Regulatory Information

Good Clinical Practice (GCP) & Good Laboratory Practice (GLP)

Overview

Good Clinical Practice (GCP) is an internationally recognised ethical and scientific quality standard for the design, conduct, documentation, and reporting of clinical trials involving human participants. Compliance with GCP is essential to protect the rights, safety, and well-being of trial participants, while ensuring the reliability and integrity of clinical trial data.
A GCP inspection is an official review of documents, facilities, records, and other resources related to the conduct of clinical trials. Inspections may occur during an ongoing clinical trial or after its completion. In some instances, for-cause inspections may be initiated in response to reports or concerns of serious non-compliance, such as data integrity issues or ethical/scientific misconduct.
NPRA GCP Inspections

In Malaysia, GCP inspections are primarily conducted by the National Pharmaceutical Regulatory Agency (NPRA), with additional oversight provided through compliance audits by the Medical Research and Ethics Committee (MREC). While NPRA typically conducts on-site inspections, remote inspections may be carried out when deemed necessary, especially in situations where on-site inspections are not feasible due to public health emergencies, travel restrictions, or other extraordinary circumstances.
Foreign regulatory authorities, such as the European Medicines Agency (EMA) and the U.S. Food and Drug Administration (USFDA), may also conduct inspections in Malaysia as part of the registration or marketing authorisation process for investigational products intended for their respective markets. NPRA inspectors may participate as observers or be involved in inter-agency joint inspections as part of international regulatory collaboration, as well as enhancing the transparency in global clinical research oversight of clinical trials.
The primary objective of GCP inspections is to verify compliance with regulatory and ethical standards, particularly those outlined in the Control of Drugs and Cosmetics Regulations 1984 and the Malaysian Guidelines for Good Clinical Practice (GCP). The Drug Control Authority (DCA) officially endorsed the Malaysian Guidelines for Good Clinical Practice Inspection at its 221st meeting on 29 October 2009, in accordance with Regulation 29 of the Control of Drugs and Cosmetics Regulations 1984. These guidelines establish a structured framework for the planning, execution, and reporting of GCP inspections in Malaysia.
In addition, NPRA has also expanded the scope of the GCP inspection to encompass Phase 1 Unit Inspection, creating a safe regulatory environment for the Phase 1 clinical trials in Malaysia. The Phase 1 Unit Inspection is designed to give assurance that the units listed in the NPRA Phase 1 Programme not only meet but surpass basic requirements under the Principles of GCP. TheMalaysian Guideline for Phase 1 Unit Inspection and Accreditation Programme was issued by the Director of Pharmaceutical Services under Regulation 29, CDCR 1984. Protocol Deviation
Protocol Deviation Submission

The Clinical Trial Import Licence (CTIL) or Clinical Trial Exemption (CTX) holder is responsible for reporting any updates or information relevant to the product or application, including protocol deviations. Detailed requirements are outlined in the Malaysian Guideline for Application for Clinical Trial Import Licence and Clinical Trial Exemption (refer to the List of Guidelines) Important Protocol Deviation: a subset of protocol deviations that may significantly impact the completeness, accuracy and/or reliability of the trial data or that may significantly affect a participant’s rights, safety or well-being. Minor Protocol Deviation:does not impact participant’s safety and data integrity but still requires documentation. Submission Requirements:

  • Format: All protocol deviation submissions must be made electronically. Hard copy submissions will not be accepted.
  • Cover Letter: Each submission must include a cover letter on the company’s official letterhead.
  • Report File: The protocol deviation report must be submitted in Excel format and renamed using the relevant reference number.
  • Template Compliance: Reports must follow the structure outlined in Form N3-FR-27: CTIL/CTX Protocol Deviation Report Template.
  • Submission Email: All correspondence and submissions should be directed to mygcp@npra.gov.my.
  • No Deviations: If no protocol deviations occur during the reporting period, notification to NPRA is not required.

Serious Breach

Serious Breach Submission

Serious Breach:Any deviation(s) from the approved clinical trial protocol, Principles of GCP, or any clinical trial-related regulations that is likely to have a significant impact on:

  1. The safety, rights or well-being of any trial participants; or
  2. The reliability and robustness of the data generated in the trial.

Submission Requirements:

  • All serious breach submissions and correspondences must be made electronicallyto the Head of Good Clinical Practice and Good Laboratory Practice Sectionvia mygcp@npra.gov.my.
  • Reporting Form: Please submit the serious breach report using this form N3-FR-82 Serious Breach Report, along with a cover letter on the company’s official letterhead.
  • The Clinical Trial Import Licence (CTIL) or Clinical Trial Exemption (CTX) holder of the clinical trial is legally responsible for the reporting of serious breach to NPRA.
  • All serious breaches should be reported without undue delay and at the latest within seven (7) calendar daysof the sponsor becoming aware of a serious breach. If the reporting responsibility is delegated to a contracted service provider such as a Contract Research Organisation (CRO), the 7-day timeline applies to the delegated party.
  • Updates on the serious breach can be made whenever further information becomes available.
  • If the investigation or corrective and preventive actions (CAPA) are ongoing at the time of reporting the serious breach, it is acceptable to outline the plans with projected timelines for completion. In such cases, the initial report should include an impact assessment and a summary of the root cause analysis.
  • Please refer to the Frequently Asked Questions (FAQ) tab for information regarding the serious breach reporting process.