Independent and not affiliated with the FDA, MHRA, ISPE, PDA, or any agency. Get the appgoutham@madhadi.com
madhadi.comData Integrity & GxP Quality
Browse all topics → Articles Templates & Procedures Learning paths GlossaryScenariosToolsRegulatory ReferencesLearning PathsTopics About Start here
Intermediate Quality Assurance

Batch Record Review: What It Is, What to Look For, and What Regulators Expect

A practical guide to GMP batch record review: the process, what makes a batch record complete, how to conduct a meaningful review, common failures, and how automated systems change the picture.

Batch record review is the quality oversight activity that stands between a completed manufacturing batch and a released pharmaceutical product. It is the last structured opportunity to identify execution errors, data integrity failures, or process deviations before product reaches patients.

Done well, batch record review catches problems. Done poorly, mechanically signing off a stack of pages without meaningful examination, it becomes a regulatory liability rather than a quality control. Inspectors know the difference, and so do the patients who depend on the product being what the label says it is.

This article walks through what a batch record is, what a complete one contains, how to review one in a way that actually finds problems, and how the picture shifts when paper gives way to electronic systems. It is written to serve three readers at once: someone new to GMP who needs the vocabulary and the rules, a working reviewer who wants sharper technique, and a quality leader thinking about review as a system rather than a task. The principles apply across small molecule drug product, sterile injectables, biologics, vaccines, and the device combination products that pair a drug with a delivery system. The vocabulary shifts a little by sector, but the obligation to reconstruct what happened from a complete, attributable record does not.


What a batch record is

Under 21 CFR 211.188, a batch production and control record must be prepared for each batch of drug product. It must include, or refer to, the master batch record and document the actual conditions and results of each significant step in manufacturing. A companion regulation, 21 CFR 211.192, requires that all production and control records, including those for packaging and labeling, be reviewed and approved by the quality control unit to determine compliance with all established procedures before a batch is released or distributed. The same regulation requires that any unexplained discrepancy or any failure of a batch to meet specifications be thoroughly investigated, whether or not the batch was already distributed.

The EU framework carries the same obligations in different words. EU GMP Volume 4, Chapter 4 sets the documentation requirements for batch processing and packaging records, and EU GMP Annex 16 makes the Qualified Person personally responsible for confirming each batch was made and checked in compliance before certification. ICH Q7, the API GMP guide, mirrors all of this for active pharmaceutical ingredients in its Sections 6.5 and 6.7. The point worth internalizing: batch record review is not a single-country rule. It is a near-universal expectation of every GMP regime, because the logic is the same everywhere. You cannot release what you cannot reconstruct.

Two documents sit at the center of the activity, and confusing them is a common early mistake.

The master batch record (sometimes called the master production record, master formula, or master formula record) defines what should happen: the formula, the procedures, the equipment, the processing parameters, and the in-process tests. It is a controlled document, approved before use, and changed only through change control. For each batch, an exact copy of the relevant portions is reproduced for execution, and 21 CFR 211.186 sets out what the master record must contain, including the requirement that it be checked, dated, and signed by a second person.

The executed batch record (EBR), also called the production batch record, documents what actually happened: the materials used, lot numbers, actual values for each parameter, results of in-process tests, any deviations, and the signatures of the personnel who performed and checked each step.

The two must be consistent. Where they differ, that difference is either an authorized deviation or a data integrity problem. There is no third category. A reviewer who treats an unexplained difference as “probably fine” has missed the entire point of the review. This single discipline, every difference must resolve to either an approved deviation or an investigation, is the mental model that separates a real reviewer from a signature.

A note on terminology, because interviewers test it. In a fully electronic environment, “EBR” usually refers to the electronic batch record system itself, often a module of a manufacturing execution system. In a paper or hybrid environment, the executed batch record is the physical or scanned packet. The acronym is the same; the thing it names depends on context. Know which you mean.


What a complete batch record contains

A compliant batch record for a typical pharmaceutical manufacturing operation includes the following. The grouping below is a way to read a record, not a regulatory list, but every item maps back to the requirements in Part 211 Subpart J, and the closely related content requirements in 21 CFR 211.186 (master record) and 211.188 (batch record).

Identity and traceability:

  • Batch number, product name, strength, dosage form
  • Date and time of each manufacturing step
  • Equipment identifiers for each piece of equipment used
  • Calibration and cleaning status of critical equipment at time of use

Materials:

  • Component list with item codes, lot numbers, and actual quantities weighed or dispensed
  • Yield reconciliation at each stage with theoretical yield calculations
  • Reject and reprocess documentation if applicable

Process execution:

  • Step-by-step record of execution with actual values (temperatures, pressures, times, agitation speeds, pH measurements)
  • In-process results against specifications
  • Environmental monitoring records for operations in classified areas
  • Instrument readings and calibration status references

People:

  • Attribution: who performed each step (individual name or ID, not a group or department)
  • Second check or verification: who checked critical steps
  • Supervisory or QA review signatures

Deviations:

  • Any deviation from the master batch record, however minor
  • Reference to the formal deviation record if one was opened
  • Impact assessment: does the deviation affect product quality?

Post-processing:

  • Results of release testing
  • References to the Certificate of Analysis
  • Final yield and reconciliation against theoretical yield

The thread running through all of these is the set of data integrity attributes summarized as ALCOA+ (see ALCOA+ in detail): each entry should be attributable, legible, contemporaneous, original, accurate, and (in the expanded form) complete, consistent, enduring, and available. A reviewer who keeps those attributes in mind has a built-in checklist for every field on the page.

A sample of what good looks like at the field level

Abstractions do not help a new reviewer recognize a good entry from a bad one. Here is a small extract of a weighing step as it should appear in a paper record, with the reviewer’s read in the third column.

