LAW: FDA cGMP Compliance
How FDA Inspects Computerized Systems Under cGMP: A Legal Overview
Computerized systems in pharmaceutical and biotech manufacturing are subject to FDA inspection under 21 CFR Parts 211 and 820, the agency’s data integrity guidance, and 21 CFR Part 11 for electronic records and signatures. This article explains the legal framework that governs these systems, what FDA inspectors assess during facility inspections, what organisations must have in place to demonstrate compliance, and the consequences of the most common failures.
Legal Disclaimer
This article provides educational information about FDA requirements for computerized systems under cGMP and 21 CFR Part 11. It does not constitute legal advice. FDA regulations are complex, subject to agency guidance updates, and their application depends on the specific facts of each situation. Consult qualified regulatory or legal counsel for guidance specific to your organisation and products.
#1
Data Integrity Violations
Data integrity failures are the most common basis for FDA Warning Letters citing computerized system deficiencies. They encompass falsification, deletion, and unauthorised modification of electronic records, as well as audit trail gaps and shared login credentials that prevent attribution of data to a specific user.
21 CFR
Part 11 and Part 211
The two primary FDA regulatory frameworks governing computerized systems in pharmaceutical manufacturing. Part 11 governs electronic records and electronic signatures as equivalents to paper records and handwritten signatures. Part 211 (cGMP for finished pharmaceuticals) establishes requirements for laboratory controls, equipment, production, and records that computerized systems must support.
2018
FDA Data Integrity Guidance
FDA’s 2018 guidance document on data integrity and compliance with drug cGMP represents the most comprehensive statement of the agency’s current expectations for computerized system controls. It addresses ALCOA principles, audit trail review, backup practices, and the specific system controls FDA assesses during inspections of pharmaceutical and biotech manufacturers.
Law Summary: The Regulatory Framework for Computerized Systems
FDA’s oversight of computerized systems in pharmaceutical and biotech manufacturing is not a single regulation. It is a framework of overlapping requirements across multiple regulatory authorities, FDA guidance documents, and international standards. Understanding which requirements apply to a given system requires understanding the purpose of the system, the data it generates or processes, and the regulatory submission or compliance context in which it operates.
21 CFR Part 11: Electronic Records and Signatures
Part 11 establishes the conditions under which FDA considers electronic records and electronic signatures to be equivalent to paper records and handwritten signatures. It requires controls including audit trails that capture who did what and when, user access controls that restrict data entry and modification to authorised personnel, system validation documentation, and operational checks to prevent invalid data entry. Part 11 applies to any electronic records created, modified, maintained, archived, retrieved, or transmitted under FDA regulations.
21 CFR Part 211: cGMP for Finished Pharmaceuticals
Part 211 is the primary cGMP regulation for finished pharmaceutical products. Its requirements for laboratory records (211.194), production records (211.188), equipment (211.68), and quality control (211.192) all have computerized system implications. When a computerized system is used to create, process, or store records required by Part 211, that system must be capable of generating accurate and complete records and must be validated for its intended use.
FDA Data Integrity Guidance (2018)
FDA’s 2018 guidance on data integrity and compliance with drug cGMP is not a binding regulation but represents the agency’s current thinking and the standard against which inspectors evaluate data governance practices. It introduces and defines the ALCOA framework (Attributable, Legible, Contemporaneous, Original, Accurate) and ALCOA+ extensions, and specifies expectations for audit trail content, review frequency, access control design, backup and recovery, and the handling of data discrepancies.
21 CFR Part 820: Quality System Regulation (Medical Devices)
For medical device manufacturers, 21 CFR Part 820 (QSR) imposes parallel requirements for computerized systems used in design control, production, process controls, and quality records. FDA’s 2024 revision of Part 820 aligned it more closely with ISO 13485:2016, strengthening design control and software requirements. Software used in medical device production or quality systems falls within the scope of design validation and device history record requirements.
Who Must Comply
Organisation Type
Applicable Framework
Part 11 Applicability
Pharmaceutical manufacturers (finished dosage forms)
21 CFR Parts 210, 211; Data Integrity Guidance 2018
Yes: all electronic records submitted to or required by FDA
API and bulk drug substance manufacturers
21 CFR Parts 210, 211; ICH Q7 for APIs
Yes: electronic batch records and laboratory data systems
Medical device manufacturers
21 CFR Part 820 (QSR); ISO 13485:2016
Yes: design history records, device history records, DHRs
Contract laboratories performing cGMP testing
21 CFR 211.194; Data Integrity Guidance 2018
Yes: LIMS, chromatography data systems, all analytical data
Contract manufacturing organisations (CMOs)
21 CFR Part 211; same as finished dosage manufacturer
Yes: all electronic manufacturing and quality records
Applicable Standards
Key Regulatory References for Computerized System Compliance
21 CFR Part 11: Electronic records and electronic signatures. Establishes audit trail, access control, system validation, and operational check requirements for electronic records used as substitutes for paper records under any FDA-administered regulation.
