ICH Q7 clause 2: Quality management
The 17 audit questions covering clause 2, each with the objective evidence to request, the nonconformities most often raised against it and what to sample. Part of the free ICH Q7 API GMP audit checklist, which holds 350 items across 18 clauses.
All 17 questions for clause 2
Open any row for its objective evidence, common nonconformities and auditor tips. You can check items off as you go. This browser remembers your progress across all 18 clauses of this checklist.
§2 Quality management
2.10 Is quality treated as the responsibility of everyone involved in manufacturing, with senior management visibly engaged in the quality system?
- Quality management policy signed by senior management
- Organisational chart showing quality function reporting lines
- Quality system manual or equivalent high-level document
- Management review meeting minutes with attendance records
- Resource allocation records for quality activities
- Quality objectives and measurable targets
- Documented quality system procedures index
- Budget approvals for quality infrastructure and staffing
- Training records showing management quality awareness
- No documented quality policy or quality system manual
- Senior management absent from quality review meetings
- Quality unit understaffed relative to production volume
- Quality system documents not reviewed or updated for years
- No measurable quality objectives defined
- Quality function reports to production management (lack of independence)
This is the foundational quality management principle for API manufacturing. Auditors should verify that senior management visibly participates in quality governance — not merely delegates it. Look for management attendance at quality review meetings, signed quality policies, and resource allocation decisions that demonstrate genuine commitment. The quality system must be comprehensive, covering organisational structure, written procedures, defined processes, adequate resources, and all activities that affect API quality and purity. A common FDA 483 observation is quality systems that exist on paper but lack evidence of active management participation or resource commitment.
2.11 Is there a quality unit organizationally independent from production, with reporting lines that confirm that independence?
- Organisational chart showing QU independence from production
- Quality unit charter or terms of reference
- Job descriptions for QA and QC roles with reporting lines
- Evidence of batch rejections or holds initiated by QU
- Documented authority matrix for quality decisions
- Meeting minutes showing QU exercising independent judgement
- Separation of QA/QC duties documented (or justification for combined role)
- Escalation procedure when QU and production disagree
- Quality unit reports directly to production or plant manager
- No documented QU charter or authority statement
- No evidence QU has ever rejected or held a batch
- QU head also holds a production management role
- Production management can override QU decisions without escalation
- QU staff performance evaluated by production metrics
Independence of the quality unit from production is a critical GMP principle. Auditors should trace the reporting lines to confirm the quality unit does not report to the head of production or manufacturing. In small organisations a single individual may fulfil QA and QC roles, but that person must still have independent authority to reject batches without production override. Verify that quality decisions (batch release, deviation closure, CAPA approval) cannot be overruled by production management. FDA warning letters frequently cite situations where QU independence is compromised by organisational structure or informal pressure.
2.12 Are the individuals authorized to approve or reject raw materials, intermediates, and APIs formally designated and documented?
- Authorised signatory list for batch disposition
- Delegation of authority matrix for material release/rejection
- Qualification records for authorised personnel
- Batch records showing named individuals approving release
- Rejection reports with authorised signatures
- Raw material acceptance records with authorised signatures
- Acceptance criteria referenced in disposition decisions
- Periodic review of authorised signatory list
- No formal authorised signatory list maintained
- Batch records signed by unqualified or undesignated personnel
- Rejection decisions not documented or not traceable
- Acceptance criteria not referenced in disposition records
- Outdated signatory lists with departed employees still listed
- No periodic review of authorised signatories
Auditors should request the list of authorised signatories for batch release, material acceptance, and rejection decisions. Verify that each person on the list has documented qualifications and formal delegation of authority. Cross- check actual batch records and rejection reports to confirm only authorised persons signed off. This clause also covers incoming raw materials — someone must be formally authorised to accept or reject them. Look for traceability: every disposition decision should link to a named individual, the date of decision, and the quality data that supported it. Unsigned or undated disposition records are a significant finding.
