In This Article
- Executive Summary
- What the Enforcement Record Actually Says
- Seven Recurring Finding Types in Testing Laboratories
- Six Sponsor Oversight Gaps That Let Them Through
- Audit Trail Review Sampling at the Contract Lab
- The Data Package That Replaces a Certificate
- Contract Terms That Make Oversight Possible
- Qualification and Requalification That Tests Data Integrity
- Running the Program Across a Portfolio of Labs
- Conclusion
- For Further Reading
- References & Sources
Executive Summary
Sponsors outsource testing to contract laboratories and then supervise those laboratories with tools that cannot see the thing most likely to go wrong. The published enforcement record from 2023 through 2026 is specific about what goes wrong in a testing laboratory, whether it is an independent contract laboratory or a manufacturer’s own quality control laboratory: original printouts in a waste bin, hundreds of peak-modification privileges exercised over three years, a shared password kept in an unsecured drawer, analysts with rights to change the date and time of a test, trial injections that never reach a record, and instruments used for batch release that have no audit trail at all.1 7 6 9 8
None of those findings would surface in a certificate of analysis, and almost none would surface in a standard two-day quality audit driven by a checklist the laboratory has seen before. The gap is not that sponsors fail to audit. It is that the audit scope, the reporting format, and the contract were all written for a world where the only question was whether the number met the specification. FDA has been direct on the principle: it considers contractors as extensions of the manufacturer’s own facility, and the clients of a contract laboratory, including drug manufacturers and application sponsors, rely on the integrity of the data that laboratory generates.2 1
This article reads the actual letters and regulatory notices, organizes the recurring finding types, maps each one to the specific sponsor oversight gap that allowed it to pass unnoticed, and then sets out what to do instead: how to sample audit trails at a laboratory you do not own, what to request in place of a certificate, which contract terms make any of it enforceable, and how to build qualification and requalification that tests data integrity rather than assuming it.
What the Enforcement Record Actually Says
There is a lot of commentary about contract laboratory data integrity and comparatively little reading of the source documents. That matters, because the commentary tends to compress everything into a single message about culture, while the letters themselves describe a set of quite different mechanical failures with quite different detection methods. If you want to design oversight that works, the mechanics are the useful part.
Start with the regulatory position, because it settles the question of whose problem this is. In its October 2024 letter to Analytical Food Laboratories, a contract testing laboratory in Grand Prairie, Texas, FDA restated the principle plainly: it considers contractors as extensions of the manufacturer’s own facility.2 In its July 2025 letter to Shiva Analyticals Private Limited, FDA noted that the laboratory’s clients, including drug manufacturers and application sponsors, rely on the integrity of the data generated there to assess drug quality and make related decisions.1 In its August 2025 letter to the Chromatography Institute of America, operating as Compounders International Analytical Laboratory, FDA told the laboratory it must inform all of its customers of any out-of-specification results or significant problems encountered during testing.3
Read those together and the position is not ambiguous. The laboratory carries its own CGMP obligations. The sponsor carries the obligation to know whether the laboratory is meeting them. Neither obligation transfers to the other party by contract.
The scale of what happens when the check fails
The consequences are not theoretical. In December 2023, following a good clinical practice inspection of Synapse Labs Pvt. Ltd, a contract research organization in Pune, India, the European Medicines Agency’s human medicines committee recommended suspending marketing authorizations for generic medicines whose bioequivalence rested on studies run at that site. EMA described the inspection as showing irregularities in study data and inadequacies in study documentation and in the computer systems. Over 400 medicines had been tested by Synapse Labs on behalf of EU companies. For around 35 of them, sufficient supporting data were available to demonstrate bioequivalence, so those authorizations were maintained. For the rest, supporting data were lacking or insufficient, and the committee recommended suspension. EMA also stated there was no evidence of harm or lack of effectiveness with any of the affected medicines.14 The committee confirmed its recommendation after re-examination in March 2024, and the European Commission issued a binding decision in May 2024.15
That is the shape of the risk. Not a recall. Not a fine. A regulator concluding that the evidence underneath a portfolio of approvals cannot be relied on, and a set of sponsors discovering at that moment that they have no independent basis to argue otherwise.
EMA, December 2023
EMA referral record
FDA, March 2025
FDA maintains a short public list of these events under the heading Notifications on Data Integrity. As of this writing it carries four notifications naming five organizations whose study data the agency has found unacceptable: Semler Research in April 2016, Panexcell Clinical Lab and Synchron Research Services in September 2021, Synapse Labs in June 2024, and Raptim Research Pvt. Ltd in March 2025.12 The Raptim notification, dated March 28, 2025, states that FDA identified significant data integrity and study conduct concerns with bioequivalence studies conducted there, that in vitro studies conducted by Raptim are not acceptable, and that affected sponsors had 30 days to respond with plans to re-conduct the studies at sites that do not have data integrity concerns or to voluntarily request withdrawal of approval.13
Four notifications in nine years is a small number, and it is tempting to read it as a rare event. The better reading is that these are the cases where a regulator inspected the laboratory directly. The population of laboratories nobody has inspected recently is much larger, and in that population the sponsor is the only party looking.
