Picture a well-run aseptic filling suite. Settle plates go out at the start of every fill and come back at the end. Contact plates are pressed on the RABS gloves, the stopper bowl surround, and the operators’ gowns on exit. Active air samplers run on schedule. The incubators are full, the media lots are growth-promotion tested, and every plate gets read by a trained microbiologist. On paper, and usually literally on paper, the program is complete.

Now ask the quality director for the trend at one Grade B sampling point over the last twelve months. What comes back, at a surprising number of sites, is a spreadsheet assembled over three days, with a note explaining that the room was renamed in March after the renovation, that the LIMS still carries the old location code, that the plates from one week in July were read a day late because of a holiday, and that the alert level shown in the chart is the one from the current SOP even though the earlier results were evaluated against a different one. The data was all collected. It just cannot be assembled into a series in which each point means the same thing.

That is the paradox this article is about. Sample collection can be complete while the trend is unusable. The failure is not in the microbiology. It is in the data: how locations are identified, how results are captured, how limits are stored, what context is recorded with each count, and whether any of it can be joined to the batch record.

Why this now matters more than it did

Three things have changed the stakes. First, the revised EU GMP Annex 1, in force since August 2023, made EM data a batch-release input in explicit terms. Paragraph 9.3 says the information from the monitoring systems should be used for routine batch certification and release, and paragraph 10.10 says EM data and trend data for classified areas should be reviewed as part of product batch certification and release.1 A trend that cannot be produced reliably is now a batch-release control that cannot be demonstrated.

Second, FDA’s expectations have been written down for two decades and inspectors are applying them. The 2004 aseptic processing guidance states that the quality control unit should provide routine oversight of near-term (daily, weekly, monthly, quarterly) and long-term trends in environmental and personnel monitoring data, and that trend reports should include data by location, shift, room, operator, or other parameters.2 FDA’s compliance program for sterile drug process inspections, 7356.002A, instructs investigators to review the quality unit’s data summaries and trend reports during every inspection, and lists EM trend data (microbial and particle counts) and personnel monitoring trend data among the quality records to examine.3

Third, the warning letters keep coming. In May 2026, FDA cited a sterile manufacturer for failing to investigate multiple action-level EM excursions in ISO 5 and ISO 7 areas between January and June 2025. The letter describes an adverse trend of mold recoveries on personnel across February, March, May, and June, with no trend investigation opened until August 27, 2025, and a recovery of 83 colony forming units, including mold, from an operator’s neck in an ISO 7 area that did not trigger a deviation investigation.4 In March 2026, another letter described at least 47 microbial recoveries from cleaning use points in an ISO 5 area and RABS between June 2023 and September 2025, 14 of them above the action limit, alongside repeated post-production EM recoveries of gram-negative water organisms and too-numerous-to-count levels on RABS gaskets during what FDA called an adverse trend in late 2023.5

Those letters read as investigation failures, and they are. But a months-long trend does not go unnoticed at a site where the data is clean, structured, and reviewed against the right limit every week. It goes unnoticed where the data is spread across worksheets, where the location code changed mid-year, and where the chart someone finally builds in August is the first time anyone has seen the whole series in one place. The mechanics of missing a trend usually start with data that could not be trended.

83 CFU Recovered from an operator’s neck in an ISO 7 area with no deviation investigation opened, per a May 2026 FDA warning letter4
14 of 47 Microbial recoveries from ISO 5 cleaning use points that exceeded the action limit over 27 months, per a March 2026 FDA warning letter5
59.7% Mean difference from manual counts for fully automatic colony counting in a 640-plate study, falling to 1.8% with visual correction6

Six Data Quality Failures Behind a Broken EM Trend

The six failures below show up in some combination at nearly every site that runs EM on paper, on Excel, or on a LIMS that was configured years ago and never revisited. They are listed roughly in the order in which they should be fixed, because the first two determine whether the others can be fixed at all.

1. Sampling-location master data drift

Every EM result is attached to a location. Annex 1 paragraph 9.4 requires the sampling locations, along with frequency, methods, and incubation conditions, to be established through a risk assessment that is reviewed regularly, and paragraph 9.7 requires the selection of monitoring locations and the orientation and positioning of sampling devices to be justified.1 FDA’s 2004 guidance says all EM locations should be described in SOPs with enough detail to allow reproducible sampling of a given location.2 So the location list exists. The trouble is that it usually exists in several places at once: as an attachment to the EM SOP, as a drawing with numbered points, as a list in the LIMS or the scheduling spreadsheet, and as whatever the sampler writes on the plate.

