In This Article
- Executive Summary
- The Record Is the Control, Not the Operator
- What the Rules Actually Require, Field by Field
- Timestamps: The Highest-Volume Source of Unexplained Discrepancy
- Material and Lot Entries
- Equipment Identification and Status
- Calculations, Unit Conversions, Yield and Reconciliation
- In-Process Checks and Step Order
- Free Text: The Field That Carries What Nobody Can Trend
- The Highest-Yield Field Fixes, Ranked by Effort
- Review by Exception: The Prerequisites Live in the Fields
- When the MES Cannot Be Changed Quickly
- Conclusion
- For Further Reading
- References & Sources
Executive Summary
Most sites treat batch record problems as a training issue. An operator missed an entry, so the operator gets retrained, the deviation closes, and the same field fails again three batches later. The pattern repeats because the failure is not in the person. It is in the field: what it asks for, when it asks, what it will accept, and whether anything downstream can tell the difference between a value that was captured and a value that was typed from memory an hour after the fact.
A small number of fields generate most of the deviations, most of the review-by-exception noise, and most of the investigation hours in an electronic batch record. Timestamps that disagree across the manufacturing execution system, the laboratory system, and the equipment historian. Material and lot identifiers that were typed instead of scanned. Equipment identity and status. Manual calculations and unit conversions. Yield and reconciliation. In-process check entries. And free-text comment boxes that hold the one piece of information nobody can trend. Each has a recognizable failure pattern, a predictable effect on investigation effort, and a design fix that is usually cheaper than the retraining it replaces.
This article works through those fields one at a time. For each, it gives the failure pattern, what it does to an investigation, and the specific design change that removes it: constrained pickers, barcode capture, calculated fields with their own audit trail, structured reason codes in place of free text, forced-order steps, and tolerance checks applied at the moment of entry rather than at review. It grounds the argument in 21 CFR 211.188 and 211.192, EU GMP Chapter 4 and Annex 11, and recent FDA warning letters. It closes with a ranked table of field fixes, the prerequisites that review by exception actually depends on, and what to do when the manufacturing execution system cannot be changed on your timeline.
The Record Is the Control, Not the Operator
There is a sentence that appears in a large share of batch record deviations across the industry, in slightly different wording each time: the operator did not follow the procedure. It is usually true and almost never useful. It describes what happened without explaining why the record permitted it, and it points every corrective action at the least changeable part of the system.
Read a year of batch record deviations at any commercial site and the concentration is striking. The same handful of fields recur. A time entry that does not match the equipment log. A component lot number that turns out to belong to a different container. An equipment identifier that was carried forward from the previous batch. A yield percentage that was calculated on a value that had already been rounded. A comment box holding two sentences that explain everything and can be trended by no one. The names on the deviations change. The fields do not.
That concentration is the useful signal. It means batch record data quality is not a diffuse cultural problem requiring a diffuse cultural response. It is a design problem with a finite surface area. If eight or ten fields produce most of the noise, then eight or ten field-level changes remove most of the noise, and the remaining deviations are more likely to be real process events worth investigating.
Those error rates come from clinical research data processing rather than from manufacturing, and they should be read as an order of magnitude rather than a manufacturing benchmark. The point they make is still the right one. Manual entry has a floor. It does not go to zero with training, and halving it requires a second person doing the same work twice. A batch record with two hundred manual entries and a 0.3 percent per-field error rate produces something in the neighborhood of one erroneous entry every other batch as a matter of arithmetic, before anyone has a bad shift.
The regulations already understand this. Several of the CGMP requirements that people read as a person-verifies-person rule are written with an explicit alternative for system-performed steps. Component dispensing under 21 CFR 211.101(c) requires each dispensed container to be examined by a second person, unless the weighing or subdividing is performed by automated equipment under 211.68, in which case one person is enough. Section 211.103 requires yield calculations to be performed by one person and independently verified by a second, unless the yield is calculated by automated equipment under 211.68, in which case one person verifies. Section 211.188(b)(11) asks for the identity of the person performing and checking each significant step, or, where the step is performed by automated equipment, the identity of the person checking what the equipment did.13
Read together, those clauses say something specific: the rule already anticipates that the system, not the operator, will do the capturing, and it lowers the human verification burden when it does. Sites that keep the human in the transcription loop are not being more compliant. They are choosing a higher error rate and a heavier review burden than the regulation requires.
What the Rules Actually Require, Field by Field
Before redesigning fields it is worth being precise about what has to be in them, because the American and European requirements are not identical and the difference matters most in exactly the field that causes the most trouble.
