Conduct GxP Audit
Plan and execute GxP audit of computerized systems, data integrity practices, or regulated processes.
When Use
- Scheduled internal audit of validated computerized system
- Supplier/vendor qualification audit for GxP-relevant software
- Pre-inspection readiness assessment before regulatory audit
- For-cause audit triggered by deviation, complaint, or data integrity concern
- Periodic review of validated system compliance posture
Inputs
- Required: Audit scope (system, process, or site to audit)
- Required: Applicable regulations (21 CFR Part 11, EU Annex 11, GMP, GLP, GCP)
- Required: Previous audit reports, open CAPA items
- Optional: System validation documentation (URS, VP, IQ/OQ/PQ, traceability matrix)
- Optional: SOPs, training records, change control logs
- Optional: Specific risk areas or concerns triggering audit
Steps
Step 1: Develop Audit Plan
# Audit Plan
## Document ID: AP-[SYS]-[YYYY]-[NNN]
### 1. Objective
[State the purpose: scheduled, for-cause, supplier qualification, pre-inspection]
### 2. Scope
- **System/Process**: [Name and version]
- **Regulations**: [21 CFR Part 11, EU Annex 11, ICH Q7, etc.]
- **Period**: [Date range of records under review]
- **Exclusions**: [Any areas explicitly out of scope]
### 3. Audit Criteria
| Area | Regulatory Reference | Key Requirements |
|------|---------------------|------------------|
| Electronic records | 21 CFR 11.10 | Controls for closed systems |
| Audit trail | 21 CFR 11.10(e) | Secure, computer-generated, time-stamped |
| Electronic signatures | 21 CFR 11.50 | Manifestation, legally binding |
| Access controls | EU Annex 11, §12 | Role-based, documented |
| Data integrity | MHRA guidance | ALCOA+ principles |
| Change control | ICH Q10 | Documented, assessed, approved |
### 4. Schedule
| Date | Time | Activity | Participants |
|------|------|----------|-------------|
| Day 1 AM | 09:00 | Opening meeting | All |
| Day 1 AM | 10:00 | Document review | Auditor + QA |
| Day 1 PM | 13:00 | System walkthrough | Auditor + IT + System Owner |
| Day 2 AM | 09:00 | Interviews + evidence collection | Auditor + Users |
| Day 2 PM | 14:00 | Finding consolidation | Auditor |
| Day 2 PM | 16:00 | Closing meeting | All |
### 5. Audit Team
| Role | Name | Responsibility |
|------|------|---------------|
| Lead Auditor | [Name] | Plan, execute, report |
| Subject Matter Expert | [Name] | Technical assessment |
| Auditee Representative | [Name] | Facilitate access and information |
Got: Audit plan approved by quality management, communicated to auditee at least 2 weeks before audit.
If fail: Reschedule if auditee cannot provide required documentation or personnel.
Step 2: Conduct Opening Meeting
Agenda:
- Introduce audit team, roles
- Confirm scope, schedule, logistics
- Explain finding classification system (critical/major/minor)
- Confirm confidentiality agreements
- Identify auditee escorts, document custodians
- Address questions
Got: Opening meeting documented with attendance record.
If fail: Key personnel unavailable? Reschedule affected audit activities.
Step 3: Collect and Review Evidence
Review documentation, records against audit criteria:
3a. Validation Documentation Review
3b. Operational Controls Review
3c. Data Integrity Assessment
3d. System Configuration Review
Got: Evidence collected as screenshots, document copies, interview notes with timestamps.
If fail: Record "unable to verify" as observation, note reason.
Step 4: Classify Findings
Classify each finding by severity:
| Classification |
Definition |
Response Required |
| Critical |
Direct impact on product quality, patient safety, or data integrity. Systematic failure of a key control. |
Immediate containment + CAPA within 15 business days |
| Major |
Significant departure from GxP requirements. Potential to impact data integrity if uncorrected. |
CAPA within 30 business days |
| Minor |
Isolated deviation from procedure. No direct impact on data integrity or product quality. |
Correction within 60 business days |
| Observation |
Opportunity for improvement. Not a regulatory requirement. |
Optional — tracked for trend analysis |
Document each finding:
## Finding F-[NNN]
**Classification:** [Critical / Major / Minor / Observation]
**Area:** [Audit trail / Access control / Change control / etc.]
**Reference:** [Regulatory clause, e.g., 21 CFR 11.10(e)]
**Observation:**
[Objective description of what was found]
**Evidence:**
[Document ID, screenshot reference, interview notes]
**Regulatory Expectation:**
[What the regulation requires]
**Risk:**
[Impact on data integrity, product quality, or patient safety]
Got: Every finding has classification, evidence, regulatory reference.