Those copies diverge. The common triggers are a renovation that renames rooms or moves a wall, a line upgrade that adds new equipment surfaces and removes old ones, a change in the risk assessment that retires a point, and a facility expansion that reuses a numbering scheme from another building. After each of these, one of three things happens to the identifier. The old ID keeps being used for a point that has physically moved, so the trend mixes two places under one name. A new ID is assigned to a point that did not move, so the trend for one place is split across two names and a real shift is diluted below the alert level. Or a retired ID is reused for a new point in a different grade, so results from a Grade C corridor are compared against Grade B history.

None of these is visible in a monthly report. The chart still draws. It just draws the wrong thing.

2. Inconsistent sampling-point identifiers between the EM plan, the LIMS, and the plate labels

Closely related, but distinct, is the case where the location has not changed at all and the identifiers still do not match. The EM plan calls a point “Filling Room 2, Point 7.” The LIMS calls it “FR2-SP07.” The schedule calls it “F2/7.” The plate label, handwritten at 05:40 by a gowned operator, says “F2 7” or sometimes “Fill 2 #7.” Personnel monitoring adds a second dimension: the plan refers to operators by role, the LIMS by employee number, the gown-exit log by name, and the plate by initials.

The mapping between these forms lives in the heads of the two or three people who have done the job longest. It works until one of them leaves, until a new operator joins with the same initials, or until someone tries to query the LIMS by location and gets half the results because the other half were entered under a variant. The FDA guidance expects trend reports by location, shift, room, and operator.2 A report by operator is only possible if the operator is recorded the same way every time.

3. Manual transcription of plate counts

The typical read workflow is: pull the plate from the incubator, count colonies at the bench, write the count on a worksheet, and later key the worksheet into the LIMS or a spreadsheet. FDA’s data integrity guidance addresses this directly. In its answer on retaining paper records from laboratory instruments, it notes that in microbiology a contemporaneous written record is maintained of the colony counts of a petri dish and the record is then subject to second-person review.7 The same guidance states that it is not acceptable to record data on pieces of paper that will be discarded after the data are transcribed to a permanent record, and that blank forms should be controlled, issued in numbered sets where appropriate, and reconciled on completion.7 PIC/S PI 041-1 devotes its entire section 8 to paper-based systems, covering control of blank templates, filling out records, making corrections, and secondary verification.8

Transcription introduces specific, recurring errors. A blank cell is later read as zero. A “TNTC” (too numerous to count) becomes a number, or a number becomes “TNTC.” A mold colony the reader mentioned aloud never makes it onto the worksheet because there was no field for it. Two adjacent rows are transposed. A result from a plate that was invalidated for a cracked lid is entered anyway. Recent Form 483 observations have focused on the qualification of the people reading plates, the procedures for handling plates during reads, and the qualification of counting instruments.9 Every one of these errors is a data point in the trend, and because EM data in a controlled area is mostly zeros, a single wrong non-zero value can move a contamination recovery rate noticeably.

4. Alert and action limits held in spreadsheets that diverge from the SOP

Annex 1 sets maximum action limits in its Table 6 and requires alert levels to be established from cleanroom qualification data and periodically reviewed against ongoing trend data; tighter action limits may be applied based on trending, the nature of the process, or the contamination control strategy.1 FDA’s guidance says levels should be based on the relationship of the sampled location to the operation and informed by historical data, media fills, qualification, and sanitization studies.2 PDA Technical Report 13 (Revised 2022) describes several statistical approaches to setting them, including nonparametric, nonparametric tolerance limit, and cutoff value methods.10

All of that means limits change. They change at requalification, after an annual trend review, when a point is reclassified, and when the CCS is updated. The SOP appendix gets revised through document control. The spreadsheet that colors cells red, or the LIMS specification record, does not always get revised with it. At some sites the spreadsheet carries a single site-wide alert level while the SOP carries per-location values. At others the spreadsheet is newer than the SOP because someone tightened a level after a review and never raised the document change.

