A hybrid record exists whenever the complete account of a GxP activity lives partly in an electronic system and partly on paper, and you need both halves to reconstruct what happened. The classic case: an analytical balance or HPLC produces electronic data, an analyst signs a paper worksheet, and the worksheet refers back to the electronic file. Neither piece alone is the full record. That seam between paper and electronic is where data integrity most often fails, and it is one of the most cited problem areas in laboratory and manufacturing inspections.
Hybrids are not illegal and not inherently bad. Regulators accept them when they are deliberately designed, documented, and controlled. They become a finding when they are accidental, when no one has decided which record governs, and when the link between the two halves is weak or breakable. This article covers how to identify your hybrids, define the record, build the reconciliation controls, survive an inspection on the topic, and plan a credible exit.
What “hybrid” actually means, and why it is a top finding source
Definition and the three patterns
A hybrid system combines manual and electronic components in the creation, review, retention, or signing of a GxP record. There are three common patterns, and the controls differ for each:
- Electronic generation, paper review and signature. The instrument or system produces electronic raw data, but the official reviewed-and-signed record is a printout or worksheet. Most legacy chromatography, balances, pH meters, and dissolution baths sit here.
- Paper generation, electronic storage. A paper batch record or logbook is the master, then scanned, transcribed, or summarized into an electronic system (a manufacturing execution summary, a spreadsheet, a quality system). The paper is the raw record; the electronic copy is secondary.
- Split-field records. A single logical record is physically split: some fields are captured electronically (time stamp, result, audit trail) and some are captured on paper (analyst initials, deviation note, second-person verification). You cannot reconstruct the event without both.
Why hybrids exist
They exist because total electronic systems are expensive, slow to validate, and often retrofitted onto instruments that predate Part 11. A balance bought in 2009 may have no user accounts, no audit trail, and a serial printout as its only output. Replacing every such instrument at once is not realistic, so the paper worksheet bridges the gap. That is a legitimate engineering reality. The problem is that the bridge is rarely engineered with the same rigor as either pure-paper or pure-electronic systems.
Why regulators care so much
The regulatory basis is the data integrity expectation that the complete original record be preserved, attributable, and reconstructable. The relevant references:
- 21 CFR Part 211 (cGMP for finished pharmaceuticals), specifically 211.68 (automatic, mechanical, and electronic equipment, including the requirement to retain backup and the appropriate controls), 211.180(c) and 211.194(a) (records of laboratory tests, including complete data derived from all tests).
- 21 CFR Part 11 (electronic records and electronic signatures, 1997), which applies to the electronic portion of a hybrid whenever that electronic record is the one being relied on to satisfy a predicate rule.
- EU GMP Annex 11 (Computerised Systems) and Chapter 4 (Documentation), which together expect that when a system generates data electronically, that electronic data, including the audit trail, is the record retained and reviewed.
- The FDA guidance Data Integrity and Compliance With Drug CGMP, Questions and Answers (December 2018), which directly addresses the difference between static and dynamic records and warns that a printout of a chromatogram is not a true copy of dynamic electronic data because it loses the underlying data and the ability to reprocess.
- The MHRA GXP Data Integrity Guidance and Definitions (March 2018) and the PIC/S PI 041-1 Good Practices for Data Management and Integrity (July 2021), both of which devote specific attention to hybrid systems and the weaknesses inspectors look for.
The recurring inspection finding is simple to state: the firm signed a paper printout and discarded or never controlled the dynamic electronic data behind it, so the audit trail, integration parameters, and the ability to detect reprocessing were lost. That is an ALCOA+ failure on Original and Complete, and frequently on Available.
ALCOA+ applied field by field to a hybrid
ALCOA+ (Attributable, Legible, Contemporaneous, Original, Accurate, plus Complete, Consistent, Enduring, Available) is the lens every inspector uses. The trap with hybrids is that each attribute can be satisfied on one half and silently broken at the seam. Walk it field by field.
| ALCOA+ attribute | The hybrid-specific failure mode | What good looks like |
|---|---|---|
| Attributable | Paper signed by analyst A, but the instrument has a shared login so the electronic action cannot be tied to a person | Electronic action and paper signature both resolve to the same named individual at the same time |
| Legible | Handwritten transcription of an electronic result is ambiguous or overwritten | Transcription is exact, single-line cross-out corrections, electronic source retained |
| Contemporaneous | Worksheet completed end-of-day from memory while the electronic time stamp is real-time | Paper entry time matches the electronic event time; no backfilling |
| Original | The printout is treated as the record and the dynamic e-data is deleted or uncontrolled | The dynamic electronic data plus audit trail is retained as the original; paper is a controlled extension, not a replacement |
| Accurate | Transcription error between electronic result and paper worksheet | Second-person verification of any manual transcription, or no transcription at all |
| Complete | Failing or aborted injections exist electronically but never appear on paper | All runs, including aborted and reprocessed, are reconciled to the paper record |
| Consistent | Paper sequence and electronic sequence disagree on order or timing | Sequence and time stamps agree across both halves |
| Enduring | Thermal printout fades; the e-record is on an unbacked-up local drive | Both halves retained for the full retention period on durable, backed-up media |
| Available | Inspector asks for the audit trail behind a 3-year-old paper result and it is gone | Electronic source and audit trail retrievable for the full retention period |
The single most important sentence to internalize: for dynamic electronic data, the dynamic electronic record (with its audit trail and metadata) is the original, and the paper printout is at best a static summary. Signing the summary does not let you discard the original.
