How structured process knowledge, quality risk management and digital models strengthen transfer readiness – and where AI can add value

What can the receiving unit now do? For Andreas Berger, Co-Founder, CTO & Managing Director at Innerspace, effective technology transfer starts with the sending unit: how can process knowledge be captured in a structured way that remains usable when transferred to a new site? Through Digital Process Models, Frame-by-Frame® structures process knowledge around individual process steps and interactions, creating a consistent data foundation for transfer.

Dr. Hussein Ghareh, Head of Professional Services at Innerspace, looks at the next challenge: whether the receiving unit can use this knowledge to understand the process, assess its risks within the new operating context, and make informed, risk-based decisions. This is where systems thinking and Quality Risk Management (QRM) become essential to a successful transfer.

Andreas explores the wider foundation in Operational Readiness in Pharma: Where AI, Data, and People in Process Collide with GMP Reality. His argument is that people, process, equipment and data have to work as one controlled system before advanced technology can add value. Technology transfer is where process knowledge must remain clear, complete and actionable as it moves from one site to another.

Together, we use both perspectives to test a transfer from Site A to Site B: did capability move, or only files? The SOPs, batch records, validation documents and meeting minutes may all be present. Yet the receiving unit (RU) may still lack the reason behind a critical limit. It may miss the context for a control or a key site difference. The files arrived. The capability did not.

The five tests that follow ask whether the RU can understand and compare the process. Can it make evidence-based QRM decisions and execute locally? Can it prove capability? The answers reveal what a complete handover can still leave behind.

What you get: key takeaways

  • A complete handover is not yet a complete transfer. Product and process knowledge, professional expertise and decision rationale must remain usable at the RU.
  • Site comparison is a technical requirement. Differences in equipment, materials, methods, people and quality systems need a structured gap analysis.
  • QRM turns differences into decisions. Evidence, assumptions and uncertainty matter more than matching risk scores.
  • The RU must execute and prove capability. Each site and project sets its training, qualification, validation and Quality oversight needs.
  • Frame-by-Frame is an enabler, not a compliance shortcut. It can structure process knowledge and SU/RU comparison. It can also link risks, controls, roles, documents and role-specific training within the manufacturer’s PQS (Pharmaceutical Quality System).

What technology transfer must transfer

The World Health Organization defines technology transfer as a controlled procedure for transferring a product or process, including its knowledge, documentation and professional expertise. The work takes place between a sending unit (SU) and an RU, with the approach proportionate to the product lifecycle phase.1

Receiving the documentation is only an input. A successful technology transfer requires evidence that the RU can execute the process consistently, manufacture to defined specifications, and meet acceptance criteria agreed before execution.

WHO organizes the work into four phases: Project initiation, Project planning, Project transfer execution, and Project review and close-out. Project initiation sets scope, parties and feasibility. Project Planning assigns responsibilities, performs due diligence and gap analysis, defines the QRM approach and sets the transfer protocol or master plan. Project Execution moves knowledge and performs the justified local work. Close-out records the results and conclusions. It also captures deviations, investigations and open actions.

The pathway depends on the product, process and lifecycle stage. A move from lab scale through scale-up differs from a transfer of established commercial production. An internal site move also differs from a project with a contract development and manufacturing organization (CDMO or CMO). The capability test remains the same.

Intellectual property ownership, licensing and commercial terms need their own controls. They are not substitutes for the manufacturing, quality and knowledge-transfer work discussed here.

The Lifecycle of Knowledge in the Pharmaceutical Product and process Lifecycle

1. Understand the process, not only the procedure

The RU needs more than the approved way of working. It needs the process-development and manufacturing history that explains why that way of working exists.

WHO expects the SU to provide process maps, master batch records and validation information. It also calls for the control-strategy rationale, critical quality attributes (CQAs), critical process parameters (CPPs), critical ranges and authorized instructions. Relevant knowledge may also sit in prior experiments, exceptions, investigations, and failed approaches. Without this context, the RU may reproduce a control without understanding the risk it addresses, why it matters, or what could happen when process conditions change.

