Independent and not affiliated with the FDA, MHRA, ISPE, PDA, or any agency. Get the appgoutham@madhadi.com
madhadi.comData Integrity & GxP Quality
Browse all topics → Articles Templates & Procedures Learning paths GlossaryScenariosToolsRegulatory ReferencesLearning PathsTopics About Start here
Work Instruction Plug-and-play starting point Data Integrity

Work Instruction: Producing Certified Copies of Paper GxP Records

A task-level work instruction for scanning paper GxP records into certified copies: record preparation and insert logging, scanner settings, duplex requirement, page-count reconciliation against a pre-numbered source, verification by risk level, the certification statement, indexing, storage and backup, and the hold checks that must pass before any paper original is destroyed.

Document type: Work Instruction

Read and copy the template below into your own quality system. It is a generic starting point for your own internal use, provided as is, with no warranty; see the Terms and License. Adopting it does not by itself create compliance.

This is a ready-to-use work instruction for one task: turning a paper GxP record into a certified copy that can be relied on as a record. It sits under the parent SOP <<FILL: parent SOP number>> and gives the step-by-step actions with the acceptance for each step. Replace every <<FILL: ...>> placeholder. A filled specimen certification block follows. This is general guidance to adapt and verify against your own processes and regulatory context, not legal or regulatory advice.

The limitation that governs everything below. Scanning produces a faithful copy of a static paper original. It does not rescue dynamic electronic data. If the paper you are scanning is a printout of dynamic electronic data, such as a chromatogram, a spectrum, a thermal profile, or a database query output, the image you produce is a copy of the printout, not a copy of the dynamic record. The underlying electronic data and its audit trail remain the original and must still be retained. Nothing in this work instruction permits deleting them. This is the single most common misunderstanding on the topic, and it has produced real findings where firms deleted electronic raw data on the belief that the archive now held the record. It did not. See static and dynamic records and true copies and hybrid paper-and-electronic records.

FieldEntry
Work instruction number<<FILL: WI-ID, e.g. WI-QA-041-01>>
Parent SOP<<FILL: parent SOP number>>
Version / effective date<<FILL>>
Applies to<<FILL: roles authorised to produce and verify certified copies>>
Qualified equipment<<FILL: scanner asset IDs and their qualification record numbers>>
Record types in scope<<FILL: e.g. executed batch records, analytical worksheets, logbooks, clinical source>>

Definitions

  • True copy: a copy that preserves the full content and meaning of the original record, including all its data and, where applicable, its metadata.
  • Certified copy: a true copy that has been verified as complete and accurate by a named person, or produced by a validated process that performs the verification, and that carries a record of that verification. A copy nobody verified is not a certified copy regardless of what the file is labelled.
  • Static record: a fixed value or image with no reprocessable content, such as a handwritten batch record page or a signed worksheet.
  • Dynamic record: data that can be reprocessed, re-integrated, re-queried, or re-plotted. A printout of a dynamic record is a static summary of it, not a copy of it.
  • Insert: anything attached to or placed within the source record that is not part of the numbered page sequence: taped-in printouts, sticky notes, appended data slips, fold-out sheets.

When to use, and when not to

Use this work instruction to produce a certified copy for archival, for transfer to another party, for a regulatory request, or as a step preceding a controlled decision about the paper original. Use it also when a record is at risk of degradation, such as thermal output, which should be copied on the day it is produced rather than at archive time.

Do not use it to copy a printout of dynamic electronic data as a substitute for retaining that data. Do not use it on records currently in execution; a record still being written to is copied only under the exception route in the parent SOP. Do not begin if the source record is incomplete, unsigned, or under an open correction, unless the parent SOP defines that state as copyable and the reason is recorded.

