In This Article
- Executive Summary
- Why the Boundary Question Keeps Coming Up
- What the Regulators Actually Say About Raw Data
- Anatomy of a CDS Record: Seven Layers From Detector to Report
- Original Record and True Copy in a CDS Context
- What the Warning Letters Show
- A Boundary Definition You Can Put in Your Data Integrity SOP
- A Review Checklist for Chromatography Data
- What Changes for Cloud-Hosted CDS and Vendor Data Formats
- Conclusion
- For Further Reading
- References & Sources
Executive Summary
Every pharma and biotech quality control laboratory runs on a chromatography data system, and every one of those systems produces a record that is far larger than the number printed on the certificate of analysis. Between the detector signal and the reported result there are acquisition methods, processing methods, integration parameters, manual integration events, reprocessing runs, audit trail entries, result tables, and reports. The question of where “raw data” ends and “processed data” begins in that chain is not academic. It decides what a site must retain for the full record retention period, what a second-person reviewer must actually look at, what must be kept when a chromatogram is reprocessed, and what an inspector will ask to see on screen.
The good news is that the regulators have converged. FDA’s December 2018 Data Integrity and Compliance With Drug CGMP Q&A, the MHRA’s 2018 GxP data integrity guidance, PIC/S PI 041-1, and WHO Technical Report Series 1033 Annex 4 converge on the same idea without using the same words. MHRA, PIC/S and WHO define raw data as the first capture of information; MHRA and PIC/S add that information captured in a dynamic state must remain available in that state. FDA never defines the term raw data at all, and speaks instead of the original record and complete data. For chromatography, that means the original electronic data file plus the metadata needed to reconstruct the analysis, not a printout. The core insight of this article is that the boundary is not a line between two files. It is a rule about which layers of the CDS record must be retained together, unchanged, and reviewable. Warning letters to Ava Inc. (2026), Unipack LLC (2025), Intas Pharmaceuticals (2023), and Divi’s Laboratories (2017) show what happens when a site draws that line in the wrong place.
This article sets the four regulatory definitions side by side, walks through the seven layers of a CDS record and classifies each one, explains what original record and true copy mean when the original is a dynamic file, reviews the enforcement evidence, and gives a boundary definition a site can adopt in its data integrity SOP. It closes with a chromatography data review checklist and a section on what changes when the CDS is cloud-hosted or the data lives in a vendor-specific format.
Why the Boundary Question Keeps Coming Up
Ask three people in a QC laboratory what the raw data for an HPLC assay is and you will often get three answers. The analyst points to the chromatogram. The QA reviewer points to the signed result printout. The IT administrator points to the project folder on the CDS server. All three are partly right, and that is exactly the problem. When the definition lives in people’s heads instead of in a procedure, four things go wrong.
Retention decisions are made on the wrong object
21 CFR 211.180 requires records to be retained as original records or true copies, and 21 CFR 211.194(a)(4) requires laboratory records to include a complete record of all data secured in the course of each test, including “all graphs, charts, and spectra from laboratory instrumentation, properly identified”78. A site that treats the PDF report as the record and lets the CDS project age out under a storage policy has retained a summary of the test, not the test. FDA’s Q&A is explicit that a printout of a dynamic record does not satisfy the requirement, a point covered in detail below1.
Second-person review reviews the wrong thing
21 CFR 211.194(a)(8) requires the initials or signature of a second person “showing that the original records have been reviewed for accuracy, completeness, and compliance”7. If the reviewer only sees the result table, they cannot see the integration, cannot see whether a peak was manually drawn, and cannot see whether an injection was run and left unprocessed. The review is then a check of arithmetic, not a check of the record.
Reprocessing leaves no trace of the first pass
Chromatography data systems allow reprocessing by design. That is a feature, not a defect. The regulatory question is whether every version of the processing is kept and whether each change carries a reason. A site that has not defined the processing method and integration events as part of the record tends to keep only the final version, which is the practice FDA’s Q&A answer 14 rejects outright1.
Inspections turn into a search for what is missing
Investigators reviewing a CDS do not start from the report. They start from the sequence, count the injections, and reconcile them against what was reported. The Unipack warning letter below is a plain example: a large number of sample injections in the electronic record (FDA redacted the counts), results generated for only a fraction of them, and no evidence that anyone reviewed the raw data for the rest11. A site that has defined its boundary correctly can answer that question in minutes. A site that has not will spend the rest of the inspection explaining.
If a regulator asked you to reproduce a reported result from what you have retained, and to show every processing step that produced it, could you do it without the analyst who ran the sample? If the answer depends on that person’s memory, on a spreadsheet outside the CDS, or on a file that a storage policy might have deleted, the boundary is in the wrong place.
What the Regulators Actually Say About Raw Data
Rather than paraphrase from memory, it is worth reading the four principal data integrity guidances against each other. All four are current. The FDA guidance is the December 2018 final Q&A, the MHRA guidance is Revision 1 of March 2018, PIC/S PI 041-1 entered into force on 1 July 2021, and the WHO guideline was published as Annex 4 of Technical Report Series 1033 in 2021. The definitions below are quoted from the documents themselves.
