How We Counted, and What the Count Covers

Most published statistics on data integrity warning letters come from third-party reviews that each define “data integrity” in their own way. The results vary widely, and the source is rarely shown. For this article we built the count ourselves, from primary sources only, so every number can be traced back to a letter on FDA’s own site.1

The Population

We started with every warning letter on FDA’s warning letter page that was issued in 2026 and posted by September 29, 2026. That gave 429 letters from all FDA centers. We kept the letters issued by the Center for Drug Evaluation and Research (CDER) whose subject line concerns drug manufacturing quality: current good manufacturing practice (CGMP) letters for finished drugs, OTC drugs, and active pharmaceutical ingredients (APIs), plus compounding letters and letters for refusing FDA’s records requests. That left 96 letters, dated January 7 to September 22, 2026.

The count leaves out several groups on purpose:

  • CDER letters about telehealth marketing claims, unapproved drugs sold online, and other non-manufacturing subjects.
  • CDER’s bioresearch monitoring letters to clinical investigators, bioequivalence sites, and nonclinical (GLP) laboratories. They concern study conduct, not manufacturing, and deserve their own analysis.
  • Letters from the biologics center (CBER), the veterinary center, devices, foods, and tobacco.
  • Letters dated in 2026 that FDA had not yet posted. FDA posts letters on a delay, so the September total will grow.

The findings themselves come from inspections that ran from July 2025 to April 2026, plus two cases where FDA reviewed records it had requested instead of inspecting the site.

The Counting Rule

We downloaded the full text of all 96 letters and searched each one for data integrity language and related citations. We then read in full every letter that turned up any marker, and classified each one. A letter counts as a data integrity letter here if FDA does one of two things:

  1. Cites its guidance Data Integrity and Compliance With Drug CGMP: Questions and Answers in connection with the firm’s findings.2 Twenty-three letters meet this test.
  2. States in its own words that the firm failed to protect the integrity of its data, and ties that statement to a specific finding. One more letter meets this test: Intas Pharmaceuticals, where FDA wrote that the firm “lacks controls to assure the integrity of electronic batch record data.”18

Three letters touch on data integrity only in passing and are not counted. One is a letter to a 503B outsourcing facility that noted unsigned procedures in its response.37 Another is a letter to an OTC maker that could not locate forced degradation studies.38 The third is a letter to a compounding pharmacy about media fill results transcribed onto a new form without an audit trail.39 Reasonable people could count one or more of these. We chose the stricter line so the total is not inflated.

Checking the Premise

The claim that data integrity appears in “most” drug warning letters did not hold up. In 2026, through September 29, it appears in 24 of 96 CDER manufacturing-quality letters. Even with the three borderline letters added, the figure would be 27 of 96. Data integrity is a serious and recurring finding. It is not the majority finding.

What Is in Force

Nothing in the underlying rules changed in 2026. The regulations FDA cited are the same sections of 21 CFR Part 211 that have applied for decades: 211.22 (responsibilities of the quality control unit), 211.68 (automatic, mechanical, and electronic equipment), and 211.194 (laboratory records).345 The data integrity guidance FDA cites in 23 of the letters is the final version issued in December 2018, and FDA’s guidance page still lists it as final.2 For API makers, FDA applies the expectations in ICH Q7, the international good manufacturing practice guide for APIs.10

One point surprised us. None of the 24 letters cites 21 CFR Part 11, the rule on electronic records and electronic signatures. Where FDA took issue with a computer system, it cited 211.68(b) or described the gap under the quality unit or laboratory records sections. None of the 24 letters involves artificial intelligence either. The only 2026 drug CGMP letter in this population that mentions AI is the Purolea letter, which does not cite the data integrity guidance and is therefore not in this count. We covered Purolea and the wider AI enforcement picture in separate articles, linked at the end.

Who Received the 24 Letters

The population is broader than a single industry segment, and it is worth being exact about it. The 24 letters went to non-sterile finished drug makers, sterile drug makers, API makers, and contract testing laboratories, in eight countries.

