Difference between revisions of "Accounting Finance:Document Imaging Management Policy"

From uniWIKI
Jump to navigation Jump to search
Line 305: Line 305:
 
| Federal regulations require that: || uniPHARM’s interpretation of and response to these requirements is contained within the GMP Manual and summarized as follows:
 
| Federal regulations require that: || uniPHARM’s interpretation of and response to these requirements is contained within the GMP Manual and summarized as follows:
 
|-
 
|-
  +
|
| rowspan="2" colspan="2"
 
 
*Every wholesaler of a drug retains records of the sale of each item, which enable a recalls from the market for a period of at least one year after the expiration date of the lot or batch unless otherwise specified in their establishment licence.
 
*Every wholesaler of a drug retains records of the sale of each item, which enable a recalls from the market for a period of at least one year after the expiration date of the lot or batch unless otherwise specified in their establishment licence.
 
||
 
||

Revision as of 14:04, 19 January 2018

Using the DIMP

  • This Document Management Imaging Policy (DIMP) Manual has been designed primarily for online use. Excessive printing of the manual is discouraged in order to aid version control and minimize costs.
  • Virtually all content is self-contained within a subject ‘table’ to make amendment and/or extraction as easy as possible.
  • The primary means of document navigation is via the Table of Contents. However, navigation is aided by the use of ‘hyperlinks’. These dynamic links allow users to jump from one subject to a related subject (or punch out to the documents located on the Internet) by simply clicking on the link. A link is displayed by underlined blue text. To return to the original location (i.e. prior to using a hyperlink), a blue return arrow should appear towards the top left hand corner of the screen). A bookmark entitled ‘Return to Table of Contents’ has been included at the commencement of many sections to assist overall navigation. Specific topics of interest (within a sentence of paragraph) have been ‘bookmarked’ and their related subjects hyperlinked to further aid navigation and to link closely related issues.
  • All references to actual Federal/Provincial regulations are in bold red text.
  • The online version of the DIMP manual is to be maintained as ‘read only’.
  • Glossary of Terms has been included clarification purposes.

1.0 Introduction

1.1 Purpose

The purpose of this document is to detail the management policy and business processes to be applied in respect of documents:

  • Scanned and stored in the Gauss Document Management System (DMS)
  • Accessed, viewed and retrieved from the DMS
  • Destroyed as a result of scanning operations

In addition, this document is intended to demonstrate linkage to the principals required for compliance with Federal/Provincial legislation, including:

  • The Personal Information Protection and Electronic Documents Act
  • Food and Drugs Act (Good Manufacturing Guideline 2002 Edition)
  • Income Tax Act
  • Employment Insurance Act
  • Employment Standards Amendment Act
  • Limitation Act

1.2 Background

uniPHARM’s vision is to operate, as far as is practical, in a ‘paperless’ environment. The UNITY Project has provided the means for realising this vision through the installation of the Gauss Document Management System (DMS). This system provides uniPHARM with the capability to capture information from a wide range of paper based or electronic sources, store an electronic image of document, and allow images to be retrieved on an enterprise basis.

The benefits of the DMS are clear in terms of efficiency, space utilization and online access to information. However, in order to ensure that the DMS itself is operated efficiently and to comply with all legal requirements covering document imaging, retention, access and privacy, it is necessary to formalize polices through Standard Operating Procedures (SOPs). This approach is consistent with those already in place in respect of GMP, Project Management and IT Management.

2.0 Ownership/Roles/Responsibilities

2.1 Background

The Personal Information Protection Act states that an organization is responsible for personal information under its control, including personal information that is not in the custody of the organization. The Act requires an organization to designate one or more individuals to be responsible for ensuring that the organization complies with the regulations.

