ICH Q7 clause 5: Process equipment
The 30 audit questions covering clause 5, each with the objective evidence to request, the nonconformities most often raised against it and what to sample. Part of the free ICH Q7 API GMP audit checklist, which holds 350 items across 18 clauses.
All 30 questions for clause 5
Open any row for its objective evidence, common nonconformities and auditor tips. You can check items off as you go. This browser remembers your progress across all 18 clauses of this checklist.
§5 Process equipment
5.10 Is equipment of appropriate design and adequate size, and suitably located for its intended use, cleaning, and maintenance?
- Equipment specification documents
- Materials of construction certificates
- Equipment sizing calculations
- Equipment layout drawings showing separation and access
- Supplier qualification records
- Equipment IQ documentation
- Maintenance access reviews
- Capacity vs batch size justification
- Equipment too small causing repeated campaigns and cleaning validation burdens
- Contact materials incompatible with process chemistry
- Equipment located in areas with poor environmental control
- No documentation of materials of construction
- Difficulty accessing equipment for cleaning/maintenance
- Equipment design review not involving quality unit input
Equipment selection must consider multiple factors: capacity sized for intended batch sizes (not over or under-sized), location that enables maintenance access and prevents cross-contamination, construction materials compatible with the API and processing conditions. Auditors verify equipment specifications match production requirements and that contact surfaces are constructed from non-reactive materials (e.g., stainless steel 316L for most chemistries).
5.11 Are product-contact surfaces non-reactive, non-additive, and non-absorptive so they do not alter API quality?
- Materials of construction certificates (mill certs)
- Extractables/leachables studies where applicable
- Corrosion resistance data for process conditions
- Gasket and seal material compatibility documentation
- Passivation records for stainless steel equipment
- Equipment material compatibility SOP
- Periodic inspection for surface degradation
- Lubricant/coolant compatibility assessment
- Contact surfaces showing corrosion, pitting, or rouging
- No extractables data for elastomers in contact with solvents
- Food-grade lubricants not used where direct contact possible
- Mixed metals creating galvanic corrosion risk
- No documentation of passivation or surface treatment
- Gasket and O-ring replacement records not linked to material compatibility data
This is a critical quality control — contact surfaces must be inert to the process chemistry. Common issues include: rouging of stainless steel at elevated temperatures, extractables/leachables from elastomer gaskets and O-rings, reactive metal surfaces (aluminum, copper) with acidic APIs. Auditors will check MOC documentation and may request extractables/leachables data for high-risk contact materials.
5.12 Where lubricants, coolants, or similar substances could contact the product, are food-grade (or equivalent) materials used?
- Food-grade lubricant specifications and CoAs
- Lubricant application SOP specifying approved lubricants
- Equipment design showing contamination prevention
- Double-seal configurations on mixers/pumps
- Lubricant contamination incident log
- Change control for lubricant substitutions
- Maintenance records showing correct lubricant use
- NSF H1 or equivalent certifications
- Non-food-grade lubricants in equipment with contamination risk
- No lubricant specification SOP
- Lubricant substitutions without change control
- Evidence of lubricant leaks in product contact areas
- Bearings lubricated without documentation
- Maintenance personnel unaware of food-grade lubricant requirements
Lubricants at bearings, seals, and mechanical interfaces can contact the product stream if seals fail. Food-grade (or NSF H1) lubricants must be used anywhere contamination is possible. Double-seal configurations with barrier fluid provide additional protection. Auditors verify lubricant specifications and check equipment design for contamination pathways.
5.13 Is closed or contained equipment used where practical, with appropriate controls when open handling is necessary?
- Process flow diagrams showing closed systems
- Open processing risk assessments
- Laminar flow hood qualification for open operations
- Current P&IDs under document control
- Equipment instrumentation drawings
- Utility system drawings
- Drawing revision control linked to change control
- Open handling SOPs with contamination controls
- Open processing without environmental controls
- Outdated P&IDs not reflecting current equipment configuration
- No risk assessment justifying open processing
- Multiple open transfers increasing contamination probability
- No drawing revision control
- Laminar flow hoods not requalified after facility layout changes
Closed systems reduce contamination risk and operator exposure. When open processing is necessary (e.g., charging, sampling, discharging), controls include laminar flow protection, dedicated clothing, short exposure times, and cleaned work surfaces. Current equipment drawings (P&IDs, instrumentation loops) must be maintained as part of the change control system.
