The microbiology QC laboratory is where data integrity programs that look solid on paper quietly fall apart. The chemistry lab has chromatography data systems with audit trails, electronic signatures, and immutable raw files. Micro has an analyst squinting at a plate, counting colonies by eye, writing a number on a form, and a second person looking over their shoulder. Most of the record is human judgment captured on paper, and the instrument data that does exist (the incubator chart, the endotoxin reader printout, the particle counter file) sits beside the paper rather than replacing it. That hybrid structure, half human and half machine with a seam in the middle, is one of the most frequently cited weak points in inspections, and it is the hardest part of a site to make genuinely defensible.
This article covers the specific integrity controls that micro work needs: contemporaneous recording at the bench, manual colony counting and second-person verification, plate reading and image retention, the integrity of environmental monitoring, bioburden, sterility, and endotoxin records, reading windows for incubated plates, and the paper-and-instrument hybrid traps that keep showing up in 483s. If you are new to the underlying principles, start with data integrity foundations and the ALCOA+ principles in detail. For the broader hybrid problem that micro is a special case of, read hybrid paper and electronic records. The worked examples and interview questions near the end are the parts to reread before an inspection or a job interview.
Why Micro Is Different (and Harder)
The regulatory basis
The same rules apply to micro as to every other GxP record. In the United States, 21 CFR 211.194 requires complete records of all tests, 211.160(b) requires that laboratory controls be scientifically sound, and 21 CFR Part 11 governs any electronic records and signatures the lab does generate. The FDA guidance “Data Integrity and Compliance With Drug CGMP: Questions and Answers” (final, December 2018) and the MHRA “GXP Data Integrity Guidance and Definitions” (March 2018) apply in full. In the European Union, EU GMP Annex 1 (the 2022 revision, effective for most provisions August 2023) sets the contamination control expectations that drive most micro testing, and EU GMP Annex 11 governs the computerized parts. PIC/S PI 041, “Good Practices for Data Management and Integrity in Regulated GMP/GDP Environments”, gives the most detailed treatment of hybrid records, which is exactly what micro runs on.
In its own terms, 21 CFR 211.194(a) requires laboratory records to carry the complete data from every test run to show compliance with the established specifications and standards. The word “complete” is the one that bites in micro. A colony count is the result of an observation that cannot be re-run. Once the analyst discards the plate, the only record of what was on it is the number they wrote and any image they captured. There is no raw data file to go back to.
Why the risk is structurally higher
Four features make micro records harder to keep defensible than chemistry records:
- The observation is destructive and time-bound. A plate is read once, at a defined time, and then discarded or overgrown. You cannot reconstruct the count later the way you can reprocess a chromatogram. The contemporaneous record is the only record.
- The primary measurement is human. Counting colonies, reading a sterility tube for turbidity, scoring a Gram stain: these are judgments, not instrument outputs. Two trained analysts can read the same plate as 47 and 52 and both be defensible. That variability is normal, but it makes the second-person check load-bearing rather than ceremonial.
- Long latency between work and result. A sterility test runs 14 days. Environmental monitoring (EM) plates incubate for days. Stability and bioburden have their own windows. The gap between performing the work and recording the final read is where contemporaneity breaks and where the temptation to “remember” a reading and write it up later creeps in.
- The records are a hybrid by nature. Almost no micro result lives in a single system. A bioburden result combines a paper bench sheet, an incubator temperature chart, and sometimes a colony-counter printout. Sterility combines a paper observation log with an isolator or incubator record. The integrity of the result depends on the seam between these holding.
The companion micro articles cover the science: environmental monitoring program, bioburden and endotoxin testing, sterility testing per USP 71, and microbial identification and EM excursions. This article is about keeping those records trustworthy, not about how to run the assays.
Contemporaneous Recording at the Bench
Why it matters
Contemporaneous is the C in ALCOA+, and it is the attribute micro fails most often. The risk is not fraud in most cases. It is an analyst reading three sets of EM plates, holding the numbers in their head, and writing them onto the forms back at the desk twenty minutes later. The record is now a reconstruction, and a reconstruction is not the original observation. If one number is transposed, nothing in the system catches it, because there is no instrument file to reconcile against.
The deeper risk is the gap between when the observation happened and when the record claims it happened. If a plate was read at 09:15 and the form is dated and timed 09:45, an inspector who notices the mismatch (against an incubator door-open log, a swipe-card record, or a calibration timestamp) has a contemporaneity finding, and contemporaneity findings cast doubt on every other number on the page.
What contemporaneous means here
The reading is recorded at the moment of observation, on the controlled form or in the controlled system, by the person who made the observation, with the actual date and time. Not before (you cannot pre-fill a reading). Not after from memory. Not by a colleague who was told the number across the room.
How to do it, step by step
- Take the controlled form (or open the controlled electronic record) to the bench or the reading station. Do not read first and write later.
- Record each observation as you make it: the colony count for that specific plate or filter, against that specific sample and plate identifier, before moving to the next plate.
- Enter the real clock time of the read, not a rounded or batch time applied to every plate at once. If ten plates were read over fifteen minutes, the times should reflect that, not show all ten at 09:00.
- If the reading station is a separate room from where the form lives, fix the process so the form travels with the work. A “transcribe back at the desk” step is a contemporaneity gap waiting to be found.
- Where an electronic colony counter or plate imager is used, let it write the timestamp, and confirm the instrument clock is synchronized. See time stamps and system clock control.
Acceptance criteria
Contemporaneous recording is in order when every micro observation is recorded at the point and time of observation by the observer, on the controlled record, with a real clock time that can survive comparison against independent timestamps (incubator logs, access logs, instrument clocks), and when there is no documented or procedural step that requires holding readings in memory before recording.
Worked example
An EM analyst reads viable air-sample plates from three cleanrooms. The defensible version: she carries the EM data sheet to the plate-reading station, reads plate EM-2026-0418-A and writes “12 CFU” with time 08:52 and her initials, then plate EM-2026-0418-B and writes “0 CFU” at 08:54, and so on, signing each as read. The indefensible version: she reads all eighteen plates, returns to the office, and fills the whole sheet at 09:20 from a sticky note. Same numbers, very different record. The second one collapses the moment an inspector cross-checks the sheet time against the incubator removal log.
Roles
The analyst owns recording at the moment of observation. The lab supervisor owns a workflow that does not force a transcription gap (form at the bench, reading station near the record). QA owns the procedure that defines contemporaneous recording and the second-person check that backs it up.
Common 483-type mistakes
- Plates read, then recorded later from memory or a scrap of paper.
- A single batch time stamped on every plate read across a twenty-minute session.
- Pre-printed or pre-dated forms filled in before the work was done.
- Readings called out by one analyst and written by another, with no record of who actually observed.
