UBC — AI Solutions

Audit — Dynamic Documentation Platform

Living documentation that stays in sync with engineering, cloud, AI, and compliance activity. Documents update themselves as the organization changes.

Back to library
Quality Manual
Fresh

UBC Quality Management System Manual

Top-level QMS Manual describing UBC's quality policy, process architecture, and integration of ISO 9001:2015 with CMMI-DEV v2.0 Level 3 practices.

Owner: Quality DirectorApprover: B. HuseltonVersion: 5.0Updated: 11/17/1969

1. Scope of the Quality Management System

The UBC Quality Management System (QMS) applies to all services delivered by UBC's AI Solutions, Patient Access, Pharmacovigilance, and Platform Engineering organizations, including client-facing hub services, voice agents, and data platforms.

The QMS is certified against ISO 9001:2015 and appraised against CMMI-DEV v2.0 Maturity Level 3. It integrates with the Information Security Management System (ISMS, ISO 27001) and the Project Management framework (PMBOK 7 / PRINCE2-aligned).

2. Quality Policy

UBC is committed to delivering pharmaceutical support services that are safe for patients, compliant with applicable regulations (21 CFR Part 11, HIPAA, GDPR), and continuously improved through evidence-based measurement. Every employee is empowered — and required — to stop work when quality is at risk.

3. Process Architecture

The QMS is organized into four process groups, mapped to ISO 9001 clauses:

3.1 Leadership & Governance (Clauses 5, 6, 9.3)

  • Executive review, quality objectives, management review.

3.2 Enabling Processes (Clause 7)

  • Human resources, competence, infrastructure, documented information.

3.3 Operational Processes (Clause 8)

  • Service delivery, SDLC, AI-DLC, project delivery, supplier management.

3.4 Improvement Processes (Clauses 9, 10)

  • Internal audit, CAPA, monitoring, continual improvement.

4. CMMI-DEV Integration

The QMS satisfies the following CMMI process areas at Maturity Level 3:

CMMI Process AreaUBC Implementation
Requirements Development & Management (RDM)SOP-SDLC-01, SOP-AIDLC-01
Technical Solution (TS)SOP-SDLC-02, SOP-AIDLC-04
Product Integration (PI)SOP-SDLC-04
Verification (VER)SOP-SDLC-05, SOP-AIDLC-05
Validation (VAL)SOP-AIDLC-06
Configuration Management (CM)SOP-SDLC-06
Process & Product Quality Assurance (PPQA)SOP-QMS-09
Measurement & Analysis (MA)SOP-QMS-10
Organizational Process Definition (OPD)This Manual
Organizational Process Focus (OPF)Management Review

5. Documented Information

All QMS documents are controlled by the Auto-Doc Engine. Every controlled document has an owner, approver, version, review cadence, and evidence trail. See the Document Control SOP for details.

6. Interfaces to Other Standards

  • ISO 27001: The ISMS operates as a compatible management system; ISMS controls appear in the Compliance tab of each relevant SOP.
  • HIPAA / GDPR: Privacy and PHI-handling requirements are baked into SOP-AIDLC-02 and SOP-PM-08.
  • 21 CFR Part 11: E-signature and audit-trail requirements are implemented in the Audit Trail service.

7. Governance & Review

The Quality Council meets monthly. Management Review is conducted quarterly by the SVP Operations and Quality Director, per ISO 9001 §9.3.

8. Amendments

This Manual is reviewed annually. Amendments require sign-off by the SVP Operations and the Quality Director.

Suggested by AI
Prepare for ML4 gap analysis
Consider commissioning a CMMI ML4 gap analysis in Q1 2027.
Frameworks
ISO 9001
CMMI-DEV
ISO 27001
SOC 2