What the Enforcement Record Actually Says

There is a lot of commentary about contract laboratory data integrity and comparatively little reading of the source documents. That matters, because the commentary tends to compress everything into a single message about culture, while the letters themselves describe a set of quite different mechanical failures with quite different detection methods. If you want to design oversight that works, the mechanics are the useful part.

Start with the regulatory position, because it settles the question of whose problem this is. In its October 2024 letter to Analytical Food Laboratories, a contract testing laboratory in Grand Prairie, Texas, FDA restated the principle plainly: it considers contractors as extensions of the manufacturer’s own facility.2 In its July 2025 letter to Shiva Analyticals Private Limited, FDA noted that the laboratory’s clients, including drug manufacturers and application sponsors, rely on the integrity of the data generated there to assess drug quality and make related decisions.1 In its August 2025 letter to the Chromatography Institute of America, operating as Compounders International Analytical Laboratory, FDA told the laboratory it must inform all of its customers of any out-of-specification results or significant problems encountered during testing.3

Read those together and the position is not ambiguous. The laboratory carries its own CGMP obligations. The sponsor carries the obligation to know whether the laboratory is meeting them. Neither obligation transfers to the other party by contract.

The scale of what happens when the check fails

The consequences are not theoretical. In December 2023, following a good clinical practice inspection of Synapse Labs Pvt. Ltd, a contract research organization in Pune, India, the European Medicines Agency’s human medicines committee recommended suspending marketing authorizations for generic medicines whose bioequivalence rested on studies run at that site. EMA described the inspection as showing irregularities in study data and inadequacies in study documentation and in the computer systems. Over 400 medicines had been tested by Synapse Labs on behalf of EU companies. For around 35 of them, sufficient supporting data were available to demonstrate bioequivalence, so those authorizations were maintained. For the rest, supporting data were lacking or insufficient, and the committee recommended suspension. EMA also stated there was no evidence of harm or lack of effectiveness with any of the affected medicines.14 The committee confirmed its recommendation after re-examination in March 2024, and the European Commission issued a binding decision in May 2024.15

That is the shape of the risk. Not a recall. Not a fine. A regulator concluding that the evidence underneath a portfolio of approvals cannot be relied on, and a set of sponsors discovering at that moment that they have no independent basis to argue otherwise.

400+ Medicines tested by one contract research organization on behalf of EU companies and drawn into a single Article 31 referral
EMA, December 2023
~35 Of those medicines that had enough independent supporting data to keep their marketing authorizations
EMA referral record
30 days Response time FDA gave sponsors relying on one contract research organization’s in vitro data to commit to repeating it elsewhere
FDA, March 2025

FDA maintains a short public list of these events under the heading Notifications on Data Integrity. As of this writing it carries four notifications naming five organizations whose study data the agency has found unacceptable: Semler Research in April 2016, Panexcell Clinical Lab and Synchron Research Services in September 2021, Synapse Labs in June 2024, and Raptim Research Pvt. Ltd in March 2025.12 The Raptim notification, dated March 28, 2025, states that FDA identified significant data integrity and study conduct concerns with bioequivalence studies conducted there, that in vitro studies conducted by Raptim are not acceptable, and that affected sponsors had 30 days to respond with plans to re-conduct the studies at sites that do not have data integrity concerns or to voluntarily request withdrawal of approval.13

Four notifications in nine years is a small number, and it is tempting to read it as a rare event. The better reading is that these are the cases where a regulator inspected the laboratory directly. The population of laboratories nobody has inspected recently is much larger, and in that population the sponsor is the only party looking.

The pattern worth noticing. In every one of these cases, the sponsors were receiving results that looked entirely normal. Certificates arrived on time. Numbers met specification. Nothing in the ordinary flow of information between laboratory and sponsor carried a signal. The failure was invisible from the sponsor’s side by design, because the sponsor had never asked to see anything that would have shown it.

Seven Recurring Finding Types in Testing Laboratories

Reading the 2023 to 2026 letters against each other, the same seven mechanisms keep appearing. They are worth separating, because each one has a different tell and a different countermeasure.

1. Unreported results and undocumented trial injections

This is the oldest pattern and still the most common. An analyst runs a sample, does not like the result, runs it again, and reports only the second run. The first run is described as a trial injection, a system check, or nothing at all.

