Cloud Computing

Moving Factory Workflows to the Cloud Changes the Compliance Problem

On this page

Moving a factory’s workflows into the cloud tends to leave the compliance burden about the same size while changing almost everything about its shape. On-premises, compliance mostly meant keeping records safe and keeping a validated system untouched. In the cloud, it means proving control over software that someone else runs and updates, in a building you’ll probably never see. Plants that treat the move as an IT project with a compliance sign-off at the end risk learning this during an inspection.

The old setup had a kind of physical honesty. The quality system lived on a server in a closet near the quality office, sometimes on an operating system its maker had stopped supporting, and everyone tolerated that because changing it meant validating it again. When an auditor arrived, somebody walked them to a shelf of binders. You could point at every piece of proof the plant owned, and it stayed where it had been left.

What Regulators Now Ask of Cloud Software

Regulators appear to have moved past that picture. The FDA’s revised guidance on software assurance for production and quality systems, reissued in February for medical device makers, says cloud software used in production or quality work must be validated for its intended use, whatever the service model. It lets manufacturers lean on a vendor’s own testing and independent audit reports, and it concedes that auditing a software supplier in person may not be feasible. That flexibility is welcome, but the manufacturer still owns the validated state, often seeing it only through documents the vendor chooses to share.

The stronger platforms seem to understand that a record of what the software did is now part of what they sell. Redzone, for example, builds its AI-assisted factory operations around logging and tracing whatever its agents recommend or do, and around keeping each plant’s data inside that customer’s own environment. That’s the right instinct, and it also raises the bar for the people running the plant. Once software suggests a changeover or opens a quality task on its own, an inspector will reasonably expect someone at the plant to have read the log of what it did and why.

In one respect, the cloud does make compliance easier, and the FDA’s guidance points the same way by preferring system logs and audit trails over screenshots and paper. The catch is volume. A plant that once hunted for a missing signature can end up with a record of everything, which helps only the person who knows which lines matter. A practical first step is to list every cloud feature that creates or changes a quality record and name the person who reviews its logs.

Your Vendor Now Sits Inside the Regulated Perimeter

Europe has pushed the logic further. The NIS2 directive, which covers many makers of machinery, vehicles, electronics and medical devices, lists supply chain security among the measures in-scope companies must take, including their relationships with direct suppliers and service providers. Applied to a cloud migration, that clause arguably makes a software subscription part of the regulated perimeter. Questions about the vendor’s development practices and incident history can land on the customer’s desk, whatever obligations the vendor carries on its own account.

National rollout has been uneven, which made it easy to treat the clause as theoretical. That gets harder now that the Commission has taken four member states to the EU’s top court over missed deadlines, while most of the others have already written the directive into national law.

How much of that perimeter a plant can see depends on which cloud service model it signed up for. Rent bare servers and the plant still patches its own applications. Subscribe to a finished application and nearly everything below the login screen belongs to the vendor, including the timing of changes. Before signing, ask for advance notice whenever an update touches a validated function, along with release notes detailed enough to review. A preview environment where your team can test changes first is worth pushing for, too.

Updates and AI Models Unsettle the Frozen System

Updates are where the old compliance model tends to strain. Validation used to assume a frozen system, tested once and then left alone, sometimes for years. A vendor that ships changes every few weeks makes freezing impossible, and the FDA’s own example of a subscription tool accepts this by having the vendor document each automatic update while the manufacturer assesses its effect. In practice, that works only if someone in quality owns the release notes and has time to read them.

Machine learning raises a harder question. Draft EU rules on AI in medicine manufacturing, still under revision, would bar models that continue learning during use from critical applications with a direct effect on product quality, patient safety or data integrity. The draft also expects manufacturers to review model documentation even when a supplier built the model. A model that ranks downtime causes probably sits outside that critical category, while one that decides whether a batch passes inspection falls squarely inside it. It’s worth asking every AI vendor whether its model is locked after testing or keeps adapting to new data.

Plan for the Day the Region Goes Dark

Almost a year ago, a timing flaw in the automation that keeps one of Amazon’s core database services reachable wiped that service’s address in its Northern Virginia region. The provider’s own post-event summary traces knock-on failures across roughly fourteen and a half hours, with parts of the repair done by hand. If your batch records or work instructions had depended on services in that region, the damage could have gone beyond lost production time.

Records that must be available on request might simply not have been. A read-only copy of the records an inspector is most likely to ask for, refreshed on a schedule and stored outside the primary region, is cheap insurance. A short outage drill helps too. Could the plant produce last week’s batch records if the vendor went dark this morning?

Custody Was Never the Same as Control

None of this makes the closet server look safer. Standard comparisons of on-premise and cloud setups point out that keeping data in-house simplifies regulatory control, and on the narrow question of physical custody they’re right. Custody was never the whole of control, though. Plenty of plants kept validated systems running on software too old to patch and called the result compliant because nothing had changed.

The threat data suggests that comfort was misplaced. Dragos’s 2026 OT cybersecurity year in review counted about 3,300 industrial organizations hit by ransomware in 2025, with manufacturers making up more than two-thirds of the victims. It also found that a quarter of the industrial security advisories it tracked came with no patch or mitigation at all. Moving to the cloud swaps that old comfort for a different belief, that a vendor’s certifications amount to the customer’s own control. Both beliefs deserve more scrutiny than they usually get.

Settle the Exit Before You Sign

The second belief is harder to see through, which is why the order of a migration matters. Guides to on-premise to cloud migration sensibly flag security and compliance as risks to manage along the way. In a regulated plant they probably belong at the very start, next to an exit question few buyers raise before signing. When the contract ends, in what form do the records come back?

Retention rules make that question urgent. The FDA’s electronic records rule in 21 CFR Part 11 expects records to stay retrievable throughout their retention period and audit trails to be kept at least as long as the records they describe. A flat export with the audit trail stripped off can’t show who changed a value or when. Run a test export once a year and check that the history comes with it.

European buyers now have more room to negotiate. Since September 2025, the EU Data Act has required cloud providers to support switching, including data export in a commonly used, machine-readable format for software and platform services, and it removes switching and data egress charges entirely from January 2027. It also expects providers to publish how they protect non-personal data held in the EU from unlawful foreign government access.

Before the Next Inspector Calls

The plant that moves its workflows to the cloud usually ends up with better evidence and less bargaining power, a trade many operations leaders would accept if it were explained before signing. If you’re planning a migration or renewal, compare your list of cloud features that touch quality records against the contract’s update and exit terms. The gaps are where inspection findings tend to start. You’ll still sign the same line as always, only now for records produced by software that changed last month. Whether that signature carries its old weight is an open question, and it’s worth settling your side of it first.

Leave a Reply

Your email address will not be published. Required fields are marked *

Chat on WhatsApp