Manual Colony Counting and Second-Person Verification
Why it matters
The colony count is the result. There is no underlying data file that proves it, so the count and the check on the count carry the full integrity burden. Two controls make a manual count defensible: a documented counting method so the number is reproducible, and an independent second-person verification so a misread or a transcription slip is caught while the plate still exists. Once the plate is gone, neither can be done.
This is where the verification step earns its place. A second-person check is not a signature ritual. Done properly it means a second qualified analyst looks at the same plate (or the retained image) and independently agrees the count is right, before the plate is discarded.
What a defensible counting method specifies
- How a colony is defined and counted, including how to handle merged or confluent growth.
- The countable range and what to do outside it (for example, “too numerous to count” handling, dilution scheme, when to report estimated or “TNTC”).
- How spreaders, satellites, and artifacts are distinguished from true colonies.
- Whether and when an electronic colony counter is used, and how its count is verified.
- The rounding and reporting convention, and the units (CFU per plate, per filter, per cubic meter, per contact area).
How second-person verification should work, step by step
- The first analyst counts the plate and records the count, time, and initials on the controlled record while the plate is in front of them.
- A second qualified analyst, independent of the first, examines the same plate (not just the written number) and confirms the count, or records a discrepancy.
- The verification happens before the plate is discarded, so a disagreement can be resolved against the physical evidence, not against memory.
- If the two counts differ beyond a defined tolerance, the procedure defines resolution: re-count together, capture an image, escalate, and document the basis for the reported number. The discrepancy and its resolution are part of the record.
- The second person dates and signs the verification. A check with no time and no name is not a verification.
A verification done after the plate is discarded is verification of a number against nothing. It confirms the second person can read the first person’s handwriting, not that the count was right. That is one of the most common hollow controls in micro.
Acceptance criteria
Verification is sound when a documented counting method exists and analysts are trained to it, the count is recorded contemporaneously by the counter, an independent second qualified person confirms the count against the plate (or a retained image of it) before the plate is discarded, discrepancies beyond tolerance are resolved and documented against physical evidence, and both the count and the check carry an attributable name and a real time.
Worked example
A bioburden plate from a drug substance sample shows growth near the upper countable limit. Analyst A counts 287 CFU and records it at 14:10. Analyst B, independent, recounts the same plate, gets 291, within the lab’s defined +/- 5 percent tolerance for counts above 100. They record both counts, agree on the reported value per the procedure (here, A’s contemporaneous count of 287, with B’s confirming count documented), B signs the verification at 14:14, and only then is the plate photographed and discarded. If B had instead “verified” the 287 the next morning from the form alone, with the plate already in the autoclave, the control would be cosmetic.
Roles
Analyst A (counter): the contemporaneous count and method adherence. Analyst B (verifier): an independent recount against the plate, not the paper. The supervisor: that verifiers are qualified and genuinely independent, and that the workflow makes verification-before-discard physically possible. QA: the counting and verification procedure, and oversight of discrepancy handling.
Common 483-type mistakes
- Second-person “verification” performed after the plate was discarded, against the written number only.
- No documented counting method, so two analysts count differently and neither is wrong or right.
- Verifier is the supervisor signing in bulk at end of shift without seeing the plates.
- Discrepant counts silently overwritten to agree, with no record of the original disagreement.
- Electronic colony-counter output accepted with no verification of the instrument’s count against the plate.
Manual Counting Versus Automated Colony Counters: Where the Risk Moves
Why it matters
Many micro labs are moving some or all colony counting from a human eye at the bench to an imaging colony counter or an automated reader that captures a plate image and applies an algorithm to call the count. The move is often sold as a data integrity improvement, and in some ways it is: an image is objective evidence a written number never was. But the risk does not disappear, it relocates. A manual count puts the whole integrity burden on the analyst and the second-person check (the general control is covered in second-person review of lab data). An automated system puts part of that burden on the algorithm, the audit trail, and whoever reviews the software’s override log. A lab that migrates counting methods without rethinking where the new risk sits usually ends up with the old paper gaps closed and a new set of unreviewed software gaps opened in their place.
A comparative risk picture
| Dimension | Manual counting | Automated or imaging colony counter |
|---|---|---|
| Primary record | The analyst’s written count on the paper form | A digital image plus a software-generated count, usually exported to a report |
| Contemporaneity risk | Reading several plates and recording the numbers later, from memory | Low if the instrument timestamps automatically and its clock is controlled |
| Objective evidence if a count is challenged | None, unless a photograph was separately taken at the bench | The retained image itself, provided it is not later overwritten or deleted |
| Second-person verification | An independent analyst recounts the same plate before it is discarded | An independent reviewer checks the image and the software’s count, including any manual override |
| Where the error usually enters | Miscounting merged or confluent colonies, or a transcription slip onto the form | The algorithm misclassifying spreaders, air bubbles, or condensation as colonies, or an operator override applied and accepted with no recorded reason |
| Audit trail | None; the paper is the record | A software audit trail of reprocessing, parameter changes, and manual overrides, if the feature is enabled and someone actually reviews it |
| Validation burden | Training and qualification of analysts to a documented counting method | A full validation of the counting algorithm against a spiked reference set, typically carried under the site’s computer system validation program |
| Distinctive 483 risk | Verification performed after the plate was already discarded | A manual override count accepted and reported with no documented reason, or the software audit trail never opened |
Acceptance criteria
An automated or imaging counter is defensible when the algorithm has been validated against a reference count on a representative set of plates including near-limit and confluent growth, every manual override carries a recorded reason and a second-person review, the software audit trail is enabled, immutable to ordinary users, and reviewed as part of result release, and the retained image (not only the printed count) is available for any result that is challenged.
Worked example
A site replaces manual bioburden counting with an imaging colony counter. On qualification, the counter is challenged with plates ranging from a handful of well-separated colonies through dense, partially confluent growth, and its counts are compared to two independent manual counts on the same plates; agreement within the site’s defined tolerance is documented before the counter goes live. Six months later, an analyst manually overrides the software’s count of 68 down to 61 on a plate with a smear the software read as three extra colonies, records the reason (“smear misread as colonies, confirmed against retained image”), and a second analyst reviews the image and agrees. That override, reason, and review are exactly what a defensible automated count looks like. The indefensible version is the same override made with no recorded reason and no second review, which looks, to an inspector reading the audit trail six months later, exactly like a number quietly adjusted to pass.
Roles
Analyst: performs the read, documents any override reason. Second reviewer: independently checks the image and the override before the result is reported. Validation: qualifies the algorithm against a reference count set and requalifies after any software update that could change how a count is called. QA: reviews the audit trail as part of routine result review, not only when a discrepancy is flagged.
Common 483-type mistakes
- The algorithm’s counting logic never validated against an independent manual reference count.
- Manual overrides of the software’s count accepted with no documented reason.
- The imaging system’s audit trail present but never reviewed.
- A software update or parameter change applied with no assessment of whether it changes historical counting behavior.
