Independent and not affiliated with the FDA, MHRA, ISPE, PDA, or any agency. Get the appgoutham@madhadi.com
madhadi.comData Integrity & GxP Quality
Browse all topics → Articles Templates & Procedures Learning paths GlossaryScenariosToolsRegulatory ReferencesLearning PathsTopics About Start here
SOP Plug-and-play starting point Data Integrity

SOP: True Copy Generation, Verification, and Certification

A plug-and-play SOP for making defensible true copies of paper and dynamic electronic records: original determination, the copy method by record type, verification, certification, original disposition, and retention, with a filled specimen and the regulations it satisfies.

Document type: SOP

Read and copy the template below into your own quality system. It is a generic starting point for your own internal use, provided as is, with no warranty; see the Terms and License. Adopting it does not by itself create compliance.

This is a ready-to-use SOP for generating, verifying, and certifying true copies of GxP records, both paper and dynamic electronic. Replace every <<FILL: ...>> placeholder with your own specifics, set your document numbers and dates, and route it through your normal document control, review, and approval. A worked filled specimen follows the template. Verify each cited regulation against the current source before you rely on it. This is general guidance to adapt and verify, not legal or regulatory advice.

Document control header

FieldEntry
Document titleTrue Copy Generation, Verification, and Certification
Document number<<FILL: SOP-ID, e.g. SOP-QA-021>>
Version<<FILL: version, e.g. 1.0>>
Effective date<<FILL: effective date>>
Supersedes<<FILL: prior version or "New">>
Document owner<<FILL: role, e.g. Head of Quality Assurance>>
Applies to<<FILL: sites / departments in scope>>

1. Purpose

This procedure defines how <<FILL: COMPANY NAME>> makes a copy of an original GxP record that preserves the full content and meaning of the original, so the copy can replace, migrate, archive, or supply the original without loss of integrity or legal weight. It exists so that records can be scanned, exported, migrated, and archived across decades and platform changes while remaining trustworthy, and so an original may be retired only when a defensible copy exists.

2. Scope

This procedure applies to true copies of any GxP record, in any media, including paper records copied to electronic image, dynamic electronic records exported or migrated between systems, and copies supplied to inspectors, partners, or archives. It covers both static records (fixed-format, non-interactive) and dynamic records (searchable, reprocessable). It does not by itself authorize destruction of any original; destruction follows <<FILL: SOP-ID for records retention and destruction>>.

3. Responsibilities

RoleResponsibility
Record owner / SMEConfirms what the original is and whether it is static or dynamic; defines what “complete” means for the record type.
Person making the copyExecutes the copy per the correct method, performs or triggers verification, applies the certification.
Independent verifierFor manual copies of critical records, performs the second-person comparison of copy against original.
ValidationEstablishes and maintains the validated copy, export, or migration processes used for electronic true copies.
Quality AssuranceApproves the method, oversees certification, authorizes original disposition, and handles exceptions.
IT / system administratorProvides read access, export tooling, checksums, and controlled storage for electronic copies.

4. Definitions

  • Original record (raw data / source data): the first durable, contemporaneous capture of an observation, in the format it was first captured. If an instrument writes a data file, that file is the original; if a value is first written by hand, that worksheet is the original.
  • Static record: a fixed-format record with no user interaction, such as a paper form or a scanned image.
  • Dynamic record: a record that allows interaction, such as a chromatographic data file that can be reprocessed and re-integrated, carrying metadata and an audit trail.
  • True copy: a copy verified to preserve the full content and meaning of the original, including metadata, audit trail, and, for a dynamic original, its dynamic (reprocessable) nature. In GCP the equivalent term is certified copy.
  • Certification: a record stating that the copy was verified against the original, by whom or by what validated process, and when.

5. Procedure

5.1 Determine the original and its type

  1. Confirm you hold the genuine original, not an earlier copy.
  2. With the record owner or SME, classify the record as static or dynamic (see the classification form referenced in section 7).
  3. Define what a complete copy must contain for this record type: content, metadata (who, when, instrument, method version), audit trail, and reprocessing ability for dynamic records.

5.2 Copy a static record (for example, scanning paper)

  1. Reproduce the record completely: all pages, both sides, attachments, and associated metadata such as the original date and any color or low-contrast detail.
  2. Confirm resolution and legibility so no field, signature, or handwritten note is lost or cut off.
  3. Proceed to verification (5.4).

5.3 Copy a dynamic record (export or migration)

  1. Use only a validated copy, export, or migration process; do not hand-copy or screen-capture a dynamic record.
  2. Include the data file, its metadata, its audit trail, and the method or configuration needed to reprocess it.
  3. Execute the copy through the validated process into the target format or system.
  4. Confirm the copy still opens and reprocesses to the same result before you rely on it (see 5.4).
  5. A printout or PDF of a dynamic record may be retained as a convenience summary, but it is not the true copy and must not be labeled as one.