24 of 962026 CDER manufacturing-quality letters that cite data integrity, posted through September 29
18 of 24Letters to facilities outside the United States; 12 of them in India
11 of 24Letters where microbiology testing or monitoring records were at the center of the finding
Recipient typeLettersRecipients
Non-sterile finished drug makers (mostly OTC; one homeopathic maker)11Fulijaya, A. Nelson, Fareva Morton Grove, Patcos, Xiamen Kang Zhongyuan, GC America, Laboratorios Jaloma, Gopaldas Visram, BioMylz, Dabur, Lico Industries
Prescription non-sterile finished drug makers2Intas, Zydus
Finished drug and API maker1Ava Inc.
Sterile drug makers4Pharmathen, Huons, Wizcure, Reliance Life Sciences
API makers3Shimoga Chemicals, Shoolin Pharma Chem, Curia New York
Contract testing laboratories3Tentamus India, Microbiological Testing & Consulting, Auriga Research
Total24

By location, 12 letters went to sites in India and 6 to sites in the United States. The other 6 went to one site each in Malaysia, the United Kingdom, China, Mexico, Greece, and South Korea. At least three of the finished drug makers were working as contract manufacturers for other companies’ products (Patcos, BioMylz, and Pharmathen), and the three contract testing laboratories tested drugs for other firms by definition. For a sponsor that outsources, six of the 24 letters describe the kind of supplier it depends on.

The full list follows, in date order, with the core data integrity finding in each letter. Every entry links to FDA’s published letter in the references.

DateRecipient (country)TypeCore data integrity finding
Jan 14Fulijaya Manufacturing (Malaysia)11OTCLogbooks with raw data for microbiology release and stability testing before May 2025 were not available
Feb 12A. Nelson & Co. (UK)12HomeopathicSigned CGMP records and analytical forms with unacceptable results found discarded; uncontrolled duplicate printing of records
Mar 3Tentamus India (India)13Contract labTorn analytical records in garbage bags; personal diaries used for CGMP data; backdating; a failing microbial count reissued as passing
Mar 3Fareva Morton Grove (US)14OTCNegative microbiology plates not recorded at the time; a plate with 20 CFU discarded without a record
Mar 12Patcos Cosmetics (India)15OTC contract makerDeliberate alteration of original laboratory data to conceal out-of-specification results
Mar 16Microbiological Testing & Consulting (US)16Contract labBasic test details not recorded; customer records showed failing results the lab did not make available
Mar 23Xiamen Kang Zhongyuan (China)17OTCFalse testing documents; a logbook returned to investigators with entries that were not there two days earlier
Mar 30Intas Pharmaceuticals (India)18Rx genericSoftware vendor changed electronic batch records at QA’s request, outside the audit trail
Apr 14Ava Inc. (US)19Finished drug and APIShared HPLC login; analysts able to delete data; deleted GC sequences; trial injections written into procedure
May 14GC America (US)20OTCPassword on a sticker on a laptop; instrument data deleted at shutdown; no audit trails
May 22Laboratorios Jaloma (Mexico)21OTCSamples recorded as collected that were never taken; GC audit trails not enabled; data files missing, no backup
May 27Pharmathen International (Greece)22Sterile contract makerMicrobiology plates with no raw data; 16 batches’ sterility tests invalidated; room monitoring with no data storage
Jun 2Zydus Lifesciences (India)23Rx finishedA failing infrared result removed from an instrument report and passing values added (records request, no inspection)
Jun 2Gopaldas Visram (India)24OTCInfrared values identical to three decimal places across two samples (records request, no inspection)
Jun 15Huons (South Korea)25SterileBioburden plates discarded; camera timestamps changed; logbook pages cut out and replaced
Jun 24Wizcure Pharmaa (India)26Sterile OTCEnvironmental monitoring plates with growth replaced by clean plates; forms pre-filled with results
Jul 13Shimoga Chemicals (India)27APIUnreported HPLC injections, including a failing assay, for a batch released to the US
Jul 13BioMylz (India)28OTC contract makerGarbage bag of original records, including executed batch records; pencil entries overwritten in ink
Jul 24Dabur India (India)29OTCFalsified equipment logbook given to investigators; reported values that did not match raw data
Jul 30Lico Industries (US)30OTCBackdated release labels; temperatures recorded while the thermometer did not work
Aug 12Auriga Research (India)31Contract labRaw data sheets blank where plate counts belonged, while summary reports showed final counts
Aug 18Reliance Life Sciences (India)32SterileColony counts recorded for samples that were never collected; test files overwritten
Aug 18Shoolin Pharma Chem (India)33APINo evidence that testing reported on certificates of analysis was performed
Sep 18Curia New York (US)34APIUnexplained chromatography injections; original records in shred bins; shared login credentials

