Operating in global pharmaceutical and medical device markets means managing regulatory relationships with several agencies at once. The US FDA, the EMA (acting on behalf of EU member state authorities), the UK MHRA (separate since Brexit), Japan’s PMDA, Health Canada, Australia’s TGA, and other competent authorities all inspect manufacturing facilities, and they do not all do it the same way. A site that ships product into multiple regions can expect to host two or three different inspecting bodies over a typical certification cycle, each with its own legal basis, its own notice conventions, and its own way of writing up what it finds.
The two frameworks that set the tone for everyone else are FDA and EU GMP. Understand how those two operate, and most of the rest of the world becomes readable by analogy. The differences are not cosmetic. They change how you prepare, what evidence you stage, who needs to be in the room, and how you respond when an observation lands. This article walks through the structural and procedural differences, gives you the roles and the step-by-step plays for each, then turns to the practical question every multi-site compliance leader eventually faces: how do you run one program that satisfies both.
This is written to apply across drug, biologic, and device manufacturing. The device world runs on its own inspection model (FDA’s QSIT was retired on 2 February 2026 when QMSR took effect, and device inspections now follow the QMSR-era Compliance Program 7382.850, alongside the MDSAP audit scheme), and those are noted where they diverge from the GMP picture.
Structural Differences
FDA. The FDA is a single federal agency. Its field investigators are employed by FDA and, following the 2017 program alignment reorganization and the renaming of the Office of Regulatory Affairs (ORA) into the Office of Inspections and Investigations (OII) effective 1 October 2024, report through the OII field structure (formerly ORA) on a commodity and program-aligned basis rather than through the old geographic districts, while specialist drug investigators sit within CDER’s Office of Pharmaceutical Quality and its Office of Pharmaceutical Manufacturing Assessment, with biologics handled by CBER and devices by CDRH. Whatever the org chart, an FDA inspection is conducted by FDA employees exercising statutory authority under the Federal Food, Drug, and Cosmetic Act.
The person at your site is technically called an Investigator, not an Inspector, and FDA takes the distinction seriously: the role is investigative, not merely a checklist walk. Under 21 USC 374, that investigator has the legal authority to inspect any facility involved in manufacturing, processing, packing, or holding of drug products. They may request access to any area, any record, any system, and any personnel they judge relevant. Refusing reasonable access is itself a basis for enforcement, and a refusal can render a drug adulterated under section 501(j) of the Act.
EMA and EU member states. EMA is a coordinating body, not an inspecting one. Inspections inside the EU are carried out by national competent authorities: ANSM in France, the relevant authority in Germany, AIFA in Italy, AEMPS in Spain, and so on across the member states. EMA coordinates inspections tied to centrally authorized products, organizes inspections of third-country (non-EU) sites that supply the EU market, and runs the mutual-recognition machinery that lets one authority’s findings count for another. But the people who walk your floor work for a national agency, not for EMA.
This matters because the legal instrument behind an EU GMP inspection is EU law transposed into national law. For human medicines the GMP requirements sit in Directive 2001/83/EC (Title IV) and Commission Directive (EU) 2017/1572, with the detailed guidance in EudraLex Volume 4, including its Annexes; the parallel framework for investigational medicinal products is Commission Delegated Regulation (EU) 2017/1569 and Annex 13. The inspector applies a harmonized EU standard, but their warrant comes from their own member state.
Practical implications. An FDA investigator carries broad unilateral authority. A single individual can access nearly anything, interview personnel, and decide independently to take physical samples. EU inspections more often run as a team with defined roles, a circulated inspection plan, and a designated lead who manages the agenda. The team format tends to produce clearer real-time signaling about what is under review, which can make the days more predictable for the host site even when the scrutiny is just as deep.
Why this distinction is load-bearing. It tells you who you are persuading. With FDA you are managing one person’s judgment across the whole visit, and consistency in how your subject matter experts answer that one investigator matters enormously. With an EU team you are managing several specialists at once, often in parallel rooms, which raises the bar on coordination but lowers the risk that a single bad interaction colors the entire inspection.
Pre-Inspection Notification
FDA. For domestic manufacturers, FDA is not required to give advance notice of a routine surveillance inspection. In practice most arrive during business hours, and a site may get an informal call, but the agency reserves the right to show up unannounced and does so, particularly when it has a concern. For foreign manufacturers, FDA generally gives advance notice of several weeks, coordinated through its in-country offices and diplomatic channels, because logistics and visas demand it. Pre-approval inspections tied to a pending application are scheduled, but the lead time can be short and the exact date can move.
