Independent and not affiliated with the FDA, MHRA, ISPE, PDA, or any agency. Get the appgoutham@madhadi.com
madhadi.comData Integrity & GxP Quality
Browse all topics → Articles Templates & Procedures Learning paths GlossaryScenariosToolsRegulatory ReferencesLearning PathsTopics About Start here
Form Plug-and-play starting point Audits & Inspection

Form: Data Integrity Cross-Reference Verification Worksheet

A plug-and-play worksheet for reconciling a GxP record against independent sources the way an FDA investigator does: batch record times versus instrument audit trail, e-signature, badge access, and the system clock, so discrepancies are found and investigated before an inspector finds them, with a filled specimen.

Document type: Form

Read and copy the template below into your own quality system. It is a generic starting point for your own internal use, provided as is, with no warranty; see the Terms and License. Adopting it does not by itself create compliance.

This is a ready-to-use worksheet for cross-reference verification, the technique an experienced FDA investigator uses to test whether a record is authentic: pull several independent sources for the same event and confirm they agree. An authentic record is internally consistent across all of them; a manipulated one almost always breaks at least one cross-reference. Running this yourself, on a risk-based sample, means you find and investigate the discrepancy before an investigator does. Replace every <<FILL: ...>> placeholder, run it under your data integrity or self-inspection program, and record actual findings as you observe them. A filled specimen follows. This content is educational reference, not legal or regulatory advice; adapt it to your systems and verify each cited regulation against the current source before you rely on it.

FieldEntry
Worksheet number<<FILL: FORM-ID, e.g. FRM-QA-102>>
Record under verification<<FILL: batch record / test record / result ID>>
Product / batch / study<<FILL>>
System(s) involved<<FILL: CDS / LIMS / MES / access system>>
Reason for verification<<FILL: routine self-inspection / for-cause / mock inspection>>
Governing procedure<<FILL: SOP-ID>>
Verifier (name, role)<<FILL>>
Date<<FILL>>

What to reconcile

For a chosen event (an assay completion, a signature, a critical process step), gather the independent sources that should describe the same moment and compare them. The sources that most often disagree when a record has been manipulated:

SourceWhat it should showIndependent of
Primary record (batch or test record)The recorded time, value, and actorThe systems below
Instrument / CDS audit trail or injection logWhen the run actually started and finishedThe paper or electronic batch record
Electronic signature audit trailWhen the signature was appliedThe recorded completion time
Badge / physical access logWhether the actor was in the room at the recorded timeThe instrument and the record
System / workstation clock vs network timeWhether the timestamp source was trustworthyEvery timestamp above
Environmental monitoring for the room/timeWhether the room was in the state the record impliesThe batch record

Reconciliation grid (blank)

Enter, for each source, what it shows for the same event, then judge consistency.

LineEvent verifiedSourceWhat the source shows (time / value / actor)Consistent with primary?Discrepancy detailInit
1<<FILL: e.g. Assay completion, Product B lot 2206>>Primary record<<FILL>>(reference)-<<FILL>>
2(same event)CDS injection log<<FILL>><<FILL: Yes/No>><<FILL>>
3(same event)E-signature audit trail<<FILL>><<FILL>><<FILL>>
4(same event)Badge access log<<FILL>><<FILL>><<FILL>>
5(same event)Workstation clock vs network time<<FILL>><<FILL>><<FILL>>
6(same event)Environmental / other<<FILL>><<FILL>><<FILL>>

Field definitions and instructions

  1. Pick the event and record it once on line 1 from the primary record, which is the reference the others are compared against.
  2. For each independent source, record exactly what it shows for that same event: the time, the value, or the actor as applicable.
  3. Judge consistency against the primary record. A difference of a few minutes may be explainable drift; a difference of hours, or an actor not present, is a discrepancy.
  4. Where sources that are independent of each other agree with one another but disagree with the primary record, the primary record is the outlier, not the three sources. State that plainly.
  5. Do not invent an explanation. If a discrepancy is real, raise it as a deviation or investigation under <<FILL: SOP-ID for deviations>> and let the investigation, not the worksheet, reach the conclusion.
  6. Retain the completed worksheet with the self-inspection or investigation record for not less than <<FILL: retention period>>.

Disposition

FieldEntry
Discrepancies found (count)<<FILL>>
Most significant discrepancy<<FILL: describe, or "none">>
Deviation / investigation reference<<FILL: number or N/A>>
Verifier (name, signature, date)<<FILL>>
QA review (name, signature, date)<<FILL>>

Acceptance criteria

  • Each independent source has been pulled and recorded for the same event.
  • Every “No” in the consistent column carries a discrepancy detail.
  • Any real discrepancy is raised into the quality system, not explained away on the worksheet.
  • The reconciliation is signed, dated, and QA-reviewed, and retained with the parent record.

References

ALCOA+ expectations (attributable, contemporaneous, accurate) as described in FDA’s Data Integrity and Compliance With Drug CGMP, Questions and Answers (2018). 21 CFR 211.68, 211.188, 211.194 (equipment checks and laboratory records). 21 CFR Part 11 (electronic records and signatures). EU GMP Annex 11, section 9 (audit trails). MHRA GxP Data Integrity Guidance and Definitions; PIC/S PI 041.

Confirm the current version and clause numbers of each reference before issue.


Filled specimen

The following reconciles a single assay completion against four independent sources. Illustrative only.

LineEvent verifiedSourceWhat the source showsConsistent with primary?Discrepancy detailInit
1Assay completion, Product B lot 2206-031Primary recordCompleted 14:05, signed 14:10, 12 Jun, analyst K. Rao(reference)-MQ
2(same)CDS injection logInjection started 19:40, 12 JunNoInstrument run 5.5 h after recorded completionMQ
3(same)E-signature audit trailSignature applied 19:55, 12 JunNoSignature 5.75 h after recorded 14:10MQ
4(same)Badge access logK. Rao entered lab 19:15, not present at 14:00NoActor not in the lab at the recorded timeMQ
5(same)Workstation clock vs networkSynced, no driftYesTimestamp source trustworthyMQ

The three independent sources (injection log, signature trail, badge log) agree with one another around 19:15 to 19:55 and all disagree with the recorded 14:05. The workstation clock was trustworthy, so the recorded time is the outlier, not a clock error. The verifier did not accept “typo”; the discrepancy was raised as an investigation into a non-contemporaneous record, an attributable and contemporaneous failure under ALCOA+. Finding it in a self-inspection, with the investigation opened and progressing, is a demonstration of control; being surprised by it during an inspection is the opposite.

Common inspection findings this worksheet prevents

  • A recorded time that contradicts the instrument’s own log, discovered by the investigator rather than the site.
  • A signature or completion attributed to someone the badge log shows was not present.
  • A result recorded before the instrument was switched on or the analyst arrived.
  • Cross-reference discrepancies that exist in the records but were never checked, because no one reconciled the independent sources.

How to adapt this worksheet

  1. Set your worksheet number and governing procedure in the header.
  2. Replace the source list with the independent systems your process actually generates (add or drop rows as needed).
  3. Use it on a risk-based sample inside your self-inspection and mock-inspection programs, focusing on high-criticality records like release results.
  4. Route any real discrepancy to your deviation and investigation process.
  5. Confirm every regulation in the references against the current published version before issue.
Use madhadi.com as an app Full screen, works offline, one tap from your home screen.