Plate Reading, Retention, and Imaging
Why it matters
Because the plate is destructive and time-bound, the question “can you prove what was on the plate” usually has only two possible answers: an image of the plate, or nothing but the analyst’s word. Retention of plates (for a limited window) and, increasingly, imaging of plates turn an unrepeatable observation into something a reviewer or inspector can examine after the fact. Where a count is contested, an EM excursion is investigated, or a sterility result is challenged, the image is often the only objective evidence left.
What “retention and imaging” means
- Short-term plate retention. Keep read plates, refrigerated or otherwise held per procedure, for a defined window (often a few days) so a count can be re-examined if a result is questioned before the plate degrades. This is a holding window, not archival; plates overgrow and become unreadable, which is exactly why imaging matters more.
- Plate imaging. Capture an image of the plate at the time of reading, especially for excursions, near-limit results, isolate recovery, and any count that feeds a critical decision. The image is a true copy of the observation at the moment it was made. See static and dynamic records and true copies for what makes a copy defensible.
- Image integrity. A retained image is a GxP record. It needs the same controls as any other: attributable to the plate and sample, timestamped, stored where it cannot be silently altered or deleted, and retained as long as the result it supports.
How to operationalize it, step by step
- Define in the procedure which results require an image: at minimum excursions, near-limit counts, sterility-positive observations, and any isolate sent for identification.
- At the read, photograph the plate with its identifier and sample visible in frame, or use an imaging colony counter that binds the image to the record.
- Name and store the image so it ties unambiguously to the plate, sample, date, and analyst. A folder of unlabeled JPEGs is not a record.
- Hold the physical plate for the defined retention window in case a re-read is needed before it degrades.
- Treat the image store as validated GxP storage: access-controlled, backed up, audit-trailed if the platform supports it. Confirm backup and restore actually return the images. See backup, restore, and disaster recovery validation.
Acceptance criteria
Retention and imaging are adequate when the procedure defines which results must be imaged and the lab does it consistently, images are bound to the correct plate/sample/date/analyst, the image store is access-controlled and backed up with restore proven, plates are held for the defined window, and a reviewer can pull the image for any imaged result and see what the analyst saw.
Worked example
A Grade A surface contact plate from an aseptic fill shows 1 CFU, an excursion for that grade. Per procedure, the analyst photographs the plate showing the single colony, the plate ID, and the location label, and the image is stored against the EM record. The colony is recovered for identification. Two weeks later, during the excursion investigation, QA pulls the image and confirms it was a single discrete colony, not a smudge or a counting artifact, and the identification ties to the recovered isolate. Without the image, the investigation would rest on the analyst’s recollection of a plate now long gone.
Roles
Analyst: capture the image at the read and bind it to the record. Lab supervisor: plates retained for the window, imaging done where required. IT/system owner: the image store is validated, access-controlled, backed up. QA: the imaging procedure and use of images in investigations.
Common 483-type mistakes
- No images of excursion or sterility-positive plates, so the investigation has no objective evidence.
- Images stored in an uncontrolled shared drive, editable and deletable by anyone, with no link to the sample.
- Plates discarded immediately after reading with no retention window, removing any chance of a re-read.
- Imaging colony-counter data never reviewed; only the headline count is transcribed and the bound image is ignored.
Integrity of EM, Bioburden, Sterility, and Endotoxin Records
Each of the core micro tests has its own integrity traps. They share a structure: a human observation, a paper record, and one or more instruments whose data sits alongside the paper. The integrity of the result depends on all three holding and on the links between them.
Growth promotion testing: the control behind every count
Every count in this article rests on one unstated assumption: that the medium the organism grew on (or failed to grow on) was actually capable of supporting growth. Growth promotion testing (GPT) is what proves that assumption, and it is a data integrity control in its own right, not just a microbiology release test. USP <61> Microbial Enumeration Tests and USP <62> Tests for Specified Microorganisms describe the expectation that each lot or batch of media be challenged with a small, defined inoculum, not more than 100 CFU, of the relevant reference organisms before or in parallel with routine use, and that growth be clearly visible within the method’s defined window.
The integrity failure mode is straightforward and recurring: a media lot is used for EM, bioburden, or sterility testing before its GPT result is available, or a lot that fails GPT is discovered only after it has already supported reported results. Either way, every result the lot touched is now standing on an unproven foundation, and the fix is not scientific, it is a traceability problem: the medium lot number has to be recorded on every test record it supports, so a failed or late GPT can be traced forward to every result at risk, not just to the next batch made.
How to operationalize it, step by step:
- Test every new lot or batch of media before it is released for routine use; do not release “pending” lots into service.
- Record the challenge organisms, inoculum level, and read result contemporaneously, at the time growth is confirmed or not confirmed, the same discipline covered earlier in this article and in good documentation practices for any other bench observation.
- Record the medium lot number on every EM, bioburden, sterility, or other test record that uses it, so the lot can be traced forward, not only backward from a complaint.
- If a lot fails GPT after it has already been used, trace forward from the lot number to every affected test and assess impact; do not stop at quarantining the remaining stock.
- Retain the GPT record for at least as long as the results it supports, since a challenge to a test result years later may still require proof the medium worked.
Acceptance criteria: growth promotion testing is sound when no lot is used before its GPT result is available and passing, the challenge and read are recorded contemporaneously, the lot number is traceable forward to every supported test record, and a failed or late GPT triggers a documented forward impact assessment rather than a quiet quarantine of what remains on the shelf.
Common 483-type mistakes: a media lot used in routine testing before GPT results were available; a received ready-to-use lot never tested at all; a failed GPT lot whose affected prior results were never traced or assessed; GPT records that show a pass with no read date, so contemporaneity cannot be shown.
Environmental monitoring
EM records are high-risk because they directly evidence the state of control of the aseptic process, and a failed EM result can implicate batches already released. That pressure is exactly why EM data integrity gets scrutinized. The records must show the full picture: every scheduled location sampled, every plate read, every excursion captured and investigated, with no quiet omissions.
The integrity questions an inspector asks of EM:
- Were all scheduled samples actually taken, or were some “missed” sampling events never recorded? Reconcile the EM plan against the executed records.
- Does the plate-and-incubator chain hold, meaning the incubation temperature and duration are documented and within range for the plates that produced the reported counts?
- Are excursions captured and escalated, or is there evidence (gaps in numbering, sequence breaks, isolates with no matching count) that an unfavorable result was dropped?
- Are active air-sampler volumes, contact-plate areas, and the resulting per-volume or per-area calculations recorded and checkable?
For the EM program itself, see environmental monitoring program and, for the contamination control context, Annex 1 and the contamination control strategy and aseptic processing and media fills.
Bioburden
Bioburden combines a paper bench sheet, dilution and filtration steps, incubation, and a colony count. The integrity traps: untracked dilution and filtration so the count cannot be tied back to a per-unit result, incubation conditions not documented against the plates, and the perennial colony-count-without-verification gap covered above. The reconciliation that matters: the number of plates set up, the dilutions used, and the final reported CFU per unit must all hang together arithmetically and be checkable from the record alone.