In its July 2026 letter to Shimoga Chemicals, an active pharmaceutical ingredient manufacturer in India inspected in January 2026, FDA recorded that the firm acknowledged undocumented trial injections, unreported analytical data, and discarded printouts, and that the unreported data included an injection with an out-of-specification assay result. The letter also states that the firm lacked procedures for electronic data review and that its quality unit did not review the electronic data.9 The two findings belong together. Unreported injections are only sustainable where nobody opens the instrument’s own record of what was run.

2. Audit trails disabled, absent, or never reviewed

There are two versions of this and they need different fixes. In the first, the function does not exist. FDA’s September 2024 letter to MMC Healthcare Ltd, following a March 2024 inspection, describes a UV-Vis spectrophotometer used for release testing of drug batches that lacked mechanisms to assure the integrity of electronic test data, including an audit trail and defined user access levels.8 The June 2024 letter to Landy International describes a stand-alone gas chromatograph computer system that lacked appropriate controls such as an audit trail.7 In its August 2025 letter to the Chromatography Institute of America, FDA recorded that the laboratory had said it would create individual logins on its computers and was looking into installing technology with audit trail capability, which is a statement about a laboratory that did not have one at the time of inspection.3

In the second version, the audit trail exists and produces a complete record that nobody reads. FDA’s July 2025 letter to Shiva Analyticals states that investigators documented laboratory analysts performing hundreds of entries related to Add/Modify/Delete peaks and Alter existing file on disk user privileges between January 16, 2022 and January 23, 2025.1 Three years of activity, all of it recorded, none of it examined until an inspector examined it.

3. Shared logins and inadequate access control

FDA’s letter to Landy International describes laboratory personnel using a shared password located in an unsecured drawer to access the gas chromatography software, and a system that lacked individual log-in access to prevent the deletion of data. The letter also records that FDA cited similar CGMP observations at the facility during a January 2017 inspection.7

The access control failure is not only about who logs in. It is about what the account can do once it is logged in. FDA’s March 2025 letter to International Laboratories Corp, following a September 2024 inspection, describes analysts holding administrative rights capable of altering and deleting data, files, and folders on chromatographic systems.6 Where analysts hold administrator privilege, the audit trail is advisory rather than protective, because the same account that generates the record can adjust it.

4. Results reprocessed until they pass

Reintegration and retesting are legitimate laboratory activities with legitimate reasons. They become a finding when the reason is not recorded, not reviewed, or not true. FDA’s November 2025 letter to Rhyz Analytical Labs, a contract testing laboratory in Provo, Utah performing chemical and microbiological testing of over-the-counter drug products, describes inadequate investigations into microbiological test failures, acceptance of unknown laboratory error as a root cause without scientific justification, and reliance on retest data without investigating the source of contamination.4

The mechanism here is subtle and it is the one sponsors are least equipped to see. Nothing was deleted. Nothing was hidden. A failing result was investigated, the investigation reached a conclusion that explained nothing, and a passing retest replaced it. From outside, the paperwork is complete.

5. Backdated and non-contemporaneous entries

FDA’s letter to MMC Healthcare describes a process validation report containing data that had been added, backdated signatures, and replaced pages, with quality personnel admitting they participated.8 FDA’s standard data integrity remediation request, which appears in letters of this kind including the January 2025 letter to Global Calcium Pvt. Limited, an API manufacturer in Hosur, India, asks firms to identify non-contemporaneous record completion among other omissions and alterations.10

The paper trail for this one often begins in a bin. FDA’s Shiva Analyticals letter describes investigators finding torn and discarded original CGMP documents in the laboratory’s main waste disposal area, including analytical balance weighing printouts, pH meter printouts, and analytical method verification records, and notes that these carried test weights different from the weights documented in testing.1 Landy International’s letter describes numerous analysis reports, test methods, raw data calibration files, and system directories found in the gas chromatograph computer’s recycling bin.7

6. Uncontrolled spreadsheets and uncontrolled forms

A calculation performed in an unmanaged spreadsheet is a result with no provenance. FDA’s Global Calcium letter describes investigators observing Microsoft Excel documents on a desktop computer, including files relating to cleaning validation samples and production details, and then finding on the second day of the inspection that all of those files had been deleted and could not be recovered.10