The United States list
21 CFR 211.188 requires a batch production and control record for every batch, containing an accurate reproduction of the master record checked for accuracy, dated and signed, plus documentation that each significant step was accomplished. The enumerated list in paragraph (b) covers dates; identity of individual major equipment and lines used; specific identification of each batch of component or in-process material used; weights and measures of components used; in-process and laboratory control results; inspection of the packaging and labeling area before and after use; a statement of actual yield and of percentage of theoretical yield at appropriate phases; complete labeling control records; description of containers and closures; any sampling performed; identification of the persons performing, supervising or checking each significant step; any investigation made under 211.192; and results of examinations under 211.134.1
Note the first item. The regulation says dates. It does not say times. Times enter United States CGMP indirectly, through 211.100 and 211.160, which require certain activities to be documented at the time of performance, through the audit trail expectations of 21 CFR Part 11, and through process-specific requirements such as hold times and exposure limits.27
The European list
EU GMP Chapter 4, clause 4.20, requires the batch processing record to contain, among other elements, the name and batch number of the product and dates and times of commencement, of significant intermediate stages, and of completion of production. It also requires the initials of the operators who performed each significant step and of the person who checked them, the batch numbers and quantities of each starting material actually weighed, any relevant processing operation or event and major equipment used, in-process controls with the initials of the people carrying them out and the results obtained, the product yield at pertinent stages, and notes on special problems with signed authorization for any deviation from the manufacturing formula.10
Chapter 4 also carries the contemporaneity requirement in plain terms. Clause 4.8 states that records should be made or completed at the time each action is taken and in such a way that all significant activities concerning the manufacture of medicinal products are traceable.10
The transatlantic gap that shows up in your record design. A record designed only against 211.188(b)(1) captures dates. A record designed against Chapter 4 clause 4.20(b) captures dates and times for start, significant intermediate stages, and completion. Most multinational sites operate one global record template, so this is not a theoretical distinction. It determines whether your record has a time field at all in the places a European inspector will look for one.
What Annex 11 adds for the electronic case
EU GMP Annex 11 supplies the computerized-system layer. Clause 5 requires that systems exchanging data electronically with other systems include appropriate built-in checks for the correct and secure entry and processing of data. Clause 6 requires that for critical data entered manually there should be an additional check on accuracy, and states that the check may be done by a second operator or by validated electronic means. Clause 8.2 requires that for records supporting batch release it should be possible to generate printouts indicating if any of the data has been changed since the original entry. Clause 9 addresses audit trails, requires that the reason be documented for changes or deletions of GMP-relevant data, and requires that audit trails be available in an intelligible form and regularly reviewed.9
Clause 6 is the single most under-used sentence in Annex 11. It gives explicit permission to replace second-person verification with a validated electronic check. Every field where you currently pay for a second signature to confirm a typed value is a field where a scan, a lookup, or a range check could carry the same regulatory weight at a fraction of the ongoing effort.
Timestamps: The Highest-Volume Source of Unexplained Discrepancy
If you rank batch record fields by the investigation hours they consume per deviation, timestamps come first at most sites. They also produce the least useful investigations, because the underlying question is almost never about the product. It is about which of three clocks was right.
The failure pattern
A single batch touches at least three systems that stamp time independently. The manufacturing execution system stamps the operator’s confirmation of a step. The laboratory system stamps sample receipt and result approval. The equipment historian stamps process values continuously at its own scan rate. Each of those stamps comes from a different clock, and in a plant that has grown by acquisition or expansion, those clocks are often synchronized to different sources or to nothing at all.
Four distinct problems hide inside the general complaint that the times do not agree.
Clock drift and no common source
Servers, workstations, and embedded equipment controllers that are not disciplined to a common time source drift apart at rates that are small per day and material per quarter. A two-minute offset between the historian and the MES turns every sequencing question into an argument.
Time zone and daylight saving
One system stores local time, another stores coordinated universal time, a third stores local time with no zone marker at all. Twice a year the local systems produce an hour that occurs twice and an hour that never occurs. Records generated in those windows cannot be ordered reliably.
Recorded at versus occurred at
The system stamps when the entry was saved. The record is asked to represent when the action happened. Those are different facts, and most record designs capture only the first while labeling it as the second.
Resolution mismatch
A historian sampling every second and an MES stamping to the minute will disagree on ordering for any two events less than a minute apart. Nothing is wrong. The record simply cannot answer the question being asked of it.
What it does to the investigation
A time discrepancy that cannot be explained is, on its face, an unexplained discrepancy. Section 211.192 requires the quality control unit to review all production and control records before release and requires that any unexplained discrepancy, or any failure of a batch or its components to meet specifications, be thoroughly investigated, whether or not the batch has already been distributed, with the investigation extending to other batches of the same drug product and other drug products that may have been associated with the failure or discrepancy.2
That is a serious obligation to trigger over a clock. The investigation has to establish which record is authoritative, whether the process step actually occurred within its validated window, whether any dependent limit such as a hold time or a bioburden exposure period was exceeded, and whether the same offset affected other batches. Sites routinely spend days on this, and the honest conclusion in most cases is that both entries were correct and the clocks were not.
The design fixes
FDA’s Part 11 guidance on scope and application addresses the time zone question directly. In a footnote to the discussion of withdrawn draft guidances, the agency states that although the draft guidance on time stamps was withdrawn, its current thinking has not changed, “in that when using time stamps for systems that span different time zones, we do not expect you to record the signer’s local time,” and adds that “when using time stamps, they should be implemented with a clear understanding of the time zone reference used. In such instances, system documentation should explain time zone references as well as zone acronyms or other naming conventions.”7
That is unusually permissive, and it points at the right design. Store one canonical time. Display local time. Document the convention.