Step 1: Find your hybrids (the inventory)
You cannot control what you have not listed. Most firms underestimate their hybrid count by half because split-field records hide inside processes everyone thinks of as “paper.”
How to build the inventory
- Start from your GxP computerized system inventory and instrument list. For each system, ask three questions: Does it generate electronic data? Is any part of the official record on paper? Do you need both to reconstruct the event? Three yeses means it is a hybrid.
- Walk the floor and the lab. Watch a real execution. The inventory misses the balance whose only output is a serial-port printout taped into a logbook, and the spreadsheet that re-keys LIMS results for a trend chart.
- For each hybrid, capture: the activity, the electronic component, the paper component, which is the declared raw record, where the link between them lives, and the current control gaps.
Acceptance criteria for the inventory
- Every GxP instrument and system has been classified as pure-paper, pure-electronic, or hybrid, with a rationale.
- Each hybrid names a single declared raw record (see Step 2).
- Each hybrid has a documented reconciliation control or a gap logged in the remediation plan.
- The inventory is a controlled document with an owner and a review cycle, not a one-time spreadsheet.
Worked example: a hybrid inventory row
| Field | Entry |
|---|---|
| Activity | Assay by HPLC, finished product |
| System | Chromatography data system, standalone workstation |
| Electronic component | Raw signal, integration, audit trail, sequence file |
| Paper component | Analyst worksheet with result, calculation, signature, reviewer signature |
| Declared raw record | Electronic dynamic data + audit trail |
| Link mechanism | Worksheet records sequence name, file path, and result ID; result ID printed on the report |
| Control gaps | Shared Windows login on workstation; no second-person review of integration changes |
| Remediation | Provision individual accounts (Q3); enforce audit trail review SOP (now) |
This level of detail is what lets you answer an inspector in seconds instead of going to the floor to figure it out live.
Step 2: Decide which record is THE record
This is the decision that prevents most findings, and the one most often skipped. For every hybrid you must declare, in writing and per record type, which artifact is the raw data / original record, and therefore which one governs in a dispute.
The decision rule
The governing record is whichever artifact contains the original observation with the highest fidelity and the metadata needed to reconstruct the activity. Apply it:
- If the system produces dynamic data (data you can reprocess, re-query, or re-integrate, such as a chromatogram, a spectrum, or a database query result), the electronic data is the raw record. A printout is a static copy and cannot be the original. This is stated plainly in the FDA 2018 data integrity Q&A and the MHRA 2018 guidance.
- If the original observation is made on paper (an analyst writes an observation, a logbook entry, a handwritten weight read off a non-connected instrument), the paper is the raw record and any electronic transcription is secondary.
- If fields are split, declare each field’s source individually. The reconstruction depends on the union of both, and your SOP must say so.
See the dedicated treatment in static and dynamic records and true copies for why a chromatogram printout fails the true-copy test.
The governing-record decision tree
Work the record through these questions in order. The first one that resolves gives you the answer, and the answer goes into the SOP as a written declaration, not as an unwritten habit.
The last branch is the one most firms miss. A record can be genuinely split, and declaring one half governing when the other holds fields nobody else captured leaves those fields uncontrolled. Where a record is split, write the split down rather than forcing an artificial single answer.
Where the decision is written
- In the SOP governing that activity (the test method, the batch record instruction, the logbook SOP).
- In the validation documentation or system description for the electronic component.
- In the data integrity governance documentation as a cross-cutting policy, so a new system inherits the rule by default.
Acceptance criteria
- A reader who has never seen the process can point to the governing record from the SOP alone.
- The retention, backup, and review controls apply to the governing record, not just the convenient paper copy.
- Where dynamic data exists, the electronic record is declared governing. If anyone declared a printout governing for dynamic data, that is a finding waiting to happen.
Common mistake
The most common and most damaging mistake: a firm reviews and signs the printout, treats the printed result as final, and never reviews the electronic audit trail. An inspector reprocesses the original injection, finds a deleted failing result or an undocumented manual integration, and the signed paper record is now evidence that review was not effective. The fix is not more paper. It is reviewing the governing electronic record, including the audit trail. See audit trail design and review and operationalizing audit trail review.
Step 3: Build the reconciliation controls
Reconciliation is the active, documented process of confirming that the paper and electronic halves agree and that nothing in either half is missing or unexplained. It is the heart of hybrid control. Without it, the two halves drift apart and no one notices until an inspector does the reconciliation for you.
What reconciliation has to prove
- Count agreement. The number of electronic events matches the number of paper entries. If the sequence ran 12 injections, the worksheet accounts for 12, including blanks, standards, and any aborted or repeated runs.
- Identity agreement. Each electronic result maps to exactly one paper entry by a stable identifier (sequence name plus injection ID, sample ID, batch and step number). No orphans on either side.
- Value agreement. Any value transcribed from electronic to paper matches the source exactly, verified by a second person or eliminated by removing transcription entirely.
- Time and sequence agreement. The order and time stamps are consistent. A paper entry dated before its electronic event, or an electronic injection with no paper trace, is a flag.
- Exception accounting. Every aborted run, reprocessing, manual integration, and out-of-sequence event is explained on the record and tied to a deviation or a documented justification.
The unique-identifier technique
The single most effective control is to print a machine-generated unique identifier on both halves so they cannot be silently separated or swapped. Practical implementations:
- The CDS prints the result ID, sequence name, acquisition date-time, and operator on every report, and the analyst copies the result ID and sequence name onto the worksheet.
- The balance printout carries a printout sequence number that the analyst logs; gaps in the sequence number reveal a discarded weighing.
- The batch record references the electronic batch identifier and the MES step ID, so a paper page cannot be substituted without a mismatch.