2.13 Are quality activities recorded contemporaneously and handled in a timely manner?
- Deviation SOP with defined timelines for initiation and closure
- Deviation log showing open/closed status and age metrics
- Batch records with contemporaneous entries (dates and times match activities)
- Investigation reports completed within SOP-defined timelines
- CAPA tracking system with due dates and completion rates
- Quality metrics dashboard showing deviation closure rates
- Logbook entries with real-time timestamps
- Escalation procedure for overdue quality activities
- Large backlog of open deviations (more than 30 days old)
- Investigation reports completed months after the event
- Evidence of predated or retroactively completed records
- No defined timelines for deviation investigation and closure
- Quality hold decisions delayed, allowing potentially affected product to ship
- CAPA actions overdue without management escalation
This clause addresses two interrelated concepts: contemporaneous recording and timeliness. Auditors should verify that quality records are created at the time of the activity (not retrospectively filled in), and that deviations, investigations, and quality decisions are completed within defined timeframes. Look for SOP-defined timelines for deviation initiation, investigation completion, and CAPA implementation. A backlog of open deviations or investigations pending for months is a red flag. Also check for evidence of predated or post-dated entries in batch records or logbooks. Timeliness protects data integrity — delayed recording increases the risk of inaccurate information.
2.14 Does the quality unit hold final authority over the release or rejection of every API batch?
- Batch release procedure requiring QU signature
- Intermediate disposition records approved by QU
- Master batch record approval workflow showing QU sign-off
- Specification approval records with QU signatures
- Sampling procedure approvals by QU
- Test method approval and change records signed by QU
- Authority matrix showing QU as final authority for release/rejection
- Evidence that QU has exercised rejection authority
- SOP defining QU role in document review and approval
- APIs released without QU approval signature
- Production staff performing batch disposition without QU oversight
- Master batch records issued without QU review
- Specifications changed without QU approval
- No evidence of QU rejecting any batch in extended period
- QU authority delegated to non-quality personnel
This clause establishes the quality unit as the final authority for all batch disposition decisions. Auditors should verify that no API batch can be released without explicit QU approval, and that QU also controls intermediate disposition. Beyond batch release, the QU must approve master batch records, specifications, sampling plans, and test methods before they are used. Check that this authority is not informally delegated — for example, a production supervisor should not be able to release APIs even temporarily. Also verify QU reviews and approves any changes to specifications or test methods. This is one of the most frequently cited areas in FDA warning letters for API manufacturers.
2.15 Is there a complete set of written procedures and systems covering the material lifecycle from receipt through API release?
- SOPs for material receipt, identification, and quarantine
- SOPs for storage, handling, and sampling of materials
- SOPs for testing and release of in-process materials and APIs
- Deviation management SOP with root cause analysis methodology
- CAPA procedure with effectiveness verification requirements
- Process controls or interlocks designed to prevent deviations
- Deviation trending reports identifying recurring issues
- Preventive action implementation records with effectiveness checks
- Material flow diagram showing control points
- Missing SOPs for one or more material handling steps
- No formal deviation management procedure
- Deviations investigated but no preventive actions implemented
- Recurring deviations with same root cause indicating ineffective CAPAs
- No systematic deviation trending or analysis
- Quarantine controls not enforced (materials used before release)
Auditors should verify a complete set of written procedures covering the full material lifecycle from receipt through final API release. Check that procedures exist for each step: receiving and identification, quarantine controls, storage conditions, handling precautions, sampling techniques, analytical testing, and formal disposition. Beyond having procedures, the clause requires systems that actively prevent deviations (process controls, interlocks, verification steps) and that deviations which do occur are promptly detected, properly investigated, and corrected with preventive measures. Verify that CAPA actions from deviation investigations are implemented and verified for effectiveness. The absence of a comprehensive deviation prevention programme is a common GMP shortcoming.
2.16 Are materials prevented from use or release until the quality unit has completed a satisfactory evaluation?
- Quarantine procedure with physical or system-based controls
- Warehouse management system showing material status tracking
- Labels or status indicators for quarantine vs. released materials
- Quality unit release records for raw materials and intermediates
- Formal approval documentation for any quarantine-release system
- Risk assessment for use of materials pending evaluation
- Physical segregation evidence (photos, layout diagrams)
- Incident reports for any inadvertent use of quarantined material
- No physical or system-based quarantine controls in place
- Materials used in production before QU release without formal system
- Quarantine release system used without documented QU approval
- Inadequate labelling — quarantine status not clearly indicated
- Warehouse layout does not support physical segregation
- No records of quarantine holds or releases
This clause establishes the principle that quality evaluation must precede material use. Auditors should verify that physical or system-based quarantine controls prevent materials from entering production before QU release. If a quarantine release system (using materials before full evaluation is complete) is used, it must be formally approved with documented controls and risk assessment. Check warehouse management systems or physical segregation practices. Verify that labels or status indicators clearly distinguish quarantined from released materials. The most common finding is inadequate physical segregation allowing unreleased materials to be inadvertently used in production.