EU. EU inspections are usually scheduled with at least a few weeks of notice, and the lead inspector often shares an inspection plan beforehand: which product lines, which systems, which records will be in scope. For-cause inspections are the exception and can arrive unannounced. The advance plan does not soften the inspection; it makes the approach more structured and, in the host’s experience, more collaborative.
Strategic implication. The possibility of an unannounced FDA visit means a US-facing site has to live in a permanent state of readiness rather than ramping up for a known date. EU sites get more runway, and the temptation is to use that runway to fix problems just before the team arrives. That is a trap. A site that only looks ready when it knows someone is coming is not actually in control of its quality system, and an experienced inspector reads the difference quickly. The discipline of ongoing inspection readiness is what holds up under either notice model.
What to do with the notice window. When you do get advance notice, the work is not last-minute remediation, it is staging. The procedure that holds up:
- Confirm scope from the inspection plan or the application under review, and map it to your document inventory.
- Stand up the front room and back room, and confirm the host, scribe, and runner roster.
- Pull and pressure-test the documents most likely to be requested (batch records for in-scope products, recent deviations and CAPAs, validation summaries, audit trail review records, training records for named operators).
- Run a focused readiness review or mock inspection on the in-scope systems, not the whole site.
- Brief management on the likely themes and the agreed messaging.
If that staging surfaces a real gap you cannot close before the visit, the correct move is to open a deviation or CAPA and be ready to show the inspector you found it yourself, not to paper over it. Self-identification ahead of an inspection is a credibility asset; a fresh, panicked fix the week before is a red flag.
Investigator Authority and Scope
FDA. FDA investigators can compel access to records under the predicate rules, including the requirement in 21 CFR 211.180 that records be retained and available, and they can physically enter all areas of a facility. They cannot compel attorney-client privileged communications, and for drug and biologic GMP they generally do not demand internal audit reports or supplier audit findings as a matter of routine policy (the records exemption reflected in CPG 130.300), though they will note whether an audit program exists and functions. That carve-out is narrower for devices: under QMSR, effective 2 February 2026, FDA removed the 21 CFR 820.180(c) exemption, so internal audit reports, supplier audit reports, and management review records are now subject to inspection at device facilities. They can collect samples of product, raw materials, and environmental swabs and send them to FDA laboratories. They may interview personnel, and an employee can choose to speak with them without a manager present.
An FDA investigator who suspects a data integrity problem can ask to sit at a workstation and drive the system directly: pull up the chromatography data system audit trail, open the LIMS sequence log, read the manufacturing execution system batch history. They do not need a host to operate the system for them, although a knowledgeable host should still be present. That direct-access capability is the single biggest reason FDA’s ability to find data integrity problems has outrun the old paper-record style of inspection.
EU. National competent authority inspectors hold comparable rights of access under EU and national law, and they will also collect samples and interview staff. The historical difference was method rather than authority: EU inspections leaned toward a structured, sample-based document review, while FDA pushed harder and earlier into live forensic data examination. That gap has closed substantially. EU inspectorates have shared data integrity inspection methodology across member states, and the MHRA’s 2018 guidance on GxP data integrity has been influential well beyond the UK. Today, expect either body to ask to open an audit trail.
The audit-report question, handled correctly. Two records are routinely confused in the front room. The first is the internal audit report and the supplier audit report. For drug and biologic GMP, FDA’s longstanding position (reflected in CPG 130.300 on its policy for routine inspections) is that it will not normally ask to review the findings of internal audits or supplier audits, and you can decline to hand them over while confirming the program exists and showing the schedule and the closure metrics. EU inspectors take a similar line for medicines. Note this is a drug and biologic GMP policy: for devices under QMSR, the 820.180(c) exemption was removed effective 2 February 2026, so audit and management review records are now in scope. The second is everything else (deviations, CAPAs, complaints, validation, training, batch records), which is squarely in scope and which you do not get to withhold. Train the host to know the difference cold, because nothing erodes trust faster than reflexively refusing a record the inspector is fully entitled to see.
What good front-room control looks like.
- One designated host speaks; subject matter experts are called in for their topic and then leave.