Prerequisites

ItemAcceptance
Qualified scanner listed in the headerQualification record current, within its requalification interval
Scanning workstation with controlled accessOnly authorised roles can write to the destination location
Destination storage with backupBackup is active and a restore has been tested within <<FILL: interval, e.g. 12 months>>
The source record, completeAll pages present, all inserts present
A pre-numbered source or a counted page referenceYou cannot reconcile a page count against a source that never stated its own total
The record’s hybrid inventory entry, if it is part of a hybridConfirms whether an electronic half exists that must be retained separately

Task A: prepare the record

StepActionAcceptance for this step
A1Confirm the record identity against the request: product or study, batch or subject, document number, date range.The record in your hands is the record requested, confirmed against two identifiers, not one.
A2Confirm the record is complete and establish the expected page count from the pre-numbered pages, the “page N of M” statement, or the record index. Write the expected count on the preparation log.An expected total exists and is written down before scanning. If the source does not state its own total, record that fact; the page-count reconciliation in Task D is weaker and the verification level rises to 100 percent.
A3Determine whether the record is part of a hybrid by checking the hybrid inventory register. If an electronic half exists, record its identifier on the preparation log.The electronic half is identified and its retention is unaffected by this task.
A4Remove staples, clips, and bindings. Count and log every fastener removed and every page it held together.Nothing separates unnoticed. Pages that were fastened together are kept in order.
A5Identify and log every insert: taped-in printouts, appended slips, sticky notes, fold-out sheets, and anything written on the reverse of an insert. Number each insert and record where it belongs.Every insert appears on the log with its location. Inserts are the most commonly lost content in the whole process, because they are not part of the numbered sequence and nothing detects their absence.
A6Detach inserts only where necessary to scan them, and only after logging their location. Reattach immediately after scanning.The record is reassembled to its original arrangement, verified against the insert log.
A7Flatten folded pages, unfold fold-outs, and identify low-contrast content: pencil, faded thermal, light-coloured highlighter over text.Content that could scan blank has been identified before scanning rather than discovered during verification.
A8Identify any content where colour carries meaning: red-ink corrections, colour-coded status stamps, highlighted values.Colour-carrying content is identified so the colour setting in Task B is a decision, not a default.
A9Do not repair, re-write, annotate, or “tidy” the source in any way.The source is unchanged. Any pre-existing damage is described on the preparation log, not corrected.

Task B: set the scanner

StepActionAcceptance for this step
B1Set resolution to at least <<FILL: minimum resolution, e.g. 300 dpi>> for text records, and <<FILL: higher resolution>> where the source contains fine detail such as a printed trace or small-font instrument output.The smallest legible character and the finest line on the source are legible in the output at 100 percent magnification.
B2Set colour mode to colour where colour carries meaning (identified in step A8), and to greyscale otherwise. Do not use bitonal or black-and-white mode for records containing handwriting or faint entries.No content whose meaning depends on colour is rendered in a way that loses that meaning. Bitonal thresholding is the setting that silently erases pencil and faded thermal entries.
B3Set duplex (double-sided) scanning on, without exception, for every record, including records believed to be single-sided.Both sides of every sheet are captured. Corrections and second-person initials on the reverse of a page are among the most commonly lost content, and the belief that a form is single-sided is not evidence.
B4Set blank-page removal off.A genuinely blank reverse is captured as a blank image rather than silently dropped, so the page and side count reconciles. Automatic blank removal also discards pages carrying only a faint entry.
B5Set the output format to <<FILL: format, e.g. PDF/A>> with any lossy compression disabled or set to the minimum the format permits.Text and handwriting remain legible; compression artefacts have not altered characters or digits.
B6Where the source is bound, damaged, oversized, or fragile, use a flatbed rather than the sheet feeder.No content is lost in the gutter of a bound record, and the source is not damaged by the feed mechanism.
B7Record the actual settings used on the certification block. Do not record the intended settings.The settings recorded match the settings the scanner reports for the job.

