PHARMA LAB · PL-06-021
CDS and LIMS migration: historical data, audit trails and reconciliation

In this article
A migration imports every expected result, but links them to the current method version instead of the version used during analysis. Counts match; laboratory history changes. Verification must therefore address content, relationships and meaning as well as row presence.
Moving between CDS or LIMS requires deciding what to transfer, what to retain in an accessible archive and how to manage transition. This article proposes editorial criteria and tests for a dedicated environment; it neither performs migration nor authorises source deletion.
1. Define what to migrate and what must remain accessible
Start with future data use. Some records still support active processes; others must remain available for retention, investigations or inspections. Moving everything into the new model is not the only strategy: a controlled archive may suit the purpose if it preserves content, access and required functions.
Describe the included population, justified exclusions, period and criteria. Assign each record class a destination and owner. Unconvertible data must not disappear from the plan: document access arrangements, limitations and impact assessment.
Archive planning must be ready before retirement. Leaving an old workstation running without controls is not a demonstrated retention strategy.
2. Inventory objects, relationships and transformations
Include samples, results, units, specifications, methods and versions, native files, processing, audit trails, signatures and historical identities. Separate identities needed to attribute past activity from accounts to enable today. Preserving an author’s name does not require leaving their old access active.
The mapping specification must explain source, destination, data type, transformation, missing-value handling and error conditions. Check decimals, precision, units, characters, dates and zones; do not silently turn a blank into zero. When a code’s meaning changes over time, preserve the relevant version’s context.
Identify one-to-many relationships too: a sample may have several tests, processing runs and decisions. A flattened final table can conceal this history. LIMS master-data version management supplies context that transfer must preserve.
3. Verify meaning with a reconciliation matrix
This original matrix links risk and evidence. Define criteria and coverage before executing transfer; there is no sampling percentage suitable for every migration.
| Object or relationship | Transformation | Risk | Check | Evidence |
|---|---|---|---|---|
| Result and unit | Field mapping or declared conversion | Correct number, wrong meaning | Compare value–unit pair and rule | Reproducible comparisons and explained differences |
| Result and method | New keys and version tables | Link to current version | Verify historical relationship | Reconciled result–version pairs |
| Native data and sequence | New path or container | File present but untraceable | Open from sequence and verify identity | Documented complete path |
| Audit trail and author | Event and identity conversion | Lost history or attribution | Compare events, times and meaning | Interpretable historical view |
| Signature and content | Representation at destination | Approval linked to different content | Verify record, version and meaning | Preserved link or approved solution |
| Records changed during transition | Incremental transfer | Loss or duplication at boundary | Reconcile interval and states | Final inventory with closed exceptions |
Use counts to find omissions and duplicates; integrity checks for identical copies where applicable; field and relationship comparisons for transformed content. A different checksum after conversion does not alone prove error, while an identical checksum on a file does not verify its link to the correct sample.
4. Plan cutover and controlled return
Cutover is the agreed operational handover between source and destination. Define when the population is fixed, which activities continue and how subsequent updates are captured. Clarify the authoritative system at each stage, avoiding unreconciled concurrent changes.
Specify prerequisites, responsibilities, operational window and go/no-go criteria. Laboratory continuity must cover samples in progress, open sequences and results under review. Records generated during interruption must enter a controlled workflow with later reconciliation.
Returning to the source may become harder after new destination records are created. Define rollback conditions and limits, copy protection and treatment of intervening data. Restarting the old server does not by itself reconstruct a consistent state.
5. Simulated case: 240 results, incorrect relationships
A trial transfer includes 240 results. Both source and destination show 240 rows. Relationship checks reveal that results acquired using method M17 version 2 now point to version 3: mapping used the method code without its version.
The team does not accept the transfer based on counts. It identifies the faulty rule, searches the entire potentially affected population and retains trial evidence. It corrects mapping to distinguish method identity and version, then repeats transfer and relevant checks in the dedicated environment.
Acceptance requires results to retain the applied version, parameters and links to original evidence. Unrecoverable relationships remain exceptions to assess and resolve; a plausible historical version must not be invented. The source remains protected under the plan.
6. Approve exceptions and demonstrate historical access
Reconciliation combines technical checks with reviewer use: start from a sample, open data, understand processing and decisions, and export what is needed. Include less straightforward cases such as corrected results, obsolete versions, former-user identities and timestamps with different offsets.
For each exception, record affected objects, cause, impact, action, repeated test and authorised decision. Specify intentional differences; investigate unexpected ones. Evidence quality matters more than a generic “100% successful” migration statement.
Before retiring the source, confirm access, readability, retention, recovery and responsibilities in the new arrangement. Retain inventory, versioned mapping, tests and decisions, distinguishing original and transformed data. Closing the project does not remove obligations for historical records.
Sources and status — checked 2 October 2026. EU GMP Annex 11, January 2011, §§4.8, 7, 10, 16–17; PIC/S PI 041-1, 1 July 2021, §§9.4 and 9.9, inspector guidance; FDA Data Integrity, final nonbinding guidance, December 2018, Q1(b), Q9–10; 21 CFR Part 11, §§11.10(b–c), 11.70, where applicable. Matrix and case are original examples, not universal percentages or protocols.
Continue exploring
PL-06-024
Hybrid Laboratory Records: Paper, Electronic Data and Responsibilities
A signature on a printout may not tell the whole analytical story. Define the components, relationships and responsibilities of the hybrid record.
Read the articlePL-06-023
Instrument Software Updates: Impact Assessment and Return to Use
A new version may start correctly while changing the meaning of exported data. Connect each change to risks, tests and release criteria.
Read the articlePL-06-022
Remote Instrument Support: Authorisation and Controls
Control the identity, activities and effects of a support session on laboratory records. A checklist and an escalation scenario guide the decision.
Read the article


