The inspector asks for the audit trail of the recipe used in a batch stopped by a level alarm. The system produces it: one hundred and twenty thousand lines in which every sensor state change weighs as much as the change to the filling set point. Nobody there had ever filtered that file. The audit trail existed; it had never been reviewed, because nobody knew how to read it.
This article settles one thing: which line data are GMP records and which are machine data. Not everything the PLC produces is a GMP record, and not every GMP record originates in the PLC. Classification does not follow from the control architecture: it is a documented risk decision, taken in the URS, and from it follow audit trail, retention, backup and periodic review.
Where the problem starts
The failure sequence is always the same. The URS describes automation by function – dosing, transport, stoppering, rejects – not by data; the supplier quotes the standard configuration of its SCADA; FAT verifies functions, not record generation; OQ tests alarms and interlocks one by one, but nobody checks that the set is manageable by an operator. In operation the system records everything and says nothing.
The cost lands downstream, in two directions. A datum found to be a GMP record once the line is running, and not retained in legible, attributable form, forces change control and partial revalidation. A datum treated as a GMP record without being one generates review nobody will use. Both errors come from one omission: nobody wrote the list of the system's GMP records, with its rationale.
The regulatory picture
| Source | Status and date | What it actually binds |
|---|---|---|
| EU GMP Annex 11 | January 2011 text, still the only one in force. Revision draft under joint EMA/PIC/S consultation, closed 7 October 2025; no adoption confirmed | Risk management, suppliers, validation, data, access, audit trail, backup, periodic review. The draft is not a requirement |
| EU GMP Annex 1 | C(2022) 5938 final, applicable since 25 August 2023 | CCS (2.3, 2.5); authorised list of interventions (8.16); interventions and stoppages in the batch record (8.17); sterilisation records per cycle (8.45) |
| 21 CFR Part 11 | In force; Scope and Application guidance 2003 still operative | Electronic records and signatures, with enforcement discretion on validation, audit trail and legacy systems. It does not replace the predicate rules |
| ICH Q9(R1) | Step 4 on 18 January 2023 | Method for justifying data classification and review scope |
| GAMP 5 Second Edition; ASTM E2500-25 | Current editions; E2500-25 supersedes E2500-20 | Risk-based lifecycle and verification. Voluntary guidance |
Two planes must be kept apart. First: the Annex 11 in force is the 2011 text, the only one you can be inspected against today; treating the draft as a requirement ties supplier and budget to a text with no final form. Second: a line specified today will stay in service for decades, and ignoring the direction the consultation made public – data lifecycle, interfaces, cybersecurity – means delivering an architecture to be modified as soon as the text changes. You validate against 2011 and design so the architecture absorbs the expected evolution, stating that as a robustness choice [GUIDEGXP].
PLC, HMI, SCADA and historian are not one system
The PLC runs machine logic in real time; the HMI is the local interface; the SCADA supervises several machines and manages recipes, users and events; the historian archives time series. On an aseptic line they sit across filler, barrier, tunnel, freeze dryer, EMS and site systems: each produces data, none the batch record.
Recipes and critical parameters
The recipe is where the decision bites. It holds critical process parameters (nominal fill volume and limits, cycle parameters, reject criteria), non-critical machine parameters and interface configuration. Only the first are GMP records in full; for the rest classification depends on demonstrated product impact [QRM]. Values and limits come from process development, URS and validation, frozen in a uniquely identified recipe version under change control [REQUIREMENT].
Alarms, events and interlocks
An interlock prevents an action. An alarm demands human action. An event records a fact. Confusing the three is the commonest cause of proliferation: every state transition becomes an alarm and the operator acknowledges, in bursts, windows nobody reads. The proliferation of non-critical alarms is itself a sterility assurance risk: the alarm on a loss of barrier overpressure drowns in the noise of the stopper hopper alarm.
