Independent and not affiliated with the FDA, MHRA, ISPE, PDA, or any agency. Get the appgoutham@madhadi.com
madhadi.comData Integrity & GxP Quality
Browse all topics → Articles Templates & Procedures Learning paths GlossaryScenariosToolsRegulatory ReferencesLearning PathsTopics About Start here
Matrix Plug-and-play starting point Quality Assurance

Matrix: Regulatory Requirement to Governing Procedure Cross-Reference

A plug-and-play matrix mapping every applicable regulatory requirement to the procedure that satisfies it, the tier it sits at, its owner, and its last review date, kept as a living artifact independent of the quality manual, with a filled specimen and a gap-detection method.

Document type: Matrix

Read and copy the template below into your own quality system. It is a generic starting point for your own internal use, provided as is, with no warranty; see the Terms and License. Adopting it does not by itself create compliance.

This is a ready-to-use requirement-to-procedure cross-reference matrix. Most companies embed a short version of this table inside the quality manual, but a manual reviewed annually goes stale fast against a document set that changes weekly; keeping this matrix as its own living artifact, updated whenever a procedure is issued, revised, or retired, is what keeps the manual’s summary version honest. Replace every <<FILL: ...>> placeholder with your own requirements and procedures. A worked filled specimen follows the template.

Document control header

FieldEntry
Document titleRegulatory Requirement to Governing Procedure Cross-Reference Matrix
Document number<<FILL: reference, e.g. XREF-QA-001>>
Version<<FILL: version>>
Effective date<<FILL: effective date>>
Owner<<FILL: role, e.g. Head of Quality Assurance>>
Update triggerAny new, revised, or retired procedure; any newly applicable regulation

1. Purpose

This matrix answers, for any regulatory requirement a reviewer names, “which of your procedures satisfies this, and is it current.” It is the fastest way to demonstrate that the company knows its own regulatory obligations and has a live, named, approved procedure for each one, and it is the fastest way for the company itself to find a gap before an inspector does.

2. The matrix

RequirementSource (regulation / standard, clause)QMS processGoverning procedure (doc no., current version)TierOwnerLast reviewed
<<FILL: e.g. Document control>><<FILL: e.g. EU GMP Ch.4; 21 CFR 211.180/211.100; ICH Q10>><<FILL>><<FILL>>2<<FILL>><<FILL>>
<<FILL: e.g. Control of records>><<FILL>><<FILL>><<FILL>><<FILL>><<FILL>><<FILL>>
<<FILL: e.g. Deviation management>><<FILL>><<FILL>><<FILL>><<FILL>><<FILL>><<FILL>>
<<FILL: e.g. CAPA>><<FILL>><<FILL>><<FILL>><<FILL>><<FILL>><<FILL>>
<<FILL: e.g. Change control>><<FILL>><<FILL>><<FILL>><<FILL>><<FILL>><<FILL>>
<<FILL: e.g. Supplier qualification>><<FILL>><<FILL>><<FILL>><<FILL>><<FILL>><<FILL>>
<<FILL: e.g. Training>><<FILL>><<FILL>><<FILL>><<FILL>><<FILL>><<FILL>>
<<FILL: e.g. Internal audit>><<FILL>><<FILL>><<FILL>><<FILL>><<FILL>><<FILL>>
<<FILL: e.g. Management review>><<FILL>><<FILL>><<FILL>><<FILL>><<FILL>><<FILL>>
<<FILL: e.g. Validation and qualification>><<FILL>><<FILL>><<FILL>><<FILL>><<FILL>><<FILL>>
<<FILL: e.g. Electronic records and signatures>><<FILL: 21 CFR Part 11; EU GMP Annex 11>><<FILL>><<FILL>><<FILL>><<FILL>><<FILL>>
<<FILL: e.g. Audit trail review>><<FILL>><<FILL>><<FILL>><<FILL>><<FILL>><<FILL>>
<<FILL: add every requirement your operation is subject to>><<FILL>><<FILL>><<FILL>><<FILL>><<FILL>><<FILL>>

