How to Follow GDP During IQ, OQ and PQ in Pharma Industry

Part 14

The governing principle is:

If an activity was performed during qualification, the qualification record should provide reliable, attributable, contemporaneous and traceable evidence of what was actually done and what actually occurred.

The source also emphasizes that final qualification documentation should provide objective, contemporaneous, traceable and scientifically justified evidence supporting fitness for intended GMP use.


14.1 What Is Good Documentation Practice?

Good Documentation Practice (GDP) in qualification means applying controlled practices so that records accurately and reliably represent:

  • what activity was performed;
  • who performed it;
  • when it was performed;
  • what equipment/system was tested;
  • what test instruments were used;
  • what conditions existed;
  • what results were obtained;
  • what raw evidence was generated;
  • whether acceptance criteria were met;
  • what unexpected events occurred;
  • how errors were corrected;
  • what deviations were raised;
  • who reviewed the evidence.

GDP is not simply about handwriting quality.

It is fundamentally about data integrity and evidentiary reliability.


14.2 Qualification Documentation as GMP Evidence

Consider the qualification lifecycle:

Approved Protocol

Execution

Actual Observations

Raw Data

Attachments / Electronic Evidence

Deviations

Review

Traceability

Qualification Conclusion

If execution records are incomplete or unreliable, the final qualification conclusion becomes difficult to defend.


14.3 Why GDP Is Critical During Qualification

Qualification testing may generate evidence supporting decisions concerning:

  • equipment release;
  • facility release;
  • utility release;
  • computerized-system acceptance;
  • GMP operation;
  • process validation;
  • cleaning validation;
  • requalification.

Poor documentation can therefore create uncertainty about whether the system was actually demonstrated to be fit for intended use.


14.4 Core Data-Integrity Principle — ALCOA+

Your source specifically requires ALCOA+ to be addressed during qualification execution.

ALCOA commonly represents:

PrincipleMeaning
A — AttributableWho performed or recorded the activity?
L — LegibleCan the record be read and understood?
C — ContemporaneousWas it recorded when the activity occurred?
O — OriginalIs it the original record or appropriately controlled true copy/equivalent?
A — AccurateDoes it correctly represent what occurred?

The commonly used “+” principles include:

  • Complete
  • Consistent
  • Enduring
  • Available

These principles should apply throughout the data lifecycle.


14.5 Attributable

Qualification data should be attributable to the individual who performed or recorded the activity.

For example:

TestResultExecuted ByDate
Emergency-stop challengePassRSP/signature30-Jul-2026

A reviewer should be able to determine who generated the result.


14.6 Attribution in Electronic Systems

Electronic qualification records may use:

  • unique user IDs;
  • authenticated electronic signatures;
  • system-generated audit trails;
  • controlled workflows.

Shared accounts can undermine attribution.

For computerized and automated systems, your source separately identifies user-role matrices, access-control testing, audit-trail assessment/testing, security and electronic-record controls as potentially required.


14.7 Legible

Records should remain readable throughout their required retention period.

Problems include:

  • illegible handwriting;
  • faint printouts;
  • damaged thermal-paper records;
  • obscured corrections;
  • cropped screenshots;
  • poor-quality photocopies;
  • unclear units.

A record that cannot be interpreted cannot reliably support the qualification conclusion.


14.8 Contemporaneous Documentation

This is one of the most important principles in Part 14.

Qualification observations should be recorded when the activity is performed or observed, according to the applicable procedure.

Correct sequence:

Perform Test → Observe Result → Record Result

Not:

Perform Many Tests → Remember Results → Reconstruct Documentation Later


14.9 Why Contemporaneous Recording Matters

Suppose 35 alarm tests are performed during OQ.

If results are entered into the protocol two days later from memory, questions arise:

  • Were all alarms actually tested?
  • Were any failures forgotten?
  • Were exact alarm messages captured?
  • Were actual times known?
  • Were unexpected observations omitted?

Contemporaneous recording substantially reduces these risks.


14.10 Original Records

Qualification evidence may originate from:

  • executed protocol entries;
  • instrument-generated records;
  • electronic systems;
  • laboratory systems;
  • data loggers;
  • SCADA;
  • PLC/HMI reports;
  • printouts;
  • photographs where appropriate;
  • screenshots;
  • calibration systems.

The applicable original record or appropriately controlled representation should remain identifiable and retrievable.


14.11 Accurate

Qualification records should correctly reflect what actually occurred.

For example:

Setpoint:

50 rpm

Actual calibrated reference measurement:

49.7 rpm

Record:

49.7 rpm

Do not record:

50 rpm

merely because 50 rpm was the expected result.


14.12 Complete

Qualification records should include relevant data—including results that do not meet expectations.

