Where the Revision Stands as of September 2026

Start with the status, because it changes how every later paragraph should be read. The draft Chapter 4 was published for stakeholder consultation on July 7, 2025, together with a revised Annex 11 (Computerised Systems) and a new Annex 22 (Artificial Intelligence). The Commission’s consultation page gave a closing date of October 7, 2025, and the page now shows the consultation as closed with no statement about adoption.1 PIC/S ran the same consultation in parallel, describing the three texts as drafted jointly by the EMA GMP/GDP Inspectors Working Group and the PIC/S Committee to keep the EU and PIC/S guides aligned.4

The Inspectors Working Group’s own 2024 to 2026 work plan set a target of the first quarter of 2026 to provide the Commission with a final text for Chapter 4, in parallel with Annex 11, with the stated purpose of assuring data integrity in the context of GMP. The same plan lists a strategic goal to develop EU-level data integrity guidance by adapting the existing published Q&As into Chapter 4 and Annex 11, in collaboration with WHO and PIC/S.5 That sentence explains a great deal about the draft: much of what looks new in it is the 2016 EMA data integrity Q&A material, promoted from a web page into the Guide.

The most recent public status came from EMA at the ISPE Europe Annual Conference in Copenhagen in April 2026. According to the published conference report, the review of comments on Chapter 4 was complete, the Annex 11 drafting group had classified roughly 2,900 comments and expected to finish its detailed review over the summer, and Annex 22 was heading into a further expert workshop at the end of June.6 Nothing in that report gives a publication date for Chapter 4. Industry associations have had a standing channel into the drafting: ISPE describes itself as one of a 16-association group coordinated by EFPIA that has met with the EMA working group since 2013, proposing topics and position briefs ahead of each meeting,16 so the final wording will reflect that comment traffic as well as the public consultation.

We checked the Commission’s EudraLex Volume 4 page on the day this article was written. It still lists Chapter 4 (Documentation) with a publication date of January 2011, and its latest-updates section has no entry for a revised Chapter 4, Annex 11, or Annex 22.3 Chapter 1 (Pharmaceutical Quality System) is also under revision; its own consultation on quality risk management, knowledge management, and product quality review ran until December 3, 2025.7 Several revised texts are therefore in the pipeline at once, and the Commission may choose to publish them together.

Status, stated plainly. As of September 3, 2026, the revised Chapter 4 is a draft. There is no final text, no publication date, and no date for coming into operation. The 2011 revision was published with a stated deadline for coming into operation (June 30, 2011), and the final revised chapter will almost certainly carry one too, but do not put a date in a project plan until the Commission publishes it. Treat the draft as a reliable signal of direction and an unreliable source of exact wording.

Why write about a draft at all? Because the work it implies is slow, and because most of it is already required by other means. The 2011 Chapter 4 already said documents may exist in hybrid forms and that relationships and control measures must be stated for both hybrid and homogenous systems.2 The EMA data integrity Q&A has said since 2016 that electronic data is the original record and that review based solely on printouts risks excluding un-investigated results.11 A company that finds a gap against the draft has, in most cases, found a gap against expectations inspectors already hold.

What Changed From the 2011 Text

The 2011 chapter gave its reason for revision in one sentence: the sections on generation and control of documentation and on retention had been revised in light of the increasing use of electronic documents.2 The 2025 draft’s reasons-for-changes statement is broader. The Inspectors Working Group and the PIC/S Committee jointly recommended revising the chapter to reflect changes in regulatory and manufacturing environments, to clarify the expectations of regulatory authorities with regard to documentation, and to take account of the related changes to Annex 11.1

9 to 17Pages, 2011 text versus 2025 draft (our count of the two Commission PDFs)12
32 to 85Numbered clauses (4.1 to 4.32 in 2011; 4.1 to 4.85 in the draft)12
12Headings in the draft’s document map, including new sections on data governance, risk management, signatures, and hybrid systems1

The new document map

The 2011 chapter had eight parts: Principle, Required GMP documentation, Generation and control, Good documentation practices, Retention, Specifications, Manufacturing formula and processing instructions, and Procedures and records. The draft reorganizes that into twelve: Principle, Data governance systems, Risk management, General requirements for documentation, Master documents, Generation and control of documentation, Good documentation practice, Signatures in GMP relevant documentation, Retention of documents, Data integrity in documentation, Hybrid systems, and a Glossary.1 Four of those twelve did not exist in any form in 2011: data governance, risk management, signatures, and the glossary. Two more (data integrity in documentation, hybrid systems) existed only as a sentence or two.

