The lab gets scrutinized first and cleans up first; then an inspector walks onto the floor and the automation gaps become visible. This checklist walks the shop floor the way an inspector does, layer by layer, and maps each item to the data integrity gaps that recur in inspections and warning letters. Use it for internal self-inspection before someone external does it for you. Mark each item Pass, Fail, or N/A with a note; every Fail becomes a remediation action with an owner. Replace the <<FILL: ...>> placeholders where system specifics belong. A filled specimen extract follows. Verify each cited regulation against the current source before you rely on it.
How to use
- Walk it per system or per line, not once for the whole plant; the gaps live in specific systems.
- Prefer evidence over assertion. “Show me” beats “we do.” Ask an operator to log in; pull a real correction; read a real audit trail.
- Every Fail gets an owner and a Remediate/Replace/Compensate decision, consistent with the legacy-system decision path.
- Score the walk with the summary at the end so trends across lines are visible.
Section 1: System inventory and criticality
| # | Item | Ref | Pass/Fail/NA | Note |
|---|---|---|---|---|
| 1.1 | An inventory exists of all floor automation systems, organized by ISA-95 level, with owner and validation status | Annex 11 | ||
| 1.2 | Each system has a documented GxP criticality tied to how its record feeds a quality decision | 211.68 | ||
| 1.3 | No GxP system is missing from the inventory or mis-flagged as non-GxP | Annex 11 | ||
| 1.4 | The historian is included, not omitted as “infrastructure” | Part 11 |
Section 2: MES / EBR
| # | Item | Ref | Pass/Fail/NA | Note |
|---|---|---|---|---|
| 2.1 | Every operator uses an individual account; no shared “production” login | 211.188, Part 11 | ||
| 2.2 | A correction retains the original value, records the new value, reason, and approver | 211.194, Part 11 | ||
| 2.3 | The system enforces critical-step sequence and blocks skip-and-backfill | 211.188 | ||
| 2.4 | An aborted or partial batch still produces a reviewable record | 211.188 | ||
| 2.5 | Master batch records and configuration are under change control; the version used for a lot is traceable | Annex 11 | ||
| 2.6 | The MES audit trail and the assembled EBR tell a consistent story | Part 11 |
Section 3: SCADA / HMI and DCS
| # | Item | Ref | Pass/Fail/NA | Note |
|---|---|---|---|---|
| 3.1 | Access events, configuration changes, and alarm acknowledgments are audit-trailed with user identity | Part 11 | ||
| 3.2 | Individual role-based accounts at the HMI; no shift-wide shared login (check the night shift) | Part 11 | ||
| 3.3 | Alarm history cannot be edited or acknowledged retrospectively without a flag | Annex 11 | ||
| 3.4 | Setpoint, recipe, and alarm-limit changes on the DCS are audit-trailed with old and new values | 211.68 | ||
| 3.5 | Configuration rights are separated from monitoring rights | Part 11 |
Section 4: PLCs and compensating controls
| # | Item | Ref | Pass/Fail/NA | Note |
|---|---|---|---|---|
| 4.1 | For any PLC controlling a critical parameter with no audit trail, compensating controls are documented and current | 211.68 | ||
| 4.2 | Physical access to controllers is restricted with documented key/access custody | Part 11 | ||
| 4.3 | The approved configuration baseline is held externally and periodically verified against the running config | Annex 11 | ||
| 4.4 | Critical setpoints are write-protected during a batch | 211.68 |
Section 5: Historian and archive
| # | Item | Ref | Pass/Fail/NA | Note |
|---|---|---|---|---|
| 5.1 | The full process record for one batch can be queried back in a readable form | Part 11 | ||
| 5.2 | Compression/deadband settings are qualified to preserve GxP-significant points, including transients | Annex 11 | ||
| 5.3 | Stored values cannot be edited without an audit trail; bulk-edit utilities are controlled | Part 11 | ||
| 5.4 | Backups run and a restore has actually been tested | Annex 11 |
Section 6: Interfaces and time synchronization
| # | Item | Ref | Pass/Fail/NA | Note |
|---|---|---|---|---|