Where FDA Puts the Citation

There is no single “data integrity” section in the CGMP regulations, so FDA attaches these findings to whichever requirement fits the facts. Across the 24 letters, the findings were cited under five main routes. A letter can use more than one.

Where the data integrity finding was citedLettersWhich letters
21 CFR 211.22, quality control unit responsibilities11A. Nelson, Tentamus, Patcos, Microbiological Testing & Consulting, Intas, GC America, Zydus, Gopaldas, BioMylz, Dabur, Lico
21 CFR 211.194, complete laboratory records10Fulijaya, Fareva Morton Grove, Patcos, Ava, Jaloma, Huons, Wizcure, Dabur, Auriga, Reliance
21 CFR 211.68(b), controls over computer systems3Ava, GC America, Jaloma
21 CFR 211.160(a), recording laboratory controls at the time3Tentamus, Ava, Pharmathen
ICH Q7 deviations for APIs (no CFR section cited)3Shimoga, Shoolin, Curia

One letter falls outside those routes. Xiamen Kang Zhongyuan cites no CGMP section at all: FDA charged insanitary conditions and, under section 501(j) of the Food, Drug, and Cosmetic Act, found that the firm limited the inspection by giving investigators false documents.17 Two other details are worth noting. Reliance’s electronic records finding is part of its 211.194 charge, not a separate 211.68 citation. Pharmathen’s unstored room monitoring data is cited under the aseptic facility requirement, 211.42(c)(10), while its microbiology records are cited under 211.160(a).

211.22: The Quality Unit Owns the Record

The most common route is not a laboratory or computer section. It is the quality unit. In 11 letters FDA framed the data integrity failure as a quality unit failure: the unit signed off on records it had not checked, allowed records to be destroyed, or did not notice that reported values did not match the source. In the Dabur letter, FDA noted that the mismatched values did not involve failing results, yet the quality unit “signed off on these records without ensuring the consistency and accuracy of the data.”29 The message is that the quality unit is accountable for whether the record is true, not only for whether the result passes.

211.194: Complete Data, Not Only Passing Data

Section 211.194(a) requires laboratory records to include “complete data derived from all tests necessary to assure compliance with established specifications and standards.”5 It is the closest thing the regulations have to a data integrity section for the laboratory, and FDA used it in 10 of the 24 letters. It does not always mean data integrity, though. One other 2026 letter, to Respilon Production, cites 211.194(a) because a certificate of analysis did not report an individual test result, with no data integrity language at all.36

211.68(b): Less Common Than Expected

Section 211.68(b) requires controls so that only authorized people can change records, and it requires backup data that is secure from alteration, erasure, or loss.4 FDA cited it in only three of the 96 letters, all three in this data integrity group. A fourth letter, to IDO Pharm, cites 211.68(a), which covers routine calibration of equipment. That citation had nothing to do with data integrity.35 Anyone counting “211.68 citations” as a proxy for data integrity would get the wrong answer in both directions: it misses most data integrity letters and catches one that is not.

A counting lesson. A search for 211.68 finds 4 letters. A search for 211.194 finds 11. Neither matches the 24 letters where FDA framed the problem as data integrity. Most data integrity findings in 2026 were cited under the quality unit section or the laboratory records section, and several API letters cite no CFR section at all. Counting by citation alone gives a misleading picture.

Seven Recurring Findings Across the Letters

Reading the 24 letters side by side, the same kinds of failure come up again and again. We grouped them into seven findings. The table marks each letter against each finding, and the counts in the last row are taken directly from the table.