- Discipline every GxP clock to one traceable source. Network time synchronization is a mature, standardized capability, specified for internet use in RFC 5905, and it is available on essentially every server and modern controller in the plant.13 The design decision is not whether to use it but which stratum of source the site trusts, how drift is monitored, and what happens to records generated while a device is out of sync.
- Store coordinated universal time with an explicit offset, display local time. A stored value that carries its own zone offset can be rendered correctly for an operator in one country and an inspector in another without altering the record. A stored local time with no offset cannot be repaired later.
- Separate “occurred at” from “recorded at” in the data model. If an entry can legitimately be made after the event, the record should hold both values and the review should see both. Merging them hides the exact information a reviewer needs, and it makes a late entry indistinguishable from a contemporaneous one.
- Make the entry window a control, not a hope. If a step must be confirmed within a defined period of the action, the system should enforce the window and require a structured reason when it is exceeded, rather than accepting the entry silently and leaving the gap for a reviewer to find weeks later.
- Reconcile clocks as a routine check, not an investigation output. A scheduled comparison of a known event across MES, laboratory system, and historian turns clock drift into a maintenance finding instead of a batch deviation.
Do not solve a clock problem by adjusting a record. Changing a stored timestamp to make two systems agree replaces a data quality problem with a data integrity problem. FDA’s data integrity guidance is explicit that CGMP regulations require certain activities to be documented at the time of performance and that records be retained as original records or true copies.8 The correct output of a clock investigation is a corrected clock, a documented offset, and an impact assessment, not a corrected record.
Material and Lot Entries
Component and lot identity is the field where a data quality defect becomes a product identity question fastest, which is why it produces investigations that are short to open and long to close.
The failure pattern
Three variants account for most of it.
Typed instead of scanned. A lot identifier that a person reads off a label and types into a field is subject to transposition, character confusion, and truncation. The value entered is usually a real lot number belonging to some material, which is what makes it dangerous. It passes any format check and fails only when reconciliation or genealogy is attempted later.
Partial lots and split containers. A dispensed quantity drawn from part of a container, or from two containers of the same lot, or from a residual quantity returned from a previous batch, exceeds what a single lot field can express. Operators resolve it by entering the primary lot and describing the rest in a comment. The record is then arithmetically incomplete and the genealogy is wrong.
Approved substitutions recorded as if they were the original. When a substitution is authorized during execution, a record with no field for it forces the substitution into free text or, worse, into an overwrite of the original entry. Either way the trending of substitution frequency becomes impossible.
What it does to the investigation
A lot identity discrepancy pulls in every other batch that used the implicated lot, because 211.192 requires the investigation to extend to other batches and other products that may have been associated with the discrepancy.2 A single mistyped character can therefore expand into a multi-batch scope exercise that consumes far more effort than the underlying error deserves.
The consequence is visible in enforcement. In a March 2026 warning letter to a compounding outsourcing facility, FDA cited failure to prepare batch production and control records with complete information, and the agency’s findings included incomplete documentation of the lot numbers of sterile materials used in a lidocaine injection batch record.16 A July 2026 warning letter to a manufacturer of drug products cited 211.188 for failure to establish adequate batch production and control records containing the accomplishment of each significant step in the manufacture, processing, packing, or holding of the batch.19 Neither observation required an exotic failure. Both describe fields that were left empty or under-specified.
The design fixes
- Barcode or two-dimensional code capture at the point of use, verified against the dispensing record. This is the clearest application of Annex 11 clause 6: a validated electronic check replacing a second human read.9 The scan should not merely populate the field. It should verify that the scanned lot is the lot the system expects for this batch, is released, and is within its retest or expiry date, and it should refuse the entry when it is not.
- Model partial lots properly. A dispensing transaction should support multiple source containers with a quantity against each, summing to the required amount. If the record can only hold one lot per component, operators will always find a workaround, and the workaround will always be free text.
- Give substitution its own structured path. A substitution field with a reason code, an approver, and a link to the authorization keeps the original intent visible and makes substitution rate a trendable number instead of a story that has to be reconstructed.
- Enforce the reconciliation at entry. Dispensed quantity, quantity added, and quantity returned should reconcile inside the transaction. A record that accepts an unreconciled dispense and flags it at review has converted a five-second correction into a deviation.
Equipment Identification and Status
Equipment fields look trivial and are not. Section 211.105(b) requires major equipment to be identified by a distinctive identification number or code that is recorded in the batch production record to show the specific equipment used in the manufacture of each batch, and permits the equipment name to be used in place of a code only where a single unit of that type exists in the facility.3 Section 211.188(b)(2) repeats the requirement to record the identity of individual major equipment and lines used.1
The failure pattern
Equipment identifiers are typically carried forward from the previous batch when the record is created, which means a wrong value is silently plausible. The equipment status question is worse. The record asserts a state that lives outside the record: cleaned, released, within calibration, within its clean hold time. When the record and the physical state disagree, the record usually wins on paper and loses on inspection.