Alarm rationalisation states, for each alarm, the triggering condition, the consequence for the aseptic process, the priority and the expected action. What needs no human action becomes an event; what must prevent an action becomes an interlock. Thresholds and priorities derive from process development, the CCS and manufacturer data, and are verified in OQ [QRM]. An alarm that brings an operator into Grade A generates an intervention, to be included in the authorised list (8.16) and recorded in the batch record with time, duration and operators (8.17) [REQUIREMENT]: alarm logic is also a choice about how many interventions the line demands, the subject of automation, robotics and gloveless aseptic processing.
IPC and rejects
IPC combines measurement, automatic correction and outcome. Rejects are the most neglected case: a container rejected for a missing or misplaced stopper – required by Annex 1 8.28 before capping run as a clean process with grade A air supply [REQUIREMENT] – produces a datum needed for batch reconciliation. If the count by cause is not attributable to the phase, reconciliation becomes an estimate.
Audit trail, access, time and continuity
Review is a risk exercise, not a volume exercise
A useful audit trail is filterable by data type, user and time window, and legible without proprietary tools. Review must be defined by scope, occasion (release, investigation, periodic) and responsibility, according to criticality [QRM]. Frequency is not copied: it is justified. A review claiming to cover everything and covering nothing is worse than a partial but targeted one.
Roles, access and electronic records
Access control must make every critical action attributable to an identified person, with roles by function and least privilege; shared departmental accounts and permanent maintenance logins are the usual breach. Electronic signature brings the Part 11 perimeter: meaning of the signature, unbreakable link to the record, identity controls [REQUIREMENT]. The 2003 guidance declares enforcement discretion, but grants no exemption from predicate rules.
Time, backup, remote access and cybersecurity
Without a time reference shared by PLC, SCADA, EMS and site systems, correlating an environmental excursion with a line intervention becomes interpretation: synchronisation must be specified in the URS and verified in qualification [GEP]. An untested backup is not a backup: frequency and method are set by criticality and proven by a documented restore [QRM]. Supplier remote access must be governed: activation on request, named authorisation, tracked session, record of what changed. An untracked remote change is an unauthorised change to a GMP-record system. Cybersecurity is the prerequisite of data integrity: OT/IT segmentation, patching compatible with the validated state and control of removable media are the conditions without which attributability cannot be demonstrated [GEP].
Machine data or GMP record: the decision matrix
| Datum produced by the line | Classification | Decision criterion | Consequences for audit trail, retention and review |
|---|---|---|---|
| Set points and recipe version of the batch | GMP record | Defines the process conditions of the batch | Audit trail on changes; batch record retention; review at release |
| Measured values and limits of critical filling parameters | GMP record | Conformity to validated limits | Archiving with metadata; review at release |
| Servo motor current, cabinet temperature | Machine data | No demonstrated quality impact | No GMP audit trail; engineering retention |
| Critical alarm leading to a Grade A intervention | GMP record | Annex 1 8.16 and 8.17: intervention to be recorded | Batch record retention; trending and CCS |
| Informational alarm on hopper level | Machine data | Logistic action, no product effect | Event in the historian; outside risk-based review |
| Reject counts by cause and by phase | GMP record | Needed for reconciliation and investigations | Batch record retention; review at release |
| Logins, failed attempts, role changes | System GMP record | Underpins attributability of other records | Dedicated audit trail; periodic review |
| Observation of aseptic operations (8.19) | GMP record that does not originate in the PLC | Documented human judgement, not machine data | In the document system; correlated with line data |
The last rows show both sides of the distinction: the PLC produces data that are not GMP records, and the GMP records deciding sterility assurance no PLC will produce.
QRM and CCS
With ICH Q9(R1) the hazard is not "the datum is wrong" but "a batch decision is taken on a datum that is not attributable or not reconstructable": the assessment weighs patient impact, detectability and independent controls, and yields data classification and review scope. In the CCS they enter as technical and organisational controls (Annex 1 2.3 and 2.5). Periodic review checks that the validated state has not drifted through accumulated changes, that backups are restorable and that the alarms are still the ones that matter [QRM]; its link with line qualification is one of continuity, not repetition.
