This is a ready-to-use checklist for one archive retrieval test, run against a real archived record on the schedule set in the records retention, archival, and retrieval verification SOP. It turns “we can retrieve archived records” from an assertion into a timed, evidenced exercise against an actual file, so a gap in the archive index, the format, or the metadata is found by the organization rather than by an inspector asking for a ten-year-old batch record. Replace every <<FILL: ...>> placeholder, set your document numbers, and route the checklist through your normal document control. A filled specimen follows. This is general guidance to adapt and verify, not legal or regulatory advice; confirm each cited regulation against the current source before you rely on it.
The rule that shapes this checklist: request the record the way a real requester would, using only the identifiers they would realistically have. Locating a record because you already know exactly where the file sits defeats the purpose of the test.
Document control header
| Field | Entry |
|---|---|
| Document title | Archive Retrieval and Readability Test Checklist |
| Document number | <<FILL: CL-ID, e.g. CL-QA-041-01>> |
| Parent SOP | <<FILL: SOP-ID for records retention, archival, and retrieval verification>> |
| Version | <<FILL: version, e.g. 1.0>> |
| Effective date | <<FILL: effective date>> |
| Document owner | <<FILL: role, e.g. Head of Quality Assurance>> |
| Applies to | <<FILL: archives / systems in scope>> |
When to use this checklist
Run it once per archive, per scheduled retrieval test, using the frequency set for that archive in the parent SOP. Run it also whenever an archive’s platform, hosting, format, or index changes, and after any decommissioning project hands a new archive into service, before that archive is relied on for the first time.
Before you start
| Item | Where it comes from |
|---|---|
| The archive’s name, location, and index reference | Archive inventory or the parent SOP’s archive record |
| A real record to request, selected without looking up its exact file location first | Pick a batch, sample, subject, or study number from a real business record (a batch list, a sample log) |
| The raw data definition for the record type under test | <<FILL: reference to the raw data definition, e.g. the system's validation package>> |
| A stopwatch or timestamped request log | <<FILL>> |
| Read access to the archive as an ordinary requester would have it, not administrator access | <<FILL: system / role>> |
How to complete
- Enter the test identification block.
- Work sections A to E in order. Do not open the record before completing section A; the point of section A is to test whether the identifiers alone are enough to find it.
- Mark each item Pass, Fail, or NA. NA requires a reason on the same line.
- Any Fail is logged in the finding log and routed for remediation. Continue the remaining items so the full picture is captured.
- Complete the timing block and the signoff.
Test identification
| Field | Entry |
|---|---|
| Archive under test | <<FILL>> |
| Record requested (identifiers only, as a requester would supply them) | <<FILL>> |
| Record type and applicable raw data definition | <<FILL>> |
| Requester (performing the test) | <<FILL>> |
| Test date | <<FILL>> |
| Reviewer | <<FILL>> |
Section A: locate
| # | Check | Pass | Fail | NA | Evidence or comment |
|---|---|---|---|---|---|
| A1 | The archive index accepted a realistic identifier (batch, lot, sample, subject, or study number and date range) without needing an internal file path | ||||
| A2 | Exactly one record, or a clearly identified set, matched the search; the search did not return an ambiguous or overly broad result | ||||
| A3 | The person performing the search had only ordinary requester access, not administrator or IT access | ||||
| A4 | The search did not require knowledge unique to the person who built the archive (an undocumented naming convention, a folder structure known only informally) |
Section B: open
| # | Check | Pass | Fail | NA | Evidence or comment |
|---|---|---|---|---|---|
| B1 | The record opened without needing software, a license, or a version that is not currently available to the requester | ||||
| B2 | If the record is dynamic, the archive provided the processing function (reprocessing, requerying) rather than only a flat view | ||||
| B3 | No error, corruption warning, or partial-file message appeared on open |
Section C: completeness and legibility
| # | Check | Pass | Fail | NA | Evidence or comment |
|---|---|---|---|---|---|
| C1 | The record matches the raw data definition for its type: all expected components are present | ||||
| C2 | The record content is legible: text is readable, numeric values are not truncated, images or chromatograms render correctly | ||||
| C3 | Metadata is present: user or operator attribution, timestamp, instrument or system identifier, and processing parameters where applicable | ||||
| C4 | The audit trail is present, continuous, and readable for the record’s active period | ||||
| C5 | Where the record was migrated from a retired system, the migrated version matches the source values on spot-check against any independently retained reconciliation evidence |
Section D: timing
| # | Check | Pass | Fail | NA | Evidence or comment |
|---|---|---|---|---|---|
| D1 | Request-to-located time was recorded | ||||
| D2 | Located-to-open-and-readable time was recorded | ||||
| D3 | Total elapsed time is within the timeframe your procedure states you would need to produce a record during an inspection |
Finding log
Record every Fail. One row per finding.