A complete record should not selectively retain:

  • only passing runs;
  • only final readings;
  • only successful screenshots;
  • only successful retests.

Failed and unexpected results are part of the qualification history.


14.13 Consistent

Data should follow the expected chronological and logical sequence.

Example:

Protocol approved

Test executed

Deviation identified

Investigation

Correction

Retest authorized

Retest performed

An unexplained sequence such as a retest occurring before the associated deviation was assessed may require investigation.


14.14 Enduring

Qualification evidence should be recorded and retained in durable controlled media appropriate to the record type.

Examples may include:

  • controlled paper records;
  • validated/qualified electronic systems;
  • approved electronic repositories;
  • controlled archival systems.

Temporary or easily lost media should not become the only evidence supporting critical qualification conclusions.


14.15 Available

Qualification records should remain retrievable when needed for:

  • protocol review;
  • qualification summary;
  • deviation investigation;
  • change control;
  • requalification;
  • periodic review;
  • internal audit;
  • regulatory inspection.

An inspector may ask for historical qualification evidence many years after initial installation.


14.16 ALCOA+ Applied to Qualification

PrincipleQualification Example
AttributableExecutor signs test
LegibleRecorded result is readable
ContemporaneousReading entered during execution
OriginalInstrument output retained
AccurateActual value recorded
CompleteFailed results retained
ConsistentDates/events follow logical order
EnduringEvidence stored in durable controlled record
AvailableQualification package retrievable

14.17 Paper Qualification Records

Where paper protocols are used, the organization should control:

  • protocol issuance;
  • revision;
  • page identification;
  • entries;
  • corrections;
  • signatures;
  • attachments;
  • unused fields;
  • reconciliation;
  • archival.

The specific method should follow the site’s controlled documentation procedure.


14.18 Permanent Ink

Your source specifically asks that permanent ink where paper records are used be addressed.

Where required by the site’s procedure, entries should be made using permanent, indelible ink suitable for maintaining the integrity and legibility of the record.

Avoid documentation methods that allow entries to be:

  • erased;
  • removed;
  • changed without evidence;
  • rendered unreadable.

The source does not prescribe a particular ink color, so any such color requirement would be company-specific.


14.19 Pencil

Pencil is generally unsuitable for controlled GMP execution records where it permits erasure without preserving the original entry.

The key principle is:

Original data and corrections must remain traceable.

Specific documentation requirements should follow the site’s approved GDP procedure.


14.20 Date Entries

Dates should be recorded according to the approved site format.

A good date format should avoid ambiguity.

For example:

30-Jul-2026

is less ambiguous internationally than:

07/30/26

or

30/07/26

The exact required format remains company-specific.


14.21 Time Entries

Where time is relevant to the qualification evidence, record it contemporaneously.

Examples include:

  • stabilization periods;
  • recovery testing;
  • hold times;
  • alarm activation;
  • backup duration;
  • power-failure recovery;
  • sampling;
  • environmental monitoring;
  • water-system studies.

Example:

ActivityStartEnd
Stabilization10:1510:45

Time-zone or clock-source considerations may also matter for computerized systems.


14.22 Signatures and Initials

Signatures/initials should identify responsible personnel according to the site’s approved system.

Typical qualification roles include:

  • executor;
  • witness;
  • reviewer;
  • verifier;
  • approver.

Do not sign for work performed by another individual unless a controlled procedure explicitly defines the nature of that verification.


14.23 Pre-Signing Is Unacceptable

Your source explicitly lists pre-signing as an unacceptable practice.

Example:

An engineer signs:

Executed By: John / 30-Jul-2026

before actually performing the test.

This creates a record claiming that an event has occurred when it has not.


14.24 Corrections to Paper Records

Errors can occur during execution.

The objective of a GDP-compliant correction is to:

  1. preserve the original entry;
  2. identify the corrected information;
  3. attribute the correction;
  4. date the correction;
  5. provide a reason where required by procedure or where the reason is not obvious.

14.25 Example of a Paper Correction

Suppose the actual result was accidentally recorded as:

45.8 rpm

but the source reading was 48.5 rpm.

A controlled correction should preserve the incorrect original entry rather than erase or obliterate it, with the corrected value entered and the correction appropriately attributable/date-controlled.

Conceptually:

45.8 48.5 rpm — initials/date — transcription error

The exact correction notation should follow the site’s approved GDP SOP.


14.26 Do Not Obliterate Original Entries

Avoid correction methods that prevent reconstruction of the original entry.

Examples:

  • correction fluid;
  • erasing;
  • scratching until unreadable;
  • overwriting digits;
  • blacking out original values.

