This is a ready-to-use work instruction for one task: turning a paper GxP record into a certified copy that can be relied on as a record. It sits under the parent SOP <<FILL: parent SOP number>> and gives the step-by-step actions with the acceptance for each step. Replace every <<FILL: ...>> placeholder. A filled specimen certification block follows. This is general guidance to adapt and verify against your own processes and regulatory context, not legal or regulatory advice.
The limitation that governs everything below. Scanning produces a faithful copy of a static paper original. It does not rescue dynamic electronic data. If the paper you are scanning is a printout of dynamic electronic data, such as a chromatogram, a spectrum, a thermal profile, or a database query output, the image you produce is a copy of the printout, not a copy of the dynamic record. The underlying electronic data and its audit trail remain the original and must still be retained. Nothing in this work instruction permits deleting them. This is the single most common misunderstanding on the topic, and it has produced real findings where firms deleted electronic raw data on the belief that the archive now held the record. It did not. See static and dynamic records and true copies and hybrid paper-and-electronic records.
Header
| Field | Entry |
|---|---|
| Work instruction number | <<FILL: WI-ID, e.g. WI-QA-041-01>> |
| Parent SOP | <<FILL: parent SOP number>> |
| Version / effective date | <<FILL>> |
| Applies to | <<FILL: roles authorised to produce and verify certified copies>> |
| Qualified equipment | <<FILL: scanner asset IDs and their qualification record numbers>> |
| Record types in scope | <<FILL: e.g. executed batch records, analytical worksheets, logbooks, clinical source>> |
Definitions
- True copy: a copy that preserves the full content and meaning of the original record, including all its data and, where applicable, its metadata.
- Certified copy: a true copy that has been verified as complete and accurate by a named person, or produced by a validated process that performs the verification, and that carries a record of that verification. A copy nobody verified is not a certified copy regardless of what the file is labelled.
- Static record: a fixed value or image with no reprocessable content, such as a handwritten batch record page or a signed worksheet.
- Dynamic record: data that can be reprocessed, re-integrated, re-queried, or re-plotted. A printout of a dynamic record is a static summary of it, not a copy of it.
- Insert: anything attached to or placed within the source record that is not part of the numbered page sequence: taped-in printouts, sticky notes, appended data slips, fold-out sheets.
When to use, and when not to
Use this work instruction to produce a certified copy for archival, for transfer to another party, for a regulatory request, or as a step preceding a controlled decision about the paper original. Use it also when a record is at risk of degradation, such as thermal output, which should be copied on the day it is produced rather than at archive time.
Do not use it to copy a printout of dynamic electronic data as a substitute for retaining that data. Do not use it on records currently in execution; a record still being written to is copied only under the exception route in the parent SOP. Do not begin if the source record is incomplete, unsigned, or under an open correction, unless the parent SOP defines that state as copyable and the reason is recorded.
