GxP Insights

GMP Batch Release Workflow in eQMS and ERP: Statuses, Permissions and Evidence

A practical systems-design approach to separating QA review, QP certification and ERP stock disposition in a traceable pharmaceutical batch release workflow.

G GuideGxP 8 min read
✓ Official sources and references ✓ Practical approach ✓ For pharmaceutical professionals
GUIDEGXP · PRACTICAL GMP INSIGHTS
Digital pharmaceutical batch release workflow showing controlled quality, QP certification and ERP stock disposition states

A pharmaceutical batch release workflow should make four related but different decisions visible and traceable: QC completion of applicable testing and review, QA completion of the batch dossier review, QP certification where EU GMP Annex 16 applies, and the operational decision to make stock available in an ERP or warehouse system. Software labels such as “Ready”, “Certified” or “Released” are not prescribed regulatory terms. They are controlled implementation choices that must support the applicable GMP requirements, preserve the QP’s independent judgement, and prevent a batch becoming operationally available through an ambiguous or unauthorised status change.

This article addresses digital workflow design rather than the wider Annex 16 release process. For the underlying batch-release lifecycle and Annex 16 context, see GuideGxP’s practical guide to batch release under EU GMP Annex 16.

Start with the decisions, not the status names

EU GMP Annex 16 sets expectations for certification by a Qualified Person and batch release. EU GMP Chapter 1 describes the Pharmaceutical Quality System, including the need for management of knowledge, quality risk management and an effective system for quality oversight. In the United States, 21 CFR 211.192 addresses review of production records and investigation of unexplained discrepancies and failures before batch release. These are regulatory requirements or regulator-issued GMP expectations in their respective contexts; they do not mandate an ERP status catalogue.

GuideGxP implementation advice: configure the digital design around explicit business and quality decisions. A “QC complete” signal should not silently mean “QA approved”. A completed QA review should not be treated as QP certification. QP certification should not automatically be assumed to mean that every physical, commercial or distribution constraint has been cleared. Where local procedures connect these activities, the system should show the connection without collapsing accountable decisions into one generic “release” action.

  • QC completion: records that applicable test results and laboratory review are complete according to the approved process. It is evidence for the dossier, not necessarily the final disposition.
  • QA dossier review: confirms that the required manufacturing, packaging, QC and quality-event evidence has been assessed under the site’s pharmaceutical quality system.
  • QP certification: the distinct certification decision required under Annex 16 where applicable. The workflow must enable, rather than substitute for, the QP’s judgement.
  • Operational stock disposition: an ERP, warehouse or distribution control that determines whether stock can be allocated, picked, shipped or otherwise used. It must be reconciled to quality decisions but remains an operational control.

An illustrative controlled state model

The following labels are GuideGxP examples only. Organisations may use different names, provided their intended meaning, entry criteria, permitted transitions and accountable roles are defined in controlled procedures and system specifications.

Illustrative stateEntry criteria and system purposePermitted exit or transition authorityKey control
DraftBatch record package is created; data collection or interfaces may still be incomplete.Configured workflow service account or authorised operational role may move it to Under Review when required records are present.Not eligible for certification or operational release.
Under ReviewEvidence package is assembled for review, with outstanding items visibly identified.QA reviewer may progress, return, or block within assigned authority.Review tasks must not conceal missing or failed evidence.
BlockedA defined quality, material, data, system or supply-chain condition prevents progression.Authorised QA role manages the block; removal requires documented justification and required approvals.ERP availability remains restricted.
Awaiting InvestigationA deviation, atypical result, discrepancy, complaint signal or other quality event requires assessment.QA may return the batch to review only when the linked quality-event outcome supports this.Use a durable link to the eQMS record, not free-text claims of closure.
Ready for QP DecisionThe defined dossier is complete for QP consideration; this does not predetermine the decision.Only the appropriately authorised QP can certify or reject.Read-only dossier snapshot and current exception status should be available.
CertifiedThe QP has made and recorded the certification decision where applicable.Controlled integration or authorised operational role can request stock disposition under defined rules.Certification identity, date/time and certified scope are immutable audit-trail events.
RejectedThe QP or other authorised quality decision-maker has rejected the batch under the applicable process.No forward release transition without a formally governed, procedurally permitted route.Stock remains unavailable and linked quality records remain visible.
Operationally ReleasedApplicable certification and defined operational checks are complete, and ERP stock is available as authorised.Subsequent hold, recall or correction uses controlled exceptional transitions.Reconcile this state to Certified; differences require investigation.

