In This Article
- Executive Summary
- The Metadata Nobody Owns
- What Documentation Control Actually Requires
- Pilot One: SOP Metadata Standardization
- Pilot Two: The Document Owner Audit
- Pilot Three: Master Batch Record Naming Across Sites
- Pilot Four: Quality Agreement Metadata
- The Metadata Quality Scorecard
- Holding the Gains After the Pilot Ends
- Conclusion
- For Further Reading
- References & Sources
Executive Summary
Every pharmaceutical and biotech company runs a document management system, and almost every one of them carries metadata that is wrong in ways nobody has written down. Document types multiply because the field is free text. Owners point at people who left three years ago. Effective dates in the system disagree with the approval records behind them. The same master batch record has a different name at each site. Quality agreements are filed under a supplier’s trading name with no indication of which products, activities, or versions they govern. None of this shows up as a finding until an inspector asks a question that requires the system to answer it.
The argument of this article is that document metadata is a data quality problem, not a documentation problem, and that it responds to the same treatment: a small, scoped pilot with a measure before and a measure after. This is part of Sakara Digital’s Data Quality Quick Wins series, whose premise is that a company does not need a five-year governance program to earn leadership’s confidence. It needs three or four visible wins that took a month each and produced a number a director can repeat.
What follows are four pilots, each scoped to two to four weeks: standardizing SOP metadata against a document type taxonomy and a controlled vocabulary, auditing document owners to drive the orphan rate down, imposing a naming convention on master batch records across sites and versions, and giving quality agreements the metadata that connects them to suppliers, products, and review dates. Each pilot is grounded in what regulators already require of documentation control under 21 CFR Part 211, EU GMP Chapter 4 and its PIC/S equivalent, ICH Q7, and ICH Q10. The article closes with a metadata quality scorecard, a sample controlled vocabulary, and the part most pilots skip: how to hold the gains after the project team goes back to its day job.
The Metadata Nobody Owns
Ask a quality director how many controlled documents the company has and you will usually get a number. Ask how many of those documents have a current, named owner who still works there, and the conversation changes. The number is knowable, the system will produce it in an afternoon, and almost nobody has looked.
This is the shape of the problem. Document management systems in life sciences are built around content control: version, approval, effective date, training assignment, withdrawal. That machinery works. What surrounds the content is a set of descriptive fields that tell you what a document is, who is responsible for it, what part of the business it belongs to, which product or site or supplier it applies to, and when it should next be looked at. Those fields are metadata, and in most companies they are the only part of the document system that no function owns end to end.
How the fields degrade
Metadata rarely fails all at once. It degrades through a set of ordinary events, none of which looks like a quality problem at the time.
- Migration. A company moves from one document system to another and maps the old fields to the new ones as best it can. Values that had no home in the new model get dropped into a free-text field. The migration validation checks that documents arrived, not that their descriptions still mean anything.
- Free text where a picklist belonged. A “document type” field that accepts typing will, over ten years, accumulate SOP, S.O.P., Standard Operating Procedure, Std Operating Proc, and Procedure as five separate types. Every report that groups by type is now wrong.
- Local convention. Two sites join the same system through an acquisition, each carrying its own naming pattern for batch records and its own idea of what a “process area” is. Neither is asked to change, because changing looks like a project.
- People leaving. The owner field is populated with a person, not a role. When that person leaves, nothing in the system notices. The document keeps its owner. The owner keeps their name on a hundred documents nobody will review.
- Placeholder values that became permanent. A field made mandatory mid-life gets backfilled with “TBD” or “N/A” for the existing population so the system will accept the records. The backfill was supposed to be temporary.
The symptoms show up somewhere other than the document system. Periodic review lists are wrong, so documents past their review date are missed while current ones are reviewed twice. Training assignments miss a group because their process area was spelled differently. An inspection request for “all procedures governing aseptic gowning at this site” takes two days and three people to assemble, and the assembly is done by memory rather than by query. A supplier audit turns up a quality agreement that nobody can match to the products the supplier actually makes.
The moment metadata becomes a compliance question. 21 CFR 211.180(c) requires that records be readily available for authorized inspection during the retention period at the establishment where the activities occurred, with records retrievable by electronic means from another location treated as meeting the requirement.1 ICH Q7 states the same expectation for API records: during the retention period, originals or copies should be readily available at the establishment, and records that can be promptly retrieved from another location are acceptable.8 Neither regulation uses the word metadata. Both of them describe an outcome that only good metadata delivers, because a document you cannot find is not readily available in any sense an inspector will accept.
Why this is a data quality problem
Treat the document register as a dataset and the diagnosis becomes routine. Each document is a record. Each field is an attribute with an expected domain of values. Completeness, validity against that domain, currency, internal consistency, and linkage to other records are all measurable in a query. The work is not new; it is the same profiling that a data team would run against a customer master or a materials master.