2.1.1 Role Definition

The primary roles associated with the DMS are defined as follows:

Regulation Bill 38 Part: 2, 4(3)
Role Definition
Owner Designated individual who is held responsible by the uniPHARM Leadership Group for the efficient management of the DMS and compliance with all relevant legislation
Administrator Designated individual who is held responsible by the Owner for the definition of Document Classes and publication of Batch Classes
Operator Designated individual who is held responsible by the Owner for the efficiency of scanning operations and the quality of scanned images
Technical/Security Administrator Designated individual who is held responsible by the Owner for the efficiency of application support and security administration
Delegate Designated individual held responsible by the Owner for fulfilling the role (as approved by the Owner) of :
  • Owner
  • Administrator
  • Operator
  • Technical/Security Administrator
User Any individual who has been approved to:
  • initiate/propose that documents be scanned
  • view scanned documents in accordance with the DMS Security Policy and possesses an authenticated iSeries User Name/Password.

2.1.2 Ownership/Roles/Responsibilities

The following table details the individuals who will be responsible and accountable for the management and delivery of the DMS and the extent of their responsibilities:

Name Nancy Ng
Role Owner of the DMS
Responsibilities
  • Accountable to the uniPHARM Leadership Group for ensuring that all aspects of DMS operations comply with relevant legislation
  • Approves document classes to be scanned
  • Approves access to the DMS
  • Reports the status of the DMS to the Leadership Group on a monthly basis
  • Conducts a ‘self-inspection’ process to verify the operation of the DMS SOPs at least annually
  • Approves DMS training requirements
  • Responds to/resolves/escalates DMS issues
  • Plans and oversees the scanning of historical documents
  • Scans ‘management-in-confidence’ documentation
  • Maintains the currency of the DIMP and DMS Log
Delegate Christine Del Rosario
Name Christine Del Rosario
Role
  • System Administrator for Finance, Buying, Human Resources and Retail Services
  • Delegate to Nancy Ng
Responsibilities'
  • Accountable to the DMS Owner for efficient definition and publication of approved document classes
  • Responsible for the scanning station located in the Finance area
  • Monitors the scanning usage and reports ‘dongle’ rate to the DMS Owner as per the DMS Reporting SOP
  • Defines and publishes documents classes as trained and in accordance with the Gauss VIP Image Capture Administrator Manual and the DMS Administration SOP
  • Provides advice regarding indexing, validation, verification and publishing of document classes as required
  • Reports issues related to Administration operations to the DMS Owner via the DMS Issue Resolution SOP
  • Fulfills the obligations of the DMS Owner as required
Delegate Nancy Ng
Name Gordie Lee
Role
  • Scanning Operator for Distribution Centre Operations (except documents containing Personal Information and Management-in-Confidence)
Responsibilities
  • Accountable to the DMS Owner for efficiency of scanning operations
  • Scans documents classes as trained and in accordance with the Gauss VIP Image Capture Administrator Manual and the DMS Scanning SOP
  • Reports issues related to scanning operations to the DMS Owner via the DMS Issue Resolution SOP
Delegates Gerald Petznek
Name Chelsea Manasala
Role
  • Scanning Operator for Finance, Buying, Human Resources and Retail Services (except documents containing Personal Information and Management-in-Confidence)
Responsibilities
  • Accountable to the DMS Owner for the efficiency of Finance, Buying, and Retail Services scanning operations
  • Scans documents classes as trained and in accordance with the Gauss VIP Image Capture Administrator Manual and the DMS Scanning SOP
  • Reports issues related to scanning operations to the DMS Owner via the DMS Issue Resolution SOP
Delegates Christine Del Rosario, Nancy Ng
Name Angela Chan
Role
  • Scanning Operator for documents containing Personal Information only
Responsibilities
  • Accountable to the DMS Owner for the efficiency of ‘personal information’ document scanning operations
  • Scans documents classes as trained and in accordance with the Gauss VIP Image Capture Administrator Manual and the DMS Scanning SOP
  • Reports issues related to scanning operations to the DMS Owner via the DMS Issue Resolution SOP
Delegates Nancy Ng
Name Norwin Uy
Role
  • Technical Support/Security Administrator
Responsibilities
  • Accountable to the DMS Owner for maintaining DMS hardware and software operability – 99% uptime is required
  • Accountable to the DMS Owner for system security administration. This means maintaining secure access to scanned documents on both the iSeries and VIP Image Capture/VIP Document Manager (and in particular – documents subject to the Personal Information Protection Act) in accordance with the DMS Security Policy at Section 4.3
  • Ensures that standard arrangements are in place for system backup and disaster recovery
  • Ensures that delegate is fully familiar with the role and responsibilities of the Technical Support/Security Administrator
  • Reports issues related to technical support and security administration to the DMS Owner via the DMS Issue Resolution SOP
Delegate Darren Freedman

