This is a ready-to-use protocol for the planned, retrospective data integrity audit that a cell or gene therapy sponsor runs on its development and clinical manufacturing data before filing a Biologics License Application. The point is to find the gaps before FDA does, score each one, and either remediate it or write a defensible justification, so data integrity becomes part of the inspection story rather than a liability discovered during it. Replace every <<FILL: ...>> placeholder, set your document numbers and dates, and route it through document control and approval. A filled specimen follows. Verify each cited regulation against the current source. This is general guidance to adapt, not legal or regulatory advice.
Approval page
| Role | Name | Signature | Date |
|---|---|---|---|
| Author (Data Governance / QA) | <<FILL>> | ||
| Reviewer (QC / Analytical) | <<FILL>> | ||
| Reviewer (Regulatory / CMC) | <<FILL>> | ||
| Approver (Quality Head) | <<FILL>> |
| Field | Entry |
|---|---|
| Protocol number | <<FILL: PROT-ID, e.g. DI-BLA-001>> |
| Version | <<FILL: 1.0>> |
| Product / program | <<FILL: product, no proprietary code>> |
| Target filing window | <<FILL: quarter / year>> |
1. Objective
To assess, against ALCOA+, the integrity of the analytical and manufacturing data generated across development and clinical manufacturing that will support the BLA for <<FILL: PRODUCT>>, to identify and rank every gap, and to disposition each gap by remediation or documented, science-based justification before filing.
2. Background and rationale
Cell and gene therapy sponsors at first BLA rarely have a single mature commercial process behind their data. The product may have been made under several protocol versions, analytical methods may have evolved, some data may have originated at clinical sites or contract organizations of varying maturity, and the commercial process may differ from the clinical process. The filing is a forcing function: all of that data must be reviewable, attributable, and internally consistent on request. This protocol makes the review a scheduled quality activity rather than a fire drill in the final months.
3. Scope
In scope: every critical result type feeding the submission, across every process and method version used, at every site (internal and contract) that generated it. As a minimum:
- Potency, viability, and identity results supporting lot disposition or comparability.
- Vector genome titer, transduction, and residual-impurity results.
- Sterility, endotoxin, and mycoplasma results.
- The manufacturing records (batch records, in-process data) tied to each lot in the submission.
- Chain-of-identity and chain-of-custody records for patient-specific material.
Out of scope: <<FILL: anything explicitly excluded, with rationale, e.g. non-GMP research characterization not cited in the filing>>.
4. Approach and roles
A cross-functional team reviews each critical result type against the questions in section 5, records findings in the gap register (section 7), scores each gap (section 6), and assigns a disposition. QA owns the protocol and the final gap list; analytical and CMC SMEs provide the technical judgment; regulatory confirms which data actually feeds the submission.
| Role | Responsibility |
|---|---|
| Data governance lead | Runs the audit, owns the gap register and schedule. |
| QC / analytical SME | Judges recoverability and reliability of each result type. |
| CMC / regulatory | Confirms which results feed the BLA and the impact of each gap. |
| QA | Approves scoring and dispositions, gates the “ready to file” decision. |
5. Review questions (applied to each critical result type)
For each critical result type, and for each process/method version, answer:
- Does the original raw data still exist and is it readable today (not only a summary or printout)?
- Can each result be tied to a specific instrument run, method version, and named analyst?
- Is the audit trail for the generating system retained for the period, or was it never captured?
- Does every invalidated, repeated, or reprocessed result have a contemporaneous reason recorded?
- For data generated before a given control existed, what control was in place instead, and why is the data still trustworthy?
- Are results consistent internally and with the manufacturing record they belong to?
6. Gap scoring and disposition scheme
Rank each gap so effort goes where the risk is.
| Dimension | Question | Scale |
|---|---|---|
| Impact | Does the gap affect a result that feeds the BLA? | Yes (higher) / No (lower) |
| Recoverability | Is the original data recoverable? | Yes / Partial / No |
| Risk rank | Combined judgement | High / Medium / Low |
Disposition rules:
- High (feeds the BLA, data not or only partly recoverable): remediate if possible; otherwise a written, science-based justification using corroborating or downstream comparability data, plus a forward commitment. No high-risk gap may be left undispositioned at filing.