5.14 Is major equipment uniquely identified so it can be referenced in batch records and logs?
- Equipment inventory list with unique IDs
- Physical identification tags/plates on equipment
- Batch records referencing specific equipment IDs
- Calibration records linked to equipment IDs
- Maintenance records by equipment ID
- Asset management database
- Equipment ID in validation documents
- Photos showing visible identification
- Equipment without unique identification
- Duplicate equipment IDs across site
- Identification tags illegible or missing
- Equipment IDs inconsistent between documents
- Temporary labels in place of permanent identification
- Batch records referencing retired or decommissioned equipment numbers
Unique equipment identification enables traceability in batch records, logbooks, and maintenance systems. Identification should be permanent, visible, and match documentation. Every major equipment item needs a unique ID that appears in: equipment logbook, batch records, validation documents, calibration records, and maintenance history.
5.15 Are substances associated with equipment operation (heat-transfer fluids, coolants) controlled so they do not contaminate the product?
- Heat transfer fluid specifications
- Coolant approved list
- Jacket leak detection procedures
- Drain design with air breaks documented
- Back-siphonage prevention device inspections
- Hydraulic fluid specifications for direct-contact equipment
- Incident log for fluid leaks
- Risk assessment for all auxiliary substances
- Non-food-grade heat transfer fluid with known leak history
- No drain air break leading to potential back-siphonage
- Auxiliary fluid substitutions without assessment
- No leak detection for jacket systems
- Hydraulic fluid specification not reviewed for product-contact risk
- Coolant system integrity checks not included in preventive maintenance schedule
Beyond lubricants (5.12), this clause covers heat transfer fluids, coolants, hydraulic fluids, and similar substances. Risk-based approach: direct contact risk = food-grade required; jacket-only contact = lower risk but still should minimize migration risk. Drains must prevent cross-contamination between systems through air gaps or equivalent.
5.16 Is defective equipment removed from service or clearly tagged to prevent its use?
- Out-of-service tagging SOP
- Defective equipment tags/labels observed during walkthrough
- Equipment status log showing defective items
- Repair records with verification of fix
- Re-qualification records before return to service
- Segregation area for defective equipment
- Root cause for recurring defects
- Equipment defect trending
- Defective equipment still in use
- Tags indicating defects ignored or removed
- No re-qualification after significant repairs
- Defective equipment near operational equipment without segregation
- No trending of equipment failures
- Return-to-service verification records missing after major overhauls
Defective equipment must be immediately tagged OUT OF SERVICE and physically segregated where practical. Clear, tamper-evident tagging prevents inadvertent use. Return to service requires verification of repair effectiveness, often with re-qualification. Auditors check equipment status tags during plant walkthroughs.
5.20 Are there schedules and written procedures for preventive maintenance of equipment, with records?
- Preventive maintenance schedule by equipment ID
- Maintenance SOPs with procedures
- Completed maintenance work orders
- Responsibility assignment matrix
- Maintenance history by equipment
- Maintenance completion metrics (planned vs actual)
- Spare parts inventory for critical items
- Contamination controls during maintenance
- PM schedules exist but not consistently executed
- No maintenance records for extended periods
- Maintenance performed during production without contamination controls
- Critical equipment without defined PM frequency
- Reactive maintenance dominating over preventive
- Spare parts inventory insufficient for critical equipment repairs
Preventive maintenance is essential for consistent equipment performance. The program must cover all major equipment with defined frequencies (often hours-based, calendar-based, or condition-based). Maintenance should be planned to avoid campaign contamination — typically performed during changeover or shutdown. Records must show planned vs actual completion.