- Every request is logged, timed, fulfilled by a runner, and tracked to closure on a request log.
- Documents are reviewed in the back room before they go to the front room, so the host is never surprised by what the inspector reads.
- No volunteering. Answer the question asked, accurately and completely, then stop.
FDA’s Data Integrity Inspection Technique
FDA built its data integrity methodology in earnest after the surge of warning letters issued during roughly 2013 to 2017, many of them to generic and API manufacturers in India and China. The techniques are worth understanding in detail, because they are now standard and because EU inspectors are using the same logic. For the underlying principles these techniques test against, see ALCOA+ data integrity principles and audit trail design and review.
Direct system access. Investigators routinely ask to operate the chromatography data system themselves. They navigate to the full instrument acquisition history, the complete record of every injection run on the instrument, not just the injections that appear in the reported sequence. They compare that history against the LIMS record and the batch record and look for injections that exist on the instrument but are absent from the official record. These are often called trial or test injections, and a pattern of unreported injections that quietly precede a passing reported result is a classic finding.
Audit trail review. Investigators know where audit trails live in the common platforms and how to export them. They know the difference between an audit trail that was disabled, one that was enabled but configured to capture too little, and one that captures everything. They know which administrative settings control what is logged and who can change those settings.
User and access-log comparison. Investigators cross-check the system user log (who logged in and when) against the batch record (who performed the test and when), against training records (was that person qualified on the method), and against instrument qualification status (was the instrument qualified on that date). A break in any link becomes an investigative thread.
Metadata examination. The raw acquisition and sequence files in most platforms carry metadata: creation date, modification dates, the application user who created them, and sometimes the operating-system account. That metadata can contradict the official narrative, for example a sequence whose file timestamp predates the day the batch record says testing began.
Cross-database reconciliation. Where a site runs separate LIMS and CDS, investigators compare results across both. A value present in the CDS but missing from the LIMS, or a number that differs between the two, is a discrepancy that drives deeper digging. The same logic extends to manufacturing data; see MES, EBR and SCADA data integrity.
A short worked example shows how these threads converge. An investigator opens the CDS instrument history for an assay batch and sees an injection of the same sample timestamped two hours before the reported sequence, run under a generic shared login, with the result file later deleted or renamed. The batch record shows a single passing run by a named analyst. The user log shows that analyst was not logged in at the time of the earlier injection. The audit trail for result deletion is found to have been disabled at the system level. No single one of those facts is conclusive, but together they describe testing into compliance, and they will anchor an observation, very likely a warning letter, and possibly a data integrity remediation expectation. The structure of that response is covered in data integrity remediation programs and 483 and warning letter response strategy.
The self-defense version of the same technique. The point of laying out the inspector’s method is so you run it on yourself first. A standing data integrity self-check should reproduce each move above against your own systems on a sampling basis:
| Inspector move | Your equivalent self-check | Evidence you keep |
|---|---|---|
| Open CDS instrument history | Periodic review of total injections vs reported injections per instrument | Reviewer-signed log with sample count and any exceptions |
| Read audit trail config | Verify audit trail enabled and capturing required fields after each upgrade and on a schedule | Configuration verification record |
| Compare user log to batch record | Spot-check named operator vs login times on selected batches | Self-audit checklist entries |
| Check for shared/generic logins | Confirm unique IDs, no shared accounts, admin rights segregated from analysts | Access review record |
| Examine file metadata | Confirm system clock is controlled and synchronized | Clock control evidence, see below |
If you can show an inspector that you already look for trial injections and disabled audit trails, the conversation shifts from “did you know” to “you knew and you control it,” which is exactly where you want to be. Build that habit into your internal audit program and your audit trail review routine, and tie it to system clock control.
EU’s Approach: Risk-Based Inspections
EU inspections are coordinated through EMA’s GMP and GDP inspectors working group and are increasingly scheduled on risk. Higher-risk operations (sterile products, biologics, high-potency or cytotoxic compounds, cell and gene therapies), sites with a poor inspection history, and products on an active approval track draw more frequent and more intensive attention. The same risk thinking that drives quality risk management under ICH Q9 drives the inspection calendar.
EU inspection types.
Routine surveillance. Scheduled on product risk and time since the last inspection, commonly on the order of every two to three years for a standard GMP manufacturer, longer where risk and history justify it.