- Medium: remediate (revalidate, re-verify affected results) on a defined timeline.
- Low: note, monitor, and fix procedurally going forward.
7. Output: ranked gap register
| Gap ID | Result type / system | Feeds BLA? | Original recoverable? | Risk rank | Disposition | Owner | Due |
|---|---|---|---|---|---|---|---|
<<FILL>> | <<FILL>> | <<FILL: Y/N>> | <<FILL: Y/Partial/N>> | <<FILL: H/M/L>> | <<FILL>> | <<FILL>> | <<FILL>> |
8. Acceptance criteria
- Every critical result type has been reviewed across every process and method version and site.
- Every gap is scored and has a disposition.
- Every high-risk gap is either remediated or carries a written, science-based justification a reviewer would accept, and none is left open at filing.
- The gap register and dispositions are QA-approved and retained as part of the inspection file.
9. Deviation handling
Any inability to complete a review line (for example data that cannot be located at all) is itself recorded as a gap and dispositioned; it does not silently drop out of scope.
10. Summary and conclusion
On completion, the team issues a summary that states the population reviewed, the gaps found by risk rank, the dispositions, and the residual risk carried into the filing, approved by QA. <<FILL: summarise at close>>.
11. References
21 CFR 211.194 (completeness of laboratory records), 211.180 (records retention). 21 CFR Part 11 (electronic records; audit trails). 21 CFR Part 1271 (HCT/P tracking and labeling, where applicable). FDA guidance, Data Integrity and Compliance With Drug CGMP (2018). PIC/S PI 041, Good Practices for Data Management and Integrity. ICH Q9(R1), Quality Risk Management (for the risk ranking).
Confirm the current version of each reference before issue.
Filled specimen
An illustrative extract of a completed gap register. IDs and dispositions are examples; replace with your own.
| Gap ID | Result type / system | Feeds BLA? | Original recoverable? | Risk rank | Disposition | Owner | Due |
|---|---|---|---|---|---|---|---|
| G-01 | Early clinical CDS audit trail not retained (release assay) | Y | Partial (paper printouts only) | High | Risk assessment plus corroborating batch records; retained audit trails committed going forward | QA | 2026-09-30 |
| G-02 | Potency calculation spreadsheet not version-controlled | Y | Y (raw values exist) | Medium | Revalidate spreadsheet, re-verify affected results | Analytical | 2026-08-15 |
| G-03 | Legacy phenotype instrument, data now unreadable | Y | N | High | Documented justification using downstream comparability; flagged as a known limitation | CMC | 2026-09-30 |
| G-04 | Reagent-lot traceability missing, non-critical assay | N | Y | Low | Note and monitor; procedural fix going forward | QC | 2026-10-31 |
In this extract, two high-risk gaps drive real work: one gets a risk assessment with corroborating records, one gets a science-based justification because the data cannot be recovered. Neither is left open. That ranked, dispositioned list is what turns an inspection question into a prepared answer.
Common inspection findings this protocol prevents
- Raw data from early clinical manufacturing that cannot be located, read, or attributed, discovered during the inspection.
- Audit trails that were never retained for systems whose results feed the submission.
- Reprocessed or invalidated results with no contemporaneous reason, found at the bench by an inspector.
- A “we think it is fine” answer with no documented, ranked assessment behind it.
How to adapt this protocol
- Set the product, filing window, and document numbers.
- Tailor the scope list in section 3 to your actual critical result types and sites, including every contract organization.
- Adjust the scoring dimensions to match your quality risk framework if it differs.
- Start the audit years before filing, ideally as a standing periodic self-audit, so gaps surface while they are still fixable.
- Confirm every regulation in section 11 against the current published version before issue.