Most GMP records are still made by hand, and most documentation findings are still about handwriting: an entry missing, a correction that hides the original, a time that cannot be true. The rules are short, they have not changed in a generation, and they are in EU GMP Chapter 4 paragraphs 4.7 to 4.9, with the batch record itself at 4.20. This guide works through them the way a reviewer works through a batch record page.
Making the entry
EU GMP 4.7 requires handwritten entries to be made in clear, legible, indelible writing. 4.8 says records should be made or completed at the time each action is taken, so that all significant activities are traceable. 4.20 requires the batch processing record to carry the initials of the operator who performed each significant step and, where appropriate, the name of any person who checked it. From those three sentences follow the practical rules.
- Ink, not pencil, and not an erasable pen. Blue or black according to site policy; the point is that it cannot be removed.
- The entry is made by the person who did the activity, at the time of the activity, at the place of the activity. Not by the supervisor, not after the fact, not from the office.
- Every entry carries initials and the date. Where the time matters, the time, from a controlled clock, not a personal watch or phone.
- Numbers are written to the precision the record asks for, with units, without rounding beyond what the method specifies.
- No blank fields. If a field does not apply, it is marked N/A with initials and date. If a step was not performed, that is a deviation, not a blank.
Correcting an entry
EU GMP 4.9 is the clause: 'Any alteration made to the entry on a document should be signed and dated; the alteration should permit the reading of the original information. Where appropriate, the reason for the alteration should be recorded.' PIC/S PI 041-1 section 8 does not spell out the method either, but its expectation that the original entry stays visible has the same effect. The single-line correction is the only method that satisfies both.
- Draw one line through the wrong entry so that it can still be read.
- Write the correct entry next to it.
- Initial and date the correction. If the time is relevant, add the time.
- Where the reason is not obvious, write it: 'transcription error', 'wrong line', 'balance re-read'.
Everything else is prohibited by implication: correction fluid, overwriting a digit, scribbling out, erasing, tearing out a page and rewriting it. Each of those destroys the original, and the moment the original is gone the reviewer cannot know whether the change was a slip of the pen or a result that was made to fit. The regulation does not ask the reviewer to trust you. It asks the record to show both versions.
Late entries
Sometimes an entry genuinely cannot be made at the time: the record was in another room, the page was damaged, the activity happened during an emergency. The regulation does not prohibit late entries. It prohibits disguising them. A late entry is written with the actual date and time of writing, marked 'late entry', states the date and time of the activity, and gives the source of the information: a personal note, the equipment log, the memory of the person who did it. The reviewer then decides how much weight to give it.
What is not acceptable is writing the activity time as if the entry were contemporaneous. That is backdating, and every guidance document names it as falsification regardless of whether the activity happened. PIC/S PI 041-1 section 8 and the EMA data integrity Q&A both make the point that the intent does not matter; the record says something untrue about when it was made.
Blank forms and logbooks
If a form can be printed by anyone, a page can be replaced by anyone. PIC/S PI 041-1 section 8.4, building on the document control expectations in EU GMP 4.2 to 4.5, expects blank forms and logbook pages to be controlled: issued with a unique number, reconciled after use, and bound or numbered so that a missing page is visible. This is not bureaucracy for its own sake. The classic finding is a batch record page that is cleaner than its neighbours, on different paper, with entries that fit perfectly, because it was rewritten after the original was found to contain a problem.
What the second-person check is for
EU GMP 4.20 requires the batch processing record to carry, where appropriate, the name of the person who checked each significant step, and Chapter 5 requires independent checks at critical steps such as dispensing and line clearance. The check is often reduced to a second set of initials applied at the end of the page. That is not what it is for. The checker is confirming, at the time, that the step was performed as recorded: the right material, the right quantity, the right setting. A checker who initials a page they did not witness is making an entry that is not attributable to an observation, which is a data integrity failure in its own right.
- The check is made at the time of the step, by someone who saw it, not at page review.
- The checker's initials mean 'I observed this'. If they did not, they do not initial.
- Review at the end of the batch is a separate activity, by QA or a supervisor, looking for completeness, corrections and consistency across the record.
Module 2 of the course takes a real batch record page with eleven problems on it and works through each one: what the failure is, which clause it breaches, and what the corrected page should look like. It is the module most sites roll out to every operator.