Part 14

The governing principle is:
If an activity was performed during qualification, the qualification record should provide reliable, attributable, contemporaneous and traceable evidence of what was actually done and what actually occurred.
The source also emphasizes that final qualification documentation should provide objective, contemporaneous, traceable and scientifically justified evidence supporting fitness for intended GMP use.
14.1 What Is Good Documentation Practice?
Good Documentation Practice (GDP) in qualification means applying controlled practices so that records accurately and reliably represent:
- what activity was performed;
- who performed it;
- when it was performed;
- what equipment/system was tested;
- what test instruments were used;
- what conditions existed;
- what results were obtained;
- what raw evidence was generated;
- whether acceptance criteria were met;
- what unexpected events occurred;
- how errors were corrected;
- what deviations were raised;
- who reviewed the evidence.
GDP is not simply about handwriting quality.
It is fundamentally about data integrity and evidentiary reliability.
14.2 Qualification Documentation as GMP Evidence
Consider the qualification lifecycle:
Approved Protocol
↓
Execution
↓
Actual Observations
↓
Raw Data
↓
Attachments / Electronic Evidence
↓
Deviations
↓
Review
↓
Traceability
↓
Qualification Conclusion
If execution records are incomplete or unreliable, the final qualification conclusion becomes difficult to defend.
14.3 Why GDP Is Critical During Qualification
Qualification testing may generate evidence supporting decisions concerning:
- equipment release;
- facility release;
- utility release;
- computerized-system acceptance;
- GMP operation;
- process validation;
- cleaning validation;
- requalification.
Poor documentation can therefore create uncertainty about whether the system was actually demonstrated to be fit for intended use.
14.4 Core Data-Integrity Principle — ALCOA+
Your source specifically requires ALCOA+ to be addressed during qualification execution.
ALCOA commonly represents:
| Principle | Meaning |
|---|---|
| A — Attributable | Who performed or recorded the activity? |
| L — Legible | Can the record be read and understood? |
| C — Contemporaneous | Was it recorded when the activity occurred? |
| O — Original | Is it the original record or appropriately controlled true copy/equivalent? |
| A — Accurate | Does it correctly represent what occurred? |
The commonly used “+” principles include:
- Complete
- Consistent
- Enduring
- Available
These principles should apply throughout the data lifecycle.
14.5 Attributable
Qualification data should be attributable to the individual who performed or recorded the activity.
For example:
| Test | Result | Executed By | Date |
|---|---|---|---|
| Emergency-stop challenge | Pass | RSP/signature | 30-Jul-2026 |
A reviewer should be able to determine who generated the result.
14.6 Attribution in Electronic Systems
Electronic qualification records may use:
- unique user IDs;
- authenticated electronic signatures;
- system-generated audit trails;
- controlled workflows.
Shared accounts can undermine attribution.
For computerized and automated systems, your source separately identifies user-role matrices, access-control testing, audit-trail assessment/testing, security and electronic-record controls as potentially required.
14.7 Legible
Records should remain readable throughout their required retention period.
Problems include:
- illegible handwriting;
- faint printouts;
- damaged thermal-paper records;
- obscured corrections;
- cropped screenshots;
- poor-quality photocopies;
- unclear units.
A record that cannot be interpreted cannot reliably support the qualification conclusion.
14.8 Contemporaneous Documentation
This is one of the most important principles in Part 14.
Qualification observations should be recorded when the activity is performed or observed, according to the applicable procedure.
Correct sequence:
Perform Test → Observe Result → Record Result
Not:
Perform Many Tests → Remember Results → Reconstruct Documentation Later
14.9 Why Contemporaneous Recording Matters
Suppose 35 alarm tests are performed during OQ.
If results are entered into the protocol two days later from memory, questions arise:
- Were all alarms actually tested?
- Were any failures forgotten?
- Were exact alarm messages captured?
- Were actual times known?
- Were unexpected observations omitted?
Contemporaneous recording substantially reduces these risks.
14.10 Original Records
Qualification evidence may originate from:
- executed protocol entries;
- instrument-generated records;
- electronic systems;
- laboratory systems;
- data loggers;
- SCADA;
- PLC/HMI reports;
- printouts;
- photographs where appropriate;
- screenshots;
- calibration systems.
The applicable original record or appropriately controlled representation should remain identifiable and retrievable.
14.11 Accurate
Qualification records should correctly reflect what actually occurred.
For example:
Setpoint:
50 rpm
Actual calibrated reference measurement:
49.7 rpm
Record:
49.7 rpm
Do not record:
50 rpm
merely because 50 rpm was the expected result.
14.12 Complete
Qualification records should include relevant data—including results that do not meet expectations.