MHRA: raw data must stay dynamic if it was captured dynamically
The MHRA guidance gives the clearest statement. Under section 6.2 it says: “Raw data is defined as the original record (data) which can be described as the first-capture of information, whether recorded on paper or electronically. Information that is originally captured in a dynamic state should remain available in that state.”2 It then removes the most common loophole: “Where this has been captured in a dynamic state and generated electronically, paper copies cannot be considered as ‘raw data’.”2 The guidance goes on to note that where the equipment does not store electronic data at all, such as a balance or pH meter that only prints, the printout is the raw data. A CDS is the opposite case. It stores everything electronically, so the printout is never the raw data.
The MHRA also defines the original record more broadly than many sites expect: “The first or source capture of data or information e.g. original paper record of manual observation or electronic raw data file from a computerised system, and all subsequent data required to fully reconstruct the conduct of the GXP activity.”2 Note the second clause. The original record is not only the first file. It is the first file plus everything needed to reconstruct the activity. For chromatography, the same guidance uses the example directly: electronic chromatography records allow a user or reviewer to reprocess the data and expand the baseline to view the integration more clearly, and once printed or converted to a static format they lose that capability2.
PIC/S PI 041-1: identical definition, plus explicit expectations for manual integration
The PIC/S glossary uses the same words as the MHRA for raw data, including the sentence that information captured in a dynamic state should remain available in that state3. Its ALCOA+ table defines “Original” as the first capture of information, whether recorded on paper (static) or electronically (usually dynamic, depending on the complexity of the system)3. Section 9.1.5.1 adds the retention consequence: “the complete capture and retention of raw data would normally be required in order to reconstruct the manufacturing event or analysis.”3
Where PIC/S goes further is in section 9.7, the expectation for data changes within computerized systems. It states that “manual integrations and reprocessing of laboratory results should be performed in an approved and controlled manner,” that “Original (unchanged) data should be retained in its original context,” and that “Any and all changes and modifications to raw data should be fully documented and should be reviewed and approved by at least one appropriately trained and qualified individual.”3 Section 9.9 then closes the loop on storage: “Storage of data should include the entire original data and all relevant metadata, including audit trails, using a secure and validated process.”3
WHO TRS 1033 Annex 4: raw data is source data, and metadata includes processing parameters
The WHO glossary defines raw data as “The original record (data) which can be described as the first-capture of information, whether recorded on paper or electronically. Raw data is synonymous with source data.”4 Its definition of static data uses chromatography as the worked example: “once printed or converted to static electronic format chromatography records lose the capability of being reprocessed or enabling more detailed viewing of baseline.”4
The WHO metadata definition is the most useful of the four for a CDS because it lists the components: “Other examples of metadata include the time or date stamp of an activity, the operator identification (ID) of the person who performed an activity, the instrument ID used, processing parameters, sequence files, audit trails and other data required to understand data and reconstruct activities.”4 Processing parameters and sequence files are named as metadata. That single sentence settles the classification of the processing method. And section 9.5 makes the versioning requirement plain: “Where results or data are processed using a different method/parameters, then each version of the processing method should be recorded.”4
FDA: dynamic records, audit trails that include integration parameters, and the injection-level save
FDA’s Q&A does not define “raw data” as a term. It uses “original record” and “complete data,” anchored to the regulations, and it defines the supporting concepts. On metadata: “Metadata is the contextual information required to understand data.”1 On audit trails, the definition is written with HPLC in mind: “the audit trail for a high performance liquid chromatography (HPLC) run should include the user name, date/time of the run, the integration parameters used, and details of a reprocessing, if any. Documentation should include change justification for the reprocessing.”1 On record format: “a dynamic chromatographic record may allow the user to change the baseline and reprocess chromatographic data so that the resulting peaks may appear smaller or larger.”1
Answer 12 sets the expectation for when data becomes a record, and it is specific to chromatography: “chromatographic data should be saved to durable media upon completion of each step or injection (e.g., peak integration or processing steps; finished, incomplete, or aborted injections) instead of at the end of an injection set, and changes to the chromatographic data or injection sequence should be documented in an audit trail. Aborted or incomplete injections should be captured in audit trails and should be investigated and justified.”1
EU GMP Chapter 4: the regulated user must define raw data
EU GMP Chapter 4 adds a governance obligation the other documents assume: “Records include the raw data which is used to generate other records. For electronic records regulated users should define which data are to be used as raw data. At least, all data on which quality decisions are based should be defined as raw data”5. In other words, a site is expected to have written down its own boundary. If the data integrity SOP does not contain that definition for the CDS, the site has a Chapter 4 gap before any question of practice arises.
