Independent and not affiliated with the FDA, MHRA, ISPE, PDA, or any agency. Get the appgoutham@madhadi.com
madhadi.comData Integrity & GxP Quality
Browse all topics → Articles Templates & Procedures Learning paths GlossaryScenariosToolsRegulatory ReferencesLearning PathsTopics About Start here
SOP Plug-and-play starting point Data Integrity

SOP: Hybrid Paper-and-Electronic Record Control and Reconciliation

A plug-and-play SOP for controlling hybrid records: declaring the governing raw record, reconciling the paper and electronic halves, reviewing the audit trail, handling corrections across the seam, and escalating discrepancies, with a filled specimen.

Document type: SOP

Read and copy the template below into your own quality system. It is a generic starting point for your own internal use, provided as is, with no warranty; see the Terms and License. Adopting it does not by itself create compliance.

This is a ready-to-use SOP. Replace every <<FILL: ...>> placeholder with your own specifics, set your document numbers and dates, and route it through your normal document control, review, and approval. A worked filled specimen follows the template. Verify each cited regulation against the current source before you rely on it, and adapt the procedure to your own processes and regulatory context.

Document control header

FieldEntry
Document titleHybrid Paper-and-Electronic Record Control and Reconciliation
Document number<<FILL: SOP-ID, e.g. SOP-QA-031>>
Version<<FILL: version, e.g. 1.0>>
Effective date<<FILL: effective date>>
Supersedes<<FILL: prior version or "New">>
Document owner<<FILL: role, e.g. Head of Quality Assurance>>
Applies to<<FILL: sites / departments in scope>>

1. Purpose

This procedure defines how <<FILL: COMPANY NAME>> identifies, declares, controls, and reconciles hybrid records, meaning records where the complete account of a GxP activity exists partly in an electronic system and partly on paper and both halves are needed to reconstruct the activity. The objective is to ensure that the governing original record is defined and preserved, that the two halves cannot silently diverge, and that any discrepancy is detected and dispositioned before the record is used to support a decision.

2. Scope

This procedure applies to all GxP hybrid records created at the sites listed in the header, across laboratory, manufacturing, engineering, warehouse, and quality operations. It covers the three hybrid patterns: electronic generation with paper review and signature; paper generation with electronic storage or summary; and split-field records where some fields exist only on one half.

It does not replace: audit trail review, governed by <<FILL: SOP-ID for audit trail review>>; batch record review, governed by <<FILL: SOP-ID for batch record review>>; records retention and destruction, governed by <<FILL: SOP-ID for retention>>; or deviation management, governed by <<FILL: SOP-ID for deviations>>. Where this procedure and a system-specific method conflict, the more stringent control applies and the conflict is raised to the document owner.

3. Responsibilities

RoleResponsibility
Process / system ownerMaintains the hybrid entry in the inventory and its system description; confirms the declared governing record; ensures reconciliation controls operate; owns open remediation actions.
Operator / analystExecutes the activity; records contemporaneously on both halves; transcribes the machine-generated identifier accurately; reports any discrepancy at the point it is noticed rather than resolving it privately.
Reviewer (second person)Performs reconciliation per section 5.4 including audit trail review; verifies transcriptions; dispositions or escalates every exception; signs with the defined meaning.
Quality AssuranceApproves the governing-record declaration; approves this procedure and system descriptions; classifies discrepancies; approves the migration plan; audits hybrid controls per section 5.8.
Validation / CSVValidates the electronic component; documents the hybrid as a designed system; supports migration and archive validation.
IT / instrument supportProvisions individual accounts; configures and protects the system clock and audit trail; maintains backup and tested restore of the electronic half.

4. Definitions

  • Hybrid record: a record where the complete account of a GxP activity exists partly electronically and partly on paper, and both halves are required to reconstruct the activity.
  • Governing record (raw record, original): the artifact declared to contain the original observation at the highest fidelity together with the metadata needed to reconstruct the activity. For dynamic electronic data this is the electronic data with its audit trail, not a printout.
  • Dynamic data: data that can be reprocessed, re-integrated, re-queried, or re-plotted, such as a chromatogram, a spectrum, a thermal profile, or a database query result.
  • Static data: a fixed value or image with no reprocessable content, such as a single balance weight or a pH reading.
  • Split-field record: a record in which some fields exist only on the electronic half and others only on the paper half, so neither half is a complete original on its own.
  • Reconciliation: the documented act of confirming that the paper and electronic halves agree on count, identity, value, time and sequence, and that every exception is explained.
  • Machine-generated identifier: a value produced by the system and not typed by the user (result ID, sequence name, printout counter, batch or step ID) used to link the two halves.
  • Certified copy: a copy verified as a complete and accurate reproduction of the original by a named person or a validated process, with the verification recorded.