The pattern worth noticing. In every one of these cases, the sponsors were receiving results that looked entirely normal. Certificates arrived on time. Numbers met specification. Nothing in the ordinary flow of information between laboratory and sponsor carried a signal. The failure was invisible from the sponsor’s side by design, because the sponsor had never asked to see anything that would have shown it.
Seven Recurring Finding Types in Testing Laboratories
Reading the 2023 to 2026 letters against each other, the same seven mechanisms keep appearing. They are worth separating, because each one has a different tell and a different countermeasure.
1. Unreported results and undocumented trial injections
This is the oldest pattern and still the most common. An analyst runs a sample, does not like the result, runs it again, and reports only the second run. The first run is described as a trial injection, a system check, or nothing at all.
In its July 2026 letter to Shimoga Chemicals, an active pharmaceutical ingredient manufacturer in India inspected in January 2026, FDA recorded that the firm acknowledged undocumented trial injections, unreported analytical data, and discarded printouts, and that the unreported data included an injection with an out-of-specification assay result. The letter also states that the firm lacked procedures for electronic data review and that its quality unit did not review the electronic data.9 The two findings belong together. Unreported injections are only sustainable where nobody opens the instrument’s own record of what was run.
2. Audit trails disabled, absent, or never reviewed
There are two versions of this and they need different fixes. In the first, the function does not exist. FDA’s September 2024 letter to MMC Healthcare Ltd, following a March 2024 inspection, describes a UV-Vis spectrophotometer used for release testing of drug batches that lacked mechanisms to assure the integrity of electronic test data, including an audit trail and defined user access levels.8 The June 2024 letter to Landy International describes a stand-alone gas chromatograph computer system that lacked appropriate controls such as an audit trail.7 In its August 2025 letter to the Chromatography Institute of America, FDA recorded that the laboratory had said it would create individual logins on its computers and was looking into installing technology with audit trail capability, which is a statement about a laboratory that did not have one at the time of inspection.3
In the second version, the audit trail exists and produces a complete record that nobody reads. FDA’s July 2025 letter to Shiva Analyticals states that investigators documented laboratory analysts performing hundreds of entries related to Add/Modify/Delete peaks and Alter existing file on disk user privileges between January 16, 2022 and January 23, 2025.1 Three years of activity, all of it recorded, none of it examined until an inspector examined it.
3. Shared logins and inadequate access control
FDA’s letter to Landy International describes laboratory personnel using a shared password located in an unsecured drawer to access the gas chromatography software, and a system that lacked individual log-in access to prevent the deletion of data. The letter also records that FDA cited similar CGMP observations at the facility during a January 2017 inspection.7
The access control failure is not only about who logs in. It is about what the account can do once it is logged in. FDA’s March 2025 letter to International Laboratories Corp, following a September 2024 inspection, describes analysts holding administrative rights capable of altering and deleting data, files, and folders on chromatographic systems.6 Where analysts hold administrator privilege, the audit trail is advisory rather than protective, because the same account that generates the record can adjust it.
4. Results reprocessed until they pass
Reintegration and retesting are legitimate laboratory activities with legitimate reasons. They become a finding when the reason is not recorded, not reviewed, or not true. FDA’s November 2025 letter to Rhyz Analytical Labs, a contract testing laboratory in Provo, Utah performing chemical and microbiological testing of over-the-counter drug products, describes inadequate investigations into microbiological test failures, acceptance of unknown laboratory error as a root cause without scientific justification, and reliance on retest data without investigating the source of contamination.4
The mechanism here is subtle and it is the one sponsors are least equipped to see. Nothing was deleted. Nothing was hidden. A failing result was investigated, the investigation reached a conclusion that explained nothing, and a passing retest replaced it. From outside, the paperwork is complete.