The same category covers uncontrolled paper. FDA’s Analytical Food Laboratories letter directs the laboratory to control the issuance and reconciliation of uncontrolled loose forms used for documenting laboratory testing, equipment use, and calibrations, and to review laboratory records for completeness including documentation of blank, sample, and mobile phase preparations.2 The Chromatography Institute letter describes an unapproved sample preparation document titled Sample Prep Tips and Tricks in use by laboratory staff without quality unit review, alongside the absence of an effective document control system for issuance, tracking, and reconciliation of CGMP documents.3

7. Instrument clocks and system dates that can be changed

The last mechanism is the one that makes all the others harder to detect, because it corrupts the sequence that an audit trail review depends on. FDA’s International Laboratories Corp letter states that analysts held administrative rights capable of altering and deleting data, files, and folders on chromatographic systems, including the date and time of tests. The same letter records that the laboratory manager confirmed the firm fabricated several laboratory investigations that were not performed, that a senior quality assurance manager acknowledged investigations were fabricated in preparation for the FDA inspection, and that numerous electronic raw data files had been deleted.6

If a user can set the clock, timestamps stop being evidence. Any review that reasons from the order of events is reasoning from something the reviewed party controls.

A note on method problems that are not integrity problems. Not every contract laboratory finding is about honesty. FDA’s February 2025 letter to ABR Laboratory LLC, a contract testing laboratory in Hollywood, Florida inspected in September 2024, cites failure to establish and document the accuracy, sensitivity, specificity, and reproducibility of its test methods, including growth media whose composition was not verified as equivalent to compendial methods and the absence of method suitability testing. The same letter describes refrigerator temperature excursions reaching 17.4 degrees Celsius in a unit holding reference microorganisms, which were not identified or investigated.5 These are competence and control findings rather than falsification findings, and they invalidate results just as completely. Oversight designed only to detect dishonesty will miss them.

Six Sponsor Oversight Gaps That Let Them Through

Each of the seven mechanisms above survived at a laboratory that had sponsors. Those sponsors were, in most cases, doing what their procedures told them to do. The procedures were the problem. Here are the six gaps that recur, matched to the findings they fail to catch.

Finding typeWhat the sponsor was looking atThe gap
Unreported results and trial injectionsThe reported result and its certificateResult reporting format shows a final number, never the injection sequence behind it
Audit trail absent or unreviewedAn audit checklist question asking whether audit trail review is performedAudit scope never opens an actual audit trail for a real batch
Shared logins, analyst administrator rightsThe laboratory’s user access procedureProcedure reviewed, live user and privilege list never requested
Reprocessing and retesting until passThe closed investigation summaryNo right of access to underlying raw data to test the stated root cause
Backdating, non-contemporaneous entrySigned and dated records supplied by the laboratoryReliance on certificates of analysis without periodic raw data review
Uncontrolled spreadsheets and formsThe laboratory’s document control SOPAudit agenda built from a checklist the laboratory has seen before
Changeable instrument clocksNothingInfrequent onsite presence, so system configuration is never observed live

Gap one: an audit scope that never opens the audit trail

The most common single weakness. A sponsor’s quality audit of a contract laboratory asks whether audit trail review is performed, receives a yes and a procedure reference, records the answer, and moves on. It does not select a batch, ask for that batch’s audit trail, and read it. The difference between those two activities is the difference between confirming a policy exists and confirming the policy is followed.

Both the Shiva Analyticals and Shimoga Chemicals letters describe circumstances a sponsor could have found this way. Three years of peak modification privileges being exercised, and a quality unit that did not review electronic data, are both visible in the first hour of looking at a real trail for a real sample.1 9

Gap two: an agenda the laboratory has seen before

Contract laboratories serving many sponsors receive many audits. Where every sponsor uses a similar checklist, the laboratory learns the checklist. Preparation becomes a routine: the documents the auditors always ask for are ready, the rooms they always visit are in order, the people they always interview are available. This is not necessarily dishonest. It is the predictable result of a predictable process.

The International Laboratories Corp letter contains the strongest statement of where this ends. A senior quality assurance manager acknowledged that laboratory investigations were fabricated in preparation for the FDA inspection.6 Preparation for an announced audit is a normal activity. When the auditor’s requests are known in advance, preparation and fabrication become adjacent activities.