The reviewer should be able to understand:

Original Entry → Correction → Corrected Entry


14.27 Unexplained Overwriting

Your source specifically identifies unexplained overwriting as an unacceptable practice.

Example:

Original:

25.4

changed by writing over the “5” until it looks like:

28.4

This obscures the original result.

A transparent correction is preferable.


14.28 Corrections to Executed Protocols

Your source separately requires discussion of corrections to executed protocols.

A distinction should be maintained between:

Data-entry correction

Example: transcription error.

Protocol instruction error

Example: incorrect test step.

Acceptance-criterion problem

Example: incorrect limit in the approved protocol.

Design/system problem

Example: machine does not behave as specified.

Not all of these should be handled as simple GDP corrections.


14.29 GDP Correction vs Protocol Deviation

A useful decision model is:

Is the issue only an obvious documentation-entry error?

→ Correct according to GDP.

Does it change the approved test method, expected result or acceptance criterion?

→ Assess under the applicable protocol deviation/amendment/change process.

Does the equipment/system fail?

→ Document the failure and assess under deviation management.

Do not use a simple handwriting correction to bypass deviation/change control.


14.30 Blank Fields

Unexplained blank fields create uncertainty.

A reviewer may not know whether the field was:

  • forgotten;
  • not applicable;
  • not tested;
  • intentionally omitted;
  • awaiting completion.

Where required by the applicable procedure, unused fields should be appropriately addressed rather than left unexplained.


14.31 N/A Entries

If a field or test is not applicable, record N/A or the site’s approved equivalent where appropriate.

But N/A should not become a mechanism for avoiding required testing.

Example:

Test: Audit Trail Verification
Result: N/A

This requires justification if the system generates GMP-relevant electronic records and audit-trail functionality is applicable.


14.32 N/A Should Be Justifiable

A strong N/A disposition should answer:

Why does this requirement/test not apply?

For example:

N/A — Equipment has no computerized control or electronic GMP-record functionality within the qualification scope.

Where significance warrants, reference the applicable system assessment.


14.33 Raw Data

Raw data are fundamental qualification evidence.

Examples include:

  • actual measurements;
  • instrument output;
  • printouts;
  • electronic files;
  • system logs;
  • alarm histories;
  • audit trails;
  • trend data;
  • test reports;
  • photographs where justified;
  • laboratory results.

The source’s final inspection-readiness checklist specifically requires raw data to be retained during execution.


14.34 Actual Data vs Check Marks

Suppose the acceptance criterion is:

Differential pressure: 10–15 Pa.

Weak record:

✓ Pass

Stronger record:

Actual result: 12.4 Pa

Acceptance: 10–15 Pa

Status: Pass

The actual measurement demonstrates why the test passed.


14.35 Do Not Record Only Expected Results

A qualification protocol might contain:

Expected result: Speed = 40 ± 2 rpm.

The executor must record the actual observed value, not simply copy:

40 ± 2 rpm

into the actual-result field.

Expected results and actual results have different purposes.


14.36 Attachments

Attachments may include:

  • calibration certificates;
  • drawings;
  • printouts;
  • screenshots;
  • raw-data sheets;
  • photographs;
  • reports;
  • instrument outputs;
  • alarm lists;
  • trend data.

Attachments should remain traceable to the relevant qualification test.


14.37 Attachment Control

A practical attachment record may include:

FieldExample
ProtocolOQ-TCM-001
TestOQ-017
AttachmentOQ-017-A01
DescriptionAlarm history
Pages1 of 3 to 3 of 3
Generated by___
Date___

The exact format depends on the site’s documentation system.


14.38 Uncontrolled Attachments

The source later identifies uncontrolled attachments as a common qualification deficiency.

Examples include:

  • loose printouts with no protocol reference;
  • screenshots with no test identification;
  • unidentified handwritten notes;
  • missing pages;
  • documents whose origin cannot be established.

An attachment should be understandable even when reviewed later.


14.39 Printouts

Equipment and computerized systems may generate:

  • alarm reports;
  • batch reports;
  • parameter reports;
  • trend reports;
  • audit trails;
  • test reports.

Where printouts form part of qualification evidence, they should be identifiable and linked to the applicable test.


14.40 Printout Identification

Depending on site procedures and system capabilities, consider:

  • equipment/system;
  • date/time;
  • report type;
  • test number;
  • page count;
  • executor identification;
  • attachment reference.

If a printout does not automatically identify its source, controlled annotation may be needed according to procedure.


14.41 Thermal Printouts

Some instruments produce records that fade over time.

Where such records are required as GMP evidence, the organization should have an appropriate method to ensure the information remains enduring and retrievable according to its record-control procedures.