5. Backdated and non-contemporaneous entries
FDA’s letter to MMC Healthcare describes a process validation report containing data that had been added, backdated signatures, and replaced pages, with quality personnel admitting they participated.8 FDA’s standard data integrity remediation request, which appears in letters of this kind including the January 2025 letter to Global Calcium Pvt. Limited, an API manufacturer in Hosur, India, asks firms to identify non-contemporaneous record completion among other omissions and alterations.10
The paper trail for this one often begins in a bin. FDA’s Shiva Analyticals letter describes investigators finding torn and discarded original CGMP documents in the laboratory’s main waste disposal area, including analytical balance weighing printouts, pH meter printouts, and analytical method verification records, and notes that these carried test weights different from the weights documented in testing.1 Landy International’s letter describes numerous analysis reports, test methods, raw data calibration files, and system directories found in the gas chromatograph computer’s recycling bin.7
6. Uncontrolled spreadsheets and uncontrolled forms
A calculation performed in an unmanaged spreadsheet is a result with no provenance. FDA’s Global Calcium letter describes investigators observing Microsoft Excel documents on a desktop computer, including files relating to cleaning validation samples and production details, and then finding on the second day of the inspection that all of those files had been deleted and could not be recovered.10
The same category covers uncontrolled paper. FDA’s Analytical Food Laboratories letter directs the laboratory to control the issuance and reconciliation of uncontrolled loose forms used for documenting laboratory testing, equipment use, and calibrations, and to review laboratory records for completeness including documentation of blank, sample, and mobile phase preparations.2 The Chromatography Institute letter describes an unapproved sample preparation document titled Sample Prep Tips and Tricks in use by laboratory staff without quality unit review, alongside the absence of an effective document control system for issuance, tracking, and reconciliation of CGMP documents.3
7. Instrument clocks and system dates that can be changed
The last mechanism is the one that makes all the others harder to detect, because it corrupts the sequence that an audit trail review depends on. FDA’s International Laboratories Corp letter states that analysts held administrative rights capable of altering and deleting data, files, and folders on chromatographic systems, including the date and time of tests. The same letter records that the laboratory manager confirmed the firm fabricated several laboratory investigations that were not performed, that a senior quality assurance manager acknowledged investigations were fabricated in preparation for the FDA inspection, and that numerous electronic raw data files had been deleted.6
If a user can set the clock, timestamps stop being evidence. Any review that reasons from the order of events is reasoning from something the reviewed party controls.
A note on method problems that are not integrity problems. Not every contract laboratory finding is about honesty. FDA’s February 2025 letter to ABR Laboratory LLC, a contract testing laboratory in Hollywood, Florida inspected in September 2024, cites failure to establish and document the accuracy, sensitivity, specificity, and reproducibility of its test methods, including growth media whose composition was not verified as equivalent to compendial methods and the absence of method suitability testing. The same letter describes refrigerator temperature excursions reaching 17.4 degrees Celsius in a unit holding reference microorganisms, which were not identified or investigated.5 These are competence and control findings rather than falsification findings, and they invalidate results just as completely. Oversight designed only to detect dishonesty will miss them.
Six Sponsor Oversight Gaps That Let Them Through
Each of the seven mechanisms above survived at a laboratory that had sponsors. Those sponsors were, in most cases, doing what their procedures told them to do. The procedures were the problem. Here are the six gaps that recur, matched to the findings they fail to catch.
| Finding type | What the sponsor was looking at | The gap |
|---|---|---|
| Unreported results and trial injections | The reported result and its certificate | Result reporting format shows a final number, never the injection sequence behind it |
| Audit trail absent or unreviewed | An audit checklist question asking whether audit trail review is performed | Audit scope never opens an actual audit trail for a real batch |
| Shared logins, analyst administrator rights | The laboratory’s user access procedure | Procedure reviewed, live user and privilege list never requested |
| Reprocessing and retesting until pass | The closed investigation summary | No right of access to underlying raw data to test the stated root cause |
| Backdating, non-contemporaneous entry | Signed and dated records supplied by the laboratory | Reliance on certificates of analysis without periodic raw data review |
| Uncontrolled spreadsheets and forms | The laboratory’s document control SOP | Audit agenda built from a checklist the laboratory has seen before |
| Changeable instrument clocks | Nothing | Infrequent onsite presence, so system configuration is never observed live |
Gap one: an audit scope that never opens the audit trail
The most common single weakness. A sponsor’s quality audit of a contract laboratory asks whether audit trail review is performed, receives a yes and a procedure reference, records the answer, and moves on. It does not select a batch, ask for that batch’s audit trail, and read it. The difference between those two activities is the difference between confirming a policy exists and confirming the policy is followed.
Both the Shiva Analyticals and Shimoga Chemicals letters describe circumstances a sponsor could have found this way. Three years of peak modification privileges being exercised, and a quality unit that did not review electronic data, are both visible in the first hour of looking at a real trail for a real sample.1 9
Gap two: an agenda the laboratory has seen before
Contract laboratories serving many sponsors receive many audits. Where every sponsor uses a similar checklist, the laboratory learns the checklist. Preparation becomes a routine: the documents the auditors always ask for are ready, the rooms they always visit are in order, the people they always interview are available. This is not necessarily dishonest. It is the predictable result of a predictable process.
The International Laboratories Corp letter contains the strongest statement of where this ends. A senior quality assurance manager acknowledged that laboratory investigations were fabricated in preparation for the FDA inspection.6 Preparation for an announced audit is a normal activity. When the auditor’s requests are known in advance, preparation and fabrication become adjacent activities.