A case reported by Paige Kane and David Twohig shows the mechanism. Development records captured a lesson about long operation near a bioreactor’s lower aeration limit. Yet the team kept those records on a limited-access site and did not turn the lesson into an accessible procedure or work instruction. The RU did not know it. Its risk assessment omitted the issue, and qualification scripts did not test the lower limit.2

This is one biopharmaceutical case, not a prevalence estimate or an aseptic fill-finish study. The practical point is simple. Knowledge only moves when the right people can find, interpret and apply it.

ICH Q10 puts knowledge management and QRM inside the PQS. Both apply from development through technology transfer and commercial manufacturing to product discontinuation. ICH Q10 tells firms to acquire, analyse, store, share and expand product and process knowledge. The RU should be able to connect each requirement or control to the evidence and risk-based rational behind it.3

2. Compare the sending and receiving contexts

Once the RU understands the origin process, it has to identify what changes at its site. A gap analysis should compare premises, utilities, equipment, instruments and computerized systems. It should also cover raw materials, API or product handling, batch sizes, process flows, analytical methods, people and quality systems.

A difference is not automatically a failure. It is a question for risk assessment. Will a different filling line change an intervention? Does a local material specification affect a CPP or CQA? Does the RU have the necessary quality-control capability? Do site methods, assigned roles or batch-record formats change the work?

The comparison should be side by side and granular enough to support decisions. If SU knowledge sits in one set of files and RU conditions in another, teams must reconstruct the relationships before they can assess the impact of differences.

For aseptic manufacturing, the comparison must also reach the contamination control strategy (CCS). EU GMP Annex 1 brings process and facility design, equipment, personnel, utilities, raw materials, vendors, outsourced activities and information transfer into the facility-wide CCS. Validation, cleaning, monitoring, investigations and continual improvement are part of the same control system. Monitoring alone does not assure sterility.4

3. Make evidence-based QRM decisions

The gap analysis produces questions. QRM turns them into controlled decisions.

Keep three risk conversations distinct:

  • Project risk: effects on schedule, cost, resources and delivery.
  • Technical or process risk: site differences that prevent repeatable execution.
  • Quality risk: effects on product quality and, ultimately, patient protection.

ICH Q9(R1) describes QRM as a lifecycle process for assessing, controlling, communicating and reviewing quality risk. Risk evaluation should draw on scientific knowledge and connect to patient protection. The effort, formality and documentation should be proportionate to risk.5

A useful decision record shows what can go wrong, how likely it is and what the consequences are. It also makes the evidence, assumptions, uncertainty, decision owner and accepted controls visible. A risk score may support this reasoning, but it cannot replace it. Equal SU and RU scores do not prove equal capability when the sites use different evidence, scales or assumptions.

Hussein describes the discipline behind this work in practical terms:

“Systems thinking helps us move beyond isolated risk scores. We need to understand how process steps, interactions, site conditions and controls are connected, and use structured data to make those relationships visible.”
Hussein Ghareh, Head of Professional Services at Innerspace

For a transfer team, that means looking beyond isolated risk entries. The relationships among process steps, site conditions, evidence, controls and responsible people need to remain visible when the work moves from the SU to the RU.

4. Execute the process under local controls

Transfer execution is where the RU converts understanding and decisions into approved work. Each function needs a clear role. That includes process owners, engineering, operations and training. It also includes quality assurance, quality control and validation.

The work can include equipment and system qualification, trial batches, process validation, analytical method transfer, approved work instructions, training and change control. WHO allows several transfer paths when the science and risk justify them. Options include confirmation tests, comparability tests, co-validation or a paper transfer. Each site normally needs its own cleaning procedures and validation.

People in aseptic operations need training and qualification for their roles. Annex 1 also expects controlled aseptic interventions and places aseptic process simulation (APS) inside a wider system of process design, qualification, controls, training and monitoring.