| Source | Term used | Core definition | What it says about chromatography |
|---|---|---|---|
| FDA Q&A (Dec 2018)1 | Original record, complete data, dynamic record | Dynamic means the record format allows interaction between the user and the record content | HPLC audit trail must include integration parameters and reprocessing details; save after each injection and processing step; aborted injections captured and justified |
| MHRA (Mar 2018)2 | Raw data, original record, true copy | First capture of information; dynamic capture must remain dynamic | Paper copies of dynamically captured electronic data cannot be considered raw data; printed chromatography records lose the ability to be reprocessed |
| PIC/S PI 041-1 (Jul 2021)3 | Raw data, original, dynamic record | Same as MHRA; complete capture and retention of raw data required to reconstruct the analysis | Manual integration and reprocessing in an approved, controlled manner; original unchanged data retained in original context; all raw data changes reviewed and approved |
| WHO TRS 1033 Annex 4 (2021)4 | Raw data (synonymous with source data), metadata, dynamic data | First capture of information; metadata explicitly includes processing parameters and sequence files | Each version of the processing method must be recorded; reviewers must have access to original electronic data and metadata |
| EU GMP Chapter 4 (2011)5 | Raw data, records | Regulated users must define which electronic data are raw data; at minimum all data on which quality decisions are based | Applies equally to all document media types, including hybrid systems |
Read together, the five documents point in one direction. Raw data is the first capture. For a CDS that capture is electronic and dynamic. It must stay dynamic. And the record is not complete without the metadata, including processing parameters, sequence files, and the audit trail, that lets a reviewer reconstruct what was done.
Anatomy of a CDS Record: Seven Layers From Detector to Report
With the definitions in hand, the next step is to apply them to what a CDS actually stores. The layers below are generic. Every commercial CDS has its own names for them, but the structure is the same across vendors.
Injection data and detector signals
The digitized detector trace for each injection, with its time base, sample identity, vial position, injection volume, and instrument identity. This is the first capture. It is raw data under every definition above. It cannot be regenerated: once a sample has been injected, the only record of what the detector saw is this file.
Acquisition method and sequence
The instrument settings in force during the run (flow, gradient, temperature, wavelength, run time) and the sequence table that lists every injection in order with its intended purpose. These are metadata in the WHO sense and part of the original record in the MHRA sense. Without the sequence, a reviewer cannot tell whether every injection is accounted for. Without the acquisition method, the trace has no scientific meaning.
Processing method and integration parameters
The integration algorithm settings (peak width, threshold, timed events such as inhibit integration), calibration settings, and calculation formulas that turn a trace into peak areas and results. WHO names “processing parameters” as metadata. FDA names “the integration parameters used” as an audit trail element. Every version that was applied to a reported result is part of the record.
Manual integration events
Any manual repositioning of a baseline, manual peak assignment, or manual timed event applied to a specific injection. Newton and McDowall propose a useful distinction: manual integration is “manual repositioning of the baselines, as opposed to manual intervention, which refers to changing integration parameters.”14 Both are changes to how raw data is interpreted. Both must be captured with who, when, and why, and both must be visible to the reviewer.
Reprocessing and reintegration records
Each time the processing method is re-applied, or an injection is reintegrated, the CDS creates a new result set. FDA’s answer 14 requires that “each result retained for review”1, and WHO requires each version of the processing method to be recorded. The first result set is not superseded in the regulatory sense. It remains part of the complete record, alongside the reason for the second pass.
Audit trail
The secure, time-stamped log of creation, modification, and deletion events across all of the layers above, including sequence edits, method changes, manual integration, reprocessing, and any deletion or abort. Under the WHO definition the audit trail is “a form of metadata,” and under MHRA metadata “form an integral part of the original record.”2 The audit trail is therefore inside the boundary, not a separate compliance artifact.
Result tables and reports
The tabulated peak results and the formatted report or PDF that is signed and attached to the batch record or certificate of analysis. These are derived records. They are essential outputs and they must be retained, but they are static views of the dynamic record beneath them. They are the last thing to review, not the first, and they are never a substitute for layers 1 through 6.
So where is the boundary?
The honest answer is that the word “raw” is doing less work than people assume. Layer 1 is raw data in the strict sense. But the regulatory obligation attaches to the original record, and the original record includes layers 1 through 6. The line that matters is not between raw and processed. It is between the dynamic record (layers 1 through 6, which must be retained together and unchanged, with every change logged) and the static outputs (layer 7, which are derived from it and can be regenerated from it). A site that retains layer 7 and discards or lets decay any of layers 1 through 6 has kept the answer and thrown away the working.
The chromatogram is raw data. The processing method is metadata. The audit trail is metadata. The report is a derived record. The original record is all of it together, held in a form that lets a qualified person reprocess the data and see exactly what the analyst saw. If any one of those pieces is missing, the record is incomplete, and 21 CFR 211.194 requires complete data.
Original Record and True Copy in a CDS Context
Two terms get used loosely in laboratory SOPs, and the distinction determines what can be archived, migrated, and retired.