Gap three: a result format that shows only the final number
Most sponsors receive test results as a certificate: analyte, method, specification, result, pass or fail, signature. That format is a summary of a decision, not evidence for it. It cannot show how many injections were made, whether any were excluded, whether the integration was adjusted, or when each event occurred.
Article 10 in this series works through where the boundary between raw data and processed data actually falls in chromatography systems, and that boundary is exactly what a certificate hides. If the reporting format never crosses it, no amount of diligence applied to the certificate will help.
Gap four: no right of access to raw data in the contract
Sponsors regularly discover, at the moment they most need it, that their agreement gives them the right to audit the laboratory but not the right to obtain and retain the underlying electronic records. The audit right permits a visit. It does not always permit an export.
This one is fixable and the regulatory expectation is already written. ICH Q7 section 16 states that all contract manufacturers, including laboratories, should comply with GMP; that they should be evaluated by the contract giver to ensure GMP compliance of the specific operations occurring at the contract sites; that there should be a written and approved contract defining in detail the GMP responsibilities of each party; and that the contract should permit the contract giver to audit the contract acceptor’s facilities for compliance with GMP.18 Article 24 in this series covers quality agreement clause drafting in depth, and that is the right place to work out the language. The point here is narrower: the access right has to exist before you need it.
Gap five: reliance on certificates without periodic raw data review
Certificates are supplier assertions. Treating them as verification is a recognized enforcement theme in its own right. FDA’s December 2025 letter to Integrity Partners Group, following a June 2025 inspection of the Chemisphere Corporation site in Saint Louis, cites the firm for failing to conduct at least one test to verify the identity of each component, having relied on supplier certificates instead.11
The same logic applies one level up. A sponsor that accepts a contract laboratory’s certificate without ever reviewing the data behind one is in the same position as a manufacturer accepting a supplier’s certificate without ever testing an incoming material. The document is a claim about the evidence, and nobody has looked at the evidence.
Gap six: infrequent onsite presence
Some findings only exist in the room. Whether the instrument workstation clock can be changed by the logged-in analyst, whether original printouts are being discarded, whether uncontrolled forms are in circulation, whether an unapproved tips document is taped inside a cupboard: these are physical observations. The Shiva Analyticals waste bin, the Landy International drawer, and the Chromatography Institute sample preparation document were all found by someone standing in the laboratory.1 7 3
Remote and paper-based oversight has real advantages and should carry most of the routine load. It cannot carry this part.
The single question that reframes a contract lab audit
Instead of asking the laboratory to demonstrate that its controls work, pick one batch you released on that laboratory’s data in the last quarter and ask the laboratory to reconstruct it completely: every injection, every user action, every reintegration, every deviation, in sequence, from the system’s own records. Then check that reconstruction against the certificate you received.
Most of the seven finding types will either appear or be ruled out in that one exercise. It also has the useful property that it cannot be prepared for in the abstract, because you choose the batch.
Audit Trail Review Sampling at the Contract Lab
Sponsors often accept that they should review audit trails at contract laboratories and then get stuck on the practical question of how much and which. Reviewing everything is not possible. Reviewing nothing is what got the industry here. What follows is a workable middle.
Define the sampling frame before you choose the sample
Do not start from a number of records. Start from a list of the decisions that laboratory’s data supports for you. Batch release. Stability trend conclusions. Comparability claims. Specification setting. Investigation closures. Each of those is a decision your organization owns, taken on evidence someone else generated. The sampling frame is the population of those decisions, not the population of the laboratory’s tests.
From that frame, weight the sample toward the decisions where a wrong answer would be least recoverable, and toward the analytes and methods with the highest historical rate of retesting or investigation. If a method has never produced a failing result across two years of routine use, that is a candidate for sampling rather than a reason to skip it.
What to actually look at
Injection and run sequence
Every injection performed on the sample set, in order, including any that were aborted, excluded, or labeled as trial, system suitability, or blank. Compare the count to the count implied by the reported result.
Processing and reintegration events
Every change to a method, integration parameter, or peak assignment after acquisition, with the user, the timestamp, and the stated reason. A reintegration with no reason recorded is a finding regardless of what the result was.
User accounts and privilege
The live account list, the privilege assigned to each, and which accounts hold rights to delete data, alter files on disk, or modify system date and time. Ask for it as a system export, not as a procedure.
System configuration and clock
Whether the audit trail is enabled for all relevant object types, whether it can be turned off and by whom, whether the workstation clock is synchronized to a controlled time source, and who can change it.
Deletion and recovery events
Any deleted file, orphaned data set, or recovered project in the period. The Landy International and Global Calcium letters both turned on deleted material, one in a recycle bin, one removed overnight during an inspection.