5.21 Are there written procedures for cleaning equipment and for verifying its cleanliness before use?
- Equipment-specific cleaning SOPs
- Cleaning SOP training records for operators
- Master cleaning SOP with annexes
- Cleaning agent specifications and approved list
- Visual inspection criteria (clean/dirty photos)
- Cleaning cycle records including hold times
- Cleaning SOP revision history
- Operator technique verification during audits
- Cleaning SOPs too generic to ensure reproducible cleaning
- Missing equipment-specific instructions
- No defined cleaning agent concentrations
- No visual inspection criteria
- Operators using different techniques with same SOP
- No cleaning verification after cleaning
Cleaning SOPs must be specific enough that different operators get consistent results. Key elements: disassembly sequence, cleaning agent concentrations, mechanical action (scrub, flush, spray), temperatures, contact times, rinse sequences, and visual inspection criteria. Each piece of equipment should have a dedicated cleaning SOP or a master SOP with equipment-specific annexes.
5.22 Do cleaning procedures contain enough detail to enable reproducible, effective cleaning by any qualified operator?
- Cleaning SOPs with quantitative parameters
- Operator certification program for cleaning
- Clean equipment covering/storage procedures
- Cleaning acceptance criteria documentation
- Reproducibility verification (different operators)
- Cleaning cycle time limits
- Clean equipment holding times validated
- Storage conditions for clean equipment
- SOPs lacking quantitative parameters (e.g., 'rinse thoroughly')
- No operator certification
- Clean equipment left uncovered between uses
- No hold time restrictions on clean equipment
- Different operators producing different cleaning outcomes
- Cleaning agent concentration not verified before each batch cleaning cycle
This clause emphasizes reproducibility — the same operator or a different qualified operator should achieve the same cleaning outcome every time. Reproducibility comes from specificity: exact quantities of cleaning agents, specific equipment settings (agitator speed, pump rates), measured contact times, standardized rinse volumes. Protection from recontamination during storage is also required.
5.23 Is the clean/dirty status of equipment clearly identified?
- Clean/dirty status tags observed on equipment during walkthrough
- Status tagging SOP
- Tag design with date, product, and signature
- Electronic equipment status system if used
- Dedicated equipment status approach documented
- Tag reconciliation procedures
- Tags tamper-evident or controlled
- Status visible without physical entry to equipment
- Equipment without visible clean/dirty status
- Expired or undated status tags
- Multiple conflicting status indicators
- No record of who cleaned and when
- Tags ignored during operations
- Clean status tags not correlated with validated clean hold times
Visual clean/dirty status identification prevents accidental use of unclean equipment or reprocessing of cleaned equipment. Typical systems use color-coded tags (green=clean, red=dirty) or electronic status displays. The tag or indicator must include the cleaning date and signature. For dedicated equipment, simpler approaches may be used but status identification is still required.
5.24 Is equipment cleaned at appropriate, risk-based intervals (and before each use where required) to prevent carryover?
- Risk assessment documenting cleaning frequency decisions
- Cleaning frequency defined per product pair
- Same-product batch-to-batch cleaning approach documented
- Product changeover cleaning procedures
- Campaign length limits
- Evidence of cleaning before each use
- Cleaning logs cross-referenced to production logs
- Cross-contamination risk matrix
- Cleaning frequency not defined by risk assessment
- Same cleaning procedure for all product changes
- Equipment reused without cleaning between different products
- No campaign length limits
- Cross-contamination events despite cleaning procedures
- Cleaning logs not cross-referenced with production batch records
Cleaning frequency is risk-based. Between batches of the same product: typically minor cleaning sufficient (minor product buildup allowed if validated). Between different products: full cleaning validation required. Between campaigns: full validated cleaning. Between potent and non-potent products: enhanced cleaning with verification. The risk assessment and cleaning frequency decisions must be documented.
