Search across the website

Find training courses, blog posts, guidelines, knowledge base articles and more.

to navigate esc to close to open

Expert Guidance on GMP Audits

5 min read
On this page

Scope and intended audience

This article covers GMP audit guidance for front-line QA, Qualified Person (QP)/Responsible Person (RP), Auditors and manufacturing professionals who plan, host, or conduct audits across GMP-regulated operations. It addresses internal self-inspections, supplier audits, and preparation for regulatory inspections.

Audit types and regulatory frameworks

GMP audits fall into three broad categories: internal audits (self-inspections), supplier or contract-giver audits, and regulatory inspections. Each operates under a different mandate and carries different consequences, but the underlying methodology overlaps.

EU GMP Chapter 9 requires manufacturers to conduct self-inspections to monitor compliance and propose corrective measures. PIC/S PI 002 provides a widely adopted model for inspection procedures. FDA cGMP (21 CFR Parts 210/211) does not prescribe a self-inspection programme in the same way, but the expectation exists through the broader Pharmaceutical Quality System (PQS) framework described in ICH Q10. Supplier audits are driven by Chapter 7 of EU GMP (outsourced activities) and by the contract giver's own quality system obligations.

Regulatory inspections are conducted by competent authorities (national agencies, FDA, WHO) against their own inspection guides. Your internal audit programme should mirror the scope and rigour of what an inspector would examine, so that the inspection itself surfaces no surprises.

Risk-based audit planning and scheduling

Build the annual audit programme from risk assessment outputs, not from a fixed calendar rotation. Inputs include site compliance history (deviation trends, recall events), product criticality (sterile vs. oral solid dose), supplier risk tier, and regulatory intelligence such as recent agency focus areas.

A site with repeated aseptic process deviations warrants a focused audit within months, not a routine visit next year. Conversely, a low-risk warehouse operation with clean inspection history can move to a longer audit cycle. Document the rationale for frequency and scope decisions; inspectors expect to see this logic in your Quality Management System (QMS).

Selecting and qualifying auditors

Auditors need documented competency in GMP requirements, audit technique, and the specific operations they assess. An auditor reviewing a sterile fill line should have direct experience with aseptic processing, media fills, and environmental monitoring. A data integrity audit demands someone who understands audit trails, electronic records, and the ALCOA+ principles.

Independence is non-negotiable for self-inspections: auditors must not audit their own work. For small sites with limited personnel, consider cross-site auditing arrangements or qualified external auditors. Maintain training records, audit logs, and periodic evaluations of auditor performance.

Audit preparation for the audited site

Preparation starts weeks before the audit date. Conduct a readiness self-assessment against the audit scope. Verify that documents the auditor is likely to request (batch records, validation protocols, Product Quality Reviews, deviation and CAPA logs, training matrices) are current and retrievable. Assign a site coordinator to manage logistics: room booking, escort schedules, access permissions, and IT access for electronic systems.

Run a gap analysis against recent deficiency trends from your own findings and published regulatory observations. If your national authority has flagged data integrity or cleaning validation in recent inspection reports, check those areas first.

Common inspection-readiness gaps

  • Overdue CAPAs, particularly effectiveness checks that were never completed.
  • Incomplete or missing PQRs, or PQRs that lack trend analysis and actionable conclusions.
  • Training records not current for personnel performing GMP-critical tasks, including temporary or contract staff.
  • Equipment qualification or calibration overdue, with no documented risk assessment justifying continued use.
  • Data integrity gaps: shared logins, disabled audit trails, or unsigned spreadsheet-based records used for GMP decisions.
  • Deviations closed without documented root cause investigation.

Conducting the audit and managing findings

The opening meeting sets scope, timeline, and expectations. Keep it short. The audit itself is evidence-driven: review documents, observe operations, and interview the people who do the work. Shop-floor interviews reveal whether SOPs are understood and followed, not just whether they exist.

Gather evidence in real time. Photograph (where permitted), note document references, and record timestamps. When you observe a potential finding, confirm it against the applicable requirement before raising it. At the closing meeting, present observations clearly, cite the evidence, and give the site an opportunity to provide immediate clarification or context.

Classifying observations and writing effective audit reports

Grade each observation by GMP risk. PIC/S and many EU competent authorities use a three-tier classification: critical, major, and other deficiencies. FDA uses Official Action Indicated (OAI), Voluntary Action Indicated (VAI), and No Action Indicated (NAI) at the inspection level, with individual observations documented on Form 483.

A well-written finding has four elements: what was observed, the evidence supporting the observation, the GMP requirement it breaches, and the assessed risk. "Training records were incomplete" is weak. "Operator [name/ID] performing aseptic gowning on [date] had no documented completion of SOP-XXX, required by the site training matrix, revision [number]" is actionable. Vague findings produce vague CAPAs.

Driving effective CAPA from audit findings

Every critical and major finding needs a CAPA with a defined owner, root cause analysis, corrective action, preventive action, timeline, and effectiveness verification. Root cause should go beyond "human error"; tools such as Ishikawa diagrams or the five-whys method are expected for significant findings.

Track audit CAPAs within the site QMS alongside all other CAPAs. This prevents audit findings from falling into a parallel tracking system that nobody reviews. Set escalation triggers: if a CAPA is overdue or its effectiveness check fails, the issue must route to senior QA management and, where relevant, to the QP/RP. Recurring audit findings in the same area signal that previous CAPAs were ineffective.

Hosting regulatory inspections

Regulatory inspections carry legal consequences that internal audits do not. Assign a back-room team to retrieve documents, verify facts, and prepare responses before information reaches the inspector. Every document provided should be reviewed by QA for accuracy and completeness before handover. Never volunteer documents that were not requested, but never delay or obstruct a request.

If an inspector raises a preliminary observation, do not argue during the inspection. Provide factual context and, if possible, supporting documentation. After the inspection, respond to the written report within the required timeline with specific, committed remediation actions. Do not promise actions you cannot deliver on schedule. Missed commitments erode credibility for future inspections.

Key takeaways

  • Base audit frequency and scope on documented risk assessments, not fixed calendars.
  • Assign auditors with demonstrated competence and independence from the area being audited.
  • Treat preparation as a structured gap analysis, not a last-minute tidy-up.
  • Write findings that cite specific evidence and the requirement breached; vague observations produce ineffective CAPAs.
  • Track audit CAPAs inside the site QMS with defined owners, deadlines, and effectiveness checks.
  • Maintain inspection readiness continuously; an inspection announcement should trigger logistics, not remediation.
Topics: GMP Audit