Sterility testing
Sterility (USP 71, EP 2.6.1) is the highest-stakes micro test, because a result decides whether a sterile product is released. The integrity points:
- The 14-day observation must be recorded contemporaneously, with each scheduled observation day documented, not back-filled at day 14.
- Any growth (turbidity) must be recorded when observed, with the observation date, not retroactively reconciled to a convenient story.
- A sterility positive triggers a formal investigation (USP 71 allows invalidation only under defined, documented conditions). The integrity question is whether positives are ever quietly re-tested away. An inspector reconciles the number of tests started against the number of results reported, looking for a started-but-vanished test.
- The reading environment and the analyst are recorded for each observation.
The classic sterility integrity failure is a positive that was observed, not recorded, and a retest reported as the only result. See sterility testing per USP 71.
A sterility positive is, by default, a true result until the investigation produces objective, documented evidence of an assignable laboratory cause, not a general assertion that a false positive is statistically more likely. USP <71> permits invalidation only where such evidence exists. The investigation record is itself data that has to survive scrutiny: it needs the recovered isolate’s identity, the environmental and personnel monitoring results for the exact test session, not the general trend for the month, the negative (media sterility) control result, and a documented comparison of the recovered organism against the test facility’s known flora and against the product’s manufacturing environment flora. A retest reported with no surviving record of how the original positive was investigated and why invalidation was justified is a data integrity gap on its own, independent of whether the underlying microbiology was handled correctly.
Endotoxin (BET)
Bacterial endotoxin testing (USP 85) is the most instrument-driven of the four, and so it looks the most like chemistry, which is exactly the trap. A kinetic or chromogenic reader produces an electronic data file with a standard curve, spike recovery, and sample values. That file is the raw data and must be retained and reviewed, not just the printed summary. Integrity points:
- The reader software audit trail, electronic file, and standard curve must be retained, not discarded after the analyst copies a single endotoxin value onto a form.
- Standard curve acceptance, positive product control (spike) recovery, and replicate criteria must be evaluated from the actual data, with failing runs visible, not suppressed.
- Reprocessing or re-analysis of a BET run carries the same expectations as reprocessing a chromatogram: a recorded reason and a retained original. See chromatography data system integrity for the analogous controls, and bioburden and endotoxin testing for the assays.
Media fill (aseptic process simulation)
A media fill, also called an aseptic process simulation, runs the real fill line with growth medium in place of product to demonstrate the process itself does not introduce contamination. It generates its own data integrity questions, separate from the science of interpreting a media fill covered in aseptic processing and media fills.
The core integrity control is unit accountability. Every unit that goes onto the line during the simulation has to be accounted for: filled, incubated and read, or removed for a specific, documented reason. The arithmetic has to close. If 3,000 units were filled and the incubation and reading records only account for 2,950, the missing 50 units are exactly the kind of gap an inspector looks for, because a unit quietly removed and never explained is indistinguishable, on paper, from a unit removed because it would have failed.
The interim reads matter as much as the final one. A 14-day media fill inspected only once, at the end, cannot show when turbidity actually appeared; the interim read dates and findings for every retained unit need to be in the record, not just a final pass or fail rolled up into a summary line. Environmental and personnel monitoring performed during the simulation, and every intervention performed during the run, need to be logged in real time and linked to the media fill record, because the whole point of the exercise is to simulate what actually happens on a live batch, and a simulation with undocumented interventions is not simulating anything checkable.
Acceptance criteria: a media fill’s data is sound when the filled, incubated, and rejected unit counts reconcile with no unexplained gap, every documented rejection carries a specific, contemporaneous reason, interim and final reads are dated and recorded for every retained unit, and the concurrent environmental monitoring, personnel monitoring, and intervention log are complete and linked to the fill record.
Worked example: A simulation fills 3,000 units. During the run, 12 units are rejected for documented mechanical reasons (a stopper seating fault caught by the line’s check station, logged with unit numbers and timestamps), leaving 2,988 units incubated. Interim reads at day 7 show all 2,988 clear; the final read at day 14 confirms all 2,988 clear. The reconciliation, 3,000 filled, 12 documented rejects, 2,988 incubated and read, closes with no gap, and the intervention log for the run matches what the environmental monitoring and video record show. Contrast a fill where the rejected-unit count is “approximately 15, not individually logged”; that fill cannot be reconciled, and an inspector has no way to distinguish a mechanical reject from a unit that was quietly pulled after early turbidity was noticed.
Roles: Line operator: contemporaneous logging of every reject at the point it happens, with unit number and reason. Micro/QC: interim and final reads, recorded per unit or per defined subgroup, dated. QA: reconciliation of filled against incubated against rejected, and review of the intervention log against the environmental monitoring for the same run.
Common 483-type mistakes: filled, incubated, and rejected unit counts that do not reconcile; interim reads skipped or backfilled at the final read; interventions performed during the run but not logged, or logged with times inconsistent with the environmental monitoring record; a media fill failure investigated without linking it back to the batches produced since the last successful fill on that line.
A cross-test reconciliation example
| Source | Count |
|---|---|
| Sterility tests started (per setup log, one campaign) | 12 |
| Sterility results reported in LIMS | 12 |
| Documented positives | 1 |
| Documented invalidations under USP 71 criteria | 0 |
| Retests reported | 0 |
| Accounted for | 12 |
| Unexplained gap | 0 |
If “tests started” were 13 and “results reported” were 12, with one positive nowhere to be found, that single-row gap is the kind of finding that escalates an inspection into a data integrity action. Build this reconciliation, and the EM-plan-to-executed-record reconciliation, into the internal audit program so you find the gap on your own terms.
Acceptance criteria
Test-record integrity is sound when, for each test type, the executed records reconcile against the plan (EM) or the setup log (sterility, bioburden), every instrument-generated file (BET reader, imaging counter, incubator chart) is retained and reviewed alongside the paper, incubation and environmental conditions are documented against the plates that produced the counts, and no started test, scheduled sample, or observed positive can vanish without a documented, justified path.
Microbial Identification and Chain of Custody
Why it matters
An isolate recovered from an EM plate, a bioburden plate, or a sterility positive is not just a lab curiosity. Its identity often decides whether a finding is routine environmental flora or a critical, investigation-triggering event, and the identification result can be the deciding input into a batch disposition. That means the physical path from “colony recovered” to “species reported” has to be provable, the same way any other result’s chain of evidence has to be provable. A finding with no traceable chain between the plate and the reported identity is a finding an inspector cannot verify, which in practice means it cannot be trusted.
What must be controlled
- A unique isolate identifier, assigned at the moment of recovery and carried through every subsequent step: subculture, shipment, identification method, and final report. Without it, an identification result cannot be traced back to the plate that produced it.