FDA’s own CGMP questions and answers make the linkage explicit for status labeling, stating that the information on the temporary status label should correspond with the information recorded in the equipment cleaning and use log, or with the previous batch record for nondedicated equipment.4 Correspondence between three artifacts is a data quality requirement, not a labeling requirement.
Recent enforcement shows both halves failing. In an April 2026 warning letter, FDA described multiple instances in which operators failed to appropriately document sterilization chamber cleaning during a period when multiple batches for the United States market were being sterilized, and found physical residue in areas the cleaning logs represented as clean.17 In a January 2026 warning letter, the agency cited a manufacturer whose equipment was documented as clean while analytical testing confirmed residues of multiple active pharmaceutical ingredients above the firm’s own allowable limit.18 In both cases the field held a value. The value was not true.
The design fixes
- Select equipment from a governed asset master, never by typing. The picker should show only equipment that is currently qualified, calibrated, released, and eligible for this product and step. Filtering at selection removes an entire class of review findings.
- Derive status rather than asserting it. Clean status, calibration status, and clean hold time should be read from the systems that own those facts at the moment of selection, and the batch record should store what was read and when. A status field that an operator can set is a status field that will eventually be wrong.
- Block, do not warn. Selecting equipment that is out of calibration or past clean hold should stop execution and require a documented decision, not raise an advisory the operator can dismiss.
- Record the equipment identity as a link, not a string. A stored reference to the asset record survives renaming and supports genealogy queries. A typed string does neither.
Calculations, Unit Conversions, Yield and Reconciliation
Manual calculation inside a batch record is the last place in a modern plant where arithmetic is performed by hand and then verified by hand, and it persists mostly because it was never revisited after the record went electronic.
The failure pattern
Four things go wrong, in rough order of frequency.
- Rounding applied before the calculation rather than after. An operator records a rounded intermediate, then calculates from the rounded value. The result differs from the same calculation performed on the captured values, and the difference lands close enough to a limit to require explanation.
- Unit conversion done in the operator’s head. Kilograms to grams, liters to milliliters, percent to fraction, mass to volume via a density the record does not carry. Every conversion that is not in the record is a calculation that cannot be reproduced during review.
- Yield calculated against the wrong basis. Theoretical yield adjusted for a calculated excess of component, or for a partial batch, or for material removed for sampling, has to be computed on a defined basis. When the basis is not stored, two reviewers reach two answers.
- Spreadsheets outside the record. A calculation performed in an uncontrolled spreadsheet and transcribed into the record breaks the chain in both directions. The record cannot show the inputs, and the spreadsheet has no audit trail.
What it does to the investigation
Yield is the one field where the regulation itself names the trigger. Section 211.192 identifies a percentage of theoretical yield exceeding the maximum or minimum percentages established in the master production and control records as an example of an unexplained discrepancy requiring thorough investigation.2 Section 211.186 requires the master record to state theoretical yield including those maximum and minimum percentages, and to state any calculated excess of component and theoretical weight or measure at appropriate phases.5 Section 211.103 requires that actual yields and percentages of theoretical yield be determined at the conclusion of each appropriate phase and that the calculation be performed by one person and independently verified by a second, or independently verified by one person where the yield is calculated by automated equipment.3
A yield investigation opened because of a calculation defect is expensive in a specific way. It cannot be closed quickly, because the first thing it must rule out is material loss, and ruling out material loss means reconstructing the mass balance from records that were the source of the problem.
The cleanest fix in the whole record. Make yield and every reconciliation a calculated field. The system reads the captured weights, applies the master-record basis, computes the percentage, compares it to the master-record limits, and writes the result with its own audit trail showing which inputs were used and which version of the formula was applied. Section 211.103 then requires one person to verify what the system did rather than two people to do and check the arithmetic, and Annex 11 clause 6 supports the validated electronic check in place of the second operator.39
The design fixes
- Capture raw values, calculate derived ones. No operator should ever enter a value the system could compute. If the value is derived, the field should be read-only and stamped with its inputs.
- Store units with values and convert in the system. A quantity field that carries its unit of measure removes conversion from the human path entirely and makes cross-site comparison possible.
- Version the formula and store the version used. When a calculation changes, batches executed before the change must still be reproducible. Storing the formula version with the result is what makes that possible without archaeology.
- Define rounding and significant figures once, in the master record. Then apply them in one place. Rounding rules that live in a training slide will be applied inconsistently forever.
- Eliminate uncontrolled spreadsheets from the execution path. Enforcement in this area is unforgiving, and the record cannot demonstrate what it cannot see.
In-Process Checks and Step Order
In-process control entries are where a batch record’s design either supports the control strategy or quietly undermines it. Section 211.110 requires written procedures describing the in-process controls, tests, or examinations to be conducted on appropriate samples of in-process materials of each batch, established to monitor the output and validate performance of the manufacturing processes responsible for causing variability.3 Chapter 4 clause 4.20(f) requires a record of the in-process controls, the initials of the people carrying them out, and the results obtained.10
The failure pattern
The entries exist. The problem is when and in what order they were made. A record that permits steps to be completed out of sequence will eventually contain an in-process result recorded before the sample was taken, a line clearance confirmed after the line was running, or a set of readings entered in a single burst at the end of a shift because the terminal was on the other side of the room.
