
The instruments on the bench.
Interactive reference tools and self-audit checklists for GxP quality work. Everything on this page runs in your browser. No login, no data sent anywhere.
Self-audit checklists.
Detailed structured checklists to evaluate compliance programs, designed to find what FDA and EMA inspectors find.
- 01 Open →DI
Data Integrity Self-Audit
5-layer DI compliance audit: infrastructure controls, system configuration, procedural controls, work practice forensics, and culture indicators. Structured around FDA, MHRA, WHO, and PIC/S DI expectations.
- 02 Open →CSV
CSV / CSA Program Self-Audit
Evaluate your computer system validation program: system inventory, GAMP category assignments, validation documentation quality, traceability, supplier assessment, change control, and periodic review. Aligned with GAMP 5 Second Edition and FDA CSA final guidance (Feb 2026).
- 03 Open →EQ
Equipment Qualification Audit
Full lifecycle qualification audit for analytical instruments and manufacturing equipment: DQ, IQ, OQ, PQ, calibration, maintenance, periodic review, and change control. References USP <1058>, EU Annex 15, and ISPE C&Q Baseline Guide.
- 04 Open →QMS
QMS Self-Audit
Complete quality management system audit: document control, deviation management, CAPA quality and effectiveness, change control, training, supplier qualification, internal audits, and quality metrics. Aligned with ICH Q10 and FDA/EMA inspection expectations.
Interactive quick-reference.
Client-side reference tools for common GxP assessments. Nothing is sent anywhere, these run in your browser.
ALCOA+ Self-Assessment
0 / 9Evaluate a GxP record or system against all nine ALCOA+ principles. Check each principle only if your current controls fully satisfy it.
Verify: unique named accounts (no shared or generic logins); e-signatures bound to the record with name, date and meaning; the audit trail captures the user for every create, modify and delete.
Common failures: shared instrument or "admin" logins; generic accounts; e-signatures not tied to an individual; an audit trail that records the change but not who made it.
How to fix: enforce unique accounts (ideally SSO), disable shared logins, configure the audit trail to capture identity, and bind e-signatures per 21 CFR Part 11.
Verify: permanent media (ink or controlled electronic); corrections made with a single-line strike-through plus initial, date and reason; electronic data not held in obsolete or proprietary formats that can no longer be rendered.
Common failures: pencil entries; correction fluid or whitespace over an error; data trapped in a format the current software can no longer open.
How to fix: ink or electronic capture only; apply good-documentation-practice correction rules; preserve readability through format and migration controls.
Verify: entries made in real time; system clocks synchronized (NTP) and not user-editable; timestamps match the true order of events; no backdating.
Common failures: recording later from scratch paper; backdated entries; local clock drift or a clock a user can change.
How to fix: require real-time entry, lock system clocks to NTP, and review audit-trail timestamps against the expected sequence.
Verify: raw data retained; dynamic records kept dynamic (a chromatogram stays re-integratable, not flattened to a PDF); any copy certified as a true copy.
Common failures: keeping only the printed report; deleting raw data after processing; storing a PDF of a record that should remain dynamic.
How to fix: retain raw and dynamic data for its full lifecycle, define a true-copy procedure, and archive originals.
Verify: values are not manipulated; integration methods and parameters are controlled; a second person reviews critical data; calculations are verified.
Common failures: re-integrating until a result passes; overriding a parameter without justification; transcription errors carried forward.
How to fix: lock integration methods, control parameter changes, and use audit-trail review (by exception) to catch undocumented edits.
Verify: every run is present including failed, aborted, repeated and out-of-specification results; nothing is selectively deleted; the audit trail is intact.
Common failures: deleting a "bad" injection; trial or test runs not recorded; selective reporting of only the passing result.
How to fix: disable record deletion, require every run to be recorded and justified, and review the audit trail for gaps.
Verify: timestamps and sequences are in the expected chronological order within a record and reconcile across independent systems (instrument, LIMS, ERP).
Common failures: timestamps out of order; the same event recorded with different times in two systems; time-zone mismatches across sites.
How to fix: synchronize time across systems, define a single time-zone convention, and reconcile cross-system records.
Verify: durable storage; defined retention periods; backups that are actually tested by restore; migrations that preserve both data and meaning.
Common failures: data on a single un-backed-up drive; backups never test-restored; retention period undefined; a migration that drops metadata or the audit trail.
How to fix: implement backup with tested restore, set a retention schedule, archive properly, and validate any data migration.
Verify: records can be retrieved and presented in readable form across the whole retention period, including quickly to an inspector; access controls do not block legitimate retrieval.
Common failures: data locked inside a decommissioned system; no way to read an archived format; retrieval that takes days during an inspection.
How to fix: archive with a retrieval capability, migrate data off decommissioned systems, and confirm a readable export exists.
GAMP 5 Category Decision Aid
Answer a short series of questions to determine the GAMP 5 software category. Based on GAMP 5 Second Edition (2022). Note: Category 2 was retired, so the categories are 1, 3, 4 and 5. Categorize each component; a system can contain pieces of more than one category.
483 Response Completeness Check
0 / 10Before submitting a 483 response, verify each element is present and substantive. Check only items that are genuinely complete, not just drafts.
Validation Deliverable Selector
Select validation type to see required and recommended deliverables. Based on GAMP 5 Second Edition and FDA/EMA expectations.