21 CFR 211.68: Automatic, mechanical, and electronic equipment. Requires that computerized systems used in pharmaceutical manufacturing be routinely calibrated, inspected, or checked and be capable of producing accurate output. Source code or access to modify system software must be controlled.
21 CFR 211.194: Laboratory records. Requires complete laboratory records including raw data from which results were derived, computations, and the date of the test. When these records exist in a computerized system, the system must preserve original data and prevent deletion or modification without traceable audit entries.
FDA Data Integrity Guidance (2018): Guidance document defining ALCOA and ALCOA+ principles for pharmaceutical data. Describes the audit trail content, review expectations, access control design, and backup practices FDA considers necessary for data integrity compliance.
GAMP 5 (Second Edition): While not an FDA regulation, the ISPE GAMP 5 framework is the industry standard for computerized system validation (CSV). FDA inspectors regularly reference GAMP 5 principles when assessing validation programmes, and facilities whose validation approach is inconsistent with GAMP 5 principles often find this reflected in 483 observations.
Key Definitions
ALCOA
Attributable, Legible, Contemporaneous, Original, Accurate. The five foundational data integrity principles that FDA expects pharmaceutical records, including electronic records, to satisfy. Attributable means data can be traced to the specific person who generated it. Contemporaneous means recorded at the time the action occurred. Original means the first capture of the information. FDA’s 2018 guidance extends these to ALCOA+ by adding Complete, Consistent, Enduring, and Available.
Audit Trail
A secure, computer-generated, time-stamped electronic record that allows the reconstruction of the course of events relating to the creation, modification, or deletion of an electronic record. Under 21 CFR Part 11.10(e), audit trails must be computer-generated and must capture the date and time of entry, the identity of the operator making the entry or change, and the original and new value of the changed data. Audit trails must not be modifiable by the operator.
Computerized System Validation (CSV)
The documented process of demonstrating that a computerized system consistently performs its intended functions. FDA requires that computer systems used in pharmaceutical manufacturing, laboratory operations, and quality systems be validated before use and revalidated when changes occur that could affect their function. Validation must be documented and must demonstrate the system’s fitness for its intended purpose, not simply that it was installed and can be accessed.
Raw Data
Under FDA cGMP, raw data is the original record (data file) from which a result is derived, including electronic data. Raw data must be preserved in its original form and must not be overwritten or deleted without a traceable explanation. For chromatography systems, for example, raw data is the unprocessed detector signal file, not the processed peak table output. Facilities that retain only processed outputs and discard or overwrite the raw data files are frequently cited for data integrity failures.
Employer Responsibilities: What Your Organisation Must Have in Place
FDA inspectors assess computerized systems against the requirements of the applicable regulation and FDA guidance. The following obligations represent the core of what organisations must demonstrate during an inspection.
1
Validate all GMP-critical computerized systems
Every computerized system used to create, modify, process, archive, or retrieve data required by FDA regulation must be validated for its intended use before it is placed in GMP service. Validation must be risk-based, documented with protocols and reports, and must cover installation qualification (IQ), operational qualification (OQ), and performance qualification (PQ) appropriate to the system’s function and risk level. Validation documentation must be retained for the life of the system.
2
Implement and review audit trails
Audit trails must be enabled in all GMP computerized systems where the capability exists. Systems that do not have built-in audit trail capability must be assessed for whether their use in a GMP context is appropriate. Enabling audit trails is insufficient on its own: FDA expects that audit trail data is reviewed by QA at a frequency commensurate with the risk of the data, and that anomalies identified in audit trail review are investigated and documented.
3
Enforce individual user accounts and access controls
Shared login credentials are a data integrity failure. Every person who enters, approves, modifies, or accesses GMP electronic records must have their own individual account. Access must be restricted by role so that personnel can only perform functions authorised for their position. Password policies must prevent the use of default, blank, or shared passwords. System administrators must not have the ability to alter or delete audit trail entries.
4
Preserve raw data and maintain backup and recovery procedures
Raw data must be preserved in its original, unprocessed form and must be retained for at least the period specified by the applicable regulation (typically one year post-expiry for pharmaceutical products). Backup procedures must ensure that data is regularly backed up, that backups are stored at a separate location, and that restoration from backup is tested periodically. The inability to restore data from backup is itself a data integrity failure.