5. Procedure

5.1 Identify hybrids and maintain the inventory

  1. Assess every GxP system, instrument, and process against three questions: does it generate electronic data; is any part of the official record on paper; are both halves needed to reconstruct the activity. Three affirmative answers means the record is hybrid.
  2. Confirm the assessment by direct observation of a real execution, not by reading the procedure alone. Record the observation date and the observer.
  3. Record each hybrid in the hybrid inventory register with the fields defined in <<FILL: register document number>>.
  4. Review the inventory at least <<FILL: frequency, e.g. annually>> and on any change to a system, instrument, method, or process that affects how the record is created or stored.
  5. Reassess whenever a new system is introduced, through change control per <<FILL: SOP-ID for change control>>.

5.2 Declare the governing record

  1. For each hybrid, determine the governing record by applying the following tests in order, stopping at the first that resolves: a. If no system captures the observation electronically at the moment it occurs, the paper entry is the original. b. If the electronic data is dynamic, the electronic data with its audit trail and metadata is the original. A printout cannot be the original. c. If the electronic output is static and the system retains it as an attributable, time-stamped entry, the electronic value is the original. d. If the instrument retains nothing, the paper capture is the only original, and the transcription is verified by a second person. e. If any field exists only on one half, the record is a split-field record and each field is declared individually.
  2. Document the declaration in the governing SOP, method, or batch record instruction for that activity, and record it in the hybrid inventory register.
  3. Quality Assurance approves each declaration. A declaration that names a printout as the original for dynamic data is not approved.
  4. Apply retention, backup, access control, and review controls to the governing record, not only to the paper copy.
  1. Require a machine-generated identifier on the electronic output and record it on the paper half. Use <<FILL: identifier type for each system, e.g. result ID and sequence name>>.
  2. Where the system prints a sequential counter, record the counter value on the paper so gaps are visible.
  3. Use controlled, pre-numbered paper forms issued and reconciled per <<FILL: SOP-ID for controlled form issuance>> so that a removed page is detectable.
  4. Where the paper record runs to more than one page, number pages as “page N of M” and carry the record identifier on every page.
  5. Where the electronic system supports a comment or custom field, record that a paper approval exists and where it is filed.

5.4 Reconcile at the point of review

Perform the following before the record is used to support any decision. Complete the reconciliation record in section 8.

  1. Retrieve the governing electronic record and its audit trail for the activity. Begin from the electronic side.
  2. Count: confirm the number of electronic events equals the number of paper entries, including blanks, standards, controls, aborted runs, and repeats. Investigate any difference before proceeding.
  3. Identity: match each electronic result to exactly one paper entry using the machine-generated identifier. Resolve every orphan on either side.
  4. Value: verify each transcribed value against the electronic source, or confirm that no transcription occurred.
  5. Time and sequence: confirm the order and time stamps are consistent across both halves. A paper entry timed before its electronic event, or an electronic event with no paper trace, is an exception.
  6. Audit trail: examine the audit trail for the period for deletions, reprocessing, manual integration, aborted or renamed runs, method or sequence edits, clock changes, and privilege changes. Confirm each is explained on the paper record or in an approved deviation.
  7. Exceptions: confirm every aborted run, repeat, out-of-sequence event, and correction is explained on the record.
  8. Sign the reconciliation with the defined meaning stated in section 5.6.

5.5 Handle corrections across the seam

  1. Correct paper entries per good documentation practices: single-line cross-out leaving the original legible, correct value, initial, date, and reason.
  2. Correct electronic entries through the system so the change is captured in the audit trail with a reason.
  3. Where a value appears on both halves, propagate the correction to both and re-reconcile the affected fields. A correction applied to only one half is a discrepancy.
  4. Record the cross-reference so a reviewer can see both corrections belong to the same event.
  5. Never obliterate, overwrite, or discard the original entry on either half.

5.6 Define the meaning of each signature

  1. Each signature on the paper half states the printed name of the signer, the date, and the meaning of the signature.
  2. The reviewer signature meaning is defined as: <<FILL: e.g. "Reviewed the governing electronic record including its audit trail, performed reconciliation per SOP-QA-031, and dispositioned all exceptions">>.
  3. A signature meaning that does not state that the electronic record and its audit trail were examined is not acceptable for a hybrid, because it permits review of the paper alone.
  4. Signatures applied on paper to approve an electronic record are linked to that specific record by the identifier required in section 5.3, consistent with 21 CFR 11.70.

