Independent and not affiliated with the FDA, MHRA, ISPE, PDA, or any agency. Get the appgoutham@madhadi.com
madhadi.comData Integrity & GxP Quality
Browse all topics → Articles Templates & Procedures Learning paths GlossaryScenariosToolsRegulatory ReferencesLearning PathsTopics About Start here
Plan Plug-and-play starting point Clinical & GCP

Plan: GCP Audit Plan (Per-Audit, Site or Vendor)

A plug-and-play per-audit GCP audit plan: objectives, scope and standard, subject or transaction sample, agenda, roles, logistics, and acceptance, with a filled specimen for an investigator site audit.

Document type: Plan

Read and copy the template below into your own quality system. It is a generic starting point for your own internal use, provided as is, with no warranty; see the Terms and License. Adopting it does not by itself create compliance.

This is a ready-to-use plan for a single GCP audit, sized for either an investigator site or a vendor. It is written and approved before the audit so scope, standard, and sample are agreed rather than improvised on the day. Replace every <<FILL: ...>> placeholder, set your document numbers, and route it through your audit SOP. A worked filled specimen for a site audit follows.

Audit plan control

FieldEntry
Audit ID<<FILL: e.g. AUD-2026-014>>
Audit typeRoutine / for-cause / qualification (select one)
Entity audited<<FILL: site name and number, or vendor and service>>
Trial(s) / scope area<<FILL: protocol number(s) or process>>
Planned dates<<FILL: date(s)>>
Location / modalityOn-site / remote / hybrid at <<FILL: address or platform>>
Lead auditor<<FILL: name>>
Co-auditor / SME<<FILL: name, area>>
Independence confirmedYes (auditor not involved in the audited activity)
Governing SOP<<FILL: SOP-ID for GCP audits>>

1. Objectives

State what this audit sets out to determine, for example: whether the site conducted the trial per the protocol, GCP, and applicable regulations; whether subject rights and safety were protected; and whether the data in the database can be traced to real, consented, treated subjects. For a for-cause audit, state the trigger and the specific question the audit must answer.

2. Scope and standard

  • In scope: <<FILL: activities, subjects, time period, systems>>
  • Out of scope: <<FILL: anything explicitly excluded>>
  • Standard measured against: ICH E6 (state R2 or R3 as in force), the protocol and its amendments, applicable regulations (<<FILL: 21 CFR Parts 312, 50, 54, 56; EU CTR 536/2014; local law>>), and the sponsor SOPs and plans (monitoring plan, safety management plan, data management plan).

3. Sample

State the sample frame and how it was chosen, so it is defensible. A common site sample frame:

  • All subjects with SAEs.
  • All early discontinuations and withdrawals.
  • The first and last enrolled subjects.
  • A random selection across the remainder to a defined count.

For a vendor audit, sample real transactions to trace end to end (for a lab, a sample from receipt to reported result; for an EDC vendor, a change request from intake to release).

4. Areas to be reviewed

List the areas and the priority order. For a site audit, typically: regulatory/essential documents and delegation, informed consent, eligibility, source-to-CRF verification, IP management and accountability, safety reporting, protocol compliance, and facilities and equipment. For a vendor audit, tailor to the service: quality system, personnel, the service-specific process, data integrity and Part 11, subcontracting, security and continuity, and inspection history.

5. Agenda

TimeActivityParticipants
<<FILL>>Opening meeting: scope, standard, schedule, how findings are communicatedAuditor, PI or vendor lead, key staff
<<FILL>>Document and facility reviewAuditor, coordinator/host
<<FILL>>Source-data verification / transaction tracingAuditor, SME
<<FILL>>Staff interviews against the delegation log / org chartAuditor, named staff
<<FILL>>Daily debriefAuditor, host
<<FILL>>Closing meeting: preliminary findings, classification, CAPA expectationsAuditor, PI/vendor lead, management

6. Roles and logistics

  • Lead auditor: runs the audit, owns the report.
  • Co-auditor / SME: provides technical depth (bioanalytical, data management, PV).
  • Host (site or vendor): provides access, staff availability, and a working space.
  • Requested in advance: <<FILL: document list, system access, subject list, prior audit/inspection history>>.
  • Confidentiality and data handling: how records are viewed and any copies controlled.

7. Acceptance criteria for the audit

The audit is complete and acceptable when: the planned sample and areas were covered or any gap is justified; findings are stated as objective fact tied to evidence and a real requirement; findings are classified per the scheme; a closing meeting communicated preliminary findings; and the report will issue within the SOP timeline with a defined CAPA response date.

8. References

ICH E6 Good Clinical Practice; the protocol and amendments; applicable regulations (21 CFR Parts 312/50/54/56, EU CTR 536/2014, local law); sponsor SOPs and plans.

Confirm the current version of each reference and the ICH E6 version in force before issue.

9. Approvals

RoleNameSignatureDate
Lead auditor<<FILL>>
QA / audit program manager<<FILL>>

Filled specimen

The following shows the plan completed for an illustrative investigator site audit. The site, numbers, and dates are illustrative; replace them with your own.

FieldEntry
Audit IDAUD-2026-014
Audit typeRoutine
Entity auditedSite 021, Riverside Clinical Research
Trial(s) / scope areaONC-301 (Phase 3)
Planned dates15-16 September 2026
Location / modalityOn-site, Riverside, with remote source access for eCRF
Lead auditorA. Lund
Co-auditor / SMES. Rahman (data management)
Independence confirmedYes

Objectives: confirm ONC-301 was conducted per protocol, GCP, and 21 CFR Parts 312/50/56 at Site 021, with subject rights and safety protected and database data traceable to source.

Sample: 12 of 34 enrolled subjects: both SAE subjects (007, 019), three early discontinuations (004, 011, 028), first and last enrolled (001, 034), and five random (006, 013, 017, 022, 030).

Areas, priority order: informed consent; eligibility; source-to-CRF for the sample; IP accountability and blinding; SAE capture and reporting timelines; protocol compliance and visit windows; delegation and training; pharmacy and sample handling.

In this example the sample is defensible on its face: it captures every safety and discontinuation subject, brackets enrollment, and adds a random draw, so the auditor is not open to the charge of only looking at clean records.

Common inspection findings this plan prevents

  • An audit with no documented plan, so scope and sample look improvised and possibly cherry-picked.
  • A sample that avoids the risky records (SAEs, discontinuations), which undermines the audit’s credibility.
  • No stated standard, so findings cannot be tied to a specific requirement.
  • No closing meeting or CAPA expectation set, so findings drift with no response clock.

How to adapt this plan

  1. Set your audit ID, entity, dates, and governing SOP in the control block.
  2. Swap the site sample frame in section 3 for a vendor transaction-tracing plan when auditing a CRO or lab.
  3. Tailor section 4 to the entity: a central lab and an eTMF vendor share almost no checklist.
  4. State the ICH E6 version in force and confirm the regulation list for the region before issue.
Use madhadi.com as an app Full screen, works offline, one tap from your home screen.