The research literature on metadata quality has been doing exactly this for two decades. Ochoa and Duval’s work on automatic evaluation of metadata quality in digital repositories defines completeness metrics that count populated fields per record and add a weighting factor so that a field of higher relevance carries more of the score, then tests those automated metrics against human review.14 That is the mechanism behind the scorecard later in this article: not every field matters equally, and a score that pretends they do will point remediation at the wrong place.
The FAIR guiding principles, published in Scientific Data in 2016, make the same point from the other direction. Findability depends on persistent unique identifiers and on data being described with rich metadata that is indexed in a searchable resource.13 FAIR was written for research data, not for a GMP document system, and it is not a regulatory expectation. It is a useful reminder that findability is a property you design and measure, not a property you hope for.
What Documentation Control Actually Requires
The regulations do not contain a chapter called metadata. They contain a set of requirements that cannot be met without it. Reading them that way is the useful move, because it converts a housekeeping project into a compliance argument that a quality council will fund.
The US requirements
21 CFR 211.100(a) requires written procedures for production and process control, and requires that those procedures be drafted, reviewed, and approved by the appropriate organizational units and reviewed and approved by the quality control unit.3 211.22(d) requires that the responsibilities and procedures applicable to the quality control unit be in writing and followed.4 Neither obligation can be demonstrated at scale unless the system can tell you, for a given procedure, who owns it and which organizational unit approved it.
21 CFR 211.186 is the strongest metadata requirement in Part 211, and it is not usually read that way. Master production and control records must be prepared for each drug product, including each batch size, and must be prepared, dated, and signed by one person and independently checked, dated, and signed by a second. The preparation of those records must itself be described in a written procedure, and that procedure must be followed. The content requirements begin with the name and strength of the product and a description of the dosage form.2 Product, strength, dosage form, and batch size are the exact fields a naming convention needs. The regulation put them there.
The European and PIC/S requirements
EU GMP Chapter 4 covers documentation, and the PIC/S Guide to Good Manufacturing Practice PE 009-17 Part I carries Chapter 4 with the same clause numbering.5 Chapter 4 is currently under revision alongside Annex 11 and the draft Annex 22, and that revision is analyzed in a separate article in this series. For present purposes the clauses that matter are the ones that have been in force for years.
- 4.1 requires that all types of document be defined and adhered to, with the requirement applying equally to all document media types. That is a document type taxonomy, stated as an obligation.
- 4.3 requires that documents containing instructions have unambiguous contents, be uniquely identifiable, and have a defined effective date. Unique identification and effective dating are metadata fields before they are anything else.
- 4.5 requires that documents within the quality management system be regularly reviewed and kept up to date. The PIC/S text adds that when a document has been revised, systems should be operated to prevent inadvertent use of superseded documents.5
- 4.10 requires that it be clearly defined which record relates to each manufacturing activity and where that record is located.
- 4.32 requires that an inventory of documents within the quality management system be maintained. That inventory is the dataset the four pilots below operate on.
For outsourced activities, EU GMP Chapter 7 requires a written contract that specifies the respective responsibilities and communication processes of the contract giver and contract acceptor, and requires that the contract clearly describe who undertakes each step of the outsourced activity, including knowledge management, technology transfer, supply chain, subcontracting, purchasing and testing of materials, and production and quality controls.6 A contract that describes all of that and is filed with a counterparty name and nothing else has satisfied the drafting requirement and defeated the retrieval one.
ICH Q7 and ICH Q10
ICH Q7 section 6 sets out the documentation system for active pharmaceutical ingredients. All documents related to manufacture should be prepared, reviewed, approved, and distributed according to written procedures, and the issuance, revision, superseding, and withdrawal of all documents should be controlled with maintenance of revision histories.8 Q7 6.41 requires master production instructions to carry the name of the intermediate or API being manufactured and an identifying document reference code where applicable. Q7 6.50 requires that a batch production record be checked before issuance to confirm it is the correct version and an accurate reproduction of the appropriate master production instruction, and that where the batch record comes from a separate part of the master document, that document reference the current master production instruction in use.8 Version control that depends on a person reading a title correctly is version control resting on metadata.
ICH Q10 supplies the management frame. Q10 treats knowledge management as an enabler of the pharmaceutical quality system, describing it as a systematic approach to acquiring, storing, and sharing information about products, manufacturing processes, and components across the product lifecycle.7 Q10 section 1.8 asks for a quality manual or equivalent documentation approach that describes the quality system, including identification of the quality system processes and their sequences, linkages, and interdependencies.7 A process taxonomy is implied in that sentence. Most companies wrote the quality manual and never connected its process list to the process area field in the document system, which is why the two disagree.
What inspection findings show
Public FDA warning letters do not cite metadata fields. They cite the consequences of not being able to produce, control, or trust documents, and the pattern is consistent.
