A studio service
Sponsor quality notifications & approvals for pharma every deviation and change, told on time and on record.
FDA guidance says a quality agreement should explain how the contractor will report manufacturing deviations to the owner, and that some changes need the owner's review and approval before they are implemented. We build a notification and approval workspace where each sponsor's agreement terms drive the deadlines, the sponsor answers in a portal, and every notice and decision is kept against the batch.

The facts behind this module
FDA, 2016
“The quality agreement should explain how the contractor will report manufacturing deviations to the owner, as well as how deviations will be investigated, documented, and resolved in compliance with CGMP.”
FDA, 2016
“There are some changes that owners should review and approve before they are implemented and other changes contractors may implement without notifying the owner.”
39 → 111
FDA CDER warning letters on manufacturing or GMP subjects rose from 39 in 2023 to 78 in 2024 and 111 in 2025.
Quoted from the sources linked. We add no estimates of our own.
What it looks like
Open notices
6
Due within 24 h
2
Awaiting sponsor
3
Overdue
1
| Record | Type | Sponsor | Batch | Deadline from agreement | Status |
|---|---|---|---|---|---|
| DEV-0412 | Deviation | Sponsor A | B-24071 | Today 16:00 | Due |
| CC-0188 | Change approval | Sponsor B | — | 12 Oct | Awaiting sponsor |
| DEV-0409 | Deviation | Sponsor A | B-24068 | Yesterday | Overdue |
| BR-2231 | Batch record review | Sponsor C | B-24062 | 15 Oct | Signed |
Interface concept with invented sample data, shown to illustrate the design. It is not a screenshot of a live system.
How it connects
SAP S/4HANA
- Batches, QM, EWM, planning
- Stays the system of record
- Core left standard, nothing changed inside
The app, in your tenancy
- SAP BTP, Azure or AWS, your region
- Audit trail, roles, single sign-on
- Read-only in a Pilot; write-back by agreement
People and plant systems
- Your teams, by role
- Sponsors, each to their own data
- MES, LIMS, QMS and logger platforms
SAP's clean-core rule, quoted: “Extensions must be developed using only released local or remote public SAP APIs, BAdIs, or ABAP RESTful application programming model business object (BO) extension points.” SAP PRESS, SAP S/4HANA Clean Core: Principles, Benefits, and Best Practices.
N° 01What SAP already covers
We start from SAP, not against it.
SAP QM records quality notifications, and your QMS manages deviations and change control. This module adds the sponsor-facing step: the notice, the deadline from your quality agreement and the sponsor's recorded decision. This module is a side-by-side extension: it reads and writes SAP only through released APIs and leaves the core standard.
N° 02Where it helps
Four situations this module is built for.
01
Deadlines kept in people's heads
Each sponsor's notification windows and approval rights configured once from the quality agreement, then enforced by the system.
02
Notices sent by email
Structured notices to the sponsor's named contacts, with read receipts and reminders before the clock runs out.
03
Approvals that can't be found at audit
Sponsor approvals and rejections recorded against the deviation, change and batch.
04
Batch record review by courier and PDF
Sponsors review the released batch documents in the portal and sign off there.
N° 03What the module covers
Scope, in plain terms.
01
Agreement rules
Per-sponsor notification windows, approval rights and contacts, taken from each quality agreement.
02
Notifications
Deviation, change, complaint and out-of-specification notices with deadlines and escalation.
03
Sponsor approvals
Approve, reject or query in the portal, with reasons recorded.
04
Batch review
Batch documents shared for sponsor review, comments and sign-off.
N° 04For each person in the decision
One page, six readers.
01
Supply chain lead
The scope above, three fixed-scope packages with prices, and a read-only Pilot you can run on one site before committing.
02
QA and validation
GAMP 5 Category 5 development documents, executed developer IQ/OQ evidence, Annex 11 and Part 11 controls in the GxP-ready package. You run and sign validation.
03
IT and your SAP team
Released SAP APIs only, no changes inside SAP, one least-privilege technical user, deployed in your own tenancy and region.
04
Sponsor-facing teams
Each sponsor sees only their own data, enforced in the data layer, with every access logged.
05
Procurement
Fixed scope and price per package, a written not-included list, and our vendor questionnaire answered in full on request.
06
Finance
The price shown is ours. SAP licences, including any SAP Digital Access for documents created in SAP, hosting and validation effort are yours and are listed as not included.
N° 05The Pilot, week by week
Eight to ten weeks, read-only from SAP.
01
Weeks 1–2: scope and access
Requirements workshop, the list of SAP APIs to be read, a technical user from your SAP team, and sample data agreed.