A complete record should not selectively retain:
- only passing runs;
- only final readings;
- only successful screenshots;
- only successful retests.
Failed and unexpected results are part of the qualification history.
14.13 Consistent
Data should follow the expected chronological and logical sequence.
Example:
Protocol approved
↓
Test executed
↓
Deviation identified
↓
Investigation
↓
Correction
↓
Retest authorized
↓
Retest performed
An unexplained sequence such as a retest occurring before the associated deviation was assessed may require investigation.
14.14 Enduring
Qualification evidence should be recorded and retained in durable controlled media appropriate to the record type.
Examples may include:
- controlled paper records;
- validated/qualified electronic systems;
- approved electronic repositories;
- controlled archival systems.
Temporary or easily lost media should not become the only evidence supporting critical qualification conclusions.
14.15 Available
Qualification records should remain retrievable when needed for:
- protocol review;
- qualification summary;
- deviation investigation;
- change control;
- requalification;
- periodic review;
- internal audit;
- regulatory inspection.
An inspector may ask for historical qualification evidence many years after initial installation.
14.16 ALCOA+ Applied to Qualification
| Principle | Qualification Example |
|---|---|
| Attributable | Executor signs test |
| Legible | Recorded result is readable |
| Contemporaneous | Reading entered during execution |
| Original | Instrument output retained |
| Accurate | Actual value recorded |
| Complete | Failed results retained |
| Consistent | Dates/events follow logical order |
| Enduring | Evidence stored in durable controlled record |
| Available | Qualification package retrievable |
14.17 Paper Qualification Records
Where paper protocols are used, the organization should control:
- protocol issuance;
- revision;
- page identification;
- entries;
- corrections;
- signatures;
- attachments;
- unused fields;
- reconciliation;
- archival.
The specific method should follow the site’s controlled documentation procedure.
14.18 Permanent Ink
Your source specifically asks that permanent ink where paper records are used be addressed.
Where required by the site’s procedure, entries should be made using permanent, indelible ink suitable for maintaining the integrity and legibility of the record.
Avoid documentation methods that allow entries to be:
- erased;
- removed;
- changed without evidence;
- rendered unreadable.
The source does not prescribe a particular ink color, so any such color requirement would be company-specific.
14.19 Pencil
Pencil is generally unsuitable for controlled GMP execution records where it permits erasure without preserving the original entry.
The key principle is:
Original data and corrections must remain traceable.
Specific documentation requirements should follow the site’s approved GDP procedure.
14.20 Date Entries
Dates should be recorded according to the approved site format.
A good date format should avoid ambiguity.
For example:
30-Jul-2026
is less ambiguous internationally than:
07/30/26
or
30/07/26
The exact required format remains company-specific.
14.21 Time Entries
Where time is relevant to the qualification evidence, record it contemporaneously.
Examples include:
- stabilization periods;
- recovery testing;
- hold times;
- alarm activation;
- backup duration;
- power-failure recovery;
- sampling;
- environmental monitoring;
- water-system studies.
Example:
| Activity | Start | End |
|---|---|---|
| Stabilization | 10:15 | 10:45 |
Time-zone or clock-source considerations may also matter for computerized systems.
14.22 Signatures and Initials
Signatures/initials should identify responsible personnel according to the site’s approved system.
Typical qualification roles include:
- executor;
- witness;
- reviewer;
- verifier;
- approver.
Do not sign for work performed by another individual unless a controlled procedure explicitly defines the nature of that verification.
14.23 Pre-Signing Is Unacceptable
Your source explicitly lists pre-signing as an unacceptable practice.
Example:
An engineer signs:
Executed By: John / 30-Jul-2026
before actually performing the test.
This creates a record claiming that an event has occurred when it has not.
14.24 Corrections to Paper Records
Errors can occur during execution.
The objective of a GDP-compliant correction is to:
- preserve the original entry;
- identify the corrected information;
- attribute the correction;
- date the correction;
- provide a reason where required by procedure or where the reason is not obvious.
14.25 Example of a Paper Correction
Suppose the actual result was accidentally recorded as:
45.8 rpm
but the source reading was 48.5 rpm.
A controlled correction should preserve the incorrect original entry rather than erase or obliterate it, with the corrected value entered and the correction appropriately attributable/date-controlled.
Conceptually:
45.848.5 rpm — initials/date — transcription error
The exact correction notation should follow the site’s approved GDP SOP.
14.26 Do Not Obliterate Original Entries
Avoid correction methods that prevent reconstruction of the original entry.
Examples:
- correction fluid;
- erasing;
- scratching until unreadable;
- overwriting digits;
- blacking out original values.