Pre-printed, controlled, sequentially numbered worksheets close the other direction: a missing worksheet number shows a removed page.
Step-by-step reconciliation procedure
- At the point of review, retrieve the governing electronic record and its audit trail for the activity.
- Confirm the count of electronic events against the paper. Investigate any difference before proceeding.
- Match each electronic result to its paper entry by the unique identifier. Resolve orphans.
- Inspect the audit trail for deletions, manual integration changes, reprocessing, aborted runs, clock changes, and method or sequence edits. Confirm each is explained on the paper record or in a deviation.
- Verify any transcribed values against the electronic source (second-person check) or confirm that no transcription occurred.
- Confirm time and sequence consistency across both halves.
- Sign the review attesting that reconciliation was performed and exceptions are accounted for. The signature meaning (“reviewed including electronic audit trail and reconciliation”) must be defined.
Acceptance criteria for reconciliation
- Counts, identities, values, times, and exceptions all reconcile, with any difference investigated and dispositioned.
- The audit trail of the governing electronic record was reviewed as part of the activity, not as a separate after-the-fact exercise.
- The reviewer signature carries a defined meaning that includes reconciliation.
- A second person can repeat the reconciliation from the record alone and reach the same conclusion.
Worked example: a balance hybrid reconciliation
A non-networked analytical balance prints a slip per weighing with a printout counter. The dispensing worksheet has columns for the counter value.
| Weigh step | Material | Printout counter | Weight (slip) | Weight (worksheet) | 2nd-person verified |
|---|---|---|---|---|---|
| 1 | Reference standard | 04471 | 50.12 mg | 50.12 mg | JD |
| 2 | Sample, prep A | 04472 | 102.45 mg | 102.45 mg | JD |
| 3 | Sample, prep B | 04473 | 101.98 mg | 101.98 mg | JD |
Reconciliation check: counter runs 04471, 04472, 04473 with no gap, three slips, three worksheet rows, all weights match, second-person initials present. If the next observed counter on the following weighing were 04476, the gap (04474, 04475) demands an explanation: two discarded weighings that must be accounted for, not ignored. That gap question is exactly what an inspector asks.
Step 4: Control the seam (the specific weaknesses)
Beyond reconciliation, hybrids carry a set of recurring structural weaknesses. Each maps to a control.
Time and clock control
If the paper entry time and the electronic time stamp come from different clocks, contemporaneity cannot be proven and the sequence can be challenged. Synchronize and protect system clocks, restrict user ability to change the clock, and capture clock changes in the audit trail. See time stamps and system clock control.
Attribution on shared instruments
Many legacy instruments have a single shared operating-system login or no login at all. The paper signature attributes the result, but the electronic action is anonymous, and a determined bad actor could delete or alter data with no trace to a person. Mitigations, in order of strength: individual application-level accounts on the CDS even where the OS login is shared; locked workstations with restricted physical access logged in a controlled logbook; and a documented justification with compensating controls where individual accounts are genuinely impossible pending replacement. Document the residual risk; do not pretend it is zero. See electronic signatures implementation.
Signatures across the seam, and the record-linking requirement
Hybrids create a signature question that pure-paper and pure-electronic systems do not have: the signature is applied in ink, on paper, but the record it approves lives electronically. Part 11 anticipated exactly this. 21 CFR 11.70 addresses signature/record linking and covers handwritten signatures executed to electronic records, not just electronic signatures:
21 CFR 11.70: “Electronic signatures and handwritten signatures executed to electronic records shall be linked to their respective electronic records to ensure that the signatures cannot be excised, copied, or otherwise transferred to falsify an electronic record by ordinary means.”
Read that clause carefully, because the phrase “handwritten signatures executed to electronic records” is the hybrid case. When an analyst signs a paper worksheet that approves an electronic chromatographic result, that ink signature has been executed to an electronic record, and the link between the two has to be strong enough that the signature cannot be moved to a different result.
What makes the link strong enough in practice:
- A machine-generated identifier on both halves. The same result ID, sequence name, acquisition time stamp, and operator that identify the electronic record appear on the signed paper. This is the same unique-identifier control described above, doing double duty: it links the signature to one specific electronic record, not to a class of records.
- No detachable summary. A signature page that could be lifted off and stapled to a different report is a weak link. Where the paper is multi-page, number the pages as “page N of M”, carry the record identifier on every page, and sign the substantive page rather than a standalone cover sheet.
- Signature meaning stated on the paper. 21 CFR 11.50 requires signature manifestations to carry the printed name of the signer, the date and time, and the meaning of the signing (authorship, review, approval). The paper half of a hybrid should carry all three explicitly. “Reviewed by” with an initial and a date, and nothing defining what was reviewed, is the version that fails.
- A reciprocal pointer where the system supports it. The stronger designs record in the electronic system that a paper approval exists and where it is filed, so the electronic record is not silently missing half its approval history. Some chromatography and laboratory systems allow a comment or a custom field for this; use it when available.
EU GMP Annex 11 addresses electronic signatures in its own clause and expects them to be permanently linked to the record and to carry the time and meaning of the signature. Note the direction of travel: nothing in either framework prohibits an ink signature in a hybrid, but both expect the link to the electronic record to be deliberate and unbreakable by ordinary means. See electronic signatures implementation for the full signature framework, and 21 CFR Part 11 and EU Annex 11 for how the two regulations map to each other.
One trap worth naming: some firms conclude that because they sign on paper, Part 11 does not apply to them at all. That is not how the scope works. Part 11 applies to the electronic records being relied on to satisfy the predicate rule, regardless of where the signature was applied, and 11.70 explicitly reaches handwritten signatures that approve those electronic records.