Evidence of the lab’s own review
The laboratory’s audit trail review records for the same period: who reviewed, what they reviewed, what they found, and what happened to what they found. A review that has never raised anything is a review to examine closely.
How often, and how to keep it honest
A reasonable baseline for a laboratory carrying material decisions is a documented review of at least one full data package per quarter, plus one during each onsite audit, plus one triggered by any event that would make you look anyway: an out-of-specification result, an investigation you found unconvincing, a change of laboratory management or of the analyst signing your work, or a regulatory action anywhere in that laboratory’s group.
Two rules keep the exercise from decaying into a formality. First, you choose the batch, not the laboratory, and you choose it after the data exists. Second, someone who understands the instrument software does the reading. A quality auditor who has never opened a chromatography data system will read what they are shown. Where that skill does not exist internally, buy it for the day.
What a good result looks like. The reconstruction matches the certificate. Every injection is accounted for. Every reintegration has a recorded reason that a second person reviewed before release. The user list contains no shared or generic accounts and no analyst with rights to delete data or change the system clock. The laboratory’s own audit trail review found something in the period, investigated it, and closed it. That last point is not a defect. A review process that has never found anything is either looking at nothing or reporting nothing.
The Data Package That Replaces a Certificate
Changing what you receive is more durable than changing how hard you look at what you already receive. The certificate of analysis should remain, because it is the formal statement of conformance. It should stop being the only thing that arrives.
Specify a data package in the technical agreement, define its contents by test type, and require it either with every batch for the highest-consequence work or on a defined sampling basis for the rest. This is not a request for the laboratory’s entire data set. It is a defined, repeatable extract.
The reported result, with its full analytical context
Method identifier and version, instrument identifier, column or detector identifier, analyst, date of acquisition, date of processing, and the reviewer. Version matters: a result produced under a method revision you were not told about is a change control question, not a data question.
The complete injection sequence for the sample set
All injections in acquisition order with their identifiers and dispositions, including system suitability, blanks, standards, and anything excluded. This is the single most valuable item, because it is what a certificate structurally cannot show.
The processing history
Every reintegration or reprocessing event affecting the reported result, with user, timestamp, and reason, plus both the original and final chromatograms where a peak assignment changed.
The audit trail extract for the sample set
A system-generated export covering the acquisition and processing window, in the system’s own format rather than transcribed into a summary document. A summary written by the laboratory is testimony. The export is evidence.
Any related deviation, investigation, or out-of-specification record
Including ones the laboratory closed as invalid or as laboratory error, and including the retest data. Rhyz Analytical Labs was cited for accepting unknown laboratory error as a root cause without scientific justification, which is only visible if you see the investigation.
Evidence of second-person review before release
Who performed the technical review, what it covered, and whether it included the electronic records rather than only the printed summary. Shimoga Chemicals was cited for lacking procedures for electronic data review and for a quality unit that did not review the electronic data.
Deciding who gets which package
Not every test justifies this. A sensible tiering is by consequence rather than by volume. Testing that supports batch release, a regulatory submission, a stability commitment, or a specification decision gets the full package. Testing that supports internal monitoring, development screening, or informational trending gets the certificate plus an annual data package review. Anything supporting a claim in a marketing application gets the full package plus a documented independent technical review before submission.
One caution on scope. A data package is only useful if someone reads it. Requiring a full package from every laboratory for every test, with no capacity to review any of them, produces a large archive and no assurance. Start with the tier that matters and expand as the review capability grows.
Contract Terms That Make Oversight Possible
Everything above depends on rights the sponsor either has or does not have when the moment comes. Article 24 in this series handles quality agreement clause drafting in detail and this section deliberately does not duplicate it. What follows is the narrow set of terms specific to data integrity oversight at a testing laboratory, and the regulatory language that already supports each one.
EU GMP Chapter 7 on outsourced activities is the clearest source. Clause 7.5 makes the contract giver responsible, before outsourcing, for assessing the legality, suitability and competence of the contract acceptor. Clause 7.7 requires the contract giver to monitor and review the performance of the contract acceptor. Clause 7.8 makes the contract giver responsible for reviewing and assessing the records and the results related to the outsourced activities. Clause 7.16 states that all records related to the outsourced activities, including analytical records, should be kept by or be available to the contract giver, and that any records relevant to assessing the quality of a product in the event of complaints or a suspected defect must be accessible and specified in the contract giver’s procedures. Clause 7.17 states that the contract should permit the contract giver to audit outsourced activities performed by the contract acceptor or its mutually agreed subcontractors. Clause 7.11 requires the contract acceptor not to subcontract without the contract giver’s prior evaluation and approval.17
Those clauses have been in force since January 2013. In practice, agreements are often written as though only the audit right in 7.17 exists. The records access right in 7.16 is the one that matters most for data integrity oversight, and it is the one most often left out.