2.17 Are there procedures to promptly notify responsible management of regulatory inspections, serious deficiencies, and related actions?
- Escalation and notification SOP with defined timelines
- Escalation matrix identifying notification recipients by scenario
- Records of management notifications for past inspections or events
- Recall notification procedure with regulatory authority contacts
- Internal communication records during regulatory inspections
- Mock recall or emergency drill records testing notification paths
- Complaint escalation records showing management involvement
- Contact information list for emergency notifications kept current
- No formal notification or escalation procedure exists
- Notification procedure exists but has never been used or tested
- Regulatory inspections occurred without timely management notification
- Escalation timelines not defined or unrealistically long
- Senior management unaware of significant quality events
- Contact lists outdated with departed personnel
Auditors should verify that formal escalation and notification procedures exist and have been tested or used. Check for documented escalation paths with named roles (not just titles) and defined timelines — for example, notification of a regulatory inspection within 24 hours, or immediate notification for product safety issues. The procedure should cover multiple scenarios: announced and unannounced inspections, critical GMP findings from internal audits, field complaints indicating product defects, and recalls. Verify that the procedure reaches senior management who can authorise resource deployment for responses. A common gap is having a notification procedure that has never been tested via simulation or drill.
2.18 Are there procedures for notifying the relevant authorities when a quality issue warrants external reporting?
- Regulatory notification SOP with triggering criteria
- Regulatory authority contact matrix by jurisdiction
- Records of past regulatory notifications with timelines
- Designated responsible person(s) for regulatory communications
- Mapping of reporting obligations by market/jurisdiction
- Templates for regulatory notification submissions
- Training records for personnel responsible for notifications
- Log of all regulatory communications (inbound and outbound)
- No procedure for regulatory notification exists
- Reportable events occurred without regulatory notification
- Notification procedure covers only one jurisdiction despite global distribution
- No designated responsible person for regulatory communications
- Notification timelines not aligned with regulatory requirements
- No records of any regulatory notifications ever made
Auditors should verify that the organisation has clear procedures for regulatory notifications — not just internal escalation but external reporting to health authorities. Check that the procedure defines triggering criteria (what constitutes a reportable event), reporting timelines per jurisdiction, responsible persons, and documentation requirements. For API manufacturers supplying globally, verify that procedures account for multiple regulatory authorities (FDA, EMA, PMDA, etc.) and different reporting timelines. Cross-reference with actual events to confirm notifications were made. A common gap is having domestic notification procedures but not covering international markets where the API is distributed.
2.20 Is the quality unit involved across all quality-related matters, not just batch release and testing?
- QU involvement matrix across all manufacturing stages
- QU participation in change control review records
- QU membership in technology transfer teams
- QU sign-off on validation protocols and reports
- QU attendance at process design and review meetings
- QU review of supplier qualification records
- Document approval workflows showing QU as required reviewer
- QU participation in out-of-specification investigations
- Periodic review records of QU scope and involvement
- QU involvement limited to final batch testing and release
- Change controls approved without QU review
- Technology transfers completed without QU participation
- Validation protocols executed without QU approval
- QU not involved in supplier qualification decisions
- No documentation of QU scope of involvement
Auditors should verify the breadth of QU involvement across all quality-related activities — not just batch release and testing. Check that the QU participates in process design, validation protocols, change control reviews, and technology transfers. Look at meeting attendance records, document approval workflows, and project team rosters. The QU should also be involved in supplier qualification, stability programmes, and out-of-specification investigations. A common gap is QU involvement limited to end-stage testing and release, without participation in upstream process decisions that fundamentally affect API quality. The clause uses "all quality-related matters" — this is broad and intentional.
2.21 Does the quality unit review and approve all quality-related documents?
- List of document types requiring QU review and approval
- Batch production records with QU review signatures and dates
- Laboratory control records with QU review evidence
- Deviation reports showing QU review and approval
- Change control records with QU approval signatures
- Validation protocols and reports with QU approval
- Specification documents with QU approval history
- Document review SOP with defined timelines
- Metrics on QU document review turnaround times
- Documents issued without QU review or approval
- QU review signatures backdated or retroactive
- No evidence of substantive QU review (no comments or corrections ever)
- Large backlog of documents awaiting QU review
- No defined list of documents requiring QU review
- QU review turnaround times not tracked or consistently exceeded
Auditors should request a comprehensive list of documents subject to QU review and approval and verify it covers all categories listed in this clause. Spot-check actual documents to confirm QU review signatures are present and timely. Check that the review is substantive — not merely a rubber stamp — by looking for evidence of QU comments, corrections, or rejections during reviews. The timeframe for review should be defined in procedures and tracked. A backlog of documents awaiting QU review suggests inadequate QU resources. Also verify that QU reviews are completed before the document is used (not retroactively approved).