Task C: scan

StepActionAcceptance for this step
C1Scan the record as one unit, in its original order, including inserts placed in their correct position in the sequence.The output is a single file, or a defined set of files with a stated relationship, and the order matches the source.
C2Scan any insert that carries content on its reverse as a two-sided item.Insert reverses are captured.
C3For bound logbooks, scan every page in the defined range, including pages that are blank or ruled but unused, unless the parent SOP defines a different rule for unused pages.The scanned range is continuous and its start and end are stated.
C4Do not rotate, crop, deskew, enhance, or edit any image after scanning beyond the settings applied at capture. Where the scanner applies automatic corrections, either disable them or record which corrections were applied.The image is a capture, not an edited derivative. Any automatic processing is disclosed.
C5Review the output visually, page by page, immediately after scanning, while the source is still in front of you.Obvious failures such as a double-feed, an upside-down page, a partially fed sheet, or a blank image are caught before the source is refiled.
C6Where any page fails, rescan that page and record the rescan on the preparation log.The final output contains one image per page and side, and every rescan is recorded rather than silently replacing a page.

Task D: reconcile the page count

This is the step that catches the failure nothing else catches. A double-feed produces a clean-looking file that is silently missing a page, and no amount of reviewing the file for quality will reveal it.

StepActionAcceptance for this step
D1Count the images in the output.The count is recorded.
D2Calculate the expected count: (number of sheets x 2 for duplex) + (insert images, counting both sides where applicable).The expected count is derived from the pre-numbered source established in step A2 and the insert log from step A5, not from the output.
D3Compare the actual count to the expected count.The two agree exactly.
D4Where they do not agree, identify every discrepancy specifically before proceeding. Do not adjust the expected count to match.Each missing or extra image is explained. A discrepancy explained as “probably a blank” is not explained.
D5Confirm the first page of the output is page 1 of the source and the last is page M, and that the “N of M” numbering runs continuously with no gap.The numbering sequence in the output is continuous and reaches its stated total.
D6Confirm every insert on the insert log appears in the output, in the position the log records.Insert count in the output equals insert count on the log.
D7Record the reconciliation result on the certification block.The count reconciliation is a recorded result, not an unrecorded belief.

Task E: verify the content

Verification level is set by the criticality of the record, and the level is decided in the parent SOP rather than per job. State the level applied on the certification block.

Record criticalityVerification levelMethod
High: supports a batch disposition, a release decision, a safety report, a clinical decision, or a submission100 percent, page by page and side by side, against the originalEvery page and side is compared to the source. Every field is read for legibility, not merely observed to be present.
Medium: supports a GxP activity but not a disposition or a safety decision100 percent page presence and order, plus content verification of a defined sample of <<FILL: percentage or number>> pages, biased toward pages carrying results, signatures, and correctionsThe sample plan and its basis are stated in the parent SOP, not chosen per job.
Low: reference or informational recordsPage count reconciliation plus content verification of <<FILL: percentage or number>> pagesThe basis for treating the record type as Low is recorded.
StepActionAcceptance for this step
E1Perform verification at the level above, by a person other than the person who scanned.Verification is independent. Self-verification does not satisfy the certified copy expectation.
E2For every page verified, confirm: all content legible, both sides present, margins and edges not trimmed, colour-carrying content rendered in colour, handwriting and corrections readable, signatures legible and identifiable.Each of these is a specific check, not a general impression. Faint pencil and faded thermal entries are the ones to look at hardest.
E3Confirm the identifiers on the images match the source: record number, product or study, batch or subject, page numbering.The copy cannot be mistaken for a copy of a different record.
E4Where verification finds a defect, rescan the affected page or pages and re-verify. Record the defect and the correction.Defects are recorded, not silently fixed. A pattern of the same defect indicates a settings or process problem to raise.
E5Record the verification method, the sample where applicable, the verifier, and the date on the certification block.Verification is attributable and dated.