Audit trail retention and review
The electronic audit trail is part of the governing record. It must be retained for the full retention period and reviewed at a defined frequency, risk-based, with critical data reviewed every time. A hybrid where the printout is signed but the audit trail is never opened is the textbook finding.
True copies and printouts
A printout of dynamic data is a static copy, not a true copy, because it cannot reproduce the dynamic data. If you need to provide a copy (for archival, transfer, or an inspector), provide the electronic data in a form that preserves the dynamic content and metadata, with a verified true-copy process. See static and dynamic records and true copies.
Backup and durability
Thermal printouts fade. Local workstation drives fail and are rarely backed up. The governing electronic record must be on durable, backed-up media with a tested restore. If a thermal slip is part of the record, photocopy it as a verified true copy and retain the copy. See backup, restore, and disaster recovery validation.
Correction and amendment rules
Paper corrections follow good documentation practices: single-line cross-out, initial, date, reason. Electronic corrections are captured in the audit trail. The hybrid risk is a value corrected on paper but not in the electronic record, or vice versa. The SOP must require that any correction is propagated and reconciled across both halves. See good documentation practices.
Scanning paper into the electronic half: true copies and when you may destroy the original
Sooner or later someone proposes scanning the paper, filing the image, and destroying the originals to recover archive space and make records retrievable. This is a legitimate and common approach, and it is also where firms create findings by moving too fast. The controlling question is not “may we scan?” but “does the copy carry everything the original carried, and can we prove it?”
True copy, certified copy, and why the words matter
A true copy is a copy of an original record that preserves the full content and meaning of that original, including all of its data and, where applicable, its metadata. A certified copy is a true copy that has been verified as complete and accurate by a named person, or produced by a validated process that performs the verification, and that carries a record of that verification. The FDA data integrity questions and answers, the MHRA data integrity guidance, and PIC/S PI 041 all address copies in these terms, and the practical requirement they share is the same: a copy that has lost content is not a substitute for the original, and a copy nobody verified is not a certified copy no matter what it is labelled.
Applied to a scan, this means the scanned image is a certified copy only when someone (or a qualified process) confirmed it against the paper and recorded that confirmation. An unverified PDF sitting in a shared folder is an image, not a record you can rely on.
What a scan can silently lose
Walk this list before certifying any scanning process, because each item has caused a real reconstruction failure:
| What gets lost | How it happens | Control |
|---|---|---|
| The reverse side | Single-sided scanning of a double-sided form or a page with a note on the back | Duplex scan by default; verification step confirms page and side count |
| Colour meaning | Greyscale scanning where red ink marks a correction, or a colour-coded status stamp | Scan in colour where colour carries meaning; state the requirement in the procedure |
| Attachments and inserts | Sticky notes, taped-in printouts, appended raw data slips removed during page preparation | Preparation step logs and re-attaches every insert; verification confirms attachment count |
| Faint thermal or pencil entries | Low-contrast source that scans blank or illegible | Resolution and contrast set by qualification; verification reads every field, not just page presence |
| Edge content | Content trimmed by the feed or lost in the gutter of a bound logbook | Flatbed for bound records; verification checks margins |
| Page order and completeness | Double-feed skips a page silently | Page count reconciled against the pre-numbered pages of the source |
| The signature link | The signed page is scanned separately from the data it approves | Scan the record as one unit, with the identifier on every page |
The double-feed case is the one that bites most often, because nothing about the output looks wrong. A batch record scanned at 47 pages when it should be 48 produces a perfectly clean-looking PDF. This is why page-count reconciliation against a pre-numbered source is not optional bureaucracy: it is the only control that catches a silent omission.
Building a defensible scanning process
- Qualify the process, not just the scanner. Cover the hardware settings (resolution, colour depth, duplex, file format), the preparation steps, the verification method, the naming and indexing convention, and the storage location with its backup. Treat it as a validated process under your normal approach. See CSV risk assessment methodology.
- Decide the verification level by risk. For high-criticality records (batch records, release testing, anything supporting a disposition decision), verify every page against the original. For lower-criticality records, a defined and justified sampling plan may be acceptable, but state the plan and its basis in the procedure rather than deciding per batch.
- Have a named person certify. The certification records what was copied, from what source, by whom, on what date, and the statement that the copy was verified as a complete and accurate reproduction of the original.
- Index so the copy is retrievable. A certified copy nobody can find fails Available just as thoroughly as one that was never made. Index by the identifiers a future reviewer will actually search: product, batch, date, document number, record type.
- Protect the image. The stored copy needs the same access control, backup, and retention as any other governing record, and any later change to it (annotation, re-scan, re-index) needs to be traceable.
- Only then consider destroying the paper, and only under the conditions in the next subsection.
The certification statement, worked
A certification block of this shape, applied per record or per defined batch of records, is what makes a copy certified rather than merely scanned:
| Field | Entry |
|---|---|
| Source record | Batch manufacturing record, product ABC 50 mg tablets, batch A-2274 |
| Source format and page count | Paper, double-sided, 48 numbered pages plus 3 appended printouts |
| Scan performed by | M. Okafor, 14 July 2026 |
| Scan settings | 300 dpi, colour, duplex, PDF/A |
| Verification method | 100 percent page-by-page comparison against original |
| Verified by | S. Lindqvist, 15 July 2026 |
| Certification statement | Verified as a complete and accurate copy of the original record, including all pages, both sides, and all appended attachments |
| Stored location and index | Document archive, indexed by product, batch, and record type |
| Original paper disposition | Retained pending scheduled destruction per retention procedure |
Note that the last row does not say “destroyed.” Destruction is a separate, later, deliberately controlled decision.
