This is a ready-to-use SOP for bringing a process historian under data integrity control. Replace every <<FILL: ...>> placeholder with your own specifics, set your document numbers and dates, and route it through your normal document control, review, and approval. A worked filled specimen follows. Verify each cited regulation against the current source before you rely on it. This SOP pairs with the Log: Process Historian GxP Tag Register and the Protocol: Process Historian Data Integrity Qualification.
Document control header
| Field | Entry |
|---|---|
| Document title | Process Historian Data Integrity Governance |
| Document number | <<FILL: SOP-ID, e.g. SOP-AUT-022>> |
| Version | <<FILL: version>> |
| Effective date | <<FILL: date>> |
| Supersedes | <<FILL: prior version or "New">> |
| Document owner | <<FILL: role, e.g. Automation / MSAT System Owner>> |
| Applies to | <<FILL: sites / historians in scope>> |
1. Purpose
This procedure defines how <<FILL: COMPANY NAME>> governs its process historian(s) as GxP computerized systems, so that time-series data used to support quality decisions is complete, accurate, attributable, and reconstructable. It addresses the traps specific to historians: compression, interpolation, quality flags, clock control, and retention versus backup.
2. Scope
Applies to every process historian that stores data used to make or support a GxP decision (batch disposition, deviation, continued process verification, environmental or utility assessment). Covers tag governance, configuration control, audit trail, time synchronization, retention and archive, report generation, and use of historian data at disposition. It does not cover the control-layer PLC/DCS/SCADA logic itself, governed by <<FILL: SOP-ID for automation systems>>.
3. Responsibilities
| Role | Responsibility |
|---|---|
| System owner (automation / manufacturing) | Accountable for the validated state, tag register, and change control of the historian; the named owner an inspector will ask for. |
| Process / area SME | Defines GxP-critical tags; justifies compression and scan rates against process control limits; reviews trends at disposition. |
| IT / infrastructure | Server, storage, time synchronization, backup, archive execution, access provisioning, patching under change control. |
| Quality Assurance | Approves validation, GxP tag classification, retention periods, and the audit trail review procedure; assesses deviations; approves disposition use of historian data. |
| Validation / CSV | Authors and executes the validation package and data integrity risk assessment; maintains traceability. |
4. Definitions
- Tag / point: a single measured or calculated variable stored as a timestamped stream.
- Compression / deadband: the algorithm that decides which raw values to store; a wide deadband can smooth real excursions out of the record.
- Interpolated value: a calculated value for a timestamp that was never actually recorded.
- Retrieval mode: how the historian returns data (raw, interpolated, sampled, aggregated); different modes can return different numbers for the same window.
- Archive vs backup: an archive is the long-term retained record; a backup is a disaster-recovery copy overwritten on a cycle. They are not interchangeable.
5. Procedure
5.1 Maintain the tag register and classify tags
- Keep a controlled tag register (see the paired Log) with GxP classification for every tag: GxP-critical, GxP-supporting, or non-GxP with documented rationale.
- Classify by the decision test: a CPP/CQA or batch-record/control-strategy parameter is GxP-critical; a value used to support a quality decision is GxP-supporting; a purely engineering value with no product or compliance use is non-GxP with the rationale recorded.
- QA approves the GxP-critical list. No tag is added, renamed, or deleted, and no compression, scan rate, engineering unit, retention, or security setting is changed, except under change control per
<<FILL: SOP-ID for change control>>.
5.2 Control capture settings
- For GxP-critical tags, disable compression (store every sample) unless storage genuinely forces a deadband; where a deadband is used, justify it numerically against the parameter’s alarm and control limits and record the justification in the register.
- Set and lock scan rates appropriate to the parameter’s dynamics.
- Restrict or disable any ability to insert or edit historical values for GxP tags; store-and-forward buffering with original timestamps is acceptable, manual backfilling is not.
5.3 Control retrieval and reports
- Define one retrieval mode per standard GxP report and validate it. Use raw mode for batch records and investigations, or clearly label interpolated values.
- Fix the aggregation method and interval boundaries for each standard report so two reports of the same parameter cannot silently disagree.
- Reports must show quality flags and data gaps, not fill them, and export as true copies with metadata, not screenshots.
5.4 Control time
- Synchronize all source devices and the historian server to a single controlled time reference.
- Restrict the ability to change system time to administrators; log every time change in the audit trail.
- Define handling of time zone and daylight saving; store timestamps unambiguously (for example UTC plus offset).
5.5 Enable and review the audit trail
- Enable the audit trail for both configuration changes (tag add/delete/rename, compression, scan rate, retention, security) and data changes (any manual edit: who, old value, new value, timestamp, reason), plus system events (time changes, archive operations).