FieldEntryReviewer read
MaterialMicrocrystalline celluloseMatches dispensing list
Item codeMCC-101Matches master record
Lot numberA4471-22Traceable to receiving and the materials issue log
Target / tolerance12.50 kg, plus or minus 0.25 kgFrom master record
Actual weight12.48 kgWithin tolerance, no action
Balance IDBAL-204In current calibration at time of use
Performed by / date / timeJ. Okafor / 14 Mar 2026 / 09:12Individual, contemporaneous, attributable
Verified by / date / timeM. Halpern / 14 Mar 2026 / 09:14Second person, different from performer

The point of seeing it laid out: every cell is a small claim the reviewer is checking against another source. The actual weight is checked against tolerance. The lot number is checked against the issue log. The balance ID is checked against the calibration system. The performer and verifier are checked against each other (they must differ on a critical step) and against the training records (both must be qualified for the task). A blank cell, two identical signatures, or a time that runs backward against the previous step is a finding, not a typo to wave through.


Who reviews a batch record and when

Review is not a single event at the end. It is a chain of checks, each catching a different class of error.

During manufacturing: Operators execute and self-check each step. In many operations, a second person verifies critical steps (weight checks, label reconciliation, critical additions) at the time of execution. Contemporaneous second checks catch errors while they are still cheap to fix, before the next step locks them in.

In-process quality oversight: In higher-risk operations, a quality or manufacturing supervisor reviews in-process records before the next stage begins. This is common in sterile operations and in personalized therapies, where a single batch may equal a single patient dose and there is no opportunity to remake it. It is equally common in continuous or campaign manufacturing, where catching a drift early prevents a string of suspect batches.

Post-manufacturing QA review: This is the formal batch record review required by 21 CFR 211.192. Quality assurance reviews the complete executed batch record before a batch can be released. This review confirms that:

  • All required entries are present
  • All values are within specification
  • All deviations are properly documented and resolved
  • The record is attributable, legible, and internally consistent
  • Release testing results are acceptable

Final disposition and release: In the United States, the quality unit makes the disposition decision under 21 CFR 211.22, which holds the quality control unit responsible for approving or rejecting all drug products. In the EU and other ICH regions, a Qualified Person (QP) certifies each batch before release under EU GMP Annex 16. The QP relies on the batch record review but is personally accountable for the certification, which is one reason the review documentation has to stand on its own and not live only in the reviewer’s head. The mechanics of that final call are covered in batch disposition decisions and the QP and batch release under Annex 16.

A clear split of duties across these roles is part of a functioning quality system; the article on roles and responsibilities in GxP covers how the quality unit’s independence underpins all of it.

Roles and responsibilities at a glance

RoleResponsibility in the review chain
Operator / technicianExecutes each step, records actual values contemporaneously, signs as performer
In-process verifierPerforms the second check on critical steps at time of execution, signs as verifier
Manufacturing supervisorReviews the record for manufacturing completeness and accuracy before it goes to QA; first-pass completeness check in many sites
QA batch record reviewerPerforms the formal 211.192 review, confirms deviations are closed, raises findings, recommends disposition
Deviation / investigation ownerOwns each deviation and its impact assessment, provides the closure the reviewer needs
QA disposition authority / QPMakes or certifies the release decision, accountable for the call
QC laboratoryProvides release testing results and the Certificate of Analysis the reviewer reconciles against

The separation matters for a reason inspectors probe directly: the person who makes a product should not be the sole judge of whether it is fit to release. Independence of the quality unit is not an organizational nicety. It is required by 211.22 and it is the first thing a finding about “QA was pressured to release” attacks.


How to conduct a meaningful batch record review

Batch record review is not reading every line to confirm signatures are present. That is document verification. Review means looking for what might be wrong. The techniques below are ordered roughly by how often they catch real problems.

Start with the deviations

Check whether any deviations are recorded in the batch record. If there are, confirm:

  • Each is formally captured in the deviation management system (or in the batch record itself, per procedure)
  • The root cause assessment is complete and reasonable
  • The impact assessment is documented and justified, not assumed
  • The deviation is closed, or the batch is being held pending closure

More telling: if there are no deviations in a complex manufacturing batch, question whether the deviation threshold is appropriately sensitive. Zero-deviation batches in a complex process can indicate that the team is not documenting minor deviations, which is itself a data integrity indicator. A mature operation expects a baseline rate of minor, no-impact deviations; their absence is more suspicious than their presence.

Check for internal consistency

Cross-reference values that appear in more than one place:

  • If a temperature is recorded at time T, does it match the in-process trend or the automated data capture?
  • If a weight is transferred between steps, do the yield calculations add up?
  • If an operator signed at 14:30 for step 5, are steps 3 and 4 signed by someone before that time?

Inconsistencies in timestamps, values, or sequences within a batch record are data integrity indicators, not just minor record errors. Every inconsistency needs an explanation.

Evaluate yield and reconciliation

Yield reconciliation catches process problems that no other control catches. Work a simple example. Suppose theoretical yield at a granulation step is 10.0 kg.

Actual yieldReconciliationReviewer action
9.6 kg4% loss, within normal rangeAccept, no action
9.1 kg9% loss, below the lower action limitInvestigate: confirm against historical range, raise a deviation if it stands
7.2 kg28% loss, well outside rangeReject for explanation: clogged filter, failed transfer, line not rinsed, lost material
10.0 kg, batch after batchExact match every timeInvestigate: real processes vary; a perfect repeat suggests numbers are being made to fit

Unexpected yield loss, consistent loss at the same step, or yield that is suspiciously perfect are all signals worth investigating. Reconciliation also matters for accountability: it forces you to account for all material, what entered the process, what came out, and what was discarded, so a diversion cannot hide in normal variation. 21 CFR 211.103 requires that actual yields and percentages of theoretical yield be determined at the conclusion of each appropriate phase of manufacturing, and 21 CFR 211.192 requires that any unexplained discrepancy be thoroughly investigated, so reconciliation is not optional good practice. It is the rule.

A worked number for the granulation row above: theoretical 10.0 kg, actual 9.1 kg.