The reviewer should be able to understand:
Original Entry → Correction → Corrected Entry
14.27 Unexplained Overwriting
Your source specifically identifies unexplained overwriting as an unacceptable practice.
Example:
Original:
25.4
changed by writing over the “5” until it looks like:
28.4
This obscures the original result.
A transparent correction is preferable.
14.28 Corrections to Executed Protocols
Your source separately requires discussion of corrections to executed protocols.
A distinction should be maintained between:
Data-entry correction
Example: transcription error.
Protocol instruction error
Example: incorrect test step.
Acceptance-criterion problem
Example: incorrect limit in the approved protocol.
Design/system problem
Example: machine does not behave as specified.
Not all of these should be handled as simple GDP corrections.
14.29 GDP Correction vs Protocol Deviation
A useful decision model is:
Is the issue only an obvious documentation-entry error?
→ Correct according to GDP.
Does it change the approved test method, expected result or acceptance criterion?
→ Assess under the applicable protocol deviation/amendment/change process.
Does the equipment/system fail?
→ Document the failure and assess under deviation management.
Do not use a simple handwriting correction to bypass deviation/change control.
14.30 Blank Fields
Unexplained blank fields create uncertainty.
A reviewer may not know whether the field was:
- forgotten;
- not applicable;
- not tested;
- intentionally omitted;
- awaiting completion.
Where required by the applicable procedure, unused fields should be appropriately addressed rather than left unexplained.
14.31 N/A Entries
If a field or test is not applicable, record N/A or the site’s approved equivalent where appropriate.
But N/A should not become a mechanism for avoiding required testing.
Example:
Test: Audit Trail Verification
Result: N/A
This requires justification if the system generates GMP-relevant electronic records and audit-trail functionality is applicable.
14.32 N/A Should Be Justifiable
A strong N/A disposition should answer:
Why does this requirement/test not apply?
For example:
N/A — Equipment has no computerized control or electronic GMP-record functionality within the qualification scope.
Where significance warrants, reference the applicable system assessment.
14.33 Raw Data
Raw data are fundamental qualification evidence.
Examples include:
- actual measurements;
- instrument output;
- printouts;
- electronic files;
- system logs;
- alarm histories;
- audit trails;
- trend data;
- test reports;
- photographs where justified;
- laboratory results.
The source’s final inspection-readiness checklist specifically requires raw data to be retained during execution.
14.34 Actual Data vs Check Marks
Suppose the acceptance criterion is:
Differential pressure: 10–15 Pa.
Weak record:
✓ Pass
Stronger record:
Actual result: 12.4 Pa
Acceptance: 10–15 Pa
Status: Pass
The actual measurement demonstrates why the test passed.
14.35 Do Not Record Only Expected Results
A qualification protocol might contain:
Expected result: Speed = 40 ± 2 rpm.
The executor must record the actual observed value, not simply copy:
40 ± 2 rpm
into the actual-result field.
Expected results and actual results have different purposes.
14.36 Attachments
Attachments may include:
- calibration certificates;
- drawings;
- printouts;
- screenshots;
- raw-data sheets;
- photographs;
- reports;
- instrument outputs;
- alarm lists;
- trend data.
Attachments should remain traceable to the relevant qualification test.
14.37 Attachment Control
A practical attachment record may include:
| Field | Example |
|---|---|
| Protocol | OQ-TCM-001 |
| Test | OQ-017 |
| Attachment | OQ-017-A01 |
| Description | Alarm history |
| Pages | 1 of 3 to 3 of 3 |
| Generated by | ___ |
| Date | ___ |
The exact format depends on the site’s documentation system.
14.38 Uncontrolled Attachments
The source later identifies uncontrolled attachments as a common qualification deficiency.
Examples include:
- loose printouts with no protocol reference;
- screenshots with no test identification;
- unidentified handwritten notes;
- missing pages;
- documents whose origin cannot be established.
An attachment should be understandable even when reviewed later.
14.39 Printouts
Equipment and computerized systems may generate:
- alarm reports;
- batch reports;
- parameter reports;
- trend reports;
- audit trails;
- test reports.
Where printouts form part of qualification evidence, they should be identifiable and linked to the applicable test.
14.40 Printout Identification
Depending on site procedures and system capabilities, consider:
- equipment/system;
- date/time;
- report type;
- test number;
- page count;
- executor identification;
- attachment reference.
If a printout does not automatically identify its source, controlled annotation may be needed according to procedure.
14.41 Thermal Printouts
Some instruments produce records that fade over time.
Where such records are required as GMP evidence, the organization should have an appropriate method to ensure the information remains enduring and retrievable according to its record-control procedures.