A useful way to read the change is that the specific content (what a specification must contain, what a batch processing record must contain) was carried over nearly word for word, while the surrounding framework was rebuilt. The following table maps the two texts.

Topic2011 text2025 draftWhat is new
PrincipleUnnumbered paragraphs4.1 to 4.9Regulated user must determine which legal provisions apply given new technologies, hybrid solutions, and services (4.2); documentation may include photography, video, and audio (4.7); hybrid and outsourced documentation held to the same requirements (4.8)
Data governanceAbsent4.10 to 4.18Entirely new: a data governance system inside the PQS, a six-stage data lifecycle, data criticality and data risk, ownership, residual risk reporting, periodic review of service providers
Risk managementAbsent4.19 to 4.22Entirely new: documented rationale for the extent of data integrity measures; electronic data generation is in scope for Annex 11 validation
Required documentsUnnumbered list4.23 to 4.27Validation Master Plan added as a required master document; technical agreements become “written proof”; hybrid records named as a record type; rule against paper conversion of electronic data (4.26)
Specifications, instructions, batch records4.13 to 4.214.28 to 4.38Largely carried over; additions include electronic code reader checks in packaging, and a cross-reference on AI-supported decisions
Procedures and records4.22 to 4.324.39 to 4.48Data integrity added to the list of required procedures; transport temperature proof at receipt; records available to the QP “at the time of the release decision”
Generation and control4.1 to 4.64.49 to 4.55Applies regardless of technology, hybrid solution, or service; revision histories required for issuance, revision, superseding, and withdrawal; instructions may use pictures, photos, and video; handwritten instructions “discouraged”
Good documentation practice4.7 to 4.94.56 to 4.63True copies where media are not durable; attribution to “the individual or the system”; four named controls for paper raw data; ALCOA++ table
SignaturesAbsent4.64 to 4.75Entirely new: signature policy, defined meaning of each signature, electronic records signed electronically, hybrid signatures to be avoided
Retention4.10 to 4.124.76 to 4.79Periods unchanged; controls must be in validation scope; hosted-service controls justified under an SLA; new documented disposal process
Hybrid systemsOne sentence in 4.14.82 to 4.85Dedicated section: definition, full system description, interface procedures, and a review procedure covering both paper and electronic data

What did not change

Three things stayed put, and they matter for planning. First, the retention periods in 4.77 are the 2011 periods: batch documentation for one year after expiry or five years after Qualified Person certification, whichever is longer, and five years after the last trial for investigational products.1 Those periods come from Directive (EU) 2017/1572, which also requires that electronic systems be validated to show data will be stored appropriately for the anticipated period and that stored data be protected and made readily available in legible form.14 Second, the required contents of the batch processing and batch packaging records are almost unchanged. Third, the definition of a record still includes the raw data used to generate other records, and the regulated user must still define which electronic data are raw data.1

One drafting detail is worth flagging because it shows the text is not final. The glossary defines data governance by listing nine attributes ending in “available,” while Table 1 and the glossary entry for ALCOA++ list ten, adding “traceable.” The glossary also repeats the “Data Risk Assessment” entry. Neither is a substantive problem; both are the kind of thing that gets tidied between draft and final, and a reminder not to quote draft clause numbers in your SOPs.

Data Governance and Risk Management Move Into Documentation

The largest structural change is that Chapter 4 now opens with data governance rather than with a list of document types. Clause 4.10 says that regardless of whether documents are created and managed electronically, on paper, or in hybrid systems, the regulated user should establish a data governance system integral to the pharmaceutical quality system to define, prioritize, and communicate its data integrity risk management activities, and that the arrangements should be documented and reviewed regularly.1

The six-stage data lifecycle

Clause 4.12 lists what the governance system must cover. The lifecycle runs through creation and recording; processing of raw data to reported (derived) data; verification of completeness, consistency, and accuracy of all data, with traceability that allows reconstruction of all processing for derived data; decision making relying on data; retaining, archiving, and retrieval; and retirement or destruction in a controlled manner.1 For a documentation SOP this is a checklist. Most SOPs written against the 2011 chapter cover stages one, two, and five well, cover stage three unevenly, and do not mention stage six at all.

