Independent and not affiliated with the FDA, MHRA, ISPE, PDA, or any agency. Get the appgoutham@madhadi.com
madhadi.comData Integrity & GxP Quality
Browse all topics → Articles Templates & Procedures Learning paths GlossaryScenariosToolsRegulatory ReferencesLearning PathsTopics About Start here
Checklist Plug-and-play starting point Data Integrity

Checklist: Multi-Site and CDMO Data Contribution Readiness for a Marketing Application

A plug-and-play checklist confirming every site, clinical manufacturing facility, and contract organization contributing data to a BLA or NDA is named correctly, GMP-qualified, pre-submission audited, and its data integrity controls verified, before that site's data is relied on in the filing, with a filled specimen and the regulations behind it.

Document type: Checklist

Read and copy the template below into your own quality system. It is a generic starting point for your own internal use, provided as is, with no warranty; see the Terms and License. Adopting it does not by itself create compliance.

This is a ready-to-use checklist for confirming that every site contributing CMC data to a marketing application, an internal manufacturing site, a clinical manufacturing facility, a contract testing laboratory, or a CDMO, is ready to have its data relied on in the filing. It is distinct from a general pre-approval inspection readiness checklist: this one is scoped to the specific question of whether a given contributing site’s data belongs in the submission at all, and whether the sponsor has actually verified it rather than accepted a summary certificate. Run it per site, well before the target filing date, because a gap found here cannot usually be fixed in the final months. Replace every <<FILL: ...>> placeholder and mark each item Pass, Fail, or N/A with evidence. A filled specimen follows. This is educational reference content, not legal or regulatory advice.

FieldEntry
Checklist number<<FILL: FORM-ID>>
Product / application<<FILL>>
Contributing site<<FILL: site name, location, role, e.g. API manufacture, drug product fill/finish, stability testing>>
Internal, clinical, or CDMO<<FILL>>
Completed by<<FILL>>
Date<<FILL>>

Section A, Site identification and application status

#ItemP/F/NAEvidenceOwner / due
A1The site is correctly named, with its function, in the application (facility diagrams, 3.2.A.1 or equivalent)<<FILL>><<FILL>><<FILL>>
A2The site holds the appropriate GMP status (licensed, registered, or otherwise qualified) for the work it performed on submission-cited material<<FILL>>
A3The site’s role and scope match what is described in the quality or technical agreement<<FILL>>
A4Any change in the site’s use (added scope, added product, changed process step) since the last qualification is captured in change control<<FILL>>

Section B, Pre-submission audit and quality agreement

#ItemP/F/NAEvidenceOwner / due
B1A pre-submission GMP and data integrity audit of this site has been completed within the program’s defined revalidation window<<FILL>><<FILL>><<FILL>>
B2All findings from that audit are dispositioned, with High-severity findings closed or carrying a QA-approved justification<<FILL>>
B3The quality or technical agreement states explicit data integrity expectations (audit trail retention, raw data access, notification of DI-relevant findings) rather than generic quality language<<FILL>>
B4The agreement gives the sponsor a contractual right to access raw data and audit trails for submission-cited results, not only summary reports<<FILL>>

Section C, Data integrity verification at the site

#ItemP/F/NAEvidenceOwner / due
C1The systems the site used to generate submission-cited data (CDS, LIMS, MES, or equivalent) are confirmed validated for the period the data was generated<<FILL>><<FILL>><<FILL>>
C2Audit trails on those systems were enabled and reviewed for the period the submission-cited data was generated<<FILL>>
C3A risk-based sample of the site’s own submission-cited results has been traced to raw data by the sponsor’s own team, not accepted from the site’s summary alone<<FILL>>
C4No submission-cited data from this site was generated under a shared or generic system login<<FILL>>
C5Any known data integrity gap at this site is self-identified, risk-assessed, and under a dated remediation plan<<FILL>>

