GxP Insights

Good Documentation Practices in GMP: Records, Corrections, Signatures and Hybrid Systems

A practical, inspection-ready guide to controlling GMP records across paper, electronic and hybrid systems, using current EU GMP Chapter 4 as the baseline.

G GuideGxP 8 min read
✓ Official sources and references ✓ Practical approach ✓ For pharmaceutical professionals
GUIDEGXP · PRACTICAL GMP INSIGHTS
Good documentation practices GMP across paper, electronic and hybrid records

Good documentation practices GMP require records and instructions to show clearly, accurately and contemporaneously what was done, by whom and when, while protecting the original information and keeping records available for review. For organisations operating to EU GMP, the applicable baseline is the European Commission’s current Chapter 4: Documentation (January 2011). It applies equally to the operational reality of paper, electronic and hybrid records: the medium may differ, but the controlled evidence must remain complete, reliable and retrievable.

This article distinguishes the applicable EU GMP requirement from regulator guidance and GuideGxP implementation advice. It is intended for experienced QA, QC, Manufacturing, Validation, Engineering, QP, Data Integrity, Training and system-owner professionals designing documentation controls that stand up to routine review and inspection.

What EU GMP Chapter 4 requires

Binding baseline for this article: current EU GMP Chapter 4 states that documentation is an essential part of the pharmaceutical quality system. Its purpose is to define specifications, manufacturing formulae, instructions, procedures and records, and to ensure that personnel have the information necessary to perform and control operations. Records provide evidence that the required steps have been performed.

Chapter 4 requires documents to be designed, prepared, reviewed and distributed with care. They must be approved, signed and dated by appropriate and authorised persons. Instructions must be written in an imperative mandatory style, be clear and unambiguous, and be available in writing. Documents must be regularly reviewed and kept up to date. A system must prevent the inadvertent use of superseded documents.

For records, the central expectations are operational rather than cosmetic. Entries must be clear, legible and indelible. They must be made or completed at the time each action is taken and in a way that permits all significant activities to be traced. Any alteration must be signed and dated, allow the reading of the original information, and, where appropriate, record the reason for the alteration.

Documentation types to place under control

The precise document set should reflect the site, products and processes. Chapter 4 identifies, among other items, specifications; manufacturing formulae; processing, packaging and testing instructions; procedures; protocols; technical agreements; batch processing and packaging records; analytical records; certificates of analysis; environmental monitoring records; validation documentation; and training records.

A robust document-management process separates controlled instructions from completed records. An approved master batch record is an instruction or template. A completed batch record is GMP evidence. Both need version control, but their issuance, completion, review, retention and change controls serve different risks.

Contemporaneous, attributable and legible records in practice

Chapter 4 does not use every modern data-integrity acronym, but its requirements directly support core record attributes. A reviewer should be able to identify the person making an entry, read the entry, establish when the activity happened, understand what was done and reconstruct the sequence without relying on memory or informal explanation.

GuideGxP implementation advice: define on each relevant record how identity, date and time are captured. On paper this may be an attributable signature or initials linked to a signature register, plus the date and, where process control requires it, time. In electronic systems, attributable identity and time information should be designed into the validated workflow rather than added later in a spreadsheet or separate log.

Legibility is a usability control. A technically permanent but unreadable entry cannot efficiently demonstrate what occurred. Train operators to enter factual observations, actual values and prescribed status information. Avoid vague wording such as “OK” where an approved record calls for a measured value, equipment identifier, yield, reconciliation result or defined verification.

Corrections preserve the original record

A correction is not an opportunity to rewrite history. Under current Chapter 4, the original entry must remain readable. For paper records, the usual controlled method is a single line through the erroneous entry, followed by the correct entry, signature or initials, date and a reason where appropriate. The local procedure should define when the reason is mandatory and how corrections are made in fields with limited space.

For electronic records, the equivalent control is not a visual strike-through. It is a controlled, attributable change process that preserves the prior value and makes the change and its context reviewable. GuideGxP implementation advice: test this behaviour during validation and periodically verify that routine users, administrators and reviewers can retrieve the relevant history.

SituationDoDo not
Paper recordingRecord the activity when it is performed, using permanent and legible entries.Transcribe notes later as if the final form were the original record.
Incorrect entryKeep the original readable; enter the correction with required attribution, date and reason where appropriate.Use correction fluid, erase, overwrite or obscure the original.
Controlled formsIssue the current approved version and reconcile or securely manage unused issued copies.Allow locally copied, obsolete or unnumbered working forms to become GMP records.
Electronic workflowUse the validated system and review available history as defined by procedure.Export data to an uncontrolled file to complete or replace the official record.
Supervisor reviewCheck completeness, chronology, exceptions and attributable approval.Limit review to confirming that every page has a signature.

Signatures, review and retention: build evidence that can be reconstructed

Approval signatures and dates are required for controlled documents under Chapter 4. Completed records must also permit traceability of significant activities. The meaning of a signature, initials, electronic approval or reviewer action should therefore be unambiguous in the relevant procedure: for example, performed, checked, approved, verified or authorised.