A workflow may need additional states for product-specific arrangements, but avoid uncontrolled status proliferation. Each state should have one unambiguous meaning, a data owner, transition conditions, a role-based permission set, and an audit-trail event. “Ready for QP Decision” is especially valuable because it separates the preparation of evidence from the QP’s decision.

Permissions and segregation of duties

Annex 11 is part of EudraLex Volume 4 and should be considered when regulated computerised systems support GMP activities. The European Commission’s EudraLex Volume 4 page is the official access point for Annex 11 and related GMP guidance. A defensible configuration uses unique identities, role-based access, attributable electronic records, controlled changes and reviewable audit trails. The detailed technical control design should be risk-based and documented through the organisation’s computerised-system lifecycle.

ActivityManufacturing/QCQAQPSystem owner/ITERP/Warehouse
Create evidence or interface recordsResponsibleInformedInformedSupportInformed
Review dossier completeness and exceptionsContributeResponsibleConsultedRead-only supportInformed
Certify or reject under Annex 16Not permittedNot permitted unless separately qualified and authorised as QPResponsible and accountableNot permittedInformed
Make stock operationally availableNot permittedApprove defined exception where procedure requiresSource decision where applicableCannot bypass workflowResponsible for controlled execution
Change workflow configuration or role mappingConsultedApprove quality impactConsultedResponsible for controlled implementationConsulted

This matrix is an implementation pattern, not a universal RACI. In particular, system administrators should not have routine business permission to certify, reject or release stock merely because they can administer the platform. Emergency access, if used, needs a controlled process, time limitation and post-event review. Periodic access review should assess active accounts, role appropriateness, privileged access, leavers and conflicts between quality decision-making and operational execution.

Build an evidence graph, not a document dump

The release workspace should link to the controlled source record or an immutable reference, with clear record version and status. Avoid copying a changing spreadsheet or relying on an email assertion that an event is closed. The reviewer and QP need efficient access to the evidence relevant to their decision, while the system preserves traceability to the originating application.

Minimum evidence links

  • Batch and packaging records, including approved-record identity and completed-record reference.
  • Applicable QC results, review status and relevant laboratory exceptions from LIMS or the controlled source.
  • Deviation, investigation, change-control and CAPA references that affect the batch, with their current controlled status.
  • Material, component and reconciliation information where required by the approved release process.
  • Relevant manufacturing, utility, equipment or validation status evidence where a batch decision depends on it.
  • QP certification record, including the authenticated signer, time of signing, decision and declared scope.
  • ERP disposition transaction, warehouse status and distribution-restriction evidence.

Electronic signatures should be attributable to the individual signer and bound to the specific decision or record. The audit trail should capture creation, change, status transition, signature, reason and relevant before-and-after values. Use controlled reason codes for meaningful events such as holds, returns to review, rejected batches, manual interface correction and operational release reversal. Free text can provide context, but should not replace a controlled reason category where trending and review are needed.

Control exceptions, interfaces and failed messages

Interfaces between MES, LIMS, eQMS and ERP are a common source of false confidence. A successful eQMS certification event does not prove that an ERP stock update succeeded; conversely, an ERP message must not become a route around the quality workflow. Define the source of truth for each data element: batch identity, quality state, certification decision, inventory status and shipment eligibility.