The source does not prescribe a specific copying/scanning method, so this should remain site-defined.
14.42 Electronic Records
Qualification may generate electronic records in:
- SCADA;
- DCS;
- MES;
- LIMS;
- BMS/EMS;
- HMI;
- data loggers;
- electronic validation systems;
- electronic document systems.
Electronic evidence should be controlled according to its GMP relevance and intended use.
14.43 Electronic Records Are More Than Screenshots
A screenshot may show what appeared on a screen at one moment.
It may not necessarily capture:
- underlying metadata;
- audit trail;
- complete sequence;
- original electronic record;
- configuration history;
- user attribution.
Therefore, screenshots should be used appropriately rather than automatically treated as substitutes for original electronic evidence.
14.44 Screenshots
Your source specifically requires screenshots to be addressed.
A useful screenshot should provide sufficient context to establish:
- what system was being tested;
- what function was displayed;
- what result was observed;
- which test it supports.
Where relevant, record:
- test ID;
- system;
- user;
- date/time;
- screen/function;
- attachment reference.
14.45 Screenshot Example
For OQ user-access testing:
OQ-ACC-004
Test:
Operator attempts access to administrator configuration.
Evidence:
Screenshot showing access denied.
Attachment:
OQ-ACC-004-A01
The protocol result should reference the attachment.
14.46 Page Numbering
Page numbering supports document completeness.
Typical controlled formats may include:
Page 15 of 87
or equivalent electronic controls.
Page numbering helps detect:
- missing pages;
- duplicated pages;
- substituted pages;
- incomplete attachments.
The exact numbering method is company-specific.
14.47 Controlled Copies
Qualification should be executed using the appropriately controlled protocol/version.
Potential problems with uncontrolled copies include:
- obsolete test steps;
- obsolete acceptance criteria;
- duplicate execution;
- missing revision control;
- inability to determine which record is official.
The protocol-control process should define issuance, reconciliation and archival where applicable.
14.48 Uncontrolled Worksheets
Your source explicitly lists uncontrolled worksheets as unacceptable.
Example:
An engineer performs testing using a personal spreadsheet, records all results there, and later transfers only passing results to the official protocol.
This creates serious questions about completeness and data integrity.
14.49 Temporary Working Notes
If temporary working records are necessary, their handling should be defined by the applicable procedure.
Do not assume that a record becomes non-GMP simply because it is called:
“rough notes”
If it contains original qualification observations/data used to support the final result, its status should be appropriately controlled.
14.50 Data Transcription
Qualification frequently requires data to be transferred from one record to another.
Examples:
- instrument → protocol;
- printout → summary table;
- electronic system → qualification worksheet;
- laboratory report → PQ table.
Transcription introduces risk of human error.
14.51 Good Transcription Practice
Where data are transcribed:
- preserve/reference the source;
- copy the value accurately;
- include units;
- maintain decimal precision appropriately;
- verify transcription where required by procedure/risk;
- correct errors transparently.
Example:
Source:
49.73 rpm
Protocol should not become:
47.93 rpm
because of a transcription error.
14.52 Direct Data Capture
Where practical and appropriately controlled, direct capture of reliable data can reduce manual transcription risk.
However, electronic automation does not automatically guarantee data integrity.
Controls remain necessary for:
- access;
- configuration;
- interfaces;
- metadata;
- security;
- retention;
- backup.
14.53 Calculation Verification
Your source specifically requires calculation verification to be addressed.
Qualification calculations may include:
- averages;
- percentage variation;
- standard deviation;
- airflow;
- air changes;
- recovery time;
- yield;
- accuracy;
- relative error.
Calculations should be correct and traceable to source data.
14.54 Example Calculation Record
For three readings:
| Reading | Value |
|---|---|
| R1 | 49.8 |
| R2 | 50.1 |
| R3 | 50.0 |
Average:
[
\frac{49.8+50.1+50.0}{3}=49.97
]
A qualification record should allow a reviewer to determine:
- input data;
- formula/method;
- calculated result;
- applicable acceptance criterion.
14.55 Automated Calculations
Where spreadsheets or computerized systems perform qualification calculations, appropriate controls should reflect:
- intended use;
- complexity;
- GMP impact;
- risk.
Potential concerns include:
- incorrect formulas;
- hidden cells;
- uncontrolled formula changes;
- incorrect rounding;
- manual overwriting.
The source does not prescribe a particular spreadsheet-validation approach in Part 14.
14.56 Second-Person Verification
Your source requires discussion of second-person verification where required.
Second-person verification may be appropriate where required by:
- procedure;
- protocol;
- risk assessment;
- criticality;
- specific operation.
It should not become a meaningless signature exercise.