In a March 2026 warning letter to a contract testing laboratory in Hyderabad, FDA described investigators finding torn analytical records, including chromatographic results, in garbage bags that the firm attempted to remove at the start of the inspection, and laboratory staff using unofficial personal diaries to record procedures, observations, results, method modifications, and deviation descriptions. FDA noted that the firm lacked procedures to control the use of those diaries.10 The finding is about uncontrolled documents: records that existed, mattered, and were outside the system that was supposed to know about them.
In an August 2026 warning letter to an API manufacturer in Tianjin, FDA cited failure to prepare master production and control records, describing batch records that lacked critical processing information, and noted that formal procedures had not been finalized because products were described as still in development.11 In a June 2026 warning letter to a manufacturer in Navi Mumbai, FDA cited quality unit failures around oversight of contract testing laboratories, referenced its quality agreements guidance, and repeated its standing position that a manufacturer is responsible for the quality of its drugs regardless of agreements in place with contract facilities.12
The through line. In each case the company had documents. What it did not have was a reliable, queryable statement of what those documents were, who was responsible for them, which version was current, and what they applied to. That is a metadata failure wearing a documentation failure’s clothes, and it is the failure the four pilots below are designed to measure.
Pilot One: SOP Metadata Standardization
Scope: one site or one function, two to four weeks, no change to the content of a single SOP.
The first pilot is the one to run first, because it produces the vocabulary the other three depend on. The goal is narrow: give the SOP population a defined set of document types, a controlled vocabulary for process area, and a completeness score that can be measured before and after.
The three artifacts
A document type taxonomy. Chapter 4.1 requires that all types of document be defined. Most companies have that definition somewhere in the document control SOP and a different, larger set of values in the system. The pilot reconciles the two. Keep the list short. Eight to fifteen types covers a GMP document population, and every type needs a one-line definition that says what belongs in it and, more usefully, what does not.
| Type code | Document type | Definition test | Typical review cycle |
|---|---|---|---|
| POL | Policy | States a commitment or principle. Contains no steps. | 3 years |
| SOP | Standard operating procedure | Describes a repeatable activity in imperative steps. Cross-functional or function-wide. | 2 years |
| WI | Work instruction | Task-level detail subordinate to a named SOP. Single role, single location. | 2 years |
| MTH | Analytical method | Test procedure with acceptance criteria for a named material or product. | Per validation status |
| SPEC | Specification | Requirements a material, intermediate, or product must meet. | Per product review |
| MBR | Master batch record | Master production and control record for one product, strength, and batch size. | Per change control |
| FRM | Form or template | Blank structure issued to capture a record. Has no standalone instructions. | With parent document |
| PLN | Plan | Time-bounded approach to a defined piece of work. Expires on completion. | On closure |
| RPT | Report | Documents the conduct and outcome of an exercise, project, or investigation. | None. Retained. |
| QAG | Quality agreement | Written agreement allocating GMP responsibilities with an external party. | 2 years or on change |
A controlled vocabulary for process area. This is the field that decides whether a search returns the right twelve documents or the wrong four hundred. Build it from the quality system process list in the quality manual, which ICH Q10 already asks you to maintain,7 rather than from the organization chart. Organization charts change every two years. Processes do not.
| Level 1 process area | Level 2 examples | Common wrong values to retire |
|---|---|---|
| Manufacturing | Dispensing; Compounding; Filling; Packaging; Line clearance | Production, Ops, Plant, Mfg, Shop floor |
| Quality control | Sampling; Chemical testing; Microbiology; Stability; Reference standards | Lab, QC Lab, Analytical, Micro |
| Quality assurance | Deviation management; CAPA; Change control; Batch release; Complaints | QA, Compliance, Quality |
| Validation and qualification | Process validation; Cleaning validation; Equipment qualification; Computer system validation | Val, CSV, Quals, Engineering |
| Materials management | Receipt and quarantine; Storage; Dispensing control; Distribution | Warehouse, Logistics, Supply chain |
| Facilities and utilities | Environmental monitoring; Water systems; HVAC; Cleaning and sanitization | Facilities, EM, Utilities, Maintenance |
| External manufacture | Supplier qualification; Contract manufacture; Contract testing; Technical transfer | CMO, Outsourcing, Vendors, Third party |
| Quality system governance | Document control; Training; Internal audit; Management review; Product quality review | Admin, Docs, QMS, General |
The right-hand column matters more than it looks. A controlled vocabulary succeeds or fails on the mapping from the values people actually typed to the values you intend to keep. Write that mapping down as a lookup table during the pilot, because you will need it again when the next system migration happens.