Pre-authorisation inspection. Conducted for a product seeking EU marketing authorisation before the authorisation is granted. This is the EU counterpart to FDA’s pre-approval inspection.
For-cause inspection. Triggered by a specific quality signal: a serious complaint, a recall, a quality defect report, or intelligence from another authority. Often unannounced.
Follow-up inspection. Conducted after an inspection that found significant deficiencies, to verify that the remediation actually took hold.
Outcomes flow into the EudraGMDP database. A satisfactory inspection of an EU site yields a GMP certificate; a satisfactory third-country inspection yields the same, which is what allows a non-EU site to supply the EU market. That public certificate record is something FDA has no direct equivalent of, and it is one of the first things a customer or partner checks when qualifying a supplier; see supplier and vendor qualification.
One more EU-specific feature: the Qualified Person. EU GMP requires a named Qualified Person (QP) to certify each batch before release, a legal role with personal accountability that has no direct FDA equivalent. An EU inspector will look at the QP’s certification records, the QP’s access to the information needed to certify, and whether the QP was placed under pressure to release questionable batches. If your network supplies the EU, the QP is part of your inspection story whether or not the inspection is happening in the EU. See Qualified Person batch release under Annex 16.
Deficiency Classification
This is one of the sharpest practical differences between the two systems.
FDA. The inspection product is the Form FDA 483, a list of inspectional observations handed over at the close-out meeting, followed in some cases by a Warning Letter issued after the agency reviews the Establishment Inspection Report. FDA does not publicly grade 483 observations as critical, major, or minor. Investigators use internal severity language, and the order and wording of observations signals weight, but there is no formal published classification on the 483 itself. An observation is listed because the investigator believes it represents a deviation from the regulations.
EU. EU inspections classify each deficiency as Critical, Major, or Minor in inspection reporting (PIC/S guidance PI 040 formally uses Critical, Major, and Other, with the third category commonly reported as Minor in EU practice). In broad terms, a critical finding is one that has caused or could cause real patient harm, or that involves data falsification or fraud; a major finding is a serious GMP shortfall that falls short of critical, or a significant breakdown in following procedures; and a minor finding is a lesser gap that does not on its own put patients at risk. The classification drives the consequence: a single critical, or a stack of majors, can hold up a GMP certificate.
Knowing the grading logic helps you read your own findings the way an inspector will. A worked classification example, using the same set of facts seen three ways:
| Observed fact | Likely EU classification | Why |
|---|---|---|
| Audit trail disabled on the release-testing CDS, and a deleted failing result is found | Critical | Falsification/data manipulation risk that directly touches batch disposition |
| Audit trail review procedure exists but is not consistently performed across instruments | Major | Substantial GMP departure that could lead to undetected manipulation, but no patient harm shown yet |
| Audit trail review is performed but the review record does not always capture the reviewer’s signature date | Minor | A documentation gap that does not present a patient risk on its own |
The same three facts on an FDA 483 would appear as observations without a printed grade, but the investigator’s internal weighting tracks the same logic, and the first one is the kind that escalates to a Warning Letter. For how grading drives your response prioritization, see audit finding classification and quality event classification and triage.
The table below summarizes the two systems side by side.
| Dimension | FDA | EU (national competent authorities, EMA-coordinated) |
|---|---|---|
| Inspecting body | Single federal agency (FDA) | National authority of the member state; EMA coordinates |
| Legal basis | FD&C Act; 21 CFR Parts 210/211, 600s, 820/QMSR; 21 USC 374 | Directive 2001/83/EC (Title IV); Commission Directive (EU) 2017/1572; EudraLex Vol. 4 and Annexes |
| Domestic notice | Often none for routine surveillance | Usually several weeks, with a shared plan |
| Inspection format | Frequently one investigator, broad authority | Often a team with defined roles |
| Deficiency grading | No public critical/major/minor on the 483 | Formal Critical / Major / Minor in EU inspection reporting (PIC/S PI 040: Critical / Major / Other) |
| Primary written outcome | Form 483; Warning Letter after review | Inspection report; GMP certificate or non-compliance |
| Public visibility | 483 via FOIA; Warning Letters posted on fda.gov | GMP certificates and non-compliance in EudraGMDP |
| Severe enforcement | Import alert, injunction, seizure, consent decree | Suspension/withdrawal of GMP certificate, MA action |
| Batch release role | Quality unit disposition; no statutory QP | Named Qualified Person certifies every batch |
Inspection Roles and Responsibilities
Both models reward the same internal discipline, a clear team with no overlapping speech. Set these roles before any inspection, name backups for each, and rehearse them.