14.57 What Should the Second Person Verify?
Depending on the activity:
- source-to-transcribed data;
- critical calculations;
- equipment identification;
- critical setup;
- challenge condition;
- test result;
- attachment completeness.
The verifier should understand what their signature means.
14.58 Witness vs Reviewer vs Verifier
These roles are not necessarily identical.
Witness
Observes the activity being performed.
Verifier
Independently confirms a specific item/result.
Reviewer
Reviews the completed documentation/evidence.
The site’s procedure should define responsibilities.
14.59 Backdating
Your source explicitly identifies backdating as unacceptable.
Example:
A test was performed on 30 July.
Documentation is completed on 2 August but intentionally dated 30 July to make it appear contemporaneous.
This compromises the reliability of the record.
14.60 Late Entry vs Backdating
These should not be confused.
If an entry was genuinely omitted, the appropriate approach is to handle the late entry transparently according to the site’s procedure.
Do not make the record falsely appear contemporaneous.
The documentation should preserve what actually happened.
14.61 Data Reconstruction Without Justification
The source explicitly identifies data reconstruction without justification as unacceptable.
Example:
Original OQ readings were not documented.
Two days later, personnel reconstruct values from memory and enter them as if they were original observations.
This is fundamentally different from a justified, transparent reconstruction using reliable source records.
14.62 Data Reconstruction Decision
If original protocol entries are missing:
Is reliable source data available?
If yes:
→ Assess according to procedure.
→ Document that the entry is reconstructed/late.
→ Reference the source.
→ Evaluate impact.
If no:
→ Do not invent values.
→ Assess whether retesting or deviation/investigation is necessary.
14.63 Discarding Failed Results
Your source explicitly identifies discarding failed results as unacceptable.
Example:
Run 1 = Fail
Run 2 = Fail
Run 3 = Pass
Final protocol contains only:
Run 3 = Pass.
This destroys the true qualification history.
14.64 Correct Failure History
The evidence should preserve:
Initial Test
↓
Failure
↓
Deviation
↓
Investigation
↓
Correction/CAPA
↓
Approved Retest
↓
Retest Result
↓
Final Assessment
This provides a scientifically defensible record.
14.65 Repeating Tests Until They Pass
Also explicitly prohibited by the source as an unacceptable practice is:
Repeating tests until they pass without investigation.
This practice is sometimes described as testing into compliance.
A failure should trigger appropriate assessment—not repeated attempts until an acceptable number appears.
14.66 Example — Speed Failure
Acceptance criterion:
20.0 ± 1.0 rpm
Initial result:
22.4 rpm — FAIL
Incorrect:
Repeat → 21.8 → Repeat → 20.9 → PASS → record only 20.9.
Correct lifecycle:
22.4 Fail → Document → Investigate → Determine Cause → Correct → Authorize Retest → Retest → Evaluate
14.67 Copying Previous Qualification Results
Your source explicitly identifies:
Copying previous qualification results without execution
as unacceptable.
Example:
Previous requalification:
Speed = 49.8 rpm.
Current protocol:
49.8 rpm copied into current result without performing the test.
This creates false evidence of execution.
14.68 Previous Qualification Data Can Still Be Useful
Historical data may legitimately support:
- risk assessment;
- test planning;
- trending;
- requalification scope;
- comparison.
But historical results should not be represented as newly executed test results.
14.69 Common GDP Deficiencies During Qualification
| Deficiency | Potential Concern |
|---|---|
| Blank fields | Completeness uncertain |
| Missing dates | Timing unclear |
| Missing signatures | Attribution unclear |
| Illegible entries | Evidence cannot be interpreted |
| Pencil/erasable entries | Original data may be altered |
| Overwriting | Original result obscured |
| Missing raw data | Pass result unsupported |
| Unidentified printout | Evidence not traceable |
| Uncontrolled worksheet | Original data may be incomplete |
| Late reconstruction | Contemporaneousness compromised |
| Discarded failures | Completeness compromised |
| Repeated testing without investigation | Testing into compliance |
| Copied previous results | False evidence |
| Missing attachments | Evidence incomplete |
| Wrong protocol revision | Execution basis uncertain |
14.70 Data Integrity Decision Tree
Qualification Data Generated
↓
Was it recorded contemporaneously?
┌──────┴──────┐
YES NO
│ ↓
│ Is reliable source
│ evidence available?
│ ┌───┴───┐
│ YES NO
│ │ │
│ Assess/ Deviation/
│ document impact assessment
│ transparently
↓
Is evidence attributable?
↓
Is original/source retained?
↓
Is record complete?
↓
Are corrections traceable?
↓
Are failures/deviations retained?