3.0 Impact of Legislation

3.1 Income Tax Act and Employment Insurance Act

Federal regulations concerning the imaging of tax/employment insurance related documentation require the following: uniPHARM’s interpretation of and response to these requirements is as follows:
  • Someone in the organization has confirmed in writing that the (imaging) program will be part of the usual and ordinary activity of the organization’s business.
  • See Section 3.5 for a statement from the CEO of uniPHARM confirming that the (imaging) program will be part of the usual and ordinary activity of uniPHARM’s business. This statement is available to be published to any regulatory body as required.
  • Systems and procedures are established and documented.
  • The systems and procedures governing the use of the document management system are laid down in this policy document.
  • A logbook kept showing:
-The date of imaging
  • All images retained within the DMS are automatically logged by the system. This audit facility enables uniPHARM or any authorized inspector to track and trace all scanned images and record deletions. In the event of system failure and the loss of the automatic auditing capability, proper safeguards have been established within this policy document to ensure that a backup of the system records is available as part of an overall business continuity strategy and disaster recovery plans.
-The signatures of the persons authorizing and performing the imaging
  • See the table at Section 3.6 for the signatures of all persons authorizing and performing the imaging. uniPHARM considers that the SOPs established within this policy document and the fact that all batches are to be initialled (electronically) by the scanning operator should be sufficient to establish the identity of scanning authority and operation.
-A description of the records imaged
  • A description of all documents approved to be scanned is maintained within the DMS Log as required under this document management policy.
-Whether source documents are destroyed or disposed of after imaging, and the date a source document was destroyed or disposed of
  • Scanned documents are to be disposed of under standing waste paper disposal arrangements and in accordance with the DMS Document Scanning SOP. All scanned documents are to be deemed ‘disposed of’ within 1 month of the date of scanning.
-The imaging software maintains an index to permit the immediate location of any record, and the software inscribes the imaging date and the name of the person who does the imaging
  • All documents scanned into the DMS will be indexed as defined in the Batch Class creation process (see VIP Image Capture Manual).
  • The indexing process will enable all scanned documents to be retrieved efficiently.
  • All batches scanned are automatically date/time stamped and are initialled (electronically) by the operator.
-The images are of commercial quality and are legible and readable when displayed on a computer screen or reproduced on paper
  • The scanning operation has in-built quality control checks to ensure that documents scanned are readable on screens. The quality of images is checked via the DMS Self-inspection SOP
-A system of inspection and quality control is established to ensure the maintenance of the required logs, indexing, and quality
  • See DMS Self-inspection SOP
-After reasonable notification, equipment in good working order is available to view, or where feasible, to reproduce hard copies
  • Hard copies of scanned images can be produced via the DMS (subject to security access permissions)