Criticality and risk as the two dials

Clause 4.13 says governance should rely on a risk management approach that considers data criticality (impact on decision making and product quality) and data risk (the opportunity for alteration or deletion, and the likelihood that routine review would detect it).1 The glossary defines both terms. This two-dial model is the same one in the EMA Q&A and in the WHO data integrity guideline,1112 and it is what makes the rest of the chapter scalable: clause 4.21 requires that decisions on the extent of data integrity measures rest on a documented rationale and a documented risk assessment that considers both.1 The practical consequence is that “we do this for everything” and “we do this for nothing” are both weaker answers than “we did this for these records because of this assessment.”

Ownership, residual risk, and the service provider review

Three clauses in the governance section will require new content in most quality systems. Clause 4.15 requires that governance address data ownership throughout the lifecycle. Clause 4.17 requires that risk mitigation measures be reviewed regularly, whether temporary or permanent, and that residual risks be reviewed periodically and communicated to management. Clause 4.18 requires periodic review of service providers’ data management policies and risk control strategies, with a frequency based on the criticality of the service.1 The last one is aimed at hosted document management, cloud archives, and outsourced scanning and storage. It turns a one-time vendor qualification into a recurring review with a documented cadence.

Where the governance clauses came from. The work plan goal was to adapt the existing published Q&As into Chapter 4 and Annex 11.5 The 2016 EMA data integrity Q&A already describes the data lifecycle as spanning IT systems, quality applications, production, analytical, stock management, back-up and archival, and internal and external organizational boundaries including cloud-based applications, and already says that data integrity can be affected at any stage.11 If your organization built its data governance program on that Q&A, the draft chapter will read as familiar. If it did not, the draft is the notice.

Risk management and the Annex 11 hand-off

Clauses 4.19 to 4.22 add the risk management section. Clause 4.20 says the depth of governance and risk management should be justified and commensurate with risks to product quality and patient safety. Clause 4.22 closes the loop with Annex 11: irrespective of the processes used to generate electronic data, they must be included in the qualification or validation requirements for the relevant computerized systems.1 Chapter 4 says what must be true of the record; Annex 11 says how the system that produces it is shown to be fit. The draft Annex 11 was published in the same consultation and is the companion text for anyone reading 4.22.10

Hybrid Records: What the Draft Actually Requires

Hybrid records are not new to Chapter 4. The 2011 text said many documents may exist in hybrid forms, some elements electronic and others paper, and that relationships and control measures for master documents, official copies, data handling, and records need to be stated for both hybrid and homogenous systems.2 What is new is that the draft stops treating hybrid as a neutral option and starts treating it as a state that needs justification, description, and specific controls. The glossary defines a hybrid system as a combination of paper-based and electronic means, and a homogenous system as one that is either paper or electronic, whether on premises or in a cloud service.1

The clause that will bite: 4.26

Clause 4.26 says that to ensure data integrity, data recorded or processed electronically should not be converted to or stored in paper form unless it meets the requirements of the hybrid systems section or the conversion is validated or verified for accuracy.1 Read that against a typical operation: chromatography data printed and stapled into a lab notebook; an electronic batch record printed for QP review; a weigh-station printout taped into a paper batch record; an audit trail report printed once a month and filed. Every one of these is a conversion of electronic data to paper. Under 4.26 each needs either to be governed as part of a described hybrid system or to have its conversion validated or verified.

This is consistent with what the EMA Q&A has said since 2016: for data generated from an electronic system, the electronic data is the original record that must be reviewed before batch release and other GMP decisions, and a review based solely on printouts risks excluding records that contain un-investigated out-of-specification data or other anomalies.11 The draft chapter converts that inspector position into a numbered clause in the Guide.

The dedicated hybrid section: 4.82 to 4.85

The four clauses of the hybrid systems section are short, and each maps to a deliverable.