Clinical operations has a working example of this discipline that manufacturing teams rarely look at. The TMF Reference Model, a community effort now part of CDISC, organizes trial master file content into zones, sections, and artifacts with defined sub-artifacts, so that hundreds of sponsors, CROs, and technology vendors can describe the same document the same way.15 Nothing about that idea is specific to clinical trials. It is a shared taxonomy with definitions, and it works because the definitions are written down and the values are constrained.
A metadata completeness score. The third artifact is the measure. Pick six to nine fields, weight them, and score each document. The scorecard section below sets out the method.
Running the four weeks
Week one: extract and profile
Pull the full document register for the pilot scope: identifier, title, type, owner, process area, site, status, effective date, next review date, related documents. Profile it the way you would profile any dataset. Count distinct values per field. Rank them by frequency. The tail of a free-text field is where the story is, and a single afternoon usually produces the slide that funds the rest of the work.
Week two: draft the taxonomy and the vocabulary
Two working sessions of ninety minutes with a document control lead, a QA representative, and one person from each major process area. Draft the type list with definitions, draft the process area list, and build the mapping table from observed values to target values. Resist the request to add a type for every edge case. Edge cases go in a note field, not in the taxonomy.
Week three: remediate in bulk, by rule
Apply the mapping. Anything the mapping resolves unambiguously is a bulk metadata update under the document control procedure. Anything ambiguous goes to a named person for a decision, and the decision is recorded in the mapping table so the same question is never asked twice. Metadata correction on an approved document is a controlled change: agree the route with QA in week two, not week three.
Week four: measure, constrain, hand over
Rerun the profile. Report the before and after. Then do the part that makes the pilot permanent: turn the type and process area fields into constrained picklists in the system so the free-text values cannot come back, and update the document control SOP to reference the taxonomy as the controlled list.
Before and after measures for Pilot One
- Distinct values in the document type field (target: equal to the taxonomy, no more)
- Distinct values in the process area field (same target)
- Percentage of documents with a valid type and a valid process area
- Weighted metadata completeness score, mean and tenth percentile
- Number of documents where the system effective date disagrees with the approval record date
- Time to assemble a defined document set for a mock inspection request, measured with a stopwatch before and after
What this pilot is not. It is not an SOP rewrite, an SOP consolidation, or a review of whether procedures reflect practice. Those are worthwhile and they are also six-month efforts with a different sponsor. Mixing them into a metadata pilot is the most reliable way to make a four-week piece of work take a year and deliver nothing measurable in the meantime.
Pilot Two: The Document Owner Audit
Scope: the full controlled document population at one site, two to three weeks.
The second pilot answers one question: does every controlled document have a current, named owner who is still employed and still in a role that makes sense for that document? The measure is the orphan rate, and it is the single most quotable number in this article, because everybody understands it and nobody has it.
Defining an orphan precisely
The definition has to be written before the extract runs, or the result will be argued rather than acted on. Four categories are enough.
Empty owner
The owner field is blank, or contains a placeholder value such as TBD, N/A, or a dash. Usually the residue of a migration or of a field made mandatory after the fact.
Departed owner
The owner is a named person who no longer appears in the active employee roster. The most common category and the easiest to detect, because it is a join between two lists.
Unowned in practice
The owner is a department, a shared mailbox, a former job title, or a generic account. Formally populated, operationally nobody. This category is usually larger than people expect.
Mismatched owner
The owner is current and real but works in a function unrelated to the document’s process area. Often a sign that ownership moved with a reorganization and the field did not.
The method
Extract the register with the owner field, join it against the active employee roster from HR, and classify. The join is the whole technique. It takes an analyst a day, and it converts a subjective worry into a count. Then work the list in this order: departed owners first because they are unambiguous, empty owners second, generic owners third, mismatches last because they need judgment.
Reassignment should be made against a role, with a named incumbent recorded alongside it. A document owned by “Manager, Sterile Manufacturing” with the current incumbent named survives the next departure; a document owned only by a person does not. Where the system has one field, use a naming pattern that carries both. Where it has two, populate both and validate the incumbent against the roster on a schedule.
The regulatory case for this pilot is short and strong. Chapter 4.5 requires documents within the quality management system to be regularly reviewed and kept up to date.5 Review is an activity a person performs. 21 CFR 211.100(a) requires procedures to be drafted, reviewed, and approved by the appropriate organizational units and reviewed and approved by the quality control unit,3 and 211.22(d) requires the quality unit’s responsibilities and procedures to be in writing and followed.4 A document with no owner has no route to either.
The failure mode to avoid. The fastest way to drive the orphan rate to zero is to assign every unowned document to the QA director. It closes the metric, creates a review backlog that one person cannot clear, and moves the problem out of sight for eighteen months. Cap the number of documents any single role may own during the pilot, and treat the documents that nobody will accept as the real finding. Some of them turn out to be documents the company no longer needs, and retiring them under the document control procedure is a legitimate and welcome outcome.
