Part of The GMP Training AcademyAll GMP courses
Findings library
MajorModule 5 18 Aug 2026

Assay results from an unlocked, unvalidated spreadsheet

Computerised systems: validation of spreadsheets

Annex 11 s.4, 6, 12; PIC/S PI 041-1 s.9

What the inspector wrote

Assay and content uniformity results were calculated in an Excel workbook stored on a shared network drive. The workbook had not been validated, formula cells were not protected, no version control was in place and the file could be edited by any user on the network. Three versions of the workbook with different rounding logic were found in use. The firm could not demonstrate which version had been used to generate results on certificates of analysis for the preceding eighteen months.

Why it was cited

A spreadsheet that calculates a reported result is a computerised system under Annex 11, whatever software it happens to run in. It needs validation, protection against unauthorised change and control of the version in use. None of that had been done, and the discovery of three variants shows the risk was real, not theoretical.

Spreadsheets are cited so often because they sit outside the IT system list, are built by the person who needs them, and are never handed over when that person leaves.

What would have prevented it

  • An inventory of every spreadsheet that generates or reports GMP data, with an owner and a validation status for each.
  • Templates with locked formula cells, a version number visible on every printout, and change control for any modification.
  • Validation against known inputs, documented, and a second-person check of results until that validation is in place. Where possible, move the calculation into the LIMS or the data system.