Questions that arrive through the contact form, answered here so the next person does not have to ask. Each answer cites the clause. Ask your own at the bottom.
How late does an entry have to be before it counts as a late entry?
There is no number of minutes in any regulation. Contemporaneous means recorded at the time the activity is performed, so an entry made after the operator has moved on to the next step is already late, and an entry made at the end of the shift certainly is. What matters is that a late entry is identified as one: dated and timed when it was actually written, with a reason and, where possible, the evidence the value came from.
The practical rule most sites use is that if you have to remember rather than read, it is a late entry. Write it as one. An honest late entry is a minor observation at worst; an entry backdated to look contemporaneous is a data integrity finding.
Our balance software only has one login. Is a shared account really a finding?
Yes, and it is one of the most cited. Annex 11 section 12 and PIC/S PI 041-1 require that only authorised people can use a system and that the identity of the person making an entry is captured. A shared account means every weighing the instrument has ever recorded is attributable to nobody, and the audit trail, if there is one, cannot say who did what.
If the software genuinely cannot support individual accounts, the accepted interim position is a procedural control: a paper usage log that records who was logged in and when, signed contemporaneously, with the gap recorded in your data integrity risk assessment and a plan to replace or upgrade. Inspectors accept an interim control with a dated plan. They do not accept 'the vendor does not support it' on its own.
Annex 11 says audit trails should be regularly reviewed; it does not say how often. The EMA data integrity Q&A and PIC/S PI 041-1 expect the frequency to follow the risk: for data that supports batch release, the audit trail for that data should be reviewed as part of the batch review, before release. For lower-risk systems a periodic review is defensible if the risk assessment says why.
The finding is rarely about frequency. It is about a review that is a signature on a checkbox with no record of what was looked at. Record which events you reviewed, which entries needed explanation, and what you concluded. A review log that shows nothing was found, every time, for a year, is its own finding.
If we print the chromatogram and sign it, is the printout the raw data?
No. The electronic record, with its metadata and audit trail, is the original; the printout is a static representation of it. PIC/S PI 041-1 and the EMA data integrity Q&A both say so explicitly. A printout cannot show the integration parameters, the processing history, or whether the result was reprocessed. Retaining only the printout and deleting or not backing up the electronic data is a finding.
A printout can serve as a true copy of a simple record where there is no dynamic content, such as a balance ticket, if the copy is verified and the process for making it is defined. For chromatography, spectroscopy and anything with processed data, the electronic record must be retained for the full retention period.
When does a spreadsheet become a GMP computerised system that needs validating?
As soon as it performs a calculation or holds a record that a GMP decision relies on: an assay result, a stability trend, a yield reconciliation, a calibration due date. At that point Annex 11 applies. In practice that means the workbook is locked so formulas cannot be changed, the calculation is verified against a known input, the file is version controlled, and access to the template is restricted.
A spreadsheet used to draft, explore or transcribe values that are then entered and checked in a validated system is a different matter. Keep a list of which is which; the inventory in the data integrity risk assessment is the usual place.
We back up the server every night. Is that the same as archiving?
No. Backup is a copy kept to restore a system after failure and is usually overwritten on a cycle. Archive is the long-term retention of the record itself, protected from change, with a way to retrieve and read it for the whole retention period. A nightly backup that is overwritten after 30 days retains nothing from last year.
The retention period is set by the regulation: at least one year after the batch expiry under EU GMP, or five years for certain records, and the archived electronic record must remain readable, which means keeping the software or a validated migration path, not just the files.
Can a batch record be corrected after it has been reviewed and signed?
Yes, provided the correction follows the same rules as any other: single line through the original so it stays legible, the new value, initials, date and a reason. Because the record was already reviewed, the correction must also be seen by the reviewer, and if it changes any result or decision it needs a deviation, not just a correction. What is never acceptable is re-issuing a clean page and destroying the signed one.
Is data integrity only a laboratory problem? We are a packaging site.
Data integrity is cited at every kind of site. Packaging sites are found on line clearance records completed in advance, checkweigher and vision system data that nobody reviews, shared logins on serialisation systems, and batch records where the counts do not reconcile with the equipment counters. The laboratory examples are prominent in the published findings because chromatography data systems make manipulation easy to detect, not because production is exempt.
The course uses laboratory and production examples in every module, and Module 6 covers how to build a site-wide data governance programme rather than a QC one.