Worked example: Site Pyxis
"Site Pyxis" is a realistic but entirely fictional example. The site installs a vial filling line in an isolator, with machine SCADA and a site historian. In the URS, automation has a chapter titled "Annex 11 and Part 11 compliance" listing expected functions: audit trail, access control, backup, electronic signature. The supplier implements them; FAT, SAT, IQ and OQ pass without findings.
The error is in that chapter: it asked for functions and never classified data. The audit trail is configured "on everything": without a list of GMP records the supplier's prudent choice is to log anything. Months later an investigation must establish whether a reject limit had been changed on the previous shift: the answer exists, but extracting it needs supplier remote support, because the file cannot be filtered by parameter type and recipe entries carry the same label as machine parameters. The batch sits in quarantine, and the review required by procedure – "sample check" – turns out to have been run on login events.
The fix is not technological: a classified data list built after the fact, reconfiguration under change control of labels and logging levels, a review procedure rewritten around scope and occasion, a rationalised alarm list. It costs more than writing it into the URS would have: data classification is a design activity, not a remedy.
Levels of prescriptiveness
| Statement | Level | Source |
|---|---|---|
| Interventions and stoppages must be recorded in the batch record with time and duration | [REQUIREMENT] | EU GMP Annex 1, 8.17 |
| A system generating GMP records needs access control, audit trail, backup and periodic review | [REQUIREMENT] | EU GMP Annex 11 (2011) |
| Part 11 Scope and Application declares enforcement discretion on audit trail and legacy systems | [GUIDANCE] | FDA, 2003 guidance |
| Risk-based software lifecycle follows industry guidance | [STANDARD] | GAMP 5 Second Edition; ASTM E2500-25 |
| Audit trail review scope and frequency are set by criticality | [QRM] | ICH Q9(R1) |
| A backup never proven by a documented restore is not a backup | [GUIDEGXP] | Editorial recommendation |
Checklist
- Classify every data flow as machine data or GMP record, with a signed rationale, before the functional specification.
- State in the URS an audit trail that is filterable and exportable.
- Rationalise alarms, separating them from events and interlocks.
- Track rejects by cause and by phase.
- Define the role/privilege matrix, banning shared accounts.
- Synchronise the time reference across PLC, SCADA, EMS and site systems.
- Verify backups with an executed, documented restore.
- Govern supplier remote access with named authorisation and tracked sessions.
- Freeze recipe versions under change control.
Recurring errors and red flags
The first red flag is a URS chapter asking for "Annex 11 compliance" without the list of GMP records: it delegates to the supplier a decision that belongs to the licence holder. The second is an alarm list that only grows: if no alarm was ever downgraded to an event, rationalisation never happened. The third is a specification built on the Annex 11 revision draft as though it were in force: the joint EMA/PIC/S consultation closed on 7 October 2025 and no adoption is confirmed – validating against a text that does not exist is one error, ignoring its direction in a plant that will live decades is another. The fourth is the clock: unsynchronised systems make line data and environmental monitoring data impossible to correlate. The fifth is the never-restored backup and the always-on, untracked remote access, both cases for troubleshooting and retrofit with the line down.
The difference between a compliant system and a useful one is a list somebody must sign before the supplier configures the SCADA: the low-visibility, expensive-to-recover decision we write about in The Pragmatic GMP.
Key points
- Machine data / GMP record classification is a documented risk decision, not a by-product of architecture.
- GMP records essential to sterility assurance originate outside the PLC; much PLC data is not a GMP record.
- Proliferation of non-critical alarms is a risk: the alarm that matters is lost in the noise.
- The Annex 11 in force is the January 2011 text; the post-consultation draft is not a requirement.
- An audit trail that cannot be filtered is formally present and substantially unusable.
- Cybersecurity does not sit beside data integrity: it is its prerequisite.