A self-inspection is not a rehearsal before the inspector arrives. It tests whether GMP, procedures and controls work in practice and whether the Pharmaceutical Quality System remains effective.
What GMP actually requires
The principle calls for monitoring GMP implementation and compliance and proposing necessary corrective measures. Section 9.1 requires the listed GMP matters to be examined at intervals following a pre-arranged programme.
Section 9.2 requires designated competent persons and an independent, detailed review. Section 9.3 requires records, observations, proposals where applicable and statements of subsequent actions.
Section 1.4(xvii) links self-inspection and quality audit to regular PQS appraisal. ICH Q9(R1) supports risk-proportionate decisions; ICH Q10 connects audits, management review and improvement.
PIC/S PE 009-17 is substantially aligned with the EU text. 21 CFR Part 211 contains Quality Unit and investigation duties, but no self-inspection provision directly equivalent to Chapter 9.
Build a genuinely risk-based programme
Create an audit universe covering processes, systems, products, outsourced activities, suppliers and end-to-end interfaces. For each object, document priority, previous coverage, limitations and next review.
Priority factors
- patient and product-quality risk;
- criticality and complexity;
- findings, deviations, OOS and complaints;
- changes, technologies or suppliers;
- data integrity and competence loss;
- overdue or ineffective CAPAs.
Out-of-plan triggers
- potentially critical event;
- recurring finding;
- material change or new outsourcing;
- declining supplier performance;
- inspection commitment at risk;
- data population that cannot be extracted.
The calendar should change as signals change. Exclusions and deferrals need residual risk, an owner, approval and a new date.
From preparation to follow-up
- Define the assurance question and decision the audit must support.
- Set criteria, scope and population from current requirements, SOPs and trends.
- Select a justified sample including exceptions and problematic records.
- Triangulate documents, interviews, shop-floor observation and data trails.
- Protect traceability of IDs, versions, periods, population and limitations.
- Escalate urgent risk immediately; do not wait for the final report.
- Issue and follow the report under the SOP; update CAPA, the universe and management review.
Defensible findings and CAPA
A useful finding links criterion → condition → evidence → extent → risk. Identify records, period, requirement and population; correct factual errors without negotiating the technical conclusion.
Administrative closure does not prove effectiveness. For significant findings, define the future evidence expected and when it will be assessed.
Audit-ready checklist
- Universe covers processes, systems, outsourcing and interfaces
- Priorities, frequencies and deferrals have documented rationale
- Auditor competence and independence are demonstrable
- Objective, criteria, scope, population and sample are documented
- Evidence trail is reproducible and limitations are declared
- Findings link criterion, evidence, extent and risk
- Urgent risks trigger immediate escalation
- Closure is distinguished from effectiveness
- Trends reach management review
- New signals update the programme
KPIs that measure assurance
Risk-weighted coverage, plan adherence with rationale, finding age by risk, recurrence, CAPA effectiveness failure and risks unresolved through resource constraints. A low finding count can also signal superficial audits.
Verified official sources
Always confirm the current version, local applicability, product and site authorisations.