- A chain of custody record for any physical transfer of the isolate, whether to an internal identification group or an outside laboratory, with the date, time, and signature of who released it and who received it at each step.
- Retention of the isolate, or of extracted material from it (for example a DNA extract), for a defined period after the identification result is reported, in case a repeat or confirmatory identification becomes necessary.
- A prompt, recorded preliminary observation, such as a Gram stain result, captured close to the time of recovery. Gram-positive cocci and Gram-negative rods point toward very different likely sources (people versus water or wet surfaces), and a preliminary call made and recorded early is more useful, and more defensible, than a memory of what the stain looked like once the full identification comes back days later.
How to operationalize it, step by step
- Assign the unique isolate identifier at the point of recovery, on the same record that documents the count or the positive result.
- Record the preliminary observation (Gram stain, colony morphology) contemporaneously, before the isolate is subcultured or shipped.
- Log every physical transfer of the isolate, internal or external, with date, time, and both parties’ signatures.
- Retain the isolate or its extracted material for the defined period after the identification result is issued.
- Report the final identification tied to the unique isolate number, and confirm that number traces cleanly back to the originating plate and sample record.
Acceptance criteria
Identification and chain of custody are sound when every reportable isolate carries a unique identifier assigned at recovery, a preliminary observation is recorded contemporaneously, every physical transfer is logged with date, time, and signatures on both ends, the isolate or extracted material is retained for the defined period, and the final identification result traces without a gap back to the plate and sample it came from.
Worked example
A Grade A settle plate yields a single colony. The analyst assigns isolate number ISO-2026-0413, records a Gram-positive, catalase-positive coccus on preliminary stain the same afternoon, and ships the isolate to the identification laboratory the next morning with a custody log signed on release and countersigned on receipt. Three days later the identification laboratory reports Staphylococcus epidermidis, tied to ISO-2026-0413. QA traces the number back to the original settle plate record without a gap, and the preliminary Gram stain, consistent with a person-associated organism, matched the final call before the final result ever arrived, which is exactly the kind of internal consistency an inspector looks for. Contrast the indefensible version: the colony is subcultured and shipped with no isolate number, the identification laboratory’s report references only a sample description, and nothing ties the final species call back to the plate that was actually read.
Roles
Analyst: assigns the isolate number, performs and records the preliminary stain, initiates the custody log. Identification laboratory (internal or external): maintains the custody log on receipt, performs and reports the identification tied to the isolate number, retains material per agreement. QA: confirms the chain traces cleanly for any isolate feeding an investigation or disposition, and watches for identification “shopping,” rerunning a method until a less alarming call appears.
Common 483-type mistakes
- An isolate discarded before identification, with no documented reason, for a recovery that required identification under procedure.
- No unique isolate numbering, so a reported species cannot be traced back to the plate or sample that produced it.
- A custody gap when an isolate is sent to an outside laboratory, with no signed release or receipt.
- A Gram stain or other preliminary observation recorded well after the isolate was already subcultured or discarded, so it cannot be independently checked against the final call.
- Repeated re-identification of the same isolate until a less alarming organism is reported, with earlier results never disclosed.
Reading Windows and Incubation Control
Why it matters
Micro plates and tubes have defined incubation conditions and reading windows for a scientific reason: read too early and you under-count slow growers, read too late and colonies overgrow and merge into uncountable confluence. The reading window is a method parameter, and reading outside it invalidates the result or, worse, produces a wrong result that looks valid. Integrity requires proving each plate was incubated for the right time at the right temperature and read inside the window, and that nothing was nudged to make a count come out a particular way.
What must be controlled and recorded
- Incubation temperature and duration, per the method, with the incubator’s actual conditions documented (chart, datalogger, or qualified monitoring) for the plates in question. A single setpoint label is not evidence; the record of actual temperature over the incubation period is.
- The reading window: the earliest and latest acceptable read times, defined in the method, and the actual read time recorded so window compliance is checkable.
- Incubator qualification and mapping, so the recorded setpoint reflects the temperature the plates actually saw, including any cold or hot spots. See temperature mapping and qualification.
- Door-open and excursion logs, so an incubation interruption is documented rather than silent.
How to operationalize it, step by step
- Define the incubation conditions and the reading window in the method, with explicit earliest and latest read times.
- Record the in and out times for each plate or batch of plates, plus the incubator used.
- Hold the incubator’s actual temperature record (datalogger or qualified monitoring) for the incubation period, and link it to the plates.
- At the read, record the actual read time and confirm it falls inside the window before accepting the count.
- If a plate is read outside the window or experienced an incubation excursion, handle it through deviation management; do not report it as a clean result.
Acceptance criteria
Reading-window control is sound when the method defines incubation conditions and an explicit reading window, every plate’s in/out and read times are recorded and fall within the window (or are deviated if not), the incubator’s actual temperature over the incubation period is documented and within range and linked to the plates, the incubator is qualified and mapped, and any out-of-window read or incubation excursion is captured as a deviation rather than reported as valid.
Worked example
A method specifies incubation at 30 to 35 C for 3 to 5 days, with the plate read on day 3 to 5. A TAMC plate goes in at 09:00 on Monday, and the datalogger shows 31.8 to 33.1 C across the period. The analyst reads it Thursday at 10:30 (day 3, inside the window) and records the read time. Window compliance is provable from the record. Contrast the indefensible case: the same plate read the following Tuesday (day 8), counted as “5 CFU”, with no read-time recorded. The colonies may have overgrown into confluence days earlier; the “5” is meaningless, and the missing read time is the tell.
Roles
Analyst: record in/out and read times, confirm window compliance at the read. Lab supervisor: incubators qualified, mapped, and monitored; window defined in the method. Metrology/engineering: incubator qualification, mapping, and datalogger calibration (see calibration and metrology program). QA: the method, deviation handling for out-of-window reads.
Common 483-type mistakes
- Plates read days outside the defined window, counted, and reported as valid.
- No recorded read time, so window compliance cannot be shown.
- Incubation temperature evidenced only by a setpoint label, with no record of actual conditions over the period.
- Incubator not mapped, so cold spots mean some plates never saw the required temperature.
- Incubation excursions (door left open, power loss) not documented and not assessed for impact.
The Paper-and-Instrument Hybrid Trap
Why it matters
This is the heart of micro data integrity and the single most cited structural weakness. Almost every micro result is a hybrid: a human observation on a paper form, plus one or more instrument records (incubator chart, BET reader file, imaging counter file, particle counter file) sitting alongside. The integrity of the result depends on three things holding: the paper, the instrument data, and the link between them. The trap is that the rich instrument record is generated, then ignored, while a single transcribed number on paper becomes the de facto record, and the electronic original is never reviewed.
The general hybrid problem is covered in hybrid paper and electronic records. Micro is the worst case because the hybrid is unavoidable and the instrument data is often the only objective evidence in an otherwise human record.