The consequence runs both ways. Results get flagged as excursions against a limit that is no longer in force, generating deviations that are later closed as “no impact” and teaching everyone to ignore flags. Or, worse, results that should have been flagged are not, because the working tool still carries a looser limit. FDA’s guidance also warns that each individual sample result should be evaluated against the alert or action level and that “Averaging of results can mask unacceptable localized conditions.”2 A spreadsheet that reports weekly averages against a monthly limit fails that test even when the limit value is correct.

5. Incubation and read-time data that never gets captured

Annex 1 paragraph 9.4 names incubation conditions (time, temperature, aerobic or anaerobic) as part of the risk-assessed EM program.1 FDA’s guidance describes typical incubation of 30 to 35 degrees Celsius for 48 to 72 hours for total aerobic count and 20 to 25 degrees for 5 to 7 days for yeast and mold, and states that consistent methods yield a database that allows sound comparisons.2 PDA TR 13 includes dedicated sections on sample holding studies and transport and on incubation strategy and validation.10 The method, in other words, has a defined window, and the result only means something if the plate was read inside it.

Yet the typical EM record holds a sample date and a count. It does not hold the time the plate went into the incubator, which incubator, the time it came out, which temperature regime it followed, or when and by whom it was read. Without those fields, a count read at 40 hours and a count read at 96 hours are treated as equivalent. A plate that waited 30 hours on a bench before incubation looks the same as one that went straight in. Variation that comes from the method masquerades as variation in the environment, and the trend absorbs noise it cannot explain.

FDA’s data integrity guidance defines metadata as the contextual information required to understand data, gives a date and time stamp, user ID, and instrument ID as examples, and says data should be maintained with all metadata required to reconstruct the activity.7 MHRA’s guidance defines raw data as the original record and first capture of information, and says it must permit full reconstruction of the activities.11 An EM count without its incubation and read metadata does not permit reconstruction. It is a number with the context stripped away.

6. No link between an EM result and the batch in the room

This is the failure with the most direct regulatory exposure. Annex 1 paragraph 9.13 requires that when action limits are exceeded, the procedure prescribe a root cause investigation and an assessment of potential impact to product, including batches produced between the monitoring and the reporting of the result.1 Paragraph 10.10 requires EM and trend data to be reviewed as part of batch certification.1 FDA’s guidance opens its EM section by noting that the program provides information on the quality of the aseptic processing environment when a given batch is being manufactured.2

In practice, the link between a result and a batch is made by a person. The microbiologist sees an excursion at “FR2-SP07” on a Tuesday, walks to the production office, looks at the room log or the batch record, and works out which lot was filling at the time. That works for one excursion. It does not work for a retrospective review of every batch exposed to a five-month mold trend, and it does not work when the EM record carries the room name and a date while the batch record carries a line number and a shift. The join is manual, error-prone, and, critically, invisible to anyone reviewing the trend. The May 2026 warning letter notes that the firm rejected batches in response to significant EM deviations.4 Whether a site can identify which batches to assess, and prove it, depends entirely on whether that link exists in the data.

The common thread. Five of the six failures are failures of master data and metadata, not of measurement. The plate count is usually right. What is wrong is the location it is attached to, the identifier it is stored under, the limit it is judged against, the incubation context that was never recorded, and the batch it was never linked to. That is why buying an EM system without first fixing master data produces an expensive copy of the same problem.

What Annex 1 and FDA Actually Expect of EM Data

It helps to separate what the regulatory documents require from what vendors and consultants say they require. The requirements below come from the documents themselves.

EU GMP Annex 1 (2022)

Section 9 of the revised Annex 1 treats the EM program as part of the contamination control strategy and states that the reliability of each monitoring element taken alone is limited; the results confirm the state of control only when considered together.1 On data and trending specifically, it requires the following. The program must be established and documented, with locations, frequency, methods, and incubation conditions justified by a risk assessment that is reviewed regularly (9.4). Alert levels and action limits must be set for viable and total particle results, with alert levels based on qualification data and periodically reviewed against ongoing trend data (9.9). Alert levels must be set so that adverse trends are detected and addressed (9.10). Monitoring procedures must define the approach to trending, and trends must include at least increasing numbers of excursions, consecutive alert-level excursions, regular but isolated action-limit excursions that may share a common cause, and changes in microbial flora type, numbers, and predominance (9.11). Action-limit excursions require a root cause investigation and product impact assessment covering batches produced between monitoring and reporting (9.13). Rapid and automated methods may be adopted after validation shows equivalence or superiority to established methods (9.28), and EM and trend data must be reviewed as part of batch certification (10.10).1