GuideGxP implementation advice: use explicit interface acknowledgements, transaction identifiers, error queues and reconciliation. A failed or delayed message should place the batch in a visible exception condition rather than allowing users to infer its availability. Manual reprocessing or correction must be authorised, attributable and reason-coded. Repeated failures should feed the quality-system process for assessment, rather than being resolved only as IT tickets.

Design exceptional branches before go-live. A hold should restrict the appropriate downstream actions. A rejected batch should not use the same transition path as an ordinary review return. Rework, where permitted by the approved quality process, needs a clearly defined relationship to the original batch record and its subsequent evidence. A recall or distribution restriction requires prompt alignment between quality status and the operational ability to allocate or distribute stock. The system should show that alignment; it should not decide the quality outcome autonomously.

Validate the workflow and monitor reconciliation

Workflow configuration is not a one-time IT setting. Status meanings, decision rules, permissions, integrations, reports and electronic-signature behaviour are regulated-process controls when they support GMP decisions. Changes should be assessed through the organisation’s change-control and computerised-system lifecycle, with risk-based testing that demonstrates intended operation and protects data integrity. This is consistent with the expectation to manage the pharmaceutical quality system and controlled computerised systems; it is not a claim that one fixed test script or validation method is mandated by regulators.

Useful reconciliation measures include the number of Certified batches not yet Operationally Released, Operationally Released batches lacking the expected certification link, blocked batches with failed interface messages, aged investigation-linked batches, and manual status corrections. Metrics should trigger review of data, workflow design and process ownership; they are not acceptance limits supplied by Annex 16 or Annex 11.

Inspection-ready checklist

  • Can the team explain the distinction between QC completion, QA review, QP certification and ERP disposition using the configured states?
  • Does every transition have defined criteria, permitted roles and an attributable audit-trail record?
  • Can a QP view the current dossier, linked exceptions and evidence provenance without relying on uncontrolled copies?
  • Are QP certification and operational release separate events, with their relationship clearly reconciled?
  • Do holds, rejection, investigation, rework and recall or restriction paths prevent inappropriate stock availability?
  • Are interface failures visible, investigated where appropriate, and reconciled to source and receiving systems?
  • Are privileged access, conflicting roles and periodic access reviews controlled?
  • Have workflow and interface changes been assessed, approved and tested within the computerised-system lifecycle?

FAQ

Does Annex 16 require a status called “Certified”?

No software status label is prescribed by the workflow example. “Certified” is a useful implementation label for recording the distinct QP decision, but organisations should define their own controlled terminology.

Can QA certify a batch on behalf of the QP?

The digital workflow should not blur QA review with QP certification. Where Annex 16 applies, certification is the QP’s distinct responsibility. Local role assignment must reflect the applicable legal and quality-system arrangements.

Should QP certification automatically release ERP stock?

Not necessarily. Automation can be appropriate when it is specified, controlled and validated, but the design must still distinguish certification from operational disposition and manage interface failures and operational restrictions.

What is the most important control for manual ERP updates?

Prevent a manual update from bypassing the defined quality decision. Require appropriate authority, a reason code, attributable audit-trail evidence and reconciliation to the originating certification or exception record.

Turn the method into an audit-ready system

Qualified Person (QP) Operational Guide - Annex 16 / Batch Release is an optional GuideGxP operational resource for deeper methods, checklists and ready-to-adapt tools. It is not regulator-endorsed and does not replace your approved procedures, QP judgement or applicable requirements.

Stay practical: The Pragmatic GMP

Subscribe to The Pragmatic GMP for evidence-led GMP analysis, practical checklists and regulatory updates.

Primary sources

THE PRAGMATIC GMP · EVERY MONDAY

The GMP topics that matter, in 7 minutes.

One GMP topic, one real-world example and one practical action, based on official sources and inspection trends.
Discover The Pragmatic GMP