Percent yield   = (9.1 / 10.0) x 100   = 91.0%
Percent loss    = 100 - 91.0           = 9.0%

If the validated normal range for this step is 95% to 99%, then 91% is below the lower action limit, and the reviewer does not accept it as “just a bit low.” It triggers a check against the campaign history and, if it stands, a deviation. The reviewer’s job is to know the action limit, not to eyeball whether a number feels reasonable. A fillable version of this calculation, with fields for every stage of a multi-step process, is the yield reconciliation worksheet.

Review in-process results in sequence

Do not just check that values are within specification. Check whether they make physical sense and whether any value changed unexpectedly between time points. A pH that drops sharply in the middle of a process step and then recovers to in-specification may indicate an undocumented operator intervention. A temperature that holds at exactly the setpoint with zero variation across an hour may indicate a sensor that is not actually reading.

For automated data capture from a distributed control system (DCS) or process historian, compare the electronic process data to the manual entries in the paper or electronic batch record. If they do not match, the discrepancy needs an explanation before the batch moves forward. The integrity of the historian itself is its own subject, treated in process historian data integrity.

Check for corrections

Every correction to a paper batch record must follow good documentation practices: single line through the error so the original stays legible, corrected value written nearby, initialed, and dated, with a reason where the procedure requires one. White-out, obliteration, erasure, and writing over the original are prohibited.

For electronic batch records, the audit trail captures all changes automatically. Review the audit trail for the batch, specifically looking for:

  • Changes made after the batch was considered complete
  • Changes to critical parameters or results
  • Changes by users who were not involved in manufacturing the batch
  • Bulk changes (multiple entries changed in a short time window)

How to read an audit trail efficiently, and what patterns signal trouble, is covered in audit trail design and review and, for the routine cadence of doing it, operationalizing audit trail review.

Confirm attribution and the performer-verifier rule

On every step that requires a second check, confirm two people signed and that they are not the same person. One operator cannot be both performer and independent verifier on a critical step; the verification means nothing if the same hands did both. Confirm too that both are qualified for the task per current training records. An entry signed by someone whose training had lapsed is a finding even if the value is correct, because the control (a qualified person doing the work) was not actually in place.

Deciding whether a discrepancy needs a deviation

Earlier this article states the rule plainly: every difference between what the master record specified and what the executed record shows resolves to either an approved deviation or a data integrity problem, with no third category. In practice a reviewer needs a repeatable path to that call, not a judgment made fresh each time. The flow below is the decision most of the techniques above eventually feed into.

There is no fourth outcome where the reviewer quietly decides a discrepancy is "probably fine" and signs anyway. Every path above ends in either a documented non-issue, a documented match to an existing approval, or a new deviation, never a silent pass.


Acceptance criteria: how you know the review is done right

A reviewer needs an explicit definition of “complete and acceptable,” not a feeling. A defensible batch record review meets all of the following before the reviewer signs:

  • Every required field is present and legible, with no unexplained blanks.
  • Every entry is attributable to a single named individual, contemporaneous with the work, and original or a verified true copy.
  • Every recorded value is within its specification or in-process limit, or is covered by a closed deviation with a documented impact assessment.
  • Yield and material reconciliation at each defined stage falls within the validated range, or any variance is explained and, where required, investigated.
  • All deviations referenced anywhere in the record exist as formal records, are root-caused, impact-assessed, and closed (or the batch is explicitly held pending closure).
  • The audit trail (electronic) or the corrections (paper) show no unexplained post-completion changes, no changes by uninvolved users, and no improper corrections.
  • Release testing is complete, in specification, and the Certificate of Analysis matches the record.
  • The review itself is documented: who reviewed, when, what was found, and how each finding was resolved.

If any one of these fails and is not resolved, the batch is not ready for disposition. “Good enough” is not an acceptance criterion. The clearest test of whether a review was real: could an inspector pick up your review record a year later and see exactly what you checked, what you found, and how it closed, without asking you?


A worked review walkthrough

To make the technique concrete, here is how a reviewer might move through a single solid-dose batch record in practice.

  1. Frame the batch. Read the batch number, product, and any holds or open events flagged at intake. Note the master record version in effect, and confirm it is the approved current version, not a superseded one.
  2. Pull the deviation list first. Two minor deviations are open: a granulation hold time exceeded by 18 minutes, and a balance that was found out of calibration after a weighing step. The first has an impact assessment referencing a validated hold-time study; the second triggers a check of every weight taken on that balance since its last good calibration. The reviewer confirms both threads are closed before going further.
  3. Walk the material accountability. Each active and excipient lot is traced from dispensing through reconciliation. One excipient lot number in the dispensing record does not match the number in the materials issue log. That is a stop. It is either a transcription error to be corrected per procedure, or a real material mix-up to be investigated.
  4. Reconcile yields step by step. Granulation, compression, and coating each reconcile within range. Final yield ties to the in-process counts.
  5. Read the in-process and environmental data in time order, comparing manual entries to the historian where one exists.
  6. Confirm attribution and second checks on every step that requires them, and that no one signed as both performer and verifier on the same critical step.
  7. Review the release testing package and confirm the Certificate of Analysis references match the batch number, strength, and specifications.
  8. Document the review itself, including what was found and how each finding was resolved, so the disposition decision and any later QP certification rest on a visible record.

The point of the sequence is that deviations and material accountability come early, because they are most likely to stop the batch, and the reviewer never relies on “looks complete” as a finding. Notice that step 3 produced a hard stop. A real review produces findings; a review that never finds anything across a year of complex batches is the one an inspector worries about.


The electronic batch record difference

When manufacturing shifts from paper batch records to electronic batch records, typically integrated with a manufacturing execution system (MES) or DCS, the review process changes. The data integrity considerations specific to these platforms are covered in MES, EBR, and SCADA data integrity, and the messy middle state where some records are paper and some electronic is covered in hybrid paper and electronic records.