None of these necessarily means the work was not done correctly. All of them make the record unable to demonstrate that it was, which is the same thing at review. FDA’s data integrity guidance is direct on this point, noting that CGMP regulations require certain activities to be documented at the time of performance.8
The severe end of this pattern is visible in enforcement. In a June 2026 warning letter, FDA described a firm where logbook pages were manipulated to look like the originals and a microbiology team leader instructed an analyst to backdate and omit testing information, and where investigators found 1,897 blank uncontrolled forms related to CGMP activities.20 Blank uncontrolled forms are what appears when the official record is too rigid or too remote to be completed during the work. The falsification is a separate and far more serious matter, but the gap that made it easy is a design gap.
The design fixes
- Force the order where order matters. Steps with a real dependency should be enforced as dependent. Steps without one should not be, because unnecessary sequencing is the most common reason people stop trusting the sequencing that does matter.
- Apply tolerance checks at the moment of entry. A value outside its limit should be identified while the operator is still standing at the equipment, when a re-read takes seconds and a real excursion can be escalated immediately. Detecting the same value at review guarantees an investigation and forecloses the cheapest possible response.
- Put the entry point where the work is. Distance between the operation and the terminal is the strongest predictor of non-contemporaneous entry. Mobile or line-side capture removes the reason for the note that gets transcribed later.
- Capture instrument results directly. Where a balance, a probe, or an analyzer can write its result into the record, the transcription step and its error rate disappear, and the reading carries the instrument identity with it.
- Make late entry legal, structured, and visible. Some entries genuinely cannot be contemporaneous. A record with a defined late-entry path, a reason code, and both timestamps produces a reviewable exception. A record without one produces either a falsified entry or a deviation.
Free Text: The Field That Carries What Nobody Can Trend
Every batch record has comment boxes, and they hold the most valuable and least usable information in the document. The comment is where the operator explains what actually happened. It is also where that explanation goes to disappear.
The failure pattern
Free text is unusable in aggregate for a reason that is structural rather than cultural. The same event is described in different words by different people on different shifts, so no query finds all instances of it. Research on protocol deviations in clinical development makes the same observation about a closely comparable record type, noting that despite efforts to standardize subcategories, variability across studies remained high, which complicates trending analysis, and that reporting is influenced by differences in language, training, and documentation practices among the people writing the entries.14 Manufacturing comment fields behave the same way for the same reasons.
The second failure is that free text becomes the overflow channel for everything the record cannot model. Partial lots, substitutions, equipment swaps, timing exceptions, and minor process adjustments all end up in comments because there is nowhere else to put them. The comment box then holds facts that should be structured data, and the site’s trending is systematically blind to whatever is most common.
The third failure is that parallel unofficial records grow up alongside the official one. In a June 2026 warning letter, FDA described quality control personnel who used uncontrolled review checklists to unofficially document laboratory record reviews and then discarded them, and found multiple particulate excursions and repeated test failures present in instrument histories that were not documented in the laboratory records at all.15 Information that exists somewhere and not in the record is, for review and investigation purposes, information that does not exist.
The design fixes
Read a year of comments before designing anything
Pull the free-text entries from twelve months of batch records and classify them by hand. The categories that emerge are the fields the record is missing. This is the single highest-return analysis available in batch record design, and it takes days rather than months.
Build a reason code list from what people actually wrote
Codes derived from real entries get used. Codes derived from a workshop produce an “other” category that absorbs most of the volume and restores the original problem. Keep the list short enough to scan on one screen.
Pair every code with a free-text field, not instead of one
The code makes the entry trendable. The narrative makes it investigable. Removing the narrative to force structure is how sites lose the detail that made investigations tractable in the first place.
Route codes to consequences
A reason code that does nothing will be selected at random. A code that determines whether the entry becomes an exception, who reviews it, and whether it appears in a trend report will be selected with care.
Review the code list on a schedule
Watch the “other” rate and the free-text volume per batch. A rising “other” rate means the process has changed and the list has not. Treat it as a maintenance signal rather than a training failure.
The Highest-Yield Field Fixes, Ranked by Effort
Not every fix requires a system change, and the ones that do not are worth doing first because they buy credibility for the ones that do. The ranking below reflects what typically holds across commercial sites. Your own comment-field analysis should reorder it.