| Role | Owns | Key behaviors |
|---|---|---|
| Inspection lead / host | The room. The agenda, the request log, the relationship with the inspector | Speaks for the site, manages pace, calls SMEs in and out, never volunteers, escalates anything sensitive |
| Back-room manager | Document staging and review before anything reaches the front room | Runs the request queue, QC’s every document for completeness and accuracy, flags risks to the host |
| Scribe | The contemporaneous record of what was asked, shown, said, and observed | Captures every request and response verbatim enough to reconstruct the day; feeds the response team |
| Runner | Physical or electronic retrieval of requested records | Fast, accurate, confirms the right version and revision before delivery |
| Subject matter experts | Their specific system or process | Answer only their topic, factually, then leave; no speculation, no opinions about other areas |
| Quality leadership | Decisions, commitments, escalations | Present at open and close, makes any commitment that binds the company, handles classification disputes |
| QP (EU-facing sites) | Batch certification narrative | Explains release decisions and the information relied on |
| Regulatory affairs | Application context for pre-approval/pre-authorisation visits | Connects the site story to the dossier under review |
The single most common organizational failure is letting an unprepared SME free-associate in front of the inspector. The host’s job is to prevent exactly that.
Warning Letters vs. EU Statements of Non-Compliance
FDA Warning Letter. A Warning Letter is a public document posted on fda.gov. It calls for a written response, conventionally within 15 working days, that addresses each cited matter and any subsequent agency requests. A non-response or an inadequate response can escalate to an import alert, an injunction, product seizure, or a consent decree. For foreign sites, an import alert (often under the detention-without-physical-examination mechanism) may be issued in parallel with or shortly after the letter, which can stop product at the US border independent of the letter itself. The reading of warning-letter trends is a useful intelligence input; see FDA warning letter patterns.
The 483 response is the document that decides if a Warning Letter follows. The 483 itself is not a Warning Letter; it is the observation list. Your written response, conventionally within 15 working days of the 483, is what the agency weighs when deciding whether to escalate. A strong response addresses each observation with: the immediate correction already taken, the root cause, the systemic corrective and preventive action, the verification of effectiveness, and the dates. It commits to what you can actually deliver and never promises what you cannot. The full method is in FDA 483 response strategy and 483 and warning letter response strategy.
EU Statement of Non-Compliance. The EU equivalent for the most serious outcomes is a statement of non-compliance with GMP, entered in EudraGMDP. It can trigger suspension or withdrawal of the site’s GMP certificate. Other authorities may then act on marketing authorisations for products made at that site, up to suspension or recall. A non-compliance statement is less publicly prominent than an FDA Warning Letter in the trade press, but its regulatory bite is at least equal: losing a GMP certificate can stop EU supply outright.
A useful mental model: FDA enforcement is more visible and more litigation-shaped, with public letters and court-enforceable remedies. EU enforcement is more administrative and certificate-shaped, working through the document that grants your right to supply. The remediation work behind both looks similar and is anchored in a strong CAPA system.
Acceptance criteria for a response that holds. Across either system, a response is “good” when each finding has a stated root cause that actually explains the failure (not “human error” full stop), corrections that are already in place with evidence, systemic CAPA that extends beyond the cited instance, an effectiveness check with a defined metric and date, and a network-wide assessment so the same gap is not still open at a sister site. See root cause analysis techniques, CAPA effectiveness verification, and human error in deviations.
Mutual Recognition and Reciprocity
The FDA and the EU operate a mutual recognition agreement covering GMP inspections of human medicines. The amended sectoral annex on GMP took effect progressively from 2017, with FDA’s capability assessment of the individual EU member state authorities completed in 2019 and the program then operational for routine inspections. Where it applies, each side can rely on the other’s inspection of a manufacturer rather than sending its own team.
In practice, if a site was recently inspected by FDA with acceptable outcomes, an EU authority may waive its own routine inspection and rely on the FDA report, and vice versa. The point is to remove duplicate inspections of low-risk, well-performing sites and let both agencies aim their finite resources at higher-risk facilities.