Original record
For a networked CDS, the original record is the project or result set in the CDS database, including the injection data, methods, integration events, reprocessing history, and audit trail. FDA’s answer 10 addresses the tempting alternative directly: electronic records from certain laboratory instruments, whether stand-alone or networked, are dynamic, and “a printout or a static record does not preserve the dynamic record format that is part of the complete original record.”1 The same answer notes that a static printout “would not satisfy CGMP requirements to retain original records or true copies” and, for spectra, that if the full spectrum is not displayed in the printout, contaminants may be excluded1. The chromatography equivalent is a report that shows integrated peaks but not the baseline placement, the inhibited regions, or the unprocessed injections.
The MHRA puts the same point as a preference rule under section 6.7: “Where the capability of the electronic system permits dynamic storage, it is not appropriate for static (printed / manual) data to be retained in preference to dynamic (electronic) data.”2
True copy
The MHRA and WHO definitions of true copy are word-for-word the same: “A copy (irrespective of the type of media used) of the original record that has been verified (i.e. by a dated signature or by generation through a validated process) to have the same information, including data that describe the context, content, and structure, as the original.”24 The MHRA then addresses format change, which is the question every CDS migration raises: “A true copy may be stored in a different electronic file format to the original record if required, but must retain the metadata and audit trail required to ensure that the full meaning of the data are kept and its history may be reconstructed.”2
FDA’s answer 9 aligns: electronic copies can serve as true copies “provided the copies preserve the content and meaning of the original record, which includes all metadata required to reconstruct the CGMP activity and the static or dynamic nature of the original records.”1 It adds that true copies of dynamic records may be kept in the original format or in a format that preserves content and meaning if a suitable reader and copying equipment are readily available, citing 211.180(d)1. FDA also defines the backup required by 211.68(b) as a true copy, and says the backup file “should contain the data (which includes associated metadata) and should be in the original format or in a format compatible with the original format.”1
What this means in practice
- A PDF report is not a true copy of a CDS result set. It does not carry the injection data, the processing method, or the audit trail, and it is static where the original is dynamic. It is a derived record and should be labeled as one.
- A CDS project exported in the vendor’s native archive format, with methods, results, and audit trail included, and verified by a validated process, can be a true copy. The verification step is what makes it one.
- A migration to a new CDS or a new format produces a true copy only if the migration was validated to preserve content and meaning. EU GMP Annex 11 clause 4.8 requires that “If data are transferred to another data format or system, validation should include checks that data are not altered in value and/or meaning during this migration process.”6 Annex 11 clause 17 adds that when the system changes, “the ability to retrieve the data should be ensured and tested.”6
- Retiring the original after a true copy is made is permitted, but only with the documented verification in hand. The MHRA guidance allows true copies to be retained in place of the original if a documented system is in place to verify and record the integrity of the copy2. Without that record, the original must stay.
FDA’s own inspection guide for QC laboratories, written in 1993 and still posted, frames the same expectation in older language: “Test results should not have been transcribed without retention of the original records, nor should test results be recorded selectively,” and for computerized data systems, “Data entries may not be deleted. Changes must be made in the form of amendments.”9 The technology has changed. The principle has not.
What the Warning Letters Show
The definitions above describe the boundary. The warning letters describe what happens when a site draws it somewhere else. Four public letters, spanning 2017 to 2026, cover the main failure modes: unprocessed injections, trial injections, deleted sequences, unapproved manual integration events, and integration configured to hide peaks.
Ava Inc., April 2026: trial injections, deleted GC sequences, shared logins
FDA’s warning letter to Ava Inc., issued April 14, 2026 after an October 2025 inspection, is the most recent public example and it touches nearly every layer of the CDS record. The firm used “a common username and password to access high performance liquid chromatography (HPLC) equipment,” analysts had administrator privileges that allowed data to be deleted, and investigators found “multiple deleted gas chromatography (GC) analytical sequences in the recycle bin, including sequences used for system suitability and stability analysis.”10 The letter also documents trial injections whose out-of-specification results were not reported or investigated, with chromatograms from those injections not saved in the analytical system or as part of the official batch record. The quality unit lacked “a written procedure to review audit trails and raw analytical data.”10
Read against the definitions, each finding is a boundary failure. A trial injection is layer 1 data. If it is not saved, the original record is incomplete. A deleted sequence removes layers 1 and 2 together. A shared login makes the audit trail (layer 6) unable to attribute anything. And the absence of a procedure for reviewing raw analytical data means second-person review was operating on layer 7 alone.
Unipack LLC, December 2025: injections without results, integration without justification
The Unipack letter, issued December 19, 2025 after a June 2025 inspection, is the clearest illustration of why the sequence table belongs inside the boundary. FDA found that approximately [redacted] sample injections had been performed with results generated for only approximately [redacted] of them, and no evidence that the laboratory manager or the quality unit had reviewed the raw data for the unprocessed injections11. In one case a three-month stability sample was injected but the results were neither processed in the HPLC system nor recorded in the notebook. The letter also found that “analysts had administrative rights on your chromatographic systems that allowed them to alter and delete data, files, and folders,” and cited “inconsistent integration of HPLC peaks” without scientific justification, noting that this “is not suitable for quantitative analysis.”11
Every one of those injections was raw data the moment it was acquired. The firm’s working boundary treated an injection as a record only if someone chose to process it. FDA’s answer 12 says the opposite: data becomes a CGMP record when generated to satisfy a CGMP requirement, and aborted or incomplete injections must be captured, investigated, and justified1.