Employee Rights and Protections
Employees and Users Have the Right To
Organisations Cannot
Report data integrity concerns, system failures, or requests to falsify records without retaliation under FDA whistleblower protections
Require employees to use shared login credentials, delete data, or generate records they did not personally create or verify
Receive training on the data integrity requirements applicable to their specific role and the systems they operate
Disable audit trail functionality in GMP systems or configure systems to allow users to modify or delete their own audit trail entries
Perform only the data entry and modification functions their access role permits, and not be pressured to perform functions outside their authorised access level
Allow system administrators unrestricted ability to modify, delete, or overwrite GMP records without generating audit trail entries for those actions
What FDA Inspectors Assess: Common Inspection Focus Areas
FDA inspectors conducting cGMP inspections that cover computerized systems typically examine a defined set of areas that reflect the most common failure modes identified in prior enforcement actions. Understanding these focus areas is the most direct preparation for an inspection.
Inspection Focus Areas and Typical Questions
Audit Trail Integrity
Are audit trails enabled? Do they capture the required elements (timestamp, user ID, old value, new value)? Are audit trails reviewed by QA? Can audit trail entries be modified or deleted by users? Are there gaps in the audit trail that cannot be explained?
User Access Controls
Does every user have an individual account? Are access roles defined and enforced? Are passwords required and meeting complexity requirements? Are inactive accounts disabled? Are access permissions reviewed and updated when personnel change roles?
Validation Documentation
Is there a validation plan and validation report for each GMP-critical system? Does the validation cover IQ, OQ, and PQ? Has the system been revalidated following changes? Does the validation documentation demonstrate the system’s fitness for its intended GMP purpose?
Raw Data Preservation
Is original raw data preserved in its unprocessed form? Are raw data files accessible and readable? Can the facility demonstrate that processed results match the underlying raw data? Are raw data files protected from deletion or overwriting without audit trail entries?
Backup and Recovery
Are backups performed at appropriate intervals? Are backups stored at a physically separate location? Has restoration from backup been tested? Can the facility recover GMP records in the event of a system failure?
System Security and Change Control
Is physical and logical access to GMP systems appropriately restricted? Are software and firmware changes managed through a documented change control process? Are system configuration settings documented and protected from unauthorised modification?
Common Violations
Most Frequently Cited Computerized System Deficiencies
Audit trail disabled or not reviewed
Highest Frequency
Audit trails that are disabled entirely, that do not capture required data elements, or that exist but are never reviewed by QA. FDA inspectors routinely check audit trail configuration and request evidence of QA review as one of the first steps in a computerized system inspection.
Shared login credentials
Very Common
Multiple users sharing a single system account, generic login credentials such as “admin” or “lab1” used across the department, or group accounts that cannot be attributed to a specific individual. Shared credentials mean that audit trail entries cannot be attributed to a specific person, which violates the Attributable principle of ALCOA and the individual accountability requirements of Part 11.
Inadequate or missing validation documentation
Common
Systems placed in GMP service without validation, validation that covers only installation and not operational or performance qualification, or validation documentation that was generated retrospectively rather than before the system was used. Missing revalidation after system changes or upgrades is also a frequently cited gap.
Raw data not preserved or accessible
Common
Facilities that retain processed outputs (printed reports, peak tables, summary tables) but do not retain or cannot access the underlying raw data files. In chromatography data systems, this typically means retaining printed chromatograms or PDF exports but not the raw CDS data files. Without the raw data, the FDA inspector cannot verify that the reported result accurately reflects the original measurement.
Backup not tested or stored on-site only
Cited Regularly
Backup procedures that exist on paper but whose restoration has never been tested, backups stored only on the same physical system or in the same server room as the primary data, or backup media that has not been checked for integrity. A backup that cannot be successfully restored is not a backup for GMP purposes.
Penalties and Consequences
Computerized system deficiencies identified during FDA inspections can lead to a range of enforcement consequences depending on the severity and scope of the violations. The progression from observation to enforcement action reflects the seriousness of the finding and the adequacy of the organisation’s response.