The source does not prescribe a specific copying/scanning method, so this should remain site-defined.


14.42 Electronic Records

Qualification may generate electronic records in:

  • SCADA;
  • DCS;
  • MES;
  • LIMS;
  • BMS/EMS;
  • HMI;
  • data loggers;
  • electronic validation systems;
  • electronic document systems.

Electronic evidence should be controlled according to its GMP relevance and intended use.


14.43 Electronic Records Are More Than Screenshots

A screenshot may show what appeared on a screen at one moment.

It may not necessarily capture:

  • underlying metadata;
  • audit trail;
  • complete sequence;
  • original electronic record;
  • configuration history;
  • user attribution.

Therefore, screenshots should be used appropriately rather than automatically treated as substitutes for original electronic evidence.


14.44 Screenshots

Your source specifically requires screenshots to be addressed.

A useful screenshot should provide sufficient context to establish:

  • what system was being tested;
  • what function was displayed;
  • what result was observed;
  • which test it supports.

Where relevant, record:

  • test ID;
  • system;
  • user;
  • date/time;
  • screen/function;
  • attachment reference.

14.45 Screenshot Example

For OQ user-access testing:

OQ-ACC-004

Test:

Operator attempts access to administrator configuration.

Evidence:

Screenshot showing access denied.

Attachment:

OQ-ACC-004-A01

The protocol result should reference the attachment.


14.46 Page Numbering

Page numbering supports document completeness.

Typical controlled formats may include:

Page 15 of 87

or equivalent electronic controls.

Page numbering helps detect:

  • missing pages;
  • duplicated pages;
  • substituted pages;
  • incomplete attachments.

The exact numbering method is company-specific.


14.47 Controlled Copies

Qualification should be executed using the appropriately controlled protocol/version.

Potential problems with uncontrolled copies include:

  • obsolete test steps;
  • obsolete acceptance criteria;
  • duplicate execution;
  • missing revision control;
  • inability to determine which record is official.

The protocol-control process should define issuance, reconciliation and archival where applicable.


14.48 Uncontrolled Worksheets

Your source explicitly lists uncontrolled worksheets as unacceptable.

Example:

An engineer performs testing using a personal spreadsheet, records all results there, and later transfers only passing results to the official protocol.

This creates serious questions about completeness and data integrity.


14.49 Temporary Working Notes

If temporary working records are necessary, their handling should be defined by the applicable procedure.

Do not assume that a record becomes non-GMP simply because it is called:

“rough notes”

If it contains original qualification observations/data used to support the final result, its status should be appropriately controlled.


14.50 Data Transcription

Qualification frequently requires data to be transferred from one record to another.

Examples:

  • instrument → protocol;
  • printout → summary table;
  • electronic system → qualification worksheet;
  • laboratory report → PQ table.

Transcription introduces risk of human error.


14.51 Good Transcription Practice

Where data are transcribed:

  1. preserve/reference the source;
  2. copy the value accurately;
  3. include units;
  4. maintain decimal precision appropriately;
  5. verify transcription where required by procedure/risk;
  6. correct errors transparently.

Example:

Source:

49.73 rpm

Protocol should not become:

47.93 rpm

because of a transcription error.


14.52 Direct Data Capture

Where practical and appropriately controlled, direct capture of reliable data can reduce manual transcription risk.

However, electronic automation does not automatically guarantee data integrity.

Controls remain necessary for:

  • access;
  • configuration;
  • interfaces;
  • metadata;
  • security;
  • retention;
  • backup.

14.53 Calculation Verification

Your source specifically requires calculation verification to be addressed.

Qualification calculations may include:

  • averages;
  • percentage variation;
  • standard deviation;
  • airflow;
  • air changes;
  • recovery time;
  • yield;
  • accuracy;
  • relative error.

Calculations should be correct and traceable to source data.


14.54 Example Calculation Record

For three readings:

ReadingValue
R149.8
R250.1
R350.0

Average:

[
\frac{49.8+50.1+50.0}{3}=49.97
]

A qualification record should allow a reviewer to determine:

  • input data;
  • formula/method;
  • calculated result;
  • applicable acceptance criterion.

14.55 Automated Calculations

Where spreadsheets or computerized systems perform qualification calculations, appropriate controls should reflect:

  • intended use;
  • complexity;
  • GMP impact;
  • risk.

Potential concerns include:

  • incorrect formulas;
  • hidden cells;
  • uncontrolled formula changes;
  • incorrect rounding;
  • manual overwriting.

The source does not prescribe a particular spreadsheet-validation approach in Part 14.


14.56 Second-Person Verification

Your source requires discussion of second-person verification where required.

Second-person verification may be appropriate where required by:

  • procedure;
  • protocol;
  • risk assessment;
  • criticality;
  • specific operation.

