Independent and not affiliated with the FDA, MHRA, ISPE, PDA, or any agency. Get the appgoutham@madhadi.com
madhadi.comData Integrity & GxP Quality
Browse all topics → Articles Templates & Procedures Learning paths GlossaryScenariosToolsRegulatory ReferencesLearning PathsTopics About Start here
SOP Plug-and-play starting point Audits & Inspection

SOP: GxP Audit Finding Classification and Grading

A plug-and-play standard operating procedure for grading audit and inspection findings as critical, major, or minor: the definitions, the grading decision path, the aggregation rule, escalation triggers by grade, and calibration, with a filled specimen and the regulations it satisfies.

Document type: SOP

Read and copy the template below into your own quality system. It is a generic starting point for your own internal use, provided as is, with no warranty; see the Terms and License. Adopting it does not by itself create compliance.

This is a ready-to-use SOP. Replace every <<FILL: ...>> placeholder with your own specifics, set your document numbers and dates, and route it through your normal document control, review, and approval. A worked filled specimen follows the template so you can see how a completed version reads. This content is educational reference, not legal or regulatory advice; verify each cited regulation against the current source and confirm your internal grading is no looser than the regulatory definitions for your audit type before you rely on it.

Document control header

FieldEntry
Document titleGxP Audit Finding Classification and Grading
Document number<<FILL: SOP-ID, e.g. SOP-QA-021>>
Version<<FILL: version, e.g. 1.0>>
Effective date<<FILL: effective date>>
Supersedes<<FILL: prior version or "New">>
Document owner<<FILL: role, e.g. Head of Quality Assurance>>
Applies to<<FILL: audit types / sites in scope>>

1. Purpose

This procedure defines how <<FILL: COMPANY NAME>> grades findings from internal audits, supplier audits, and self-inspections into consistent tiers, so that the grade reliably signals risk, drives proportionate corrective action, and holds up when a regulator later reads the audit file. It exists to make grading reproducible across auditors and defensible to auditees.

2. Scope

This procedure applies to findings raised during <<FILL: audit types, e.g. internal GxP audits, supplier/vendor audits, self-inspections, for-cause audits>>. It does not govern the grading of externally issued regulatory observations (for example an FDA Form 483 or an inspection deficiency), which are handled under <<FILL: SOP-ID for regulatory inspection response>>, though this SOP’s tiers may be used to triage them internally. Corrective and preventive action after a finding is governed by <<FILL: SOP-ID for CAPA>>.

3. Responsibilities

RoleResponsibility
Lead auditorOwns the final grade of each finding; ensures every finding carries requirement, condition, evidence, and consequence; applies the definitions consistently; resolves grading disputes within the audit team.
Audit team member / SMEIdentifies the technical nonconformity, supplies the subject-matter consequence, helps establish spread and severity.
Auditee / process ownerConfirms or corrects the factual condition during the audit; does not decide the grade of a finding against their own area; owns root cause and corrective action afterward.
Quality Assurance / audit program ownerMaintains these definitions and the grading standard; reviews critical and major findings before escalation; runs calibration; keeps grading consistent over time.
Senior / receiving managementReceives critical-finding escalation within the defined window; makes the business decisions the grade triggers.

4. Definitions

  • Critical finding: a departure from a requirement that has produced, or realistically could produce, product or a clinical situation capable of harming a patient or trial subject, or that involves falsification, fraud, or fabrication of data or product. A single instance is sufficient.
  • Major finding: a non-critical departure that could let product leave in a state not matching its authorized description, or that reflects a systemic breakdown of a required process or release control, or an aggregation of related minor findings that together show a process out of control.
  • Minor finding: a genuine, evidenced departure from a requirement that is isolated and low in consequence and does not indicate a broken system.
  • Observation / opportunity for improvement (OFI): a compliant condition that could be improved, or a risk that is not yet a requirement gap. No CAPA is required.
  • Objective evidence: records, artifacts, or observed conditions with enough identifiers (document/version, batch/lot, page/line, timestamp, system/equipment ID) that a second person could relocate them.
  • Aggregation: combining several related minor findings into one major finding when together they demonstrate a systemic failure.

