This is a ready-to-use defect log for the findings a pre-BLA or pre-NDA data integrity audit produces. It is the single place every broken trace, every audit trail gap, and every undisclosed excursion found during the audit gets recorded, scored, assigned an owner, and tracked to closure before the target filing date. Pair it with the CMC data traceability matrix, which is where most rows in this log originate, and the pre-BLA CMC data integrity audit protocol that defines the audit this log tracks. Replace every <<FILL: ...>> placeholder. A filled specimen follows.
Header
| Field | Entry |
|---|---|
| Log number | <<FILL: LOG-ID>> |
| Product / application | <<FILL>> |
| Audit protocol reference | <<FILL: pre-BLA audit protocol number and version>> |
| Log owner | <<FILL: QA / DI SME>> |
| Target filing date | <<FILL>> |
Severity definitions and filing-gate rule
| Severity | Definition | Filing rule |
|---|---|---|
| High | Affects a result behind an acceptance criterion, a PPQ batch, or a registration stability lot (the 100-percent-verification population); or the original data cannot be recovered | Must be remediated, or carry a written, science-based justification approved by QA, before filing. No exception. |
| Medium | Affects development, characterization, or risk-weighted-sample data; original data recoverable | Must be remediated (re-verified, revalidated, or procedurally corrected) on a defined timeline that closes before filing. |
| Low | Affects routine, non-load-bearing data with no direct submission claim | May close post-filing on a tracked timeline, noted as a residual item; document the rationale for deferral. |
A finding’s severity is set from the result’s sampling tier in the audit protocol, not from a subjective read of “how bad it looks.” A broken trace on a 100-percent-verification result is High by definition; downgrading it requires a written rationale approved by QA, not a default judgment call.
Field table
| Field | Entry |
|---|---|
| Defect ID | Unique, sequential (e.g. <<FILL: DEF-2026-001>>) |
| Result / record affected | The specific result, batch, or record, with its matrix row ID if applicable |
| Module 3 / CMC section | The submission section this result supports |
| Data type | Analytical result / process validation / stability / multi-site or CDMO |
| Description | What was found, in enough detail that a reader unfamiliar with the audit understands the gap |
| Severity | High / Medium / Low, per the rule above |
| Root cause (if known at logging) | <<FILL: or "under investigation">> |
| CAPA / deviation reference | Linked corrective action or deviation record |
| Owner | Named individual, not a function or department |
| Target closure date | Must precede the target filing date for High severity |
| Status | Open / In progress / Closed |
| QA disposition | Remediated / Justified and accepted / Deferred (Low only), with the approving QA name |
The log
| Defect ID | Result / record | Section | Data type | Description | Severity | Root cause | CAPA/dev ref | Owner | Target closure | Status | QA disposition |
|---|---|---|---|---|---|---|---|---|---|---|---|
<<FILL>> | <<FILL>> | <<FILL>> | <<FILL>> | <<FILL>> | <<FILL>> | <<FILL>> | <<FILL>> | <<FILL>> | <<FILL>> | Open | <<FILL>> |
Instructions for use
- Log every finding the same day it is identified during audit execution, regardless of how minor it appears at the time; do not wait for the audit to conclude.
- Set severity from the sampling tier of the affected result, per the rule above, at the time of logging; re-score only with a written, dated rationale.
- Assign a named owner and a target closure date at the time of logging, not after a follow-up meeting.
- Review the full log at every program milestone and explicitly at the pre-BLA meeting readiness check; every High-severity row must show a path to closure before the filing date is treated as real.
- On closure, record whether the finding was remediated (objective evidence of a fix, re-verification, or revalidation) or justified (a written, QA-approved rationale); “closed, no further action” with neither is not an acceptable disposition for High or Medium severity.
- Feed every closed finding’s root cause into the broader quality system; a pattern across multiple findings (for example, the same instrument or the same site recurring) is itself a signal that belongs in a CAPA, not just three separate log rows. See what is a CAPA.
Retention
Retain this log, and every referenced CAPA and deviation record, per the site’s records retention schedule, for not less than <<FILL: retention period>>, and as part of the permanent inspection file for the application. The log is not archived or closed out until every row is Closed or explicitly carried forward as a documented residual item in the audit summary report.
Summary roll-up
| Metric | Count |
|---|---|
| Total findings logged | <<FILL>> |
| High severity, open | <<FILL>> (must be zero at filing) |
| High severity, closed (remediated / justified) | <<FILL>> |
| Medium severity, open | <<FILL>> |
| Low severity, deferred with tracked date | <<FILL>> |
References
21 CFR 211.192 (investigation of discrepancies), 211.194 (laboratory records). FDA Data Integrity and Compliance With Drug CGMP, Questions and Answers (2018). ICH Q9(R1), Quality Risk Management, for the severity-to-risk basis.
Confirm the current version of each reference before issue.
Filled specimen
An excerpt from an example biologic BLA audit log, roughly six months before the target filing date.
| Defect ID | Result / record | Section | Data type | Description | Severity | Root cause | CAPA/dev ref | Owner | Target closure | Status | QA disposition |
|---|---|---|---|---|---|---|---|---|---|---|---|
| DEF-2026-011 | Purity, batch DS-2409 (matrix row T-058) | 3.2.S.4.1 | Analytical | 3 of 9 injections in the sequence not reported, no documented reason; analyst account held admin rights | High | Under investigation: possible undocumented trial injections during method troubleshooting | INV-2026-0087 | R. Alvarez (Analytical) | 2026-09-15 | In progress | Pending |
| DEF-2026-014 | Stability chamber CH-07, 12-month pull | 3.2.P.8 | Stability | 18-hour excursion to 14C, not disclosed until audit found the chamber log | High | Power event; chamber alarm acknowledged but not documented at the time | DEV-2026-0201 | K. Osei (Stability) | 2026-08-20 | Closed | Justified and accepted: impact assessment shows mean kinetic temperature within demonstrated acceptable range; disclosed in submission |
| DEF-2026-019 | Reagent lot traceability, non-critical in-process assay | 3.2.P.3 | Process validation | Reagent lot number not captured on 4 of 60 sampled in-process records | Low | Form field not mandatory in current template | CAPA-2026-0044 | J. Kim (Manufacturing) | 2026-11-30 | Open | Deferred: template correction in progress, procedural fix; not load-bearing |
Two things this excerpt shows. First, DEF-2026-011 is exactly the kind of finding a pre-BLA audit exists to catch and a real inspection does not get to find first, it is High severity, has a named owner, and a target closure date that precedes the filing window. Second, DEF-2026-014 shows the log working as intended: an unrecorded excursion became a documented, assessed, disclosed item instead of a hidden one, and it closed with QA’s written justification on file, not a silent “fine, move on.”
Common inspection findings this log prevents
- A defect found during the internal audit that was never logged, so there is no record it was ever assessed or closed.
- A High-severity finding closed with no evidence of remediation and no QA-approved justification, just a status change to “Closed.”
- Findings with no named owner or target date, so nothing closes before the filing date arrives.
- A pattern of related findings (same site, same system, same instrument) tracked as isolated rows with no CAPA connecting them.
How to adapt this log
- Set the product, application, and audit protocol reference in the header.
- Confirm your severity thresholds match the sampling tiers in your audit protocol; do not use a generic severity scale disconnected from what result the finding actually affects.
- Keep this log as the single source of audit findings reported at every program milestone; do not let a parallel, informal tracker develop.
- Route every Medium and High finding into your CAPA or deviation system per your normal quality procedures, and keep the cross-reference current in this log.
- Confirm every regulation in the references against the current published version before issue.