Enforcement Action
Trigger
Consequence
FDA Form 483 Observation
Inspectional observation of a deviation from FDA requirements
Requires written response within 15 business days; failure to respond adequately increases Warning Letter risk
Warning Letter
Inadequate 483 response or significant ongoing violations
Public document; may block product approvals and imports; requires comprehensive CAPA response
Import Alert
Ongoing cGMP violations, particularly data integrity failures at foreign facilities
Products detained at US ports of entry; significant commercial impact; difficult to lift
Consent Decree
Systemic, persistent violations across multiple inspections
Court-ordered remediation; third-party oversight; product seizures; significant operational disruption
Compliance Checklist
Validation
All GMP-critical systems have documented validation covering IQ, OQ, and PQ
Revalidation completed after system changes or upgrades
Validation documentation retained for the life of the system
Risk-based approach documented in validation plan
Data Integrity
Audit trails enabled and capturing all required data elements
QA review of audit trails documented at appropriate frequency
Individual user accounts for all GMP system users; no shared credentials
Raw data files preserved in original format and accessible
Backup and Security
Backup performed at defined intervals and stored at separate location
Restoration from backup tested periodically and documented
Access controls restrict GMP system functions by role
System changes managed through documented change control
Key Takeaways
Audit trail review, not just enablement, is what FDA inspectors verify
The most common finding in computerized system inspections is not that audit trails were disabled but that they existed, captured data, and were never reviewed. FDA’s 2018 data integrity guidance is explicit: audit trails must be reviewed with appropriate frequency by someone independent of the data entry function. An enabled audit trail that has not been reviewed since implementation does not demonstrate data integrity control.
Data integrity failures carry consequences that extend beyond the facility
Import alerts and Warning Letters for data integrity violations affect the entire product portfolio distributed from the cited facility, not just the specific products involved in the observed failure. A data integrity finding in the analytical laboratory applies to every batch released using that laboratory’s data. The commercial and regulatory consequences of data integrity enforcement action are disproportionately large relative to the cost of the controls that prevent them.
System validation is a programme, not a one-time event
Validation performed when a system was installed five years ago, with no revalidation since, does not demonstrate that the system is currently operating in a validated state. Software updates, configuration changes, hardware replacements, and changes in intended use all require change control assessment and may require revalidation. A validated state is maintained through ongoing change control, periodic review, and documented qualification activities, not through a validation report that was filed at implementation.
Frequently Asked Questions
Does 21 CFR Part 11 apply to all computerized systems used by pharmaceutical companies?
Part 11 applies to electronic records that are created, modified, maintained, archived, retrieved, or transmitted under records requirements established by FDA regulations. If an electronic record is required by an FDA regulation (such as a batch record required by 21 CFR 211.188 or a laboratory record required by 211.194) and that record exists in electronic form, Part 11 applies. Systems used purely for administrative purposes that do not generate or process FDA-required records are generally outside Part 11’s scope. FDA’s 2003 guidance on Part 11 scope and application provides further clarification on which systems are within scope, and notes that the agency exercises enforcement discretion with respect to some Part 11 requirements.
What is the difference between a 21 CFR Part 11 audit trail and a data integrity audit trail?
Part 11 defines the technical requirements: the audit trail must be computer-generated, time-stamped, and capture information sufficient to reconstruct events relating to record creation, modification, or deletion. It specifies what the audit trail must contain. FDA’s 2018 data integrity guidance adds the governance layer: it specifies who must review audit trails, at what frequency, and what happens when anomalies are found. A system that generates a technically conformant Part 11 audit trail but whose audit trail has never been reviewed by QA satisfies the technical requirement and fails the governance one. During an inspection, FDA investigators typically assess both dimensions: first whether the audit trail captures required data elements, then whether there is documented evidence of periodic QA review and investigation of anomalies. Failing the second dimension is as consequential as failing the first.
How long must computerized system validation documentation be retained?
At minimum, for as long as the records the system supports must be retained. Under 21 CFR 211.180, batch records must be kept for one year post-expiry or three years post-distribution, whichever is longer. Validation documentation should be kept for the life of the system plus the applicable record retention period, and should be preserved after system retirement to support inspection of historical records.
What should an organisation do when an FDA inspector requests to review computer systems during an inspection?
Cooperate fully. FDA has the authority to inspect computerized systems that create, store, or process records required under applicable regulations, and refusal to provide access is itself a compliance failure that can support an inspection refusal finding. Prepare by ensuring that the employees who manage and use GMP systems are familiar with the inspection process and know to contact the quality unit immediately when an inspector requests system access. Have system administrators and IT staff available to demonstrate audit trail content, user access configurations, and backup procedures. Do not attempt to modify system settings or records during the inspection. If an inspector identifies a potential issue, document it accurately and address it through your CAPA system.
Government and Regulatory Sources
Related VelSafe Articles
Preparing for the Computerized System Portion of Your Next FDA Inspection
The computerized system requirements that FDA inspectors assess have not changed significantly since the 2018 data integrity guidance consolidated the agency’s expectations. What changes between inspection cycles is how thoroughly and systematically organisations implement them. Audit trail review programmes that exist in writing but are not executed, validation documentation that was completed at implementation and not maintained, and shared login credentials that have persisted for years despite policies prohibiting them are the consistent findings across enforcement actions. The technical controls are known and available. The gap is almost always in whether those controls are operational in practice, not whether they are described in a procedure. Find more pharmaceutical and biotech compliance resources at velsafe.com.