May you destroy the paper original?
Sometimes, and the conditions are specific. Regulators generally accept that a verified certified copy can replace an original where the copy genuinely preserves content and meaning, but several conditions have to hold together:
- The copy is certified, by the process above, and the certification is itself retained.
- The copy is at least as durable and available as the original, on backed-up media with a tested restore, retrievable for the full retention period.
- The record is static. Scanning a paper record produces a faithful copy of a static original. Scanning a printout of dynamic electronic data does not rescue that data: the dynamic electronic original still has to be retained, because no image of a chromatogram is a true copy of the chromatogram. This is the single most common misunderstanding in the whole topic.
- A documented policy authorises it, with the decision, the record types in scope, and the retention terms written down and approved by Quality.
- No local legal or regulatory requirement demands the paper. This varies by jurisdiction and by record type. Some national requirements, and some contractual or clinical-trial obligations, call for retention of the original paper regardless of what your GMP archive policy says. Confirm this for the countries you operate in before you shred anything, and treat that confirmation as part of the approval, not an afterthought.
- Nothing is destroyed while it is under any hold. An open investigation, a pending or ongoing inspection, litigation, or a regulatory request suspends scheduled destruction. Build the hold check into the destruction procedure so it cannot be skipped.
Destruction should be scheduled, approved, witnessed, and recorded, with the record of destruction retained. The record of what you destroyed and when outlives the thing destroyed.
Common findings on scanning and copies
- Paper destroyed after scanning with no verification step, so the “certified copies” were never certified.
- Double-sided originals scanned single-sided, losing corrections and second-person initials recorded on the reverse.
- Printouts of dynamic data scanned and the underlying electronic data deleted, on the theory that the archive now holds the record. It does not.
- Certified copies stored on media with no backup, or indexed so poorly they cannot be produced during an inspection within a reasonable time.
- Destruction proceeding on schedule while the batch was under investigation, because the hold check lived in a different procedure that nobody consulted.
Step 5: Validate and document the hybrid as a designed system
A hybrid is a validated process, not an accident. The electronic component is validated per your CSV approach. The paper component and the reconciliation controls are part of the same process description.
What to document
- A system description identifying the electronic and paper components, the data flow, and the governing record.
- The user requirements and risk assessment that justify the controls, including the residual risk where a control is compensating rather than preventive. See user requirements and traceability and CSV risk assessment methodology.
- The SOPs for execution, review, reconciliation, and correction.
- The data integrity controls map: for each ALCOA+ attribute, the control that satisfies it across the seam.
Roles and responsibilities
| Role | Responsibility in a hybrid |
|---|---|
| Process / system owner | Maintains the system description, ensures reconciliation controls operate, owns the remediation plan |
| Operator / analyst | Executes the activity, records contemporaneously on both halves, copies unique identifiers accurately |
| Reviewer (technical, second person) | Performs reconciliation including audit trail review, verifies transcriptions, dispositions exceptions |
| QA | Approves the SOP and system description, audits hybrid controls, classifies any breakdown as a deviation, approves the migration plan |
| Validation / CSV | Validates the electronic component, documents the hybrid as a designed system, supports migration validation |
| IT / instrument support | Provisions individual accounts, configures clock sync and audit trail, manages backup and restore |
| Vendor / supplier | Supplies the electronic system with the controls needed; supports configuration of accounts, audit trail, and export. See supplier and vendor qualification |
The point of writing roles down is so that no one can say “I thought the other reviewer checked the audit trail.” Reconciliation has one named owner per record.
Step 6: Migrate off the hybrid
Hybrids are a transitional state, and inspectors increasingly expect a plan to retire them. The MHRA and PIC/S guidance both frame hybrids as higher-risk and encourage moving to fully electronic records where the technology allows. You do not have to eliminate every hybrid tomorrow, but you do need a risk-prioritized roadmap and visible progress.
Prioritize by risk
Rank hybrids by data criticality and control weakness. A hybrid feeding a release decision with shared logins and no audit trail review is top of the list. A low-criticality logbook with strong controls can wait. Use your data criticality and data risk assessment to rank.
The migration paths
- Upgrade the electronic component so the whole record can live electronically (individual accounts, audit trail, electronic review and e-signature), then retire the paper worksheet. This is the cleanest exit. Confirm the upgraded system meets Part 11 and Annex 11 before declaring paper retired.
- Replace the instrument or system with a current one that natively supports full electronic records, then qualify and migrate.
- Networked data system (a CDS that pulls standalone instruments into a controlled server with central accounts, audit trail, and backup) removes the standalone-workstation weaknesses for a whole lab at once.
Handling legacy data during migration
When you move from hybrid to electronic, the existing records do not vanish. You must decide whether legacy electronic data is migrated, archived in a readable form, or retained on the original validated system for the retention period. Any migration of data is itself a validated activity: prove that records are complete and unaltered after the move, including audit trails. See data migration validation and, for old systems you are not replacing yet, retroactive validation of legacy systems.
Acceptance criteria for retiring a hybrid
- The new fully-electronic process is validated and meets Part 11 / Annex 11 for the electronic record and signature.
- Reconciliation is no longer needed because there is only one record, or the residual paper is purely informational and declared non-governing.
- Legacy hybrid records remain retrievable and reconstructable for their full retention period.
- The change is controlled through change control, and the inventory and SOPs are updated. See change control for validated systems.
