Independent and not affiliated with the FDA, MHRA, ISPE, PDA, or any agency. Get the appgoutham@madhadi.com
madhadi.comData Integrity & GxP Quality
Browse all topics → Articles Templates & Procedures Learning paths GlossaryScenariosToolsRegulatory ReferencesLearning PathsTopics About Start here
Plan Plug-and-play starting point Audits & Inspection

Plan: Multi-Agency Inspection Program (FDA and EU)

A plug-and-play program plan for running one inspection-readiness program that satisfies both FDA and EU GMP oversight: harmonize to the higher bar, one notice-agnostic playbook, dual predicate-rule computerized systems, network-wide CAPA, and a two-agency intelligence feed, with a filled specimen.

Document type: Plan

Read and copy the template below into your own quality system. It is a generic starting point for your own internal use, provided as is, with no warranty; see the Terms and License. Adopting it does not by itself create compliance.

This is a ready-to-use program plan for running one inspection program across FDA and EU oversight. Replace every <<FILL: ...>> placeholder with your own specifics and route it through your normal quality governance. A worked filled specimen of the site-readiness matrix follows. This is educational guidance to adapt and verify, not legal or regulatory advice.

For a company with sites under both FDA and EU oversight, the operating model that holds up is one program, built to the higher bar, applied everywhere. Maintaining separate FDA and EU playbooks that drift apart, or a lower bar for sites that “only” face one agency, invites the inconsistency an investigator probes when comparing a network. This plan defines that single program.

Document control header

FieldEntry
Document titleMulti-Agency Inspection Program (FDA and EU)
Document number<<FILL: DOC-ID, e.g. QP-INS-001>>
Version<<FILL: version>>
Program owner<<FILL: role, e.g. VP Quality / Head of Compliance>>
Sites in scope<<FILL: list of sites and the agencies each faces>>

1. Scope

This plan covers inspection readiness and management for all sites at <<FILL: COMPANY>> that are subject to FDA, EU national competent authority, or MHRA oversight, across drug, biologic, and (where applicable) combination-product manufacturing. It applies to routine, pre-approval and pre-authorisation, and for-cause inspections, announced and unannounced.

2. Approach

  • Harmonize to the stricter requirement. Where FDA and EU GMP differ (for example the EU Qualified Person batch certification, which has no direct FDA counterpart), design the quality system to the more stringent requirement and run one system, not parallel systems.
  • One quality standard across sites. Run every site to the standard expected by the most demanding authority likely to inspect it, regardless of which agencies currently do.
  • One notice-agnostic playbook. A single inspection management procedure that works whether the notice is weeks or none, with one front-room and back-room workflow, a trained host and scribe pool, and a live request log.
  • Dual predicate-rule systems. Build computerized systems to satisfy 21 CFR Part 11 and EU GMP Annex 11 at once (validation, audit trails, access control, electronic signatures, data retention).
  • Network-wide CAPA. A CAPA that closes a finding at one site is assessed and applied across the network, because a fix at the cited site while the gap persists elsewhere is a finding waiting to happen.
  • Two-agency intelligence feed. Read FDA 483s and Warning Letters and EU EudraGMDP entries and member-state guidance, and route the themes into the internal audit plan.

3. Risk basis

Prioritize readiness effort by site risk: product type (sterile, biologic, high-potency, cell and gene therapy), inspection history, time since last inspection, and active approval tracks. Higher-risk sites get more frequent mock inspections and self-inspections. The risk logic mirrors the risk-based scheduling the authorities themselves use.