What becomes easier:

  • Automated data capture eliminates manual transcription errors
  • In-process limits can be enforced in real time; the system will not let you proceed if a critical parameter is out of range
  • Calculations are performed automatically, reducing arithmetic errors
  • Review can include automated exception reports instead of reading every line

What becomes more complex:

  • The reviewer must understand the audit trail and know how to interpret it
  • Automated enforcement can create a false sense of security: if the limits are configured wrong, the system enforces the wrong thing, consistently, on every batch
  • System failures create gaps in the electronic record that must be managed and explained
  • Integration interfaces between systems introduce data integrity risk at transfer points, which is why those interfaces are a focus of automation validation

What regulators focus on in EBR review:

  • Were the process parameter limits in the EBR correct for this batch and product?
  • Were any fields entered or modified manually that should have been automated?
  • What does the audit trail show for the batch?
  • Are there any time gaps in automated data capture that need explanation?

The applicable expectations sit in 21 CFR Part 11 in the United States and in EU GMP Annex 11 in Europe; the practical mapping between them is in Part 11 and Annex 11. The shorter version: an electronic record review is not lighter than a paper one, it is differently distributed, with more weight on configuration correctness and audit trail interpretation and less on legibility and arithmetic. A reviewer in an electronic environment who never opens the audit trail is doing the paper job on an electronic record, which is to say half a job.


Paper, hybrid, and full EBR review compared

The prose above describes what changes as records move from paper to electronic. Laid out dimension by dimension, the differences are sharper, and they explain why a site cannot simply reuse a paper reviewer checklist unchanged on a hybrid or electronic record.

DimensionPaper batch recordHybrid (paper record plus electronic instruments or systems)Full electronic batch record (EBR / MES)
Typical review time for a routine batchLongest: every page and every calculation read and re-checked by handOften the slowest of the three in practice, because the paper portions still need full reading and the electronic exports have to be reconciled against themShortest per batch once review by exception is validated; the underlying data set reviewed is larger but the reviewer reads a filtered exception report, not every point
Dominant failure modeTranscription and arithmetic error, illegible or missing entries, improper correctionsThe paper-to-electronic reconciliation gap: a value transcribed from an instrument printout that is itself never checked against the system it came from, or a printout that is not retained as the true sourceA misconfigured limit or exception rule that consistently enforces or approves the wrong thing on every batch, silently, because the system never disagrees with itself
Role of the audit trailNone; the paper record instead relies on ink corrections and second-person witnessing at the time of entryExists on the electronic pieces (LIMS, historian, standalone instrument) but not on the paper record itself, so continuity between the two has to be checked manually, entry by entryCentral: the audit trail is often the primary evidence a reviewer examines, more than the raw values, because it shows what changed, when, and by whom
Where arithmetic and reconciliation happenManual: the reviewer re-checks yield and unit conversions by hand against the raw entriesMixed: some calculations are automated (an in-process assay result, for example) while others are still hand-entered and hand-checkedSystem-calculated: the reviewer confirms the calculation logic was validated, not the arithmetic itself, which shifts the review question from “is the math right” to “was the formula ever right”
What “complete” meansEvery required field filled, legible, signed, with no correction irregularitiesAll of the paper criteria, plus every electronic export or printout present and traceably linked to the paper entry it supportsEvery required field populated by the system or a validated manual entry, with no unexplained gap in automated capture
CorrectionsSingle line through the error, initialed, dated, reason where required; the original must remain legibleThe paper portion follows paper correction rules and the electronic portion follows electronic ones; a correction that touches both has to be reconciled in both places, which is easy to missSystem-mediated correction function; the original stays visible in the audit trail alongside the corrected value, the reason, and the approver, see correcting an electronic batch record
Review-by-exception feasibilityNot feasible; there is nothing to programmatically filterPartial at best: the electronic components can be filtered, but the paper components still need a full manual read, so the time saving is smaller than it looksFully feasible once the exception rules are validated against seeded failures, see review by exception design
Typical inspection focusLegibility, correction technique, second-person verification, arithmetic accuracyWhether the two record types were actually reconciled entry by entry, or whether the paper record and the electronic source were ever allowed to quietly divergeConfiguration correctness, audit trail interpretation, and whether manual overrides of the system were properly justified and reviewed

The reconciliation checklist for the hybrid case, the exact steps for tying a paper entry back to its electronic source, is its own document; see the hybrid record reconciliation checklist and hybrid paper and electronic records for the full treatment. The one-line summary a reviewer should carry between all three: paper review finds errors people made, electronic review finds errors the configuration made, and hybrid review has to find both, plus the errors introduced at the seam between the two.

Combination product batch records: what changes

A drug-device combination product, a prefilled syringe, an autoinjector, an on-body delivery system for a biologic, executes a batch record that is not simply a drug batch record with a few extra rows. It carries the drug-side content in full (formulation, fill, in-process testing) and adds device-side content that a reviewer trained only on drug manufacturing can easily under-scrutinize. The regulatory basis for how a combination product’s quality system is built, the streamlined approach under 21 CFR Part 4, the primary mode of action determination, and which provisions get added to which base system, is covered in full in combination products and cGMP compliance under 21 CFR Part 4. This section stays narrower: what specifically changes in the batch record itself and what a reviewer checks differently.

