PHARMA LAB · PL-06-003

ELN in GMP Laboratories: Protocols and Electronic Records

Design an electronic notebook that preserves the context of bench work: protocols, samples, attachments, corrections, review and signatures. An operational matrix and simulated case.
Laboratory bench with a balance inside a closed draft shield, samples on a tray, a small tablet showing abstract fields and a closed paper notebook.

An ELN, or electronic laboratory notebook, is useful in GMP when it allows people to reconstruct what was planned, what was actually performed, by whom and using which data. Digitising the boxes on a form is not enough: the protocol, sample, materials, instruments, attachments, corrections and decisions must retain understandable relationships throughout the retention period. Start with the intended use and the complete record; then configure the operational pathway, review and necessary controls.

This article concerns ELN use in GMP laboratory activities for human medicines. It offers an original matrix and a simulated case of moving from paper to digital records. It does not assume that every research notebook is a GMP record or that an electronic signature automatically makes a system compliant.

1. Distinguish the notebook, protocol and GMP record

A free-form notebook captures observations, reasoning and results. A controlled protocol describes approved operations and recording instructions. The execution record documents what actually happened. An ELN can support all these functions, but you need to clarify which it performs for each activity and which content informs quality decisions.

Define the boundary between exploratory research, development and GMP-regulated activities, rather than relying on the software’s name. Establish which data constitute the original, where they reside and how they connect to external information. Chapter 4 distinguishes instructions and records; Annex 11 concerns computerised systems used in GMP activities. [2] [1] The intended-use document must translate this scope into testable functions.

Involve analysts, method owners, reviewers, QA, IT and owners of connected systems. Agree responsibilities for scientific content, configuration, access and retention. If one platform supports different activities, clearly separate statuses, permissions and rules. An exploratory experiment must not become release evidence simply by changing the project label.

2. Build controlled templates without losing touch with practice

The template should identify the method, revision, effective date, instructions and necessary fields. Specify units, recording precision, calculation rules and checks on critical data according to the applicable method. Distinguish prefilled values, acquired data and operator declarations: a populated field does not demonstrate that a step was performed.

When starting a record, keep the protocol version used identifiable. Define how to handle an update while work is in progress, with appropriate assessment and authorisation. Do not silently replace instructions in a record that has already been started. Test the system’s behaviour with a new revision and check that the reviewer can retrieve the previous context.

Avoid both an entirely free-form page where structured controls are needed and a pathway so rigid that analysts take notes elsewhere. Provide for observations, interruptions, justified non-applicable steps and managed exceptions. The requirement is to document the process faithfully, not to produce all-green screens through automatic confirmations or fictitious entries.

3. Link samples, materials, instruments and attachments

Associate the record with the relevant sample and aliquots, avoiding ambiguous or reused identifiers. Record the materials needed to reconstruct the work, such as the reagent batch, prepared solution and applicable status. Link instruments through their identity and information relevant to use; there is no need to copy indiscriminately every item held in other systems.

For each attachment, define its origin, author or producing system, relevant date, version and relationship to the step. A file named “final_results” does not explain which preparation it belongs to. Karolinska Institutet’s institutional practice illustrates the value of documenting methods, materials, processing and the location of external results; it is an academic example, not a GMP requirement. [6]

If the dynamic original remains in the instrument system or a scientific archive, ensure that the link supports authorised retrieval of the record and necessary metadata. A PDF or image may be a useful representation without replacing all original data. The distinction depends on the record and its use: FDA guidance addresses completeness and context in electronic data. [3]

4. Record at the time of the activity and make corrections visible

Design the workstation so that recording can occur as work is performed: an accessible device, individual authentication, a usable interface and conditions compatible with the bench. Test gloves, cleaning, screen position and realistic interruptions. A procedure cannot demand contemporaneous recording if the only terminal is far away and occupied; the problem needs an operational solution.

Distinguish the event time from the entry time when they differ. A late entry must be identifiable, justified and assessed according to the procedure, without backdating or presenting a reconstruction as a contemporaneous record. Chapter 4 requires records to accompany actions and changes to leave previous information legible. [2]

Define how to correct an error, add an observation and manage a deviation. Preserve the previous value, new information, identity, time and relevant reason. Do not delete an unsuccessful preparation to retain only the favourable one. Even a “cancelled” status should allow someone to understand why the activity was interrupted and what decision followed.

5. Give review, statuses and signatures a defined meaning

Separate record completion from declaring the work complete and from review. Define what each role checks: method execution, completeness, calculations, attachments, exceptions and relevant audit-trail information. The reviewer must be able to follow the pathway without asking the author to reconstruct it from memory. The sequence must reflect actual responsibilities and approved procedures.

For each signature, establish identity, meaning, signed content and its binding to the specific record version. Annex 11 requires a permanent link between signature and record, together with the date and time. [1] If content changes after approval, the system and procedure must manage the impact on the approved status and any further review; do not allow an earlier signature to appear to cover information added later.

For FDA-regulated activities, assess Part 11 applicability alongside the underlying record requirements. The scope guidance does not automatically extend Part 11 to every electronic note. [4] An image of a signature, an approval tick and a commercial function called “e-signature” are not interchangeable evidence of an adequately controlled process.

6. Integrate the ELN while preserving meaning and responsibility

Assign an authoritative source to each shared item of information. The LIMS may govern identification and the request; the ELN may document preparation; the instrument may retain raw data; an SDMS may manage scientific archives. This is one possible arrangement, not a mandatory allocation. Specify which identifiers, units, versions and statuses pass between systems.

Test missing, duplicate, rejected and delayed messages. The transfer must make its outcome, any discrepancy and the person responsible for recovery identifiable. If the ELN receives a weighing value, the context must show which sample, instrument and record produced it. A working connection alone does not demonstrate that the association is correct.

