This is a ready-to-use plan for a single GCP audit, sized for either an investigator site or a vendor. It is written and approved before the audit so scope, standard, and sample are agreed rather than improvised on the day. Replace every <<FILL: ...>> placeholder, set your document numbers, and route it through your audit SOP. A worked filled specimen for a site audit follows.
Audit plan control
| Field | Entry |
|---|---|
| Audit ID | <<FILL: e.g. AUD-2026-014>> |
| Audit type | Routine / for-cause / qualification (select one) |
| Entity audited | <<FILL: site name and number, or vendor and service>> |
| Trial(s) / scope area | <<FILL: protocol number(s) or process>> |
| Planned dates | <<FILL: date(s)>> |
| Location / modality | On-site / remote / hybrid at <<FILL: address or platform>> |
| Lead auditor | <<FILL: name>> |
| Co-auditor / SME | <<FILL: name, area>> |
| Independence confirmed | Yes (auditor not involved in the audited activity) |
| Governing SOP | <<FILL: SOP-ID for GCP audits>> |
1. Objectives
State what this audit sets out to determine, for example: whether the site conducted the trial per the protocol, GCP, and applicable regulations; whether subject rights and safety were protected; and whether the data in the database can be traced to real, consented, treated subjects. For a for-cause audit, state the trigger and the specific question the audit must answer.
2. Scope and standard
- In scope:
<<FILL: activities, subjects, time period, systems>> - Out of scope:
<<FILL: anything explicitly excluded>> - Standard measured against: ICH E6 (state R2 or R3 as in force), the protocol and its amendments, applicable regulations (
<<FILL: 21 CFR Parts 312, 50, 54, 56; EU CTR 536/2014; local law>>), and the sponsor SOPs and plans (monitoring plan, safety management plan, data management plan).
3. Sample
State the sample frame and how it was chosen, so it is defensible. A common site sample frame:
- All subjects with SAEs.
- All early discontinuations and withdrawals.
- The first and last enrolled subjects.
- A random selection across the remainder to a defined count.
For a vendor audit, sample real transactions to trace end to end (for a lab, a sample from receipt to reported result; for an EDC vendor, a change request from intake to release).
4. Areas to be reviewed
List the areas and the priority order. For a site audit, typically: regulatory/essential documents and delegation, informed consent, eligibility, source-to-CRF verification, IP management and accountability, safety reporting, protocol compliance, and facilities and equipment. For a vendor audit, tailor to the service: quality system, personnel, the service-specific process, data integrity and Part 11, subcontracting, security and continuity, and inspection history.
5. Agenda
| Time | Activity | Participants |
|---|---|---|
<<FILL>> | Opening meeting: scope, standard, schedule, how findings are communicated | Auditor, PI or vendor lead, key staff |
<<FILL>> | Document and facility review | Auditor, coordinator/host |
<<FILL>> | Source-data verification / transaction tracing | Auditor, SME |
<<FILL>> | Staff interviews against the delegation log / org chart | Auditor, named staff |
<<FILL>> | Daily debrief | Auditor, host |
<<FILL>> | Closing meeting: preliminary findings, classification, CAPA expectations | Auditor, PI/vendor lead, management |
6. Roles and logistics
- Lead auditor: runs the audit, owns the report.
- Co-auditor / SME: provides technical depth (bioanalytical, data management, PV).
- Host (site or vendor): provides access, staff availability, and a working space.
- Requested in advance:
<<FILL: document list, system access, subject list, prior audit/inspection history>>. - Confidentiality and data handling: how records are viewed and any copies controlled.
7. Acceptance criteria for the audit
The audit is complete and acceptable when: the planned sample and areas were covered or any gap is justified; findings are stated as objective fact tied to evidence and a real requirement; findings are classified per the scheme; a closing meeting communicated preliminary findings; and the report will issue within the SOP timeline with a defined CAPA response date.
8. References
ICH E6 Good Clinical Practice; the protocol and amendments; applicable regulations (21 CFR Parts 312/50/54/56, EU CTR 536/2014, local law); sponsor SOPs and plans.
Confirm the current version of each reference and the ICH E6 version in force before issue.
9. Approvals
| Role | Name | Signature | Date |
|---|---|---|---|
| Lead auditor | <<FILL>> | ||
| QA / audit program manager | <<FILL>> |
Filled specimen
The following shows the plan completed for an illustrative investigator site audit. The site, numbers, and dates are illustrative; replace them with your own.
| Field | Entry |
|---|---|
| Audit ID | AUD-2026-014 |
| Audit type | Routine |
| Entity audited | Site 021, Riverside Clinical Research |
| Trial(s) / scope area | ONC-301 (Phase 3) |
| Planned dates | 15-16 September 2026 |
| Location / modality | On-site, Riverside, with remote source access for eCRF |
| Lead auditor | A. Lund |
| Co-auditor / SME | S. Rahman (data management) |
| Independence confirmed | Yes |
Objectives: confirm ONC-301 was conducted per protocol, GCP, and 21 CFR Parts 312/50/56 at Site 021, with subject rights and safety protected and database data traceable to source.
Sample: 12 of 34 enrolled subjects: both SAE subjects (007, 019), three early discontinuations (004, 011, 028), first and last enrolled (001, 034), and five random (006, 013, 017, 022, 030).
Areas, priority order: informed consent; eligibility; source-to-CRF for the sample; IP accountability and blinding; SAE capture and reporting timelines; protocol compliance and visit windows; delegation and training; pharmacy and sample handling.
In this example the sample is defensible on its face: it captures every safety and discontinuation subject, brackets enrollment, and adds a random draw, so the auditor is not open to the charge of only looking at clean records.
Common inspection findings this plan prevents
- An audit with no documented plan, so scope and sample look improvised and possibly cherry-picked.
- A sample that avoids the risky records (SAEs, discontinuations), which undermines the audit’s credibility.
- No stated standard, so findings cannot be tied to a specific requirement.
- No closing meeting or CAPA expectation set, so findings drift with no response clock.
How to adapt this plan
- Set your audit ID, entity, dates, and governing SOP in the control block.
- Swap the site sample frame in section 3 for a vendor transaction-tracing plan when auditing a CRO or lab.
- Tailor section 4 to the entity: a central lab and an eTMF vendor share almost no checklist.
- State the ICH E6 version in force and confirm the regulation list for the region before issue.