Batch record sectionDrug-only contentAdded for a single-entity combination product (example: an autoinjector)
Component receipt and releaseActive ingredient, excipients, primary containerDevice components: needle, spring, housing, plunger, each released against its own dimensional and functional specification, not treated as generic bought-in hardware
Process executionFormulation, fill, stoppering, sealingAssembly steps: sub-assembly, needle shielding, spring loading, final assembly, each with its own sequence and tolerance in the master record
In-process testingFill weight, pH, bioburden, in-process assayDevice functional tests: activation or actuation force, delivered dose or volume accuracy, audible or tactile confirmation where the design specifies one
Container closure integrityStandard test on the vial or cartridge, see container closure integrity testingPerformed at the final assembled configuration, not the container alone, because the seal the patient depends on is the assembled device
LabelingDrug label content, lot number, expiryAdds device lot or serial capture and, where applicable, unique device identifier (UDI) application and verification
DeviationsDrug-process deviations: fill weight, temperature, hold timeAdds device-process deviations: mechanical failure, a use-error signal from a design or human factors study, a dose-accuracy miss, routed through the same CAPA system extended to device failure modes

The reviewer discipline that matters most here is not new technique, it is refusing to apply two different standards inside one record. The same attribution, second-check, and deviation-handling rules that apply to the fill and formulation pages apply exactly to the assembly and functional-test pages. The common miss is a reviewer who reads the drug-side data closely, because that is the training they had, and moves quickly through the device-side pages because the vocabulary (torque, actuation force, delivered volume) is less familiar. An inspector does not grade the two halves of the record on different curves, and neither should the reviewer.

Batch record review under continuous manufacturing and real-time release testing

Continuous manufacturing (CM) breaks the assumption behind most of this article: that a batch is a discrete, fixed quantity that moves through sequential unit operations and earns one review at the end. Under CM, material flows continuously through connected unit operations, and a “batch” is typically defined by a time window, a defined quantity, or a state-of-control boundary (start-up, steady state, planned or unplanned stop) rather than a vessel-full. ICH Q13, Continuous Manufacturing of Drug Substances and Drug Products, finalized by the ICH Assembly in November 2022 and adopted by FDA as final guidance in March 2023, sets the scientific and regulatory expectations for this mode; the validation-lifecycle differences it drives are covered in the process validation lifecycle and the disposition mechanics of real-time release testing (RTRT) are covered in batch disposition decisions. This section covers only how the review activity itself has to change.

The review paradigm shifts in three concrete ways:

  • From step-by-step reading to state-of-control confirmation. Instead of confirming each discrete step happened in sequence within limits, the reviewer confirms the process held a defined state of control for the entire run, including start-up and shutdown, which are higher-risk periods that a batch-based checklist built for a steady sequence of steps will not naturally probe.
  • From a single yield reconciliation to traceable material genealogy. A continuous run needs residence-time-based traceability: if an input lot changes, or an excursion is detected at a specific point in time, the control strategy has to show which output material corresponds to that window so only the affected material is diverted, not the whole run and not too little. The reviewer’s job is to confirm the diversion boundary the system applied matches what the validated residence-time model actually supports, not to accept a round-number estimate.
  • From end-product testing to model-in-state confirmation. Where RTRT substitutes in-process measurements and models for some or all end-product testing, the reviewer has to confirm the model or process analytical technology (PAT) measurement was in its qualified, in-control state for this specific run, the same logic as confirming an exception-report rule was validated before trusting what it did not flag. A model that drifted silently during the run and was not caught invalidates the release basis for whatever it was substituting for.

A worked example makes the diversion-boundary point concrete. A continuous tablet line runs an 8-hour batch. At minute 220, an in-line near-infrared sensor flags a blend uniformity excursion. The validated residence-time distribution for this line states that material affected by an event at the blender travels for 6 to 9 minutes before reaching the tablet press. The control system automatically diverts tablets compressed 6 to 9 minutes after minute 220 (that is, material corresponding to that window) to reject, and the rest of the 8-hour run proceeds to disposition on its own merits. The reviewer’s task is not to re-derive the residence-time model; it is to confirm the diversion the system actually executed matches the qualified window, that the sensor’s own performance check was in range through the run, and that no other excursion in the same run was left un-diverted. Reviewing this the way a fixed-batch record is reviewed, by reading a stack of pages for a single end-of-run signature, would miss the one question that actually matters: was the diversion boundary correct.

Review checkpointFixed-batch manufacturingContinuous manufacturing
Unit under reviewOne batch, a defined quantity from one vessel or one campaignA time- or quantity-defined run, potentially spanning multiple raw-material lots
Yield reconciliationActual against theoretical for the whole batch at defined stagesMaterial balance and residence-time-based traceability confirming input-to-output correspondence, not a single end-of-run number
Deviation scopeApplies to the whole batch unless a sub-lot is separately identifiedApplies to a residence-time-bounded window of material; the reviewer confirms the diversion boundary, not just that a deviation was opened
Basis for releaseEnd-product test results (standard) or a registered parametric exception (uncommon)Often RTRT: in-process measurements and models substitute for some or all end-product testing, gated on the model’s own qualified, in-control state during the run

The common miss is procedural inertia: applying a fixed-batch review checklist to a continuous run without rebuilding it for a data stream. A checklist built to confirm “was step 7 completed before step 8” has nothing useful to say about “was the process in a state of control from minute 40 to minute 460,” and a reviewer who only knows the first question will sign a review that never actually asked the second.


Common batch record review failures

These are the patterns that recur in inspection findings and warning letters. None of them require an exotic process to occur; they happen in ordinary operations under ordinary pressure to release. The broader inspection patterns these feed into are catalogued in FDA warning letter patterns.

1. Rubber stamp review. The reviewer signs the batch record within minutes of receiving a record that should take much longer to examine, with no evidence of meaningful work. In an inspection, investigators may ask reviewers how long they spend on a batch record and what they look for. A reviewer who cannot describe their process reveals that the review is a formality.

2. Deviation documentation avoidance. Small deviations, a process time that ran 10 minutes long, a temperature that exceeded the in-process limit by 0.2 degrees C, go undocumented because “they are within the range we have always accepted.” If it is not in the procedure, it is a deviation. If the wider range is genuinely acceptable, change the procedure through change control to reflect the real control range, with data to support it.

3. Incomplete yield reconciliation. Yield is calculated but not reconciled against material balances or against the campaign history. Without true reconciliation, a material diversion or a quiet process drift can go undetected for many batches. This is a recurring 211.103 citation.

