USD ^
USD ^

The most common GxP data integrity findings in FDA warning letters

Dr. Rachel Benett

Across a number of inspections I have observed over the years, the same pattern tends to surface: an investigator turns to a batch record, finds a corrected value with no initials, no date, and no explanation for the change. That single omission is often enough to turn a routine inspection into a Form 483, and a Form 483 into a warning letter that can cost a site months of remediation and, in some cases, a client relationship. It is precisely the kind of moment that Good Documentation Practice (GDocP) training exists to prevent, because the underlying gap is rarely a manufacturing defect. It is a documentation habit that goes unaddressed for years.

Regulators do not treat documentation as paperwork. FDA’s Data Integrity and Compliance With Drug CGMP guidance and the ALCOA+ framework it endorses (attributable, legible, contemporaneous, original, accurate, plus complete, consistent, enduring, and available) are the lens every inspector now uses to read a batch record, a lab notebook, or an electronic audit trail. EMA has said plainly data integrity is key to protecting public health, and both agencies expect the same underlying discipline: if a firm cannot demonstrate who did what, when, and why, the data behind that action is considered unreliable, regardless of the result it produced. That expectation is precisely what a GDocP course is built to instill.

The article in 10 slidesswipe to explore →

What Data Integrity Findings Actually Look Like in a Warning Letter

Data integrity language appears in the majority of GMP-related warning letters, and the pattern is consistent: a supervisor who initials a page without reading it, a technician who backdates an entry because the correct date “was not important” that day, or a quality unit that closes an investigation without documenting why a discrepancy was probed in the first place.

FDA’s most frequently cited CGMP provision, 21 CFR 211.22(d), covers exactly this gap: written procedures that quality units fail to follow. The second most common citation, 211.192, addresses the requirement to thoroughly investigate any unexplained discrepancy. Both point back to the same root cause, and both are exactly what structured documentation discipline is designed to prevent.

Some of the most damaging citations regulators use in 2026 include:

  • Shared login credentials: when an operator signs an electronic record under another employee’s identity, the record can no longer be attributed to a specific, accountable person.
  • Missing or disabled audit trails: systems configured so that changes to raw data leave no trace are treated as a serious integrity failure, not a technical oversight.
  • Backdated or reconstructed entries: contemporaneous recording is a basic expectation of the standard; documentation created after the fact undermines the entire record.
  • Testing into compliance: repeating a test until a passing result appears, without a documented and justified investigation, is among the findings inspectors treat as most severe.

None of these require malicious intent. A missed step, repeated often enough and never corrected, is enough to turn a routine inspection into a citation.

The ALCOA+ Principles Regulators Are Actually Testing Against

When an inspector pulls a record, they are silently checking it against ALCOA+. Attributable means every entry traces to a specific individual, not an initial that could belong to three different people on a shift. Legible means a crossed-out value must still be readable underneath the correction, never obliterated with correction fluid. Contemporaneous means the entry was made at the time the work happened, not reconstructed from memory at the end of the shift. Original and accurate mean the first, unaltered record is preserved and reflects reality. The “plus” attributes, complete, consistent, enduring, and available, extend that logic to how long records survive and how easily they can be retrieved during an audit.

Teams that have never taken GDocP training tend to treat these as abstract ideals. Teams that have completed structured GDocP training treat them as a daily checklist, which is precisely the difference regulators are looking for when they compare a compliant site to one that is one inspection away from a warning letter.

Where Documentation Breaks Down: Paper and Electronic Records Alike

Data integrity gaps are not limited to legacy paper systems. Electronic batch records, Laboratory Information Management System (LIMS) entries, and validated software can fail the same ALCOA+ tests if the underlying discipline is missing.

When I work with quality units after a citation has already landed, the root cause is almost never the software itself. It is a validated system that nobody trained the team to use the way it was designed to be used, so staff built their own workarounds instead.

This is where GDocP training and training on FDA 21 CFR Part 11 reinforce each other. GDocP teaches the discipline of accurate, attributable recording, while Part 11 governs the electronic systems, audit trails, and electronic signatures that carry that discipline into a validated digital environment. A site that trains on only one of the two is leaving half of its data integrity exposure unaddressed. Treating ALCOA+ as a single framework across both paper and electronic systems is what keeps an inspection from escalating into a warning letter.

FDA guidance is explicit that these expectations, set out under 21 CFR Parts 210, 211, and 212, apply to every firm manufacturing drugs for the US market, regardless of where that manufacturing takes place. EMA’s GMP data integrity guidance mirrors that expectation across the EU. Whether a record lives in a binder or a database, the benchmark for audit-ready documentation does not change.