Intas Pharmaceuticals, July 2023: aborted sequences and unapproved integration events
The July 28, 2023 warning letter to Intas Pharmaceuticals (the Sanand site) found that the firm had “aborted hundreds of chromatographic sequences in your QC laboratories between January 2020 to November 2022” and, while each incident was investigated individually, lacked trending and a systemic CAPA12. On integration, analysts “manually reprocessed chromatograms by adding integration events that were not approved by QC management,” and the firm “lacked appropriate procedures describing when the analyst can manually input integration events.”12
This is a layer 4 failure. The CDS captured the manual events (that is how FDA saw them), so the record was technically complete. What was missing was the control: an approved definition of when manual integration is allowed, who may perform it, and who must review it. PIC/S section 9.7 describes exactly that control3.
Divi’s Laboratories, April 2017: integration configured to hide peaks
The April 13, 2017 letter to Divi’s Laboratories Unit II remains the reference case for layer 3. FDA found the HPLC software “configured to permit extensive use of the ‘inhibit integration’ function without scientific justification,” with parameters for impurity release testing “set to inhibit integration at four different time periods throughout the analysis.”13 The agency’s conclusion: “It can mask identification and quantitation of impurities in your API.”13 The letter also recorded that audit trail functionality for some systems “was enabled only the day before the inspection.”13
Inhibit integration has legitimate uses, such as excluding a solvent front. The problem at Divi’s was that the processing method, which is metadata within the original record, had been set in a way that changed what the record showed, with no justification recorded anywhere. Newton and McDowall’s rule for a chromatography SOP is that inhibiting integration should be restricted to circumstances documented in the validated analytical method14.
None of these four firms lacked a CDS capable of keeping the complete record. In every case the system captured more than the firm reported, and the inspector found the difference by reading the system rather than the report. The gap was never technical. It was a definition of the record that stopped at the result table, and a review process that stopped there with it.
A Boundary Definition You Can Put in Your Data Integrity SOP
EU GMP Chapter 4 requires the regulated user to define which electronic data are raw data5. The definition below is written to be lifted into a site data integrity SOP or a CDS-specific procedure, adjusted for the system’s own terminology. It is deliberately structured as a list of record components rather than a single sentence, because a single sentence is what leaves room for the interpretations that produced the warning letters above.
1. Raw data. The electronic data file for each injection as acquired from the detector, together with the sample identity, sequence position, instrument identity, and date and time of acquisition. Raw data includes every injection made, including system suitability, standards, blanks, samples, and any injection that was aborted, incomplete, or not used to calculate a reportable result. Raw data is created at the moment of acquisition and is not dependent on subsequent processing.
2. Metadata forming part of the original record. The acquisition method, the sequence table, every version of the processing method and its integration parameters applied to any injection, every manual integration event with its user, timestamp, and reason, every reprocessing or reintegration event and its result set, the calibration and calculation settings, and the complete audit trail for the project or result set.
3. Original record. Items 1 and 2 together, held in the CDS in dynamic form such that a qualified reviewer with appropriate access can reprocess the data and view the integration as applied. The original record is complete only when every injection in the sequence is accounted for by a processed result, a documented invalidation, or a documented justification for non-processing.
4. Derived records. Result tables, reports, PDFs, exported summaries, and LIMS entries generated from the original record. Derived records are retained as required but are not substitutes for the original record and are not raw data.
5. True copy. A copy of the original record, in the original format or in a format validated to preserve content, meaning, metadata, and audit trail, whose equivalence to the original has been verified through a validated process or a dated signature and recorded. Only a true copy may replace the original record in the archive.
6. Retention. The original record or its true copy is retained for the full retention period applicable to the batch or study. Derived records do not satisfy this requirement on their own.
Four supporting rules make the definition operable.
Save at the injection, not the sequence
Configure the CDS so that data is committed to durable storage after each injection and each processing step, as FDA’s answer 12 expects. Verify during validation that the auto-save cannot be disabled by an analyst, which PIC/S section 9.7 lists as a specific check.
Automatic first, manual by exception
All integration is performed automatically in the first instance, using a processing method developed for the specific analytical procedure. Manual integration and manual intervention are permitted only under conditions written into the chromatography SOP or the method, with a reason recorded in the CDS, and are subject to review by a designated experienced reviewer.
Every processing version is kept
Reprocessing creates a new result set and never overwrites the previous one. The SOP states that the first result set is part of the record, that the reason for reprocessing is documented before it is performed, and that the reviewer compares the versions.