| Item # | What was observed | Severity (see below) | Immediate action | Deviation / CAPA reference | Notified to, date |
|---|---|---|---|---|---|
<<FILL>> | <<FILL>> | <<FILL>> | <<FILL>> | <<FILL>> | <<FILL>> |
Severity guide
| What was found | Severity | Action |
|---|---|---|
| Record located and read correctly, but slower than the target timeframe | Minor | Log and trend; consider index or process improvement |
| Record located but a metadata element or the audit trail is missing or unreadable | Major | Deviation; assess whether other records in the same archive share the gap |
| Record could not be located using realistic identifiers | Major | Deviation; fix the index; re-test |
| Record could not be opened at all (format, license, or corruption) | Critical | Escalate immediately; assess the full scope of records in the same format or batch; do not close as a routine deviation until scope is known |
| Record opened but content does not match the raw data definition or reconciliation evidence | Critical | Escalate as a potential data integrity event per <<FILL: SOP-ID for data integrity events>> |
Timing and disposition
| Field | Entry |
|---|---|
| Request time | <<FILL>> |
| Located time | <<FILL>> |
| Opened and readable time | <<FILL>> |
| Total elapsed time | <<FILL>> |
| Overall outcome | Pass / Pass with minor finding / Fail |
| Requester (name, signature, date) | <<FILL>> |
| Reviewer / QA approval (name, signature, date) | <<FILL>> |
Acceptance criteria
- The record was located using only realistic requester-level identifiers and ordinary access.
- The record opened without error and, if dynamic, retained its processing function.
- The record is complete against its raw data definition, legible, and carries its metadata and audit trail.
- Total elapsed time is recorded and compared against the inspection-readiness timeframe in your procedure.
- Every Fail is logged, classified by severity, and routed to remediation before the archive is relied on again for that record type.
References
21 CFR 211.180(c) (records readily available for inspection). 21 CFR Part 11 (electronic records, retrievability and readability over the retention period). EU GMP Annex 11 (Computerised Systems) and EU GMP Chapter 4 (Documentation). MHRA GxP Data Integrity Guidance and Definitions (March 2018). PIC/S PI 041, Good Practices for Data Management and Integrity.
Confirm the current version and clause numbers of each reference before issue.
Filled specimen
The following shows the checklist completed for an example archive of laboratory raw data migrated from a retired chromatography data system. Company, system, and numbers are illustrative.
Test identification
| Field | Entry |
|---|---|
| Archive under test | Legacy CDS archive ARC-QC-04 |
| Record requested | Batch A-1187, assay results, March 2019 |
| Record type | Chromatography raw data, dynamic |
| Requester | J. Alvarez (IT), acting as an ordinary requester |
| Test date | 14 July 2026 |
| Reviewer | R. Gomez (QA) |
Selected item results
| # | Result | Evidence or comment |
|---|---|---|
| A1 | Pass | Batch number and 2019 date range located the record set without a file path |
| A2 | Pass | One matching record set of 8 injections returned |
| A3 | Pass | Search performed with standard read access |
| B1 | Pass | Opened in the retained, licensed read-only application instance |
| B2 | Pass | Reprocessing function available in the retained instance |
| C1 | Pass | Chromatogram, integration, method, sequence, and audit trail all present |
| C2 | Pass | Legible, chromatogram renders correctly |
| C3 | Pass | Instrument ID, operator, and timestamps present |
| C4 | Pass | Audit trail continuous for the acquisition period |
| C5 | Pass | Spot-checked against migration reconciliation record MIG-CDS-014, values match |
| D1 to D3 | Pass | Located in 4 minutes, opened and readable within 1 additional minute, total 5 minutes, within the stated inspection timeframe |
Disposition
| Field | Entry |
|---|---|
| Total elapsed time | 5 minutes |
| Overall outcome | Pass |
| Requester | J. Alvarez, signed, 14 July 2026 |
| QA approval | R. Gomez, signed, 15 July 2026 |
What makes this specimen useful is not only that it passed, but that the test was run the way a real requester would run it: by batch number and date, on ordinary access, without a shortcut to the file location. A test performed by the person who built the archive, searching by the internal path they already know, would not have exercised the index at all.
Common inspection findings this checklist prevents
- An archive that has never had a retrieval attempted against it before an inspector’s request became the first real test.
- A record technically present in the archive but locatable only by someone who already knows exactly where it sits.
- A dynamic record archived as a flat export, discovered only when a challenged result needs reprocessing.
- Metadata or audit trail missing from an archived record, discovered years after the source system was retired and cannot be reconstructed.
- No record of how long retrieval actually takes, so an inspection request is the first time anyone learns it takes days rather than minutes.
How to adapt this checklist
- Set your document number and point the parent SOP field at your real retention, archival, and retrieval procedure.
- Set your inspection-readiness timeframe in section D from your own procedure rather than assuming a number.
- If the archive spans multiple record types with different raw data definitions, select a representative record from each type across the test cycle rather than the same type every time.
- Where an archive was created by a decommissioning project, run the first test for that archive as part of decommissioning closure, not on the next routine cycle.
- Confirm every regulation in the references section against the current published version before issue.