5.7 Escalate discrepancies

  1. Record every discrepancy on the reconciliation record with the detail and the initial assessment.
  2. Classify per the table below and act accordingly. Notify Quality Assurance the same working day for any classification other than “corrected at source”.
What was foundClassificationAction
Transcription error found and corrected by the second-person checkControl functionedRecord, trend, no deviation
Transcription error not caught, no effect on any result or decisionDocumentation errorDeviation, retraining, trend for pattern
Transcription error that changed a result or a dispositionSignificantDeviation with product impact assessment; widen review to the surrounding period
Reconciliation not performed although records agreeProcedural failureDeviation; the control was absent
Unexplained gap in a sequence, counter, or page numberPotential lost dataInvestigate as potential discarded data until demonstrated otherwise
Unexplained deletion or alteration in the audit trail, or attribution cannot be establishedPotential data integrity eventEscalate immediately per <<FILL: SOP-ID for data integrity events>>; do not close as a routine deviation
  1. Do not release or use affected data until the discrepancy is resolved and dispositioned.

5.8 Periodic verification of hybrid controls

  1. At least <<FILL: frequency, e.g. quarterly>>, Quality Assurance independently examines a sample of hybrid records per system.
  2. Select records judgementally, biased toward high-criticality hybrids, systems with open remediation actions, periods of operational pressure, and records containing exceptions, together with a small number of routine records.
  3. Begin each examination from the electronic record and its audit trail, then require the paper to account for it.
  4. Include at least one end-to-end retrieval test per year: request a hybrid record at least <<FILL: number>> years old and record the elapsed time to produce both halves.
  5. Record results, raise deviations for findings, and feed findings into the hybrid retirement plan priority.

5.9 Retirement of a hybrid

  1. Retirement of a hybrid to a fully electronic record is executed through change control and the hybrid retirement plan <<FILL: plan document number>>.
  2. Paper is retired only after the electronic process is validated and the electronic record and signature controls are confirmed adequate.
  3. Legacy hybrid records remain retrievable and reconstructable for their full retention period after retirement.
  4. Update the inventory, the governing-record declaration, and all affected SOPs at retirement.

6. Acceptance criteria

A hybrid record is acceptable when all of the following are true:

  • The record appears on the hybrid inventory with an approved governing-record declaration.
  • The machine-generated identifier appears on both halves and resolves to exactly one electronic record.
  • Count, identity, value, time and sequence all reconcile, with every difference investigated and dispositioned.
  • The audit trail of the governing electronic record was examined as part of the review, and every critical entry is explained.
  • Every transcribed value was verified, or no transcription occurred.
  • Each signature carries a printed name, a date, and a stated meaning that includes reconciliation and audit trail review.
  • No unexplained gaps exist in any sequence, counter, or page numbering.
  • A second person can repeat the reconciliation from the record alone and reach the same conclusion.

7. References

21 CFR 211.68 (automatic, mechanical, and electronic equipment), 211.180 (general records requirements), 211.194 (laboratory records). 21 CFR Part 11 (electronic records and electronic signatures), in particular 11.10 (controls for closed systems), 11.50 (signature manifestations), and 11.70 (signature/record linking). EU GMP Annex 11 (Computerised Systems) and EU GMP Chapter 4 (Documentation). FDA guidance, Data Integrity and Compliance With Drug CGMP, Questions and Answers (December 2018). MHRA GXP Data Integrity Guidance and Definitions (March 2018). PIC/S PI 041, Good Practices for Data Management and Integrity in Regulated GMP/GDP Environments. ICH Q9, Quality Risk Management, for the risk basis of review frequency and sampling.

Confirm the current version and clause numbers of each reference before issue.

8. Record generated: hybrid reconciliation record

FieldEntry
Activity and record identifier<<FILL>>
Hybrid inventory reference<<FILL: inventory ID>>
Governing record declared<<FILL: electronic / paper / split-field>>
Electronic system and identifier(s)<<FILL: system, result ID, sequence>>
Paper record and form numbers<<FILL: form ID, pages N of M>>
Count reconciled (electronic / paper)<<FILL>> / <<FILL>>
Identity: all events matched, no orphansYes / No
Transcribed values verified (or none transcribed)<<FILL>>
Time and sequence consistentYes / No
Audit trail reviewed, period covered<<FILL: from>> to <<FILL: to>>
Critical audit trail entries and explanation<<FILL: count and detail>>
Sequence, counter, or page gaps<<FILL: none, or detail>>
Exceptions and disposition<<FILL: none, or list>>
Deviation reference (if raised)<<FILL: number or N/A>>
Reviewer (name, signature, date, meaning)<<FILL>>
QA approval (name, signature, date)<<FILL>>

9. Revision history

VersionDateAuthorSummary of change
<<FILL: 1.0>><<FILL: date>><<FILL: author>>Initial issue.