Name every injection before the run
The sequence is built with a controlled naming convention that states the purpose of each injection (suitability, standard, blank, sample, control) before acquisition starts. Terms such as “test” or “trial” are not permitted. Any injection not described in the method is treated as an extra injection requiring documented justification.
Rules 2 and 4 draw on the SOP content that Newton and McDowall recommend, including their expectation that “All integration, in the first instance, must be performed automatically,” their guidance that labeling injections and peaks after the run gives analysts an opportunity to mislead reviewers, and their recommendation that manual adjustments be reviewed by a senior scientist able to judge the scientific merit of the integration14. A 2025 peer-reviewed review of peak integration in GMP laboratories reaches the same conclusions for capillary electrophoresis, recommending that integration parameters be documented, justified, and reviewed, and that sites combine an integration SOP with method-specific parameters, analyst training, and visual inspection regardless of whether integration was automated15.
A Review Checklist for Chromatography Data
Second-person review is where the boundary definition either does its job or does not. FDA’s answer 10 requires that original laboratory records, paper and electronic, be subject to second-person review under 211.194(a)(8) “to make certain that all test results and associated information are appropriately reported.”1 WHO section 12.2 requires reviewers to have access to original electronic data and metadata, and section 12.3 requires routine review of audit trails with frequency set by system criticality4. PIC/S section 9.8 requires the reviewer to determine whether operations were performed correctly, whether any change was made to original information, and “whether any relevant unreported data was generated.”3 Annex 11 clause 9 requires audit trails to be “available and convertible to a generally intelligible form and regularly reviewed.”6
The checklist below is ordered by the layers of the record, which is also the order in which a reviewer should work. Reviewing the report first and working backward is how sample results get looked at before system suitability, which Newton and McDowall warn can itself be seen as testing into compliance14.
| Layer | Reviewer confirms | Where to look in the CDS |
|---|---|---|
| Sequence and injections | Every injection in the sequence is accounted for: processed, invalidated with a documented investigation, or justified as not processed. No injections exist outside the sequence for this sample. Injection names follow the convention and were assigned before acquisition. No aborted or incomplete runs are unexplained. | Sequence table, injection list, project-level audit trail for sequence edits and aborts |
| Acquisition method | The method version matches the approved analytical procedure. No changes to acquisition parameters between standards and samples. | Method version history, audit trail for method changes |
| Processing method and integration parameters | The processing method is the approved version for the procedure. Timed events, especially inhibit integration, match those documented in the validated method. Standards and samples were processed with the same parameters. | Processing method, timed events table, method audit trail |
| Manual integration events | Each manual event has a user, timestamp, and reason. The reason is scientifically plausible and permitted by the SOP. Baselines were not repositioned in a way that reduces or increases area selectively (peak skimming or enhancing). Manual events on standards are examined with particular care. | Per-injection integration events, overlay of automatic and manual baselines |
| Reprocessing and reintegration | Every result set is present. The reason for each reprocessing was recorded before it was run. The reported result set is identified, and differences from the earlier set are explained. Reprocessing was not used to move a failing result to a passing one without an investigation. | Result set history, reprocessing log, audit trail |
| Audit trail | The audit trail was enabled throughout. Entries are attributable to individual users. No deletions of injections, sequences, or result sets. No changes to system time. Entries from the time window of the analysis are consistent with the analyst’s record. | Project, result, and system audit trails; system administration log |
| Result tables and report | System suitability passes before any sample result is examined. Reported values match the identified result set. Calculations, units, and factors are correct. The report is a faithful rendering of the dynamic record, not a curated subset. | Result table, report template, calculation fields |
The review record contains a positive statement that the audit trail was examined and whether anything was found, with the date and reviewer signature, as the MHRA guidance requires2. The percentage of manually integrated peaks per method is trended and falls over time as methods are improved. Reviewers can reproduce a reported result from the retained record without asking the analyst. Injections that were not used are visible in the review package with a reason, not discovered later by an inspector.
Two review practices deserve emphasis. First, review the audit trail as part of reviewing the record, not as a separate periodic task. FDA’s answer 7 compares audit trail review to checking cross-outs on paper: the person responsible for record review should review the audit trail entries associated with that record as they review the rest of it1. Second, use the CDS’s own tools. Most systems can list injections without results, list manual integration events per project, and flag reprocessed result sets. A reviewer working from the PDF cannot see any of that.
What Changes for Cloud-Hosted CDS and Vendor Data Formats
The boundary definition does not change when the CDS moves to a hosted environment or when data is exported to a new format. What changes is who controls each layer of the record and how a site proves the record has survived intact.
Cloud-hosted CDS: ownership, access, and the retention period
The MHRA guidance addresses cloud, SaaS, PaaS, and IaaS providers in section 6.20: “Where ‘cloud’ or ‘virtual’ services are used, attention should be paid to understanding the service provided, ownership, retrieval, retention and security of data.”2 It requires the technical agreement to “ensure timely access to data (including metadata and audit trails) to the data owner and national competent authorities upon request,” to define responsibilities for archiving and continued readability throughout the retention period, and to include tested business continuity arrangements2. It also asks the regulated company to consider the physical location of the data and the laws that apply there.