The agreement does not cover everything. Certain product categories sit outside its scope, including some biologics and human blood and plasma products, and vaccines and plasma-derived products have been handled with caveats and phased treatment. Cell and gene therapy products, investigational products, and for-cause situations are commonly still inspected independently by both bodies. So reliance is real but partial, and a compliance leader should never assume an MRA removes the possibility of either agency arriving in person.
The device parallel: MDSAP. Devices have their own reliance scheme, the Medical Device Single Audit Program, under which a single audit by an authorized auditing organization can satisfy the requirements of multiple participating regulators (US, Canada, Brazil, Australia, Japan). It is conceptually the device-world answer to the same problem the GMP MRA solves: cut duplicate audits of sound sites. If your network includes device manufacturing, understand which scheme governs which facility, and how the medical device quality system under QMSR and the EU MDR/IVDR framework apply to those sites.
Managing a Multi-Agency Inspection Program
For a company with sites under both FDA and EU oversight, the operating model that holds up is one program, built to the higher bar, applied everywhere.
Harmonize the quality system to the stricter requirement. FDA and EU GMP share the same foundations but diverge in specifics, for example the EU requirement for a Qualified Person to certify each batch before release, which has no direct FDA counterpart. Where requirements differ, design to the more stringent one and run a single pharmaceutical quality system rather than parallel systems that drift apart and confuse staff.
One quality standard across sites. The strongest posture is to run every site at the standard expected by the most demanding authority likely to inspect it. Maintaining a lower bar for sites that “only” face one agency invites inconsistency, and inconsistency is exactly what an investigator probes when comparing your network.
Build computerized systems to satisfy both predicate rules. FDA’s 21 CFR Part 11 and the EU’s EudraLex Annex 11 are functionally close on most points: validation, audit trails, access control, electronic signatures, and data retention. Build to both at once. A practical mapping of the two is covered in 21 CFR Part 11 and EU Annex 11 and in the Part 11 and Annex 11 practical guide. Ground the data layer itself in a clear data governance framework.
Run inspection intelligence on both agencies. FDA’s 483s (obtainable through FOIA) and its posted Warning Letters tell you exactly what investigators are pressing on. EU inspection summaries, EudraGMDP entries, and member state guidance do the same for the EU side. Read both, and feed the themes back into your internal audit program so your own audits find the issue before an inspector does. The mechanics of running that signal feed are in regulatory intelligence and 483 trends.
Keep post-inspection responses globally consistent. A CAPA written to close an FDA 483 observation almost always has EU relevance too, and vice versa. Apply the remediation across the network, not just at the site that was cited. Inconsistent remediation, where the named site fixes a problem that persists everywhere else, is a finding waiting to happen at the next stop.
A simple readiness practice ties this together: maintain a single inspection management procedure that works under either notice model, a single front-room and back-room workflow, a trained host and scribe pool, and a standing data integrity self-check that mirrors the techniques described above. Detail on building that capability sits in FDA inspection readiness and the broader inspection readiness program guidance. The discipline of running a live inspection day, regardless of agency, is covered in managing a live inspection.
Common Mistakes and Inspection-Finding Patterns
These are the recurring failures, written generically. None of them are about which agency is in the building; all of them appear under both.
- Treating an EU notice window as time to fix, not stage. Last-minute remediation reads as loss of control. Stage evidence; do not invent fixes.
- Letting an unprepared SME talk past the question. Volunteered information opens threads the inspector had not planned to pull.
- Refusing a record you are required to produce. Confusing in-scope records (deviations, CAPAs, batch records) with the limited set you may withhold (internal and supplier audit reports) destroys credibility fast.
- Shared or generic logins on GxP systems. The single most common data integrity root cause, and it breaks the entire who-did-what chain the inspector reconstructs.
- Audit trails enabled but never reviewed. Having the trail is necessary but not sufficient; the absence of a review record is itself a finding.
- Disabled or under-configured audit trails on release-critical systems. This is the one that becomes a critical deficiency and a Warning Letter.
- System clocks uncontrolled. Editable timestamps undercut the integrity of every dated record on the system.
- Site-only remediation. Closing a finding at the cited site while the same gap stays open across the network. The next inspection finds it.
- Root cause stated as “human error” with no system explanation. Inspectors read this as a failure to actually investigate.
