Part of The GMP Training AcademyAll GMP courses
Templates

The templates the course is built on

Structure and guidance for every section, free. The sections that carry the most weight in an inspection show their heading and a summary here; the full guidance, the worked examples and the editable files are in the course.

Module 4 · used by QC reviewers, QA, system owners

Audit trail review log

The record that an audit trail review actually happened: which system, which data, which events were looked at, what was found and what was done about it. Written so that an inspector can see the review was risk-based and not a signature on a checkbox.

  1. 1. System and scope

    System name and version, the instrument or module, the data set or batch under review, the date range, and the audit trail views or reports used to perform the review.

    • Which audit trail: system, method, sequence, result, or all four?
    • Is the review per batch, per period, or triggered by an event?
  2. 2. Reviewer and independence

    Who reviewed, their role, and confirmation they did not generate the data being reviewed. Date and time of the review, before the batch was released.

  3. 3. Events reviewed

    Full version in the course

    The event types the procedure requires you to look at and why: aborted runs, reprocessing and reintegration, manual integration, changes to results after first calculation, deletions, changes to methods or sequences, and privileged-account activity.

    The course adds the full guidance, the questions this section must answer, a weak and a defensible worked example, and the reviewer's notes.

  4. 4. Findings

    Each event that needed explanation, with the audit trail entry identifier, the user, the time, the change made and the reason recorded. An entry with no recorded reason is a finding in itself.

    • Was every reprocessed or reinjected sample justified in writing before the repeat?
    • Does any result differ from the first calculated value, and is the reason documented?
    • Did anyone with administrator rights change data or settings in the period?
  5. 5. Evaluation and impact

    Full version in the course

    For each finding: whether it is acceptable practice under the procedure, a documentation gap, or a data integrity concern that affects the reported result and must be escalated as a deviation.

    The course adds the full guidance, the questions this section must answer, a weak and a defensible worked example, and the reviewer's notes.

  6. 6. Actions and escalation

    Deviation or CAPA references raised, who was informed, and whether release was held pending the outcome.

  7. 7. Conclusion and sign-off

    Full version in the course

    A statement of what was reviewed and the overall conclusion, signed by the reviewer and countersigned by QA where the procedure requires it. Wording that an inspector can read without the checklist.

    The course adds the full guidance, the questions this section must answer, a weak and a defensible worked example, and the reviewer's notes.

Module 6 · used by QA, system owners, data governance leads

Data integrity risk assessment

A system-by-system and process-by-process assessment of where data can be lost, altered or made unattributable, used to set the level of control and the audit trail review frequency, and to build a remediation plan that regulators have seen before.

  1. 1. Inventory

    Every system, instrument, spreadsheet and paper record type that generates or holds GMP data, with its owner, the data it produces, and whether the record is paper, electronic or hybrid.

    • Which spreadsheets perform a GMP calculation or hold a GMP record?
    • Which instruments print a result that is then transcribed?
  2. 2. Data criticality

    For each item, the decision the data supports (batch release, stability, calibration, cleaning) and the consequence of the data being wrong. Criticality drives the depth of control.

  3. 3. Vulnerability assessment

    Full version in the course

    For each item, whether data can be created, changed or deleted without attribution: shared accounts, administrator rights held by users, audit trail off or not reviewed, unlocked cells, uncontrolled printouts, records completed after the event.

    The course adds the full guidance, the questions this section must answer, a weak and a defensible worked example, and the reviewer's notes.

  4. 4. Risk rating

    Full version in the course

    Criticality against vulnerability, on a scale the site already uses for ICH Q9 assessments. The rating decides review frequency, access changes and remediation priority.

    The course adds the full guidance, the questions this section must answer, a weak and a defensible worked example, and the reviewer's notes.

  5. 5. Existing controls

    Technical controls (access, audit trail, validation, backup) and procedural controls (second-person check, periodic review, training) currently in place, with the evidence that each is working.

  6. 6. Remediation plan

    Full version in the course

    Actions in priority order with owner and date: interim procedural controls first, technical fixes second, and the point at which each risk is re-rated. Interim controls named explicitly, because inspectors ask what protects the data until the fix lands.

    The course adds the full guidance, the questions this section must answer, a weak and a defensible worked example, and the reviewer's notes.

  7. 7. Review and approval

    Assessment date, approvers, and the trigger for re-assessment: new system, system change, a data integrity deviation, or annual review.

Module 2 · used by Operators, analysts, supervisors, QA reviewers

GDocP correction and late-entry record

The controlled way to correct an entry, add an entry after the fact, or explain a blank field, so that the original stays legible, the change is attributable, and nobody has to guess what happened when the page is read in five years.

  1. 1. Record identification

    Document number and version, page, batch or sample number, and the field or entry concerned. Enough that the correction can be found from this record alone.

  2. 2. Original entry

    What was recorded originally, transcribed exactly, including if it was blank. The original on the page itself is struck through with a single line and stays readable.

    • Can the original still be read on the page?
    • If the field was blank, is the reason for the blank recorded?
  3. 3. Corrected or late entry

    The new value, the date and time the correction or late entry was made (not the time of the original activity), and the initials of the person making it.

  4. 4. Reason and evidence

    Full version in the course

    Why the original was wrong or missing, and the objective evidence for the new value: an equipment log, a printout, a witness. 'Error' on its own is not a reason.

    The course adds the full guidance, the questions this section must answer, a weak and a defensible worked example, and the reviewer's notes.

  5. 5. Late-entry justification

    Full version in the course

    For entries made after the activity: how long after, why it was not recorded at the time, how the value was established, and whether the delay affects reliance on it. Wording that keeps the entry honest without making it look worse than it is.

    The course adds the full guidance, the questions this section must answer, a weak and a defensible worked example, and the reviewer's notes.

  6. 6. Review and impact

    Full version in the course

    Supervisor or QA review of the correction, whether it changes any result, calculation or decision downstream, and whether a deviation is required. Threshold for escalation stated.

    The course adds the full guidance, the questions this section must answer, a weak and a defensible worked example, and the reviewer's notes.

  7. 7. Approval

    Reviewer initials and date. Cross-reference from the corrected page to this record.

The full versions

9 sections are summarised above. The course opens all of them.

When the course opens you get the three templates as editable files, every section with full guidance and worked examples, three complete practice records and audit trails, the assessment and the certificate. 1.5 hours, self-paced.