↓
Is evidence reviewable/retrievable?
↓
QUALIFICATION EVIDENCE ACCEPTABLE
14.71 GDP During IQ
During IQ, GDP applies particularly to:
- equipment IDs;
- component IDs;
- serial numbers;
- materials;
- instrument IDs;
- calibration status;
- drawings;
- software versions;
- certificates.
Do not write:
“All instruments calibrated — Pass”
if individual instruments are supposed to be verified and identified.
14.72 GDP During OQ
OQ generates extensive functional evidence.
Particular attention should be given to:
- actual parameter values;
- alarm challenges;
- interlock results;
- failure modes;
- user access;
- recipes;
- audit trails;
- backup/restore;
- electronic records.
Your source requires OQ to address these functions where applicable.
14.73 GDP During PQ
PQ documentation may include:
- operating conditions;
- load;
- material;
- operators;
- parameter values;
- samples;
- laboratory results;
- run duration;
- deviations;
- reproducibility data.
Your source requires PQ to consider approved procedures, trained operators, materials, operating ranges, load configurations, sampling, acceptance criteria and deviations.
14.74 Example — Proper OQ Entry
Test
Turret Speed Verification
Setpoint
50 rpm
Reference Instrument
Tachometer ID: TAC-014
Calibration Due
15-Dec-2026
Actual Reading
49.8 rpm
Acceptance Criterion
Approved protocol criterion
Result
PASS
Executor
Name/signature/date
Evidence
Attachment OQ-SPD-004-A01
This provides substantially stronger evidence than:
Speed checked — OK.
14.75 Example — Alarm Test Documentation
| Alarm | Challenge | Expected | Actual | Evidence | Result |
|---|---|---|---|---|---|
| Guard Open | Open guard | Defined machine response | Response observed as specified | ATT-07 | Pass |
| Low Lubrication | Simulated approved condition | Alarm + defined response | Recorded | ATT-08 | Pass |
| Emergency Stop | Activate E-stop | Safe defined response | Recorded | ATT-09 | Pass |
Actual wording and acceptance criteria should come from the approved qualification protocol.
14.76 Documentation of Unexpected Observations
Not every unexpected observation is automatically a critical deviation.
However, it should not simply disappear.
Ask:
Does the observation affect the test method?
Does it affect acceptance criteria?
Does it indicate equipment malfunction?
Does it affect another test?
Does it affect GMP/data integrity?
Does it require deviation assessment?
Part 15 addresses this in detail.
14.77 Responsibilities
A typical allocation may be:
| Role | GDP Responsibility |
|---|---|
| Executor | Contemporaneous and accurate entries |
| Witness/Verifier | Verify defined critical activity/data |
| Validation | Ensure protocol/evidence completeness |
| Engineering | Support technical evidence |
| Automation/IT | Support electronic evidence |
| QA | Independent GMP/data-integrity oversight |
| Reviewer | Detect inconsistencies/gaps before closure |
Actual responsibilities should follow the company’s PQS.
14.78 Reviewer Responsibilities
The reviewer should check more than signatures.
Review should include:
- Were tests executed completely?
- Are actual results recorded?
- Are units present?
- Are calculations correct?
- Are attachments present?
- Are corrections GDP compliant?
- Are failures documented?
- Are deviations linked?
- Are retests justified?
- Are dates chronologically logical?
- Are signatures attributable?
- Is the evidence sufficient to support pass/fail?
14.79 Inspector Perspective — “Show Me the Raw Data”
Your source specifically anticipates inspectors asking:
What raw data supports this result?
A strong qualification package can move directly from:
Protocol Test
↓
Actual Result
↓
Raw Data
↓
Attachment/Electronic Record
↓
Acceptance Criterion
↓
Pass/Fail Conclusion
14.80 Inspector Perspective — Corrections
An inspector seeing many corrected entries may assess:
- Are originals visible?
- Who made the correction?
- When?
- Why?
- Is there a pattern?
- Were results altered after review?
- Are corrections consistent with procedure?
A correction is not inherently a problem.
An unexplained or nontransparent correction may be.
14.81 Inspector Perspective — Repeated Testing
An inspector seeing:
Test 1 — Fail
Test 2 — Fail
Test 3 — Pass
will reasonably ask:
Why was the test repeated?
What caused the failures?
Where is the deviation?
Who authorized the retest?
What changed before the passing result?
The source specifically lists “Who approved the re-test?” and “How were qualification failures investigated?” among expected inspection questions.
14.82 Inspector Perspective — Electronic Evidence
For computerized equipment, an inspector may compare:
Paper Protocol
with:
Electronic System Record
and ask whether:
- timestamps agree;
- user attribution agrees;
- audit trail shows changes;
- reported result matches original data;
- records remain available.