FDA aseptic processing guidance (2004) and compliance program 7356.002A

FDA’s guidance calls the EM program one of the most important laboratory controls in aseptic processing. It expects a written program with a list of locations, sample timing and frequency chosen for their relationship to the operation, and SOPs that describe each location in enough detail for reproducible sampling and that specify sampling frequency, timing, duration, sample size, equipment, alert and action levels, and responses. It expects levels informed by historical data, individual evaluation of every result, written procedures for data review frequency, quality unit oversight of near-term and long-term trends, trend reports by location, shift, room, and operator, specialized reports such as a search on a particular isolate over a year, and a defined system for keeping responsible managers informed of trends. It also notes that because false negatives occur, an increased incidence of contamination over a period is an equal or more significant trend than consecutive growth results.2

Compliance program 7356.002A translates this into what investigators look for. The Facilities and Equipment system coverage includes trending data supporting the adequacy of cleanroom quality; the Laboratory system coverage includes the systems used for recovery, identification, and trending of EM isolates; and the Quality system coverage lists EM and personnel monitoring results that exceed alert or action levels among the discrepancy investigations to review, and EM and personnel monitoring trend data among the trend reports and summaries to review during every inspection.3

Data integrity guidance that applies to EM records

None of the EM-specific documents tell a site what system to use. What they require is that the records, whatever their form, meet data integrity expectations. PIC/S PI 041-1 states that its principles apply equally to paper-based, computerized, and hybrid systems, and describes the data lifecycle as including transfers between paper and computerized systems.8 MHRA’s guidance addresses hybrid systems directly: where they are used, it should be clearly documented what constitutes the whole data set, and all records defined by that data set should be reviewed and retained.11 It also classifies data captured by photograph or imagery as its own category with the same lifecycle storage requirements, which becomes relevant for plate images later in this article.11 PDA Technical Report 80 provides a framework for a data integrity management system across paper, hybrid, and computerized laboratory systems, including microbiology.12

ExpectationEU GMP Annex 1 (2022)FDA guidance and inspection programData integrity guidance
EM data feeds batch release9.3 and 10.10: monitoring information used for batch certification; EM and trend data reviewed as part of release2004 guidance: EM informs quality of the environment when a batch is madePIC/S 041: data lifecycle includes use for decision-making
Trending approach defined9.11: procedures define trending; four minimum trend typesQC unit oversees near- and long-term trends; reports by location, shift, room, operatorMHRA: raw data must permit full reconstruction
Limits reviewed against data9.9: alert levels from qualification, reviewed against trend dataLevels informed by historical data; each result evaluated individuallyPIC/S 041 section 8: controlled templates and records
Locations justified and documented9.4 and 9.7: risk-assessed, justified, reviewedSOPs describe each location for reproducible samplingFDA Q&A: metadata needed to reconstruct the activity
Incubation conditions defined9.4: time, temperature, aerobic or anaerobic in the risk assessmentTypical conditions stated; consistent methods build a comparable databaseFDA Q&A: time stamps and instrument IDs as metadata
Contemporaneous count with reviewGeneral GMP documentation requirementsFDA Q&A: contemporaneous colony count record with second-person review; no discardable paperPIC/S 041 8.8: secondary checks on records
Rapid and automated methods9.28 and 10.11: after validation of equivalence or superiority2004 guidance: acceptable after demonstration of equivalenceMHRA: imagery is a record format with lifecycle requirements
A note on what the documents do not say. Neither Annex 1 nor FDA’s guidance requires an electronic EM system. Paper and spreadsheets are permitted. What is not permitted is a paper or spreadsheet record that cannot be reconstructed, cannot be attributed, cannot be shown to have been evaluated against the limit in force at the time, or cannot be tied to the batch it was meant to protect. Sites that treat “we are still on paper” as their compliance gap are usually solving the wrong problem. The gap is the data design, and it will follow them into any system they buy.