Data integrity terms worth checking in your current agreements
- Electronic records access, not only audit access. The right to request, receive, and retain system-generated audit trail extracts and raw data files in native or agreed format, within a defined number of business days.
- Unannounced and short-notice visits. A defined number per year, with a scope that explicitly includes observing live systems and user privilege.
- Notification of regulatory contact. Written notice within a short fixed period of any inspection, observation, warning letter, statement of non-compliance, or import action affecting the site or the systems used for your work.
- Notification of data integrity events. A duty to inform you of any confirmed or suspected data integrity issue affecting your samples, including invalidated results and any retrospective data review the laboratory undertakes.
- Subcontracting consent. No transfer of your testing to another site or third party without prior written approval, matching Chapter 7 clause 7.11 and ICH Q7 clause 16.14.
- Retention and return on exit. Defined retention periods for raw data and audit trails, and a defined mechanism for obtaining readable copies if the relationship or the laboratory ends.
- Change notification for systems and methods. Notice before changes to instruments, chromatography data systems, method versions, or the release approver for your work.
One more point, and it is not a clause. Article 20 in this series deals with what happens when three vendors touch one record and nobody owns the defect. The contract terms above only work if the sponsor has decided internally who reads the data package, who acts on a notification, and who has authority to stop using a laboratory. A right nobody is accountable for exercising is not a control.
Qualification and Requalification That Tests Data Integrity
Most contract laboratory qualification programs were designed to answer a competence question: can this laboratory perform this method to an acceptable standard. That question is still worth asking. It is not the question the enforcement record says is failing.
What to add to initial qualification
Three additions cover most of the gap, and none of them require a longer visit.
Test the system, not the procedure. During qualification, ask the laboratory to demonstrate live, on the actual system that will run your work, that the audit trail is enabled, that it captures deletion and reintegration, that it cannot be disabled by an ordinary analyst account, and that the workstation clock cannot be altered by that account. Ask to see the current user and privilege export. This takes under an hour and it distinguishes a laboratory with controls from a laboratory with a controls SOP.
Run a reconstruction on a real historical batch. Ask the laboratory to reconstruct any completed sample set from its own records, of your choosing, from the last six months. You are not assessing the result. You are assessing whether the reconstruction is possible, how long it takes, and whether the laboratory’s staff can do it without help from the vendor.
Check compliance status independently. Manufacturers’ authorizations and GMP certificates can be verified using the MHRA-GMDP database or the EU database, and statements of GMP non-compliance are published in EudraGMDP alongside positive certificates.19 20 FDA’s Notifications on Data Integrity page carries the drug-side notifications about specific research organizations.12 These checks take minutes and belong in the qualification file, dated, with a defined recheck frequency.
Accreditation is not the same as compliance. A laboratory holding an accreditation, or an award under a voluntary conformity assessment scheme, has demonstrated something real about its technical competence. It has not thereby demonstrated GMP compliance for your operations, and no regulator treats it as a substitute. In its February 2024 letter to industry on fraudulent and unreliable laboratory testing data, FDA encouraged working with third-party laboratories accredited under its voluntary program while stating plainly that this does not substitute for independent assessment of all third-party data.16
What to change about requalification
Requalification on a fixed calendar is the norm and it is the weakest part of most programs. Two years pass, a form is completed, the same checklist produces the same answers, and the file is closed. Nothing in that cycle responds to what has actually happened at the laboratory.
Move to a risk-triggered model layered on top of a maximum interval. Keep the outer limit so nothing drifts indefinitely. Then define triggers that pull a requalification forward:
- Any regulatory action, observation, or non-compliance statement affecting the site, the group, or a sister site using the same systems.
- A change of quality unit leadership, laboratory management, or the person who approves release of your results.
- Migration or upgrade of the chromatography data system, laboratory information management system, or the instruments running your methods.
- A rise in invalidated results, retests, or investigations on your work, whatever conclusion those investigations reached.
- A data package review that produced a finding, or a reconstruction request the laboratory could not complete promptly.
- Transfer of your testing to a different site within the same organization.
The last trigger deserves attention. Work moves between sites inside a laboratory group more often than sponsors realize, and the qualification file frequently still describes the original site. EU GMP Chapter 7 clause 7.11 and ICH Q7 clause 16.14 both require prior evaluation and approval before work is passed to a third party.17 18 Movement within a group is not always treated as subcontracting by the laboratory, so it is worth naming explicitly in the agreement.
Running the Program Across a Portfolio of Labs
A mid-size sponsor may use twenty or more testing laboratories. Applying everything above to all of them at once is not realistic, and attempting it usually produces a program that looks thorough in a procedure and is not performed. Three practical constraints shape a version that survives.
