This is a ready-to-use requirement-to-procedure cross-reference matrix. Most companies embed a short version of this table inside the quality manual, but a manual reviewed annually goes stale fast against a document set that changes weekly; keeping this matrix as its own living artifact, updated whenever a procedure is issued, revised, or retired, is what keeps the manual’s summary version honest. Replace every <<FILL: ...>> placeholder with your own requirements and procedures. A worked filled specimen follows the template.
Document control header
| Field | Entry |
|---|---|
| Document title | Regulatory Requirement to Governing Procedure Cross-Reference Matrix |
| Document number | <<FILL: reference, e.g. XREF-QA-001>> |
| Version | <<FILL: version>> |
| Effective date | <<FILL: effective date>> |
| Owner | <<FILL: role, e.g. Head of Quality Assurance>> |
| Update trigger | Any new, revised, or retired procedure; any newly applicable regulation |
1. Purpose
This matrix answers, for any regulatory requirement a reviewer names, “which of your procedures satisfies this, and is it current.” It is the fastest way to demonstrate that the company knows its own regulatory obligations and has a live, named, approved procedure for each one, and it is the fastest way for the company itself to find a gap before an inspector does.
2. The matrix
| Requirement | Source (regulation / standard, clause) | QMS process | Governing procedure (doc no., current version) | Tier | Owner | Last reviewed |
|---|---|---|---|---|---|---|
<<FILL: e.g. Document control>> | <<FILL: e.g. EU GMP Ch.4; 21 CFR 211.180/211.100; ICH Q10>> | <<FILL>> | <<FILL>> | 2 | <<FILL>> | <<FILL>> |
<<FILL: e.g. Control of records>> | <<FILL>> | <<FILL>> | <<FILL>> | <<FILL>> | <<FILL>> | <<FILL>> |
<<FILL: e.g. Deviation management>> | <<FILL>> | <<FILL>> | <<FILL>> | <<FILL>> | <<FILL>> | <<FILL>> |
<<FILL: e.g. CAPA>> | <<FILL>> | <<FILL>> | <<FILL>> | <<FILL>> | <<FILL>> | <<FILL>> |
<<FILL: e.g. Change control>> | <<FILL>> | <<FILL>> | <<FILL>> | <<FILL>> | <<FILL>> | <<FILL>> |
<<FILL: e.g. Supplier qualification>> | <<FILL>> | <<FILL>> | <<FILL>> | <<FILL>> | <<FILL>> | <<FILL>> |
<<FILL: e.g. Training>> | <<FILL>> | <<FILL>> | <<FILL>> | <<FILL>> | <<FILL>> | <<FILL>> |
<<FILL: e.g. Internal audit>> | <<FILL>> | <<FILL>> | <<FILL>> | <<FILL>> | <<FILL>> | <<FILL>> |
<<FILL: e.g. Management review>> | <<FILL>> | <<FILL>> | <<FILL>> | <<FILL>> | <<FILL>> | <<FILL>> |
<<FILL: e.g. Validation and qualification>> | <<FILL>> | <<FILL>> | <<FILL>> | <<FILL>> | <<FILL>> | <<FILL>> |
<<FILL: e.g. Electronic records and signatures>> | <<FILL: 21 CFR Part 11; EU GMP Annex 11>> | <<FILL>> | <<FILL>> | <<FILL>> | <<FILL>> | <<FILL>> |
<<FILL: e.g. Audit trail review>> | <<FILL>> | <<FILL>> | <<FILL>> | <<FILL>> | <<FILL>> | <<FILL>> |
<<FILL: add every requirement your operation is subject to>> | <<FILL>> | <<FILL>> | <<FILL>> | <<FILL>> | <<FILL>> | <<FILL>> |
3. How to build and maintain it
- Start from the applicable regulatory framework, not from your existing procedure list. List every regulation, standard, and guidance that binds your operation (GMP, GCP, GLP, the specific CFR parts, ICH guidelines, ISO standards for any device constituent), then derive the requirements each imposes.