5.4 Verify the copy against the original

  1. Manual verification (static or low-volume): an independent qualified person compares the copy to the original page by page, or field by field, for completeness and legibility, and records the result.
  2. Automated verification (electronic, high-volume): confirm integrity by checksum or hash match, record counts, and a sampled re-open-and-reprocess test that confirms the copy still behaves dynamically.
  3. If verification fails, do not certify; correct the copy method and repeat.

5.5 Certify the copy

  1. Apply a certification that identifies the original (document number, batch, study, sample ID), states the verification performed, and names the verifier or the validated process, with the date.
  2. For manual copies, use a signed certification statement. For electronic copies, the validated process attests to the copy, supported by a QA-reviewed certification for the batch of copies.
  3. Enter the certification in the true copy certification register (<<FILL: register ID or link>>).

5.6 Disposition of the original

  1. The default is to retain the original per the retention schedule.
  2. An original may be destroyed only after a certified true copy exists, only if <<FILL: SOP-ID for records retention and destruction>> permits it, and only with QA authorization. The certification must predate the destruction.
  3. For a migrated dynamic record, confirm retrieval and reprocessing work in the target environment before retiring the source system or its data.

6. Acceptance criteria

A true copy is acceptable when all of the following are true:

  • The copy contains the complete content and meaning of the original, including metadata and audit trail.
  • For a dynamic original, the copy is still dynamic and reprocesses to the same result, not a flattened image.
  • A verification step was performed and documented (human signature or validated-process attestation).
  • A certification exists identifying the original, the verifier or process, and the date, and it is entered in the register.
  • If the original was destroyed, a controlled procedure authorized it and the certification predates the destruction.

7. References

21 CFR Part 11 (electronic records and signatures). 21 CFR 211.180 and 211.194 (records and retention; laboratory records). FDA Guidance, Data Integrity and Compliance With Drug CGMP: Questions and Answers (2018). MHRA GxP Data Integrity Guidance and Definitions (2018), true copy and dynamic record definitions. PIC/S PI 041, Good Practices for Data Management and Integrity. EU GMP Annex 11, Computerised Systems; ICH E6 Good Clinical Practice (certified copy).

Related deliverables: the Form: Static vs Dynamic Record Classification and Original-Record Determination feeds section 5.1, and the Log: True Copy Certification Register captures section 5.5. Confirm the current version and clause numbers of each reference before issue.

8. Records generated

  • True copy certification statement or record (per copy or per batch of copies).
  • Entry in the true copy certification register.
  • Verification evidence (comparison record, checksum report, reprocess test result).

9. Revision history

VersionDateAuthorSummary of change
<<FILL: 1.0>><<FILL: date>><<FILL: author>>Initial issue.

10. Approvals

RoleNameSignatureDate
Author<<FILL>>
Reviewer (QA)<<FILL>>
Approver (Quality Head)<<FILL>>

Filled specimen

The example below shows the certification for one electronic true copy batch, so you can see the level of detail an inspector expects. The company, system, and numbers are illustrative; replace them with your own.

Record type: dynamic (chromatography data files with audit trails).

FieldEntry
Original identityCDS project ARCHIVE-2021-Q3, instrument HPLC-07, 1,284 data files plus audit trails
ClassificationDynamic (reprocessable); PDFs of reports retained separately as summaries only
Copy methodValidated archival export routine ARC-EXP v3.2 into vendor-neutral archive
Completeness definitionData file, metadata, full audit trail, acquisition method
Integrity verificationSHA-256 hash match, 1,284 of 1,284 passed; record count matched
Dynamic reprocess test25 files re-opened and re-integrated in the archive viewer to the same result
Certified byValidated process ARC-EXP v3.2 plus QA reviewer M. Okafor
Certification date18 July 2026
Register entryTCR-2026-0087
Original dispositionSource CDS project retired after retrieval confirmed in archive

In this example the copy preserved the dynamic nature (files still reprocess), integrity was proven by hash and by a reprocess sample, the certification names both the validated process and a QA reviewer, and the source was retired only after retrieval was confirmed in the target. That chain, complete copy to verification to certification to controlled retirement, is exactly what a reviewer expects to see.

Common inspection findings this SOP prevents

  • A flattened PDF of a dynamic record is filed and labeled a “true copy,” with no reprocessing ability and no audit trail.
  • An original is destroyed with no certified copy, or with a certification dated after the destruction.
  • A copy is made and filed with no documented verification against the original.
  • Metadata or audit trail is stripped on copy, so the copy no longer carries the record’s meaning.
  • Routine IT backups are treated as archival true copies, and the restore-and-reprocess path was never tested.

How to adapt this SOP

  1. Set your document number, owner, and effective date in the header.
  2. Point the cross-references in sections 2, 5.6, and 7 to your real retention/destruction, classification, and register documents.
  3. Name the validated export, migration, and checksum tools you use in section 5.3 and 5.4, and reference their validation records.
  4. Set the second-person verification rule in 5.4 to match your criticality thresholds.
  5. Confirm every regulation in section 7 against the current published version before issue.
Use madhadi.com as an app Full screen, works offline, one tap from your home screen.