Gap three: a result format that shows only the final number

Most sponsors receive test results as a certificate: analyte, method, specification, result, pass or fail, signature. That format is a summary of a decision, not evidence for it. It cannot show how many injections were made, whether any were excluded, whether the integration was adjusted, or when each event occurred.

Article 10 in this series works through where the boundary between raw data and processed data actually falls in chromatography systems, and that boundary is exactly what a certificate hides. If the reporting format never crosses it, no amount of diligence applied to the certificate will help.

Gap four: no right of access to raw data in the contract

Sponsors regularly discover, at the moment they most need it, that their agreement gives them the right to audit the laboratory but not the right to obtain and retain the underlying electronic records. The audit right permits a visit. It does not always permit an export.

This one is fixable and the regulatory expectation is already written. ICH Q7 section 16 states that all contract manufacturers, including laboratories, should comply with GMP; that they should be evaluated by the contract giver to ensure GMP compliance of the specific operations occurring at the contract sites; that there should be a written and approved contract defining in detail the GMP responsibilities of each party; and that the contract should permit the contract giver to audit the contract acceptor’s facilities for compliance with GMP.18 Article 24 in this series covers quality agreement clause drafting in depth, and that is the right place to work out the language. The point here is narrower: the access right has to exist before you need it.

Gap five: reliance on certificates without periodic raw data review

Certificates are supplier assertions. Treating them as verification is a recognized enforcement theme in its own right. FDA’s December 2025 letter to Integrity Partners Group, following a June 2025 inspection of the Chemisphere Corporation site in Saint Louis, cites the firm for failing to conduct at least one test to verify the identity of each component, having relied on supplier certificates instead.11

The same logic applies one level up. A sponsor that accepts a contract laboratory’s certificate without ever reviewing the data behind one is in the same position as a manufacturer accepting a supplier’s certificate without ever testing an incoming material. The document is a claim about the evidence, and nobody has looked at the evidence.

Gap six: infrequent onsite presence

Some findings only exist in the room. Whether the instrument workstation clock can be changed by the logged-in analyst, whether original printouts are being discarded, whether uncontrolled forms are in circulation, whether an unapproved tips document is taped inside a cupboard: these are physical observations. The Shiva Analyticals waste bin, the Landy International drawer, and the Chromatography Institute sample preparation document were all found by someone standing in the laboratory.1 7 3

Remote and paper-based oversight has real advantages and should carry most of the routine load. It cannot carry this part.

The single question that reframes a contract lab audit

Instead of asking the laboratory to demonstrate that its controls work, pick one batch you released on that laboratory’s data in the last quarter and ask the laboratory to reconstruct it completely: every injection, every user action, every reintegration, every deviation, in sequence, from the system’s own records. Then check that reconstruction against the certificate you received.

Most of the seven finding types will either appear or be ruled out in that one exercise. It also has the useful property that it cannot be prepared for in the abstract, because you choose the batch.

Audit Trail Review Sampling at the Contract Lab

Sponsors often accept that they should review audit trails at contract laboratories and then get stuck on the practical question of how much and which. Reviewing everything is not possible. Reviewing nothing is what got the industry here. What follows is a workable middle.

Define the sampling frame before you choose the sample

Do not start from a number of records. Start from a list of the decisions that laboratory’s data supports for you. Batch release. Stability trend conclusions. Comparability claims. Specification setting. Investigation closures. Each of those is a decision your organization owns, taken on evidence someone else generated. The sampling frame is the population of those decisions, not the population of the laboratory’s tests.

From that frame, weight the sample toward the decisions where a wrong answer would be least recoverable, and toward the analytes and methods with the highest historical rate of retesting or investigation. If a method has never produced a failing result across two years of routine use, that is a candidate for sampling rather than a reason to skip it.

What to actually look at

SEQUENCE

Injection and run sequence

Every injection performed on the sample set, in order, including any that were aborted, excluded, or labeled as trial, system suitability, or blank. Compare the count to the count implied by the reported result.

CHANGES

Processing and reintegration events

Every change to a method, integration parameter, or peak assignment after acquisition, with the user, the timestamp, and the stated reason. A reintegration with no reason recorded is a finding regardless of what the result was.

IDENTITY

User accounts and privilege

The live account list, the privilege assigned to each, and which accounts hold rights to delete data, alter files on disk, or modify system date and time. Ask for it as a system export, not as a procedure.