Migration roadmap example
| Hybrid | Criticality | Weakness | Target state | Path | Quarter |
|---|---|---|---|---|---|
| Standalone HPLC, release assay | High | Shared login, no audit trail review | Networked CDS, e-review | Network + accounts | Q1-Q2 |
| Analytical balances, dispensing | Medium | Thermal slips, manual transcription | Connected balances to LIMS | Replace + interface | Q3 |
| Stability chamber log | Low | Paper log, strong controls | Electronic monitoring | Defer, monitor | Year 2 |
A roadmap like this, with dates and owners, is exactly what you show an inspector who asks “what is your plan for hybrids?” The wrong answer is “we don’t have one.”
Hybrids outside the QC laboratory
Most written treatment of hybrids uses laboratory examples, because chromatography is where the problem is sharpest. The seam exists in every other GxP area too, with its own failure modes.
Manufacturing and the paper batch record
A paper batch manufacturing record sitting alongside electronic equipment is the largest hybrid most firms own, and it is rarely on the hybrid inventory because everyone calls it “the paper batch record” and stops thinking. Look at what the paper actually depends on:
| Paper element | The electronic half it depends on | Where the seam fails |
|---|---|---|
| Dispensing weights entered by hand | Balance or weigh-and-dispense system with its own log | Weight transcribed with no verification; balance log never reconciled to the record |
| ”Autoclave cycle acceptable” signature | Cycle chart, printer output, or cycle data file with the real profile | Signature applied without the cycle data attached or reviewed; printout fades |
| Process parameters written each hour | DCS, SCADA, or historian trending continuously | Hourly manual entries look compliant while the continuous trend shows an excursion between readings |
| Environmental monitoring result pasted in | EM system, particle counter, and plate reading records | Excursion visible in the electronic system and never reflected on the batch record |
| Line clearance checklist | Vision system, checkweigher, or reconciliation counts | Reconciliation numbers copied without reference to the machine counts that produced them |
| Deviation cross-reference | Electronic quality system holding the deviation | Batch record cites a deviation number that does not resolve, or the deviation closes without updating the record |
The controlling principle is unchanged: where the equipment holds the higher-fidelity original, that electronic data is the record, and the batch record entry is a controlled extension that has to reconcile to it. The specific manufacturing risk is that the paper looks complete on its own. A batch record with every blank filled and every signature present can still sit on top of an unreviewed alarm history. Batch record review therefore has to reach the electronic sources it depends on, not just verify that the paper is fully populated. See batch record review and automation validation for PLC, SCADA, and DCS.
Continuous electronic data creates a second issue that hand-written records do not have: the electronic system records everything, including the moments between the hourly manual readings. Once that data exists, it is part of the record, and an excursion in it is not excused by a compliant-looking manual entry. Firms sometimes discover this the hard way when an inspector asks to see the historian trend behind an hour that the paper says was in specification.
Clinical and GCP hybrids
Clinical research runs on hybrids more than almost any other GxP area, because investigator sites keep paper source documents (medical charts, worksheets, diaries, consent forms) while the sponsor collects data electronically in an EDC system. The seam sits between site source and sponsor database, and it is crossed by transcription rather than by interface.
The specific characteristics that make clinical hybrids different:
- The original mostly lives at the site, not with the sponsor. The medical record is the source. The EDC entry is derived from it. That inverts the laboratory pattern, where the electronic system usually holds the original.
- Certified copies carry more weight. Sites and sponsors routinely work from copies of source documents, so the certified-copy discipline described above is a routine operational control in clinical work rather than an archive-time activity.
- Direct access is a regulatory expectation. Monitors, auditors, and inspectors are entitled to examine the source records, which means the paper half has to be organised, retained, and produceable, not merely present somewhere at the site.
- Consent is its own hybrid. Paper informed consent forms with electronic tracking of consent status are a hybrid, and a mismatch between the two is a serious finding because it touches subject protection rather than data quality alone.
ICH E6(R3), Good Clinical Practice, reached Step 4 on 6 January 2025 and its Principles and Annex 1 took effect in the EU on 23 July 2025. It is deliberately more technology-neutral than the version it replaced, framing expectations around data governance across the data lifecycle rather than around a presumed paper process, which makes it a better fit for reasoning about hybrid clinical records. Annex 2, which addresses decentralised and other pragmatic trial elements, reached Step 4 following ICH adoption on 3 June 2026 and CHMP adoption on 25 June 2026, and comes into effect on 15 January 2027. Decentralised elements tend to multiply hybrids rather than reduce them, because data arrives from home visits, local laboratories, and participant devices on a mix of paper and electronic paths. Read the current text for the operative wording rather than relying on a summary. See clinical systems, GCP, and digital quality and clinical QA and GCP data integrity.
Retention, archiving, and the decommissioned-system problem
Hybrids have a long tail. The record has to remain reconstructable for its full retention period, which frequently outlives the system that created the electronic half. The failure pattern is predictable: the instrument is replaced, the old workstation is wiped or scrapped, and three years later nobody can open the electronic half of a record whose paper half is still neatly filed.
Handle it deliberately:
- Decide the archive strategy before decommissioning, not after. The options are migrating the data into the replacement system, exporting to a durable, readable, non-proprietary format that preserves the dynamic content and metadata where possible, or retaining the legacy system in a controlled read-only state for the retention period. Each has a cost, and the do-nothing option has the highest cost of all.
- Test retrieval, do not assume it. Restore a record and open it. A backup nobody has restored from is a hypothesis. Include a hybrid record in the restore test, so you confirm both halves can still be brought together.