What a Usable Trend Program Needs

A usable EM trend program has four structural elements. They are listed in dependency order: each one relies on the ones before it.

ELEMENT 1

Location hierarchy as master data

One governed list of sampling points with immutable IDs, versioned attributes, effective dates, and change control. Every other record points to it.

ELEMENT 2

Structured result capture

Every result is a complete record: point, sample type, method, media lot, sampler, times, incubation, reader, count with controlled codes, verifier, and activity context.

ELEMENT 3

Limits under change control

Alert and action levels stored as versioned data with effective dates, per point and sample type, driving both the SOP appendix and the system flags from one source.

ELEMENT 4

Automated excursion linkage

An excursion automatically creates an event tied to the point, the batches in the room during the sampling window, the operator, and the preceding results.

Element 1: the location hierarchy as master data

The sampling-point list is master data in the same sense that a material master or an equipment register is master data: a governed reference that other records point to rather than copy. The hierarchy runs site, building, suite or area, room, and sampling point. Each point needs a unique identifier that never changes and is never reused, a human-readable name that can change, the cleanroom grade, the sample types taken there (settle plate, contact plate, active air, glove, gown), a physical description or coordinate precise enough to reproduce the sampling, the risk assessment reference that justifies it, an effective-from date, and, when retired, an effective-to date and the reason.

Two rules make this work. First, a physical change creates a new version of the point or a new point, never a silent edit. If a wall moves and the point moves with it, the point is retired and a new one created with a documented link to its predecessor, so the trend can be split deliberately rather than corrupted accidentally. If only the room name changes, the name attribute is versioned and the ID stays. Second, changes go through change control with the EM risk assessment updated at the same time, which is what Annex 1 paragraph 9.4 asks for in any case.1 The location master then becomes the single source that the SOP attachment, the sampling schedule, the LIMS, and the plate labels are all generated from, rather than four lists maintained by hand.

Element 2: structured result capture

A result record needs enough fields that any future reviewer can reconstruct what happened without asking anyone. At minimum: the point ID and version, the sample type and method, the media lot, the sampler’s identity, the sample start and end times, the incubation start time and incubator ID, the incubation regime, the read date and time, the reader’s identity, the count, the second-person verifier, and the activity context (which batch, which process step, or “at rest”). The count field deserves particular care. It should be numeric, with a separate controlled field for the non-numeric states that matter: no growth, too numerous to count, plate invalidated with a reason, and result pending identification. Storing “TNTC” as text in a numeric column, or storing a blank to mean zero, are the two most common ways an EM series becomes uncomputable.

Where plates are labeled with a barcode generated from the location master and the schedule, several failure modes disappear at once: the identifier on the plate matches the system by construction, the sample time can be captured by scan, and the read can be recorded against the right record without transcription. Where barcoding is not yet in place, the same discipline can be enforced on a controlled paper worksheet with pre-printed point IDs from the master, which is the approach described in the next section.

Element 3: limits under change control

Alert and action levels should be stored as data, not as cell formatting. Each limit record carries the point ID (or a group of points), the sample type, the alert value, the action value, the basis (qualification data, annual trend review, Annex 1 Table 6 maximum), the approver, and effective-from and effective-to dates. Two consequences follow. The SOP appendix is generated from the limit table rather than maintained separately, so they cannot diverge. And historical results are always evaluated against the limit that was in force on the sample date, which is the only defensible answer when an inspector asks why a result from eighteen months ago was not flagged.

This also makes the periodic review that Annex 1 paragraph 9.9 requires a data operation rather than a document exercise.1 The review reads the trend, proposes new levels, and, once approved, adds a new limit version with a new effective date. The old version stays, with its own dates, for as long as the results it governed are retained.

Element 4: automated excursion linkage

When a result exceeds its limit, the system should create the event, not a person. The event record links to the result, the point, the limit version that was exceeded, the sampler and reader, and, through the activity context captured in Element 2 or a join against the batch record’s room and time, the batches present in the room during the sampling window. Annex 1 paragraph 9.13 requires the impact assessment to cover batches produced between monitoring and reporting, which for a five-day yeast and mold incubation can be several lots.1 The linkage also pulls the preceding results for the same point and the same operator, so the investigator sees the trend context immediately rather than reconstructing it.