5.25 Are validated maximum hold times established between equipment use and cleaning, and between cleaning and reuse?
- Validated dirty hold time documentation
- Validated clean hold time documentation
- Cleaning SOPs specifying maximum hold times
- Batch records documenting actual hold times
- Deviation handling for exceeded hold times
- Hold time extension protocols if needed
- Environmental monitoring during clean hold
- Production scheduling respecting hold times
- Hold times used but not validated
- Dirty hold time exceeded without revalidation
- Clean hold time without microbial verification
- No hold time records in batch records
- Production planning exceeding validated hold times routinely
- Hold time extension justifications lacking scientific supporting data
Two hold times matter: dirty hold time (post-production to cleaning start) and clean hold time (post-cleaning to next use). Both require validation. Dirty hold time validation shows that residues dry but remain removable. Clean hold time validation shows cleaned equipment doesn't become recontaminated before use. Both times must be documented in cleaning SOPs and batch records.
5.26 Is non-dedicated (shared) equipment cleaned between products to validated residue limits?
- Shared equipment list with products manufactured
- Cleaning validation reports for each product combination
- Worst-case product identification with rationale
- Residue limits calculated scientifically (PDE/ADE)
- Swab and rinse sampling records
- Analytical methods validated for residue detection
- Campaign changeover procedures
- Cleaning validation maintenance program
- Shared equipment without cleaning validation
- No scientific residue limits
- Validation based on only one product pair
- Worst-case product not identified
- Changeover cleaning not following validated procedure
- Swab sampling locations not representative of hardest-to-clean equipment surfaces
Non-dedicated (shared) equipment is the highest cross-contamination risk in API manufacturing. Cleaning validation must demonstrate effective residue removal to scientifically justified limits (PDE or dose-based calculations). Sampling typically uses swabs at worst-case locations plus rinse samples. The worst-case product determines the cleaning challenge. Every product pair must be covered, often using a matrix approach.
5.30 Are there written procedures for calibrating quality-critical control, weighing, measuring, and test equipment?
- Calibration SOPs for each instrument type
- Calibration schedule by equipment ID
- Calibration records with traceable standards referenced
- Calibration status labels on instruments
- Calibration certificates from external services
- Standards traceability documentation
- Out-of-tolerance procedure
- Calibration training records for technicians
- Instruments without calibration records
- Calibration performed without traceable standards
- No status labels on instruments
- Overdue calibrations still in use
- Out-of-tolerance events not investigated
- In-house calibration without traceability
Calibration is the metrological foundation of quality — if instruments aren't calibrated, all measurements are suspect. The program must cover all quality-critical instruments (balances, thermometers, pH meters, HPLC detectors, etc.) with written procedures and defined frequencies. Traceability to certified standards (NIST, national metrology institutes) is required. Current calibration status must be easily verifiable on every instrument.
5.31 Is calibration performed against standards traceable to certified national or international standards?
- Certificates of calibration showing NIST (or equivalent) traceability
- Working standards inventory with traceability chain
- Current calibration certificates for all standards
- In-house primary standard characterization reports
- Standards storage and handling procedures
- Standards replacement schedule
- Chain of traceability documented for each measurement
- Calibration service provider qualifications
- Calibration standards without traceability certificates
- Expired traceability certificates on working standards
- In-house standards used without characterization
- No chain of traceability documented
- Calibration done with unqualified reference equipment
- Reference standard storage conditions not controlled per manufacturer specifications
Traceability to certified standards (typically NIST in the US, NPL in UK, PTB in Germany, etc.) provides the chain of measurement from the factory floor back to internationally accepted reference values. Each working standard used for calibration must have a current traceability certificate. When no certified standard exists (rare for common measurements), in-house primary standards require characterization documentation.
5.32 Are calibration records maintained for each instrument?
- Calibration records with all required content elements
- As-found vs as-left data captured
- Standards identification on each record
- Technician and reviewer signatures
- Acceptance criteria stated
- Pass/fail determination
- Calibration records traceable to equipment ID
- Electronic or paper calibration record system
- Calibration records missing key data elements
- No as-found data — only as-left reported
- Reviewer signatures missing
- Acceptance criteria not stated on record
- Records unable to be traced to specific instruments
- Calibration results not reviewed for out-of-tolerance
Calibration records must provide complete audit trail for every calibration event. Key content: instrument ID, calibration date and due date, standards used with serial numbers, as-found values (before adjustment), as-left values (after adjustment), acceptance criteria, pass/fail, technician signature, reviewer signature. As-found data is critical for assessing impact on previously tested batches if drift is found.