It should not become a meaningless signature exercise.


14.57 What Should the Second Person Verify?

Depending on the activity:

  • source-to-transcribed data;
  • critical calculations;
  • equipment identification;
  • critical setup;
  • challenge condition;
  • test result;
  • attachment completeness.

The verifier should understand what their signature means.


14.58 Witness vs Reviewer vs Verifier

These roles are not necessarily identical.

Witness

Observes the activity being performed.

Verifier

Independently confirms a specific item/result.

Reviewer

Reviews the completed documentation/evidence.

The site’s procedure should define responsibilities.


14.59 Backdating

Your source explicitly identifies backdating as unacceptable.

Example:

A test was performed on 30 July.

Documentation is completed on 2 August but intentionally dated 30 July to make it appear contemporaneous.

This compromises the reliability of the record.


14.60 Late Entry vs Backdating

These should not be confused.

If an entry was genuinely omitted, the appropriate approach is to handle the late entry transparently according to the site’s procedure.

Do not make the record falsely appear contemporaneous.

The documentation should preserve what actually happened.


14.61 Data Reconstruction Without Justification

The source explicitly identifies data reconstruction without justification as unacceptable.

Example:

Original OQ readings were not documented.

Two days later, personnel reconstruct values from memory and enter them as if they were original observations.

This is fundamentally different from a justified, transparent reconstruction using reliable source records.


14.62 Data Reconstruction Decision

If original protocol entries are missing:

Is reliable source data available?

If yes:

→ Assess according to procedure.

→ Document that the entry is reconstructed/late.

→ Reference the source.

→ Evaluate impact.

If no:

→ Do not invent values.

→ Assess whether retesting or deviation/investigation is necessary.


14.63 Discarding Failed Results

Your source explicitly identifies discarding failed results as unacceptable.

Example:

Run 1 = Fail

Run 2 = Fail

Run 3 = Pass

Final protocol contains only:

Run 3 = Pass.

This destroys the true qualification history.


14.64 Correct Failure History

The evidence should preserve:

Initial Test

Failure

Deviation

Investigation

Correction/CAPA

Approved Retest

Retest Result

Final Assessment

This provides a scientifically defensible record.


14.65 Repeating Tests Until They Pass

Also explicitly prohibited by the source as an unacceptable practice is:

Repeating tests until they pass without investigation.

This practice is sometimes described as testing into compliance.

A failure should trigger appropriate assessment—not repeated attempts until an acceptable number appears.


14.66 Example — Speed Failure

Acceptance criterion:

20.0 ± 1.0 rpm

Initial result:

22.4 rpm — FAIL

Incorrect:

Repeat → 21.8 → Repeat → 20.9 → PASS → record only 20.9.

Correct lifecycle:

22.4 Fail → Document → Investigate → Determine Cause → Correct → Authorize Retest → Retest → Evaluate


14.67 Copying Previous Qualification Results

Your source explicitly identifies:

Copying previous qualification results without execution

as unacceptable.

Example:

Previous requalification:

Speed = 49.8 rpm.

Current protocol:

49.8 rpm copied into current result without performing the test.

This creates false evidence of execution.


14.68 Previous Qualification Data Can Still Be Useful

Historical data may legitimately support:

  • risk assessment;
  • test planning;
  • trending;
  • requalification scope;
  • comparison.

But historical results should not be represented as newly executed test results.


14.69 Common GDP Deficiencies During Qualification

DeficiencyPotential Concern
Blank fieldsCompleteness uncertain
Missing datesTiming unclear
Missing signaturesAttribution unclear
Illegible entriesEvidence cannot be interpreted
Pencil/erasable entriesOriginal data may be altered
OverwritingOriginal result obscured
Missing raw dataPass result unsupported
Unidentified printoutEvidence not traceable
Uncontrolled worksheetOriginal data may be incomplete
Late reconstructionContemporaneousness compromised
Discarded failuresCompleteness compromised
Repeated testing without investigationTesting into compliance
Copied previous resultsFalse evidence
Missing attachmentsEvidence incomplete
Wrong protocol revisionExecution basis uncertain

14.70 Data Integrity Decision Tree

Qualification Data Generated
          ↓
Was it recorded contemporaneously?
       ┌──────┴──────┐
      YES            NO
       │              ↓
       │       Is reliable source
       │       evidence available?
       │          ┌───┴───┐
       │         YES      NO
       │          │        │
       │      Assess/     Deviation/
       │      document    impact assessment
       │      transparently
       ↓
Is evidence attributable?
       ↓
Is original/source retained?
       ↓
Is record complete?
       ↓
Are corrections traceable?
       ↓
Are failures/deviations retained?
       ↓
Is evidence reviewable/retrievable?
       ↓
QUALIFICATION EVIDENCE ACCEPTABLE

14.71 GDP During IQ

During IQ, GDP applies particularly to:

  • equipment IDs;
  • component IDs;
  • serial numbers;
  • materials;
  • instrument IDs;
  • calibration status;
  • drawings;
  • software versions;
  • certificates.