4.82

Define and identify

Hybrid systems should be clearly defined and identified, and each contributing element validated and controlled according to risk management principles. Deliverable: an inventory of hybrid systems, each with its paper and electronic elements listed and the validation status of each element recorded.1

4.83

Describe the whole system

A detailed description of the entire system should be available, outlining major components, their functions, their interactions, and the controls for data management and integrity. Procedures and records should manage the interface between manual and computerized parts. Deliverable: a system description per hybrid system and an interface procedure.1

4.84

Show the controls work

Quality risk management principles should be followed when assessing, defining, and demonstrating the effectiveness of the control measures applied to the system. Deliverable: a documented risk assessment per hybrid system with evidence that the controls were checked, not just listed.1

4.85

Review both halves

Procedures should manage the review of data generated by hybrid systems and clearly set out the evaluation, approval, and archiving of both electronic and paper-based data. Deliverable: a review procedure that says which reviewer looks at which half, in what order, and where each half is archived.1

Signatures in hybrid systems

The signatures section adds the rule with the most direct effect on hybrid workflows. Clause 4.70 says that if records exist electronically, they should be signed electronically; that the use of a hybrid system should be avoided; and that where signatures exist in parallel on paper and electronically, the regulated user should define which signature is the regulatory-relevant one.1 The ECA Academy’s reading of the draft makes the same point and adds that the permanence of the electronic signature must be maintained over the entire lifetime of the document.8

Notice what 4.70 does not say. It does not prohibit hybrid systems. It says “should be avoided,” which in GMP language means a justified exception is possible, and it then tells you what the exception must contain: a defined regulatory-relevant signature. A quality team that keeps a wet-ink QP signature on a printed release document next to an electronic approval in the batch system has a hybrid signature arrangement. Under the draft, the question an inspector will ask is not “why do you have two” but “which one counts, and where is that written down.”

Hybrid records as a record type

The master documents section (4.27) now names hybrid records explicitly: records can exist as hybrid records combining paper, electronic, or other means, and the completeness and integrity of records, including all relevant raw data and metadata, should be ensured and protected based on risk.1 The metadata reference is the part that catches paper-first thinking. When the electronic half of a hybrid record is the original, its metadata (timestamps, user identities, audit trail entries, instrument settings) is part of the record, and a paper copy that drops it is incomplete. That is the connection to true copies.

True Copies, Signatures, and the Original Record

True copy enters the EU GMP Guide

The 2011 Chapter 4 did not use the term “true copy.” An ECA Academy analysis from 2021 noted that EU GMP referred to official copies and working documents without defining either, that the true-copy concept came from the US regulations and from the WHO, MHRA, and PIC/S data integrity guidance, and that any company using the term had to define it for itself.13 The draft ends that gap. Its glossary defines a true copy as an exact copy of original documentation that preserves the same content, meaning, and attributes of the original, and states that the term is synonymous with certified copy or verified copy.1

Two clauses put the term to work. Clause 4.58 requires that recorded media be durable throughout the retention period and, where that is not feasible, that true copies be generated under a documented system that verifies and records the integrity of the copy. Clause 4.79 requires a documented disposal process ensuring that the correct original records or true copies are disposed of only after the defined retention period.1

For comparison, the WHO guideline on data integrity (TRS 1033, Annex 4) defines a certified true copy as a copy of the original record, on any media, that has been verified by a dated signature or by generation through a validated process to have the same information, including the data that describe the context, content, and structure, as the original.12 The WHO wording is more operational than the draft’s: it says how verification happens (dated signature or validated process) and what “the same information” includes (context, content, structure). US regulation is older and simpler: 21 CFR 211.180(d) allows records to be retained as originals or as true copies such as photocopies, microfilm, microfiche, or other accurate reproductions.15

The test that matters for hybrid records: attributes

The draft’s definition turns on the word “attributes.” A photocopy of a signed paper form preserves the content, meaning, and attributes of that form. A printout of an electronic record preserves the content and perhaps the meaning, but not the attributes: the audit trail, the dynamic ability to re-query or re-integrate, the metadata that says who did what and when. Table 1 in the draft makes the same distinction under “Original”: information originally captured in a dynamic state should remain available in that state. Under “Legible” it says that where the dynamic nature of electronic data is important to the content and meaning of the record, the ability to interact with the data using a suitable application is part of the record’s availability.1

The practical rule. A printout of dynamic electronic data is not a true copy of that data. It can be a controlled working copy, a summary, or a signed attestation of what the reviewer saw, and it can be filed in a hybrid record if the hybrid system is described and the electronic original is retained. What it cannot do is replace the original. Companies that have been retiring electronic records after printing them, or that keep instrument data files only until the paper batch record is closed, are the ones with the largest gap.