Before and after measures for Pilot Two
- Orphan rate overall and by type (empty, departed, generic, mismatched)
- Orphan rate for documents in the highest-risk process areas, reported separately
- Number of documents past their next review date, split by whether they have a valid owner
- Number of distinct owners, and documents owned by the busiest ten owners (a concentration check)
- Number of documents retired during the pilot because no function claimed them
- Percentage of owner records expressed as a role plus a named incumbent rather than a bare name
Pilot Three: Master Batch Record Naming Across Sites
Scope: one product family across all sites that make it, or all master batch records at two sites, three to four weeks.
The third pilot is the one with the clearest regulatory anchor and the highest political difficulty, because naming conventions are where sites defend their local practice hardest. It helps to start from the point that the fields in question are not a preference. 21 CFR 211.186 requires master production and control records for each drug product including each batch size, and requires the record to state the name and strength of the product and a description of the dosage form.2 ICH Q7 6.41 asks for the name of the intermediate or API and an identifying document reference code.8 Chapter 4.3 asks that documents be uniquely identifiable with a defined effective date, and 4.17 requires the manufacturing formula to carry the product name with a reference code relating to its specification, plus the pharmaceutical form, strength, and batch size.5
Put those together and the required fields are already listed: site, product, dosage form, strength, batch size, document type, version. The pilot’s job is to make sure each of those lives in its own metadata field, and that the human-readable title is generated from those fields rather than typed independently.
A structured identifier
A workable pattern is a fixed-order identifier with a stable separator, plus a title built from the same values.
| Segment | Source | Rule | Example |
|---|---|---|---|
| Site | Site master list | Three-character site code. Never a city name, never an abbreviation of the legal entity. | ATH |
| Document type | Type taxonomy (Pilot One) | Fixed code from the controlled list. | MBR |
| Product code | Product master | The same code used in the specification and the ERP material master. One code, one product. | P0417 |
| Dosage form | Controlled list | Short code from an agreed list. Not free text. | TAB |
| Strength | Product master | Value and unit, no spaces, leading zeros for sortability. | 050MG |
| Batch size | Product master | Required, because 211.186 requires a master record for each batch size. | 250K |
| Version | System-generated | Held in the version field only. Never typed into the title. | 04 |
The result is an identifier such as ATH-MBR-P0417-TAB-050MG-250K, with the version carried by the system. The title reads as a sentence built from the same fields, so that a person scanning a list sees the same facts the query sees.
| Before (three sites, one product) | After |
|---|---|
| MBR 50mg tablet rev 4 FINAL | ATH-MBR-P0417-TAB-050MG-250K (v4) |
| Master Batch Rec_Product 417_250k_v4.1_updated | BRN-MBR-P0417-TAB-050MG-250K (v4) |
| BR-0417-B (large batch) 2024 | SGP-MBR-P0417-TAB-050MG-500K (v4) |
The third row is the reason this pilot pays for itself. Two of those records looked like the same document under three names, and one of them is a different batch size, which under 211.186 is a different master record entirely. Naming inconsistency does not just make search harder. It hides a distinction the regulation requires you to make.
Sequence the work correctly. Fix the metadata fields first and generate the title from them second. Changing the title of an approved master batch record is a change control action with training and effective-date consequences; populating a previously empty batch size field on the same record usually is not, though the route still has to be agreed with QA before you start. Companies that begin with renaming stall in change control. Companies that begin with fields have a clean dataset by week three and rename on the next scheduled revision of each record.
Before and after measures for Pilot Three
- Number of distinct naming patterns in use across the sites in scope
- Percentage of master records whose metadata fields match the values printed in the record header
- Percentage of master records with batch size populated as a field rather than embedded in a title
- Number of master records where the version appears in the title as well as the version field (the double-source problem behind Q7 6.50)
- Retrieval time in a drill: name every current master record for one product across all sites, measured before and after
- Number of duplicate or superseded master records identified and retired
Pilot Four: Quality Agreement Metadata
Scope: every active quality agreement in the company, two to three weeks. This population is small, usually between thirty and three hundred documents, which is why it makes such a good pilot.
Quality agreements are typically filed as PDFs with two pieces of metadata: the counterparty’s name and the date somebody uploaded it. What they govern is inside the document. That arrangement works until somebody asks a question that requires the set to be read as data: which agreements cover this product, which suppliers have no agreement, which agreements have not been reviewed since the last change of scope, which agreements name a legal entity we no longer buy from.