Prerequisites
| Item | Acceptance |
|---|---|
| Qualified scanner listed in the header | Qualification record current, within its requalification interval |
| Scanning workstation with controlled access | Only authorised roles can write to the destination location |
| Destination storage with backup | Backup is active and a restore has been tested within <<FILL: interval, e.g. 12 months>> |
| The source record, complete | All pages present, all inserts present |
| A pre-numbered source or a counted page reference | You cannot reconcile a page count against a source that never stated its own total |
| The record’s hybrid inventory entry, if it is part of a hybrid | Confirms whether an electronic half exists that must be retained separately |
Task A: prepare the record
| Step | Action | Acceptance for this step |
|---|---|---|
| A1 | Confirm the record identity against the request: product or study, batch or subject, document number, date range. | The record in your hands is the record requested, confirmed against two identifiers, not one. |
| A2 | Confirm the record is complete and establish the expected page count from the pre-numbered pages, the “page N of M” statement, or the record index. Write the expected count on the preparation log. | An expected total exists and is written down before scanning. If the source does not state its own total, record that fact; the page-count reconciliation in Task D is weaker and the verification level rises to 100 percent. |
| A3 | Determine whether the record is part of a hybrid by checking the hybrid inventory register. If an electronic half exists, record its identifier on the preparation log. | The electronic half is identified and its retention is unaffected by this task. |
| A4 | Remove staples, clips, and bindings. Count and log every fastener removed and every page it held together. | Nothing separates unnoticed. Pages that were fastened together are kept in order. |
| A5 | Identify and log every insert: taped-in printouts, appended slips, sticky notes, fold-out sheets, and anything written on the reverse of an insert. Number each insert and record where it belongs. | Every insert appears on the log with its location. Inserts are the most commonly lost content in the whole process, because they are not part of the numbered sequence and nothing detects their absence. |
| A6 | Detach inserts only where necessary to scan them, and only after logging their location. Reattach immediately after scanning. | The record is reassembled to its original arrangement, verified against the insert log. |
| A7 | Flatten folded pages, unfold fold-outs, and identify low-contrast content: pencil, faded thermal, light-coloured highlighter over text. | Content that could scan blank has been identified before scanning rather than discovered during verification. |
| A8 | Identify any content where colour carries meaning: red-ink corrections, colour-coded status stamps, highlighted values. | Colour-carrying content is identified so the colour setting in Task B is a decision, not a default. |
| A9 | Do not repair, re-write, annotate, or “tidy” the source in any way. | The source is unchanged. Any pre-existing damage is described on the preparation log, not corrected. |
Task B: set the scanner
| Step | Action | Acceptance for this step |
|---|---|---|
| B1 | Set resolution to at least <<FILL: minimum resolution, e.g. 300 dpi>> for text records, and <<FILL: higher resolution>> where the source contains fine detail such as a printed trace or small-font instrument output. | The smallest legible character and the finest line on the source are legible in the output at 100 percent magnification. |
| B2 | Set colour mode to colour where colour carries meaning (identified in step A8), and to greyscale otherwise. Do not use bitonal or black-and-white mode for records containing handwriting or faint entries. | No content whose meaning depends on colour is rendered in a way that loses that meaning. Bitonal thresholding is the setting that silently erases pencil and faded thermal entries. |
| B3 | Set duplex (double-sided) scanning on, without exception, for every record, including records believed to be single-sided. | Both sides of every sheet are captured. Corrections and second-person initials on the reverse of a page are among the most commonly lost content, and the belief that a form is single-sided is not evidence. |
| B4 | Set blank-page removal off. | A genuinely blank reverse is captured as a blank image rather than silently dropped, so the page and side count reconciles. Automatic blank removal also discards pages carrying only a faint entry. |
| B5 | Set the output format to <<FILL: format, e.g. PDF/A>> with any lossy compression disabled or set to the minimum the format permits. | Text and handwriting remain legible; compression artefacts have not altered characters or digits. |
| B6 | Where the source is bound, damaged, oversized, or fragile, use a flatbed rather than the sheet feeder. | No content is lost in the gutter of a bound record, and the source is not damaged by the feed mechanism. |
| B7 | Record the actual settings used on the certification block. Do not record the intended settings. | The settings recorded match the settings the scanner reports for the job. |
Task C: scan
| Step | Action | Acceptance for this step |
|---|---|---|
| C1 | Scan the record as one unit, in its original order, including inserts placed in their correct position in the sequence. | The output is a single file, or a defined set of files with a stated relationship, and the order matches the source. |
| C2 | Scan any insert that carries content on its reverse as a two-sided item. | Insert reverses are captured. |
| C3 | For bound logbooks, scan every page in the defined range, including pages that are blank or ruled but unused, unless the parent SOP defines a different rule for unused pages. | The scanned range is continuous and its start and end are stated. |
| C4 | Do not rotate, crop, deskew, enhance, or edit any image after scanning beyond the settings applied at capture. Where the scanner applies automatic corrections, either disable them or record which corrections were applied. | The image is a capture, not an edited derivative. Any automatic processing is disclosed. |
| C5 | Review the output visually, page by page, immediately after scanning, while the source is still in front of you. | Obvious failures such as a double-feed, an upside-down page, a partially fed sheet, or a blank image are caught before the source is refiled. |
| C6 | Where any page fails, rescan that page and record the rescan on the preparation log. | The final output contains one image per page and side, and every rescan is recorded rather than silently replacing a page. |
Task D: reconcile the page count
This is the step that catches the failure nothing else catches. A double-feed produces a clean-looking file that is silently missing a page, and no amount of reviewing the file for quality will reveal it.