WHO section 7 covers the same ground from the contract side. Ownership of data and each party’s responsibilities must be described in written agreements, and “Provisions should be made for responsibilities relating to data when an agreement expires.”4 Where retention is contracted out, particular attention goes to security, transfer, storage, access, and restoration, and “This includes static data and dynamic data.”4 PIC/S section 8.10.2 permits records to be retained through an outside storage service subject to quality agreements, provided the locations of the provider’s facilities are identified and a risk assessment shows the retention arrangement is suitable3. Annex 11 clause 3.1 requires formal agreements with clear statements of responsibility whenever a third party provides, maintains, or retains a computerized system or processes data6.
Applied to a hosted CDS, five questions need documented answers before the first GMP sample is injected:
- Which layers does the provider control? In a typical SaaS CDS the provider controls infrastructure, backup, and the database that holds layers 1 through 6. The site must be able to show that the audit trail (layer 6) is not editable by the provider’s administrators without a record, and that the site can export the complete original record, not just reports, on demand.
- Can the site retrieve a true copy in a usable format on exit? The contract should name the export format, confirm it carries methods, results, integration events, and audit trail, and state the timeframe. Annex 11 clause 7.1 requires access to data throughout the retention period and stored data to be checked for accessibility, readability, and accuracy6. If the provider’s retention period is shorter than the site’s, the site owns the gap.
- What happens to dynamic records when the subscription ends? The MHRA true copy definition allows a different format as long as metadata and audit trail are retained and the data’s history can be reconstructed2. A read-only archive viewer provided under a separate license may satisfy this. A pile of PDFs does not.
- Can an inspector see the record? Both MHRA and WHO require timely access for competent authorities. A hosted CDS that requires provider intervention to grant read access during an inspection is a risk the site should have tested in advance.
- Who reviews provider-side audit trails? Infrastructure events (restores, database maintenance, time synchronization) can affect the integrity of the record. FDA’s footnote to answer 8 lists instrument operational status, communication logs, and alert records as audit trails that may be reviewed on a risk-based frequency1. The equivalent for a hosted CDS is the provider’s change and incident log, and the agreement should say who reads it.
Vendor data formats: the original is in a proprietary format, and that is fine until it is not
Every commercial CDS stores injection data, methods, and results in its own proprietary structure. That is the original record, in the original format, and the regulations are content with that as long as the site can read it for the retention period. The trouble starts in three situations: when the CDS is replaced, when data must be shared with a partner or contract laboratory that uses a different system, and when the site wants to use the data for trending, analytics, or AI work outside the CDS.
In each case the exported data is a copy, and the question is whether it is a true copy. The test from the MHRA definition is whether the copy retains “the metadata and audit trail required to ensure that the full meaning of the data are kept and its history may be reconstructed.”2 A flat export of peak areas does not meet that test. It is a derived record. It may be perfectly adequate for trending, but it cannot replace the original in the archive, and a site that migrates to a new CDS by exporting result tables and decommissioning the old database has destroyed the original record.
Vendor-neutral formats are maturing, and they change the calculation. The Allotrope Foundation publishes the Allotrope Simple Model (ASM), a set of public JSON schemas organized by technique, with separate schema folders for liquid chromatography, gas chromatography, and LC-MS among more than sixty domains17. An open-source library, allotropy, converts instrument software output into ASM JSON, with the stated aim of reading text or Excel-based instrument output and returning a JSON representation that conforms to the published ASM schema16. WHO section 9.6 is the relevant guidance for any such transformation: data transfer and migration procedures must be validated, careful consideration must be given to understanding the data format and the potential for alteration at each stage, and “The challenges of migrating data are often underestimated, particularly regarding maintaining the full meaning of the migrated records.”4
Three practical positions follow.
- Treat vendor-neutral exports as derived records unless validated as true copies. An ASM file that carries the chromatogram, the peak list, the processing parameters, and a verified link to the audit trail could be validated as a true copy. One that carries only the peak list is a derived record. The site decides which it is building, validates accordingly, and labels the output.
- Keep the original CDS record for as long as the retention period runs, or until a validated true copy exists. This is the same rule as for any migration. FDA’s definition of backup as a true copy “in the original format or in a format compatible with the original format”1 is the standard to design against.
- Make the boundary definition part of the data flow documentation. When chromatography data leaves the CDS for a data lake, a LIMS, or an analytics platform, the interface specification should state which layers travel with it and which stay behind. This is what turns a data integrity SOP into something an architect can build to.
Conclusion
The question “where does raw data end in a CDS” has a settled regulatory answer, and it is not the one most sites have written down. Raw data is the first capture, which for chromatography is the detector trace for every injection. The original record is that raw data plus the metadata needed to reconstruct the analysis: the acquisition and processing methods, every integration parameter and manual event, every reprocessing result, and the audit trail. That record must stay dynamic, it must be retained complete, and it is what a second person must review. Reports and result tables are derived from it and cannot stand in for it. Four regulators say this in nearly the same words, and four public warning letters across nine years show the same failure repeated: a record defined as the report, a review that stopped at the report, and an inspector who read the system instead.