Paper documentation should not contradict the electronic source.
14.83 GDP Review Checklist — Before Execution
The source’s final inspection-readiness checklist specifically identifies the following pre-execution controls: approved protocol, approved URS, completed risk assessment, justified acceptance criteria, current calibration, available drawings, completed prerequisites and trained personnel.
Therefore verify:
- □ Correct approved protocol
- □ Correct revision
- □ Equipment/system identified
- □ Required URS available
- □ Risk assessment available
- □ Acceptance criteria predefined
- □ Prerequisites complete
- □ Test instruments identified
- □ Calibration current
- □ Drawings/specifications available
- □ Personnel trained
- □ Controlled protocol issued
14.84 GDP Review Checklist — During Execution
Your source specifically calls for: contemporaneous entries, retained raw data, documented deviations, actual results, attached evidence, identified test personnel and GDP-compliant corrections.
Check:
- □ Entries contemporaneous
- □ Actual results recorded
- □ Numerical values recorded where required
- □ Units recorded
- □ Date/time entered where applicable
- □ Executor identified
- □ Test instruments identified
- □ Raw data retained
- □ Printouts controlled
- □ Screenshots traceable
- □ Attachments identified
- □ Corrections transparent
- □ Blank fields addressed
- □ N/A justified where necessary
- □ Failures retained
- □ Deviations initiated when required
- □ Retesting controlled
14.85 GDP Review Checklist — Before Closure
- □ All protocol pages accounted for
- □ All tests completed/dispositioned
- □ All actual results recorded
- □ All attachments reconciled
- □ All raw data available
- □ Calculations verified
- □ Required second-person verification completed
- □ Deviations linked
- □ Failed tests retained
- □ Retests justified
- □ Corrections reviewed
- □ Traceability updated
- □ Outstanding issues assessed
- □ Protocol summary completed
- □ Required review/approval completed
The source’s broader closure checklist also requires deviations to be resolved or appropriately dispositioned, retests justified, traceability completed, outstanding risks evaluated, SOPs/training completed, summary report approved and QA release documented where required.
14.86 Eight Unacceptable Practices Required by the Source
Part 14 explicitly identifies eight practices that must be addressed.
| Unacceptable Practice | Why It Is a Concern |
|---|---|
| Backdating | Creates a false chronology |
| Pre-signing | Claims completion before activity occurs |
| Unjustified data reconstruction | Original contemporaneous evidence may be absent |
| Uncontrolled worksheets | Completeness/integrity uncertain |
| Unexplained overwriting | Original entry obscured |
| Discarding failed results | Record becomes incomplete/biased |
| Repeat until pass without investigation | May constitute testing into compliance |
| Copying previous results without execution | Creates false evidence of current execution |
14.87 Documentation Red Flags
An inspection-ready review should investigate patterns such as:
Perfectly identical handwriting/results across different days
Many tests signed at exactly the same time
Protocol approval after execution
Missing original printouts
Only successful screenshots retained
Multiple unexplained retests
No failed data despite known deviations
Copied historical values
Different ink/handwriting without attribution
Electronic timestamps inconsistent with paper entries
Missing pages
Loose unidentified attachments
These do not automatically prove misconduct, but they warrant appropriate assessment.
14.88 Good Documentation Practice Flow
APPROVED PROTOCOL
↓
Controlled Execution
↓
Observe Activity / Measurement
↓
Record Contemporaneously
↓
Retain Original / Raw Evidence
↓
Attribute Entry
↓
Acceptance Criterion Comparison
↓
Result
↙ ↘
PASS FAIL
↓ ↓
Document Document Failure
↓ ↓
│ Deviation/
│ Assessment
│ ↓
│ Investigation
│ ↓
│ Correction
│ ↓
│ Authorized Retest
│ ↓
└──────────┘
↓
Review Complete Evidence
↓
Traceability
↓
Qualification Conclusion
14.89 Golden Rules for Qualification Documentation
Rule 1 — Record what actually happened.
Not what was expected to happen.
Rule 2 — Record it when it happens.
Do not rely on memory.
Rule 3 — Preserve the original evidence.
Do not hide incorrect or failed results.
Rule 4 — Make every critical result attributable.
The reviewer should know who performed the activity.
Rule 5 — Correct transparently.
Never erase history.
Rule 6 — Record actual values.
A check mark is not a substitute for required numerical data.
Rule 7 — Control attachments and electronic evidence.
Every supporting record should be traceable.
Rule 8 — Investigate failures before retesting.
Do not test until something passes.
Rule 9 — Do not fabricate execution.