10. Approvals

RoleNameSignatureDate
Author<<FILL>>
Reviewer (QA)<<FILL>>
Approver (Quality Head)<<FILL>>

Filled specimen

The following shows the reconciliation record completed for an example standalone chromatography workstation with a paper analyst worksheet. Company, system, and numbers are illustrative; replace them with your own.

FieldEntry
Activity and record identifierAssay by HPLC, finished product, batch A-2274, worksheet WS-4471
Hybrid inventory referenceHYB-001
Governing record declaredElectronic (dynamic chromatographic data with audit trail)
Electronic system and identifier(s)CDS standalone workstation HPLC-07, sequence SEQ-2607-118, result IDs 4471-01 through 4471-12
Paper record and form numbersControlled worksheet WS-4471, pages 1 of 3, 2 of 3, 3 of 3
Count reconciled (electronic / paper)12 / 12 (2 blanks, 3 standards, 6 sample injections, 1 aborted run)
Identity: all events matched, no orphansYes. Each result ID appears once on the worksheet.
Transcribed values verified (or none transcribed)6 sample results verified against the electronic source by second person (T. Nwosu)
Time and sequence consistentYes. Worksheet entry times fall within the acquisition window for each injection.
Audit trail reviewed, period covered12 July 2026 08:14 to 12 July 2026 15:52
Critical audit trail entries and explanation3 entries. One aborted run (injection 07, pressure fault, documented on worksheet page 2 and repeated as injection 08). One manual integration on result 4471-09 with recorded reason (shoulder on trailing edge, integrated to valley per method). One sequence edit adding the repeat injection.
Sequence, counter, or page gapsNone. Result IDs run 01 to 12 with no gap; worksheet pages 1 to 3 accounted for.
Exceptions and dispositionManual integration on 4471-09 reviewed against the method and accepted; reviewer confirmed the integration parameters against the method-defined approach and recorded the assessment on page 3.
Deviation reference (if raised)N/A
ReviewerT. Nwosu, signed, 13 July 2026. Meaning: reviewed the governing electronic record including its audit trail, performed reconciliation per SOP-QA-031, and dispositioned all exceptions.
QA approvalL. Fernandes, signed, 14 July 2026

What makes this specimen defensible is not that it is clean. It is that the aborted run is visible, accounted for on both halves, and linked to its repeat; the manual integration carries a reason that was independently assessed rather than accepted; and the reviewer began from the electronic record rather than confirming that the worksheet was fully filled in. A reviewer who had signed only the worksheet would have seen 11 tidy results and no evidence that a twelfth injection ever existed.

Common inspection findings this SOP prevents

  • No procedure states which half of a hybrid record is the original, so different reviewers treat different halves as authoritative.
  • A printout is signed and treated as the record while the dynamic electronic data behind it is uncontrolled, overwritten, or deleted.
  • The reviewer signature carries no defined meaning, and review of the electronic audit trail cannot be demonstrated.
  • Aborted, repeated, or reprocessed runs exist electronically and never appear on the paper record.
  • Gaps in a printout counter or in controlled worksheet page numbers are present and unexplained.
  • Values were transcribed from the electronic source to paper with no second-person verification, and an error changed a reported result.
  • A correction was applied to one half of the record and never propagated to the other.
  • Ink signatures approve electronic records with nothing linking the signature to the specific record it approves.

How to adapt this SOP

  1. Set your document number, owner, effective date, and site scope in the header.
  2. In section 5.3, name the actual machine-generated identifier each of your systems produces. This is the highest-value line in the procedure and it is system-specific.
  3. In section 5.6, write the signature meaning you will actually print on your forms, and then check that your existing forms have room for it.
  4. Point the cross-references in sections 2, 5.1, 5.5, 5.7, and 5.9 to your real procedures for change control, deviations, data integrity events, retention, and controlled form issuance.
  5. Set the review sample size and frequency in section 5.8 to match the size of your hybrid population, and record the basis for the number you chose.
  6. Confirm every regulation in section 7 against the current published version before issue.
Use madhadi.com as an app Full screen, works offline, one tap from your home screen.