Do not write:

“All instruments calibrated — Pass”

if individual instruments are supposed to be verified and identified.


14.72 GDP During OQ

OQ generates extensive functional evidence.

Particular attention should be given to:

  • actual parameter values;
  • alarm challenges;
  • interlock results;
  • failure modes;
  • user access;
  • recipes;
  • audit trails;
  • backup/restore;
  • electronic records.

Your source requires OQ to address these functions where applicable.


14.73 GDP During PQ

PQ documentation may include:

  • operating conditions;
  • load;
  • material;
  • operators;
  • parameter values;
  • samples;
  • laboratory results;
  • run duration;
  • deviations;
  • reproducibility data.

Your source requires PQ to consider approved procedures, trained operators, materials, operating ranges, load configurations, sampling, acceptance criteria and deviations.


14.74 Example — Proper OQ Entry

Test

Turret Speed Verification

Setpoint

50 rpm

Reference Instrument

Tachometer ID: TAC-014

Calibration Due

15-Dec-2026

Actual Reading

49.8 rpm

Acceptance Criterion

Approved protocol criterion

Result

PASS

Executor

Name/signature/date

Evidence

Attachment OQ-SPD-004-A01

This provides substantially stronger evidence than:

Speed checked — OK.


14.75 Example — Alarm Test Documentation

AlarmChallengeExpectedActualEvidenceResult
Guard OpenOpen guardDefined machine responseResponse observed as specifiedATT-07Pass
Low LubricationSimulated approved conditionAlarm + defined responseRecordedATT-08Pass
Emergency StopActivate E-stopSafe defined responseRecordedATT-09Pass

Actual wording and acceptance criteria should come from the approved qualification protocol.


14.76 Documentation of Unexpected Observations

Not every unexpected observation is automatically a critical deviation.

However, it should not simply disappear.

Ask:

Does the observation affect the test method?

Does it affect acceptance criteria?

Does it indicate equipment malfunction?

Does it affect another test?

Does it affect GMP/data integrity?

Does it require deviation assessment?

Part 15 addresses this in detail.


14.77 Responsibilities

A typical allocation may be:

RoleGDP Responsibility
ExecutorContemporaneous and accurate entries
Witness/VerifierVerify defined critical activity/data
ValidationEnsure protocol/evidence completeness
EngineeringSupport technical evidence
Automation/ITSupport electronic evidence
QAIndependent GMP/data-integrity oversight
ReviewerDetect inconsistencies/gaps before closure

Actual responsibilities should follow the company’s PQS.


14.78 Reviewer Responsibilities

The reviewer should check more than signatures.

Review should include:

  • Were tests executed completely?
  • Are actual results recorded?
  • Are units present?
  • Are calculations correct?
  • Are attachments present?
  • Are corrections GDP compliant?
  • Are failures documented?
  • Are deviations linked?
  • Are retests justified?
  • Are dates chronologically logical?
  • Are signatures attributable?
  • Is the evidence sufficient to support pass/fail?

14.79 Inspector Perspective — “Show Me the Raw Data”

Your source specifically anticipates inspectors asking:

What raw data supports this result?

A strong qualification package can move directly from:

Protocol Test

Actual Result

Raw Data

Attachment/Electronic Record

Acceptance Criterion

Pass/Fail Conclusion


14.80 Inspector Perspective — Corrections

An inspector seeing many corrected entries may assess:

  • Are originals visible?
  • Who made the correction?
  • When?
  • Why?
  • Is there a pattern?
  • Were results altered after review?
  • Are corrections consistent with procedure?

A correction is not inherently a problem.

An unexplained or nontransparent correction may be.


14.81 Inspector Perspective — Repeated Testing

An inspector seeing:

Test 1 — Fail
Test 2 — Fail
Test 3 — Pass

will reasonably ask:

Why was the test repeated?

What caused the failures?

Where is the deviation?

Who authorized the retest?

What changed before the passing result?

The source specifically lists “Who approved the re-test?” and “How were qualification failures investigated?” among expected inspection questions.


14.82 Inspector Perspective — Electronic Evidence

For computerized equipment, an inspector may compare:

Paper Protocol

with:

Electronic System Record

and ask whether:

  • timestamps agree;
  • user attribution agrees;
  • audit trail shows changes;
  • reported result matches original data;
  • records remain available.