Task F: certify

StepActionAcceptance for this step
F1Complete every field of the certification block below.No field is blank.
F2The certifier signs the statement that the copy is a complete and accurate reproduction of the original, including all pages, both sides, and all inserts.The statement is signed by a named person with the date, and that person performed or supervised the verification.
F3Store the certification with the copy, so that the copy and its evidence of verification cannot be separated.Retrieving the copy retrieves its certification. A certification filed elsewhere is a certification that will be lost.
F4Where the certification applies to a defined batch of records rather than a single record, list every record in scope by identifier.The scope of the certification is unambiguous and enumerable.

Certification block

FieldEntry
Source record identity<<FILL: record type, product or study, batch or subject, document number>>
Source format, sheet count, insert count<<FILL: e.g. paper, double-sided, 48 numbered sheets, 3 inserts>>
Hybrid inventory reference, if applicable<<FILL: HYB-ID or N/A>>
Electronic half retained separately (if hybrid)<<FILL: system and identifier, or N/A>>
Preparation log reference<<FILL>>
Scanned by, date<<FILL>>
Scanner asset ID and qualification reference<<FILL>>
Settings actually used<<FILL: resolution, colour mode, duplex, blank-page removal, output format, compression>>
Expected image count and actual image count<<FILL>> / <<FILL>>
Page-count reconciliation resultAgreed / Discrepancy resolved (describe)
Verification level applied and basis<<FILL: 100 percent / sample of N, per record criticality>>
Verification method<<FILL>>
Verified by, date<<FILL>>
Defects found and corrected<<FILL: none, or list with the correction>>
Certification statementVerified as a complete and accurate reproduction of the original record, including all pages, both sides, and all inserts.
Certified by, signature, date<<FILL>>
Stored location and index entries<<FILL>>
Original paper disposition at this date<<FILL: retained, filed at ...>>

Task G: index

A certified copy nobody can find fails on availability just as thoroughly as one that was never made.

StepActionAcceptance for this step
G1Name the file per the naming convention in <<FILL: naming convention reference>>.The name is deterministic: a second person given the same record produces the same name.
G2Index the copy against the identifiers a future reviewer will actually search: <<FILL: e.g. product, batch, study, subject, date, document number, record type>>.Each index field is populated and matches the source record.
G3Where the record is part of a hybrid, index the identifier of the electronic half alongside it.A future reviewer can retrieve both halves from one search.
G4Record the index entry on the certification block.The location is documented at the time of certification, not reconstructed later.
G5Perform a retrieval check: close the file, search the index for the record as a reviewer would, and open the result.The record was retrieved by search rather than by knowing where it was put.

Task H: store, protect, and back up

StepActionAcceptance for this step
H1Store the copy in <<FILL: repository>> with access control appropriate to the record.Only authorised roles can read it; only authorised roles can change it.
H2Confirm the location is covered by the backup schedule, and record the date of the last tested restore.A backup that has never been restored from is a hypothesis.
H3Confirm the copy cannot be modified without traceability. Any later annotation, re-scan, or re-index is recorded.Change to a certified copy is visible, or the copy is held in a form that prevents change.
H4Confirm the retention period applied to the copy is at least the retention period of the original, per <<FILL: retention schedule reference>>.Retention is set explicitly rather than inherited by accident.
H5Where the copy replaces the original as the retained record, confirm the copy is at least as durable and as available as the paper was.Durability and retrievability are equal or better, and this is recorded rather than assumed.

Task J: hold checks before any paper original is destroyed

Destruction is a separate, later, deliberately controlled decision, made under the parent SOP and the retention procedure. It is never a step in scanning. Every condition below is confirmed and recorded before a destruction request proceeds. Any single failed condition stops the request.