| Field fix | Effort | What it removes | Where it is grounded |
|---|---|---|---|
| Discipline all GxP clocks to one traceable time source and monitor drift | Low, infrastructure only | Cross-system time disagreements that trigger 211.192 investigations with no product question in them | 211.192; Part 11 audit trail expectations26 |
| Document the time zone convention and display local time from a stored canonical value | Low, mostly documentation | Ambiguity about which zone a stamp represents; daylight saving ordering failures | FDA Part 11 scope and application guidance, footnote on time stamps7 |
| Move tolerance checks from review to the moment of entry | Low to medium, configuration | Out-of-limit values found weeks later, when the cheap correction is no longer available | 211.110; Annex 11 clause 539 |
| Replace typed lot entry with verified barcode capture | Medium, hardware plus configuration | Transposition errors in identity fields; multi-batch scope expansions from a single character | Annex 11 clause 6; 211.101(c); 211.188(b)(3)931 |
| Convert yield and reconciliation to calculated fields with their own audit trail | Medium, configuration | Arithmetic and rounding defects that open yield investigations; double manual verification effort | 211.103; 211.186; 211.192352 |
| Select equipment from a governed master filtered by live qualification and clean status | Medium, needs master data work | Carried-forward equipment identifiers; status fields that disagree with physical state | 211.105(b); FDA CGMP questions and answers on status labels34 |
| Replace the top free-text categories with structured reason codes | Medium, needs the comment analysis first | Untrendable narrative; blind spots in the site’s most common events | Trending limitations of unstructured entries14 |
| Separate “occurred at” from “recorded at” in the data model | Medium to high, data model change | Late entries that are indistinguishable from contemporaneous ones | Chapter 4 clause 4.8; FDA data integrity guidance108 |
| Model partial lots, split containers, and authorized substitutions as first-class transactions | High, data model change | The largest single driver of free-text overflow in dispensing records | 211.101(c) and (d); 211.188(b)(3) and (b)(4)31 |
| Enforce step order only where a real dependency exists, and remove it elsewhere | High, requires process analysis | Sequencing deviations that carry no product risk and dilute attention from the ones that do | 211.100 and 211.110 process control expectations3 |
A note on how to sequence this. The first three rows can usually be completed inside one quarter without touching the manufacturing execution system’s validated functionality, and they remove a visible share of the deviation volume. That result is what funds the data model work in the last three rows, which is genuinely expensive and genuinely worth doing.
Review by Exception: The Prerequisites Live in the Fields
Review by exception is usually presented as a review process change. It is not. It is a claim about the quality of your fields, and it fails when the fields cannot support the claim.
The regulatory basis in Europe is narrower than most business cases assume. A note attached to EU GMP Chapter 4 clause 4.20 states that where a validated process is continuously monitored and controlled, automatically generated reports may be limited to compliance summaries and exception or out-of-specification data reports.10 Read the conditions carefully. The process must be validated. It must be continuously monitored and controlled. The report is automatically generated. None of that is satisfied by a record that is electronic but still filled in by hand.
Annex 11 supplies the second condition. Clause 8.2 requires that for records supporting batch release it be possible to generate printouts indicating if any data has been changed since the original entry.9 A reviewer who is looking only at exceptions has to be able to trust that nothing was changed outside them, and that trust is a system capability rather than a procedural assurance.
What has to be true before you narrow the review
- The values under review are captured, not typed. If the critical parameters still arrive by transcription, exception review only means you have stopped looking at most of the places errors are introduced.
- Every limit that defines an exception is in the system and versioned. A limit that lives in a procedure and is applied by a reviewer cannot generate an exception. It generates a judgment.
- The exception rules are validated against known cases. The testing has to demonstrate that events that should be caught are caught and classified correctly, and, just as importantly, that a critical event cannot be suppressed without leaving a trace.
- Changes to the exception configuration are under change control with the same rigor as the record itself. The rules that decide what a human sees are more consequential than most of the record content, and they are frequently held in configuration that receives less scrutiny than code.
- The audit trail is reviewable in a form a person can use. Annex 11 clause 9 requires audit trails to be available and convertible to a generally intelligible form and regularly reviewed.9 An audit trail that can only be read as raw system output does not meet the practical test.
- There is a rationale for every parameter you decided not to present. The decision not to show something to a reviewer is a documented risk decision, and it will be examined as one.
The underlying logic is simple enough to state in one sentence: the approach depends on screening manufacturing and quality data so that only critical exceptions are presented for review and disposition, which presupposes that the data being screened is complete and reliable enough for the screen to mean anything. The ISPE GAMP good practice guidance on manufacturing execution systems addresses electronic production record functionality, including review by exception, within a full lifecycle approach, which is the right frame: the functionality is not separable from how the system was specified, configured, and verified.11
The failure mode to watch for. A site that turns on review by exception without fixing its fields does not reduce its investigation burden. It relocates it. The errors that used to be caught at record review are now caught at deviation, at annual product review, or at inspection, where each one is more expensive and less recoverable than it was.
When the MES Cannot Be Changed Quickly
The honest constraint at most sites is that the manufacturing execution system is validated, heavily configured, supported by a vendor on a release cycle you do not control, and shared across products and sometimes across sites. A field-level redesign that would take a week in a greenfield system takes three quarters here. That is a real limit and it is not a reason to do nothing.
Three moves are available while the system change works its way through.
1. Fix what sits outside the validated boundary
Time synchronization, master data quality, terminal placement, scanner deployment, label print quality, and the governance of the equipment asset register are all outside the MES change control boundary at most sites, and every one of them changes the error rate inside the record. Clock discipline in particular is infrastructure work that removes a category of deviation without a single system change request.