CONFIG

System configuration and clock

Whether the audit trail is enabled for all relevant object types, whether it can be turned off and by whom, whether the workstation clock is synchronized to a controlled time source, and who can change it.

EXCEPTIONS

Deletion and recovery events

Any deleted file, orphaned data set, or recovered project in the period. The Landy International and Global Calcium letters both turned on deleted material, one in a recycle bin, one removed overnight during an inspection.

REVIEW

Evidence of the lab’s own review

The laboratory’s audit trail review records for the same period: who reviewed, what they reviewed, what they found, and what happened to what they found. A review that has never raised anything is a review to examine closely.

How often, and how to keep it honest

A reasonable baseline for a laboratory carrying material decisions is a documented review of at least one full data package per quarter, plus one during each onsite audit, plus one triggered by any event that would make you look anyway: an out-of-specification result, an investigation you found unconvincing, a change of laboratory management or of the analyst signing your work, or a regulatory action anywhere in that laboratory’s group.

Two rules keep the exercise from decaying into a formality. First, you choose the batch, not the laboratory, and you choose it after the data exists. Second, someone who understands the instrument software does the reading. A quality auditor who has never opened a chromatography data system will read what they are shown. Where that skill does not exist internally, buy it for the day.

What a good result looks like. The reconstruction matches the certificate. Every injection is accounted for. Every reintegration has a recorded reason that a second person reviewed before release. The user list contains no shared or generic accounts and no analyst with rights to delete data or change the system clock. The laboratory’s own audit trail review found something in the period, investigated it, and closed it. That last point is not a defect. A review process that has never found anything is either looking at nothing or reporting nothing.

The Data Package That Replaces a Certificate

Changing what you receive is more durable than changing how hard you look at what you already receive. The certificate of analysis should remain, because it is the formal statement of conformance. It should stop being the only thing that arrives.

Specify a data package in the technical agreement, define its contents by test type, and require it either with every batch for the highest-consequence work or on a defined sampling basis for the rest. This is not a request for the laboratory’s entire data set. It is a defined, repeatable extract.

1

The reported result, with its full analytical context

Method identifier and version, instrument identifier, column or detector identifier, analyst, date of acquisition, date of processing, and the reviewer. Version matters: a result produced under a method revision you were not told about is a change control question, not a data question.

2

The complete injection sequence for the sample set

All injections in acquisition order with their identifiers and dispositions, including system suitability, blanks, standards, and anything excluded. This is the single most valuable item, because it is what a certificate structurally cannot show.

3

The processing history

Every reintegration or reprocessing event affecting the reported result, with user, timestamp, and reason, plus both the original and final chromatograms where a peak assignment changed.

4

The audit trail extract for the sample set

A system-generated export covering the acquisition and processing window, in the system’s own format rather than transcribed into a summary document. A summary written by the laboratory is testimony. The export is evidence.

5

Any related deviation, investigation, or out-of-specification record

Including ones the laboratory closed as invalid or as laboratory error, and including the retest data. Rhyz Analytical Labs was cited for accepting unknown laboratory error as a root cause without scientific justification, which is only visible if you see the investigation.

6

Evidence of second-person review before release

Who performed the technical review, what it covered, and whether it included the electronic records rather than only the printed summary. Shimoga Chemicals was cited for lacking procedures for electronic data review and for a quality unit that did not review the electronic data.

Deciding who gets which package

Not every test justifies this. A sensible tiering is by consequence rather than by volume. Testing that supports batch release, a regulatory submission, a stability commitment, or a specification decision gets the full package. Testing that supports internal monitoring, development screening, or informational trending gets the certificate plus an annual data package review. Anything supporting a claim in a marketing application gets the full package plus a documented independent technical review before submission.

One caution on scope. A data package is only useful if someone reads it. Requiring a full package from every laboratory for every test, with no capacity to review any of them, produces a large archive and no assurance. Start with the tier that matters and expand as the review capability grows.

Contract Terms That Make Oversight Possible

Everything above depends on rights the sponsor either has or does not have when the moment comes. Article 24 in this series handles quality agreement clause drafting in detail and this section deliberately does not duplicate it. What follows is the narrow set of terms specific to data integrity oversight at a testing laboratory, and the regulatory language that already supports each one.

