clear view of which vendors or data transfers need closer attention.
Typical timeline: 1 week data-flow mapping → 2 weeks DPIA & documentation → ongoing vendor review as needed.
Ask about data protection for health data →Quality assurance consulting of pharmacovigilance systems against GVP requirements — assessing whether your PV system would hold up under inspection, not running the day-to-day case processing itself.
This sits alongside broader regulatory-affairs support: submission planning, CMO oversight, and project management across multi-functional regulatory initiatives.
Typical timeline: 1 week scoping → 2–4 weeks PV system mock inspection & consulting → 1 week findings report.
Ask about PV & regulatory QA →Quality assurance consulting of manufacturing systems against GMP requirements — assessing whether your GMP system would hold up under inspection, not running the day-to-day operations itself.
This sits alongside broader regulatory-affairs support: process controls planning, CMO oversight, and project management across multi-functional regulatory initiatives.
Typical timeline: 1 week scoping → 2–4 weeks GMP system mock inspection & consulting → 1 week findings report.
Ask about GMP systems consulting →Quality assurance consulting of clinical trial systems against GCP requirements (ICH E6(R3)) — assessing whether your GCP system would hold up under inspection, not running day-to-day trial operations itself.
This sits alongside broader regulatory-affairs support: protocol and Trial Master File (TMF) planning, CRO oversight, and project management across multi-functional regulatory initiatives.
Typical timeline: 1 week scoping → 2–4 weeks GCP system mock inspection & consulting → 1 week findings report.
Ask about GCP systems consulting →Quality assurance consulting of wholesale distribution systems against GDP requirements (EU GDP Guidelines 2013/C 343/01) — assessing whether your GDP system would hold up under inspection, not running day-to-day logistics itself.
This sits alongside broader regulatory-affairs support: cold-chain and wholesale-distribution planning, logistics-partner oversight, and project management across multi-functional regulatory initiatives.
Typical timeline: 1 week scoping → 2–4 weeks GDP system mock inspection & consulting → 1 week findings report.
Ask about GDP systems consulting →Quality assurance consulting of documentation and data-integrity systems against GDocP requirements (ALCOA+ principles) — assessing whether your GDocP system would hold up under inspection, not running day-to-day record-keeping itself.
This sits alongside broader regulatory-affairs support: data-integrity planning, electronic-system validation oversight, and project management across multi-functional regulatory initiatives.
Typical timeline: 1 week scoping → 2–4 weeks GDocP system mock inspection & consulting → 1 week findings report.
Ask about GDocP systems consulting →Quality assurance consulting of non-clinical laboratory systems against GLP requirements (OECD GLP Principles) — assessing whether your GLP system would hold up under inspection, not running day-to-day study conduct itself.
This sits alongside broader regulatory-affairs support: study-protocol planning, test-facility oversight, and project management across multi-functional regulatory initiatives.
Typical timeline: 1 week scoping → 2–4 weeks GLP system mock inspection & consulting → 1 week findings report.
Ask about GLP systems consulting →The same expertise behind our audits and consulting work, built into structured courses — starting with a complete, ready-to-run internal auditor programme. All content is provided under ©PizarroMethod.
A complete, ready-to-run programme that takes your staff from GxP fundamentals to conducting their first internal audit — training materials, templates and mentoring included, so there is nothing extra to build in-house.
Delivered as a structured curriculum rather than a one-off workshop, so your internal audit function is operational immediately, not just theoretically trained.
Typical timeline: 2 days fundamentals workshop → 2 weeks self-paced modules → 1 mentored audit (timing depends on your audit calendar).
Ask about Internal Auditor Training →Site Activation and EU/non-EU Batch Release are next, with further topics shaped by the training needs we hear most often from quality and regulatory teams.
Full course library access for a single learner.
Progress tracking across a quality or regulatory team at one site.
Annual subscription for organisations training across multiple sites or business units.
Timelines above are indicative and vary by scope, organisation size and current documentation maturity — confirmed during the initial conversation.
With no larger portfolio of accounts to protect, findings aren't softened to preserve a bigger relationship elsewhere in the business.
You work directly with the person doing the audit and writing the findings — not a rotating account team.
Direct experience auditing multinational manufacturers translates into knowing what inspectors actually check for.
Tell us about your organisation and where you are in your compliance or AI-governance journey — we'll recommend the right starting point.
Request a consultation