The statistics only work on a consistent series

A great deal has been written about how to trend EM data that is mostly zeros. USP General Chapter 1116 introduced contamination recovery rates, the percentage of samples with any recovery over a period, as an alternative to averaging colony counts in environments where most plates show nothing.13 Caputo and Huffman, writing in the PDA Journal in 2004, proposed monitoring the frequency between non-zero recoveries as an event rather than the count itself, because traditional control charts are inappropriate when recovery is generally zero.14 Yang and colleagues in 2013 proposed setting alert and action limits from a zero-inflated model.15 Gordon and colleagues in 2015 compared different calculation approaches for defining microbiological control levels from historical data.16 PDA TR 13 describes nonparametric, tolerance-limit, and cutoff approaches, along with quantitative and qualitative trending rules.10 Practitioner guidance commonly treats three or more consecutive points at or above the alert level, or a drift, as a trend that warrants investigation.17

Every one of these methods assumes that the series it is applied to is consistent: that each point in the series comes from the same physical location, was read inside the same incubation window, and is being compared against the same or a deliberately versioned limit. Apply a zero-inflated model to a series that mixes two locations under one ID and the model will produce a number. It will be wrong. The four elements above are not a substitute for good statistics. They are the precondition for good statistics to mean anything.

The test of a usable program. A quality director should be able to ask, at any time, for the twelve-month series at any single point, the limit in force on each sample date, and the list of batches exposed to every excursion, and get all three within the hour from a single query without anyone reconciling anything by hand. If that is not true, the trend program is not yet usable, regardless of what system it runs on.

A Realistic Path for a Site Running EM on Paper and Excel

Most sites in this position have been told the answer is a LIMS EM module or a dedicated EM system, and most have been told the price. The honest sequence starts before any purchase, because the first three steps are prerequisites for the purchase to succeed and they require no software at all. ISPE’s GAMP Good Practice Guide on Data Integrity by Design makes the general point that data integrity has to be built in from the initial planning of a business process, not added to a system afterward.18 For EM, that means fixing the data design first.

1

Freeze and reconcile the location master

Walk the floor with the EM plan, the LIMS or schedule list, and a stack of recent plate labels. Produce one list. Assign every point an immutable ID, map every historical variant to it, retire duplicates with dated records, and document which historical IDs cannot be mapped with confidence. Put the list under change control and tie it to the EM risk assessment. This is the single highest-value step and it is entirely a paper exercise.

2

Redesign the paper worksheet to capture the whole record

Issue a controlled, reconciled worksheet with the point IDs pre-printed from the master and fields for every attribute in Element 2: media lot, sampler, sample times, incubation start and incubator, read time and reader, count with a separate code box for no growth, TNTC, and invalidated, verifier, and activity context including batch number. Controlled and reconciled blank forms are what FDA’s data integrity guidance asks for.7 Nothing is written on a loose sheet to be copied later.

3

Bring the spreadsheet under control, or replace it with a small database

Reduce to one workbook with a locked structure: a results table keyed to the point ID, a limits table with effective dates, and validated formulas that evaluate each result against the limit in force on its sample date. Use data validation lists for codes. Put the workbook under change control with a validation record, restricted access, and a defined review. Where IT can support it, a simple database with the same three tables is more defensible than a spreadsheet and is a better staging ground for later migration.

4

Backfill and qualify the historical series

Load historical results against the reconciled master, evaluated against the limit versions in force at the time. Flag every result that could not be mapped or that lacks incubation metadata, and document the decision on how to treat it (include with a caveat, exclude with a reason). The output is a trend series whose provenance is written down, which is more than most sites can say today.

5

Select and implement a system with the data design as the requirement

Only now write the user requirements for an EM system or LIMS module, and write them around the location master, the result record, the limit versioning, and the excursion linkage already in use. Migration then moves a clean, mapped series rather than four years of unreconciled worksheets. Vendor demonstrations should be run against the site’s own location master and a sample of its own historical data.

The order matters. Sites that start at step 5 spend the implementation reconciling locations under time pressure, discover that the spreadsheet limits and the SOP limits disagree during data migration, and end up with a validated system holding an unvalidated series. Sites that start at step 1 arrive at step 5 with a short, specific requirements list and a migration that can be tested.