If fail: Classification disputed? Escalate to audit program manager for adjudication.
Step 5: Conduct Closing Meeting
Agenda:
- Present findings summary (no new findings should be raised)
- Review finding classifications
- Discuss preliminary CAPA expectations, timelines
- Confirm next steps, report timeline
- Acknowledge auditee cooperation
Got: Closing meeting documented with attendance. Auditee acknowledges findings (acknowledgement ≠ agreement).
If fail: Auditee disputes finding? Document disagreement, escalate per SOP.
Step 6: Write Audit Report
# Audit Report
## Document ID: AR-[SYS]-[YYYY]-[NNN]
### 1. Executive Summary
An audit of [System/Process] was conducted on [dates] against [regulations].
[N] findings were identified: [n] critical, [n] major, [n] minor, [n] observations.
### 2. Scope and Methodology
[Summarize audit plan scope, criteria, and methods used]
### 3. Findings Summary
| Finding ID | Classification | Area | Brief Description |
|-----------|---------------|------|-------------------|
| F-001 | Major | Audit trail | Audit trail disabled for batch record module |
| F-002 | Minor | Training | Two users missing annual GxP training |
| F-003 | Observation | Documentation | SOP formatting inconsistencies |
### 4. Detailed Findings
[Include full finding details from Step 4 for each finding]
### 5. Positive Observations
[Document areas of good practice observed during the audit]
### 6. Conclusion
The overall compliance status is assessed as [Satisfactory / Needs Improvement / Unsatisfactory].
### 7. Distribution
| Recipient | Role |
|-----------|------|
| [Name] | System Owner |
| [Name] | QA Director |
| [Name] | IT Manager |
### Approval
| Role | Name | Signature | Date |
|------|------|-----------|------|
| Lead Auditor | | | |
| QA Director | | | |
Got: Report issued within 15 business days of closing meeting.
If fail: Delayed beyond 15 days? Notify stakeholders, document reason.
Step 7: Track CAPA and Verify Effectiveness
For each finding requiring CAPA:
## CAPA Tracking
| Finding ID | CAPA ID | Root Cause | Corrective Action | Due Date | Status | Effectiveness Check |
|-----------|---------|------------|-------------------|----------|--------|-------------------|
| F-001 | CAPA-2025-042 | Configuration oversight during upgrade | Enable audit trail, verify all modules | 2025-04-15 | Open | Scheduled 2025-07-15 |
| F-002 | CAPA-2025-043 | Training matrix not updated | Complete training, update tracking | 2025-05-01 | Open | Scheduled 2025-08-01 |
Got: CAPAs assigned, tracked, effectiveness verified per defined timeline.
If fail: Unresolved CAPAs escalate to QA management, flagged in next audit cycle.
Checks
Pitfalls
- Scope creep: Expanding audit scope during execution without formal agreement leads to incomplete coverage, disputes.
- Opinion-based findings: Findings must reference specific regulatory requirements, not personal preferences.
- Adversarial tone: Audits are collaborative quality improvement exercises, not interrogations.
- Ignoring positives: Reporting only findings without acknowledging good practices undermines trust.
- No effectiveness check: Closing CAPA without verifying fix actually works is recurring regulatory citation.
See Also
perform-csv-assessment — full CSV lifecycle assessment (URS through validation summary)
setup-gxp-r-project — project structure for validated R environments
implement-audit-trail — audit trail implementation for electronic records
write-validation-documentation — IQ/OQ/PQ protocol, report writing
security-audit-codebase — security-focused code audit (complementary perspective)
1---2name: conduct-gxp-audit-63description: Conduct a GxP audit of computerized systems and processes. Covers audit planning, opening meetings, evidence collection, finding classification (critical/major/minor), CAPA generation, closing meetings, report writing, and follow-up verification. Use for scheduled internal audits, supplier qualification audits, pre-inspection readiness assessments, for-cause audits triggered by deviations or data integrity concerns, or periodic compliance posture reviews of validated systems.4license: MIT5---67# Conduct GxP Audit89Plan and execute GxP audit of computerized systems, data integrity practices, or regulated processes.1011## When Use1213- Scheduled internal audit of validated computerized system14- Supplier/vendor qualification audit for GxP-relevant software15- Pre-inspection readiness assessment before regulatory audit16- For-cause audit triggered by deviation, complaint, or data integrity concern17- Periodic review of validated system compliance posture1819## Inputs2021- **Required**: Audit scope (system, process, or site to audit)22- **Required**: Applicable regulations (21 CFR Part 11, EU Annex 11, GMP, GLP, GCP)23- **Required**: Previous audit reports, open CAPA items24- **Optional**: System validation documentation (URS, VP, IQ/OQ/PQ, traceability matrix)25- **Optional**: SOPs, training records, change control logs26- **Optional**: Specific risk areas or concerns triggering audit2728## Steps2930### Step 1: Develop Audit Plan3132```markdown33# Audit Plan34## Document ID: AP-[SYS]-[YYYY]-[NNN]3536### 1. Objective37[State the purpose: scheduled, for-cause, supplier qualification, pre-inspection]3839### 2. Scope40- **System/Process**: [Name and version]41- **Regulations**: [21 CFR Part 11, EU Annex 11, ICH Q7, etc.]42- **Period**: [Date range of records under review]43- **Exclusions**: [Any areas explicitly out of scope]4445### 3. Audit Criteria46| Area | Regulatory Reference | Key Requirements |47|------|---------------------|------------------|48| Electronic records | 21 CFR 11.10 | Controls for closed systems |49| Audit trail | 21 CFR 11.10(e) | Secure, computer-generated, time-stamped |50| Electronic signatures | 21 CFR 11.50 | Manifestation, legally binding |51| Access controls | EU Annex 11, §12 | Role-based, documented |52| Data integrity | MHRA guidance | ALCOA+ principles |53| Change control | ICH Q10 | Documented, assessed, approved |5455### 4. Schedule56| Date | Time | Activity | Participants |57|------|------|----------|-------------|58| Day 1 AM | 09:00 | Opening meeting | All |59| Day 1 AM | 10:00 | Document review | Auditor + QA |60| Day 1 PM | 13:00 | System walkthrough | Auditor + IT + System Owner |61| Day 2 AM | 09:00 | Interviews + evidence collection | Auditor + Users |62| Day 2 PM | 14:00 | Finding consolidation | Auditor |63| Day 2 PM | 16:00 | Closing meeting | All |6465### 5. Audit Team66| Role | Name | Responsibility |67|------|------|---------------|68| Lead Auditor | [Name] | Plan, execute, report |69| Subject Matter Expert | [Name] | Technical assessment |70| Auditee Representative | [Name] | Facilitate access and information |71```7273**Got:** Audit plan approved by quality management, communicated to auditee at least 2 weeks before audit.74**If fail:** Reschedule if auditee cannot provide required documentation or personnel.7576### Step 2: Conduct Opening Meeting7778Agenda:791. Introduce audit team, roles802. Confirm scope, schedule, logistics813. Explain finding classification system (critical/major/minor)824. Confirm confidentiality agreements835. Identify auditee escorts, document custodians846. Address questions8586**Got:** Opening meeting documented with attendance record.87**If fail:** Key personnel unavailable? Reschedule affected audit activities.8889### Step 3: Collect and Review Evidence9091Review documentation, records against audit criteria:9293#### 3a. Validation Documentation Review94- [ ] URS exists, approved95- [ ] Validation plan matches system category, risk96- [ ] IQ/OQ/PQ protocols executed with results documented97- [ ] Traceability matrix links requirements to test results98- [ ] Deviations documented, resolved99- [ ] Validation summary report approved100101#### 3b. Operational Controls Review102- [ ] SOPs current, approved103- [ ] Training records demonstrate competence for all users104- [ ] Change control records complete (request, assessment, approval, verification)105- [ ] Incident/deviation reports handled per SOP106- [ ] Periodic review conducted on schedule107108#### 3c. Data Integrity Assessment109- [ ] Audit trail enabled, not modifiable by users110- [ ] Electronic signatures meet regulatory requirements111- [ ] Backup and recovery procedures documented, tested112- [ ] Access controls enforce role-based permissions113- [ ] Data is attributable, legible, contemporaneous, original, accurate (ALCOA+)114115#### 3d. System Configuration Review116- [ ] Production configuration matches validated state117- [ ] User accounts reviewed — no shared accounts, inactive accounts disabled118- [ ] System clocks synchronized, accurate119- [ ] Security patches applied per approved change control120121**Got:** Evidence collected as screenshots, document copies, interview notes with timestamps.122**If fail:** Record "unable to verify" as observation, note reason.123124### Step 4: Classify Findings125126Classify each finding by severity:127128| Classification | Definition | Response Required |129|---|---|---|130| **Critical** | Direct impact on product quality, patient safety, or data integrity. Systematic failure of a key control. | Immediate containment + CAPA within 15 business days |131| **Major** | Significant departure from GxP requirements. Potential to impact data integrity if uncorrected. | CAPA within 30 business days |132| **Minor** | Isolated deviation from procedure. No direct impact on data integrity or product quality. | Correction within 60 business days |133| **Observation** | Opportunity for improvement. Not a regulatory requirement. | Optional — tracked for trend analysis |134135Document each finding:136137```markdown138## Finding F-[NNN]139**Classification:** [Critical / Major / Minor / Observation]140**Area:** [Audit trail / Access control / Change control / etc.]141**Reference:** [Regulatory clause, e.g., 21 CFR 11.10(e)]142143**Observation:**144[Objective description of what was found]145146**Evidence:**147[Document ID, screenshot reference, interview notes]148149**Regulatory Expectation:**150[What the regulation requires]151152**Risk:**153[Impact on data integrity, product quality, or patient safety]154```155156**Got:** Every finding has classification, evidence, regulatory reference.157**If fail:** Classification disputed? Escalate to audit program manager for adjudication.158159### Step 5: Conduct Closing Meeting160161Agenda:1621. Present findings summary (no new findings should be raised)1632. Review finding classifications1643. Discuss preliminary CAPA expectations, timelines1654. Confirm next steps, report timeline1665. Acknowledge auditee cooperation167168**Got:** Closing meeting documented with attendance. Auditee acknowledges findings (acknowledgement ≠ agreement).169**If fail:** Auditee disputes finding? Document disagreement, escalate per SOP.170171### Step 6: Write Audit Report172173```markdown174# Audit Report175## Document ID: AR-[SYS]-[YYYY]-[NNN]176177### 1. Executive Summary178An audit of [System/Process] was conducted on [dates] against [regulations].179[N] findings were identified: [n] critical, [n] major, [n] minor, [n] observations.180181### 2. Scope and Methodology182[Summarize audit plan scope, criteria, and methods used]183184### 3. Findings Summary185| Finding ID | Classification | Area | Brief Description |186|-----------|---------------|------|-------------------|187| F-001 | Major | Audit trail | Audit trail disabled for batch record module |188| F-002 | Minor | Training | Two users missing annual GxP training |189| F-003 | Observation | Documentation | SOP formatting inconsistencies |190191### 4. Detailed Findings192[Include full finding details from Step 4 for each finding]193194### 5. Positive Observations195[Document areas of good practice observed during the audit]196197### 6. Conclusion198The overall compliance status is assessed as [Satisfactory / Needs Improvement / Unsatisfactory].199200### 7. Distribution201| Recipient | Role |202|-----------|------|203| [Name] | System Owner |204| [Name] | QA Director |205| [Name] | IT Manager |206207### Approval208| Role | Name | Signature | Date |209|------|------|-----------|------|210| Lead Auditor | | | |211| QA Director | | | |212```213214**Got:** Report issued within 15 business days of closing meeting.215**If fail:** Delayed beyond 15 days? Notify stakeholders, document reason.216217### Step 7: Track CAPA and Verify Effectiveness218219For each finding requiring CAPA:220221```markdown222## CAPA Tracking223| Finding ID | CAPA ID | Root Cause | Corrective Action | Due Date | Status | Effectiveness Check |224|-----------|---------|------------|-------------------|----------|--------|-------------------|225| F-001 | CAPA-2025-042 | Configuration oversight during upgrade | Enable audit trail, verify all modules | 2025-04-15 | Open | Scheduled 2025-07-15 |226| F-002 | CAPA-2025-043 | Training matrix not updated | Complete training, update tracking | 2025-05-01 | Open | Scheduled 2025-08-01 |227```228229**Got:** CAPAs assigned, tracked, effectiveness verified per defined timeline.230**If fail:** Unresolved CAPAs escalate to QA management, flagged in next audit cycle.231232## Checks233234- [ ] Audit plan approved, communicated before audit235- [ ] Opening and closing meetings documented with attendance236- [ ] Evidence collected with timestamps, source references237- [ ] Every finding has classification, evidence, regulatory reference238- [ ] Audit report issued within 15 business days239- [ ] CAPAs assigned with due dates for all critical and major findings240- [ ] Previous audit CAPAs verified for closure effectiveness241242## Pitfalls243244- **Scope creep**: Expanding audit scope during execution without formal agreement leads to incomplete coverage, disputes.245- **Opinion-based findings**: Findings must reference specific regulatory requirements, not personal preferences.246- **Adversarial tone**: Audits are collaborative quality improvement exercises, not interrogations.247- **Ignoring positives**: Reporting only findings without acknowledging good practices undermines trust.248- **No effectiveness check**: Closing CAPA without verifying fix actually works is recurring regulatory citation.249250## See Also251252- `perform-csv-assessment` — full CSV lifecycle assessment (URS through validation summary)253- `setup-gxp-r-project` — project structure for validated R environments254- `implement-audit-trail` — audit trail implementation for electronic records255- `write-validation-documentation` — IQ/OQ/PQ protocol, report writing256- `security-audit-codebase` — security-focused code audit (complementary perspective)