Tier by consequence and be honest about the tail
Rank laboratories by what their data decides, not by spend. A small laboratory running one release method for one commercial product outranks a large one running development screening. Put the full data package, quarterly audit trail review sampling, and short-interval requalification on the top tier. For the tail, apply a lighter cycle and accept the residual risk explicitly, in writing, with a named owner. An acknowledged gap is manageable. An unacknowledged one is what turns into a surprise.
Build the skill before you build the procedure
Audit trail review at a contract laboratory needs someone who can read a chromatography data system’s own records and recognize what is missing. That skill is scarce in quality organizations and it does not arrive with a new SOP. Identify who has it, and if nobody does, train two people properly or contract the capability for the reviews that matter. A procedure requiring a review nobody can perform generates completed forms and no assurance.
Close the loop back into your own decisions
A finding at a contract laboratory has to reach the decisions that were made on that laboratory’s data. That means the qualification file, the audit trail review record, and the batch release record need to be connected well enough that you can answer one question quickly: which of our released batches, submissions, and stability conclusions rest on data from this site, over what period. Sponsors caught by the Synapse Labs and Raptim Research notifications discovered that the hard part was not reacting to the notice. It was establishing the exposure.14 13
The realistic first year. Pick the three laboratories whose data supports your highest-consequence decisions. Add the data package to those agreements at the next amendment. Run one reconstruction exercise per laboratory in the first quarter, with someone who can read the system. Verify each site’s public compliance status and record the check. Add the data integrity triggers to your requalification procedure. That is a year of work for a small team, it is achievable, and it covers the exposure that would be hardest to recover from.
Conclusion
The enforcement record from 2023 through 2026 is unusually clear about what fails in testing laboratories, whether they are independent contract laboratories or a manufacturer’s own quality control laboratory, and it is not mysterious. Original printouts in a bin. A shared password in a drawer. Analyst accounts with rights to delete files and change the system clock. Trial injections that never reach a record. Reintegrations nobody reviewed for three years. Instruments performing release testing with no audit trail at all. Investigations closed to unknown laboratory error, and retests reported as though the first result had never happened. Each of these appears in a public letter, at a named site, with a date.
What the record also shows is that sponsors were present throughout. They had contracts, quality agreements, audit schedules, and approved supplier lists. The oversight was real. It was aimed at the wrong surface. A certificate cannot show an unreported injection, a document control SOP cannot show an uncontrolled spreadsheet, and a checklist question about audit trail review cannot show a trail nobody opened. The correction is not more oversight. It is oversight pointed at the underlying data, supported by a contract that gives you the right to obtain it and a reviewer who can read it.
Sakara Digital works with pharma and biotech organizations on data integrity and vendor oversight programs that hold up under inspection, including audit trail review sampling at contract laboratories, data package specifications, and qualification approaches that test the controls rather than the procedures describing them. If you are reworking how you supervise the laboratories your release decisions depend on and want an independent perspective on where to start, we are happy to have that conversation.
For Further Reading
For Further Reading
- Data Quality SLAs in CRO and CDMO Contracts: Language That Actually Holds
- Lab Instrument Data Integration: Raw Data, Metadata, and the Contextualization Gap
- Data Integrity and ALCOA+ in the Digital Age: Modernizing Compliance for Cloud and AI Systems
- Supplier Quality Management for Pharma: What Good Looks Like in 2026
- Vendor Qualification in a Cloud-First World: Adapting Your Process
- Third-Party Risk Management for Pharma: Building Resilient Vendor Ecosystems
- Internal Audit Program Analytics: Scheduling Audits by Risk, Not Calendar
References & Sources
- U.S. Food and Drug Administration. “Shiva Analyticals Private Limited – 707857 – 07/23/2025.” Warning Letter, July 23, 2025. https://www.fda.gov/inspections-compliance-enforcement-and-criminal-investigations/warning-letters/shiva-analyticals-private-limited-707857-07232025
- U.S. Food and Drug Administration. “Analytical Food Laboratories, Inc. – 687513 – 10/10/2024.” Warning Letter, October 10, 2024. https://www.fda.gov/inspections-compliance-enforcement-and-criminal-investigations/warning-letters/analytical-food-laboratories-inc-687513-10102024