Simulation helps people practise process-specific decisions and behaviours before applying them in the manufacturing environment. It does not, by itself, qualify personnel or a site, validate the process, or replace APS. Good manufacturing practices, approved protocols, the PQS and Quality oversight continue to govern execution.

5. Demonstrate capability and preserve the evidence

The final test is not whether the RU received the package. It is whether the RU can execute and control the process in its own environment against agreed acceptance criteria.

WHO expects the transfer report to capture the scope, critical parameters at both units, conclusions, changes, deviations, investigations and actions. Supporting data should remain accessible. Statistical trending or capability studies may be appropriate, but the evidence and success criteria remain project-specific.

Close-out should also leave the next team with usable knowledge. Static archives can split the report from its risk rationale, training evidence and change history. The next transfer or process optimization effort then starts with the same gap.

Where Frame-by-Frame contributes

At Innerspace, we see technology transfer as both a process-understanding and capability-transfer challenge. Frame-by-Frame creates a shared Digital Process Model that structures process knowledge around the interactions between people, equipment, materials and the environment.

This provides a common data foundation for the five transfer tests:

  • Understand: Process steps, interactions, hazards and expert knowledge are captured in a common structure. Knowledge can be connected to where it matters in the process, rather than remaining distributed across separate documents and systems.
  • Compare: The SU process and RU context can be represented using the same structure. Differences in equipment, layouts, materials, flows, interventions and responsibilities can then be identified and assessed systematically.
  • Decide: Process knowledge and site-specific differences can be connected to hazards, risks, controls and their rationale. This creates greater traceability for QRM and makes the evidence behind a decision more visible. Expert judgement remains essential.
  • Execute: The same process knowledge can support work instructions, risk documentation, handover and validation activities, as well as stakeholder-specific outputs. The training approach uses the same process knowledge to create role-specific training and simulation.
  • Prove and maintain: Connections between the process, risks, controls, documentation and training preserve the context behind decisions. When the process or site changes, teams have a structured starting point for assessing what is affected and what needs to be reviewed.
Four Phases and four Gates of Tech Transfer in Pharma

Innerspace’s technology-transfer workflow starts by capturing the process and its associated knowledge at the sending unit. The model can then be adapted to the receiving unit, making site-specific differences visible and supporting risk assessment, knowledge transfer and implementation.

Frame-by-Frame supports these activities; it does not change their regulatory ownership. The manufacturer’s PQS and Quality Risk Management processes remain responsible for the assessment, approval, documentation, and control of technology-transfer decisions and associated risks.

Structured knowledge comes before advanced analytics

A shared process structure can also create better context for bounded analytics or AI. It cannot authorize an AI model to make GMP decisions.

Andreas summarizes the required order clearly:

“The sequence matters: Standardize first. Structure the data. Build process understanding. Then automate and scale.”
Andreas Berger, CTO & Managing Director at Innerspace

The FDA’s January 2025 draft guidance, which is nonbinding and not for implementation, starts with a defined question and context of use. It then considers model influence and decision consequences. It also calls for data that fits the intended use and that teams can trace. Teams must prove the model works and manage it through its lifecycle. The EMA reflection paper also puts manufacturing AI inside QRM. It calls for data integrity, product-quality controls, monitoring and human oversight.67

The sequence is practical: understand and structure the process first; govern risk and data next; then assess a bounded use case with accountable human oversight.

Practical technology-transfer readiness checklist

Use these questions at your next SU/RU review:

  • Can the RU demonstrate the process intent, critical steps, CQAs, CPPs and control rationale?
  • Can the team retrieve development history, prior failures, assumptions and lessons when making decisions?
  • Does the gap analysis compare relevant SU/RU equipment, materials, methods, flows, systems, roles and capabilities side by side?
  • Are project, technical/process and quality risks distinguished?
  • Does each material decision show its evidence, assumptions, uncertainty, owner, control and residual action?
  • Are the roles clear? Do engineering, operations, quality assurance, quality control, validation and training know what they own?
  • Does each site use a justified path for analytical method transfer, qualification and process validation? Are change control and APS boundaries clear?
  • Does role-specific training connect what people must do with why it matters? Does the team assess effectiveness?
  • Can the RU demonstrate capability against a priori acceptance criteria and produce an accessible, evidence-backed transfer report?