RecipientRecords missing or not producedRecords altered or made upOriginals discardedComputer controlsUnreported injectionsMicrobiology recordsRecords withheld or delayed
Fulijaya✓✓
A. Nelson✓
Tentamus India✓✓✓✓✓
Fareva Morton Grove✓✓✓
Patcos✓
Microbiological Testing & Consulting✓✓✓
Xiamen Kang Zhongyuan✓✓✓
Intas✓✓
Ava✓✓
GC America✓
Laboratorios Jaloma✓✓✓✓
Pharmathen✓✓✓
Zydus✓
Gopaldas Visram
Huons✓✓✓✓
Wizcure✓✓✓
Shimoga✓✓✓✓
BioMylz✓✓✓
Dabur✓✓✓✓
Lico Industries✓✓
Auriga Research✓✓
Reliance Life Sciences✓✓✓
Shoolin✓
Curia New York✓✓✓
Letters1312883115

Gopaldas Visram has no mark because its finding does not fit these seven. FDA reviewed infrared spectra the firm submitted and found values identical to three decimal places across two independently collected talc samples. FDA called this statistically unlikely and said it “raises concerns regarding the authenticity of the reported results,” but it did not find that the data had been altered.24 The Zydus letter, issued the same day, contains a similar pattern: 21 of 29 approved talc results from 2022 to 2025 showed identical maxima across different lots and dates. In that case FDA also found that a failing result had been removed from an instrument report.23

1. Records Missing or Not Produced (13 Letters)

The most frequent finding is the simplest: when investigators asked for the record behind a reported result, the firm could not produce it. Shoolin Pharma Chem could not provide any printouts, notebooks, worksheets, or analytical data showing that the testing on its certificates of analysis had been performed, and it reported contract laboratory results on its own letterhead without naming the laboratory.33 Dabur could not produce test procedures, analytical workbooks, or data sheets behind the certificates of analysis for a number of US batches; FDA redacted that number.29 Shimoga had no raw data, paper or electronic, for the long-term stability study behind its API expiry date.27

2. Records Altered, Backdated, or Made Up (12 Letters)

Twelve letters describe records that did not reflect what happened. Some are about entries made after the fact: a laboratory manager at Tentamus was seen signing and backdating reconciliation records, and five blank maintenance forms had been pre-signed and dated.13 Some are about work that never took place: at Laboratorios Jaloma and at Reliance Life Sciences, samples were recorded as collected when analysts confirmed they had not been taken.2132 At Lico Industries, temperature data was entered while the thermometer was not working.30 And some are direct falsification. Dabur gave investigators an equipment logbook that appeared newly created and left out US-marketed products; the original was later found in the document room.29

3. Original Records Discarded or Destroyed (8 Letters)

Investigators found original records in garbage bags at Tentamus and BioMylz, in discarded material at A. Nelson, and in shred bins at Curia New York.13281234 At Curia, the shred bins were collected for off-site destruction by a third party with no QA review, so the firm could not say how much had already been destroyed.34 At Huons, a microbiology team leader admitted using a knife to remove completed pages from a logbook, which were then replaced with pages made to look like the originals.25

4. Computer System Controls (8 Letters)

Eight letters include a finding about access, audit trails, or keeping electronic data. These are covered in their own section below.

5. Unreported or Trial Injections (3 Letters)

Three letters, to Ava, Shimoga, and Curia New York, describe chromatography injections run outside the official record. This is the classic data integrity finding of the last decade. In 2026 it appeared in 3 of 24 letters.

6. Microbiology Records (11 Letters)

This is the largest single area of practice in the group, and it gets its own section below.