- Keep the link alive. If the electronic half moves to a new location or format, the paper half’s pointer to it goes stale. Record the new location so the identifier on the worksheet still resolves.
- Retain the audit trail with the data. An archive that preserves results and drops the audit trail has preserved the wrong half of the record’s evidentiary value.
See data migration validation and backup, restore, and disaster recovery validation.
Auditing your own hybrids before someone else does
Self-audit is the control that tells you whether everything above is real or merely written. The mistake is auditing the paper, since the paper is the half designed to look complete. Audit the seam.
How to pull a sample
Judgement-based selection beats random selection here, because you are testing specific weaknesses rather than estimating a population rate. Bias the sample toward:
- The highest-criticality hybrids on the inventory, especially anything feeding a release decision.
- Systems with known control gaps still open in the remediation plan.
- Records from periods of pressure: month-end, campaign runs, a new product introduction, a period with staff turnover.
- Records where something was repeated, aborted, or deviated, since exceptions are where reconciliation gets skipped.
- At least a few routine, unremarkable records, so you learn what normal practice looks like rather than only what exception practice looks like.
A workable cadence for a mid-size site is a small number of records per hybrid system per quarter, deep rather than broad. Ten records examined properly against their electronic sources tell you far more than a hundred records checked for signature presence.
What to test on each record
- Start from the electronic side, not the paper. Pull the electronic record and its audit trail first, then ask the paper to account for it. Starting from the paper only ever confirms that the paper is complete.
- Reconcile counts, identities, values, times, and exceptions per the reconciliation procedure, independently. Reach the conclusion yourself rather than reading the reviewer’s conclusion.
- Open the audit trail and look for deletions, reprocessing, manual integration, aborted runs, renamed files, clock changes, and privilege changes in the period.
- Test attribution: can every electronic action be tied to a named person, and does that person match the paper signature?
- Test the signature link: does the paper identify the specific electronic record it approves, and does the meaning of the signature cover reconciliation and audit trail review?
- Test retrieval end to end: ask for a record from several years ago and time how long it takes to produce both halves. This is the test most firms have never run and the one an inspector runs first.
- Check the inventory itself: walk one process end to end and see whether the hybrid you find on the floor is the hybrid the inventory describes.
What a finding means
Not every discrepancy is a data integrity event, and treating them all as one destroys the credibility of the programme. Sort them:
| What you found | How to treat it |
|---|---|
| Transcription error caught by second-person check and corrected properly | The control worked. Record it, trend it, no deviation. |
| Transcription error not caught, no impact on the result or decision | Documentation error. Deviation, retraining, trend for pattern. |
| Transcription error that changed a result or a disposition | Deviation with product impact assessment, and a look at every other record from that period. |
| Reconciliation not performed but records agree | Procedural failure. Deviation. The control was absent, and the fact that nothing was wrong this time is luck, not evidence. |
| Unexplained gap in a sequence or counter | Investigate as potential lost or discarded data until proven otherwise. Do not close on the assumption it was benign. |
| Audit trail shows deletion or alteration with no explanation, or attribution cannot be established | Escalate immediately as a potential data integrity event under your governance process, not as a routine deviation. |
That last row is the one to get right in advance. Decide who is notified, how the scope is widened, and how product impact is assessed before you find something, because deciding those things while looking at a live finding produces slow and defensive decisions. See the data integrity self-audit checklist and data integrity program architecture for the surrounding programme.
Common inspection findings on hybrids
These are the patterns regulators cite, stated generically. If your hybrid has any of them, fix it before someone finds it.
- Signed the printout, lost the dynamic data. The static report was treated as the record; the electronic raw data and audit trail were deleted, overwritten, or never controlled. Original and Complete fail.
- No audit trail review. The reviewer signed the result but never opened the electronic audit trail, so deletions, reprocessing, and manual integrations went undetected. Review was not effective.
- Shared logins. Actions on the electronic component cannot be attributed to a person, defeating Attributable and enabling untraceable alteration.
- Transcription errors and no second check. Values re-keyed from electronic to paper without verification, with errors that change a result or a release decision.
- Unexplained gaps. Missing printout sequence numbers, missing worksheet page numbers, aborted injections absent from the paper record. The classic “testing into compliance” pattern, where failing runs were quietly discarded.
- Clock not controlled. Users could change the instrument clock, so contemporaneity and sequence cannot be proven.
- No defined raw record. No SOP says which half governs, so different reviewers treat different halves as authoritative and the firm cannot answer the most basic question about its own data.
- No migration plan. Hybrids treated as permanent with no risk ranking and no roadmap, signaling the data integrity program is not actually managing them.
Each maps to a control already covered above. The fix is rarely more paper; it is defining the record, reviewing the electronic original, controlling attribution and time, and reconciling.
Interview-ready: questions and strong answers
“What is a hybrid system and why is it a data integrity risk?” A record where the complete account of a GxP activity lives partly electronically and partly on paper, and both are needed to reconstruct the event. The risk concentrates at the seam: attribution can break on the electronic side, the dynamic original can be lost when only the printout is signed, and the two halves can drift apart without reconciliation. It is one of the most cited laboratory data integrity findings.
“In a hybrid, which is the raw record, the printout or the electronic file?” For dynamic data, the electronic data with its audit trail is the original; the printout is a static copy and cannot be the raw record. This is stated in the FDA 2018 data integrity Q&A and the MHRA 2018 guidance. If the original observation is made on paper, the paper is raw and the electronic copy is secondary. You declare this per record type in the SOP.