| Step | Action | Acceptance for this step |
|---|---|---|
| D1 | Count the images in the output. | The count is recorded. |
| D2 | Calculate the expected count: (number of sheets x 2 for duplex) + (insert images, counting both sides where applicable). | The expected count is derived from the pre-numbered source established in step A2 and the insert log from step A5, not from the output. |
| D3 | Compare the actual count to the expected count. | The two agree exactly. |
| D4 | Where they do not agree, identify every discrepancy specifically before proceeding. Do not adjust the expected count to match. | Each missing or extra image is explained. A discrepancy explained as “probably a blank” is not explained. |
| D5 | Confirm the first page of the output is page 1 of the source and the last is page M, and that the “N of M” numbering runs continuously with no gap. | The numbering sequence in the output is continuous and reaches its stated total. |
| D6 | Confirm every insert on the insert log appears in the output, in the position the log records. | Insert count in the output equals insert count on the log. |
| D7 | Record the reconciliation result on the certification block. | The count reconciliation is a recorded result, not an unrecorded belief. |
Task E: verify the content
Verification level is set by the criticality of the record, and the level is decided in the parent SOP rather than per job. State the level applied on the certification block.
| Record criticality | Verification level | Method |
|---|---|---|
| High: supports a batch disposition, a release decision, a safety report, a clinical decision, or a submission | 100 percent, page by page and side by side, against the original | Every page and side is compared to the source. Every field is read for legibility, not merely observed to be present. |
| Medium: supports a GxP activity but not a disposition or a safety decision | 100 percent page presence and order, plus content verification of a defined sample of <<FILL: percentage or number>> pages, biased toward pages carrying results, signatures, and corrections | The sample plan and its basis are stated in the parent SOP, not chosen per job. |
| Low: reference or informational records | Page count reconciliation plus content verification of <<FILL: percentage or number>> pages | The basis for treating the record type as Low is recorded. |
| Step | Action | Acceptance for this step |
|---|---|---|
| E1 | Perform verification at the level above, by a person other than the person who scanned. | Verification is independent. Self-verification does not satisfy the certified copy expectation. |
| E2 | For every page verified, confirm: all content legible, both sides present, margins and edges not trimmed, colour-carrying content rendered in colour, handwriting and corrections readable, signatures legible and identifiable. | Each of these is a specific check, not a general impression. Faint pencil and faded thermal entries are the ones to look at hardest. |
| E3 | Confirm the identifiers on the images match the source: record number, product or study, batch or subject, page numbering. | The copy cannot be mistaken for a copy of a different record. |
| E4 | Where verification finds a defect, rescan the affected page or pages and re-verify. Record the defect and the correction. | Defects are recorded, not silently fixed. A pattern of the same defect indicates a settings or process problem to raise. |
| E5 | Record the verification method, the sample where applicable, the verifier, and the date on the certification block. | Verification is attributable and dated. |
Task F: certify
| Step | Action | Acceptance for this step |
|---|---|---|
| F1 | Complete every field of the certification block below. | No field is blank. |
| F2 | The certifier signs the statement that the copy is a complete and accurate reproduction of the original, including all pages, both sides, and all inserts. | The statement is signed by a named person with the date, and that person performed or supervised the verification. |
| F3 | Store the certification with the copy, so that the copy and its evidence of verification cannot be separated. | Retrieving the copy retrieves its certification. A certification filed elsewhere is a certification that will be lost. |