3.2 Personal Information Protection & Electronic Documents Act

To be compliant with Federal regulations, organizations are required to: uniPHARM’s interpretation of and response to these requirements is as follows:
  • Consider what a reasonable person would consider appropriate in the circumstances (re: protection of personal information)
  • See Section 3.5 for a statement from the CEO of uniPHARM confirming that the document management policy and practices are considered reasonable to protect the privacy of personal information subject to imaging.
  • Accept responsibility for personal information under its control, including personal information that is not in the custody of the organization
  • See Section 3.5 for a statement from the CEO of uniPHARM confirming acceptance of responsibility for personal information under uniPHARM’s control. Personal information, not in uniPHARM’s custody is subject to a separate policy.
  • Designate one or more individuals to be responsible for ensuring that the organization complies with the Act (the individuals may delegate the duties required)
  • See the table at Section 2.1.2 for details of the designated individual and delegates. The responsibility extends only to personal information processed by the DMS.
  • Make available to the public, the position, name or title and contact details of each designated (or delegated) individual responsible for compliance
  • This is not within the scope of this Document Imaging Management Policy (DIMP)
  • Develop and follow policies and practices that are necessary to meet the obligations of the Act
  • The systems and procedures governing the use of the document management system are laid down in this DIMP
  • Develop a process to respond to complaints
  • This is not within the scope of this DIMP
  • Make information available upon request about:
-The policies and practices followed
-The complaint process
  • This Document Imaging Management Policy is available to all uniPHARM staff at the following location:

\\Superserver\FormsGeneral\Document Imaging Management Policy\DIMP_1.1.doc

  • The complaint process is not within the scope of this DIMP
  • Make a reasonable effort to ensure that personal information collected by or on behalf of the organization is accurate and complete, if the personal information
-is likely to be used by the organization to make a decision that affects the individual to whom the personal information relates, or
-is likely to be disclosed by the organization to another organization.
  • The content of personal information scanned into DMS is not within the scope of this DIMP. However, details related to the actual source document such as the scanning date are automatically captured by the system log.
  • Protect personal information in its custody or under its control by making reasonable security arrangements to prevent unauthorized access, collection, use, disclosure, copying, modification or disposal or similar risks
  • Personal information scanned into the DMS is subject to security measures specifically designed to prevent unauthorized access e.g. access to all document classes categorized as ‘personal’ is restricted to personal described at Section 4.3 (Security/Access) by means of in-built system security functionality.
  • It is considered that it is extremely difficult to modify a scanned image of a source document. Thus the risk of this occurring is very low indeed. In any event this DIMP expressly forbids the unauthorized modification, use, disclosure, copying, and disposal etc. of scanned images of documents containing personal information.
  • The DMS is responsible for conducting a self-inspection process at least annually to ensure that the DMS remains compliant.
  • Retain personal that information for at least one year after using it so that the individual has a reasonable opportunity to obtain access to it (if an organization uses an individual's personal information to make a decision that directly affects the individual)
  • See ‘Personal’ category - Section 4.2 – Document Image Retention Policy
  • Destroy its documents containing personal information, or remove the means by which the personal information can be associated with particular individuals, as soon as it is reasonable to assume that
-the purpose for which that personal information was collected is no longer being served by retention of the personal information, and
-retention is no longer necessary for legal or business purposes
  • See Section 5.3– Personal Information Document Scanning SOP

3.3 Food and Drugs Act/GMP Guidelines (2002)

Federal regulations require that: uniPHARM’s interpretation of and response to these requirements is contained within the GMP Manual and summarized as follows:
  • Every wholesaler of a drug retains records of the sale of each item, which enable a recalls from the market for a period of at least one year after the expiration date of the lot or batch unless otherwise specified in their establishment licence.
  • See ‘Business’ category - Section 4.2 – Document Image Retention Policy.
  • Also, under the GMP Records SOP, the IT Manager is to ensure that, at a minimum, data is to be immediately accessible from the live production system (or within 1 [one] day if from a verifiable back up source) that will enable any drug to be recalled from any Customer for a period of at least one year after the expiration date of that drug.
  • Distribution records of all sales of drugs are maintained including those of professional samples.
  • Records of all sales are retained or readily accessible in a manner that will permit a complete and rapid recall of any lot or batch of a drug. This does not necessarily imply tracking by lot number.
Example Example
Example Example
Example Example