| 6.1 | A data-flow map exists for critical values, showing every hop and transformation | Annex 11 | ||
| 6.2 | Interface transformations (units, rounding, time zone) are specified and verified | Part 11 | ||
| 6.3 | A failed or partial transfer alarms rather than failing silently; buffering preserves timestamp and order | Annex 11 | ||
| 6.4 | Every GxP system is synchronized to a common time source; drift is monitored | Part 11 | ||
| 6.5 | Who can change a system clock is controlled | Part 11 |
Section 7: Review and governance
| # | Item | Ref | Pass/Fail/NA | Note |
|---|---|---|---|---|
| 7.1 | Batch review includes audit-trail review; “no exceptions” is not treated as “no review” | Annex 11 | ||
| 7.2 | Review-by-exception rules are validated and change-controlled | PIC/S PI 041 | ||
| 7.3 | No orphaned data on engineering laptops or local drives outside the controlled record | Part 11 | ||
| 7.4 | Test and production are separated; recipe changes are not tested in the live system | Annex 11 |
Scoring summary
| Section | Items | Pass | Fail | N/A | Highest-risk open gap |
|---|---|---|---|---|---|
| 1 Inventory | 4 | <<FILL>> | <<FILL>> | <<FILL>> | <<FILL>> |
| 2 MES/EBR | 6 | <<FILL>> | <<FILL>> | <<FILL>> | <<FILL>> |
| 3 SCADA/DCS | 5 | <<FILL>> | <<FILL>> | <<FILL>> | <<FILL>> |
| 4 PLC | 4 | <<FILL>> | <<FILL>> | <<FILL>> | <<FILL>> |
| 5 Historian | 4 | <<FILL>> | <<FILL>> | <<FILL>> | <<FILL>> |
| 6 Interfaces/time | 5 | <<FILL>> | <<FILL>> | <<FILL>> | <<FILL>> |
| 7 Review/governance | 4 | <<FILL>> | <<FILL>> | <<FILL>> | <<FILL>> |
Signoff
| Role | Name | Signature | Date |
|---|---|---|---|
| Assessor | <<FILL>> | ||
| Area owner | <<FILL>> | ||
| QA | <<FILL>> |
References
21 CFR 211.68, 211.188, 211.194; 21 CFR Part 11. EU GMP Annex 11 (computerized systems); Chapter 4 (documentation). FDA Guidance, Data Integrity and Compliance With Drug CGMP; PIC/S PI 041.
Confirm the current version and clause numbers of each reference before issue.
Filled specimen
An extract from a walk of one sterile fill line, showing how Fails convert to actions.
| # | Item | Result | Note / action |
|---|---|---|---|
| 2.1 | Individual MES accounts | Pass | Verified two operators, entries attributed correctly |
| 3.2 | No shared HMI login | Fail | Night-shift HMI uses a shared “line1” login. Action: enable individual accounts, interim shift logbook tying named operators to activity. Owner: Automation Eng. Remediate by Q3. |
| 4.1 | PLC compensating controls | Pass | Autoclave PLC has documented compensating controls, baseline verified last month |
| 5.2 | Historian compression qualified | Fail | Deadbands set at commissioning for storage, never qualified against process precision. Action: qualify deadbands, lock under change control. Owner: Plant IT. |
| 6.4 | Time synchronization | Fail | SCADA server drifting ~6 min vs MES. Action: bring onto NTP, qualify as a system attribute. Owner: Plant IT. |
Three Fails, each with an owner and a decision. The shared night-shift login carries an interim compensating control (the logbook) while the technical fix lands, which is exactly the managed posture an inspector accepts, versus a gap nobody owns.
Common inspection findings this checklist catches early
- Shared HMI logins surviving on the night shift after day shift moved to individual accounts.
- Corrections that overwrite the original value in the EBR.
- Historian compression tuned for disk space, quietly dropping the transient that proves a limit was or was not breached.
- Clock drift across systems treated as cosmetic until an investigation cannot order events.
- Audit trail present but never reviewed at batch review.
How to adapt this checklist
- Add rows for site-specific systems and the gaps your own deviations have surfaced.
- Walk it per line and per system; aggregate the scoring to see where risk concentrates.
- Convert every Fail to an action with an owner and a Remediate/Replace/Compensate decision.
- Feed the results into your data integrity gap assessment and inspection-readiness program.
- Confirm the referenced regulations against their current published versions before issue.