Paper documentation should not contradict the electronic source.


14.83 GDP Review Checklist — Before Execution

The source’s final inspection-readiness checklist specifically identifies the following pre-execution controls: approved protocol, approved URS, completed risk assessment, justified acceptance criteria, current calibration, available drawings, completed prerequisites and trained personnel.

Therefore verify:

  • □ Correct approved protocol
  • □ Correct revision
  • □ Equipment/system identified
  • □ Required URS available
  • □ Risk assessment available
  • □ Acceptance criteria predefined
  • □ Prerequisites complete
  • □ Test instruments identified
  • □ Calibration current
  • □ Drawings/specifications available
  • □ Personnel trained
  • □ Controlled protocol issued

14.84 GDP Review Checklist — During Execution

Your source specifically calls for: contemporaneous entries, retained raw data, documented deviations, actual results, attached evidence, identified test personnel and GDP-compliant corrections.

Check:

  • □ Entries contemporaneous
  • □ Actual results recorded
  • □ Numerical values recorded where required
  • □ Units recorded
  • □ Date/time entered where applicable
  • □ Executor identified
  • □ Test instruments identified
  • □ Raw data retained
  • □ Printouts controlled
  • □ Screenshots traceable
  • □ Attachments identified
  • □ Corrections transparent
  • □ Blank fields addressed
  • □ N/A justified where necessary
  • □ Failures retained
  • □ Deviations initiated when required
  • □ Retesting controlled

14.85 GDP Review Checklist — Before Closure

  • □ All protocol pages accounted for
  • □ All tests completed/dispositioned
  • □ All actual results recorded
  • □ All attachments reconciled
  • □ All raw data available
  • □ Calculations verified
  • □ Required second-person verification completed
  • □ Deviations linked
  • □ Failed tests retained
  • □ Retests justified
  • □ Corrections reviewed
  • □ Traceability updated
  • □ Outstanding issues assessed
  • □ Protocol summary completed
  • □ Required review/approval completed

The source’s broader closure checklist also requires deviations to be resolved or appropriately dispositioned, retests justified, traceability completed, outstanding risks evaluated, SOPs/training completed, summary report approved and QA release documented where required.


14.86 Eight Unacceptable Practices Required by the Source

Part 14 explicitly identifies eight practices that must be addressed.

Unacceptable PracticeWhy It Is a Concern
BackdatingCreates a false chronology
Pre-signingClaims completion before activity occurs
Unjustified data reconstructionOriginal contemporaneous evidence may be absent
Uncontrolled worksheetsCompleteness/integrity uncertain
Unexplained overwritingOriginal entry obscured
Discarding failed resultsRecord becomes incomplete/biased
Repeat until pass without investigationMay constitute testing into compliance
Copying previous results without executionCreates false evidence of current execution

14.87 Documentation Red Flags

An inspection-ready review should investigate patterns such as:

Perfectly identical handwriting/results across different days

Many tests signed at exactly the same time

Protocol approval after execution

Missing original printouts

Only successful screenshots retained

Multiple unexplained retests

No failed data despite known deviations

Copied historical values

Different ink/handwriting without attribution

Electronic timestamps inconsistent with paper entries

Missing pages

Loose unidentified attachments

These do not automatically prove misconduct, but they warrant appropriate assessment.


14.88 Good Documentation Practice Flow

APPROVED PROTOCOL
        ↓
Controlled Execution
        ↓
Observe Activity / Measurement
        ↓
Record Contemporaneously
        ↓
Retain Original / Raw Evidence
        ↓
Attribute Entry
        ↓
Acceptance Criterion Comparison
        ↓
      Result
     ↙      ↘
  PASS      FAIL
   ↓          ↓
Document   Document Failure
   ↓          ↓
   │       Deviation/
   │       Assessment
   │          ↓
   │      Investigation
   │          ↓
   │      Correction
   │          ↓
   │      Authorized Retest
   │          ↓
   └──────────┘
        ↓
Review Complete Evidence
        ↓
Traceability
        ↓
Qualification Conclusion

14.89 Golden Rules for Qualification Documentation

Rule 1 — Record what actually happened.

Not what was expected to happen.

Rule 2 — Record it when it happens.

Do not rely on memory.

Rule 3 — Preserve the original evidence.

Do not hide incorrect or failed results.

Rule 4 — Make every critical result attributable.

The reviewer should know who performed the activity.

Rule 5 — Correct transparently.

Never erase history.

Rule 6 — Record actual values.

A check mark is not a substitute for required numerical data.

Rule 7 — Control attachments and electronic evidence.

Every supporting record should be traceable.

Rule 8 — Investigate failures before retesting.