- U.S. Food and Drug Administration. “Chromatography Institute of America dba Compounders International Analytical Laboratory – 708944 – 08/20/2025.” Warning Letter, August 20, 2025. https://www.fda.gov/inspections-compliance-enforcement-and-criminal-investigations/warning-letters/chromatography-institute-america-dba-compounders-international-analytical-laboratory-708944-08202025
- U.S. Food and Drug Administration. “Rhyz Analytical Labs – 715298 – 11/12/2025.” Warning Letter, November 12, 2025. https://www.fda.gov/inspections-compliance-enforcement-and-criminal-investigations/warning-letters/rhyz-analytical-labs-715298-11122025
- U.S. Food and Drug Administration. “ABR Laboratory LLC – 696872 – 02/10/2025.” Warning Letter, February 10, 2025. https://www.fda.gov/inspections-compliance-enforcement-and-criminal-investigations/warning-letters/abr-laboratory-llc-696872-02102025
- U.S. Food and Drug Administration. “International Laboratories Corp – 698522 – 03/10/2025.” Warning Letter, March 10, 2025. https://www.fda.gov/inspections-compliance-enforcement-and-criminal-investigations/warning-letters/international-laboratories-corp-698522-03102025
- U.S. Food and Drug Administration. “Landy International – 679066 – 06/12/2024.” Warning Letter, June 12, 2024. https://www.fda.gov/inspections-compliance-enforcement-and-criminal-investigations/warning-letters/landy-international-679066-06122024
- U.S. Food and Drug Administration. “MMC Healthcare Ltd. – 684644 – 09/24/2024.” Warning Letter, September 24, 2024. https://www.fda.gov/inspections-compliance-enforcement-and-criminal-investigations/warning-letters/mmc-healthcare-ltd-684644-09242024
- U.S. Food and Drug Administration. “Shimoga Chemicals – 727904 – 07/13/2026.” Warning Letter, July 13, 2026. https://www.fda.gov/inspections-compliance-enforcement-and-criminal-investigations/warning-letters/shimoga-chemicals-727904-07132026
- U.S. Food and Drug Administration. “Global Calcium Pvt. Limited – 692000 – 01/16/2025.” Warning Letter, January 16, 2025. https://www.fda.gov/inspections-compliance-enforcement-and-criminal-investigations/warning-letters/global-calcium-pvt-limited-692000-01162025
- U.S. Food and Drug Administration. “Integrity Partners Group – 716953 – 12/15/2025.” Warning Letter, December 15, 2025. https://www.fda.gov/inspections-compliance-enforcement-and-criminal-investigations/warning-letters/integrity-partners-group-716953-12152025
- U.S. Food and Drug Administration. “Notifications on Data Integrity.” Drug Safety and Availability, accessed September 2026. https://www.fda.gov/drugs/drug-safety-and-availability/notifications-data-integrity
- U.S. Food and Drug Administration. “FDA Advises Pharmaceutical Companies That Certain Studies Conducted by Raptim Research Pvt. Ltd. Are Unacceptable.” March 28, 2025. https://www.fda.gov/drugs/drug-safety-and-availability/fda-pharmaceutical-companies-certain-studies-conducted-raptim-research-pvt-ltd-are-unacceptable
- European Medicines Agency. “Synapse Labs Pvt. Ltd: EMA recommends suspension of medicines over flawed studies.” News, December 15, 2023. https://www.ema.europa.eu/en/news/synapse-labs-pvt-ltd-ema-recommends-suspension-medicines-over-flawed-studies
- European Medicines Agency. “Synapse: Article 31 referral.” Referral procedure record, initiated July 2023, Commission decision May 24, 2024. https://www.ema.europa.eu/en/medicines/human/referrals/synapse
- U.S. Food and Drug Administration. “Fraudulent and Unreliable Laboratory Testing Data in Premarket Submissions: FDA Reminds Medical Device Manufacturers to Scrutinize Third-Party-Generated Data.” Letter to Industry, February 20, 2024. https://www.fda.gov/medical-devices/industry-medical-devices/fraudulent-and-unreliable-laboratory-testing-data-premarket-submissions-fda-reminds-medical-device
- European Commission. “EudraLex Volume 4, EU Guidelines for Good Manufacturing Practice for Medicinal Products for Human and Veterinary Use, Chapter 7: Outsourced Activities.” Revision 1, in operation 31 January 2013. https://health.ec.europa.eu/document/download/58b5106a-cf6f-4352-9dca-1caf5d27d97e_en
- International Council for Harmonisation. “ICH Q7: Good Manufacturing Practice Guide for Active Pharmaceutical Ingredients,” Section 16, Contract Manufacturers (Including Laboratories). https://database.ich.org/sites/default/files/Q7%20Guideline.pdf
- Jackson, Ian. “GMP & GDP Certificates.” MHRA Inspectorate blog, May 16, 2025. https://mhrainspectorate.blog.gov.uk/2025/05/16/gmp-gdp-certificates/
- European Medicines Agency. “EudraGMDP: GMP non-compliance search.” Public database of statements of non-compliance with good manufacturing practice, accessed September 2026. https://eudragmdp.ema.europa.eu/inspections/gmpc/searchGMPNonCompliance.do
- U.S. Food and Drug Administration. “FDA Takes Action to Address Data Integrity Concerns with Two Chinese Third-Party Testing Firms.” Press announcement, May 22, 2025. https://www.fda.gov/news-events/press-announcements/fda-takes-action-address-data-integrity-concerns-two-chinese-third-party-testing-firms








Your perspective matters—join the conversation.