The signature policy

The signatures section (4.64 to 4.75) is new in full. Clause 4.67 requires the regulated user to establish a signature policy, with personnel authorized to sign identified by name and bound to the policy. Clause 4.68 requires identification of the records that require a legally binding signature. Clause 4.66 requires that the meaning of a signature (review, approval, responsibility, authorship) be clear and that the data or documents associated with it be identified. Clause 4.74 places the management and control of signatures inside the data governance system, and 4.75 requires the signed data to meet ALCOA++.1

Most companies have a signature list. Fewer have a signature policy in the sense the draft means: a document that says which records need a legally binding signature, what each signature type means, who may apply it, and how the signature stays bound to the record for the whole retention period. Clause 4.65 adds that the signatory should sign with date and time, and that abbreviated signatures (initials) need a defining procedure.1 The date-and-time requirement is another place where paper struggles: paper signatures are usually dated, rarely timed.

Attribution to a system

One small wording change in good documentation practice has a wide reach. The 2011 clause 4.8 said records should be made so that all significant activities are traceable. The draft’s 4.59 says it should be possible to identify the individual or the system that performed the task and when.12 Table 1 repeats this under “Attributable.” A record generated by an automated step is attributable to the system that generated it, which means the system’s identity, version, and configuration at the time become part of what the record must carry. Clause 4.24 makes the same move for artificial intelligence and automatic scripts: accountability for the integrity of records produced or processed by them rests with the regulated user.1

Document Lifecycle, Retention, and Disposal

Lifecycle control of instructions

The generation and control section adds a lifecycle requirement that the 2011 text implied but did not state. Clause 4.54 requires that the issuance, revision, superseding, and withdrawal of all documents be controlled, with revision histories maintained. Clause 4.52 adds that instructions may be supported with pictures, photos, or videos, that data entry formats should be clearly defined, and that instructions should be easily accessible where the described activity is carried out. Clause 4.55 says handwritten instructions are discouraged.1 Together these push toward electronic document management with controlled distribution to the point of use, and they make paper master copies with handwritten annotations harder to defend.

Retention: the periods stay, the controls grow

Clause 4.76 keeps the 2011 requirement that it be clearly defined which record relates to each activity and where it is located, and extends it in four ways. The control methods must be risk-based and must be covered by the validation scope. For electronic recording they must include back-up, restore, and archiving procedures plus physical and logical controls. Where the regulated user relies on hosted services, it is the user’s responsibility to understand, approve, and justify the provider’s control measures on the basis of a service level agreement. And records must be available for review at any time during the retention period, in human-readable form, to all applicable personnel.1

The retention periods in 4.77 and the “retain while the marketing authorization is in force” rule for supporting data in 4.78 are carried over from 2011 with one addition: products derived from human blood or plasma join advanced therapy medicinal products as examples of products with longer legislated retention.1 The underlying legal requirement is Directive (EU) 2017/1572, Article 9, which sets the batch documentation period and requires that electronic systems be validated to show the data will be stored appropriately for the anticipated period, and that stored data be protected against unlawful access, loss, or damage with audit trails maintained.14

Disposal becomes a controlled process

Clause 4.79 is new. It requires a documented process for the disposal of records ensuring that the correct original records or true copies are disposed of only after the defined retention period, measures to reduce the risk of deleting the wrong documents, and controlled access rights for disposal.1 Retirement or destruction is also the sixth stage of the data lifecycle in 4.12. Many organizations have a retention schedule and no disposal procedure; records accumulate because no one is authorized to delete them and no one has written down how to do it correctly. The draft treats an uncontrolled non-deletion as a governance gap in the same way as an uncontrolled deletion.