FDA’s guidance on contract manufacturing arrangements says a quality agreement describes the owner’s and the contract facility’s roles and manufacturing activities under CGMP, defines key roles and responsibilities, establishes expectations for communication with key contacts for both parties, and specifies which products or services the owner expects from the contract facility and who has final approval for various activities. It lists the sections most quality agreements contain: purpose and scope, definitions, resolution of disagreements, manufacturing activities, and the life cycle of and revisions to the agreement. It notes that quality agreements may be reviewed during inspections.9
The guidance also describes product-specific considerations that a comprehensive agreement may address, including product and component specifications, defined manufacturing operations including batch numbering processes, responsibilities for expiration and retest dating, storage, shipment and lot disposition, and responsibilities for process validation.9 Every one of those is a reason the agreement needs to be findable by product, not only by supplier.
EU GMP Chapter 7 adds the requirement that the contract describe clearly who undertakes each step of the outsourced activity.6 And the enforcement record shows why this matters: FDA’s June 2026 letter to a manufacturer in Navi Mumbai cited quality unit failures in the oversight of contract testing laboratories and restated that a manufacturer remains responsible for the quality of its drugs regardless of agreements in place with contract facilities.12 An agreement you cannot locate against a supplier and a product is not oversight.
The metadata set to add
| Field | Why it is needed | Validation rule |
|---|---|---|
| Supplier ID | Links the agreement to the approved supplier list and to purchasing records | Must exist in the approved supplier list. No free text. |
| Legal entity and manufacturing site | Agreements are often signed with a parent and performed at a named site | Both populated. Site validated against the supplier’s registered sites. |
| Products in scope | Answers the question an investigation or a recall will ask first | One or more product codes from the product master, or an explicit “all products” flag. |
| Activities in scope | Chapter 7.15 requires clarity on who does each step | Multi-select from a controlled list: manufacture, packaging, testing, storage, distribution, release. |
| Effective date | Establishes which version governed a given batch | Date, mandatory, must not be later than today for an active agreement. |
| Next review date | FDA lists the agreement’s own life cycle and revisions as a standard section | Date, mandatory, calculated from effective date plus the review interval. |
| Version and status | Prevents an expired or superseded agreement being read as current | Controlled status list: draft, active, superseded, terminated. |
| Owner | Somebody has to answer for the review | Role plus named incumbent, validated against the roster (Pilot Two). |
| Parent commercial agreement | Scope changes usually start in the commercial contract | Reference to the master services or supply agreement record. |
Before and after measures for Pilot Four
- Percentage of agreements linked to a valid supplier ID on the approved supplier list
- Percentage of agreements with at least one product code and at least one activity in scope
- Number of active suppliers performing GMP activities with no quality agreement on file
- Number of agreements on file for suppliers no longer in use or entities that no longer exist
- Number of agreements past their review date, and the oldest effective date still marked active
- Time to answer the question: show every agreement covering this product, and the version in force on this date
What good looks like at the end of two weeks. A single table with one row per agreement, joined cleanly to the approved supplier list and to the product master, that answers a scope question in one query rather than one meeting. The agreements themselves have not changed. What changed is that the set can now be read, reviewed on schedule, and produced during an inspection without a search of shared drives.
The Metadata Quality Scorecard
Four pilots produce four sets of numbers. Leadership will remember one. The scorecard’s job is to be that one, and to survive contact with a quarterly review a year from now when the person who ran the pilots has moved on.
Five dimensions
Keep the dimensions few and defined in a sentence each, so that a number can always be traced back to a rule.
| Dimension | Question it answers | Example rule | Weight |
|---|---|---|---|
| Completeness | Is the field populated at all? | Owner, type, process area, effective date, review date are not null and not a placeholder value. | 30% |
| Validity | Is the value from the controlled list? | Type is in the taxonomy. Process area is in the vocabulary. Site is in the site master. | 25% |
| Currency | Is the record still true today? | Owner is on the active roster. Review date is in the future. Status matches the approval record. | 20% |
| Consistency | Do the fields agree with each other and with the document? | Effective date matches the approval record date. Title fields match the metadata fields. | 15% |
| Linkage | Does the record connect to the things it governs? | Quality agreement links to a supplier ID. Master record links to a product code. Work instruction links to a parent SOP. | 10% |
The weights are a starting point, not a standard. What matters is that they are decided once, written down, and applied the same way each quarter, because the value of the score is entirely in the comparison. Ochoa and Duval’s finding that weighted completeness tracks human judgment better than a flat field count is the reason to weight at all.14 If everything counts the same, an optional note field can offset a missing owner, and the score stops meaning anything.
How to report it
Report three things and no more: the score now, the score before, and the single worst-performing field. The third item is what turns a metric into an action, because it tells the next person where to start. Report the tenth percentile alongside the mean, since a mean of 82 percent can hide two hundred documents scoring under 40 percent, and those two hundred are the ones that will be asked for.
Do not attach the score to a person. The moment a metadata score appears in an individual’s objectives, the fields get populated rather than corrected, and “N/A” becomes the most popular value in the system. Report by process area and by document type. Let the owners of those areas decide who does the work.