Master data deserves specific attention. A material master with duplicate entries, an equipment register with retired assets still selectable, and a product master with stale limits will defeat any amount of field design. Cleaning them is unglamorous and it is usually the highest-return work available in the first ninety days.
2. Move the check earlier without moving it into the MES
If the record cannot enforce a check at entry, a scheduled reconciliation running against the same data can still catch the error within hours instead of at review. A daily comparison of MES step times against historian events, a daily reconciliation of dispensed against consumed quantities, and a daily check of equipment status assertions against the maintenance system all convert would-be deviations into same-day corrections while the underlying design work proceeds.
Two cautions apply. First, these reports have to be controlled records with defined ownership and retention, not personal spreadsheets. The enforcement example of discarded unofficial review checklists is exactly what happens when a helpful side process is not brought inside the quality system.15 Second, a reconciliation report that finds a discrepancy has found a discrepancy. It does not authorize a silent correction.
3. Separate configuration from code and exploit the difference
A substantial share of what people describe as an MES change is configuration: picklist contents, limit values, mandatory-field flags, reason code lists, display order, and entry masks. Configuration items usually carry a lighter, faster change path than functional changes, provided the site has defined which is which and validated accordingly. Sites that have never drawn that line treat every change as maximum effort and consequently make none.
One thing to avoid completely. Do not let anyone change record content or configuration outside the quality system, however small the change or however helpful the intent. In a March 2026 warning letter, FDA found that a quality assurance employee had instructed the firm’s software vendor to make changes to the electronic batch record that were not captured in the audit trail or managed through the quality system, including replacing one employee identification number with another for a “Dispensed by” entry, with the change recorded neither in the audit trail nor in the electronic batch record.21 The agency required a retrospective review of software-related communications with support vendors and a product impact assessment. A shortcut in configuration becomes a data integrity finding with a retrospective scope attached.
The sequence that works
Sites that get through this successfully tend to follow the same order. They start by counting: how many deviations by field, how many investigation hours by field, how much free text by category. They fix the infrastructure and master data problems that need no system change. They configure the checks that the current system already supports. They use the measured reduction to justify the data model changes that require real project funding. And they keep measuring, because the only durable defense against the next round of field-level noise is knowing which fields are producing it.
Conclusion
Batch record data quality is not a maturity attribute or a cultural aspiration. It is the sum of a set of specific design decisions about a small number of fields, and those decisions are legible in the deviation log of every site that has one. The regulations that govern this work are more accommodating of good design than most quality organizations assume. Annex 11 clause 6 permits a validated electronic check in place of a second operator. Sections 211.101, 211.103, and 211.188(b)(11) reduce the human verification burden for steps performed by automated equipment. FDA’s guidance on time stamps asks for a documented time zone convention rather than a particular local time. The constraints people cite most often when defending a manual record are usually not in the text.
What we see repeatedly is that the effort required to fix a field is smaller than the effort already being spent investigating what that field produces, and that the first quarter of work needs no system change at all. Clock discipline, master data cleanup, terminal placement, and a serious read of a year’s worth of comment boxes will tell a site more about its record than any assessment, and will pay for the harder work that follows.
Sakara Digital works with pharma and biotech organizations on exactly this kind of record-level data quality work: finding which fields are generating the investigations, deciding what to change in the record rather than in the training plan, and sequencing the changes that need the system against the ones that do not. If you are looking at a rising deviation count in your batch records, or weighing a move to review by exception and unsure whether your fields will support it, we are happy to have that conversation.
For Further Reading
For Further Reading
- Review by Exception for Batch Records: The Prerequisites Nobody Lists
- Data Historian Modernization on the Pharma Shop Floor
- MES Selection for Life Sciences: A Decision Framework for Pharmaceutical Manufacturing Execution Systems
- Batch Genealogy for Biologics: Tracing a Lot Back Through Bulk and Cell Bank
- Deviation Trending Analytics: From Excel to Real-Time Dashboards
