Independent and not affiliated with the FDA, MHRA, ISPE, PDA, or any agency. Get the appgoutham@madhadi.com
madhadi.comData Integrity & GxP Quality
Browse all topics → Articles Templates & Procedures Learning paths GlossaryScenariosToolsRegulatory ReferencesLearning PathsTopics About Start here
Form Plug-and-play starting point Data Integrity

Certificate of Destruction for GxP Records

A plug-and-play certificate of destruction form for GxP records reaching the end of their retention period: eligibility check against the retention schedule, a mandatory legal-hold check, authorization, destruction method and verification, and the signatures that make disposal a defensible, controlled act, with a filled specimen.

Document type: Form

Read and copy the template below into your own quality system. It is a generic starting point for your own internal use, provided as is, with no warranty; see the Terms and License. Adopting it does not by itself create compliance.

This is a ready-to-use certificate of destruction. It is the one document in a records-retention program that closes an irreversible act, so it is built to make that act deliberate: nothing on this form can be completed until the retention clock has genuinely lapsed and a legal hold check has cleared. Replace every <<FILL: ...>> placeholder with your own specifics, set your form number under document control, and route it through your normal review and approval. A worked filled specimen follows the blank form so you can see how a completed version reads. Verify each cited regulation against the current source before you rely on it.

Document control header

FieldEntry
Form titleCertificate of Destruction
Form number<<FILL: FORM-ID, e.g. FRM-QA-041-02>>
Version<<FILL: version, e.g. 1.0>>
Effective date<<FILL: effective date>>
Linked SOP<<FILL: SOP-ID for records retention, archival, and retrieval, or for decommissioning>>
Page<<FILL: page of pages>>

When to use this form

Complete one certificate per destruction event: a defined set of records of the same type, reaching eligibility for disposal at the same time, destroyed by the same method on the same date. Do not use one certificate to cover a mixed batch of record types with different retention bases; each record type’s eligibility has to be shown separately, because the fact that one record type has lapsed proves nothing about another. This form is generated at the end of the disposition sequence: retention determination, then the migrate-versus-archive-versus-destroy decision, then, only for records dispositioned to destroy, this certificate.

Field table

FieldFormatRequiredWho completes itWhen
Record type(s) and identifiers or ranges destroyedText, specific enough to reconstruct scope later (batch range, date range, system of origin)YesRecords owner / archivistAt initiation
VolumeCount or size (record count, file count, or physical volume)YesRecords owner / archivistAt initiation
Retention basis and clock-start eventText, citing the schedule row and the event that started the clockYesRecords owner, from the retention scheduleAt initiation
Retention lapse dateDateYesRecords ownerAt initiation
Legal hold check resultYes / No hold applies, with checker name and dateYesLegalBefore authorization
AuthorizationName, role, signature, dateYesQuality Assurance and Legal (both)Before execution
Destruction methodText (secure data wipe, cryptographic erasure, physical media destruction, shredding) and standard followedYesExecuting function (IT / records management)At execution
Execution date and operatorDate, name, signatureYesExecuting functionAt execution
Verification of completeness and irrecoverabilityText describing how completeness was confirmedYesIndependent verifier, not the executing operatorAfter execution
Certificate retentionDuration and location the certificate itself is keptYesRecords ownerAt closure

Instructions

  1. Confirm the record type’s retention period has genuinely lapsed against the current records retention and disposition schedule; cite the specific schedule row, not a general recollection of the period.
  2. Route the legal hold check to Legal before doing anything else. Legal confirms, in writing on this form, that no active hold, inspection, investigation, litigation, or recall touches any record in scope. A hold on any part of the scope stops the whole certificate; do not destroy the unheld portion and defer the rest without splitting the certificate into two, one per disposition outcome.
  3. Obtain authorization from both Quality Assurance and Legal before execution. Neither signs on behalf of the other; both are required.
  4. Execute destruction using the method stated, appropriate to the medium (electronic media, paper, or a hybrid) and to any applicable privacy or security requirement.
  5. Have a person who did not execute the destruction verify and document that it was complete and unrecoverable. This is a segregation-of-duties control, not a formality; self-verified destruction defends nothing.
  6. Sign and issue the certificate. Do not backdate any field; if execution slips past the planned date, record the actual date.
  7. File the completed certificate as a controlled GxP record in its own right.