Limit manual copying, but do not confuse automation with accuracy. For critical data entered manually, Annex 11 provides for an additional check by a second operator or validated electronic means. [1] Choose the approach according to risk, and also verify relevant decimal separators, conversions, formulas and rounding.

7. Govern access, history and retrieval over time

Use individual accounts and permissions consistent with duties; manage the creation, modification and revocation of access. Appropriately separate administration from operational activities, documenting responsibilities even when the service is hosted externally. Cloud hosting does not automatically transfer all laboratory responsibilities to the provider.

Design an audit trail that can be reviewed: relevant events, before and after, author, date, reason and a link to the record. Define review responsibilities and frequency in relation to risk and the process. A large log that nobody can interpret does not achieve the practical purpose of the control; test retrieval of an actual change within the context of an execution.

Distinguish backup, restoration and archiving. Backup supports recovery; an archive must retain interpretable content for the applicable period. Verify retrieval of attachments, relationships, versions and necessary signature information. Annex 11 and MHRA guidance address these matters throughout the lifecycle. [1] [5] Do not adopt a universal number of years or assume that a PDF export is sufficient.

8. An original matrix: from event to evidence

The following matrix is a GuideGxP proposal to adapt to the local process. Turn each row into an identified requirement and a test with an expected outcome. Evidence must concern the actual version and configuration, including what happens when the normal pathway fails.

EventRecord and metadataControlReviewEvidence
Activity startsSample, protocol and revisionApplicable version identifiedConsistency with the requestExecution linked to the approved template
Material is usedIdentity, batch and relevant statusAssociation with the stepSuitability for the methodMaterial traceable from the execution
Instrument acquisitionValue, unit, origin and contextTransfer and mapping verifiedConsistency with original dataTransfer history and retrievable record
CorrectionBefore/after, author, time and reasonAuthorised and visible changeRationale and impactReconstructable history within the record
Interruption or deviationEvent, status and investigation referenceNo unauthorised progressionDecision on resumptionDocumented exception and authorisation
External attachmentIdentity, version, origin and relationshipDurable link and accessCompleteness and readabilityRetrieval of the file in its context
ApprovalSignatory, meaning, date and versionSignature bound to the contentCoverage and responsibilitySigned record and management of later changes
Archive retrievalRecord, attachments, history and relationshipsAccessibility and integrity verifiedInterpretability over timeDocumented complete-retrieval test

9. Simulated case: digitising a sample preparation

A laboratory transfers a preparation involving weighing and dilution to its ELN. The paper sheet contains quantities, the reagent batch, balance identifier, notes and a reference to the weighing printout. The first digital proposal reproduces only quantities and the calculated result. During the pilot, the reviewer cannot reconstruct the origin of a weighing or the instruction version: visual similarity has concealed a loss of context.

The team changes the template to link the sample, aliquot, versioned method, material and instrument record. It distinguishes acquired data from operator confirmation and tests the calculation with test values. A captured printout remains identified as a copy, with its origin and relationship defined; it is not declared a universal substitute for the electronic original.

During a second test, a method revision becomes effective while execution is already under way. The system preserves the starting version and makes the authorised decision to continue or interrupt visible according to the procedure. A wrong reagent association is corrected with a reason and history, rather than deleting the execution and recreating it as though it were new.

The reviewer finds the instructions applied, actual times, attachments, correction and exception outcome. The test demonstrates that the new pathway preserves the intended context; it does not by itself constitute full validation or authorisation for GMP use. The checks and approvals established by the project still need to be completed before release.

10. Prepare migration, training and routine use

Decide which historical notebooks to transfer and which to retain in the original system with guaranteed access. When migrating data, verify that value and meaning remain unchanged; a scan can lose links, order or necessary information. Define the management of originals and copies according to applicable requirements, without destroying paper simply because a file exists.

Use authorised or synthetic data, representative scenarios and approved acceptance criteria in the pilot. Train users in corrections, exceptions, review and outages, as well as routine entry. The continuity plan must explain how to document work during a failure and reconcile records afterwards without duplication or backdating.

  • Are intended use, owners and the complete record defined?
  • Are templates and calculations controlled in the actual configuration?
  • Do samples, materials and attachments retain verifiable relationships?
  • Have corrections, interruptions and signatures been tested?
  • Do access, audit trail and review have assigned responsibilities?
  • Have restoration, retention and export been demonstrated?
  • Are training, support and change management operational?

Return to the Digital Lab and Data Integrity HUB and LIMS, ELN, CDS and SDMS: Laboratory System Roles and Boundaries to define responsibilities across platforms.

Sources and applicability

Sources checked on 30 September 2026. The EU GMP index consulted still lists the January 2011 revisions of Annex 11 and Chapter 4; proposed revisions are not treated as current requirements. The European context considered here is human medicines. FDA and MHRA guidance apply within their respective scopes; the KI example concerns academic research. The matrix, case and checklist are original GuideGxP work to adapt and approve locally.

  1. European Commission — EU GMP Annex 11 — Computerised Systems. Revision 1, January 2011; effective 30 June 2011.
  2. European Commission — EU GMP Chapter 4 — Documentation. Revision 1, January 2011; effective 30 June 2011.
  3. FDA — Data Integrity and Compliance With Drug CGMP: Questions and Answers. Final guidance, December 2018.
  4. FDA — Part 11, Electronic Records; Electronic Signatures — Scope and Application. Final guidance, September 2003.
  5. MHRA — GXP Data Integrity Guidance and Definitions. Revision 1, March 2018.
  6. Karolinska Institutet — What you can/shall store in ELN. Institutional page, updated 3 February 2026.
Technical content for informed decisions; it does not replace the approved procedure, applicable requirements or the instrument manual.

Continue exploring