7. Records Withheld or Delayed During the Inspection (5 Letters)

In five letters the firm did not hand over records promptly or completely. FDA used section 501(j), which covers delaying, denying, or limiting an inspection, against Tentamus and Xiamen Kang Zhongyuan.1317 At Tentamus, investigators saw the firm trying to remove two garbage bags of analytical documents at the start of the inspection, and a laboratory manager said senior management had told him not to share details about audits. FDA’s current guidance on what counts as delaying or limiting an inspection is the June 2024 revision.7 At Microbiological Testing & Consulting, the lab had only two investigations to show for the past two years, while records from one of its customers showed the lab had reported several out-of-limit and objectionable microorganism results in that period.16

The Microbiology Lab Is Where Most of These Start

If you read only the headline cases from past years, you might expect data integrity letters to be about chromatography software. In 2026 the microbiology laboratory appears more often. Eleven of the 24 letters center on microbiology testing or environmental monitoring records. The reason is practical. A chromatography system produces an electronic file with metadata and, when configured, an audit trail. A microbiology plate is a physical object that someone counts by eye and writes down. If the plate is thrown away, the written count is the only record left.

What the Letters Describe

  • Plates replaced. At Wizcure, an investigator saw personnel monitoring plates with visible growth in the incubator. The next day, plates with the same identification showed no growth. Management and a microbiologist confirmed the originals had been discarded and replaced. FDA called this false data that misrepresented the conditions of the ISO 5 aseptic filling area, and described “serious recurring data integrity breaches” in the laboratory.26
  • Samples never taken. At Laboratorios Jaloma, a microbiologist admitted that routine samples documented as collected were never taken.21 At Reliance Life Sciences, environmental monitoring samples were logged as collected and incubated, colony counts were recorded as if incubation were under way, and analysts later confirmed the samples had not been collected.32
  • Plates missing. At Dabur, notebooks recorded microbiology plates as incubated that were not in the incubators, with no explanation of where they went. FDA gave approximate counts but redacted the numbers.29
  • Counts not recorded. At Fareva Morton Grove, negative plates were not recorded at the time, and blank entries were later recorded automatically as zero. Investigators found a plate that had been counted at 20 CFU and then discarded without the count being written down.14
  • Raw data sheets blank. At Auriga Research, a contract testing laboratory, raw data sheets had blank spaces where plate counts should have been, while the summary reports sent to customers showed final counts. FDA redacted the number of samples affected.31
  • Failures hidden. At Huons, the first run of a study failed endotoxin limits and the second showed significant bioburden. A team leader told staff to discard the bioburden plates and changed camera timestamps to create backdated documentation. Investigators also found 1,897 blank, uncontrolled CGMP forms in the microbiology laboratories.25

What FDA Now Asks For

The remedies FDA requested for microbiology show where it thinks the controls belong. In the Wizcure and Auriga letters, FDA asked for a chain of custody for every microbiology sample: unique labels, signatures of everyone who handles the sample, the date and time of each step from collection to reading, digital time-stamped photographs of all plates, and quality assurance verification.2631 In the Huons letter, FDA went further and asked the firm to contract a third party to be physically present in the microbiology laboratory to oversee sampling and analysis of US products, with photographic evidence protected by audit trails.25

The practical point. Time-stamped photographs of plates turn a physical result into an electronic record with metadata. That is the control FDA asked for in three letters. Sites that still rely on a handwritten count with no image, no reconciliation of plates in and out of the incubator, and no second reader have the same exposure these firms had.

The stakes are highest at sterile sites, where microbiology data is the evidence of sterility. Huons acknowledged in its own response that, given the data integrity issues, it “may be premature to draw conclusions about product impact based on the sterility assurance data” from the prior three years.25 When the underlying records cannot be trusted, the firm loses the evidence it would use to defend its product.

Chromatography and Computer Controls Have Not Gone Away

Eight letters include a finding about computerized systems. They are fewer than the paper findings, but the details are specific and familiar to anyone who has run a laboratory system assessment.