Where the seam breaks
- The electronic original is abandoned after transcription. A BET reader produces a full data file; the analyst writes one endotoxin value onto a form; the form is reviewed; the reader file is never looked at again. The audit trail that mattered (the one in the reader software, showing reprocessing or a suppressed failing run) was never reviewed.
- Transcription with no verified check. A number copied from an instrument display to paper with no second-person confirmation against the source is an unverified transcription, and transcription is where digits transpose.
- Orphaned instrument data. The reader, imager, or particle counter logged runs that never appear in any reported result, the micro equivalent of testing into compliance.
- No link between the paper and the file. The form says “endotoxin 0.05 EU/mL” but nothing ties it to a specific reader run, so the reported number cannot be traced back to its source data.
- Instrument audit trails never reviewed. The reader or imaging counter has an audit trail; nobody reviews it; reprocessing or deletions go unseen. See audit trail design and review and operationalizing audit trail review.
How to keep the seam intact, step by step
- Designate, in the method, which record is the original for each result. For BET, the reader’s electronic file is the original; the paper value is a secondary copy. For a manual colony count, the contemporaneous paper count (plus any image) is the original.
- Retain every instrument-generated file as raw data, for as long as the result it supports, in validated storage. Do not discard the reader file once a value is transcribed.
- Require a verified second-person check at every instrument-to-paper hand-off, confirming the transcribed value against the source display or file.
- Bind the paper record to the instrument run: record the run ID, file name, or sequence so the number can be traced to its source.
- Review the instrument audit trail (reader, imager, counter) as part of the result review, not just the headline number, looking for reprocessing, deletions, or suppressed runs.
- Reconcile instrument runs against reported results to catch orphans, the same injection-to-result logic used in chromatography, applied to BET and imaging runs.
Acceptance criteria
The hybrid is defensible when the original record for each result is defined and retained, every instrument file is kept as raw data in validated storage for the result’s full life, each instrument-to-paper transcription has a verified second-person check, the paper record is traceably linked to its source run, the instrument audit trail is reviewed as part of result review, and instrument-run-to-result reconciliation closes to zero unexplained items.
Worked example
A BET run reads four product samples. The reader file shows the standard curve passed, spike recovery was acceptable, and one of four samples initially failed, then was reprocessed with a documented reason and passed on re-evaluation within criteria. The defensible record: the reader file is retained, the reviewer opens it and confirms the reprocess reason and the passing criteria, the reviewer checks the audit trail, and the form carries the run ID and a verified transcription of each value. The indefensible record: the analyst writes the four final values onto a form, the form is reviewed, the reader file is deleted at month end to save disk space, and nobody ever sees that one sample was reprocessed. The reported numbers might be perfectly correct, but the record cannot prove it, and an inspector who finds the deleted-file pattern has a finding regardless.
Roles
Analyst: retain the instrument file, link it to the paper, record the run ID. Reviewer (second person): verify the transcription against the source and review the instrument audit trail, not just the number. System owner/IT: validated, backed-up storage for instrument files; instrument audit trail enabled and immutable. QA: the method defining the original record and the hand-off controls; inspection defense of the hybrid.
Common 483-type mistakes
- Instrument data file discarded after a single value is transcribed to paper.
- BET or imaging reader audit trail never reviewed; reprocessing and deletions invisible.
- Transcription from instrument to paper with no verified second-person check.
- No traceable link from the paper value to the instrument run that produced it.
- Reader runs that never reached a reported result, never reconciled.
Rapid and Alternative Microbiological Methods: New Instruments, the Same Questions
Why it matters
Rapid and alternative microbiological methods, ATP bioluminescence, flow cytometry, impedance, and molecular methods such as PCR-based detection, are displacing or supplementing growth-based testing in some labs, mainly to shorten time to result. USP <1223> Validation of Alternative Microbiological Methods sets the expectation that any such method be demonstrated comparable to the compendial growth-based method it replaces, not simply accepted on a vendor’s validation package. Industry guidance such as PDA Technical Report No. 33 on evaluating, validating, and implementing alternative and rapid microbiological methods, most recently revised in 2026, covers the statistical and practical approach to that comparability work in more depth than this article attempts.
The data integrity picture changes with the method. A colony count puts the burden on a human observation with no re-runnable raw file behind it. A rapid method almost always produces a purely electronic signal, so the integrity questions move entirely onto the instrument: what raw signal was captured, what algorithm or threshold turned that signal into a pass or fail call, whether the raw signal is retained at all, and whether anyone reviews the audit trail when a borderline result gets reprocessed.
Growth-based methods compared with rapid or alternative methods
| Attribute | Growth-based (plate count, turbidity) | Rapid or alternative method (ATP, flow cytometry, PCR-based) |
|---|---|---|
| Primary evidence | The physical plate or tube, destructible, plus an image if one was retained | An electronic raw signal file, retained or discarded depending on how the system is configured |
| Interpretation | Human judgment: colony morphology, turbidity, Gram stain | A software algorithm applied against a validated threshold or cutoff |
| Contemporaneity risk | An analyst transcribing a reading from memory | Low if the instrument timestamps automatically, but the risk shifts to whether the raw signal file is kept at all |
| Verification point | A second analyst recounts the same physical plate | A second reviewer checks the raw signal and the threshold applied, not only the printed pass or fail |
| Validation demand | Method suitability under USP <71> or <61> | A full comparability study against the growth-based reference method under USP <1223> |
| Where the seam breaks | The contemporaneous count is never recorded at the bench | The threshold or algorithm is changed after validation with no change control or re-validation assessment |
| Distinctive 483 risk | Verification performed after the plate was discarded | A borderline signal reported as pass or fail with no retained raw trace for anyone to check the call against |
Acceptance criteria
A rapid or alternative method is defensible when the raw signal data is retained for the full life of the result it supports, comparability to the reference growth-based method is documented under USP <1223> rather than asserted from vendor literature, any change to the threshold or algorithm goes through change control with a documented re-validation assessment, and the instrument’s audit trail, including any manual reprocessing, is reviewed as part of releasing the result, not only consulted when something looks wrong.
Worked example
A rapid sterility screening method flags a sample with a signal close to its validated cutoff. The analyst reprocesses the run with a slightly adjusted gate, and the result flips from a fail to a pass. In the defensible version, the reprocessing reason is recorded, both the original and the reprocessed runs are retained as raw data, and a reviewer opens the instrument’s audit trail and confirms the gate adjustment was within the validated method parameters before accepting the passing result. In the indefensible version, only the passing printout survives, the first, failing run is never mentioned in the record, and the audit trail showing the reprocessing is never opened by anyone before the result is reported.
Roles
Instrument or system owner: retains raw signal data and configures the audit trail to be immutable to ordinary users. Validation: owns the USP <1223> comparability study and the change control trigger for any threshold or algorithm update. Analyst: records the run and any reprocessing reason at the time it happens. QA: reviews the audit trail, including reprocessing and threshold changes, as part of result release.