#ConditionHow it is confirmedAcceptance
J1A certified copy exists for the record, certification complete and signedRetrieve the certification blockCertification is present, complete, and names a verifier
J2The verification was performed before the paper left controlled custodyPreparation log and certification datesVerification date precedes any transfer or destruction request. Verification after destruction is not verification.
J3The copy is retrievable by index search and opens correctly todayPerform the retrievalThe record was retrieved and read, not merely located
J4The copy is on backed-up media with a restore tested within <<FILL: interval>>Backup and restore test recordsRestore test is current
J5The record is static. If the paper is a printout of dynamic electronic data, the underlying electronic data and its audit trail are retained and under controlHybrid inventory entry and the electronic half’s retention recordThe electronic original is retained independently. Destroying the paper printout is permissible only because the printout was never the original; destroying the electronic data is not permitted by this route at all.
J6A documented, approved policy authorises destruction for this record type, stating the record types in scope and the retention termsRetention and destruction policy <<FILL: reference>>Policy is current and covers this record type explicitly
J7No local legal, national, contractual, or clinical-trial obligation requires retention of the paper original for this record type in the applicable jurisdictionsDocumented confirmation from <<FILL: function, e.g. Legal / Regulatory Affairs>>Confirmation is on file and current, treated as part of the approval rather than an afterthought
J8The record is not subject to any hold: open investigation or deviation, open or announced inspection, regulatory request, litigation hold, product complaint, recall, or any hold flagged in the quality systemHold check against <<FILL: quality system and hold register>>, performed and recorded on the destruction requestThe hold check is performed at the time of the destruction request, not at the time of scanning, and is recorded with its date
J9The retention period for the original has expired per the retention scheduleRetention schedule calculationExpiry date is calculated and recorded
J10The destruction is approved, scheduled, witnessed, and recorded, and the record of destruction is itself retainedDestruction recordThe record of what was destroyed, when, by whom, and under what approval outlives the thing destroyed

The hold check in J8 is the one that most often fails in practice, because it lives in a different procedure from the destruction schedule and nobody consults it. Build it into the destruction request form so it cannot be skipped.

References

21 CFR 211.180 (general records requirements) and 211.194 (laboratory records). 21 CFR Part 11 (electronic records and electronic signatures), where the copy becomes an electronic record relied on to satisfy a predicate rule. EU GMP Chapter 4 (Documentation) and EU GMP Annex 11 (Computerised Systems). FDA guidance, Data Integrity and Compliance With Drug CGMP, Questions and Answers (December 2018), which addresses true copies and the difference between static and dynamic records. MHRA GXP Data Integrity Guidance and Definitions (March 2018), which defines true copy and certified copy. PIC/S PI 041, Good Practices for Data Management and Integrity in Regulated GMP/GDP Environments. ICH E6 Good Clinical Practice, for certified copy expectations applied to clinical source documents.

Confirm the current version and clause numbers of each reference before issue.


Filled specimen

The following certification block is completed for an example executed batch record. Company, names, numbers, and dates are illustrative; replace them with your own.

FieldEntry
Source record identityExecuted batch manufacturing record, product code MAB-2210, 50 mg tablets, batch A-2274, document BMR-114 rev 6
Source format, sheet count, insert countPaper, double-sided, 48 numbered sheets (“page N of 48”), 3 inserts: one taped-in dispensing printout (single-sided), one appended line-clearance photograph sheet (single-sided), one fold-out cleaning record (content on both sides)
Hybrid inventory referenceHYB-003
Electronic half retained separatelyProcess historian, batch window 09 July 2026 04:12 to 11 July 2026 02:40; alarm and event extract EXT-2026-0771. Retained under the historian retention schedule and unaffected by this copy.
Preparation log referencePREP-2026-0219
Scanned by, dateM. Okafor, 14 July 2026
Scanner asset ID and qualification referenceSCN-04, qualification QUAL-IT-2025-018, requalification due 30 November 2026
Settings actually used300 dpi, colour, duplex on, blank-page removal off, PDF/A, compression disabled
Expected image count and actual image countExpected 100 (48 sheets x 2 = 96, plus 2 single-sided inserts = 2, plus 1 double-sided insert = 2). Actual 100.
Page-count reconciliation resultAgreed. Initial scan returned 98 images. Investigation identified a double-feed at sheets 31 and 32, which produced a clean-looking file missing two images with no visible defect. Sheets 31 and 32 were rescanned individually on the flatbed and reinserted in position. Rescan recorded on PREP-2026-0219.
Verification level applied and basis100 percent, page by page and side by side. Basis: batch record supports batch disposition, classified High criticality in the record type table.
Verification methodEach of the 100 images compared against the corresponding physical page or side. Every recorded value, signature, initial, correction, and insert checked for legibility. Red-ink corrections on sheets 12 and 29 confirmed rendered in colour.
Verified by, dateS. Lindqvist, 15 July 2026
Defects found and correctedTwo: the double-feed described above; and sheet 44 reverse initially scanned with the lower margin trimmed by the feeder, rescanned on the flatbed with the full margin captured. Both recorded and re-verified.
Certification statementVerified as a complete and accurate reproduction of the original record, including all pages, both sides, and all inserts.
Certified by, signature, dateS. Lindqvist, signed, 15 July 2026
Stored location and index entriesDocument archive repository, path /archive/bmr/2026/A-2274; indexed by product, batch A-2274, record type “executed batch record”, manufacturing date range, document number BMR-114, and cross-indexed to historian extract EXT-2026-0771
Original paper disposition at this dateRetained, filed in manufacturing archive location ARC-B-14, pending scheduled destruction per the retention procedure. Not destroyed.

