Independent and not affiliated with the FDA, MHRA, ISPE, PDA, or any agency. Get the appgoutham@madhadi.com
madhadi.comData Integrity & GxP Quality
Browse all topics → Articles Templates & Procedures Learning paths GlossaryScenariosToolsRegulatory ReferencesLearning PathsTopics About Start here
Report Plug-and-play starting point Data Integrity

Report: Data Integrity Self-Audit Summary Report

A plug-and-play summary report for a completed data integrity self-audit: scope and sampling basis, findings by severity and layer, systemic-versus-isolated read, remediation timelines, and the overall conclusion an inspector or management review can rely on, with a filled specimen.

Document type: Report

Read and copy the template below into your own quality system. It is a generic starting point for your own internal use, provided as is, with no warranty; see the Terms and License. Adopting it does not by itself create compliance.

This is a ready-to-use report template. Replace every <<FILL: ...>> placeholder with your own specifics and route through your normal audit and management review process. A worked filled specimen follows the template. Verify each cited regulation against the current source before you rely on it.

Report header

FieldEntry
Report titleData Integrity Self-Audit Summary Report
Report number<<FILL>>
Systems / areas audited<<FILL>>
Audit period covered<<FILL: from>> to <<FILL: to>>
Audit dates<<FILL>>
Lead auditor<<FILL>>
Audit sponsor<<FILL>>

1. Scope and sampling basis

<<FILL: name the systems and time window audited, the sample size and how it was selected (random plus targeted, with the targeting rationale), and the depth of review applied to each system>>. State explicitly why this scope is defensible, not merely convenient.

2. Method

This audit followed the five-layer method (infrastructure controls, system configuration, procedural controls, work practice verification, culture indicators) described in Data Integrity Self-Audit: A Compliance Checklist, using the paired five-layer field checklist as the working instrument. <<FILL: note any deviation from the standard method and why>>.

3. Findings summary

LayerItems assessedPassFailNAFindings raised
1. Infrastructure<<FILL>><<FILL>><<FILL>><<FILL>><<FILL>>
2. System configuration<<FILL>><<FILL>><<FILL>><<FILL>><<FILL>>
3. Procedural controls<<FILL>><<FILL>><<FILL>><<FILL>><<FILL>>
4. Work practice<<FILL>><<FILL>><<FILL>><<FILL>><<FILL>>
5. Culture indicators<<FILL>><<FILL>><<FILL>><<FILL>><<FILL>>

4. Findings detail

For each finding, state it in the defensible form: named system, stated requirement, quantified sample, the specific gap, the risk it creates, the regulation it maps to, and the recommended action.

#FindingSeveritySystemic / IsolatedRegulatory referenceRecommended actionCAPA reference
<<FILL>><<FILL>>Critical/Major/Minor<<FILL>><<FILL>><<FILL>><<FILL>>

5. Systemic pattern assessment

<<FILL: state whether any weakness recurs across layers (for example a configuration gap plus a matching work-practice gap on the same control), which is a stronger signal than either finding alone, per the pattern discussion in the source article>>.

6. Repeat-finding check

<<FILL: state whether any finding in section 4 also appeared in a prior audit cycle. A repeat finding is reclassified as a CAPA-effectiveness failure, not a fresh observation, and the prior root-cause work is reopened>>.

7. Remediation timeline

SeverityTarget timelineOwner
CriticalImmediate stop/escalate; impact assessment in parallel with root cause<<FILL>>
Major30 to 60 days<<FILL>>
Minor90 to 120 days<<FILL>>

8. Overall conclusion

<<FILL: state the overall conclusion, honestly. A clean result should be accompanied by a statement of confidence in the audit's own depth and independence, not presented as proof of a perfect program>>.

9. Distribution

<<FILL: management review, QA leadership, system owners, and any other required recipient>>.

References

FDA Data Integrity and Compliance With Drug CGMP guidance (December 2018). MHRA GxP Data Integrity Guidance and Definitions (March 2018). Audit finding classification for the severity grading logic used above.

Confirm the current version of each reference before issue.


Filled specimen (excerpt)

Scope and sampling basis: Chromatography data system CDS-HPLC-07 and its associated LIMS interface, January through June 2026. Sample: 15 of 612 analytical sequences (10 random, 5 targeted around OOS events), plus a full-population review of audit trail review records for the period.

Findings summary (excerpt):

LayerItems assessedPassFailFindings raised
2. System configuration7611 (audit trail review not performed)
4. Work practice5411 (undisposed injections preceding a reported result)

Finding (excerpt):

Finding 1 (Major, systemic): Audit trail review was not performed for CDS-HPLC-07 from January through June 2026. Procedure QC-014 requires documented review at each batch disposition. A sample of 12 disposition packages showed no audit trail review record in any of the 12. Risk: changes to integration or results between acquisition and reporting would not have been detected at review. Regulatory reference: FDA Data Integrity and CGMP guidance (December 2018); EU GMP Annex 11 clause 9. Recommended action: root cause and CAPA, retrospective review of the affected period’s audit trails, assessment of product impact. CAPA-2026-0089.

Overall conclusion (excerpt): Two findings raised, one Major (systemic) and one Major (isolated, referred for deeper record forensics per the source checklist’s work-practice method). No repeat findings from the prior cycle. Both CAPAs opened with the timelines in section 7. The audit is assessed as adequately independent and sufficiently deep to be relied on for the current inspection-readiness posture; the retrospective review triggered by Finding 1 is the item to track to closure before the next management review.

Common inspection findings this report prevents

  • A self-audit “passed” with no findings and no visible evidence the audit looked hard enough to find any.
  • Findings written as opinions (“needs improvement”) rather than in the defensible form with a named record and a regulatory reference.
  • A report that never states whether a finding is a repeat, letting a CAPA-effectiveness failure hide as a fresh observation year after year.

How to adapt this report

  1. Pair this report with the five-layer field checklist as the source data; this report is the synthesis, the checklist is the working evidence.
  2. Set your severity and timeline conventions in sections 4 and 7 to match your internal audit program if it defines its own.
  3. Route section 9 distribution to match your actual management review structure so DI findings genuinely reach the top of the quality system, not just the audit file.
Use madhadi.com as an app Full screen, works offline, one tap from your home screen.