Common 483-type mistakes
- Raw signal data purged once the interpreted pass or fail result is transcribed or exported.
- A threshold or algorithm change made informally, with no validation impact assessment or change control record.
- Comparability to the compendial reference method asserted from the vendor’s validation package alone, never independently demonstrated at the site.
- The rapid method’s software audit trail never reviewed, the same seam problem covered earlier for BET readers and imaging colony counters.
Roles and Responsibilities Across the Micro Lab
Micro integrity fails where ownership is unclear. Map it explicitly, usually in the data governance framework and the lab procedures.
| Role | Owns |
|---|---|
| Analyst (data originator) | Contemporaneous recording at observation; documented counting method; retaining instrument files; honest readings and recorded reasons for any change |
| Second-person verifier | Independent recount against the plate (not the paper) before discard; verified transcription checks at instrument-to-paper hand-offs |
| Lab supervisor / process owner | A workflow that makes contemporaneous and verify-before-discard physically possible; qualified, independent verifiers; window and incubation control |
| QA | The methods and procedures; review of excursions, positives, and discrepancies; audit-trail review of micro instruments; inspection defense |
| Metrology / engineering | Incubator qualification and mapping; datalogger and instrument calibration; NTP-synchronized instrument clocks |
| IT / system owner | Validated storage for images and instrument files; immutable instrument audit trails; backup and restore proven |
| Validation | Verifying instrument audit-trail configuration and imaging-counter behavior during qualification and after change |
| Growth promotion / media owner | Testing and documenting GPT before lot release; tracing a failed or late lot forward to every affected result |
| Media fill execution team | Contemporaneous reject logging, interim and final reads, intervention logging during the simulation |
| Identification group (internal or outside lab) | Custody log on receipt; identification tied to the unique isolate number; retention of the isolate or extract |
| Rapid/alternative method system owner | Raw signal retention; threshold and algorithm change control; audit trail configuration and review |
The load-bearing segregation in micro: the person who makes the observation cannot be the only person who confirms it, and the person who can administer an instrument’s data store must not be able to silently delete reader files or audit entries. Where small-lab staffing makes full segregation hard, document a compensating control, for example an independent reviewer for any self-verified work and a deleted-files report that QA reviews.
What an Inspector Does in the Micro Lab
Inspectors approach micro with the same instinct they bring to chemistry: find daylight between what the official record says and what the evidence shows. The method is adapted to the hybrid:
- They reconcile the EM plan against executed records, looking for scheduled samples that were never taken or never recorded.
- They reconcile sterility tests started against results reported, hunting for a started-but-vanished test or a positive that became a clean retest.
- They open the instrument records directly (BET reader, imaging counter, particle counter), not the transcribed paper, and read the audit trail for reprocessing, deletions, and suppressed runs.
- They check incubation evidence against the plates: actual temperature over the period, in/out times, read times against the defined window.
- They probe the second-person verification: when was it done, against the plate or against the paper, and was the verifier independent.
- They look for orphaned instrument runs that never reached a result.
- They interview an analyst about a specific plate, count, or BET run they have already spotted, asking for the contemporaneous record and the instrument file on the spot.
The thread is constant: every gap between the paper and the instrument, every observation that cannot be tied to a contemporaneous record, every started test without a result is a potential finding. The FDA inspection readiness and data integrity self-audit checklist articles cover preparing for exactly this.
Worked Example: Following a Contamination Investigation Data Trail, Start to Finish
The sections above cover each control in isolation. In a real investigation they all have to hold together, in sequence, while the evidence is still fresh. The path below is the same one covered piece by piece earlier in this article, laid out as a single sequence.
Walk it end to end on one example. A viable air sample in a Grade B corridor returns 8 CFU against an action level of 5. The analyst retains and photographs the plate before disposal, the same control covered earlier in this article, and a deviation is opened within the hour. Confirming the result is real means checking the session’s negative control (clean), the same-lot plates from other rooms that shift (normal), and the growth promotion record for the media lot (passing, dated before use); nothing points to a lab artifact, so the result stands as a real excursion rather than being waved off.
The recovered colonies are assigned isolate number ISO-2026-0587, Gram-stained the same day (Gram-negative rods, recorded before the isolate is shipped), and sent to the identification group with a signed custody log. Product impact assessment considers which batches had material moving through that corridor during the exposure window, cross-checked against concurrent EM in the adjoining Grade A suite (clean) and the personnel monitoring for staff who transited the corridor that shift. Identification comes back Pseudomonas species, consistent with a water or wet-surface source given the Gram-negative preliminary call, which points the root cause investigation toward drains, sinks, or a wet mop head rather than toward gowning. Root cause lands on a floor drain trap that had run dry, allowing a path for organisms normally sealed off; the fix is a revised drain-flushing schedule plus a design change to prevent the trap running dry between shifts. Enhanced monitoring at the corridor site for the following weeks returns clean, and the deviation closes with every step, from the retained plate through the identification chain of custody to the verified fix, standing on its own contemporaneous record.
Notice what makes this defensible end to end: nothing was reconstructed from memory at any step, the isolate’s identity pointed the investigation in a specific, falsifiable direction rather than a generic one, and the closure rests on a verification result, not on an assumption that the fix probably worked.
Interview Questions and How to Answer Them
Expect these in a micro, QC, or data integrity interview, and from inspectors.
“Why is data integrity harder in micro than in chemistry?” The primary measurement is a destructive, time-bound human observation with no re-runnable raw file, the result is human judgment rather than instrument output, there is long latency between the work and the final read, and almost every result is an unavoidable hybrid of paper and instrument data. The contemporaneous record is often the only record.
“What makes a manual colony count defensible?” A documented counting method so the number is reproducible, contemporaneous recording by the counter, and an independent second-person verification against the plate (not the written number) before the plate is discarded, with discrepancies beyond tolerance resolved and documented against the physical plate.
“A second analyst signed to verify a count yesterday, but the plate was already discarded. What is the problem?” That is verification of a number against nothing. It confirms the second person can read the first person’s writing, not that the count was right. Verification must happen against the plate or a retained image while the evidence still exists.
“What is the reading window, and why does it matter for integrity?” The defined earliest and latest acceptable read time for an incubated plate. Read too early and slow growers are undercounted; too late and colonies overgrow into confluence. A count read outside the window is invalid or wrong, so the actual read time must be recorded and shown to fall inside the window, with the incubator’s actual temperature documented for the period.
“Walk me through the hybrid trap in BET.” The reader produces a full electronic file (standard curve, spike recovery, sample values, audit trail). The trap is transcribing one value to paper, reviewing the paper, and ignoring or deleting the reader file. The file is the raw data and must be retained and reviewed, the transcription must be verified, the paper must link to the run, and the reader audit trail must be reviewed for reprocessing and deletions.
