Independent and not affiliated with the FDA, MHRA, ISPE, PDA, or any agency. Get the appgoutham@madhadi.com
madhadi.comData Integrity & GxP Quality
Browse all topics → Articles Templates & Procedures Learning paths GlossaryScenariosToolsRegulatory ReferencesLearning PathsTopics About Start here
Checklist Plug-and-play starting point Manufacturing Automation

Checklist: Shop-Floor Data Integrity Assessment

A ready-to-use walkthrough checklist for assessing data integrity across manufacturing automation, MES/EBR, SCADA, DCS, PLCs, historians, interfaces, and time synchronization, mapped to the gaps inspectors actually find, with pass/fail/NA and a filled specimen.

Document type: Checklist

Read and copy the template below into your own quality system. It is a generic starting point for your own internal use, provided as is, with no warranty; see the Terms and License. Adopting it does not by itself create compliance.

The lab gets scrutinized first and cleans up first; then an inspector walks onto the floor and the automation gaps become visible. This checklist walks the shop floor the way an inspector does, layer by layer, and maps each item to the data integrity gaps that recur in inspections and warning letters. Use it for internal self-inspection before someone external does it for you. Mark each item Pass, Fail, or N/A with a note; every Fail becomes a remediation action with an owner. Replace the <<FILL: ...>> placeholders where system specifics belong. A filled specimen extract follows. Verify each cited regulation against the current source before you rely on it.

How to use

  • Walk it per system or per line, not once for the whole plant; the gaps live in specific systems.
  • Prefer evidence over assertion. “Show me” beats “we do.” Ask an operator to log in; pull a real correction; read a real audit trail.
  • Every Fail gets an owner and a Remediate/Replace/Compensate decision, consistent with the legacy-system decision path.
  • Score the walk with the summary at the end so trends across lines are visible.

Section 1: System inventory and criticality

#ItemRefPass/Fail/NANote
1.1An inventory exists of all floor automation systems, organized by ISA-95 level, with owner and validation statusAnnex 11
1.2Each system has a documented GxP criticality tied to how its record feeds a quality decision211.68
1.3No GxP system is missing from the inventory or mis-flagged as non-GxPAnnex 11
1.4The historian is included, not omitted as “infrastructure”Part 11

Section 2: MES / EBR

#ItemRefPass/Fail/NANote
2.1Every operator uses an individual account; no shared “production” login211.188, Part 11
2.2A correction retains the original value, records the new value, reason, and approver211.194, Part 11
2.3The system enforces critical-step sequence and blocks skip-and-backfill211.188
2.4An aborted or partial batch still produces a reviewable record211.188
2.5Master batch records and configuration are under change control; the version used for a lot is traceableAnnex 11
2.6The MES audit trail and the assembled EBR tell a consistent storyPart 11

Section 3: SCADA / HMI and DCS

#ItemRefPass/Fail/NANote
3.1Access events, configuration changes, and alarm acknowledgments are audit-trailed with user identityPart 11
3.2Individual role-based accounts at the HMI; no shift-wide shared login (check the night shift)Part 11
3.3Alarm history cannot be edited or acknowledged retrospectively without a flagAnnex 11
3.4Setpoint, recipe, and alarm-limit changes on the DCS are audit-trailed with old and new values211.68
3.5Configuration rights are separated from monitoring rightsPart 11

Section 4: PLCs and compensating controls

#ItemRefPass/Fail/NANote
4.1For any PLC controlling a critical parameter with no audit trail, compensating controls are documented and current211.68
4.2Physical access to controllers is restricted with documented key/access custodyPart 11
4.3The approved configuration baseline is held externally and periodically verified against the running configAnnex 11
4.4Critical setpoints are write-protected during a batch211.68

Section 5: Historian and archive

#ItemRefPass/Fail/NANote
5.1The full process record for one batch can be queried back in a readable formPart 11
5.2Compression/deadband settings are qualified to preserve GxP-significant points, including transientsAnnex 11
5.3Stored values cannot be edited without an audit trail; bulk-edit utilities are controlledPart 11
5.4Backups run and a restore has actually been testedAnnex 11