References & Sources
- U.S. Government Publishing Office. “21 CFR 211.188: Batch production and control records.” Code of Federal Regulations, Title 21, Volume 4, 2025 edition. https://www.govinfo.gov/content/pkg/CFR-2025-title21-vol4/pdf/CFR-2025-title21-vol4-sec211-188.pdf
- U.S. Government Publishing Office. “21 CFR 211.192: Production record review.” Code of Federal Regulations, Title 21, Volume 4, 2025 edition. https://www.govinfo.gov/content/pkg/CFR-2025-title21-vol4/pdf/CFR-2025-title21-vol4-sec211-192.pdf
- U.S. Government Publishing Office. “21 CFR 211.101, 211.103, 211.105 and 211.110: Charge-in of components, calculation of yield, equipment identification, and sampling and testing of in-process materials.” Code of Federal Regulations, Title 21, Volume 4, 2025 edition. https://www.govinfo.gov/content/pkg/CFR-2025-title21-vol4/pdf/CFR-2025-title21-vol4-sec211-103.pdf
- U.S. Food and Drug Administration. “Questions and Answers on Current Good Manufacturing Practice Regulations: Production and Process Controls.” Equipment status identification labels and batch records. https://www.fda.gov/drugs/guidances-drugs/questions-and-answers-current-good-manufacturing-practice-regulations-production-and-process
- U.S. Government Publishing Office. “21 CFR 211.186: Master production and control records.” Code of Federal Regulations, Title 21, Volume 4, 2025 edition. https://www.govinfo.gov/content/pkg/CFR-2025-title21-vol4/pdf/CFR-2025-title21-vol4-sec211-186.pdf
- U.S. Government Publishing Office. “21 CFR 11.10: Controls for closed systems.” Code of Federal Regulations, Title 21, Volume 1, 2025 edition. https://www.govinfo.gov/content/pkg/CFR-2025-title21-vol1/pdf/CFR-2025-title21-vol1-sec11-10.pdf
- U.S. Food and Drug Administration. “Guidance for Industry. Part 11, Electronic Records; Electronic Signatures: Scope and Application.” September 2003, footnote 5. https://www.fda.gov/media/75414/download
- U.S. Food and Drug Administration. “Data Integrity and Compliance With Drug CGMP: Questions and Answers. Guidance for Industry.” December 2018. https://www.fda.gov/media/119267/download
- European Commission. “EudraLex Volume 4, Annex 11: Computerised Systems.” June 2011, clauses 5, 6, 8.2 and 9. https://ec.europa.eu/health/sites/health/files/files/eudralex/vol-4/annex11_01-2011_en.pdf
- European Commission. “EudraLex Volume 4, Chapter 4: Documentation.” January 2011, clauses 4.8 and 4.20. https://ec.europa.eu/health/sites/health/files/files/eudralex/vol-4/chapter4_01-2011_en.pdf
- International Society for Pharmaceutical Engineering. “GAMP Good Practice Guide: Manufacturing Execution Systems, A Strategic and Program Management Approach.” https://ispe.org/publications/guidance-documents/gamp-manufacturing-execution-systems
- Garza, M.Y., Williams, T., Ounpraseuth, S., Hu, Z., Lee, J., Snowden, J., Walden, A.C., Simon, A.E., Devlin, L.A., Young, L.W., Zozus, M.N. “Error Rates of Data Processing Methods in Clinical Research: A Systematic Review and Meta-Analysis of Manuscripts Identified Through PubMed.” Research Square preprint, December 2023. https://pmc.ncbi.nlm.nih.gov/articles/PMC10775420/
- Mills, D., Martin, J., Burbank, J., Kasch, W. “Network Time Protocol Version 4: Protocol and Algorithms Specification.” RFC 5905, Internet Engineering Task Force, June 2010. https://www.rfc-editor.org/rfc/rfc5905
- Zou, M., Popko, L., Gaudio, M. “Using Large Language Models for Advanced and Flexible Labelling of Protocol Deviations in Clinical Development.” Therapeutic Innovation & Regulatory Science, 2025. https://pmc.ncbi.nlm.nih.gov/articles/PMC12181094/
- U.S. Food and Drug Administration. “Warning Letter: Genzyme Ireland Limited, MARCS-CMS 728681.” June 22, 2026. https://www.fda.gov/inspections-compliance-enforcement-and-criminal-investigations/warning-letters/genzyme-ireland-limited-728681-06222026
- U.S. Food and Drug Administration. “Warning Letter: RC Outsourcing, LLC, MARCS-CMS 722877.” March 20, 2026. https://www.fda.gov/inspections-compliance-enforcement-and-criminal-investigations/warning-letters/rc-outsourcing-llc-722877-03202026
- U.S. Food and Drug Administration. “Warning Letter: CareFusion 213, LLC, MARCS-CMS 722729.” April 30, 2026. https://www.fda.gov/inspections-compliance-enforcement-and-criminal-investigations/warning-letters/carefusion-213-llc-722729-04302026
- U.S. Food and Drug Administration. “Warning Letter: Cohance Lifesciences Limited, MARCS-CMS 718812.” January 30, 2026. https://www.fda.gov/inspections-compliance-enforcement-and-criminal-investigations/warning-letters/cohance-lifesciences-limited-718812-01302026
- U.S. Food and Drug Administration. “Warning Letter: Woodbine Products Company Inc., MARCS-CMS 729345.” July 27, 2026. https://www.fda.gov/inspections-compliance-enforcement-and-criminal-investigations/warning-letters/woodbine-products-company-inc-729345-07272026
- U.S. Food and Drug Administration. “Warning Letter: Huons Co., Ltd., MARCS-CMS 724650.” June 15, 2026. https://www.fda.gov/inspections-compliance-enforcement-and-criminal-investigations/warning-letters/huons-co-ltd-724650-06152026
- U.S. Food and Drug Administration. “Warning Letter: Intas Pharmaceuticals Limited, MARCS-CMS 721151.” March 30, 2026. https://www.fda.gov/inspections-compliance-enforcement-and-criminal-investigations/warning-letters/intas-pharmaceuticals-limited-721151-03302026








Your perspective matters—join the conversation.