2.22 Are the core duties of the quality unit defined, assigned, and performed without being delegated to production?
- QU duties matrix mapping all 15 duties to SOPs and responsible persons
- API batch release records signed by QU
- Intermediate disposition records for external use
- Raw material, packaging, and labelling material release system records
- Batch record review checklists for critical process steps
- Deviation investigation records approved by QU
- Master production instruction approval records
- Internal audit programme and audit reports
- Contract manufacturer approval records
- Change control records with QU approval
- Validation protocol and report approval records
- Quality complaint investigation records
- Equipment calibration and maintenance oversight records
- Material testing oversight and result review records
- Stability programme and data review records
- Product quality review reports
- One or more of the 15 duties not assigned to QU in writing
- QU duties delegated to non-quality personnel without formal authorisation
- No evidence of QU performing specific duties (e.g., no internal audits conducted)
- API released without QU batch record review
- Contract manufacturers approved without QU involvement
- No product quality review programme in place
- Stability programme not overseen by QU
This is the most detailed clause in Section 2 and represents the core duties of the quality unit. Auditors should verify that each of the 15 listed duties is explicitly assigned to the QU, documented in writing, and actively performed with supporting evidence. Create a matrix mapping each duty to the responsible QU personnel, the governing SOP, and evidence of execution. Any duty that lacks a governing procedure or evidence of execution within the audit period is a potential finding. Note the clause states these duties should not be delegated outside the QU — verify there are no informal delegations. This clause is the single most important reference for QU compliance in API manufacturing under ICH Q7.
2.30 Are the responsibilities for production activities clearly defined, assigned, and documented in procedures?
- Production responsibilities document or SOP
- Master production instructions signed and distributed
- Batch records showing production review and sign-off
- Production deviation reports submitted to QU
- Facility cleaning and disinfection logs
- Calibration records maintained by production
- Equipment maintenance logs and schedules
- Production management review of validation protocols
- Change evaluation records with production input
- Equipment qualification records with production sign-off
- Job descriptions defining production quality responsibilities
- Production responsibilities not documented in writing
- Batch records not reviewed or signed by production management
- Production deviations not reported or reported late
- No cleaning or maintenance logs for production facilities
- Calibration records missing or incomplete
- Production not involved in change evaluation for process changes
- New equipment used without qualification
Auditors should verify that each of the 10 listed production responsibilities is formally assigned, documented in SOPs, and actively performed with supporting evidence. Create a matrix similar to the QU duties in clause 2.22. Check that production management's responsibilities complement but do not overlap with QU responsibilities — the two should be clearly delineated. Look for evidence of production personnel performing each duty: production instructions prepared and distributed, batch records reviewed and signed, deviations reported to QU, facility cleaning logs, calibration records, maintenance logs, validation involvement, change evaluation participation, and equipment qualification records. Production and quality should have clear handoff points defined.
2.40 Are regular internal (self-inspection) audits performed against a defined GMP programme?
- Internal audit schedule covering all GMP areas (risk-based frequency)
- Internal audit SOP defining methodology, classification, and reporting
- Auditor qualification records demonstrating independence and competence
- Completed audit reports with observations classified by severity
- Corrective action plans with responsible persons and due dates
- CAPA tracking system showing completion status of audit findings
- Management review presentation of internal audit results
- Follow-up audit records verifying effectiveness of corrective actions
- Audit programme annual review and risk re-assessment records
- No internal audit programme or schedule in place
- Audits not covering all GMP areas per ICH Q7
- Auditors not independent from the area being audited
- Audit reports with zero findings over multiple years
- Corrective actions from audits not completed or overdue
- No management review of internal audit results
- Audit schedule not risk-based — all areas audited at same frequency
Auditors should review the internal audit programme schedule to verify it covers all GMP areas per ICH Q7. Check that audits are performed by personnel who did not work in the area being audited (independence). Review audit reports for completeness — they should identify observations, classify them by severity, and include agreed corrective actions with responsible persons and due dates. Verify that corrective actions are tracked to completion and their effectiveness verified. The audit schedule should be risk-based — higher-risk areas (e.g., aseptic processing, water systems, data integrity) should be audited more frequently. A common finding is internal audits that are superficial or never identify any observations, suggesting lack of rigour.