Section D, Data handoff and ongoing oversight

#ItemP/F/NAEvidenceOwner / due
D1The method by which the site’s data reaches the sponsor’s system of record is verified (validated interface, checksum, or a documented manual-transcription check), not an unverified retype<<FILL>><<FILL>><<FILL>>
D2A named sponsor contact owns this site’s data readiness through filing and through the pre-license or pre-approval inspection window<<FILL>>
D3A contingency exists if this site becomes unavailable, closes, or loses accreditation before the inspection (data export, retained copies, an alternate qualified site)<<FILL>>
D4The site is on the program’s standing audit schedule for ongoing oversight, not audited once and then left unmonitored until the next filing<<FILL>>

Acceptance criteria

  • Every item is Pass or a justified N/A, or carries a Fail with a named owner and a due date well ahead of the target filing date.
  • Section C is backed by the sponsor’s own produced verification evidence for a risk-based sample of the site’s results, not the site’s self-report alone.
  • Any known data integrity gap at the site is self-identified with a dated remediation plan, never left to be found by the site’s own audit alone or by an investigator.
  • This checklist is completed and Pass for every contributing site before that site’s data is treated as filing-ready.

Signoff

RoleNameSignatureDate
Program / project management<<FILL>>
Quality Assurance<<FILL>>
CMC regulatory lead<<FILL>>

References

21 CFR 211.22, 211.34 (quality unit responsibilities extending to contracted operations). FDA guidance, Contract Manufacturing Arrangements for Drugs: Quality Agreements (Nov 2016, final). FDA Data Integrity and Compliance With Drug CGMP, Questions and Answers (2018). 21 CFR Part 11 (electronic records and signatures), for the audit trail and access items in Section C.

Confirm the current version of each reference before issue.


Filled specimen

A partial completed checklist for an example contract testing laboratory running stability for a biologic drug product.

#ItemP/F/NAEvidenceOwner / due
A1Site correctly named in the applicationPassFacility diagram rev. 3, 3.2.A.1-
A2Site holds appropriate GMP statusPassCurrent site GMP certificate, verified against agency database-
B1Pre-submission audit completedPassAudit report QA-2026-014, conducted 14 months before target filing-
B2Audit findings dispositionedFailOne High-severity finding (audit trail review gap) still openM. Chen, due 30 Sept
C1Systems validated for the data periodPassValidation summary confirmed for CDS and LIMS in use during the study-
C3Risk-based sample traced by sponsor’s own teamPass8 of 24 time-point results traced to raw data, all intact-
D3Contingency if site becomes unavailableFailNo documented contingency; raw data export not yet testedQA Program Lead, due 15 Oct

Here B2 is the item that matters most: a pre-submission audit happened, which is good, but a High-severity finding from that audit was still open, which means the site was not actually ready even though the audit box was technically checked. D3 is the kind of gap that looks theoretical until a site loses accreditation or closes eighteen months before filing; testing the export now, while there is time, is cheap insurance against something that is very expensive to discover late.

Common inspection findings this checklist prevents

  • A site named in the application that was never independently GMP-confirmed by the sponsor.
  • A pre-submission audit that happened on schedule but whose findings were never closed before the data was relied on.
  • Submission-cited data from a contract site accepted on a summary certificate alone, with no sponsor-side trace to raw data.
  • No contingency plan when a contributing site becomes unavailable between the data-generation period and the inspection.

How to adapt this checklist

  1. Run one copy of this checklist per contributing site, not one combined checklist for the whole program.
  2. Set the audit and remediation timelines against your actual target filing date; items found late in this checklist are, by definition, found too late to fix comfortably.
  3. Where a site contributes more than one data type (for example, an API site that also does stability), confirm Section C is completed separately for each data type it generates.
  4. Feed every Fail into the program’s tracked action list alongside the pre-BLA audit defect log, so site-level gaps and result-level gaps are visible in one place.
  5. Confirm every regulation in the references against the current published version before issue.
Use madhadi.com as an app Full screen, works offline, one tap from your home screen.