Data Quality Audit Checklist for an EM Program

The checklist below is designed for an internal audit, a supplier or CMO audit, or a pre-inspection readiness review. It is organized by the four elements plus the review process, and each item names the evidence to ask for rather than the question to ask, because the evidence is what distinguishes a program that works from one that is described as working.

AreaCheckEvidence to request
Location master dataOne authoritative list of sampling points exists and every other list is generated from itThe master list; the SOP attachment; the LIMS or schedule export; a comparison showing they match
Every point has an immutable, never-reused ID and a versioned namePoint records with IDs, effective dates, and change history
Renovations and layout changes created new versions or new points, not silent editsChange controls for the last two facility modifications and the corresponding master data changes
Retired points are dated and their history preservedList of retired points with effective-to dates and reasons
The location master is tied to the EM risk assessment required by Annex 1 9.4The risk assessment, its review dates, and cross-references to point IDs
IdentifiersPlate labels carry the master point ID (barcode or pre-printed)A sample of recent plates or labels; the label generation source
Operators are identified consistently across schedule, gown-exit log, and resultsPersonnel monitoring results for one month queried by operator
A query by location returns all results for that locationLive query for one point over twelve months compared against the paper or schedule record count
Historical identifier variants are mapped and the mapping is documentedThe mapping table and the record of unmappable results
Result captureCounts are recorded contemporaneously at the read, not transcribed from loose paperObservation of a plate read; the worksheet or system entry with time stamps
Blank worksheets are controlled, issued, and reconciledIssue log and reconciliation for the last month of worksheets
Non-numeric states (no growth, TNTC, invalidated) use controlled codes, not free text or blanksData dictionary; a sample of records containing each state
Every result carries sampler, media lot, sample times, incubation start, incubator, read time, and readerTen randomly selected records with all fields populated
Second-person verification of counts is recorded and reviewers are trained on plate readingVerifier field on records; training and qualification records for readers
LimitsAlert and action levels are stored as versioned data with effective datesThe limits table with history
The SOP appendix and the working tool carry identical limitsSide-by-side comparison for every point, both current and at a date twelve months ago
Each result is evaluated individually against the limit in force on its sample dateEvaluation logic (formula or configuration) and a test case using a historical result
The periodic limit review required by Annex 1 9.9 is performed and produces dated limit versionsLast two review reports and the resulting limit changes
Batch linkageEvery result carries activity context (batch, step, or at rest)Ten in-operation results with batch numbers populated
Excursions automatically identify the batches exposed during the sampling and incubation windowThe last three excursion records and their batch lists; how the list was produced
EM and trend data are reviewed at batch certification and the review is recordedBatch certification checklist or record showing the EM review and the data reviewed
Trending and reviewThe trending approach is defined in a procedure and covers the four Annex 1 9.11 trend typesThe procedure; the last quarterly trend report
Trend reports can be produced by location, shift, room, and operatorA report of each type for the same period
Contamination recovery rates or an equivalent zero-appropriate method are usedThe calculation method and its justification
Responsible managers are informed of trends on a defined scheduleDistribution record for the last two trend reports
How to use the checklist. Run the “live query” items first. If a query by location or by operator cannot be produced within the hour, most of the other items will fail for the same underlying reason, and the audit report should say so rather than listing thirty separate findings that share one root cause.

Automated EM Systems and Rapid Methods: The Data Quality View

Automation is often presented as the solution to everything above. It solves some of it. It also creates new data quality questions, and this section stays with those questions rather than the technology itself.

Automated plate readers and colony counters

An automated plate reader captures an image of each plate and uses software to identify and count colonies, producing a digital workflow in place of a bench count and a worksheet.9 Two data quality points follow. First, the image becomes a record. MHRA’s guidance treats data captured by photograph or imagery as its own format, subject to the same lifecycle storage considerations as any other raw data.11 The site needs a retention, backup, and retrieval plan for plate images that matches the retention of the results derived from them, and the image must be linked to the result record, not stored in a folder named by date.

