This is a ready-to-use work instruction. Replace every <<FILL: ...>> placeholder with your own specifics and reference it from your parent deviation and investigation SOP. A worked filled specimen follows the template. It is an educational aid to adapt and verify, not legal, HR, or disciplinary advice; run any accountability decision through your own HR and legal processes.
Control header
| Field | Entry |
|---|---|
| Work instruction number | <<FILL: WI-ID, e.g. WI-QA-031>> |
| Parent SOP | <<FILL: deviation / investigation SOP-ID>> |
| Version | <<FILL: version>> |
| Effective date | <<FILL: date>> |
| Owner | <<FILL: role, e.g. Head of Quality>> |
Purpose
Classify a data integrity event so the response fits what actually happened. The aim is to separate the honest reporter, whose event is a signal to fix the system, from the deliberate falsifier, whose event calls for accountability, and to name the large middle category of at-risk behavior that most normalized deviance falls into. Applying one response to all three is the fastest way to kill a reporting culture.
When to use
Use this work instruction whenever an event involves the reliability of a GxP record: a deleted or re-run result, a changed value without a reason, a record made not-contemporaneously, a shared login, a bench practice that differs from the procedure, or any similar finding. Use it before deciding on corrective action, and before any conversation that could feel disciplinary.
Definitions
- Honest error: an unintended departure from a correct procedure. Driven by inattention, ambiguity, or poor system design.
- At-risk behavior: a shortcut that the person did not recognize as risky, usually because the system had made it feel normal. Neither a deliberate falsification nor something every careful peer would have done.
- Falsification: knowingly recording something untrue, usually under pressure.
- Fraud: deliberate, organized deception for gain.
- Substitution test: would another competent, similarly trained person, in the same situation with the same information and the same system, plausibly have done the same thing?
- Knowledge test: did the person knowingly record something false, or knowingly take an unjustifiable risk?
Procedure
Step 1: Secure the facts before anyone is interviewed
- Preserve the records and their context (the audit trail, the instrument files, the surrounding batch or run). Do not let the person alter anything further.
- Assemble what was done, when, by whom, and against which procedure version. Confirm the person was trained on that version.
- Do not form a conclusion yet. The classification comes from the two tests, not from how serious the outcome looks.
Step 2: Apply the substitution test
- Ask whether a competent, similarly trained peer, in the same system with the same information and pressure, would plausibly have done the same thing.
- If yes, the system shares the blame. The primary fix is a design fix (a clearer procedure, a system control, a removed pressure), whatever else follows. Continue to Step 3, because a design-driven event can still involve a knowing act.
Step 3: Apply the knowledge test
- Ask whether the person knowingly recorded something untrue, or knowingly took a risk they could not justify.
- If they knowingly recorded something false: this is falsification (or, if organized for gain, fraud). Accountability applies regardless of the pressure they were under.
- If they took a shortcut they did not recognize as risky: this is at-risk behavior. The response is coaching plus removing the incentive or condition that made the shortcut feel normal, not punishment.
- If neither is true and a careful peer would plausibly have done the same: this is honest error. The response is a system or design fix.
Step 4: Assess data reliability beyond the single event
- One deleted injection implies a question about the whole data set and possibly other batches or runs. Widen the assessment accordingly.
- Decide product impact, batch impact, and any field-action or disclosure question through the parent SOP. A falsification carries reliability and disclosure obligations that an honest error does not.
Step 5: Record the classification and route the response
- Record the event, the two test outcomes, the classification, and the basis for it.
- Route the corrective action to match the category (design fix, coaching, or accountability), and open the product-impact and CAPA work through the parent SOP.
- Do not close a deliberate act with “retrain the analyst.” Training is not a corrective action for a rule someone broke on purpose.
Classification at a glance
| Substitution test | Knowledge test | Category | Primary response |
|---|---|---|---|
| A peer would plausibly do the same | No knowing false record or unjustified risk | Honest error | System / design fix, error-proofing |
| A peer would not clearly do the same | Took a shortcut, did not see the risk | At-risk behavior | Coaching, remove the enabling incentive |
| Either | Knowingly recorded something false | Falsification | Accountability, plus reliability and disclosure assessment |
| Either | Organized deception for gain | Fraud | Investigation, HR and legal, accountability |
Acceptance criteria
- The two tests were applied and their outcomes recorded before any accountability decision.
- Data reliability was assessed beyond the single event.
- The corrective action matches the category, and no deliberate act was closed with training alone.
- An honest reporter was not treated the same as a deliberate falsifier.
References
FDA guidance, Data Integrity and Compliance With Drug CGMP: Questions and Answers (December 2018). 21 CFR 211.192 (investigation of discrepancies and failures). The just-culture framework as applied in high-reliability safety fields, distinguishing honest error and at-risk behavior from reckless disregard and willful violation.
Confirm the current version of each reference before you rely on it.
Record generated: event classification record
| Field | Entry |
|---|---|
| Event / deviation reference | <<FILL: number>> |
| Record(s) affected | <<FILL: system, run, batch>> |
| Procedure version in force and training confirmed | <<FILL: version, trained Y/N>> |
| Substitution test outcome | <<FILL: peer would / would not plausibly do the same, why>> |
| Knowledge test outcome | <<FILL: knowing false / unjustified risk / neither>> |
| Classification | Honest error / At-risk / Falsification / Fraud |
| Data reliability scope assessed | <<FILL: single event / wider data set / other batches>> |
| Response routed | <<FILL: design fix / coaching / accountability>> |
| Classified by (name, date) | <<FILL>> |
| QA concurrence (name, date) | <<FILL>> |
Revision history
| Version | Date | Author | Summary of change |
|---|---|---|---|
<<FILL: 1.0>> | <<FILL: date>> | <<FILL: author>> | Initial issue. |
Filled specimen
An analyst is found to have re-run a sample after an out-of-specification injection and reported the passing re-run, with the first injection deleted from the sequence. The classification record, completed:
| Field | Entry |
|---|---|
| Event / deviation reference | DEV-2026-0208 |
| Record(s) affected | Chromatography data system, run HPLC-04-2607-014, plus a review of the analyst’s last 20 runs |
| Procedure version in force and training confirmed | OOS SOP Rev E; analyst trained 12 Jan 2026 (Y) |
| Substitution test outcome | A competent peer would open an OOS investigation, not delete the first injection; a peer would not plausibly do the same |
| Knowledge test outcome | The analyst knowingly deleted a failing result and reported the passing re-run: knowing false record |
| Classification | Falsification |
| Data reliability scope assessed | Widened to the analyst’s last 20 runs; two more deletions found, expanding the investigation |
| Response routed | Accountability through HR and QA; product-impact and disclosure assessment opened; not closed with retraining |
| Classified by | A. Okafor, 06 Aug 2026 |
| QA concurrence | R. Mehta, 06 Aug 2026 |
The point of the record is that the classification is driven by the two tests and documented, so the response (accountability plus a wider reliability review, not a training record) is defensible.
Common inspection findings this work instruction prevents
- Deliberate acts closed with “retrain the analyst,” signaling the root cause was never found.
- Honest errors treated punitively, which teaches people to stop reporting.
- A single falsification investigated in isolation, without assessing whether other records are affected.
- No consistent, documented method for deciding accountability, so decisions look arbitrary.
How to adapt this work instruction
- Point the parent-SOP references at your real deviation and investigation procedures.
- Align the accountability routing with your HR and legal processes; this document classifies behavior, it does not administer discipline.
- Keep the two tests exactly as written; their value is that they are applied before, and independent of, the seriousness of the outcome.
- Confirm each reference against its current published version before issue.