Archiving defined

The glossary defines archiving as long-term or permanent retention of completed documentation and relevant metadata in its final form for the purpose of reconstructing a process or activity.1 Two words carry the weight: “metadata” and “reconstruction.” An archive that holds PDFs of electronic batch records without the underlying audit trail data may hold the documentation but not the metadata, and may not support reconstruction of what happened. That is the test to apply to any archive design, including the 30-year designs we have discussed elsewhere on this site.

New Technologies and Outsourced Documentation Services

The regulated user decides what applies

Clause 4.2 puts a duty on the regulated user that did not exist in 2011: to determine which legal provisions apply to documentation, considering the new technologies, hybrid solutions, and services in use.1 The glossary’s “type of service” entry names the two cases the drafters had in mind: on-premises IT service, or outsourced hosted (cloud) IT service.1 The clause means that “our vendor is compliant” is not an answer. The regulated user must have worked out, and written down, which requirements attach to each service it uses.

Media beyond paper and screen

Clause 4.7 extends the recognized forms of documentation to other means, giving photography, imagery, video, and audio recordings as examples.1 This is a bigger change than it looks. Video evidence of line clearance, photographs of label reconciliation, and voice-captured observations already exist in many plants without a home in the documentation SOP. Under the draft they are documentation, so they need the same lifecycle controls: attribution, retention, true copies where the media are not durable, and controlled disposal.

Automatic scripts and AI in documentation

Three clauses address automation without reaching into Annex 22’s territory. Clause 4.23 says that reliance on electronic, paper, hybrid, or hosted services for documentation requires compliance with all EU GMP provisions including Annex 11 where decision making in manufacturing (batch release based on in-process controls and process analytical technology, for example) is supported by automatic validation scripts or artificial intelligence, with a pointer to Annex 22. Clause 4.24 assigns accountability for the integrity of records produced or processed by such means to the regulated user. Clause 4.25 requires that such support be included in the pharmaceutical quality system whether on premises or hosted, and adds that electronically created records should enable trend analysis of quality-critical data.1 The batch processing record clause (4.36) repeats the pointer for decisions supported by scripts or AI.1

The trend analysis sentence is easy to skip and hard to satisfy. It means the format in which electronic records are kept should allow quality-critical data to be trended, which rules out storing them only as flat images or PDFs.

Outsourced documentation services

Four separate clauses reach outsourced documentation. Clause 4.8 says the same requirements apply when documentation is outsourced. Clause 4.18 requires periodic review of service providers’ data management policies and risk control strategies at a frequency based on criticality. Clause 4.76 places the burden of understanding, approving, and justifying a hosted provider’s control measures on the regulated user, under a service level agreement. Clause 4.80 requires that documents and records be controlled in a risk-based way regardless of whether they are in house or hosted.1 The technical or quality agreement, meanwhile, is redefined in 4.27 as written proof of agreement between contract giver and acceptor for outsourced activities.1

The EMA Q&A has long held that the responsibility for records integrity through the retention period remains with the manufacturing authorization holder regardless of how many parties are involved, that archiving may be off site under that holder’s responsibility, and that assessment of a service provider’s data governance can be done by on-site audit or desk-based review depending on data criticality and risk.11 The draft adopts that position and adds the cadence.

A workable reading for hosted document systems. Treat each hosted service as a data governance object with four artifacts: a service description that identifies what GMP documentation it holds and which requirements apply (4.2); a quality agreement or SLA that names the provider’s controls and the user’s approval of them (4.76); a periodic review record with a risk-based frequency (4.18); and evidence that back-up, restore, archive, and disposal are within the validation scope (4.76, 4.79). Companies that already run this for their eQMS and LIMS providers will find the draft asks for the same structure, applied more consistently.

What Changes in Practice: Document Control, Batch Record Review, and Archiving

This section translates the clauses into the three quality functions most affected. The intent is not to prescribe; final wording may shift. It is to show where the work is likely to be.