An honest word about benchmarks
There is no published industry benchmark for document metadata completeness in pharmaceutical quality systems, and any consultant who offers you one has made it up. The comparison that matters is against yourself: the same query, the same rules, the same population, three months apart. That is a real measurement, and it is more persuasive to a board than a borrowed number nobody can source.
Holding the Gains After the Pilot Ends
Most metadata pilots work. Most metadata pilots also decay, and they decay for a reason that has nothing to do with whether the cleanup was done well. The cleanup fixed the stock of documents. Nothing changed about the flow. Six months of new documents arrive under the old habits and the score drifts back toward where it started.
Five things prevent that, and all five are small enough to complete in the week after the pilot closes.
Constrain the fields in the system, not in a guidance document
A controlled vocabulary that lives in a PDF is a suggestion. The same vocabulary configured as a picklist that rejects free text is a control. If the system cannot enforce a list, the fallback is a weekly validity query with a named recipient, and that fallback should be treated as a temporary condition with a date on it.
Validate the owner field against the employee roster on a schedule
The orphan rate does not stay at zero. It grows every time somebody leaves. A monthly join between the document register and the active roster, producing a short list to a named document control owner, keeps the number near zero for a few minutes of effort a month. This is the single highest-return control in the article.
Write the rules into the document control procedure and the change control checklist
ICH Q7 requires that documents be prepared, reviewed, approved, and distributed according to written procedures, and that issuance, revision, superseding, and withdrawal be controlled with revision histories.8 The metadata rules belong inside those procedures. Add one line to the change control checklist: metadata fields verified against the controlled lists. A checklist line is what makes a rule survive a change of personnel.
Name a steward for the document register
Not a committee. One role, with the mapping table, the taxonomy, and the vocabulary as its deliverables, and the authority to reject a new value. The role takes a few hours a month once the pilots are done. It has to be a role rather than a person for the same reason document ownership does.
Put the score in management review
ICH Q10 asks for performance indicators to monitor the effectiveness of quality system processes, and for a quality manual that identifies those processes and their linkages.7 A quarterly metadata score for the document register is a legitimate quality system performance indicator, and putting it on that agenda is what keeps it funded. Chapter 4.32 already requires an inventory of documents within the quality management system.5 Reporting on the health of that inventory is the natural next sentence.
What to do after the four pilots
The four pilots are deliberately shallow and deliberately visible. Once they are done and the numbers have been reported twice, the organization has three things it did not have before: a controlled vocabulary, a measure, and a demonstrated ability to change a metadata population without breaking anything. That combination is what a larger program needs in order to be approved, and it is the reason to run the pilots in this order rather than starting with a governance charter.
Natural next steps, each of which is easier because the pilots ran: extend the type taxonomy to records as well as instructions, so that Chapter 4.10’s requirement to define which record relates to each activity and where it is held becomes a query rather than an interview;5 connect the process area vocabulary to the training curriculum so that assignment follows the same taxonomy; and apply the same profiling to the specification and analytical method populations, where the linkage dimension usually scores worst.
One further piece of practice is worth borrowing from engineering. ISPE’s good practice guide on the management of engineering standards treats a standard as having a full lifecycle from chartering through periodic review to retirement, with the review process being what keeps content current and compliant.16 Controlled documents deserve the same explicit lifecycle, including the retirement step. A large fraction of the metadata problem in an old document system is documents that should have been retired years ago and instead kept collecting owners, review dates, and search results.
Conclusion
The reason document metadata stays broken is not that it is hard. It is that it belongs to nobody and shows up in nobody’s objectives, while the work to fix it looks like administration rather than quality. The four pilots here are designed to break that framing by making the problem measurable in a fortnight and by tying each measure to something a regulator already requires: documents defined by type and uniquely identifiable, reviewed and kept current, retrievable when asked for, master records that state product, strength, dosage form, and batch size, and agreements that say who does what for which product. None of those obligations can be met by a system that cannot describe its own contents.
What makes these quick wins rather than a program is the scope discipline. No SOP content changes. No system is replaced. No governance body is created. A defined population, a written rule, a measured before and after, and a control that stops the problem returning. Do that four times and a company has both a materially better document system and the internal credibility to ask for something larger, which is exactly the order in which these things should happen.
Sakara Digital works with pharma and biotech organizations on data quality in regulated environments, including the unglamorous parts that decide whether an inspection week is calm or expensive. If you are considering where to start on document and record metadata, and want an independent view of which pilot would produce the clearest result in your systems, we are happy to have that conversation.
