This is a ready-to-use worksheet for cross-reference verification, the technique an experienced FDA investigator uses to test whether a record is authentic: pull several independent sources for the same event and confirm they agree. An authentic record is internally consistent across all of them; a manipulated one almost always breaks at least one cross-reference. Running this yourself, on a risk-based sample, means you find and investigate the discrepancy before an investigator does. Replace every <<FILL: ...>> placeholder, run it under your data integrity or self-inspection program, and record actual findings as you observe them. A filled specimen follows. This content is educational reference, not legal or regulatory advice; adapt it to your systems and verify each cited regulation against the current source before you rely on it.
Header
| Field | Entry |
|---|---|
| Worksheet number | <<FILL: FORM-ID, e.g. FRM-QA-102>> |
| Record under verification | <<FILL: batch record / test record / result ID>> |
| Product / batch / study | <<FILL>> |
| System(s) involved | <<FILL: CDS / LIMS / MES / access system>> |
| Reason for verification | <<FILL: routine self-inspection / for-cause / mock inspection>> |
| Governing procedure | <<FILL: SOP-ID>> |
| Verifier (name, role) | <<FILL>> |
| Date | <<FILL>> |
What to reconcile
For a chosen event (an assay completion, a signature, a critical process step), gather the independent sources that should describe the same moment and compare them. The sources that most often disagree when a record has been manipulated:
| Source | What it should show | Independent of |
|---|---|---|
| Primary record (batch or test record) | The recorded time, value, and actor | The systems below |
| Instrument / CDS audit trail or injection log | When the run actually started and finished | The paper or electronic batch record |
| Electronic signature audit trail | When the signature was applied | The recorded completion time |
| Badge / physical access log | Whether the actor was in the room at the recorded time | The instrument and the record |
| System / workstation clock vs network time | Whether the timestamp source was trustworthy | Every timestamp above |
| Environmental monitoring for the room/time | Whether the room was in the state the record implies | The batch record |
Reconciliation grid (blank)
Enter, for each source, what it shows for the same event, then judge consistency.
| Line | Event verified | Source | What the source shows (time / value / actor) | Consistent with primary? | Discrepancy detail | Init |
|---|---|---|---|---|---|---|
| 1 | <<FILL: e.g. Assay completion, Product B lot 2206>> | Primary record | <<FILL>> | (reference) | - | <<FILL>> |
| 2 | (same event) | CDS injection log | <<FILL>> | <<FILL: Yes/No>> | <<FILL>> | |
| 3 | (same event) | E-signature audit trail | <<FILL>> | <<FILL>> | <<FILL>> | |
| 4 | (same event) | Badge access log | <<FILL>> | <<FILL>> | <<FILL>> | |
| 5 | (same event) | Workstation clock vs network time | <<FILL>> | <<FILL>> | <<FILL>> | |
| 6 | (same event) | Environmental / other | <<FILL>> | <<FILL>> | <<FILL>> |
Field definitions and instructions
- Pick the event and record it once on line 1 from the primary record, which is the reference the others are compared against.
- For each independent source, record exactly what it shows for that same event: the time, the value, or the actor as applicable.
- Judge consistency against the primary record. A difference of a few minutes may be explainable drift; a difference of hours, or an actor not present, is a discrepancy.
- Where sources that are independent of each other agree with one another but disagree with the primary record, the primary record is the outlier, not the three sources. State that plainly.
- Do not invent an explanation. If a discrepancy is real, raise it as a deviation or investigation under
<<FILL: SOP-ID for deviations>>and let the investigation, not the worksheet, reach the conclusion. - Retain the completed worksheet with the self-inspection or investigation record for not less than
<<FILL: retention period>>.
Disposition
| Field | Entry |
|---|---|
| Discrepancies found (count) | <<FILL>> |
| Most significant discrepancy | <<FILL: describe, or "none">> |
| Deviation / investigation reference | <<FILL: number or N/A>> |
| Verifier (name, signature, date) | <<FILL>> |
| QA review (name, signature, date) | <<FILL>> |
Acceptance criteria
- Each independent source has been pulled and recorded for the same event.
- Every “No” in the consistent column carries a discrepancy detail.
- Any real discrepancy is raised into the quality system, not explained away on the worksheet.
- The reconciliation is signed, dated, and QA-reviewed, and retained with the parent record.
References
ALCOA+ expectations (attributable, contemporaneous, accurate) as described in FDA’s Data Integrity and Compliance With Drug CGMP, Questions and Answers (2018). 21 CFR 211.68, 211.188, 211.194 (equipment checks and laboratory records). 21 CFR Part 11 (electronic records and signatures). EU GMP Annex 11, section 9 (audit trails). MHRA GxP Data Integrity Guidance and Definitions; PIC/S PI 041.
Confirm the current version and clause numbers of each reference before issue.
Filled specimen
The following reconciles a single assay completion against four independent sources. Illustrative only.
| Line | Event verified | Source | What the source shows | Consistent with primary? | Discrepancy detail | Init |
|---|---|---|---|---|---|---|
| 1 | Assay completion, Product B lot 2206-031 | Primary record | Completed 14:05, signed 14:10, 12 Jun, analyst K. Rao | (reference) | - | MQ |
| 2 | (same) | CDS injection log | Injection started 19:40, 12 Jun | No | Instrument run 5.5 h after recorded completion | MQ |
| 3 | (same) | E-signature audit trail | Signature applied 19:55, 12 Jun | No | Signature 5.75 h after recorded 14:10 | MQ |
| 4 | (same) | Badge access log | K. Rao entered lab 19:15, not present at 14:00 | No | Actor not in the lab at the recorded time | MQ |
| 5 | (same) | Workstation clock vs network | Synced, no drift | Yes | Timestamp source trustworthy | MQ |
The three independent sources (injection log, signature trail, badge log) agree with one another around 19:15 to 19:55 and all disagree with the recorded 14:05. The workstation clock was trustworthy, so the recorded time is the outlier, not a clock error. The verifier did not accept “typo”; the discrepancy was raised as an investigation into a non-contemporaneous record, an attributable and contemporaneous failure under ALCOA+. Finding it in a self-inspection, with the investigation opened and progressing, is a demonstration of control; being surprised by it during an inspection is the opposite.
Common inspection findings this worksheet prevents
- A recorded time that contradicts the instrument’s own log, discovered by the investigator rather than the site.
- A signature or completion attributed to someone the badge log shows was not present.
- A result recorded before the instrument was switched on or the analyst arrived.
- Cross-reference discrepancies that exist in the records but were never checked, because no one reconciled the independent sources.
How to adapt this worksheet
- Set your worksheet number and governing procedure in the header.
- Replace the source list with the independent systems your process actually generates (add or drop rows as needed).
- Use it on a risk-based sample inside your self-inspection and mock-inspection programs, focusing on high-criticality records like release results.
- Route any real discrepancy to your deviation and investigation process.
- Confirm every regulation in the references against the current published version before issue.