4. Inconsistent reviewer standards. Different QA reviewers apply different standards. What one approves as a minor documentation issue, another would reject. This inconsistency is itself a data integrity risk: it suggests the outcome depends on who reviews, not on documented criteria. Calibration sessions, where several reviewers review the same record and compare findings, are an effective fix.

5. Post-release corrections. A batch record is reviewed, approved, and the batch released. Then someone notices an error and corrects it after release. Post-release corrections are not prohibited, but they require justification, a new QA review, and documentation of why the error was not caught before release. A rising rate of them is a signal that the pre-release review is not working.

6. Reviewing around an open investigation. The batch record is signed and the batch dispositioned while a related deviation or out-of-specification result is still open. 211.192 requires investigation of any unexplained discrepancy before release; a reviewer who closes the record ahead of the investigation has inverted the order. The investigation gates the release, not the other way around. The mechanics of those investigations sit in the OOS investigation process.

7. Treating a manual override as routine. In an electronic environment, an operator override of an automated control is sometimes recorded but rarely scrutinized. Every override is a place where the validated control was bypassed by a human decision, and each one deserves a reason and an impact read, not a glance.

These failures rarely stay contained to one record. A pattern of weak review is read by inspectors as a quality culture problem, and it shapes how the rest of the inspection goes. When a finding like this lands, the response strategy is its own discipline, covered in 483 and warning letter response.


Reviewer calibration: running a real calibration session

Finding #4 above, inconsistent reviewer standards, is the one most sites name as a known risk and least often actually fix. Naming a calibration session as the remedy is easy; running one that produces a real, documented result is a different exercise. The mechanics below turn the idea into something repeatable.

Cadence. A workable default is quarterly for an established team, plus an unscheduled session whenever a trigger appears: a new reviewer’s first 90 days, a rejection-rate or finding-rate that diverges noticeably between reviewers, or a significant change to the batch record format or review procedure.

Selecting records. Choose two or three representative executed batch records, spanning routine and more complex products. Where possible, use records with known, already-closed findings, so there is a defined answer set to score reviewers against rather than relying on group consensus alone to define “correct.”

Running the session, step by step:

  1. Each participating reviewer reviews the selected record independently, within the same time window, without discussing it with the others, and documents every finding they would raise exactly as they would in a real review.
  2. A facilitator (typically a QA lead not among the reviewers being calibrated) compiles a comparison matrix: for each known or emergent finding, which reviewers caught it, which missed it, and whether anyone raised something the others did not.
  3. The group reviews the divergences item by item. The discussion stays procedural, not personal: does the miss trace to an ambiguous instruction in the checklist, an outdated procedure, or a genuine gap in one reviewer’s technique?
  4. Document each reviewer’s individual catch rate and the group’s overall agreement rate for the session.
  5. Close the loop. A divergence traced to an ambiguous procedure gets a procedure or checklist fix under change control. A divergence traced to an individual gap gets targeted retraining, documented and dated. A calibration session that surfaces no divergence at all is not evidence of a healthy program; it is more often evidence that reviewers compared notes before submitting, which defeats the purpose.
  6. Record the session (participants, records used, matrix, catch rates, actions) and retain it as its own record, separate from the batch reviews themselves.

A worked example. Three reviewers independently review the same record, which carries four known findings seeded from a prior real investigation.

Known findingReviewer AReviewer BReviewer C
Missing second-check signature on step 12CaughtCaughtMissed
Granulation yield 9 percent loss, below the 5 percent action limit, unflagged in the recordCaughtMissedCaught
Deviation referenced in the comments with no deviation record on fileCaughtCaughtCaught
Audit trail gap: a 40-minute system-disabled windowMissedCaughtMissed
Individual catch rate3 of 4 (75%)3 of 4 (75%)2 of 4 (50%)

No single reviewer caught everything, and no single reviewer would have signed off missing all four; the value is in seeing where the misses cluster. Reviewer C’s two misses both trace to skipping the audit trail check this article recommends doing every time, a technique gap addressed with targeted coaching. Reviewer B’s miss traces to eyeballing the yield as “close enough” instead of checking it against the documented action limit, which points to a checklist gap: the review checklist did not force a lookup against the actual limit table, so the fix here is procedural, not personal, and applies to every reviewer, not just Reviewer B.

Acceptance criteria for a calibration program. A defined cadence exists and is followed; the records used are representative and, where feasible, carry known findings; every session is documented with individual and group results; every divergence is traced to a cause (procedure or technique) and closed with a recorded action; and the agreement rate is trended across sessions over time, not reported once and filed. A ready-to-use record for capturing this is the reviewer calibration session log.

What makes a batch record unreviewable

Some batch records cannot be reviewed in their current state. A batch record review procedure should define the criteria for returning a record for correction before the QA review clock starts. Examples:

  • Missing attribution on critical steps (no operator name or ID)
  • Missing second check on a critical step that requires one
  • Corrections made incorrectly (white-out, obliteration, illegible original)
  • Deviation referenced in the record but no deviation record exists
  • Unexplained blanks in required fields
  • Values outside specification with no deviation or explanation

Returning a record for correction before review prevents the review from being completed with known deficiencies, and it keeps cycle-time metrics honest, because the clock should not run while the record is being made reviewable. One caution: the act of returning a record is itself a quality event worth tracking. A particular product or line that generates unreviewable records repeatedly is telling you the master record, the training, or the form design needs work, not just that one operator had a bad shift.

Turning the list above into a gate a reviewer applies at intake, before spending time on the substantive review, keeps the decision consistent across reviewers:

A record that is returned and comes back with the same defect a second time is no longer a one-off correction, it is a signal about the process that produced it, and belongs in the trend, not just the log.

Track every return with the batch record return-for-correction log, and screen incoming records against the batch record completeness and review readiness checklist so the gate above is applied the same way every time, not reconstructed from memory by whoever is on shift.