Document control

Document control gains four concrete obligations. It must maintain revision histories covering issuance, revision, superseding, and withdrawal (4.54). It must keep an inventory of documents within the pharmaceutical quality system (4.48, carried over from 2011). It must own the signature policy or at least enforce it at the point of approval (4.67, 4.68). And it must apply the four named controls for paper raw data: control over issuance and use of loose sheets and blank forms, control over issuance of bound and paginated notebooks, control over issuance and reconciliation of sequentially numbered copies of blank forms with authenticity controls, and control that raw data is recorded contemporaneously by permanent means (4.62).1

The paper controls in 4.62 are the draft’s answer to the most common data integrity finding in paper-based operations: uncontrolled blank forms. They read like a PIC/S or MHRA guidance section because that is where they came from. Sites that have not implemented blank form reconciliation will need to, and sites that have will need to show that the reconciliation is documented and that failures are investigated.

Batch record review

The required contents of the batch processing record are unchanged, but three things around it move. First, 4.43 now says all records should be available to the Qualified Person at the time of the release decision, an addition to the 2011 “all records should be available.”12 For hybrid batch records that means the electronic half must be reviewable at release, not retrieved afterward. Second, the hybrid review procedure in 4.85 requires a written process for evaluation, approval, and archiving of both electronic and paper-based data. Third, the rule in 4.26 against unverified conversion of electronic data to paper applies directly to the practice of printing electronic data for review.

There is one relaxation to note. The batch packaging record clause (4.38) says that where there are validated electronic controls in place during packaging, there may be justification for not including the reconciliation of printed packaging materials and bulk product; the 2011 wording said “robust” electronic controls.12 “Validated” is a higher and clearer bar than “robust,” and it is another instance of the draft tying documentation relief to Annex 11 validation status. The same clause adds a record of checks that electronic code readers, label counters, and similar devices are functioning as expected.1

For review-by-exception programs, the note under 4.36 survives: where a validated process is continuously monitored and controlled, automatically generated reports may be limited to compliance summaries and exception or out-of-specification data reports.1 What is new is the cross-reference to the principle clauses for any decision supported by scripts or AI. Review by exception remains available; the prerequisites for it now include the governance and attribution requirements described above.

Archiving

Archiving acquires a definition (final form plus relevant metadata, for reconstruction), a validation requirement (retention controls within validation scope, with back-up, restore, and archiving procedures for electronic records), a hosted-service justification requirement (SLA-based), a disposal procedure requirement, and a true-copy requirement where media are not durable (4.58, 4.76, 4.79, glossary).1 The commentary from ECA Academy points out that raw data remains under-specified in the draft and is likely to generate discussion,8 and that matters here: the archive must hold the raw data the regulated user has defined as such, and 4.27 still requires that all data on which quality decisions are based be defined as raw data.1

One analysis of the draft describes the data governance sections as a complete lifecycle from creation through retirement, with ownership accountability throughout and service provider oversight built in.9 For the archive function that description is the specification: the archive is the last two stages of a lifecycle that somebody owns from the first.

A Gap Assessment a Quality Team Can Run This Quarter

The following approach is built to be run against your current documentation SOPs using the draft as a checklist, while the final text is pending. It produces a list of gaps with an owner and a difficulty rating rather than a compliance score, because a score against a draft is not meaningful. It also front-loads the hybrid inventory, since that is where the longest lead-time work is.

1

Inventory every hybrid record and every conversion to paper

Walk production, QC, warehouse, and QA and list every place electronic data becomes paper or paper becomes electronic: printouts filed in batch records, scanned wet-ink forms, instrument reports stapled to notebooks, printed audit trail reviews, e-signature plus wet-ink combinations. For each, record the electronic original’s location and retention, and whether the conversion is validated, verified, or neither. This is the 4.26 and 4.82 evidence base.

2

Map your documentation SOP set against the draft’s twelve headings

Take the document map in the draft and, for each heading, name the SOP that covers it. Expect blanks under data governance, risk management, signatures, and hybrid systems, and partial coverage under data integrity in documentation. A blank is a gap; a partial is an update.

3

Test the six lifecycle stages on three record types

Pick a batch record, an analytical result, and a deviation record. For each, trace creation, processing to derived data, verification, decision, retention and retrieval, and disposal. Note who owns each stage and whether the stage is written down. Stages five and six usually expose the largest gaps.