Shared or Exposed Credentials

Three letters describe passwords that were shared or left open to anyone. Ava used a common username and password to access HPLC equipment for impurity testing, and analysts had administrator privileges to modify and delete data.19 At GC America, the password for an instrument was on a sticker attached to the laptop used to process its results.20 At Curia New York, an analyst used another analyst’s login credentials to run calibrations and sample testing on a system that otherwise enforced unique accounts. The firm’s own procedure already prohibited sharing; its retrospective review covered 12 stand-alone instruments for one year, which FDA found too narrow.34

Audit Trails Missing, Disabled, or Bypassed

At Laboratorios Jaloma, audit trails on a gas chromatography system were not enabled, the control software was not validated, and file creation and modification dates were wrong.21 GC America could not provide audit trails at all.20 At Ava, the audit trail for an infrared instrument showed no activity from September 23 to 30, 2025, while the usage log showed testing during that time.19 The Intas case is different and worth attention from anyone running a vendor-hosted system. A QA employee asked the software vendor to change electronic batch records, including replacing one employee identification number with another in the “Dispensed by” field. The changes were not captured in the audit trail and did not go through the quality system.18 FDA asked Intas for a review of all communications with software support vendors, not only the one named in the letter.

Data Deleted, Overwritten, or Never Stored

At GC America, data from an instrument was deleted automatically when the laptop shut down, so no record of quality review existed.20 At Reliance Life Sciences, integrity test reports were not saved with unique file names and were overwritten after a set number of tests (FDA redacted the number), so failed tests could not be retrieved.32 At Pharmathen, pressure, temperature, and humidity monitors in the aseptic area showed live readings only and stored nothing, so excursions that happened when no one was watching went unrecorded.22 Jaloma had several chromatography data files that could not be found and did not back up the instrument computer.21

Trial Injections and the “Developer” Role

The Curia New York letter is the most detailed chromatography case of the year. FDA reported “thousands of unexplained injections using Empower over the last 30 months, and over 70 trial injections using TotalChrom in October 2025 alone.”34 FDA found Empower injections run under the software’s “Developer” role rather than the “Operator” role, without documentation. The firm’s own review found that nearly 20 percent of its Empower trial injections were acquired or altered in Developer mode. The firm stopped trial injections and removed the Developer role. FDA asked for an independent data integrity assessment of every computerized system at all its facilities, not only the two chromatography systems.

At Ava, the problem was in the procedure itself. The firm’s gas chromatography procedure required a trial injection that was “not processed as a part of raw data.” FDA noted that writing this practice into a procedure directed staff away from basic CGMP requirements, and concluded: “Your systematic use of trial injections indicates a fundamental lack of oversight of data integrity in your laboratory.”19 At Shimoga, an unreported injection gave a failing assay result while a passing injection went into the batch record, and the batch was released to the US because no one reviewed the electronic data.27

Access

Who Can Do What

Unique accounts on every system, including stand-alone instruments. No administrator rights for analysts. No development or configuration roles used for CGMP samples.

Audit trail

What Changed and Why

Audit trails turned on, validated, and reviewed as part of batch release. Vendor and IT changes to GxP records routed through the quality system, never by email request.

Retention

What Is Kept

No automatic deletion at shutdown, no reused file names, and backups that are tested. Monitoring systems that store data and alarms, not only show live values.

Review

Who Looks at the Source

Reviewers check the original electronic data and the injection sequence, not a printout or a photocopy. Every injection accounted for against a sample or a documented purpose.

Why FDA Called the Responses Inadequate

Most of these letters follow a written response to the inspection findings and explain why that response fell short. Read together, the explanations are the most useful part of the record, because they show what FDA will not accept.

Treating a Pattern as a One-Off

Several firms described the problem as an isolated event or a single person’s misconduct. BioMylz attributed destroyed documents to a former plant manager and called it an isolated incident. FDA said this was contradicted by evidence that the manager had repeatedly destroyed records and falsified data.28 FDA said Dabur’s corrective actions treated the problems “as isolated procedural gaps rather than as evidence of a systemic breakdown in QU oversight and a deficient quality culture.”29 Reliance told FDA that “the unaccounted samples may have been misplaced,” which FDA pointed out did not address its own analysts’ statements that the samples were never collected.32

Auriga Research tried the opposite framing, describing its documentation gaps as “consistent with an institutional procedural and cultural gap rather than individual misconduct or a coordinated effort to conceal or falsify results.” FDA read that as confirmation that the practice applied to all the drugs the lab tested, including those for the US market.31