| F4 | Where the certification applies to a defined batch of records rather than a single record, list every record in scope by identifier. | The scope of the certification is unambiguous and enumerable. |
Certification block
| Field | Entry |
|---|---|
| Source record identity | <<FILL: record type, product or study, batch or subject, document number>> |
| Source format, sheet count, insert count | <<FILL: e.g. paper, double-sided, 48 numbered sheets, 3 inserts>> |
| Hybrid inventory reference, if applicable | <<FILL: HYB-ID or N/A>> |
| Electronic half retained separately (if hybrid) | <<FILL: system and identifier, or N/A>> |
| Preparation log reference | <<FILL>> |
| Scanned by, date | <<FILL>> |
| Scanner asset ID and qualification reference | <<FILL>> |
| Settings actually used | <<FILL: resolution, colour mode, duplex, blank-page removal, output format, compression>> |
| Expected image count and actual image count | <<FILL>> / <<FILL>> |
| Page-count reconciliation result | Agreed / Discrepancy resolved (describe) |
| Verification level applied and basis | <<FILL: 100 percent / sample of N, per record criticality>> |
| Verification method | <<FILL>> |
| Verified by, date | <<FILL>> |
| Defects found and corrected | <<FILL: none, or list with the correction>> |
| Certification statement | Verified as a complete and accurate reproduction of the original record, including all pages, both sides, and all inserts. |
| Certified by, signature, date | <<FILL>> |
| Stored location and index entries | <<FILL>> |
| Original paper disposition at this date | <<FILL: retained, filed at ...>> |
Task G: index
A certified copy nobody can find fails on availability just as thoroughly as one that was never made.
| Step | Action | Acceptance for this step |
|---|---|---|
| G1 | Name the file per the naming convention in <<FILL: naming convention reference>>. | The name is deterministic: a second person given the same record produces the same name. |
| G2 | Index the copy against the identifiers a future reviewer will actually search: <<FILL: e.g. product, batch, study, subject, date, document number, record type>>. | Each index field is populated and matches the source record. |
| G3 | Where the record is part of a hybrid, index the identifier of the electronic half alongside it. | A future reviewer can retrieve both halves from one search. |
| G4 | Record the index entry on the certification block. | The location is documented at the time of certification, not reconstructed later. |
| G5 | Perform a retrieval check: close the file, search the index for the record as a reviewer would, and open the result. | The record was retrieved by search rather than by knowing where it was put. |
Task H: store, protect, and back up
| Step | Action | Acceptance for this step |
|---|---|---|
| H1 | Store the copy in <<FILL: repository>> with access control appropriate to the record. | Only authorised roles can read it; only authorised roles can change it. |
| H2 | Confirm the location is covered by the backup schedule, and record the date of the last tested restore. | A backup that has never been restored from is a hypothesis. |
| H3 | Confirm the copy cannot be modified without traceability. Any later annotation, re-scan, or re-index is recorded. | Change to a certified copy is visible, or the copy is held in a form that prevents change. |
| H4 | Confirm the retention period applied to the copy is at least the retention period of the original, per <<FILL: retention schedule reference>>. | Retention is set explicitly rather than inherited by accident. |
| H5 | Where the copy replaces the original as the retained record, confirm the copy is at least as durable and as available as the paper was. | Durability and retrievability are equal or better, and this is recorded rather than assumed. |
Task J: hold checks before any paper original is destroyed
Destruction is a separate, later, deliberately controlled decision, made under the parent SOP and the retention procedure. It is never a step in scanning. Every condition below is confirmed and recorded before a destruction request proceeds. Any single failed condition stops the request.
