Independent and not affiliated with the FDA, MHRA, ISPE, PDA, or any agency. Get the appgoutham@madhadi.com
madhadi.comData Integrity & GxP Quality
Browse all topics → Articles Templates & Procedures Learning paths GlossaryScenariosToolsRegulatory ReferencesLearning PathsTopics About Start here
Work Instruction Plug-and-play starting point Manufacturing Automation

Work Instruction: Electronic Batch Record Correction and Error Handling

A ready-to-use, task-level work instruction for correcting an entry in an electronic batch record so the original is retained, the reason and approver are captured, and no critical step is bypassed, with a filled specimen and the parent SOP link.

Document type: Work Instruction

Read and copy the template below into your own quality system. It is a generic starting point for your own internal use, provided as is, with no warranty; see the Terms and License. Adopting it does not by itself create compliance.

An entry in an electronic batch record was made wrong and needs correcting. There is no ink to line through, so the correction has to follow a defined process that keeps the original, records the new value, captures the reason, and identifies who made and approved the change. Getting this wrong, overwriting the original so it disappears, is one of the most common and most damaging manufacturing data integrity findings, because it suggests the system was configured without understanding what a GMP record is. This work instruction gives operators and supervisors the exact steps. Replace every <<FILL: ...>> placeholder, tie it to your parent MES/batch-record SOP, and train against it. A filled specimen follows. Verify each cited regulation against the current source before you rely on it.

Parent SOP and scope

FieldEntry
Work instruction number<<FILL: WI-ID, e.g. WI-MFG-021>>
Parent SOP<<FILL: SOP-ID for EBR execution / batch record>>
Applies toCorrections to entries in the electronic batch record on <<FILL: MES name / lines>>
RolesOperator (makes the correction), Verifier/Supervisor (approves), QA (reviews at batch review)

This instruction covers correcting a data entry (a typed value, a selection, a timestamped confirmation) in an in-progress or completed EBR before batch disposition. It does not cover deviations to the process itself, which follow <<FILL: SOP-ID for deviations>>, though a correction may reveal one.

Before you start

  • Do not delete, overtype, or blank the original entry. The system must retain it. If your system allows an entry to be silently overwritten, stop and raise it to the system owner; that is a configuration gap, not a correction method.
  • A correction records what the value should have been and why. It is not a way to change a result to a preferred outcome. If the “correct” value is in doubt, raise a deviation rather than guessing.
  • Corrections to a critical process parameter, a result, or a signed step may require a second-person verification or an electronic signature; check the field’s control level in the parent SOP.

Procedure

StepActionPer-step acceptance
1Identify the entry to correct and confirm it is the wrong one (right step, right field).The entry, step, and field are unambiguously identified before any change.
2Determine the correct value from the source of truth (balance printout, instrument reading, verified record), not from memory.The correct value is traceable to a source, recorded in the reason.
3Use the system’s correction function (not delete-and-re-enter) to enter the new value. Confirm the original remains visible in the record and audit trail.Original entry retained and viewable; new entry recorded; both timestamped and attributed.
4Enter a meaningful reason for change: what was wrong and how the correct value was determined. Not “error”, “x”, or blank.Reason states the cause and the source of the correct value.
5Obtain the required verification or electronic signature for the field’s control level.Verifier/approver is a different person from the operator where a second check is required; signature captures name, date/time, and meaning.
6If the correction reveals a process problem (out-of-limit value, wrong material, a step done out of order), raise a deviation per the deviation SOP and reference it.Any process impact is routed to a deviation, not hidden inside a data correction.
7Do not attempt to progress past a critical step that the system has locked pending a required entry or verification; complete the entry properly rather than working around the lock.No critical-step bypass; the enforced sequence is respected.

What a defensible correction retains

After the correction, the record and its audit trail must show, together, all of: the original value, the corrected value, who made each entry, the timestamp of each (against a synchronized clock), the reason for the change, and the approver where required. If any one of those is missing, the correction is not defensible.

Acceptance criteria

  • The original entry is retained and viewable alongside the correction; nothing was erased.
  • The corrected value traces to a real source, and the reason for change is meaningful.
  • Attribution and timestamps are present for both the original and the correction.
  • Required verification or e-signature is applied, by an independent person where the field demands it.
  • No critical step was bypassed, and any process impact was raised as a deviation.

References

21 CFR 211.188 and 211.194 (batch and laboratory records, complete data, personnel identity). 21 CFR Part 11 (audit trails, electronic signatures). EU GMP Annex 11 (accuracy checks, audit trails) and Chapter 4 (documentation). ALCOA+ expectations (Original and Complete): see the parent SOP and site GDP procedure.

Confirm the current version and clause numbers of each reference before issue.


Filled specimen

An operator dispensed buffer A and typed the weight into the EBR wrong. The defensible correction, as it appears in the audit trail:

FieldOriginal entryCorrected entry
StepDispense buffer ADispense buffer A
Value12.50 kg21.50 kg
Entered byJ. Operator (ID 4471)J. Operator (ID 4471)
Timestamp2026-07-30 08:42:11 UTC2026-07-30 08:43:02 UTC
Reason for change(n/a)Transposition error at keyboard entry; correct value 21.50 kg confirmed against balance printout BP-0730-14
Approved by(n/a)M. Supervisor (ID 2208), e-signature

Both rows survive. A reviewer sees the original 12.50, the correction to 21.50, who made each entry, when, why, the source that confirmed the correct value, and who approved it. The reason names the cause and the source, not just “error.” That is what turns a correction from a red flag into a normal, defensible event at batch review.

Common inspection findings this instruction prevents

  • A wrong value overwritten so the original is gone, an Original-and-Complete failure under ALCOA+.
  • A correction with a blank or meaningless reason (“error”, “x”), so no one can judge whether it was proper.
  • The operator both making and approving the correction to a critical field, with no independent check.
  • A correction used to change a result to a preferred outcome instead of raising a deviation.
  • An operator working around a locked critical step by back-filling entries.

How to adapt this work instruction

  1. Set the WI number and point the parent-SOP field at your real EBR/batch-record procedure.
  2. Match the control levels in steps 5 and 7 to how your MES actually enforces verification, signatures, and critical-step locks.
  3. Point the deviation cross-reference at your real deviation SOP.
  4. Train operators and verifiers against the filled specimen so the expected reason quality is clear.
  5. Confirm the referenced regulations against their current published versions before issue.
Use madhadi.com as an app Full screen, works offline, one tap from your home screen.