For Further Reading
For Further Reading
- GxP Records Retention and Archiving: Designing for 30 Years
- Master Data Management for Life Sciences: Creating a Single Source of Truth Across Global Operations
- Data Quality Metrics That Matter: How Pharma Leaders Measure Integrity and Readiness for AI
- SOP Authoring Pattern for AI-Augmented Manufacturing Operations
References & Sources
- U.S. Government Publishing Office. “21 CFR 211.180, General requirements (records and reports).” Code of Federal Regulations, Title 21, Volume 4, 2024 edition. https://www.govinfo.gov/content/pkg/CFR-2024-title21-vol4/pdf/CFR-2024-title21-vol4-sec211-180.pdf
- U.S. Code of Federal Regulations. “21 CFR 211.186, Master production and control records.” Legal Information Institute, Cornell Law School. https://www.law.cornell.edu/cfr/text/21/211.186
- U.S. Food and Drug Administration. “21 CFR 211.100, Written procedures; deviations.” Electronic Code of Federal Regulations, Title 21, Part 211, Subpart F. https://www.ecfr.gov/current/title-21/chapter-I/subchapter-C/part-211/subpart-F/section-211.100
- U.S. Government Publishing Office. “21 CFR 211.22, Responsibilities of quality control unit.” Code of Federal Regulations, Title 21, Volume 4, 2025 edition. https://www.govinfo.gov/content/pkg/CFR-2025-title21-vol4/pdf/CFR-2025-title21-vol4-sec211-22.pdf
- Pharmaceutical Inspection Co-operation Scheme. “Guide to Good Manufacturing Practice for Medicinal Products, Part I (PE 009-17), Chapter 4: Documentation.” PIC/S, August 25, 2023. https://www.gmp-compliance.org/files/guidemgr/pe-009-17-gmp-guide-part-i-basic-requirements-for-medicinal.pdf
- European Commission. “EudraLex Volume 4, Part I, Chapter 7: Outsourced Activities.” Health and Consumers Directorate-General, effective January 31, 2013. https://health.ec.europa.eu/system/files/2016-11/vol4-chap7_2012-06_en_0.pdf
- International Council for Harmonisation. “ICH Q10: Pharmaceutical Quality System (Step 5), EMA/CHMP/ICH/214732/2007.” Published by the European Medicines Agency. https://www.ema.europa.eu/en/documents/scientific-guideline/international-conference-harmonisation-technical-requirements-registration-pharmaceuticals-human-guideline-q10-pharmaceutical-quality-system-step-5_en.pdf
- U.S. Food and Drug Administration. “Q7 Good Manufacturing Practice Guidance for Active Pharmaceutical Ingredients: Guidance for Industry.” ICH harmonised tripartite guideline, September 2016. https://www.fda.gov/regulatory-information/search-fda-guidance-documents/q7-good-manufacturing-practice-guidance-active-pharmaceutical-ingredients-guidance-industry
- U.S. Food and Drug Administration. “Contract Manufacturing Arrangements for Drugs: Quality Agreements. Guidance for Industry.” Center for Drug Evaluation and Research, November 2016. https://www.fda.gov/media/86193/download
- U.S. Food and Drug Administration. “Warning Letter: Tentamus India Private Limited, CMS 720463.” Center for Drug Evaluation and Research, March 3, 2026. https://www.fda.gov/inspections-compliance-enforcement-and-criminal-investigations/warning-letters/tentamus-india-private-limited-720463-03032026
- U.S. Food and Drug Administration. “Warning Letter: Tianjin Kilo Pharmaceutical Sci-tech Co., Ltd., CMS 731761.” Center for Drug Evaluation and Research, August 6, 2026. https://www.fda.gov/inspections-compliance-enforcement-and-criminal-investigations/warning-letters/tianjin-kilo-pharmaceutical-sci-tech-co-ltd-731761-08062026
- U.S. Food and Drug Administration. “Warning Letter: Gopaldas Visram & Co., Ltd., CMS 721755.” Center for Drug Evaluation and Research, June 2, 2026. https://www.fda.gov/inspections-compliance-enforcement-and-criminal-investigations/warning-letters/gopaldas-visram-co-ltd-721755-06022026
- Wilkinson, Mark D., et al. “The FAIR Guiding Principles for scientific data management and stewardship.” Scientific Data 3, article 160018, March 15, 2016. https://www.nature.com/articles/sdata201618
- Ochoa, Xavier, and Erik Duval. “Automatic evaluation of metadata quality in digital repositories.” International Journal on Digital Libraries 10, pages 67-91, 2009. https://link.springer.com/article/10.1007/s00799-009-0054-4
- TMF Reference Model Community Group. “Version 3.0 of the Trial Master File Reference Model is HERE.” June 16, 2015 (the model is now part of CDISC). https://tmfrefmodel.com/version-3-released
- ISPE. “Good Practice Guide: Management of Engineering Standards.” International Society for Pharmaceutical Engineering. https://ispe.org/publications/guidance-documents/good-practice-guide-management-engineering-standards








Your perspective matters—join the conversation.