Risk Assessment
Seal's Validation Risk Assessment is a systematic approach to identifying, evaluating, and mitigating potential risks that could compromise the integrity, safety, and efficacy of a process or product. The risk assessment distinguishes high-risk elements that require stringent controls from lower-risk components, for a basic, unconfigured Seal platform.
The following pages documents particular risks that Seal could present given a basic, unconfigured architecture. For each risk, a brief explanation, the inherent risk level, the treatment, and the residual risk is provided.
The risk assessment is conducted for an unconfigured Seal Platform. This does not serve as legal counsel as a risk assessment for a customised platform. Customers should risk assess their own business processes in how they utilise Seal and its features and functions, and the impact on product safety and risks.
For more information or to export this for your documentation, please reach out to our team at support@seal.run.
Customer Risks
Customer lack of understanding Lack of support channels to help the Customer achieve its goals or report and issue
User guides and documentation
Customer communication channel Lack of support channels to help the Customer achieve its goals or report and issue
User Guides & communication channels
Data Integrity Not maintaining data integrity on the platform (input or output)
Project Quality and Product Plan
Governance Risks
Breaches and Incidents Not proper identification or evaluation of breaches and incidents
Data Backup and Disaster Mitigation
Fraud Prevention Lack of proper controls to prevent fraudulent activities
Information Security Policy
System changes Lack of proper controls to prevent fraudulent activities by making unauthorised changes to the system and/or infrastructure
Information Security Policy
Project Quality and Product Plan
Regulatory Risks
Data Breach Individuals affected by a breach of their personal information
Information Security Policy
Data Backup and Disaster Mitigation
Audit Trail Continuity Loss of data and data entries in the audit log
Validation process
Project Quality and Product Plan
Data Privacy Personal information is collected and used not following privacy obligations
Project Quality and Product Plan
Data Backup and Disaster Mitigation
Technology Risks
Storage Protection Unauthorised access to the platform or the information
Information Security Policy
Firewall Unauthorised connections due to the lack of firewall controls
GCP is the cloud hosting provider, risk transferred
Authorised Changes Unauthorised changes to the platform architecture
Information Security Policy
Internal employee platform
Physical Security Unauthorised physical access to the platform
Opvia is a cloud solution hosted on Google’s servers
Network protection Lack of proper network protection permitting vulnerabilities or unauthorised access
Information Security Policy
The risk assessment presents an overall maximum risk rating of low. Based on the assessment, an unconfigured Seal platform is considered to be a medium risk.
The Seal Platform is used for sample management and quality management; including document control and quality events. Seal's aims to replace physical records and activities related to physical records.
Last updated