This is a ready-to-use traceability matrix for a marketing application’s CMC data package. It takes the seven-element trace a pre-license or pre-approval investigator runs on a single result and applies it, row by row, across the whole population of results a pre-BLA audit is scoped to cover: every specification-supporting result, every PPQ batch, every registration stability lot. The point is to have the trace already built and reviewed before an investigator asks for it, not to reconstruct it in real time during the inspection. Replace every <<FILL: ...>> placeholder, run it against the population your pre-BLA CMC data integrity audit protocol defines, and route it through QA review. A filled specimen follows, showing both an intact trace and a broken one. This is educational reference content, not regulatory advice.
When to use this matrix, and how it differs from a single-result trace
Use this matrix for population-level coverage: every result that has to be defensible gets one row, so gaps and coverage are visible at a glance across the whole submission. For a deep, step-by-step forensic trace of one specific result, including the transfer path into the system of record and the audit trail reconciliation around it, use the single-result data integrity trace form instead, or after this matrix flags a row as broken and you need the full forensic detail behind it.
Header
| Field | Entry |
|---|---|
| Matrix number | <<FILL: MTX-ID>> |
| Product / application | <<FILL: product, application type>> |
| Module 3 / CMC section(s) covered | <<FILL: e.g. 3.2.S.4.1, 3.2.P.5.4>> |
| Population source | <<FILL: pre-BLA audit protocol reference and section>> |
| Owner | <<FILL: DI SME / audit lead>> |
| Date range covered | <<FILL>> |
Legend and column definitions
| Column | Meaning |
|---|---|
| Row ID | Unique identifier for this trace row |
| Module 3 / CMC ref | The specific submission section this result supports |
| Reported result | The value in the specification table or CoA, with units and pass/fail |
| Raw acquisition | The CDS sequence, instrument file, plate reader output, or notebook entry, and its audit trail status |
| Method | The controlled method ID and version effective on the analysis date |
| Analyst | The person who generated the result and their training status on that method version |
| Reviewer | The second person who reviewed and approved the result, and the review date |
| Instrument | The instrument ID and its calibration/qualification status on the analysis date |
| Sample | The sample login record: batch, condition, pull date, chain of custody |
| Sampling tier | Which row of the audit’s sampling rule this result fell under (100 percent / risk-weighted / statistical) |
| Status | Intact / Partial / Broken |
| Finding ref | The defect log entry ID if Status is not Intact |
A row is Intact only when every one of the seven trace columns is populated with a verified, cited source, not an assertion. One empty or unverifiable cell makes the row Partial; a cell that contradicts another (for example, an analyst not trained on the method version used) makes the row Broken.
The matrix
| Row ID | Module 3 / CMC ref | Reported result | Raw acquisition | Method | Analyst | Reviewer | Instrument | Sample | Tier | Status | Finding ref |
|---|---|---|---|---|---|---|---|---|---|---|---|
<<FILL>> | <<FILL>> | <<FILL>> | <<FILL>> | <<FILL>> | <<FILL>> | <<FILL>> | <<FILL>> | <<FILL>> | <<FILL>> | Intact / Partial / Broken | <<FILL: or N/A>> |
Coverage summary
| Metric | Count |
|---|---|
| Total rows in scope (per the audit population) | <<FILL>> |
| Rows completed | <<FILL>> |
| Status Intact | <<FILL>> |
| Status Partial | <<FILL>> |
| Status Broken | <<FILL>> |
| Coverage percentage (completed / total in scope) | <<FILL>> % |
| Open findings from Partial/Broken rows | <<FILL>> |
A matrix is not ready to support a filing decision until every row in the defined population is completed and every Partial or Broken row has a logged, dispositioned finding in the defect log.
Sign-off
| Role | Name | Signature | Date |
|---|---|---|---|
| Author (DI SME / audit lead) | <<FILL>> | ||
| Reviewer (Analytical SME) | <<FILL>> | ||
| Approver (QA) | <<FILL>> |
References
21 CFR 211.194 (completeness of laboratory records), 211.68 (automatic, mechanical, and electronic equipment). 21 CFR Part 11 (electronic records and signatures). FDA Data Integrity and Compliance With Drug CGMP, Questions and Answers (2018). ICH Q2(R2), Validation of Analytical Procedures (for the method-validity column).
Confirm the current version of each reference before issue.
Filled specimen
Two rows from an example biologic BLA, one intact and one broken, so you can see the level of detail an inspector expects and what a broken trace looks like on the matrix.
| Row ID | Module 3 ref | Reported result | Raw acquisition | Method | Analyst | Reviewer | Instrument | Sample | Tier | Status | Finding ref |
|---|---|---|---|---|---|---|---|---|---|---|---|
| T-041 | 3.2.S.4.1 | Purity 99.2%, batch DS-2402, released | CDS SEQ-2024-0311, inj. 7; audit trail: one integration, no reprocessing, no deleted injections | PUR-HPLC-007 v4.0, eff. 02 Jan 2024 | Trained on v4.0, 10 Jan 2024 (before test date) | Second-person review, dated 15 Mar 2024 | INST-HP-22, calibrated 05 Feb 2024, next due 05 Aug 2024 | S-77310, batch DS-2402, ambient, pulled 08 Mar 2024 | 100 percent (spec-supporting) | Intact | N/A |
| T-058 | 3.2.S.4.1 | Purity 98.6%, batch DS-2409, released | CDS SEQ-2024-0512 shows 9 injections; only 6 reported, no documented reason for the other 3 | PUR-HPLC-007 v4.0 | Same analyst account holds admin rights | Reviewed, but review predates the audit trail export date | INST-HP-22 | S-77455 | 100 percent (spec-supporting) | Broken | DEF-2026-011 |
Row T-041 is the trace an inspector wants to see: every column verified, nothing left to explain. Row T-058 is the trace that generates a finding: three injections in the sequence never made it to the reported set, with no documented reason, and the analyst account that ran the sequence also holds administrator rights, which is itself a separate control gap. That row does not get resolved by re-running the number; it gets logged, investigated, and either explained with contemporaneous evidence or treated as selective reporting.
Coverage summary (excerpt)
| Metric | Count |
|---|---|
| Total rows in scope | 340 |
| Rows completed | 340 |
| Status Intact | 337 |
| Status Partial | 1 |
| Status Broken | 2 |
| Coverage percentage | 100 % |
| Open findings from Partial/Broken rows | 3, all logged in the defect log with owners and due dates |
Common inspection findings this matrix prevents
- A specification-supporting result with no documented link to its raw acquisition, discovered only when an investigator asks for it directly.
- Selective reporting (injections or acquisitions performed but not reported) that nobody reconciled before the submission was finalized.
- A result attributed to an analyst who was not yet trained on the method version used, missed because training status was never cross-checked against the analysis date.
- A matrix or trace exercise claimed as complete with no row-level status and no coverage percentage to support the claim.
How to adapt this matrix
- Set your matrix number, product, and the Module 3 sections it covers.
- Populate the row population directly from your pre-BLA audit protocol’s defined scope; do not build the matrix from a sample of convenience.
- Use exactly the sampling tier your audit protocol assigned to each result, so reviewers can see the rigor was proportionate to risk.
- Mark a row Broken the moment any column cannot be verified; do not leave it blank pending investigation, log the finding immediately.
- Re-run the coverage summary after every batch of rows is completed, and do not treat the matrix as filing-ready until coverage is complete and every non-Intact row has a finding reference.