2.41 Are corrective actions arising from internal audits documented, owned, and completed in a timely manner?
- CAPA tracking system or log for internal audit findings
- Root cause analysis records for audit observations
- Corrective action implementation evidence
- Effectiveness verification records for completed CAPAs
- Overdue CAPA escalation records to management
- Management meeting minutes addressing audit CAPA status
- Trend report showing audit finding recurrence rates
- Metrics on CAPA on-time closure rates
- No CAPA tracking system for audit findings
- Corrective actions overdue without management escalation
- No root cause analysis performed for audit findings
- Same findings recurring in consecutive audit cycles
- No effectiveness verification for completed corrective actions
- Management not informed of overdue audit CAPAs
Auditors should review the CAPA tracking system for internal audit findings. Check that each audit observation has an assigned corrective action with a responsible person, target completion date, and root cause analysis. Verify that completed actions include effectiveness verification — evidence that the root cause was actually eliminated. Calculate the on-time closure rate: if a significant proportion of CAPAs are overdue, this indicates a systemic issue. Also check that management is informed of overdue actions and that resources are allocated for completion. Common gaps include corrective actions that address symptoms rather than root causes, leading to recurring findings in subsequent audit cycles.
2.50 Are periodic product quality reviews conducted for APIs to confirm process consistency?
- Product quality review reports for each API (annual)
- Statistical trending of in-process controls and API test results
- Summary and analysis of failed batches
- Review of critical deviations with root cause patterns
- Summary of process and analytical method changes
- Stability monitoring programme results and trending
- Complaint and recall summary with trend analysis
- CAPA effectiveness assessment
- Conclusions and recommendations for corrective action or revalidation
- Management sign-off on PQR conclusions and actions
- No product quality review programme in place
- PQRs overdue by more than one year
- PQR compiles data but contains no analysis or conclusions
- One or more of the seven required review elements missing
- No statistical trending of critical results
- PQR recommends corrective actions but no follow-through documented
- Process consistency issues identified but not acted upon
The product quality review (PQR), sometimes called annual product review (APR), is a critical retrospective analysis of process consistency. Auditors should verify that PQRs are conducted at least annually for each API and include all seven specified review elements. Check that the review includes statistical trending (not just listing) of in-process controls and test results. Verify that failed batches, deviations, changes, stability data, complaints, and CAPA effectiveness are all evaluated. The review should conclude with an assessment of whether the process remains in a validated state of control. Recommendations for corrective action or revalidation should be documented and tracked. Common gaps include PQRs that compile data without analysis, or reviews that are overdue by months or years.
2.51 Do product quality reviews drive a documented assessment of whether process or specification changes are needed?
- PQR conclusions section with corrective action assessment
- Documented rationale for corrective action decisions
- CAPA records arising from PQR findings
- Revalidation assessments triggered by PQR trends
- Specification or method change proposals resulting from PQR
- Process control revisions based on PQR analysis
- Trending data showing early identification of process drift
- PQR action items tracked to completion with timelines
- Continuous improvement programme inputs from PQR
- PQR completed but no assessment of corrective action need
- Negative trends identified in PQR but no action taken
- Revalidation not considered despite process changes or drift
- PQR corrective actions not tracked or completed
- PQR treated as standalone exercise with no link to improvement programme
- Same negative trends reported in consecutive PQRs without resolution
This clause extends clause 2.50 by requiring that PQR findings lead to actionable outcomes. Auditors should verify that PQR conclusions include a documented assessment of whether corrective action or revalidation is needed, with supporting rationale. Where corrective actions are identified, verify they are tracked and completed in a timely manner. Check that the PQR specifically evaluates whether specifications, test methods, process controls, or manufacturing procedures need updating based on the trends observed. The PQR should identify process drift before it results in out-of-specification results. Also verify the PQR feeds into the broader continuous improvement programme — it should not be an isolated annual exercise but a driver of quality system improvements.
Each item shows its evidence, common nonconformities and auditor tips. The clause index has the PDF of all 350 items, formatted for a clipboard.
The rest of the ICH Q7 API GMP audit checklist
350 items across 18 clauses. Back to the clause index.