This is a readiness diagnostic, not a universal regulatory checklist. Save it and share it with the transfer team before the next gate.

Conclusion: Capability has to arrive with the documents

Hussein’s opening question brings the argument full circle: What can the receiving unit now do? If the RU cannot explain the process, assess its risks, execute it under local controls and demonstrate capability, the transfer is not complete, however complete the document package may look.

Andreas adds the technology test. Structured data, digital models and AI create value only after the operational logic is explicit and usable. They should strengthen expert judgement and traceability, not hide missing process knowledge behind another system.

Our shared conclusion is practical: move the knowledge and decision rationale with the documents, compare the two operating contexts, govern the differences through QRM and preserve the evidence the RU needs to perform. That is what turns handover into transferable process capability.

If you are preparing a complex aseptic transfer, use the checklist to find where capability is still implicit. Then assess whether a shared Digital Process Model fits your existing knowledge-management, QRM, validation and implementation approach. Talk to Innerspace about the fit.

Frequently Asked Questions (FAQ)

WHO defines technology transfer as a controlled procedure for moving a product or process from an SU to an RU. The transfer includes its knowledge, documentation and professional expertise. The approach should match the lifecycle stage and the needs of the project.

The package is project-specific. Typical elements include assigned roles and process history. Add maps, site comparisons, gap and risk assessments, analytical methods and validation information. The package should also cover the control strategy, training and acceptance criteria. A protocol or master plan precedes execution; the transfer report records the result.

The sending unit is the originating organization or site for the product, process or method. The receiving unit is the group of disciplines expected to receive and implement it. Transfer success depends on the RU demonstrating capability in its own premises, equipment and quality system.

QRM helps teams assess, control, communicate and review quality risk. It also shows the evidence, assumptions and unknowns behind each choice. The method and level of formality should be proportionate to risk, and quality risk should remain distinct from project and technical/process risk.

No. Simulation can support practice and process-specific training, but it does not by itself qualify personnel or a site, validate a process or replace APS. Applicable requirements and approved protocols still apply. The manufacturer’s PQS and Quality Unit retain oversight.

Frame-by-Frame, the Digital Process Model structures process knowledge around the interactions between people, equipment, materials and the environment. During technology transfer, this common structure can connect SU process knowledge with the RU context, making site differences, risks, controls, responsibilities and training needs more visible and traceable. It supports risk-based decision-making and knowledge transfer; it does not replace the manufacturer’s PQS, QRM, qualification or validation activities.

Sources

  1. World Health Organization: Technology Transfer in Pharmaceutical Manufacturing ↩︎
  2. Case report by Paige Kane and David Twohig ↩︎
  3. ICH Q10: Pharmaceutical Quality System ↩︎
  4. EU GMP Annex 1 ↩︎
  5. ICH Q9(R1): Quality Risk Management ↩︎
  6. FDA January 2025 draft guidance ↩︎
  7. EMA reflection paper on AI in the medicinal product lifecycle ↩︎

Did you like this article? Share it with your network!

  • Operational Readiness in Pharma: Where AI, Data, and People in Process Collide with GMP Reality

    Advanced AI cannot fix an unready operational foundation. Discover how biopharma leaders can modernize Operational Readiness, build a GMP-compliant data…

    19min read
  • Innovation vs Regulation – how to implement AI in Pharmaceutical Manufacturing?

    Artificial intelligence promises revolutionary gains for pharmaceutical manufacturing, yet stringent GMP regulations make implementation complex. This article explores how pharma…

    16min read