| # | Condition | How it is confirmed | Acceptance |
|---|---|---|---|
| J1 | A certified copy exists for the record, certification complete and signed | Retrieve the certification block | Certification is present, complete, and names a verifier |
| J2 | The verification was performed before the paper left controlled custody | Preparation log and certification dates | Verification date precedes any transfer or destruction request. Verification after destruction is not verification. |
| J3 | The copy is retrievable by index search and opens correctly today | Perform the retrieval | The record was retrieved and read, not merely located |
| J4 | The copy is on backed-up media with a restore tested within <<FILL: interval>> | Backup and restore test records | Restore test is current |
| J5 | The record is static. If the paper is a printout of dynamic electronic data, the underlying electronic data and its audit trail are retained and under control | Hybrid inventory entry and the electronic half’s retention record | The electronic original is retained independently. Destroying the paper printout is permissible only because the printout was never the original; destroying the electronic data is not permitted by this route at all. |
| J6 | A documented, approved policy authorises destruction for this record type, stating the record types in scope and the retention terms | Retention and destruction policy <<FILL: reference>> | Policy is current and covers this record type explicitly |
| J7 | No local legal, national, contractual, or clinical-trial obligation requires retention of the paper original for this record type in the applicable jurisdictions | Documented confirmation from <<FILL: function, e.g. Legal / Regulatory Affairs>> | Confirmation is on file and current, treated as part of the approval rather than an afterthought |
| J8 | The record is not subject to any hold: open investigation or deviation, open or announced inspection, regulatory request, litigation hold, product complaint, recall, or any hold flagged in the quality system | Hold check against <<FILL: quality system and hold register>>, performed and recorded on the destruction request | The hold check is performed at the time of the destruction request, not at the time of scanning, and is recorded with its date |
| J9 | The retention period for the original has expired per the retention schedule | Retention schedule calculation | Expiry date is calculated and recorded |
| J10 | The destruction is approved, scheduled, witnessed, and recorded, and the record of destruction is itself retained | Destruction record | The record of what was destroyed, when, by whom, and under what approval outlives the thing destroyed |
The hold check in J8 is the one that most often fails in practice, because it lives in a different procedure from the destruction schedule and nobody consults it. Build it into the destruction request form so it cannot be skipped.
References
21 CFR 211.180 (general records requirements) and 211.194 (laboratory records). 21 CFR Part 11 (electronic records and electronic signatures), where the copy becomes an electronic record relied on to satisfy a predicate rule. EU GMP Chapter 4 (Documentation) and EU GMP Annex 11 (Computerised Systems). FDA guidance, Data Integrity and Compliance With Drug CGMP, Questions and Answers (December 2018), which addresses true copies and the difference between static and dynamic records. MHRA GXP Data Integrity Guidance and Definitions (March 2018), which defines true copy and certified copy. PIC/S PI 041, Good Practices for Data Management and Integrity in Regulated GMP/GDP Environments. ICH E6 Good Clinical Practice, for certified copy expectations applied to clinical source documents.
Confirm the current version and clause numbers of each reference before issue.
Filled specimen
The following certification block is completed for an example executed batch record. Company, names, numbers, and dates are illustrative; replace them with your own.
| Field | Entry |
|---|---|
| Source record identity | Executed batch manufacturing record, product code MAB-2210, 50 mg tablets, batch A-2274, document BMR-114 rev 6 |
| Source format, sheet count, insert count | Paper, double-sided, 48 numbered sheets (“page N of 48”), 3 inserts: one taped-in dispensing printout (single-sided), one appended line-clearance photograph sheet (single-sided), one fold-out cleaning record (content on both sides) |
| Hybrid inventory reference | HYB-003 |
| Electronic half retained separately | Process historian, batch window 09 July 2026 04:12 to 11 July 2026 02:40; alarm and event extract EXT-2026-0771. Retained under the historian retention schedule and unaffected by this copy. |
| Preparation log reference | PREP-2026-0219 |
| Scanned by, date | M. Okafor, 14 July 2026 |
| Scanner asset ID and qualification reference | SCN-04, qualification QUAL-IT-2025-018, requalification due 30 November 2026 |
| Settings actually used | 300 dpi, colour, duplex on, blank-page removal off, PDF/A, compression disabled |
| Expected image count and actual image count | Expected 100 (48 sheets x 2 = 96, plus 2 single-sided inserts = 2, plus 1 double-sided insert = 2). Actual 100. |