Never copy previous qualification results as though they were newly generated.
Rule 10 — Make the complete evidence tell the story.
An independent reviewer should be able to reconstruct what happened without relying on the executor’s memory.
14.90 ALCOA+ Self-Assessment
For every critical qualification result, ask:
Attributable
Who generated this data?
Legible
Can I clearly read and interpret it?
Contemporaneous
When was it recorded relative to execution?
Original
Where is the original/source evidence?
Accurate
Does it reflect what actually occurred?
Complete
Are failures, repetitions and deviations included?
Consistent
Does the chronology make sense?
Enduring
Will this evidence remain intact?
Available
Can it be retrieved during review or inspection?
If one of these cannot be answered satisfactorily, further assessment may be needed.
14.91 Practical Example — Tablet Compression Machine OQ
Assume OQ requires verification of:
Turret speed at lower, nominal and upper approved test points.
Correct execution record
| Test Point | Setpoint | Reference Instrument | Actual | Acceptance | Status |
|---|---|---|---|---|---|
| Lower | 20 rpm | TAC-014 | 20.1 rpm | Approved criterion | Pass |
| Nominal | 50 rpm | TAC-014 | 49.8 rpm | Approved criterion | Pass |
| Upper | 80 rpm | TAC-014 | 79.7 rpm | Approved criterion | Pass |
Supporting documentation:
- tachometer identification;
- valid calibration status;
- executor/date;
- raw output if generated;
- protocol test ID;
- reviewer.
This creates a defensible evidence chain:
URS → Risk → OQ Test → Calibrated Instrument → Actual Data → Acceptance Criterion → Pass → Traceability
14.92 Practical Example — Failed Interlock
Suppose a compression-machine guard interlock fails.
Actual observation
Guard opened while machine operating; expected defined interlock response did not occur.
Do not:
- erase the result;
- mark Pass;
- ask the vendor to fix it secretly;
- repeat until successful;
- attach only the successful retest.
Correct lifecycle:
Record Actual Failure → Mark/Disposition Test per Procedure → Raise Deviation → Assess Impact → Investigate → Correct under Appropriate Control → Determine Retest Scope → Approve Retest → Execute Retest → Retain Original + Retest Evidence → Final Assessment
This preserves the true qualification history.
14.93 Qualification Documentation Quality Model
A useful model is:
Good Protocol + Poor Execution Documentation = Weak Qualification
Good Execution + Poor Raw-Data Control = Weak Qualification
Good Data + Missing Deviations = Weak Qualification
Good Testing + Untraceable Evidence = Weak Qualification
A robust package requires all of them:
Approved Protocol + Controlled Execution + ALCOA+ Data + Raw Evidence + Transparent Deviations + Traceability + Review
14.94 Part 14 — Key Takeaway
Your source requires Part 14 to establish strong controls for ALCOA+, permanent paper entries, dates/times, signatures, corrections, blanks, N/A entries, raw data, attachments, printouts, electronic records, screenshots, page numbering, controlled copies, transcription, calculations, second-person verification and corrections to executed protocols.
The fundamental evidence chain is:
Approved Protocol → Actual Execution → Contemporaneous Entry → Original/Raw Evidence → Attribution → Transparent Correction → Deviation Where Required → Controlled Retest → Review → Traceability → Qualification Conclusion
The strongest documentation principle is simple:
The qualification record must tell the complete story—including what passed, what failed, what changed, what was corrected, what was repeated, who did it, when it occurred, and what objective evidence supports the final conclusion.
This is why the source explicitly treats backdating, pre-signing, unjustified data reconstruction, uncontrolled worksheets, unexplained overwriting, discarding failed results, repeat-until-pass testing without investigation, and copying historical qualification results without execution as unacceptable practices.
Next — Part 15: Deviation Management During Qualification
Part 15 moves directly into the lifecycle:
Observation → Documentation → Initial Assessment → Impact Assessment → Investigation → Root Cause where required → CAPA/Correction → Re-test → QA Assessment → Closure
It will distinguish documentation errors, test discrepancies, protocol deviations, equipment failures, acceptance-criteria failures, design deficiencies and GMP-critical failures, including the critical decision of when qualification may continue versus when execution should stop pending assessment.
About the Author
Ramesh Palav is a pharmaceutical professional with 20+ years of industry experience in manufacturing, GMP, quality systems, validation, compliance, and operational excellence. Through Pharma Manufacturing Hub, he shares practical insights on pharmaceutical careers, manufacturing, quality, validation, Pharma 4.0, AI, and professional development.
His goal is to help students, freshers, experienced professionals, and career-break professionals build the knowledge and skills needed to succeed in the pharmaceutical industry.