5. Procedure

5.1 Confirm a real nonconformity exists

Before grading, confirm there is an actual requirement (a regulation clause, standard section, or the auditee’s own SOP step) and that it is genuinely not met, supported by objective evidence you can relocate later. If you cannot name the breached requirement, you have a question or an observation, not a finding.

5.2 Pin the objective evidence and establish spread

Record the identifiers of the evidence before leaving the area or screen. Then determine whether the issue is isolated or a pattern by pulling additional samples on the spot; the minor/major line usually turns on spread, which can only be assessed with access.

5.3 Grade using the decision path

Apply the tiers in order and stop at the first that fits:

  1. Falsification/fraud/fabrication, or direct risk of harm to a patient or subject? Grade Critical.
  2. Systemic process breakdown, deviation from the marketing authorization or validated process, failed release control, or an aggregation of related minors? Grade Major.
  3. Genuine but isolated, low-consequence departure that does not show a broken system? Grade Minor.
  4. Compliant but improvable, or a not-yet-requirement risk? Record as Observation / OFI (no CAPA).

Test critical before major and major before minor, so a falsification is never caught in the minor net and aggregation is considered before you settle for a single minor.

5.4 Apply the aggregation test

Where several related minor findings exist (for example the same documentation lapse across departments), assess whether together they show the underlying system is not in control. If so, raise one major finding and reference the constituent observations rather than listing isolated minors.

5.5 Write the finding with all four parts

Every finding states: the requirement (specifically cited), the condition (the factual, verifiable observed state), the objective evidence (artifacts with identifiers), and the consequence (the link to patient/subject safety, product quality, or data reliability, from which the grade follows). Do not embed the fix and do not speculate about intent beyond what the evidence supports.

5.6 Lead-auditor and QA review

The lead auditor reviews every finding for the four parts and grade consistency. QA reviews all critical and major findings before they trigger escalation or leave the report. Where the internal grading matrix would downgrade a falsification below critical, the matrix does not override this SOP.

5.7 Escalate by grade

Escalate and set response commitments according to the table in section 6. Critical findings are notified to senior management and QA within <<FILL: number>> hours and require interim containment where product or subjects are exposed.

6. Acceptance criteria

A graded finding is acceptable when all of the following are true:

  • The requirement is cited specifically (clause, section, or SOP step and version), not by a vague principle.
  • The condition is verifiable by a second person from the identifiers given.
  • Objective evidence is recorded as artifacts, not impressions.
  • The consequence ties to a protected interest and the grade follows from it.
  • The grade matches both the applicable framework and this SOP, with no looser-than-regulation grading.
  • Spread was assessed and aggregation considered for repeated minors.
  • The finding is factual and neutral, embeds no solution, and speculates no intent beyond the evidence.
  • Two competent auditors reading the same evidence would reach the same grade.

Grade-to-response commitments

GradeAcknowledge / respond byInterim containmentRoot cause + CAPAEscalationCAPA closure target
Critical<<FILL: e.g. same day to 3 days>>Required immediately where product/subjects exposedFull documented root cause + impact assessmentSenior management + QA within <<FILL: hours>>; regulator where required<<FILL: e.g. days to weeks>>, effectiveness check mandatory
Major<<FILL: e.g. 15 to 30 days>>Case by caseDocumented root cause + effectiveness checkQA program owner before closure<<FILL: e.g. 30 to 90 days>>
Minor<<FILL: e.g. 30 days>>Rarely neededCorrection, optional lightweight actionNone routine<<FILL: e.g. 60 to 90 days>>
Observation / OFILogged, no committed dateNoneNoneNoneTracked or closed at discretion

7. Calibration

At least <<FILL: frequency, e.g. annually>>, auditors grade a common set of <<FILL: number, e.g. 5>> historical scenarios independently, then reconcile differences to the correct grade and adjust the definitions or anchored examples that allowed the spread. Calibration records are retained per section 9.

