EN-GUIDE-08 · PHARMACEUTICAL COMPUTERISED SYSTEMS
Data Integrity, Audit Trail, Backup, Restore & Review Evidence
A value on an HMI, a row in a database or a completed backup job does not by itself prove a complete, consistent and accurate GMP record. Fix the record and system boundary, preserve the first evidence and metadata, reconcile time and interfaces, review relevant audit trails, prove recovery and place the final decision with named system, record and quality owners.
OBSERVABLE TRIGGERS
Conditions that require record-path evidence—not a screen check.
- An HMI, PLC, SCADA, historian, laboratory system, MES or interface shows conflicting values, timestamps, users or batch context.
- Data can be changed, deleted, repeated or exported without a visible reason, reviewer or link to the affected record.
- Shared accounts, unmanaged administrator access, inactive users or role differences obscure who performed an action.
- Clock offset, time-zone handling, daylight-saving rules or sequence resolution prevent reliable event comparison.
- A backup job is green, but restore scope, dependencies, metadata, interfaces or post-restore reconciliation have not been demonstrated.
- Review covers a report or exception list while relevant source data, metadata, audit trail, interface failures or aborted runs remain outside scope.
STOP-WORK CONDITIONS
Hold changes, deletion, reset or return to use when evidence may be lost or misattributed.
System, instrument, record, product, batch, process step, equipment, time window or owner cannot be fixed.
A reset, overwrite, migration, restore, service action or log rotation could obscure source data, metadata or audit trail.
Shared credentials, unknown sessions, unmanaged privileges or absent approval prevent action attribution.
Clock source, offset, zone, sequence resolution or interface delay is unknown and event order would be inferred.
Backup content, restore method, dependencies, licenses, keys, configuration or data reconciliation are incomplete.
Exceptions, deviations, affected batches, restrictions or acceptance authority remain outside the review package.
Protect source records and configuration, maintain the authorized hold, document any unavoidable preservation action and return the next decision to the named site authority. This guide does not authorize access, deletion, data correction, restore, electronic signature, validation approval or batch disposition.
PRE-WORK COLLECTION
Fix the record-generating boundary before asking whether the data are trustworthy.
| Collect | Minimum evidence | Why it matters |
|---|---|---|
| Record identity | Site, system/instrument, record type and ID, product/batch/process, equipment, event window, status and owners | Prevents evidence from different records or batches being merged. |
| Source and metadata | Original entry, raw signal/file, units, method, user, timestamps, sequence, context, calculations and transformations | Supports reconstruction from generation to reported result. |
| Access and audit trail | Accounts, roles, privileges, sessions, administrator actions, relevant create/modify/delete events, reasons and review | Connects actions to authorized identities and exceptions. |
| Interfaces and time | Source/destination tags, queues, acknowledgements, retries, failures, clocks, offsets, zones and sequence resolution | Shows whether transfer or time handling changed meaning or completeness. |
| Backup and restore | Scope, schedule, success evidence, configuration, application/data versions, dependencies, retention, restore method and test result | Separates file existence from recoverable and reconciled operation. |
| Review and decision | Review scope, exception criteria, deviations, affected records/batches, reviewer, restrictions, approval and residual ownership | Makes the accountable final decision visible. |
SIX EVIDENCE GATES
Follow one relevant record from generation to accountable review.
| Gate | Required evidence | Hold when |
|---|---|---|
| 1. Record identity | Record, system, product/batch/process, equipment, time window and owners describe the same activity. | Boundary or responsible owner is missing. |
| 2. Source & metadata | Original or verified true-copy evidence retains context, units, method, user, time and transformations. | Only a transcription, screenshot or unexplained export remains. |
| 3. Identity & time | Unique user/role, authorization, session and clock provenance support attribution and sequence. | Shared access or unreconciled time makes attribution uncertain. |
| 4. Audit trail & interfaces | Relevant changes, deletions, repeats, failures and transfers are reviewed with reasons and affected records. | Relevant exceptions sit outside review scope. |
| 5. Backup & restore | Approved content can be restored with dependencies, metadata and interface/data reconciliation. | Backup success is the only recovery proof. |
| 6. Review & control | Deviations, affected batches, restrictions, validation status, decision and residual owners are recorded. | Technical completion is treated as quality acceptance. |
EIGHT-STEP EVIDENCE PROCEDURE
Test the integrity of the record path without changing the evidence first.
- Fix the record and system identity.
Name the record, source device/application, product/batch/process, equipment, time window, current status and responsible owners.
- Preserve source data and metadata.
Secure the original or controlled true copy, context, units, method, configuration, raw files, logs and export method before resets or corrections.
- Reconcile user, role and privilege.
Map each relevant action to a unique identity, authorized role, session and approval; preserve privileged and administrator activity.
- Establish time provenance.
Record clock source, synchronization state, offset, zone, daylight-saving handling, event resolution and known interface delay.
- Review relevant audit trails and exceptions.
Use an approved, risk-based scope that includes create/modify/delete, reason, repeated or aborted runs and unexplained gaps—not only a final report.
- Trace interfaces end to end.
Compare source and destination identity, value, units, quality, timestamp, acknowledgement, retry, failure and reconciliation evidence.
- Prove backup and restore.
Restore the approved scope in an authorized test boundary and verify configuration, metadata, permissions, dependencies, interfaces and record completeness.
- Review, disposition and hand over.
Connect findings to deviations, affected records/batches, validation status, restrictions, quality decision, as-left state and residual ownership.
EXPERT REVIEW
Questions that prevent a convenient record from becoming unsupported evidence
- Can a reviewer reconstruct who did what, when, why and under which approved method from the retained source and metadata?
- Does the reported result remain linked to the generating instrument, configuration, calculation, transformation and affected batch?
- Are privileged access, administrator actions, repeated runs, aborted sequences and deletions visible to the approved review scope?
- Can events across PLC, SCADA, historian, MES and laboratory systems be ordered without guessing around clock or interface gaps?
- Does recovery prove more than file availability—application/configuration compatibility, users/roles, metadata, interfaces and reconciliation?
- Are technical repair, validated state, record acceptance and batch disposition kept as separate named decisions?
AS-LEFT HANDOVER
Transfer the evidence, limitations and authority that actually remain.
System/instrument, record, product/batch/process, equipment, time window, system owner, record owner and quality authority.
Original/true copy, metadata, user/role, clock evidence, audit trail, interface path, calculations and transformations.
Backup scope, versions, dependencies, restore method, actual test, reconciliation, exceptions and validation status.
Deviations, affected records/batches, restrictions, monitoring, approval, open items and accountable follow-up owners.
The PDF preserves the collection table, six gates, procedure, application limits and handover package.
OFFICIAL PRIMARY REFERENCES
Apply each source only within its jurisdiction and approved site framework.
- eCFR 21 CFR Part 11 — Electronic Records; Electronic Signatures United States regulatory text; confirm scope and predicate-rule applicability.
- FDA — Data Integrity and Compliance With Drug CGMP United States final guidance for drugs, including biologics.
- European Commission — EU GMP Annex 11 Computerised Systems European Union GMP computerised-systems guidance; confirm the current Volume 4 publication.
- NIST SP 800-82 Rev. 3 — Guide to OT Security United States cybersecurity guidance, not a pharmaceutical validation or batch-release standard.
Confirm the country, predicate rules, product authorization, pharmacopoeia, AHJ, site quality system, approved SOPs, validation/qualification plan, data-retention schedule, cybersecurity policy, OEM support and qualified reviewers. This page supplies no universal review frequency, retention duration, validation acceptance value or batch-release authority.
RELATED SCOPE