The certificate

FieldEntry
Certificate number<<FILL>>
Record type(s) destroyed<<FILL>>
Identifiers or ranges<<FILL>>
System(s) of origin<<FILL>>
Volume<<FILL>>
Retention schedule reference<<FILL: schedule row / record type ID>>
Retention basis and clock-start event<<FILL>>
Retention lapse date<<FILL>>
Legal hold checkNo hold applies / Hold applies (stop)
Legal hold checked by (name, signature, date)<<FILL>>
Quality Assurance authorization (name, signature, date)<<FILL>>
Legal authorization (name, signature, date)<<FILL>>
Destruction method<<FILL>>
Standard followed (if applicable)<<FILL>>
Execution date<<FILL>>
Executed by (name, signature)<<FILL>>
Verification method<<FILL>>
Verified by (name, signature, date, independent of executor)<<FILL>>
ResultComplete and unrecoverable / Exception noted: <<FILL>>

Retention

Retain this certificate as a controlled GxP record indefinitely, or for the period set by <<FILL: records retention policy reference>>, whichever your policy specifies. The certificate is the permanent proof that disposal was lawful; do not apply the destroyed record’s own retention period to the certificate that documents its destruction.

Acceptance criteria

A certificate is acceptable when the record type’s retention has genuinely lapsed against the current schedule, the legal hold check was performed by Legal and documented before authorization, both Quality Assurance and Legal authorized the destruction, the method used was appropriate and stated, destruction was verified as complete and unrecoverable by someone other than the person who executed it, and the certificate itself is retained as a controlled record.

References

21 CFR 211.180 and 211.194 (records retention and availability; destruction is only appropriate once these periods and any longer applicable period have lapsed). 21 CFR Part 11 and EU GMP Annex 11 (electronic records; controlled disposal as part of the record lifecycle). EU GMP Chapter 4 (Documentation), retention and disposal expectations. MHRA GxP Data Integrity Guidance and Definitions (March 2018). PIC/S PI 041, Good Practices for Data Management and Integrity.

Confirm the current version and clause numbers of each reference before issue. This form does not itself set retention periods; it executes disposition decisions already made under the records retention and disposition schedule and the legal hold register.


Filled specimen

The following shows the certificate completed for an example laboratory instrument log whose retention lapsed after a legacy system’s archive was confirmed and no hold applied. Company, system, and numbers are illustrative; replace them with your own.

FieldEntry
Certificate numberDST-2027-011
Record type(s) destroyedInstrument configuration exports, non-GxP-decision reference data, from a retired chromatography data system archive
Identifiers or rangesConfiguration snapshot set CFG-CDS-04-2014 through CFG-CDS-04-2019
System(s) of originLegacy CDS archive ARC-QC-04
Volume1,860 files
Retention schedule referenceRT-045, Instrument configuration exports (non-GxP-decision)
Retention basis and clock-start eventCompany policy, configuration snapshot date plus 7 years; not tied to any batch or product retention clock because the data is non-decision reference only
Retention lapse date04 March 2027
Legal hold checkNo hold applies
Legal hold checked byM. Okafor, Legal, signed, 10 March 2027
Quality Assurance authorizationR. Gomez, signed, 12 March 2027
Legal authorizationM. Okafor, signed, 12 March 2027
Destruction methodCryptographic erasure of the storage volume, per the company’s approved media sanitization standard
Standard followedCompany media sanitization standard MSS-IT-02, aligned to NIST SP 800-88 sanitization categories
Execution date15 March 2027
Executed byD. Ferreira, IT Operations, signed
Verification methodPost-erasure read-attempt confirming no recoverable content, performed on a sample of the affected volume and on the erasure log
Verified byJ. Alvarez, IT (independent of execution), signed, 16 March 2027
ResultComplete and unrecoverable

In this example, the destroyed data was explicitly non-decision reference material with its own shorter, policy-set clock, kept separate on this certificate from the GxP release data in the same archive, whose 30-year clock had not lapsed and was not touched. The legal hold check and both authorizations predate execution, and verification was performed by someone other than the person who ran the erasure. That sequence, eligibility to hold check to dual authorization to execution to independent verification, is what a reviewer expects to see.

Common inspection findings this form prevents

  • Records destroyed with no documented proof of what was destroyed, when, by whom, or under what authority.
  • A whole system or archive wiped in one action, sweeping up record types whose individual retention clocks had not lapsed.
  • No legal hold check performed, or the check performed by the same person requesting the destruction rather than by Legal.
  • Only one function (commonly IT alone, or Quality alone) authorized a destruction that required both Quality and Legal sign-off.
  • Destruction “verified” by the same person who executed it, with no independent confirmation of irrecoverability.
  • The certificate itself was not retained, so years later there is no proof the earlier disposal was lawful.

How to adapt this form

  1. Set your form number, linked SOP, and effective date in the header.
  2. Point the retention schedule reference field at your actual records retention and disposition schedule, not a restated period.
  3. Confirm your legal hold register is the single source Legal checks against before completing the hold-check field.
  4. Adjust the destruction method options to the media types you actually handle (electronic, paper, hybrid, physical devices).
  5. If your organization uses a single combined Quality/Legal sign-off role, document that as a compensating control rather than silently dropping one signature line.
  6. Confirm every regulation in the references against the current published version before issue.
Use madhadi.com as an app Full screen, works offline, one tap from your home screen.