4

Write, or find, the signature policy

List the records that require a legally binding signature. For each, state the signature meaning, the authorized roles, whether it is applied on paper or electronically, and where both exist, which one is regulatory-relevant. If this document does not exist, the gap is the document; if it exists, the gap is usually the “which one counts” column.

5

Audit the retention and disposal controls

For each electronic record system, confirm that back-up, restore, and archiving are within a validation scope and that a disposal procedure exists with controlled access. For each hosted service, confirm an SLA or quality agreement names the provider’s controls and that a periodic review is scheduled with a documented frequency.

6

Check the paper raw-data controls

Verify blank form issuance and reconciliation, bound notebook issuance, sequential numbering with authenticity controls, and contemporaneous permanent recording. These four are named in the draft and are already inspected against under existing data integrity guidance.

7

Rate, own, and sequence

Give each gap an owner and a difficulty rating: procedural (write or revise an SOP), technical (change or validate a system), or structural (change how a process runs). Start the structural items now, because they take longest, and hold the procedural items until the final text is published so the clause references are right the first time.

A worksheet to run it with

The table below is a starting worksheet. The clause numbers are the draft’s and will change; the questions will not.

Draft clauseQuestion to ask of your SOPsEvidence that closes the gap
4.2Have we written down which requirements apply to each documentation technology, hybrid solution, and hosted service we use?Applicability statement per system or service
4.10 to 4.13Is there a documented data governance system inside the PQS that uses data criticality and data risk?Governance procedure with a criticality and risk method and a review cadence
4.12 (vi), 4.79Do we have a documented disposal process with controlled access?Disposal SOP, access rights record, disposal log
4.15, 4.80Is data ownership assigned for each record type across the lifecycle?Ownership matrix
4.17Are residual data integrity risks reviewed and reported to management?Management review input with residual risk list
4.18, 4.76Do we periodically review each service provider’s data management policies at a risk-based frequency, and have we approved hosted controls under an SLA?Review schedule, review records, SLA or quality agreement
4.26Is every conversion of electronic data to paper either part of a described hybrid system or validated or verified?Hybrid inventory with conversion status
4.27Have we defined which electronic data are raw data, and do hybrid records protect raw data and metadata?Raw data definition per system; hybrid record specification
4.54Do revision histories cover issuance, revision, superseding, and withdrawal?Document control SOP and system audit trail
4.58Where media are not durable for the retention period, do we generate verified true copies under a documented system?True copy procedure and verification records
4.62Are the four paper raw-data controls in place and reconciled?Blank form logs, notebook issuance logs, reconciliation records
4.64 to 4.75Do we have a signature policy that names records requiring legally binding signatures and defines the regulatory-relevant signature in hybrid cases?Signature policy, authorized signatory list bound by name
4.82 to 4.85For each hybrid system, is there a full description, an interface procedure, a risk assessment showing controls are effective, and a review procedure covering both halves?Per-system description and procedures
What not to do yet. Do not rewrite SOP clause references to the draft’s numbering, do not train staff on “the new Chapter 4” as though it were in force, and do not set an internal compliance date. The draft’s own drafting inconsistencies show it will change. Do the inventory, the lifecycle trace, and the signature policy, because those are right under either text.

Conclusion

The revised Chapter 4 is still a draft, and the honest position for any quality leader is to say so and to plan accordingly. But the draft is not speculative. It is the EMA data integrity Q&A, the WHO and PIC/S data integrity guidance, and a decade of inspection experience with hybrid records, rewritten as numbered clauses of the GMP Guide by the same inspectors who enforce it. The specific wording will change; the expectations will not. A company whose documentation SOPs cannot yet answer where each hybrid record’s electronic original is, which signature counts, who owns each stage of the data lifecycle, and how records are disposed of has gaps against current practice, not only against a future text. The best use of the waiting period is to find those gaps in your own operation while the answer is still yours to design.

Sakara Digital works with pharma and biotech organizations that are getting their documentation and data governance ready for the revised EU GMP texts, including the hybrid inventories, signature policies, and hosted-service reviews the draft Chapter 4 implies. If you are working out where your paper-and-electronic seams are and want an independent perspective on where to start, we are happy to have that conversation.

For Further Reading