- For each requirement, name the QMS process that satisfies it and the specific procedure, by document number and current version, that governs it.
- Do not leave a requirement row with no procedure. A blank cell here is exactly the gap an inspector is trained to find; if the gap is real, open a CAPA or a document-control action to close it, do not leave the row blank waiting for someone to notice later.
- Update this matrix the moment a procedure is issued, revised, or retired, and whenever a new regulation or guidance becomes applicable. Treat it as a document-control-triggered artifact, not an annual exercise.
- Spot-check both directions periodically: pick a requirement and confirm the named procedure current and correct, then pick a procedure and confirm it maps to a real requirement (an orphan procedure governing nothing you are actually obligated to do is a sign of scope drift).
4. Acceptance criteria
- Every requirement genuinely applicable to the operation has exactly one primary governing procedure named, current, and correctly versioned.
- No cell references a retired, superseded, or renumbered document.
- The matrix has been updated within the current document control cycle for every procedure change since its last review.
- A spot-check in both directions (requirement to procedure, and procedure to requirement) finds no broken link.
5. References
EU GMP Chapter 4 (Documentation), for the expectation of a controlled, traceable document set. ICH Q10, Pharmaceutical Quality System, for the model of interacting, documented QMS processes this matrix maps. 21 CFR 211.22(d) and 211.100, for the “written procedures, followed” expectation this matrix demonstrates is met.
Confirm the current version of each reference before issue.
6. Revision history
| Version | Date | Author | Summary of change |
|---|---|---|---|
<<FILL: 1.0>> | <<FILL: date>> | <<FILL: author>> | Initial issue. |
Filled specimen
The following shows four rows completed for an example biologics manufacturer, so you can see the level of detail expected. The company and document numbers are illustrative; replace them with your own.
| Requirement | Source | QMS process | Governing procedure | Tier | Owner | Last reviewed |
|---|---|---|---|---|---|---|
| Document control | EU GMP Ch.4; 21 CFR 211.180/211.100; ICH Q10 | Document control | SOP-QA-001 v4.0 | 2 | Head of QA | 2026-03-01 |
| CAPA | ICH Q10 §3.2.2; 21 CFR 211.192 | CAPA | SOP-QA-010 v3.1 | 2 | Head of QA | 2026-01-15 |
| Audit trail review | 21 CFR Part 11; EU GMP Annex 11 §9 | Data integrity | SOP-QA-014 v2.0 | 2 | Head of QA | 2026-06-15 |
| Supplier qualification | EU GMP Annex 11 §3.2; ICH Q10 | Supplier management | SOP-PROC-004 v1.2 | 2 | Head of Procurement Quality | 2026-05-01 |
A gap assessment against this specimen would immediately flag if, for example, “electronic signatures” had no dedicated row, since it is a distinct Part 11 subpart C obligation from general audit trail review and deserves its own line rather than being assumed to be covered by an adjacent one.
Common inspection findings this matrix prevents
- A requirement the inspector names for which the company has no ready answer, because no single artifact maps requirements to procedures.
- A procedure cited as governing a requirement that turns out to be retired or superseded.
- Genuine coverage gaps (a requirement with no procedure at all) discovered live during the inspection rather than through the company’s own periodic self-check.
- Scope drift, where procedures exist for activities the company no longer performs, or new obligations exist with no procedure written yet.
How to adapt this matrix
- Set the owner and update-trigger fields in the header; this matrix only stays useful if someone owns keeping it current.
- Build the requirement list from your actual regulatory footprint (site, products, markets), not from a generic template list; a cell and gene therapy site and a combination-product site will need different rows.
- Wire this matrix’s update into your document control SOP so every new or revised procedure automatically triggers a matrix update, rather than relying on someone remembering.
- Use it as the first artifact in a self-inspection or gap assessment; see the QMS document hierarchy gap assessment checklist for the fuller method this matrix feeds.