Building Audit-Ready Documentation with GxP Training’s Good Documentation Practice (GDocP) Course

Good Documentation Practice (GDocP) course cover
Good Documentation Practice (GDocP)

This Good Documentation Practice (GDocP) course was built by a team of Regulatory Affairs Experts with qualifications from Northeastern University, Boston, and walks clients through exactly the habits that separate an audit-ready site from one collecting warning letter citations. It covers how and when to apply GDocP, the different categories of GMP documents, the standards every record must meet, and the practical mechanics of completing forms, batch records, and lab notebooks correctly the first time.

Course Details

  • Duration: 2 hours
  • Skill Level: Regulatory (Professional)
  • Final Exam: Yes
  • Accreditation: Fully CPD/CEU accredited
  • Compliance: 21 CFR Part 11 compliant, traceable certificate

Detailed Curriculum Overview

  • Introduction to Good Documentation Practices
  • Chapter 1: What are Good Documentation Practices?
  • Chapter 2: How and when to apply Good Documentation Practices
  • Chapter 3: Document types (commitment, directive, and record documents)
  • Chapter 4: Good documentation standards (approval, clarity, periodic review, formal presentation, records)
  • Chapter 5: How to complete documentation, including data collection forms and batch records
  • Chapter 6: How to add raw data to forms and lab notebooks
  • Chapter 7: Typical mistakes
  • Chapter 8: How to fix data entry mistakes and omissions
  • Chapter 9: How to date, sign, and mark records
  • Final evaluation

Who Needs This Training?

Quality assurance and quality control professionals are the most obvious audience, since they are the ones who sign off on the very records inspectors pull first, but manufacturing operators and lab technicians need the same grounding because they are the ones actually filling in the batch records and lab notebooks that get scrutinized, and a single uninitialed correction at their level can undo months of upstream validation work. Internal auditors and compliance teams rely on that same foundation to know what a compliant record should look like before an external inspector ever sees it, while regulatory affairs specialists lean on it when they need to defend a submission or respond to an agency request for supporting data. Submission managers, in turn, need that grounding to ensure the documentation package behind a New Drug Application (NDA) or a variation will hold up under review, and QA auditors use it to close Corrective and Preventive Actions (CAPAs) with confidence instead of guesswork. Anyone whose signature, initials, or timestamp will ever appear on a GMP record benefits from structured Good Documentation Practice training before that signature is tested during an inspection.

The Business Case for Documentation Training in the 2026 Market

A warning letter is rarely a single event. It typically triggers a remediation plan, a follow-up inspection, delayed approvals, and, in the worst cases, an import alert that halts revenue from a market overnight. Against that backdrop, the cost of a two-hour GDocP course per employee is negligible next to the six-figure remediation a single warning letter can trigger, which makes it one of the most direct preventive controls a quality organization can put in place. In the 2026 market, where FDA and EMA inspection activity has intensified and data integrity remains a dominant citation category, sites that can show a documented, auditable training program for every employee touching a GMP record are demonstrating exactly the state of control regulators expect. That documentation itself becomes evidence during an inspection: a signed, dated, CPD/CEU-accredited certificate for every team member who has completed Good Documentation Practice (GDocP) training is a benchmark an investigator can check against the very findings they are trained to look for.

Why Choose GxP Training?

Every course is expert-led and developed by regulatory affairs professionals who have sat on the other side of the inspection table, so the content reflects what actually gets cited rather than a generic compliance checklist. Each completion produces a unique, verifiable certificate carrying CPD and CEU accreditation that clients can check through our online certificate verifier and share directly on LinkedIn, giving both the individual and the employer a credential they can point to during an audit. Access runs for twelve months on a self-paced basis, so shift workers and globally distributed teams can complete training around their schedule rather than around a classroom, while managers get progress tracking and HR-ready reporting tools to confirm the whole team is current. Content is refreshed monthly to keep pace with evolving FDA and EMA expectations, and every course is compatible with the Sharable Content Object Reference Model (SCORM) standard, so it drops cleanly into an existing Learning Management System (LMS) without a separate integration project.

The finding that turns a routine inspection into a warning letter is rarely the dramatic one. It is the missed initial, the adjusted date, the discrepancy nobody explained, the same small habits that add up long before fraud ever enters the conversation. What closes that gap is not a new manufacturing process or a larger budget. It is a documentation habit that regulators can trust on sight, and that habit is exactly what structured GDocP training builds into a team before an inspector ever walks through the door.

More news

We might have this course but it's not displayed online. Please type your email and we will get back to you within 24h

No video yet for this course