- Ensure entries are attributable to unique individuals; no shared accounts on GxP functions.
- Review the audit trail on a risk-based cycle: configuration changes to GxP-critical tags and any manual data edits are reviewed per
<<FILL: frequency>>; underlying continuous data is reviewed through trend review at disposition. Document the review.
5.6 Control retention and archive
- Set retention per tag in the register to satisfy the longest applicable requirement (predicate rule, marketing authorization, GMP chapter, local law).
- Keep the archive separate from rolling backups. Down-sampling on archive is disabled for GxP-critical tags unless a justified, change-controlled decision documents otherwise.
- Prove archived data is restorable and unchanged by an actual restore test on a defined cycle; maintain a migration plan so data stays readable if software or format is retired.
- Control, authorize, and record disposal at end of retention.
5.7 Use at disposition
- Trends used at disposition must be from validated, GxP-classified tags, in the specified retrieval mode, with quality flags and gaps shown, timestamps from the controlled clock, and exported as true copies.
- Reviewers approving disposition confirm they understand the retrieval settings behind the trend.
6. Acceptance criteria
- A controlled tag register exists, every tag is classified, and the GxP-critical list is QA-approved.
- Compression and scan settings for critical tags are documented and justified so no excursion of concern can be hidden.
- The audit trail is enabled for configuration and data changes, attributable, and reviewed on a defined cycle with evidence.
- Time is synchronized and clock changes are restricted and logged.
- Retention per tag meets the longest requirement, archive is separate from backup, and a restore test has proven archived data complete and readable.
- GxP reports specify a validated retrieval mode, show flags and gaps, and export as true copies.
7. References
21 CFR 211.68 (automatic equipment, I/O checks), 211.180-211.188 (records), 211.194 (laboratory records where applicable). 21 CFR Part 11 (electronic records and signatures). EU GMP Annex 11 (computerised systems), clauses on validation, data accuracy, storage, audit trail, and security; EU GMP Chapter 4 (documentation and retention). A draft revision of Annex 11 and a new draft Annex 22 went to consultation in July 2025 (consultation closed 7 October 2025) and remain drafts as of mid-2026; confirm the final text and clause numbers before citing. MHRA GxP Data Integrity Guidance (2018); PIC/S PI 041 (2021); WHO TRS 1033 Annex 4 (2019); GAMP 5 (2nd ed., 2022).
Confirm the current version and clause numbers of each reference before issue.
8. Records generated
- Controlled tag register; change-control records for configuration changes.
- Audit trail review records; restore-test records; disposition trend true copies.
9. Revision history
| Version | Date | Author | Summary of change |
|---|---|---|---|
<<FILL: 1.0>> | <<FILL: date>> | <<FILL: author>> | Initial issue. |
10. Approvals
| Role | Name | Signature | Date |
|---|---|---|---|
| Author | <<FILL>> | ||
| Reviewer (QA) | <<FILL>> | ||
| Approver (Quality Head) | <<FILL>> |
Filled specimen
Illustrative extract of an audit trail review record under this SOP, for a bioreactor historian.
| Field | Entry |
|---|---|
| Historian / scope | Site historian, bioreactor suite tags |
| Review period | 01 June 2026 to 30 June 2026 |
| Configuration changes to GxP-critical tags | 1: deadband on BR101.DO.PV changed 0.1% to 0.2%, change control CC-2026-0410, QA-approved before effect |
| Manual data edits | None |
| Time changes | 1 daylight-saving adjustment, automatic, logged |
| Findings / exceptions | None; the deadband change was justified against the DO control limit and pre-approved |
| Reviewer / QA (name, signature, date) | <<FILL>> |
The point: a compression-deadband change is a GxP-relevant configuration change because it alters what gets captured, so it goes through change control and appears in the audit trail review, not silently in an engineer’s session.
Common inspection findings this SOP prevents
- Historian holds GxP data but was never classified as a GxP system and has no tag register.
- Audit trail exists but was never enabled, or covers data only and not configuration changes such as compression.
- Compression deadbands set for storage efficiency smooth real excursions out of the record.
- “Retained” data lives only on a rolling backup that overwrites before the retention period ends.
- No one can name the system owner.
How to adapt this SOP
- Set your document number and owner, and point the change-control and automation-systems cross-references to your real procedures.
- Insert your audit-trail review frequency and retention basis.
- Align the roles with your actual automation, IT, and QA split; a historian with no named owner is the first gap to close.
- Confirm every regulation in section 7 against the current published version, including the pending Annex 11 revision, before issue.