Review by exception in automated manufacturing

In operations with complete automated data capture, reviewing every data point by hand is neither practical nor value-adding. Review by exception focuses reviewer attention on:

  • Parameters that approached or exceeded limits
  • Steps that took longer or shorter than expected
  • Alarms that fired during the batch
  • Manual interventions that overrode automated control
  • Deviations or in-process holds

This is a risk-based approach in the spirit of quality risk management under ICH Q9. It does not eliminate the review requirement; it restructures it. Two conditions have to hold for it to be defensible. First, the exception criteria must be defined procedurally and justified, so that what is screened out was screened out on purpose, not by accident. Second, the system that generates the exception report must be validated, because the report is now part of the control. If the report logic silently drops a class of exceptions, the reviewer will never see what they were supposed to catch, and the gap can persist across an entire campaign before anyone notices.

A practical test inspectors apply: ask to see the configuration that defines an exception, and ask what happens to a data point that is within limit but anomalous in shape (the flat-line sensor, the suspiciously perfect repeat). If review by exception is genuinely capturing risk, someone has thought about the data that is technically in-limit but still wrong. If it is just a way to read fewer pages, that thinking is missing and the finding writes itself.


Minimum compliant baseline

For a small organization in early manufacturing, the floor looks like this:

  1. Master batch record reviewed and approved before each batch
  2. Executed batch record captures all required fields per 21 CFR 211.188
  3. All deviations documented, root-caused, and impact-assessed before batch disposition
  4. QA review completed and documented before batch release, per 21 CFR 211.192
  5. Yield reconciliation calculated for each batch per 21 CFR 211.103, with an explanation of any significant variance
  6. Corrections in paper records made correctly: single line, initial, date, reason where required

Better maturity state

For a commercial-stage operation, the target moves from compliant to capable:

  • Electronic batch record with validated automated data capture and audit trail
  • A formal batch record review procedure with defined review criteria and realistic time standards, see the batch record review SOP
  • Review-by-exception capability with validated exception report generation
  • Batch record trend review: not just per-batch review but periodic trending of yield, deviations, and in-process excursions across the campaign, feeding the annual product review
  • An operator training program that teaches what makes a batch record entry attributable, contemporaneous, and accurate, not just how to fill in the fields
  • Batch record review metrics as a quality indicator: review cycle time, rejection rate, and deviation rate per batch, watched for drift over time rather than reported once and filed, in line with quality metrics and KPIs

The difference between the two states is not mainly technology. It is whether review is treated as a one-record-at-a-time gate or as a system that learns from its own output and gets tighter over time.


Batch record review cycle time: what good looks like

Cycle time is one of the metrics named in the maturity state above; it deserves a sharper treatment than a bullet point, because a poorly defined cycle-time metric can look healthy while hiding exactly the problem it is supposed to catch. The general discipline of trending quality metrics, choosing median over mean, tracking aging distributions, avoiding a mean-only report that a stuck tail skews, is covered in full in quality metrics and KPIs. This section applies that discipline specifically to batch record review.

Define the start and stop points precisely, in the procedure, not by convention. A common weakness is starting the clock at “batch completed manufacturing” rather than “record marked complete and reviewable,” which conflates review time with in-process hold time or the time spent making a record reviewable in the first place. Start the clock when the record passes the unreviewable-criteria screen above and reaches the QA reviewer’s queue; stop it when the review is complete and the record is forwarded toward disposition. Report the unit (business days or calendar days) explicitly.

A worked example. Ten consecutive batches for one product, review cycle time in business days from queue entry to review complete:

BatchCycle time (business days)
12
22
33
43
54
62
73
89
93
102

Mean: 3.3 business days. Median: 3 business days. Percent within a 3-business-day internal target: 8 of 10, or 80 percent. The mean alone looks unremarkable, 3.3 days against a 3-day target reads as close enough. The median and the percent-within-target tell a more accurate story: one batch (batch 8) took three times the target, and investigating why matters more than the average. In this example the root cause was not a slow reviewer; batch 8 sat waiting on a deviation-impact assessment from another function for six of its nine days, meaning the review itself was fast but the record was not actually reviewable-and-complete for most of that window, a signal to fix upstream, not to pressure the reviewer.

Acceptance criteria for a defensible cycle-time metric:

  • The start and stop points are defined in the procedure and applied consistently, not left to convention or memory.
  • Both the median and the percent within target are reported; the mean alone is not sufficient, because a single stuck record can make an unhealthy process look acceptable on average.
  • Outlier batches are individually investigated for root cause rather than averaged away; an aging batch is a signal, not noise.
  • Cycle time is trended over rolling periods and watched alongside the finding rate, not reported as a single snapshot. A cycle time that is falling while the finding rate is also falling is the rubber-stamp pattern (failure #1 above) wearing a metrics-friendly disguise; a genuine improvement shows a stable or rising finding rate at a faster cycle time, which means the same rigor is being applied faster, not that less is being checked.

Interview questions on batch record review

These come up for QA reviewer, QA disposition, and quality manager roles, and they separate people who have done the work from people who have read about it. Short, concrete answers win.

“What is the difference between the master batch record and the executed batch record?” The master defines what should happen and is a controlled, pre-approved document changed only through change control. The executed record documents what actually happened for one specific batch. The two must agree, and any difference is either an approved deviation or a data integrity problem.

“Which regulations govern batch record review?” In the US, 21 CFR 211.188 requires the batch record, 211.186 the master record, 211.192 the production record review by the quality unit before release, and 211.103 yield reconciliation. Disposition authority sits with the quality unit under 211.22. In the EU, the documentation requirements are in EU GMP Chapter 4 and QP certification in Annex 16. ICH Q7 Sections 6.5 and 6.7 cover the same ground for APIs.

“A batch has zero deviations. Is that good?” Not necessarily. For a simple, well-controlled step it can be fine. For a complex batch it is a flag, because real processes generate minor, no-impact deviations and their total absence often means the team is not documenting them, which is a data integrity concern. I would check the deviation threshold and the trend across recent batches.