5.33 Is the current calibration status of instruments readily visible to users?
- Calibration status labels visible on all instruments
- Calibration due date tracking system
- Out-of-tolerance tagging procedure
- Impact assessment procedure for OOT events
- OOT investigation reports
- Batch impact assessment from instrument OOT
- Calibration due date alerts before expiration
- Periodic audit of calibration status labels
- Instruments without visible calibration status
- Calibration labels with conflicting dates
- OOT instruments still in use
- No impact assessment performed for OOT events
- Expired calibration dates ignored
- Calibration due date alert system not functioning or not monitored
Visible calibration status enables operators to verify at-use that instruments are in-tolerance. Labels should show: last calibration date, next due date, calibration ID (linking to the record). Out-of-tolerance instruments must be immediately removed from service and impact assessment performed on all measurements since the last known-good calibration. This impact assessment may require batch-level investigation.
5.34 When an instrument is found out of calibration, is the impact on prior results formally assessed?
- OOT impact assessment SOP
- OOT investigation reports with batch impact analysis
- Timeline analysis from last successful calibration
- Affected batch list for each OOT event
- Risk assessment based on magnitude of deviation
- CAPA linked to OOT events
- Batch disposition reviews for OOT impact
- Regulatory notification where required
- OOT events closed without batch impact assessment
- Impact assessment limited to current batch only
- No documented analysis of deviation magnitude
- Recurring OOT events without systemic CAPA
- Batch release proceeding despite OOT on critical instruments
- Historical calibration drift data not reviewed during impact assessment
This is one of the most significant clauses for data integrity. When an instrument is found out of tolerance, all measurements taken since the last successful calibration are potentially suspect. The impact assessment must identify all affected batches and evaluate whether quality conclusions could change based on the magnitude of the deviation. For critical instruments (assay balances, critical process monitors), this can trigger significant retroactive investigation.
5.35 Are deviations from approved calibration procedures documented and investigated?
- Calibration deviation reports
- Root cause analysis for calibration deviations
- Batch impact assessment from calibration deviations
- CAPA records linked to calibration issues
- Calibration technician training records
- Calibration procedure review triggered by deviations
- Calibration deviation trending
- Management review of calibration program
- Calibration deviations not documented
- Deviations closed without root cause
- No batch impact when calibration procedure not followed
- Recurring calibration deviations without CAPA
- Technician errors not addressed through training
- Calibration procedure revisions not triggered by repeated deviations
This clause covers deviations in the calibration process itself — e.g., using wrong standards, skipping calibration points, adjustment techniques not per procedure. Such deviations may invalidate the calibration. Investigation determines whether the calibration was actually successful, whether batches tested since the last valid calibration are affected, and what corrective action prevents recurrence.
5.40 Are GMP-related computerized systems validated for their intended use?
- Computerized systems inventory with risk categorization
- CSV master plan
- IQ/OQ/PQ documentation for GMP-critical systems
- Vendor assessment records
- GAMP 5 category assignments
- Validation protocols and reports
- System release for operational use
- Change control records for computerized systems
- GMP-critical systems in use without validation
- CSV not performed based on risk
- Vendor assessments not documented
- Validation scope disproportionate to system criticality
- Systems modified without revalidation
- Computerized system inventory incomplete or not maintained
Computerized systems validation (CSV) follows a risk-based approach per GAMP 5. Systems categorized by complexity: Category 1 (infrastructure), Category 3 (off-the-shelf), Category 4 (configured), Category 5 (custom). Higher categories require more extensive validation. Commercial software (e.g., commercial LIMS) benefits from vendor qualification but still requires IQ/OQ in the user's environment. The depth of validation must match the criticality to GMP.