- Promising more than you can deliver in the response. A missed commitment date in a CAPA is a worse position than a realistic, slightly longer one.
Interview-Ready: Questions and How to Answer
These come up in compliance, quality systems, and inspection-readiness interviews, and inspectors ask versions of them in the room.
“What is the practical difference between an FDA investigator and an EU inspector’s authority?” FDA investigators are federal employees with broad unilateral authority under 21 USC 374; one person can access nearly any area, record, or system and take samples independently. EU inspections are run by national competent authorities, usually as a team with a lead and a shared plan, applying a harmonized EU standard but acting under their own member state’s law. EMA coordinates but does not itself inspect.
“How do FDA and the EU classify deficiencies differently, and why does it matter?” FDA does not print a critical/major/minor grade on the 483; the investigator’s internal weighting and the order of observations carry the signal, and escalation to a Warning Letter is the real measure. The EU formally grades each deficiency Critical, Major, or Minor in inspection reporting (the PIC/S PI 040 categories are Critical, Major, and Other), and the grade drives the consequence: a single critical or a stack of majors can suspend a GMP certificate.
“What is the EU equivalent of a Warning Letter?” A statement of non-compliance with GMP, entered into EudraGMDP, which can suspend or withdraw the site’s GMP certificate and trigger marketing authorisation actions. It is less visible in the trade press than a public FDA Warning Letter but its regulatory bite is at least equal, because losing the GMP certificate can stop EU supply outright.
“Walk me through how an inspector finds testing into compliance.” They open the CDS instrument history, see the full set of injections, and compare it against the reported sequence, the LIMS, and the batch record. Unreported trial injections before a passing result, run under a shared login, with the failing file deleted, plus a disabled deletion audit trail, plus a user log that contradicts the named analyst, together describe manipulation. I would prevent it by enforcing unique logins, locking audit trail configuration, and reviewing total versus reported injections as a routine self-check.
“What does the MRA between FDA and the EU actually do, and what are its limits?” It lets each side rely on the other’s GMP inspection of a human-medicines manufacturer rather than duplicating it, operational for routine inspections after FDA’s member-state capability assessments completed in 2019. It does not cover everything; some biologics, blood and plasma products, vaccines with caveats, investigational products, cell and gene therapies, and for-cause situations are still inspected independently. So I never assume an MRA removes the chance of either agency arriving.
“Your site is FDA-only today but the company is filing for an EU authorisation. What changes?” The big additions are the Qualified Person batch certification role with personal accountability, EudraLex Annex 11 expectations layered on Part 11, the PIC/S deficiency grading mindset, and a pre-authorisation inspection. The right move is to harmonize the quality system to the stricter requirement now, build computerized systems to satisfy both predicate rules, and run a mock inspection in the EU style before the real one.
“How do you keep one program satisfying both agencies without doubling the work?” One quality system built to the higher bar, one inspection management procedure that works announced or unannounced, computerized systems validated to both Part 11 and Annex 11, network-wide CAPA so a fix at one site closes the gap everywhere, and an inspection-intelligence feed reading both FDA 483s/Warning Letters and EudraGMDP/member-state guidance into the internal audit plan.
Practical Tips and Cross-Links
- Keep one inspection management SOP that is agency-agnostic and notice-agnostic. Do not maintain separate FDA and EU playbooks that drift apart.
- Rehearse the host and scribe roles, not just the SOP. The day is won in behavior, not paperwork.
- Maintain a live request log template and a back-room QC step so no document reaches the front room unreviewed.
- Run the inspector’s data integrity moves on yourself quarterly. Reading ALCOA+ in detail tells you what they are testing against.
- Treat EU notice windows as staging time, never as remediation time.
- Read both FDA Warning Letters and EudraGMDP non-compliance entries as a standing intelligence feed, and route the themes to internal audit.
- For the response that follows any finding, anchor on a real root cause, network-wide CAPA, and an effectiveness check, see what is a CAPA and CAPA effectiveness verification.
- If your network touches devices, map which facilities fall under MDSAP and QMSR versus GMP.
The era when a manufacturer could keep different quality standards for different regions is over. FDA inspects foreign facilities. EU authorities inspect non-EU sites that supply the EU market. PMDA, the MHRA, and others run their own foreign inspections for their own approvals. Building once, to the highest standard, and running it the same way at every site is now the only strategy that survives contact with all of them.