3. How to build and maintain it

  1. Start from the applicable regulatory framework, not from your existing procedure list. List every regulation, standard, and guidance that binds your operation (GMP, GCP, GLP, the specific CFR parts, ICH guidelines, ISO standards for any device constituent), then derive the requirements each imposes.
  2. For each requirement, name the QMS process that satisfies it and the specific procedure, by document number and current version, that governs it.
  3. Do not leave a requirement row with no procedure. A blank cell here is exactly the gap an inspector is trained to find; if the gap is real, open a CAPA or a document-control action to close it, do not leave the row blank waiting for someone to notice later.
  4. Update this matrix the moment a procedure is issued, revised, or retired, and whenever a new regulation or guidance becomes applicable. Treat it as a document-control-triggered artifact, not an annual exercise.
  5. Spot-check both directions periodically: pick a requirement and confirm the named procedure current and correct, then pick a procedure and confirm it maps to a real requirement (an orphan procedure governing nothing you are actually obligated to do is a sign of scope drift).

4. Acceptance criteria

  • Every requirement genuinely applicable to the operation has exactly one primary governing procedure named, current, and correctly versioned.
  • No cell references a retired, superseded, or renumbered document.
  • The matrix has been updated within the current document control cycle for every procedure change since its last review.
  • A spot-check in both directions (requirement to procedure, and procedure to requirement) finds no broken link.

5. References

EU GMP Chapter 4 (Documentation), for the expectation of a controlled, traceable document set. ICH Q10, Pharmaceutical Quality System, for the model of interacting, documented QMS processes this matrix maps. 21 CFR 211.22(d) and 211.100, for the “written procedures, followed” expectation this matrix demonstrates is met.

Confirm the current version of each reference before issue.

6. Revision history

VersionDateAuthorSummary of change
<<FILL: 1.0>><<FILL: date>><<FILL: author>>Initial issue.

Filled specimen

The following shows four rows completed for an example biologics manufacturer, so you can see the level of detail expected. The company and document numbers are illustrative; replace them with your own.

RequirementSourceQMS processGoverning procedureTierOwnerLast reviewed
Document controlEU GMP Ch.4; 21 CFR 211.180/211.100; ICH Q10Document controlSOP-QA-001 v4.02Head of QA2026-03-01
CAPAICH Q10 §3.2.2; 21 CFR 211.192CAPASOP-QA-010 v3.12Head of QA2026-01-15
Audit trail review21 CFR Part 11; EU GMP Annex 11 §9Data integritySOP-QA-014 v2.02Head of QA2026-06-15
Supplier qualificationEU GMP Annex 11 §3.2; ICH Q10Supplier managementSOP-PROC-004 v1.22Head of Procurement Quality2026-05-01

A gap assessment against this specimen would immediately flag if, for example, “electronic signatures” had no dedicated row, since it is a distinct Part 11 subpart C obligation from general audit trail review and deserves its own line rather than being assumed to be covered by an adjacent one.

Common inspection findings this matrix prevents

  • A requirement the inspector names for which the company has no ready answer, because no single artifact maps requirements to procedures.
  • A procedure cited as governing a requirement that turns out to be retired or superseded.
  • Genuine coverage gaps (a requirement with no procedure at all) discovered live during the inspection rather than through the company’s own periodic self-check.
  • Scope drift, where procedures exist for activities the company no longer performs, or new obligations exist with no procedure written yet.

How to adapt this matrix

  1. Set the owner and update-trigger fields in the header; this matrix only stays useful if someone owns keeping it current.
  2. Build the requirement list from your actual regulatory footprint (site, products, markets), not from a generic template list; a cell and gene therapy site and a combination-product site will need different rows.
  3. Wire this matrix’s update into your document control SOP so every new or revised procedure automatically triggers a matrix update, rather than relying on someone remembering.
  4. Use it as the first artifact in a self-inspection or gap assessment; see the QMS document hierarchy gap assessment checklist for the fuller method this matrix feeds.
Use madhadi.com as an app Full screen, works offline, one tap from your home screen.