5.41 Are computerized systems subject to appropriate installation and operational qualification?
- IQ protocols for each computerized system
- IQ reports verifying installation
- OQ protocols covering functional testing
- OQ test cases with expected vs actual results
- OQ reports showing acceptance criteria met
- Hardware inventory documentation
- Software version control
- Configuration documentation
- CSV without formal IQ/OQ distinction
- OQ tests not covering critical functions
- Test cases without expected results defined
- Deviations in OQ closed without impact assessment
- No version control on tested software
- Performance qualification omitted for systems with throughput-sensitive GMP functions
IQ covers hardware installation (correct computers, network, peripherals per specification) and software installation (correct version, configuration, access controls). OQ tests system functions across the operating range — data entry, calculations, reports, alarms, security. OQ is often the largest part of CSV documentation. Both should be pre-approved protocols with defined test cases and acceptance criteria.
5.42 Are commercially available (off-the-shelf) systems verified as fit for purpose in the actual environment?
- Vendor assessment reports
- Vendor quality system documentation
- User acceptance testing protocols and reports
- Configuration documentation for commercial software
- Interface testing between systems
- Leverage plan documenting use of vendor data
- Supplier audits for critical vendors
- Periodic vendor requalification
- Commercial systems used without vendor assessment
- No user acceptance testing — relying entirely on vendor claims
- Configuration not documented
- Vendor audits not performed for high-risk systems
- Vendor software modifications not tracked
- Interface testing between integrated systems not performed
Commercial software (LIMS, MES, ERP, etc.) benefits from the vendor's development and testing, but the user organization must still verify fit for purpose in their environment. Vendor assessment (often via questionnaire and audit) documents the vendor's quality system. User acceptance testing (UAT) verifies configuration and integration. Leveraging vendor documentation is acceptable but not a replacement for user-specific validation.
5.43 Are controls in place to prevent unauthorized access to, or changes in, computerized systems and data?
- Access control SOP with role definitions
- Unique user IDs for all users
- Password policy (complexity, expiration)
- Access review reports
- Role-based permission matrix
- Automatic logout settings
- Terminated employee access removal records
- Physical server access controls
- Shared user accounts in use
- Weak or no password policies
- Access not removed for departed employees
- No periodic access review
- Overly broad permissions (e.g., all users as administrators)
- Automatic session timeout not configured on GMP workstations
Access control is foundational to data integrity. Controls include: unique user IDs (no sharing), strong passwords with expiration, role-based permissions, automatic logout, physical access control to servers. Data integrity requires that data cannot be deleted, only marked as corrected with full audit trail. Periodic review of access rights is critical, especially for departed employees.
5.44 Is GMP data routinely backed up, with backups verified and securely stored?
- Backup SOP with frequency and scope
- Backup schedule and automated backup logs
- Offsite or cloud backup records
- Restore test procedure and results
- Disaster recovery plan
- Backup media management
- Backup retention aligned with record retention
- Backup encryption for sensitive data
- No backup for GMP-critical systems
- Backups stored only on-site
- No restore testing — backup integrity unverified
- No disaster recovery plan
- Backup retention shorter than record retention
- Backup encryption missing for systems containing proprietary batch data
Data backup protects against loss from hardware failure, software corruption, or disaster. Standards include: regular automated backups (daily typical), offsite or cloud backup for disaster recovery, documented restore procedures, periodic restore testing to verify backup integrity, retention matching record retention requirements. Backup alone is insufficient without verified restore capability.
5.45 Are changes to electronic data captured with the original value, new value, who made the change, when, and why?
- Audit trail enabled on all GMP systems
- Audit trail review SOP with frequency
- Audit trail review reports
- Audit trail protected from modification
- Reason codes for data changes
- Audit trail coverage verification during validation
- User training on audit trail expectations
- Periodic audit trail functionality testing
- Audit trail not enabled on GMP systems
- Audit trail review not performed
- Users can disable or modify audit trails
- Reason codes not required for data changes
- Audit trail coverage gaps (some operations not tracked)
- Audit trail entries lacking timestamps synchronized to a validated time source
Audit trails are the cornerstone of data integrity for electronic records. They must capture: original value, new value, who made the change, when (timestamp), and why (reason). Audit trails themselves must be tamper-evident and protected from deletion. Periodic review of audit trails is a critical regulatory expectation — not just for anomalies but to confirm the audit trail function is working and being used correctly.