“How do you review an electronic batch record differently from a paper one?” Less weight on legibility and arithmetic, which the system handles, and more on the audit trail and on whether the configured limits were correct for this product and batch. I look for post-completion changes, changes by users not involved in the batch, manual overrides of automated controls, and gaps in automated capture. Wrong configuration is the dangerous failure because the system then enforces the wrong thing on every batch consistently.

“You find a value out of specification with no deviation. What do you do?” The record is not reviewable as is. I return it or initiate the deviation and the investigation, depending on procedure. The batch is not dispositioned until the investigation is complete, because 211.192 requires any unexplained discrepancy to be investigated before release.

“Walk me through how you actually review a record.” Frame the batch and confirm the master version, then deviations first, then material accountability, then yield reconciliation, then in-process data in time order against the historian, then attribution and second checks, then the testing package and Certificate of Analysis, then document what I found and how it closed. Deviations and materials come first because they are most likely to stop the batch.

“What is review by exception and when is it acceptable?” Focusing reviewer attention on exceptions (limit excursions, alarms, manual interventions, long or short steps) rather than every data point. It is acceptable only when the exception criteria are defined and justified procedurally and the exception report itself is validated, because the report is now part of the control. It restructures the review, it does not remove the requirement.

“How would you know if your review program is weak?” Rising post-release corrections, very short review times with no findings, inconsistent outcomes between reviewers on similar records, and a deviation rate that does not match process complexity. I would run reviewer calibration sessions and trend the metrics rather than treat each record in isolation.

“How do you run a reviewer calibration session?” Pick a few representative executed batch records, ideally with known, already-closed findings so there is a defined answer set. Each reviewer reviews independently, without comparing notes first, and documents every finding they would raise. Then compile a matrix of who caught what, discuss every divergence to find whether it traces to an ambiguous procedure or a genuine gap in one reviewer’s technique, and close the loop with a procedure fix or targeted retraining. A calibration session that never finds a divergence usually means people compared notes before they should have, not that the team is perfectly aligned.

“What changes in the batch record for a combination product like an autoinjector?” The drug-side content, formulation, fill, in-process assay, does not change. The record adds device-side content: component release for the mechanical parts, assembly and torque steps, functional tests like activation force and delivered-dose accuracy, and container closure integrity performed at the final assembled configuration, not just the vial alone. I apply the same attribution, second-check, and deviation standards to those device pages as to the drug pages; treating the assembly section as a lighter check because the vocabulary is less familiar is the common miss.

“How does batch record review change under continuous manufacturing?” There is often no single vessel-full batch; the unit reviewed is a time- or quantity-defined run. Review shifts from confirming discrete steps happened in sequence to confirming the process held a defined state of control for the whole run, that any excursion was diverted using a traceable, validated residence-time boundary rather than an estimate, and that any real-time-release model substituting for end-product testing was in its qualified, in-control state during that run. Applying a fixed-batch checklist unchanged to a continuous run is the failure mode I watch for.

“How would you define a defensible batch record review cycle-time metric?” Fix the start and stop points in the procedure, record marked reviewable to review complete, not manufacturing complete to disposition, so review time is not conflated with something upstream of it. Report the median and the percent within target, not just the mean, because one stuck batch can hide inside an average. Investigate outliers individually rather than averaging them away, and watch cycle time next to the finding rate together, because a faster review paired with a falling finding rate is a rubber-stamp risk, not an improvement.

More questions across the quality function are collected in GxP quality interview preparation.


Practical tips

  • Read the deviations and the material accountability first. They stop more batches than anything else, and finding the stop early saves the rest of the review.
  • Keep a one-page reviewer aid taped to the desk: the ALCOA+ attributes, the performer-verifier rule, and the unreviewable criteria. Consistency between reviewers is a real data integrity control.
  • Trend your own findings. If the same field is wrong across many batches, fix the form or the training, do not keep catching it one record at a time.
  • Treat a suspiciously perfect number with the same suspicion as an out-of-limit one. Both are abnormal.
  • In an electronic shop, open the audit trail every time. It is the part of the record paper review never had, and it is where the interesting failures hide.
  • Document the review so it stands alone. The QP or disposition authority, and an inspector a year later, should see what you checked and how each finding closed without asking you.
  • Run the calibration session even when nobody is asking for it. Waiting for an inspector or an audit to surface reviewer inconsistency means finding out the hard way, on a record that already shipped.
  • On a combination product, budget real attention for the device-side pages, not just the drug-side ones. The same rigor on unfamiliar vocabulary is still the same rigor.

References

  • 21 CFR 211.22, Responsibilities of quality control unit
  • 21 CFR 211.100 and 211.103, Written procedures; deviations; and yield calculation
  • 21 CFR 211.186, Master production and control records
  • 21 CFR 211.188, Batch production and control records
  • 21 CFR 211.192, Production record review
  • 21 CFR 211.68, Automatic, mechanical, and electronic equipment
  • 21 CFR Part 11, Electronic Records; Electronic Signatures
  • EU GMP Volume 4, Chapter 4, Documentation
  • EU GMP Volume 4, Annex 11, Computerised Systems
  • EU GMP Volume 4, Annex 16, Certification by a Qualified Person and Batch Release
  • EU GMP Volume 4, Annex 17, Real Time Release Testing and Parametric Release
  • ICH Q7, Good Manufacturing Practice Guide for Active Pharmaceutical Ingredients (Sections 6.5, 6.7)
  • ICH Q13, Continuous Manufacturing of Drug Substances and Drug Products (finalized by the ICH Assembly November 2022, adopted by FDA as final guidance March 2023)
  • 21 CFR Part 4, Regulation of Combination Products
  • FDA Guidance: Data Integrity and Compliance With Drug CGMP, Questions and Answers (December 2018)
  • ICH Q9(R1), Quality Risk Management
  • ICH Q10, Pharmaceutical Quality System
Use madhadi.com as an app Full screen, works offline, one tap from your home screen.