4. Deliverables

DeliverableDescriptionOwner
Inspection management SOPOne notice-agnostic front-room/back-room procedure<<FILL>>
Trained host and scribe poolNamed, rehearsed roles with backups per site<<FILL>>
Request log and back-room QC stepEvery request logged, QC’d before the front room<<FILL>>
Dual-predicate computerized-system standardPart 11 and Annex 11 satisfied together<<FILL>>
Data integrity self-inspection routineThe inspector’s forensic technique run on yourself<<FILL>>
Network-wide CAPA processRead-across of every finding across sites<<FILL>>
Two-agency intelligence feed483/Warning Letter and EudraGMDP themes into audits<<FILL>>
QP inspection story (EU-facing sites)QP certification records and access to information<<FILL>>

5. Roles

RoleResponsibility
Program ownerOwns the program, harmonization decisions, and network consistency
Site inspection lead / hostRuns the room at each site under the one playbook
Back-room managerDocument staging and QC before anything reaches the front room
Quality leadershipCommitments, classification disputes, escalations
Regulatory affairsApplication context for pre-approval and pre-authorisation visits
Qualified Person (EU sites)Batch certification narrative and access to certifying information

6. Schedule

  • Mock inspections: <<FILL: cadence by site risk, e.g. high-risk sites annually>>
  • Data integrity self-inspections: <<FILL: e.g. quarterly>>
  • Intelligence review and audit-plan refresh: <<FILL: e.g. quarterly>>
  • Program review: <<FILL: e.g. annually and after any significant finding>>

7. Acceptance criteria

  • One inspection management procedure is in use at every site, notice-agnostic.
  • Computerized systems are validated to both Part 11 and Annex 11.
  • Every inspection finding is assessed network-wide and the CAPA applied across sites.
  • The two-agency intelligence feed demonstrably drives the internal audit plan.
  • EU-facing sites can present a complete QP certification story.
  • No site runs to a lower standard than the most demanding authority likely to inspect it.

8. References

FDA: FD&C Act; 21 CFR Parts 210/211 and Part 11; 21 USC 374; the 483 and Warning Letter process. EU: Directive 2001/83/EC (Title IV); Commission Directive (EU) 2017/1572; EudraLex Volume 4 and its Annexes, including Annex 11 and Annex 16. PIC/S PI 040 (deficiency classification) and PI 041 (data integrity), referenced by number and title. The FDA and EU mutual recognition agreement for GMP inspections of human medicines, and its scope limits.

Confirm the current version of each reference before issue.

Revision history

VersionDateAuthorSummary of change
<<FILL: 1.0>><<FILL: date>><<FILL: author>>Initial issue.

Approvals

RoleNameSignatureDate
Author<<FILL>>
Program owner<<FILL>>
Approver (QA)<<FILL>>

Filled specimen: site-readiness matrix

The following shows the matrix completed for an example three-site network, so you can see how the one-program-to-the-higher-bar principle plays out. The sites and details are illustrative; replace them with your own.

SiteProductsAgencies that inspectStandard appliedExtra EU elementsMock cadence
Site ASterile biologicFDA, EU (national CA), MHRAHighest bar across all threeQP certification, Annex 1, Annex 11Annually
Site BOral solid, US market only todayFDA today; EU filing plannedBuilt now to the EU bar in anticipationQP role and Annex 11 being stood up ahead of the filingAnnually
Site CAPI intermediateFDA, EUHighest barAnnex 11, EudraGMDP certificate maintainedEvery 18 months

In this example Site B faces only FDA today but is a planned EU filing, so it is already being run to the EU bar, including standing up the Qualified Person role and Annex 11 controls before the pre-authorisation inspection rather than scrambling later. Building to the higher standard everywhere means no site becomes the weak link an investigator finds when comparing the network.

Common failures this plan prevents

  • Separate FDA and EU playbooks that drift apart and confuse staff.
  • A lower standard at a site that “only” faces one agency, exposed the moment a second agency arrives or the network is compared.
  • A CAPA that fixes the cited site while the same gap stays open across the network.
  • Computerized systems built to one predicate rule, failing the other at inspection.
  • An EU-facing site with no coherent Qualified Person certification story.

How to adapt this plan

  1. List your real sites and the agencies each faces, and set the standard to the most demanding likely inspector.
  2. Point the deliverables at your actual SOPs, self-inspection routine, and intelligence feed.
  3. Set the mock and self-inspection cadences from your site risk.
  4. Review the plan after any significant finding and apply the read-across across the network.
  5. Keep the regulatory references current, since inspection frameworks and the MRA scope are periodically revised.
Use madhadi.com as an app Full screen, works offline, one tap from your home screen.