GuideGxP implementation advice: maintain a controlled signature and initials register where handwritten initials are used. For electronic signatures, define the account-holder’s responsibility, prohibit shared credentials, and ensure that roles align with the approved workflow. The procedure should state what the reviewer is expected to assess, not merely require a signature at the end of the record.

Current Chapter 4 requires batch documentation to be retained for at least one year after expiry of the batch to which it relates, or at least five years after certification by the Qualified Person, whichever is longer. It also requires records to be readily available. Retention design must therefore consider retrieval, readability over time, access control and the ability to relate records to the relevant batch, product and version.

Supervisor review checklist

  • Confirm that the approved current instruction or record version was used.
  • Check entries are complete, legible, attributable and made in a coherent chronology.
  • Verify required dates, times, identifiers, calculations, reconciliations and attachments.
  • Assess corrections: original data remain readable, attribution and dating are present, and reasons are recorded where appropriate.
  • Identify blanks, unusual values, late entries, repeated corrections and unexplained discrepancies.
  • Confirm deviations, investigations and related records are referenced and progressed through the quality system.
  • For electronic elements, verify that the approved system and defined review of history were used.
  • Document the review outcome and escalate concerns before batch disposition, where applicable.

Controlling paper, digital and hybrid records

Chapter 4 permits documentation systems based on paper, electronic or photographic media, provided the system is validated as appropriate. The applicable requirement is not to choose one medium over another; it is to ensure that documents and records remain controlled, accurate and usable throughout their lifecycle.

A hybrid record is one GMP process whose evidence is distributed across more than one medium: for example, a paper batch record supported by electronic equipment data, or an electronic workflow with a scanned attachment. Hybrid systems create hand-offs, and hand-offs create risk. The site should identify which record is the official record for each activity, how related records are linked, who checks the linkage, and how the full set is retrieved.

A practical hybrid-record control model

  1. Map the evidence: identify every paper form, instrument output, electronic record, scan, attachment and manual transcription that supports the activity.
  2. Define the authoritative record: specify where the original information resides and what constitutes a true copy for operational use or retention.
  3. Control issuance and capture: use approved templates, unique identifiers where appropriate, and defined attachment or upload steps.
  4. Verify transfer points: require a documented check when data move between paper and electronic systems, particularly for critical values and exceptions.
  5. Protect retrieval: test retrieval of the complete record set by batch, equipment, date and document version.

Chapter 4 states that records may be retained as originals or true copies, such as photocopies, microfilm, microfiche or other accurate reproductions of original records. GuideGxP implementation advice: establish a documented true-copy process that demonstrates the copy is accurate, complete and readable, and that preserves the contextual information needed to interpret it. A scan that omits reverse pages, marginal annotations, attachments or record identifiers is not a dependable substitute merely because it looks clear.

Use a risk-based approach to prioritise hybrid controls. A data integrity risk assessment (DIRA) for GMP audits can help teams identify vulnerable creation, review, transfer, storage and retrieval points before they become inspection findings.

Inspection lessons and training questions

Practical illustrations, not generalised conclusions: FDA warning letters issued to A. Nelson & Co. on 12 February 2026 and Wizcure Pharmaa on 24 June 2026 are useful illustrations of documentation risks involving discarded records, duplicate uncontrolled forms and incomplete data. These letters concern the cited firms and facts; they do not establish a universal finding or replace the applicable GMP requirements for another site.

Turn such examples into scenario-based training rather than a slide on “GDP rules”. Ask operators, reviewers and system owners:

  • If you make an error, how do you correct it without concealing the original entry?
  • What makes a form controlled, and what should you do if only an uncontrolled copy is available?
  • Where is the official record when paper data, equipment output and an electronic workflow all exist?
  • How would you retrieve the complete evidence package for a selected batch?
  • What must you do when a value is missing, unclear or entered later than the activity?

FAQ

Is the 2025 revised EU GMP Chapter 4 already applicable?

No conclusion that it is applicable should be drawn from the consultation materials alone. The European Commission’s 2025 Chapter 4, Annex 11 and Annex 22 consultation and the associated draft revised Chapter 4 text are closed consultation materials. They are not the applicable final guideline unless an official source confirms finalisation and applicability. Use the current January 2011 Chapter 4 as the baseline addressed here.

Can a scanned record be retained instead of paper?

Current Chapter 4 permits originals or true copies, including accurate reproductions. The organisation must be able to demonstrate that the retained copy is accurate, complete, readable and retrievable for the required retention period.

Does an electronic record remove the need for review?

No. Electronic systems may change how information is captured and how prior information is preserved, but they do not remove the need for defined review, approval, traceability and record availability.

Primary sources

Stay practical: The Pragmatic GMP

Subscribe to The Pragmatic GMP for evidence-led GMP analysis, practical checklists and regulatory updates.

THE PRAGMATIC GMP · EVERY MONDAY

The GMP topics that matter, in 7 minutes.

One GMP topic, one real-world example and one practical action, based on official sources and inspection trends.
Discover The Pragmatic GMP