Section 6: Interfaces and time synchronization

#ItemRefPass/Fail/NANote
6.1A data-flow map exists for critical values, showing every hop and transformationAnnex 11
6.2Interface transformations (units, rounding, time zone) are specified and verifiedPart 11
6.3A failed or partial transfer alarms rather than failing silently; buffering preserves timestamp and orderAnnex 11
6.4Every GxP system is synchronized to a common time source; drift is monitoredPart 11
6.5Who can change a system clock is controlledPart 11

Section 7: Review and governance

#ItemRefPass/Fail/NANote
7.1Batch review includes audit-trail review; “no exceptions” is not treated as “no review”Annex 11
7.2Review-by-exception rules are validated and change-controlledPIC/S PI 041
7.3No orphaned data on engineering laptops or local drives outside the controlled recordPart 11
7.4Test and production are separated; recipe changes are not tested in the live systemAnnex 11

Scoring summary

SectionItemsPassFailN/AHighest-risk open gap
1 Inventory4<<FILL>><<FILL>><<FILL>><<FILL>>
2 MES/EBR6<<FILL>><<FILL>><<FILL>><<FILL>>
3 SCADA/DCS5<<FILL>><<FILL>><<FILL>><<FILL>>
4 PLC4<<FILL>><<FILL>><<FILL>><<FILL>>
5 Historian4<<FILL>><<FILL>><<FILL>><<FILL>>
6 Interfaces/time5<<FILL>><<FILL>><<FILL>><<FILL>>
7 Review/governance4<<FILL>><<FILL>><<FILL>><<FILL>>

Signoff

RoleNameSignatureDate
Assessor<<FILL>>
Area owner<<FILL>>
QA<<FILL>>

References

21 CFR 211.68, 211.188, 211.194; 21 CFR Part 11. EU GMP Annex 11 (computerized systems); Chapter 4 (documentation). FDA Guidance, Data Integrity and Compliance With Drug CGMP; PIC/S PI 041.

Confirm the current version and clause numbers of each reference before issue.


Filled specimen

An extract from a walk of one sterile fill line, showing how Fails convert to actions.

#ItemResultNote / action
2.1Individual MES accountsPassVerified two operators, entries attributed correctly
3.2No shared HMI loginFailNight-shift HMI uses a shared “line1” login. Action: enable individual accounts, interim shift logbook tying named operators to activity. Owner: Automation Eng. Remediate by Q3.
4.1PLC compensating controlsPassAutoclave PLC has documented compensating controls, baseline verified last month
5.2Historian compression qualifiedFailDeadbands set at commissioning for storage, never qualified against process precision. Action: qualify deadbands, lock under change control. Owner: Plant IT.
6.4Time synchronizationFailSCADA server drifting ~6 min vs MES. Action: bring onto NTP, qualify as a system attribute. Owner: Plant IT.

Three Fails, each with an owner and a decision. The shared night-shift login carries an interim compensating control (the logbook) while the technical fix lands, which is exactly the managed posture an inspector accepts, versus a gap nobody owns.

Common inspection findings this checklist catches early

  • Shared HMI logins surviving on the night shift after day shift moved to individual accounts.
  • Corrections that overwrite the original value in the EBR.
  • Historian compression tuned for disk space, quietly dropping the transient that proves a limit was or was not breached.
  • Clock drift across systems treated as cosmetic until an investigation cannot order events.
  • Audit trail present but never reviewed at batch review.

How to adapt this checklist

  1. Add rows for site-specific systems and the gaps your own deviations have surfaced.
  2. Walk it per line and per system; aggregate the scoring to see where risk concentrates.
  3. Convert every Fail to an action with an owner and a Remediate/Replace/Compensate decision.
  4. Feed the results into your data integrity gap assessment and inspection-readiness program.
  5. Confirm the referenced regulations against their current published versions before issue.
Use madhadi.com as an app Full screen, works offline, one tap from your home screen.