“How do you review a hybrid chromatography record correctly?” You review the governing electronic record including the audit trail, not just the signed printout. You reconcile counts, identities, and values between the electronic data and the worksheet, you check the audit trail for deletions, reprocessing, manual integration, aborted runs, and method or sequence edits, and you confirm every exception is explained. Then you sign with a defined meaning that includes reconciliation.
“How would you prove no data was deleted in a hybrid where injections happen on a standalone workstation?” Review the electronic audit trail and sequence for aborted or deleted runs and reprocessing, confirm the sequence count reconciles to the paper record, and use a machine-generated identifier, a result ID or a printout counter, so gaps are visible. A gap in the counter is unexplained discarded data until proven otherwise.
“You have hundreds of standalone instruments with shared logins. What do you do?” Inventory and risk-rank them, apply compensating controls now (individual application-level accounts where possible, controlled access logbooks, audit trail review, clock control), document the residual risk honestly, and put a dated migration roadmap in place starting with the highest-criticality, weakest-control systems, typically networking the CDS so a whole lab is fixed at once.
“What’s wrong with signing a printout of a chromatogram?” The printout is static. It loses the dynamic data, the integration parameters, and the audit trail, so you cannot reprocess or detect that the result was reintegrated or that a failing injection was deleted. Signing it does not make it the original and does not let you discard the electronic raw data, which remains the governing record.
“Can we scan our paper batch records and destroy the paper?” Potentially, under conditions. The scan has to be a certified copy: produced by a qualified process, verified against the original by a named person or a validated process, and carrying a record of that verification. The copy has to be at least as durable and retrievable as the paper, on backed-up media, for the full retention period. A written policy approved by Quality has to authorise it, no local legal requirement can demand the paper original, and nothing under investigation, inspection, or legal hold gets destroyed. And a critical limit: scanning a printout of dynamic electronic data does not let you delete that electronic data. The image is a copy of the printout, not of the chromatogram.
“Our signatures are on paper, so Part 11 doesn’t apply, right?” No. Part 11 applies to the electronic records relied on to satisfy a predicate rule, regardless of where the signature was applied, and 21 CFR 11.70 explicitly covers handwritten signatures executed to electronic records. In a hybrid, the ink signature approving an electronic result has to be linked to that specific record strongly enough that it cannot be transferred to another one. In practice that means a machine-generated identifier on both halves, no detachable signature page, and a stated signature meaning.
“A paper batch record is fully completed and signed. What could still be wrong?” The paper is the half designed to look complete, so completeness of the paper proves very little on its own. The electronic sources it depends on may tell a different story: an alarm or excursion in the historian between the hourly manual readings, an EM result that never made it onto the record, a balance log that does not reconcile to the dispensing weights, or a cited deviation number that does not resolve. Batch record review has to reach into those electronic sources rather than confirming that every blank was filled.
“How would you audit hybrid controls?” Start from the electronic side, never the paper, because starting from the paper only confirms the paper is complete. Pull the electronic record and its audit trail first and make the paper account for it. Reconcile independently rather than reading the reviewer’s conclusion, test attribution and the signature link, and run an end-to-end retrieval test on a record several years old to see how long producing both halves actually takes. Bias the sample toward high-criticality systems, known open gaps, and periods of operational pressure.
“How do you know your hybrid controls are working?” Self-audit. Pull records and independently reconcile paper to electronic, open audit trails, check attribution and clock control, and look for unexplained gaps. Track findings as deviations and feed them into the migration priority. See the data integrity self-audit checklist.
Practical tips
- Reconcile at the point of review, while the activity is fresh and the analyst is available, not weeks later when the floor has moved on.
- Print a machine-generated unique identifier on every electronic output and require it on the paper. It is the cheapest control with the highest payoff.
- Use controlled, sequentially numbered worksheets so a removed page is visible.
- Define what each signature means. “Reviewed” must explicitly include the electronic audit trail and reconciliation, or reviewers will sign the paper alone.
- Photocopy thermal printouts as verified true copies on the day they are made; the original will fade before the retention period ends.
- Never let “we’ve always done it on paper” justify discarding dynamic electronic data. The original is the original regardless of habit.
- Keep the hybrid inventory and migration roadmap current and bring both to inspections. Showing control and a plan is far stronger than showing zero hybrids you cannot actually prove.
- Put the hybrid inventory question to manufacturing, not only the laboratory. The paper batch record is usually the biggest hybrid on site and the one least likely to be on the list.
- Verify scans against the original before the paper leaves the building. Verification after destruction is not verification.
- Scan double-sided by default. Corrections and second-person initials on the back of a page are the most commonly lost content in the whole archive process.
- Reconcile scanned page counts against a pre-numbered source. A double-feed produces a clean-looking file that is silently missing a page.
- Run one retrieval drill a year: ask for a hybrid record from several years ago and time how long it takes to produce both halves. It is the fastest way to find out whether your archive strategy is real.
- Decide the archive path before you decommission a system, never after. Once the workstation is wiped, the options narrow to expensive or impossible.
Related articles
- ALCOA+ in detail
- Data integrity foundations
- Static and dynamic records and true copies
- Audit trail design and review
- Operationalizing audit trail review
- Chromatography data system integrity
- 21 CFR Part 11 and EU Annex 11
- Good documentation practices
- Electronic signatures implementation
- Time stamps and system clock control
- Data migration validation
- Retroactive validation of legacy systems
- Data criticality and data risk
- Data integrity self-audit checklist
- Data integrity program architecture
- Batch record review
- Automation validation for PLC, SCADA, and DCS
- Clinical systems, GCP, and digital quality
- Clinical QA and GCP data integrity
- Backup, restore, and disaster recovery validation