Two things in this specimen carry the weight. The first is that the count reconciliation failed on the first attempt and the record says so. A double-feed at sheets 31 and 32 produced a file that looked perfect, and only the arithmetic caught it; a certification that never records a discrepancy across hundreds of batch records is more likely to indicate that nobody counted than that nothing ever went wrong. The second is the last row. It says “retained”, not “destroyed”. Producing a certified copy and deciding to destroy an original are two different decisions taken at two different times under two different approvals, and the hold checks in Task J stand between them.

Common inspection findings this work instruction prevents

  • Paper originals destroyed after scanning with no verification step, so the files described as certified copies were never certified.
  • Double-sided originals scanned single-sided, losing corrections and second-person initials recorded on the reverse.
  • A page silently missing from a scanned batch record because a double-feed was never caught by a page-count reconciliation.
  • Inserts, taped-in printouts, and appended slips absent from the copy because they were removed during preparation and never logged.
  • Red-ink corrections and colour-coded status stamps scanned in greyscale or bitonal mode, so the meaning carried by colour is lost.
  • Pencil or faded thermal entries scanned blank because a bitonal threshold was applied by default.
  • Printouts of dynamic electronic data scanned and the underlying electronic data deleted, on the reasoning that the archive now holds the record.
  • Certified copies stored on media with no tested restore, or indexed so poorly they cannot be produced during an inspection within a reasonable time.
  • Destruction proceeding on schedule while the batch was under investigation, because the hold check lived in a different procedure that nobody consulted.
  • Verification performed by the same person who scanned the record, so the independent check never existed.

How to adapt this work instruction

  1. Set the work instruction number and point the parent SOP field at your real records and archiving procedure.
  2. Set the resolution, colour, and format values in Task B from your scanner qualification, not from this document. Then check that the qualification actually tested the settings you are specifying, including the low-contrast and colour cases.
  3. Define the record criticality tiers in Task E and map your record types to them centrally, in the parent SOP, so the verification level is never a per-job judgement.
  4. Where a source record type does not state its own page total, either introduce “page N of M” numbering on the form or accept that the verification level rises to 100 percent for that record type. Record which choice you made and why.
  5. Build the Task J hold checks into your destruction request form as mandatory fields, so a request cannot be submitted without them. The J8 hold check is performed at the time of the destruction request, not carried forward from the scanning date.
  6. For clinical records, add the certified copy expectations from your sponsor procedures and the trial master file filing conventions, and account for copies produced at investigator sites rather than centrally.
  7. For records at risk of degradation, such as thermal output, add a trigger to your execution procedures so the copy is made on the day the record is produced rather than at archive time.
  8. Confirm every regulation in the references section against the current published version before issue.
Use madhadi.com as an app Full screen, works offline, one tap from your home screen.