| Page-count reconciliation result | Agreed. Initial scan returned 98 images. Investigation identified a double-feed at sheets 31 and 32, which produced a clean-looking file missing two images with no visible defect. Sheets 31 and 32 were rescanned individually on the flatbed and reinserted in position. Rescan recorded on PREP-2026-0219. |
| Verification level applied and basis | 100 percent, page by page and side by side. Basis: batch record supports batch disposition, classified High criticality in the record type table. |
| Verification method | Each of the 100 images compared against the corresponding physical page or side. Every recorded value, signature, initial, correction, and insert checked for legibility. Red-ink corrections on sheets 12 and 29 confirmed rendered in colour. |
| Verified by, date | S. Lindqvist, 15 July 2026 |
| Defects found and corrected | Two: the double-feed described above; and sheet 44 reverse initially scanned with the lower margin trimmed by the feeder, rescanned on the flatbed with the full margin captured. Both recorded and re-verified. |
| Certification statement | Verified as a complete and accurate reproduction of the original record, including all pages, both sides, and all inserts. |
| Certified by, signature, date | S. Lindqvist, signed, 15 July 2026 |
| Stored location and index entries | Document archive repository, path /archive/bmr/2026/A-2274; indexed by product, batch A-2274, record type “executed batch record”, manufacturing date range, document number BMR-114, and cross-indexed to historian extract EXT-2026-0771 |
| Original paper disposition at this date | Retained, filed in manufacturing archive location ARC-B-14, pending scheduled destruction per the retention procedure. Not destroyed. |
Two things in this specimen carry the weight. The first is that the count reconciliation failed on the first attempt and the record says so. A double-feed at sheets 31 and 32 produced a file that looked perfect, and only the arithmetic caught it; a certification that never records a discrepancy across hundreds of batch records is more likely to indicate that nobody counted than that nothing ever went wrong. The second is the last row. It says “retained”, not “destroyed”. Producing a certified copy and deciding to destroy an original are two different decisions taken at two different times under two different approvals, and the hold checks in Task J stand between them.
Common inspection findings this work instruction prevents
- Paper originals destroyed after scanning with no verification step, so the files described as certified copies were never certified.
- Double-sided originals scanned single-sided, losing corrections and second-person initials recorded on the reverse.
- A page silently missing from a scanned batch record because a double-feed was never caught by a page-count reconciliation.
- Inserts, taped-in printouts, and appended slips absent from the copy because they were removed during preparation and never logged.
- Red-ink corrections and colour-coded status stamps scanned in greyscale or bitonal mode, so the meaning carried by colour is lost.
- Pencil or faded thermal entries scanned blank because a bitonal threshold was applied by default.
- Printouts of dynamic electronic data scanned and the underlying electronic data deleted, on the reasoning that the archive now holds the record.
- Certified copies stored on media with no tested restore, or indexed so poorly they cannot be produced during an inspection within a reasonable time.
- Destruction proceeding on schedule while the batch was under investigation, because the hold check lived in a different procedure that nobody consulted.
- Verification performed by the same person who scanned the record, so the independent check never existed.
How to adapt this work instruction
- Set the work instruction number and point the parent SOP field at your real records and archiving procedure.
- Set the resolution, colour, and format values in Task B from your scanner qualification, not from this document. Then check that the qualification actually tested the settings you are specifying, including the low-contrast and colour cases.
- Define the record criticality tiers in Task E and map your record types to them centrally, in the parent SOP, so the verification level is never a per-job judgement.
- Where a source record type does not state its own page total, either introduce “page N of M” numbering on the form or accept that the verification level rises to 100 percent for that record type. Record which choice you made and why.
- Build the Task J hold checks into your destruction request form as mandatory fields, so a request cannot be submitted without them. The J8 hold check is performed at the time of the destruction request, not carried forward from the scanning date.
- For clinical records, add the certified copy expectations from your sponsor procedures and the trial master file filing conventions, and account for copies produced at investigator sites rather than centrally.
- For records at risk of degradation, such as thermal output, add a trigger to your execution procedures so the copy is made on the day the record is produced rather than at archive time.
- Confirm every regulation in the references section against the current published version before issue.