5.46 Are audit trails maintained for computerized systems and reviewed as part of record review?
- Audit trail review as part of batch record review
- QA review of audit trails for release
- Audit trail review documentation
- Audit trail review training
- Examples of issues found through audit trail review
- Audit trail review metrics
- Audit trail accessibility for review
- Periodic system-level audit trail review
- Audit trails not reviewed as part of batch release
- Review is a checkbox exercise without actual examination
- Issues in audit trails not escalated to CAPA
- No documentation of audit trail review
- Audit trail review limited to changes only (not entries)
- Batch-specific audit trail reports not generated for QA reviewer access
This clause reinforces audit trail requirements with emphasis on review as part of batch record review. The review is not optional — it must happen as part of QA batch review. Key questions during review: were all data entries made contemporaneously? Are there suspicious patterns (e.g., all entries by one user late at night)? Are reasons for changes appropriate? Documented review by QA closes the compliance loop.
5.47 Is critical manually entered data subject to an additional verification check?
- SOP requiring second-person verification for critical data entry
- Evidence of second-person verification in records
- Barcode scanning use where possible to eliminate manual entry
- Validated double-entry systems if used
- Training on verification procedures
- Manual entry error tracking
- Controls preventing bypass of verification step
- Critical data identified requiring verification
- Manual entry of critical data without verification
- Second-person verification bypassed or faked
- No distinction between critical and non-critical manual data
- Barcode scanners available but not used
- High rate of manual entry errors without process change
- Transcription error trending not performed for manually entered batch data
Manual data entry is error-prone. Critical data (product IDs, batch numbers, quantities, test results) entered manually should be verified by a second person or automated means. Common approaches: second-person verification with electronic signature, double-key entry (same data entered twice and compared), barcode scanning where possible. The verification must be documented at the point of entry.
5.48 Are computerized-system incidents recorded, investigated, and resolved?
- Computer system incident log
- Incident investigation reports
- Impact assessment for system incidents affecting data
- CAPA linked to system incidents
- Incident response procedures
- System downtime records
- Root cause analysis for recurring incidents
- Integration with quality deviation system
- System incidents not logged or investigated
- No impact assessment on data integrity
- Recurring incidents without systemic CAPA
- Software errors dismissed without root cause analysis
- Incidents handled in isolation from quality system
- Business continuity procedures absent for prolonged system outages
Computerized system incidents include: system crashes during data capture, software errors producing wrong calculations, hardware failures losing data, unauthorized access discovered, audit trail gaps. Each incident must be logged, investigated for root cause, and assessed for impact on data and quality. Critical incidents may trigger OOS investigations or batch impact assessments.
5.49 Are changes to computerized systems managed through formal change control?
- Change control records for computerized system changes
- Change impact assessments
- Revalidation records driven by changes
- System change log separate from code repository
- QA approval of changes before implementation
- Post-implementation verification
- Version control on software and configuration
- Periodic system status review
- System changes made without change control
- No impact assessment for changes
- Revalidation skipped for 'minor' changes without justification
- Configuration changes not documented
- Vendor patches applied without validation assessment
- Operating system updates deployed without regression testing on GMP applications
Computerized systems drift out of validation without change control. Every change (software updates, configuration changes, hardware replacements, interface modifications) must go through the quality change control process. Impact assessment determines revalidation scope — some changes require full revalidation, others only targeted testing. The goal is maintaining the validated state throughout the system lifecycle.
Each item shows its evidence, common nonconformities and auditor tips. The clause index has the PDF of all 350 items, formatted for a clipboard.
The rest of the ICH Q7 API GMP audit checklist
350 items across 18 clauses. Back to the clause index.