Do not test until something passes.

Rule 9 — Do not fabricate execution.

Never copy previous qualification results as though they were newly generated.

Rule 10 — Make the complete evidence tell the story.

An independent reviewer should be able to reconstruct what happened without relying on the executor’s memory.


14.90 ALCOA+ Self-Assessment

For every critical qualification result, ask:

Attributable

Who generated this data?

Legible

Can I clearly read and interpret it?

Contemporaneous

When was it recorded relative to execution?

Original

Where is the original/source evidence?

Accurate

Does it reflect what actually occurred?

Complete

Are failures, repetitions and deviations included?

Consistent

Does the chronology make sense?

Enduring

Will this evidence remain intact?

Available

Can it be retrieved during review or inspection?

If one of these cannot be answered satisfactorily, further assessment may be needed.


14.91 Practical Example — Tablet Compression Machine OQ

Assume OQ requires verification of:

Turret speed at lower, nominal and upper approved test points.

Correct execution record

Test PointSetpointReference InstrumentActualAcceptanceStatus
Lower20 rpmTAC-01420.1 rpmApproved criterionPass
Nominal50 rpmTAC-01449.8 rpmApproved criterionPass
Upper80 rpmTAC-01479.7 rpmApproved criterionPass

Supporting documentation:

  • tachometer identification;
  • valid calibration status;
  • executor/date;
  • raw output if generated;
  • protocol test ID;
  • reviewer.

This creates a defensible evidence chain:

URS → Risk → OQ Test → Calibrated Instrument → Actual Data → Acceptance Criterion → Pass → Traceability


14.92 Practical Example — Failed Interlock

Suppose a compression-machine guard interlock fails.

Actual observation

Guard opened while machine operating; expected defined interlock response did not occur.

Do not:

  • erase the result;
  • mark Pass;
  • ask the vendor to fix it secretly;
  • repeat until successful;
  • attach only the successful retest.

Correct lifecycle:

Record Actual Failure → Mark/Disposition Test per Procedure → Raise Deviation → Assess Impact → Investigate → Correct under Appropriate Control → Determine Retest Scope → Approve Retest → Execute Retest → Retain Original + Retest Evidence → Final Assessment

This preserves the true qualification history.


14.93 Qualification Documentation Quality Model

A useful model is:

Good Protocol + Poor Execution Documentation = Weak Qualification

Good Execution + Poor Raw-Data Control = Weak Qualification

Good Data + Missing Deviations = Weak Qualification

Good Testing + Untraceable Evidence = Weak Qualification

A robust package requires all of them:

Approved Protocol + Controlled Execution + ALCOA+ Data + Raw Evidence + Transparent Deviations + Traceability + Review


14.94 Part 14 — Key Takeaway

Your source requires Part 14 to establish strong controls for ALCOA+, permanent paper entries, dates/times, signatures, corrections, blanks, N/A entries, raw data, attachments, printouts, electronic records, screenshots, page numbering, controlled copies, transcription, calculations, second-person verification and corrections to executed protocols.

The fundamental evidence chain is:

Approved Protocol → Actual Execution → Contemporaneous Entry → Original/Raw Evidence → Attribution → Transparent Correction → Deviation Where Required → Controlled Retest → Review → Traceability → Qualification Conclusion

The strongest documentation principle is simple:

The qualification record must tell the complete story—including what passed, what failed, what changed, what was corrected, what was repeated, who did it, when it occurred, and what objective evidence supports the final conclusion.

This is why the source explicitly treats backdating, pre-signing, unjustified data reconstruction, uncontrolled worksheets, unexplained overwriting, discarding failed results, repeat-until-pass testing without investigation, and copying historical qualification results without execution as unacceptable practices.

Next — Part 15: Deviation Management During Qualification

Part 15 moves directly into the lifecycle:

Observation → Documentation → Initial Assessment → Impact Assessment → Investigation → Root Cause where required → CAPA/Correction → Re-test → QA Assessment → Closure

It will distinguish documentation errors, test discrepancies, protocol deviations, equipment failures, acceptance-criteria failures, design deficiencies and GMP-critical failures, including the critical decision of when qualification may continue versus when execution should stop pending assessment.

About the Author

Ramesh Palav is a pharmaceutical professional with 20+ years of industry experience in manufacturing, GMP, quality systems, validation, compliance, and operational excellence. Through Pharma Manufacturing Hub, he shares practical insights on pharmaceutical careers, manufacturing, quality, validation, Pharma 4.0, AI, and professional development.

His goal is to help students, freshers, experienced professionals, and career-break professionals build the knowledge and skills needed to succeed in the pharmaceutical industry.

Leave a Comment

Scroll to Top