Second, the automatic count is not automatically right. A 2023 peer-reviewed evaluation of a commercial colony counting imaging station, across 640 agar plates of bacteria and yeast, found a mean difference from manual counts of 59.7 percent for bacteria and 71.4 percent for Candida albicans when the instrument ran fully automatically, falling to 1.8 percent and 2.8 percent after an operator visually corrected the results on screen. Fully automatic counting tended to overestimate at low colony densities and underestimate at high densities, and the instrument sometimes counted scratches, air bubbles, and light reflections.6 That study was performed in a clinical microbiology setting rather than on EM plates, and instruments differ, but the data design lesson is general: the corrected count is a human decision layered on a machine output, and both values, the identity of the person who corrected, and the reason must be retained in the audit trail. A system that overwrites the automatic count with the corrected one has discarded raw data.

Continuous and automated monitoring

Annex 1 requires continuous particle monitoring in Grade A for the full duration of critical processing, with each sample result correlated against alert levels and action limits frequently enough that an excursion can be identified and acted on in time, and with alarms when alert levels are exceeded; it recommends a similar system for Grade B.1 The data volume changes character: from a few discrete results per shift to a continuous time series per sampling location. Trending now means analyzing alarm frequency, duration, and clustering against interventions, which means the alarm record, the intervention log, and the batch record all need a common time base and a common location reference. The location master from Element 1 is exactly as necessary for a particle counter probe as it is for a settle plate, and a probe that is moved during a line change without a master data update produces the same corrupted trend.

Rapid microbiological methods

Annex 1 encourages manufacturers to consider rapid and automated monitoring methods to speed detection of contamination, permits them once validation shows equivalence or superiority to established methods (9.28), requires validation for the products or processes concerned where they are used for general manufacturing (10.11), and specifically suggests them for products with short shelf lives where conventional EM data may not be available at release (10.10).1 FDA’s 2004 guidance accepts rapid methods for EM after they are shown to be equivalent or better than traditional methods.2 On the compendial side, the European Pharmacopoeia Commission adopted a revised general chapter 5.1.6 on alternative methods for control of microbiological quality in March 2026; it was published in July 2026 with an implementation date of April 1, 2027, and updates the described technologies, clarifies supplier and user responsibilities, and introduces risk-based validation strategies.19 PDA TR 13 devotes a section to rapid methods in EM, including their scientific principles, benefits, and validation.10

The data quality implication that gets the least attention is the break in the series. Many rapid methods do not report colony forming units. They report fluorescence signal, auto-fluorescent particle counts, or a growth-based readout on a different time scale. The historical CFU series and the new series are different measurements of the same environment, and they are not directly comparable. Alert and action levels have to be re-derived from data generated by the new method during a parallel-running period; the point at which the series changes has to be documented as a deliberate discontinuity; and any trend review that spans the change has to say which method produced which points. A site that migrates to a rapid method without planning for this will find, a year later, that its twelve-month trend is uninterpretable for a reason that has nothing to do with the environment. The argument that rapid and automated methods reduce manual entry and transcription risk in microbiology laboratories is sound,20 but it applies to the capture step only. Everything upstream (location master, limits) and downstream (batch linkage, review) remains the site’s responsibility.

Automation moves the data quality problem. It does not remove it. An automated reader with an unreconciled location master produces beautifully imaged results attached to the wrong points. A continuous monitoring system with limits configured from an outdated spreadsheet generates alarms against the wrong thresholds. A rapid method introduced without a documented series break produces a trend nobody can read. Instrument configuration is master data too, and it needs the same change control.

Conclusion

The sites that struggle with EM trending are rarely the ones that skip samples. They are the ones that have collected everything and cannot assemble it, because the location list has drifted, the identifiers do not match, the counts were transcribed, the limits in the spreadsheet stopped matching the SOP, the incubation context was never captured, and the batch was never linked. The regulatory documents are unambiguous about what is expected: Annex 1 makes EM and trend data a batch certification input and defines the minimum trend types, FDA’s guidance expects quality unit oversight of trends by location, shift, room, and operator, and FDA’s inspection program tells investigators to review the trend reports every time. The 2026 warning letters show what happens when a months-long trend goes unseen. The fix is not primarily technological. It is a location hierarchy managed as master data, a complete result record, limits under change control, and an excursion that links itself to the batches it affects. Those four things can be started on paper, and they are the requirements that any later system should be bought against.

Sakara Digital works with pharma and biotech organizations building this kind of data foundation for their quality and laboratory records, from the master data reconciliation through to system requirements and migration. If you are looking at your own EM program and want an independent perspective on where to start, we are happy to have that conversation.

For Further Reading