Sakara Digital works with pharma and biotech organizations on the data integrity foundations that make laboratory systems inspection-ready, including CDS record definitions, review procedures, and the contractual and technical controls that hosted and vendor-neutral data platforms require. If you are revisiting your data integrity SOP, preparing for a CDS migration or cloud move, or want an independent read on whether your chromatography review process would hold up to the questions above, we are happy to have that conversation.
For Further Reading
For Further Reading
References & Sources
- U.S. Food and Drug Administration. “Data Integrity and Compliance With Drug CGMP: Questions and Answers. Guidance for Industry.” December 2018. https://www.fda.gov/media/119267/download
- Medicines and Healthcare products Regulatory Agency. “‘GXP’ Data Integrity Guidance and Definitions, Revision 1.” March 2018. https://assets.publishing.service.gov.uk/media/5aa2b9ede5274a3e391e37f3/MHRA_GxP_data_integrity_guide_March_edited_Final.pdf
- Pharmaceutical Inspection Co-operation Scheme. “PI 041-1: Good Practices for Data Management and Integrity in Regulated GMP/GDP Environments.” 1 July 2021. https://picscheme.org/docview/4234
- World Health Organization. “Guideline on Data Integrity.” WHO Technical Report Series No. 1033, Annex 4, 2021. https://cdn.who.int/media/docs/default-source/medicines/norms-and-standards/guidelines/inspections/trs1033-annex4-guideline-on-data-integrity.pdf
- European Commission. “EudraLex Volume 4, Chapter 4: Documentation.” Revision effective 30 June 2011. https://health.ec.europa.eu/system/files/2016-11/chapter4_01-2011_en_0.pdf
- European Commission. “EudraLex Volume 4, Annex 11: Computerised Systems.” Revision effective 30 June 2011. https://health.ec.europa.eu/system/files/2016-11/annex11_01-2011_en_0.pdf
- Code of Federal Regulations. “21 CFR 211.194: Laboratory Records.” Legal Information Institute, Cornell Law School. https://www.law.cornell.edu/cfr/text/21/211.194
- Code of Federal Regulations. “21 CFR 211.180: General Requirements (Records and Reports).” Legal Information Institute, Cornell Law School. https://www.law.cornell.edu/cfr/text/21/211.180
- U.S. Food and Drug Administration. “Guide to Inspections of Pharmaceutical Quality Control Laboratories.” July 1993. https://www.fda.gov/inspections-compliance-enforcement-and-criminal-investigations/inspection-guides/pharmaceutical-quality-control-labs-793
- U.S. Food and Drug Administration. “Warning Letter: Ava Inc. (721180).” April 14, 2026. https://www.fda.gov/inspections-compliance-enforcement-and-criminal-investigations/warning-letters/ava-inc-721180-04142026
- U.S. Food and Drug Administration. “Warning Letter: Unipack LLC (716621).” December 19, 2025. https://www.fda.gov/inspections-compliance-enforcement-and-criminal-investigations/warning-letters/unipack-llc-716621-12192025
- U.S. Food and Drug Administration. “Warning Letter: Intas Pharmaceuticals Limited (652067).” July 28, 2023. https://www.fda.gov/inspections-compliance-enforcement-and-criminal-investigations/warning-letters/intas-pharmaceuticals-limited-652067-07282023
- U.S. Food and Drug Administration. “Warning Letter: Divi’s Laboratories Ltd. (Unit II) (518434).” April 13, 2017. https://www.fda.gov/inspections-compliance-enforcement-and-criminal-investigations/warning-letters/divis-laboratories-ltd-unit-ii-518434-04132017
- Newton, M.E. and McDowall, R.D. “Data Integrity in the GxP Chromatography Laboratory, Part III: Integration and Interpretation of Data.” LCGC North America 36(5), May 2018, pp. 330-335. https://www.chromatographyonline.com/view/data-integrity-gxp-chromatography-laboratory-part-iii-integration-and-interpretation-data
- Blanc, T., Wätzig, H., and Sänger-van de Griend, C. “Peak Integration of Electropherograms in GMP and Research Labs: Navigating Increased Scrutiny Amid Data Integrity Audits and Inspections.” Electrophoresis 46(11-12), 2025, pp. 653-668. https://pmc.ncbi.nlm.nih.gov/articles/PMC12366258/
- Benchling Open Source. “allotropy: A Python library for converting instrument data into Allotrope Simple Model (ASM).” GitHub repository. https://github.com/Benchling-Open-Source/allotropy
- Allotrope Foundation. “Allotrope Simple Models: JSON Schemas by Technique (json-schemas/adm).” GitLab public repository. https://gitlab.com/allotrope-public/asm/-/tree/main/json-schemas/adm








Your perspective matters—join the conversation.