“How would you detect testing into compliance in micro?” Reconcile sterility tests started against results reported and observed positives against documented outcomes; reconcile the EM plan against executed records; reconcile instrument runs (BET, imaging) against reported results. Any started test, scheduled sample, observed positive, or instrument run that does not map to a documented outcome is an orphan to run down.
“What is the original record for a manual colony count, and for a BET result?” For a manual count, the contemporaneous paper count plus any retained image. For BET, the reader’s electronic file. Defining which record is the original, and retaining it for the result’s full life, is the first step in keeping the hybrid defensible.
“How do you prove a plate was incubated correctly?” The incubator is qualified and mapped, the actual temperature over the incubation period is recorded by a datalogger or qualified monitoring and linked to the plates, the in/out and read times are recorded, and any incubation excursion is captured as a deviation rather than ignored.
“What is growth promotion testing, and why does it matter for data integrity?” It is the test proving a lot of media can actually support growth of a low inoculum of reference organisms before that lot is used for EM, bioburden, or sterility testing. The integrity risk is a lot used before its GPT result is available, or a failed lot whose results were never traced forward to the tests it already supported; the lot number has to be recorded on every test record it touches so that trace is always possible.
“How is a media fill’s data different from a routine EM or bioburden record?” It depends on unit-level accountability across thousands of units rather than a single count: filled, incubated, and rejected units all have to reconcile, every rejection needs a contemporaneous documented reason, and interim reads across the full incubation period matter as much as the final read, because a fill inspected only at the end cannot show when turbidity actually appeared.
“Why does isolate chain of custody matter if the identification result comes back clean?” Because the identification result is only trustworthy if it can be traced back to the specific plate and sample it came from. A clean or reassuring identification with no traceable chain is unverifiable, which in an inspection reads the same as a result that might have been shopped for.
“What changes about data integrity when a lab moves to a rapid or alternative microbiological method?” The evidence stops being a physical, human-read plate and becomes an electronic signal interpreted by an algorithm. The integrity questions move to whether the raw signal is retained, whether the method has been shown comparable to the growth-based reference method it replaces (USP <1223>), and whether the instrument’s audit trail, including any reprocessing or threshold change, is actually reviewed.
Common 483 and Inspection Findings in Microbiology QC Data Integrity, in One Place
The mistakes are scattered through the sections above by topic. Here they are gathered as a single quick-reference list, the kind worth rereading the morning of an inspection.
- Plate counts written on scratch paper or a sticky note at the bench, then transcribed to the official form later, so the form is a copy of a copy.
- Incubator temperature excursions recorded in a utility log that is never cross-referenced to the specific plates or units that were inside the chamber at the time.
- Incubation start or read times estimated or backdated to make a result appear to fall inside the defined reading window.
- Environmental monitoring reported with only the passing plates transcribed to the summary, while an excursion sits in the raw bench sheet, unescalated.
- Colony counts recorded and signed by a single analyst with no independent second-person verification, or verification performed after the plate was already discarded.
- A repeat plating performed and the first, unfavorable count discarded, with no record that a repeat happened or why.
- A sterility or EM result invalidated as “probable lab error” with no objective, documented assignable cause.
- An isolate discarded before identification, or identified but never linked back to the plate and sample it came from.
- Growth promotion testing performed after a media lot was already used, or a failed lot’s results never traced forward to the tests it supported.
- Media fill unit counts that do not reconcile: units filled, incubated, and rejected do not add up, and the gap is never explained.
- Instrument audit trails (BET reader, imaging colony counter, rapid method platform) never opened as part of result review.
This section is intentionally a flat list rather than another table, since these are close to the sentences an inspector actually writes on a Form 483, and reading them in one place is more useful than finding them spread across a report.
Runnable Checklist: A Twenty-Point Micro Data Integrity Walkthrough
Use this on the bench or in self-inspection prep. Each unchecked item is a gap to close before an inspector finds it.
Recording and counting
- Every colony count was written at the reading station at the moment of observation, not from memory later.
- A documented counting method exists and is followed for handling merged, confluent, and too-numerous-to-count plates.
- Second-person verification happened against the physical plate or a retained image, before the plate was discarded.
- Discrepant counts were resolved against physical evidence, and the resolution is documented.
Retention and imaging
- Plates requiring an image (excursions, near-limit counts, sterility positives, recovered isolates) were actually photographed.
- Retained images are named and stored so they tie unambiguously to plate, sample, date, and analyst.
- The image store is access-controlled, backed up, and a restore has been proven.
Incubation and reading windows
- Incubator temperature over the incubation period is documented by datalogger or qualified monitoring, not a setpoint label alone.
- Every plate’s actual read time is recorded and falls inside the defined reading window.
- Incubation excursions (door open, power loss) are captured as deviations, not silently absorbed.
Growth promotion and media
- No media lot was used before its growth promotion result was available and passing.
- The media lot number used is traceable forward to every test record it supports.
EM, bioburden, sterility, endotoxin, media fill
- The EM sampling plan reconciles against the executed records with no unexplained missed sites.
- Sterility tests started reconcile against results reported, with every positive accounted for.
- The BET reader’s raw electronic file is retained and reviewed, not just the transcribed value.
- Media fill unit counts reconcile: filled equals incubated plus documented rejects, with no unexplained gap.
Identification and the hybrid seam
- Every reportable isolate carries a unique ID traceable back to its originating plate.
- Instrument audit trails (imaging counter, BET reader, rapid method platform) are reviewed as part of result review, not left unopened.
- No instrument run exists with no corresponding reported result (the orphan check).
Governance
- Roles for contemporaneous recording, second-person verification, and audit-trail review are named, not assumed.
Ready-to-Use Templates for This Article
These controls are only as good as the documents that operationalize them at the bench. Five ready-to-use templates build directly on this article: the SOP: Data Integrity Controls for Manual Microbiological Plate Reading and Counting, the Work Instruction: Environmental Monitoring Excursion Data Trail Documentation, the Log: Microbiology Laboratory Contemporaneous Data Recording Log, the Risk Assessment: Microbiology QC Data Integrity Gap Assessment, built on the same methodology as the site’s DI gap assessment methodology, and the Checklist: Microbiology Data Integrity Self-Inspection Checklist.
The Durable Principle
A micro result rests on an observation that cannot be repeated and a record that is half human and half machine. The integrity question is always the same: can you prove, from the record alone, what was actually observed, by whom, at the correct time and incubation, confirmed independently before the evidence was gone, with every instrument file that supports the result retained and reviewed. If you can answer that for any EM plate, any bioburden count, any sterility observation, and any endotoxin run, the lab is defensible.
The recurring failure is treating the paper number as the record and the instrument file as a printout to be discarded, or treating the second-person check as a signature rather than an independent look at the plate. Both are seams, and inspectors go straight for the seam. Build the record around the original (the contemporaneous count, the image, the reader file), keep the seam between paper and instrument intact, and verify against the physical evidence while it still exists. The plate will not be there tomorrow to prove you right.