A Retrospective Review That Was Too Small

FDA rejected reviews it judged too narrow for the findings. Pharmathen proposed a third-party review of a statistical sample of records; FDA said the degree of review was not sufficient given the significance of the practices found.22 Curia’s review of shared credentials covered 12 instruments over one year.34 Dabur proposed testing a small number of samples for cross-contamination, which FDA called statistically insufficient.29 Intas reviewed its emails to one software vendor but not to others.18

The Not-for-the-US Argument

Tentamus said the discarded validation documents were not related to products for the United States, and Auriga said the same about its incomplete test sheets. FDA gave the same answer both times: the firm runs one quality system and one set of procedures, so the failure applies to everything it tests.1331

Holding Back the Investigation

Huons commissioned a third-party data integrity assessment and committed to share the interim and final reports, then told FDA the assessment was an “internal audit” and would not be provided. FDA disagreed, because the assessment was started in response to inspection findings rather than as a routine audit, and wrote: “The agency expects full transparency throughout your remediation process.”25

Help Arriving Too Late

A. Nelson planned an external data integrity audit for May 2026, eight months after the inspection. FDA called this “an excessive delay given the extent of the data integrity violations observed,” and noted that the consultant was engaged to audit the firm’s corrections rather than to guide them.12

What FDA Asked For Instead

Most of the 24 letters request the same set of deliverables, in nearly the same words. They form FDA’s working definition of an acceptable data integrity remediation:

1

A Comprehensive Investigation

A written protocol and method covering every laboratory, operation, and system, with a justification for anything left out. Interviews of current and former employees, preferably by a qualified third party. An assessment of omissions, alterations, deletions, record destruction, and records completed after the fact.

2

A Current Risk Assessment

An analysis of the risk to patients from drugs released on the basis of affected data, and of the risk from continuing operations.

3

A Management Strategy

A corrective action plan for the reliability and completeness of all data, root causes matched to the scope of the findings, a statement of whether the people responsible can still influence CGMP data, interim measures such as recalls or added testing, and long-term changes to procedures, systems, and oversight.

4

Independent Follow-Up

In the longer letters, a commitment to annual audits by a qualified consultant for at least two years after the remediation, and a statement of whether the firm will appoint a chief integrity officer who can receive anonymous employee complaints.

Twelve of the 24 letters ask about a chief integrity officer or a similar role. Most ask the firm to tell FDA whether it will hire one. The Curia New York letter asks for confirmation that the firm will hire a data integrity compliance officer.34 One letter is not a trend, but it is worth watching.

What Happened to the Firms

A warning letter is rarely the only consequence. The letters themselves record what else followed.

10 of 24Letters stating the firm’s drugs were placed on, or remain on, Import Alert 66-40
8 of 24Letters recording a recall after the inspection or an FDA teleconference
4 of 24Letters recording that the firm suspended production for the US market

Import Alert 66-40 allows FDA to detain drugs from foreign firms that appear not to follow CGMP, without physical examination.9 Ten of the 18 foreign firms in this group were on it. In every case the alert came before the letter, from three days earlier for Xiamen Kang Zhongyuan to more than two years earlier for Patcos, which was placed on the alert in November 2023 after an earlier records request.1715 Wizcure was placed on the alert in December 2025, six months before its letter.26

Recalls followed in eight cases: Xiamen Kang Zhongyuan, Pharmathen, Huons, Wizcure, Shimoga, Dabur, Reliance Life Sciences, and Shoolin. Shimoga’s recall notice for its API cited deficiencies in its quality system and data integrity concerns.27 On March 25, 2026, Huons committed to a voluntary recall of all drugs made at its facility.25 Pharmathen, Huons, Wizcure, and Reliance suspended US production.

Records Requests and Unannounced Inspections

Two letters, to Zydus and Gopaldas Visram, came from records requests under section 704(a)(4) of the Food, Drug, and Cosmetic Act, with no inspection at all. Both were among nine talc-related letters FDA issued on June 2, 2026. FDA found the data problems by reading the spectra the firms submitted. FDA’s final guidance on remote regulatory assessments, issued in June 2025, describes how it uses these requests.6 For a firm, the lesson is that a submitted record can be examined as closely as one reviewed on site, and statistically odd data will be noticed.