EU GMP Chapter 7 on outsourced activities is the clearest source. Clause 7.5 makes the contract giver responsible, before outsourcing, for assessing the legality, suitability and competence of the contract acceptor. Clause 7.7 requires the contract giver to monitor and review the performance of the contract acceptor. Clause 7.8 makes the contract giver responsible for reviewing and assessing the records and the results related to the outsourced activities. Clause 7.16 states that all records related to the outsourced activities, including analytical records, should be kept by or be available to the contract giver, and that any records relevant to assessing the quality of a product in the event of complaints or a suspected defect must be accessible and specified in the contract giver’s procedures. Clause 7.17 states that the contract should permit the contract giver to audit outsourced activities performed by the contract acceptor or its mutually agreed subcontractors. Clause 7.11 requires the contract acceptor not to subcontract without the contract giver’s prior evaluation and approval.17

Those clauses have been in force since January 2013. In practice, agreements are often written as though only the audit right in 7.17 exists. The records access right in 7.16 is the one that matters most for data integrity oversight, and it is the one most often left out.

Data integrity terms worth checking in your current agreements

  • Electronic records access, not only audit access. The right to request, receive, and retain system-generated audit trail extracts and raw data files in native or agreed format, within a defined number of business days.
  • Unannounced and short-notice visits. A defined number per year, with a scope that explicitly includes observing live systems and user privilege.
  • Notification of regulatory contact. Written notice within a short fixed period of any inspection, observation, warning letter, statement of non-compliance, or import action affecting the site or the systems used for your work.
  • Notification of data integrity events. A duty to inform you of any confirmed or suspected data integrity issue affecting your samples, including invalidated results and any retrospective data review the laboratory undertakes.
  • Subcontracting consent. No transfer of your testing to another site or third party without prior written approval, matching Chapter 7 clause 7.11 and ICH Q7 clause 16.14.
  • Retention and return on exit. Defined retention periods for raw data and audit trails, and a defined mechanism for obtaining readable copies if the relationship or the laboratory ends.
  • Change notification for systems and methods. Notice before changes to instruments, chromatography data systems, method versions, or the release approver for your work.

One more point, and it is not a clause. Article 20 in this series deals with what happens when three vendors touch one record and nobody owns the defect. The contract terms above only work if the sponsor has decided internally who reads the data package, who acts on a notification, and who has authority to stop using a laboratory. A right nobody is accountable for exercising is not a control.

Qualification and Requalification That Tests Data Integrity

Most contract laboratory qualification programs were designed to answer a competence question: can this laboratory perform this method to an acceptable standard. That question is still worth asking. It is not the question the enforcement record says is failing.

What to add to initial qualification

Three additions cover most of the gap, and none of them require a longer visit.

Test the system, not the procedure. During qualification, ask the laboratory to demonstrate live, on the actual system that will run your work, that the audit trail is enabled, that it captures deletion and reintegration, that it cannot be disabled by an ordinary analyst account, and that the workstation clock cannot be altered by that account. Ask to see the current user and privilege export. This takes under an hour and it distinguishes a laboratory with controls from a laboratory with a controls SOP.

Run a reconstruction on a real historical batch. Ask the laboratory to reconstruct any completed sample set from its own records, of your choosing, from the last six months. You are not assessing the result. You are assessing whether the reconstruction is possible, how long it takes, and whether the laboratory’s staff can do it without help from the vendor.

Check compliance status independently. Manufacturers’ authorizations and GMP certificates can be verified using the MHRA-GMDP database or the EU database, and statements of GMP non-compliance are published in EudraGMDP alongside positive certificates.19 20 FDA’s Notifications on Data Integrity page carries the drug-side notifications about specific research organizations.12 These checks take minutes and belong in the qualification file, dated, with a defined recheck frequency.

Accreditation is not the same as compliance. A laboratory holding an accreditation, or an award under a voluntary conformity assessment scheme, has demonstrated something real about its technical competence. It has not thereby demonstrated GMP compliance for your operations, and no regulator treats it as a substitute. In its February 2024 letter to industry on fraudulent and unreliable laboratory testing data, FDA encouraged working with third-party laboratories accredited under its voluntary program while stating plainly that this does not substitute for independent assessment of all third-party data.16

What to change about requalification

Requalification on a fixed calendar is the norm and it is the weakest part of most programs. Two years pass, a form is completed, the same checklist produces the same answers, and the file is closed. Nothing in that cycle responds to what has actually happened at the laboratory.