02
Weeks 3–5: build
The module built in your tenancy against your SAP test system, with a working demo every week.
03
Weeks 6–7: your data
Connected to the agreed SAP data, tested by your users, findings fixed.
04
Weeks 8–10: live on one site
Go-live for up to 25 users, a handover session, and a written decision paper for the Production package.
N° 06Your three options
Inside SAP, packaged, or beside SAP.
01
Customise inside SAP
Done by your SAP partner. SAP's clean-core rule limits extensions to released APIs and extension points, and each change follows your SAP change and validation process.
02
Buy a packaged product
A vendor's standard product and roadmap, with its own licence, validation package and integration to your SAP.
03
Build beside SAP (this page)
An app scoped to your process, in your tenancy, connected through released SAP APIs, with the source code and documentation handed to you.
N° 07AI assists
Where AI helps, and where a person decides.
Designed to the draft EU GMP Annex 22: predictive models are static, versioned and show their confidence; generative tools only draft for a person to confirm. No assist releases, rejects or ships a lot.
01
Notice drafting
A draft sponsor notice written from the deviation record, for QA to edit and send. Generative, non-critical, a person approves every word.
02
Deadline risk
A static model flags open items likely to miss their window, with confidence, so they are chased first.
N° 08Investment
Pilot, production, or GxP-ready.
Pilot
From $30,000
One site, read from SAP through released APIs, live in 8–10 weeks.
- Agreement rules and deviation notifications for up to three sponsors
- Batch and material data read from SAP so each notice names the affected lots
- Read-only connection to SAP S/4HANA (OData APIs and CDS views), no core changes
- Audit trail on every record, role-based access, SSO with your identity provider
- One site, up to 25 named users
- Not included: write-back to SAP, electronic signatures, validation documentation, SAP BTP licences
Production
From $50,000
Two-way with SAP and one more plant system, across sites.
- Everything in Pilot
- Change approvals and batch record review
- Events pulled from your QMS and SAP QM notifications automatically
- Two-way integration through SAP APIs or SAP Integration Suite, clean-core compliant
- Digital Access check with your SAP licence team before any write-back is switched on
- Up to three sites and 250 users
- 60 days of hypercare after go-live
- Not included: validation documentation, SAP or BTP licences (including any SAP Digital Access your contract requires for documents created in SAP), SAP-side configuration by your SAP partner
GxP-ready
From $80,000
Built and documented for GMP use.
- Everything in Production
- 21 CFR Part 11 / EU Annex 11 electronic signatures and record controls
- GAMP 5 Category 5 SDLC pack: URS trace matrix, FS/DS, code review records
- IQ/OQ scripts with executed developer evidence; change control for later releases
- Not included: validation execution and QA sign-off (your CSV team), hosting qualification, SAP licences
Before you buy
What you get
- An independent build that connects to SAP only through SAP's released APIs
- A read-only Pilot that creates nothing in SAP, so it carries no SAP licence exposure
- Delivery alongside your SAP partner and IT, who keep control of SAP itself
What we don’t do
- SAP licences, or SAP Digital Access for documents a two-way build creates in SAP
- Changes to your SAP configuration or custom code inside SAP
- SAP certification of the integration, unless you ask us to scope it in
DesignKompanie is an independent studio and is not affiliated with, endorsed by or a partner of SAP SE. SAP and SAP S/4HANA are trademarks of SAP SE.
N° 09Questions
The answers we give most often.
- Does this replace our QMS?
- No. Deviations, CAPAs and change control stay in your QMS. This covers the sponsor-facing step: telling them on time and capturing their decision.
- How are sponsors kept separate?
- Every notice and document belongs to one sponsor, enforced in the data layer; a sponsor only ever sees their own.
- Can it work without SAP write access?
- Yes. It only needs to read batch and material data from SAP, so it carries no SAP Digital Access exposure.
- Are you an SAP partner?
- No. We are an independent studio. We build beside SAP using its released APIs and work with your SAP partner, who stays responsible for SAP itself. If you need the integration certified by SAP, we scope that into the project.
N° 10Related
- Pharma supply chain apps for SAP S/4HANA
- Security, validation & your SAP partner
- Sponsor portal & client-owned material
- Cross-system batch genealogy
- Cold chain & excursion evidence
- Control tower across SAP, MES and LIMS
- GMP warehouse floor app for SAP
- Campaign material planning for SAP
- Supplier CoA intake for SAP QM
- Tech transfer workspace
- AI assist layer
- Enterprise app development
Start your book
Planning the Sponsor quality notifications & approvals build?
Tell us your sites, the systems you run and what has to change. You'll get a scoped plan and a fixed price within two business days.