8. References

21 CFR Part 11; 21 CFR 211 (as applicable to GMP records and laboratory controls). EU GMP, including Annex 11 (computerised systems) and the deficiency classification principles used by EU/PIC/S inspectorates. PIC/S PI 040, Guidance on Classification of GMP Deficiencies. ICH Q9 (R1), Quality Risk Management (risk-based severity vocabulary). ICH E6 (R2)/(R3), Good Clinical Practice (for GCP audit grading). ISO 19011 and ISO/IEC 17025 (management-system and laboratory audit terminology). ISPE GAMP 5 (Second Edition) (for computerized-system and data-integrity findings).

Confirm the current version and clause numbers of each reference before issue.

9. Records generated

  • Graded finding records (per audit report), retained not less than <<FILL: retention period>>.
  • Calibration session records.
  • Escalation notifications for critical findings.

10. Revision history

VersionDateAuthorSummary of change
<<FILL: 1.0>><<FILL: date>><<FILL: author>>Initial issue.

11. Approvals

RoleNameSignatureDate
Author<<FILL>>
Reviewer (QA)<<FILL>>
Approver (Quality Head)<<FILL>>

Filled specimen

The following shows how a single finding is graded and recorded under this SOP. The company, systems, and numbers are illustrative; replace them with your own.

Scenario. During an internal QC laboratory audit, the auditor samples four finished-product batch records and finds that the chromatography data system audit trail review was documented after the batch disposition decision in three of the four.

ElementEntry
Finding ID / gradeINT-2026-019 / Major
RequirementEU GMP Annex 11 paragraph 9 and site SOP-QC-114 v4 step 6.2 require audit trail review prior to batch disposition.
ConditionIn three of four sampled batch records (lots A231, A239, A241), the CDS audit trail review was dated later than the disposition decision.
Objective evidenceDisposition signatures dated 2026-03-02, 2026-03-09, 2026-03-15; corresponding review checklists FRM-114-01 dated 2026-03-04, 2026-03-11, 2026-03-18; confirmed on screen in the CDS audit trail; audit note AN-07.
ConsequenceA required release control operated after the release decision it informs, across most of the sample, so the release-control process is not functioning as designed. No patient harm shown.
Grade rationale (decision path)Not falsification/no direct patient harm shown (not critical); systemic failure of a release control across the sample (major); not isolated (not minor).
Spread / aggregation3 of 4 sampled; pattern, not a one-off.
Escalation / responseQA program owner review; response plan within 30 days; root cause + effectiveness check; CAPA target 90 days.

In this example the grade follows directly from the consequence sentence, every element points at a relocatable artifact, and the decision path shows why it is a major and not a minor or a critical. That traceability is what makes the grade hold up when challenged.

Common inspection findings this SOP prevents

  • Internal audits that graded a real problem below its risk (deflation), so escalation and CAPA rigor never triggered.
  • Findings with no cited requirement, no relocatable evidence, or no consequence statement, which the auditee waved away.
  • Twelve isolated minors listed with no one stepping back to see the systemic major (missed aggregation).
  • The same gap graded differently by different auditors, with no calibration.
  • The auditee negotiating the grade down to ease their own remediation burden.

How to adapt this SOP

  1. Set your document number, owner, and effective date in the header.
  2. Confirm the reference list in section 8 matches your audit types (drop GCP or ISO rows if not applicable, keep the GMP set for manufacturing).
  3. Set the concrete numbers in the grade-to-response table (section 6) against your risk appetite and existing CAPA SOP timelines.
  4. Point the cross-references in section 2 to your real CAPA and inspection-response procedures.
  5. Confirm every regulation in section 8 against the current published version before issue.
Use madhadi.com as an app Full screen, works offline, one tap from your home screen.