Move to a risk-triggered model layered on top of a maximum interval. Keep the outer limit so nothing drifts indefinitely. Then define triggers that pull a requalification forward:

  • Any regulatory action, observation, or non-compliance statement affecting the site, the group, or a sister site using the same systems.
  • A change of quality unit leadership, laboratory management, or the person who approves release of your results.
  • Migration or upgrade of the chromatography data system, laboratory information management system, or the instruments running your methods.
  • A rise in invalidated results, retests, or investigations on your work, whatever conclusion those investigations reached.
  • A data package review that produced a finding, or a reconstruction request the laboratory could not complete promptly.
  • Transfer of your testing to a different site within the same organization.

The last trigger deserves attention. Work moves between sites inside a laboratory group more often than sponsors realize, and the qualification file frequently still describes the original site. EU GMP Chapter 7 clause 7.11 and ICH Q7 clause 16.14 both require prior evaluation and approval before work is passed to a third party.17 18 Movement within a group is not always treated as subcontracting by the laboratory, so it is worth naming explicitly in the agreement.

Running the Program Across a Portfolio of Labs

A mid-size sponsor may use twenty or more testing laboratories. Applying everything above to all of them at once is not realistic, and attempting it usually produces a program that looks thorough in a procedure and is not performed. Three practical constraints shape a version that survives.

Tier by consequence and be honest about the tail

Rank laboratories by what their data decides, not by spend. A small laboratory running one release method for one commercial product outranks a large one running development screening. Put the full data package, quarterly audit trail review sampling, and short-interval requalification on the top tier. For the tail, apply a lighter cycle and accept the residual risk explicitly, in writing, with a named owner. An acknowledged gap is manageable. An unacknowledged one is what turns into a surprise.

Build the skill before you build the procedure

Audit trail review at a contract laboratory needs someone who can read a chromatography data system’s own records and recognize what is missing. That skill is scarce in quality organizations and it does not arrive with a new SOP. Identify who has it, and if nobody does, train two people properly or contract the capability for the reviews that matter. A procedure requiring a review nobody can perform generates completed forms and no assurance.

Close the loop back into your own decisions

A finding at a contract laboratory has to reach the decisions that were made on that laboratory’s data. That means the qualification file, the audit trail review record, and the batch release record need to be connected well enough that you can answer one question quickly: which of our released batches, submissions, and stability conclusions rest on data from this site, over what period. Sponsors caught by the Synapse Labs and Raptim Research notifications discovered that the hard part was not reacting to the notice. It was establishing the exposure.14 13

The realistic first year. Pick the three laboratories whose data supports your highest-consequence decisions. Add the data package to those agreements at the next amendment. Run one reconstruction exercise per laboratory in the first quarter, with someone who can read the system. Verify each site’s public compliance status and record the check. Add the data integrity triggers to your requalification procedure. That is a year of work for a small team, it is achievable, and it covers the exposure that would be hardest to recover from.

Conclusion

The enforcement record from 2023 through 2026 is unusually clear about what fails in testing laboratories, whether they are independent contract laboratories or a manufacturer’s own quality control laboratory, and it is not mysterious. Original printouts in a bin. A shared password in a drawer. Analyst accounts with rights to delete files and change the system clock. Trial injections that never reach a record. Reintegrations nobody reviewed for three years. Instruments performing release testing with no audit trail at all. Investigations closed to unknown laboratory error, and retests reported as though the first result had never happened. Each of these appears in a public letter, at a named site, with a date.

What the record also shows is that sponsors were present throughout. They had contracts, quality agreements, audit schedules, and approved supplier lists. The oversight was real. It was aimed at the wrong surface. A certificate cannot show an unreported injection, a document control SOP cannot show an uncontrolled spreadsheet, and a checklist question about audit trail review cannot show a trail nobody opened. The correction is not more oversight. It is oversight pointed at the underlying data, supported by a contract that gives you the right to obtain it and a reviewer who can read it.

Sakara Digital works with pharma and biotech organizations on data integrity and vendor oversight programs that hold up under inspection, including audit trail review sampling at contract laboratories, data package specifications, and qualification approaches that test the controls rather than the procedures describing them. If you are reworking how you supervise the laboratories your release decisions depend on and want an independent perspective on where to start, we are happy to have that conversation.

For Further Reading