The other side of the picture is unannounced inspections. In May 2025 FDA announced it would expand unannounced inspections at foreign manufacturing sites, and said they would help expose firms that falsify records or conceal violations.8 The A. Nelson and Patcos letters both describe unannounced inspections. We cannot tell from the letters whether the other foreign inspections in this group were announced in advance, so we do not draw a conclusion about the effect of the policy. What the letters do show is that several findings, such as plates replaced overnight at Wizcure and records carried out in garbage bags at Tentamus, were caught because investigators were present while the work was happening.

What to Check at Your Own Sites and Suppliers

For pharma and biotech companies, these letters are useful in two directions. They describe what an FDA investigator will look for at your own sites, and they describe what can go wrong at the contract manufacturers and laboratories whose data you put into your batch records and submissions. Six of the 24 letters went to contract testing laboratories or firms making product for others.

Checks Drawn Directly From the 2026 Letters

  • Microbiology reconciliation. Can every plate in the incubator be matched to a sample record, and every sample record matched to a plate? Is there a photograph or second reader for each count? Are negative results recorded at the time, not filled in later?
  • Blank and uncontrolled forms. Are CGMP forms issued and reconciled by quality, or can anyone print a fresh copy? The Huons count of 1,897 blank forms and the A. Nelson finding on duplicate printing both point here.
  • Where records are lost. Who reviews what goes into shred bins and trash in laboratory and production areas? Curia could not determine how much had already been destroyed, and FDA asked it to establish how long the practice had gone on.
  • Stand-alone instruments. Stand-alone meters and infrared instruments were among the places where the shared passwords, auto-deleted data, and gaps in audit trails were found, along with HPLC and GC systems. Do they have unique logins and stored data?
  • Chromatography injection accounting. Can every injection in the sequence be tied to a sample or a documented system suitability purpose? Are development or administrator roles in use for CGMP work?
  • Vendor access to GxP records. Can a software vendor change production records at someone’s request, and would the audit trail show it?
  • Environmental monitoring data retention. Do differential pressure, temperature, and humidity systems store readings and alarm history, or only display them?
  • What reviewers look at. Are second-person reviews done against original electronic data or against printouts and photocopies?

For Your Contract Manufacturers and Laboratories

The Auriga letter warns that FDA may refuse admission of client products tested at that laboratory.31 The Shoolin letter shows an API maker reporting contract laboratory results on its own letterhead.33 The Gopaldas letter faults the firm’s quality unit for not overseeing its contract laboratory’s methods.24 In each case the sponsor or customer relied on a certificate that did not show what was behind it. Our September article on contract laboratory oversight covers audit design and contract terms in detail; the 2026 letters add one point to it. A supplier audit that looks only at chromatography software will miss most of what FDA found this year. Ask to see the microbiology laboratory, the incubators, and the plate reconciliation, and ask where discarded paper goes.

A useful test for any site. Pick three reported results at random: one chemistry, one microbiology, one environmental monitoring. Ask for everything behind each one, from sample collection to the reported value, and time how long it takes to produce. In 13 of this year’s 24 letters, the firm could not produce a complete record behind at least one result or activity.

Conclusion

The 2026 record gives a clearer and more useful picture than the usual claim. Data integrity appeared in one in four FDA drug manufacturing-quality letters posted through September, not most of them. Where it appeared, it was usually about people and paper: records missing, records made up after the fact, originals thrown away, and microbiology results that could not be traced to a real plate. Computer controls still matter, and the Curia, Ava, and Intas letters show that large and small firms alike can lose control of chromatography data and vendor access. But the most common failure was a quality unit that signed a record without checking that it was true.

For pharma and biotech leaders, the practical response is to test the evidence behind reported results, at your own sites and at your suppliers, with the same questions FDA asked this year. Sakara Digital works with pharma and biotech organizations on data integrity programs, laboratory system assessments, and supplier oversight. If you are reviewing your own controls or preparing a contract manufacturer or laboratory for inspection and want an independent perspective on where to start, we are happy to have that conversation.

For Further Reading