Small Devices – Incomplete Data – Big Trouble

This is the first post in a short blog series on Data Integrity. I'll share practical experiences from audits and assessments, combined with recent regulatory observations and emerging guidance. I look forward to your feedback and would be happy to discuss your thoughts.

Figure 1: Graphical Abstract for this blog. Created with the support of an AI assistant!

Why small devices deserve attention

During audits, I always pay particular attention to small stand-alone devices such as particle counters, filter integrity testers, and balances. They often reveal how seriously an organization takes Data Governance and Data Integrity. They provide an excellent opportunity to compare the SOP world with the shop-floor reality. As an added benefit, many of these devices are widely used, so experienced auditors already know their strengths—and their weaknesses.

Typical challenges include:

  • Limited integration into automation systems, often “hybrid data

  • Controls that can be relatively easy to circumvent, depending on the implementation

  • Devices that are moved between rooms or manufacturing areas, making traceability more difficult

  • Suppliers with surprisingly weak Data Integrity capabilities ("The URS was written after the purchasing decision? That explains a lot...")

Recent regulatory action

These issues recently resulted in an FDA Warning Letter [1] citing 21 CFR 211.194(a), which requires laboratory records to include complete data. The observations can be grouped into three key themes:

Table 1: Quick Overview of the Findings.

How can we improve?

These issues must be addressed regardless of regulatory expectations. Discarding failed measurements—such as particle counts—doesn't improve quality; it simply creates a false picture while increasing the risk to product quality and, ultimately, patient safety.

An effective approach combines technical, procedural, and cultural controls.

Technical controls

  • Integrate stand-alone devices directly with higher-level systems such as MES or LIMS.

  • Use automated review-by-exception workflows to identify aborted runs, failed tests, or unusual patterns for human review.

Procedural controls

  • Implement meaningful audit trail reviews that assess not only individual runs but also the relationship between consecutive runs and repeated testing.

Cultural enablers

  • Conduct regular Gemba walks to understand how work is actually performed and encourage open dialogue between operators and quality personnel.

  • Foster an environment where employees feel comfortable speaking up and reporting mistakes without fear. Strong Data Integrity begins with the right culture.

What comes next?

You may have noticed that I mentioned "3 + 1" observations.

The additional point may explain why this case escalated from an FDA Form 483 to a Warning Letter. While the company's response focused on corrective actions for the specific Data Integrity failures, it did not sufficiently assess the broader impact on other operations or the potential consequences for product quality.

This broader, system-level perspective will be the focus of my next blog post.

Stay tuned and sign up for more content here.

Previous
Previous

Alarms Are Forgotten… Until an Inspector Asks for Them

Next
Next

Implementing AI/ML in GMP: Guardrails as Risk Controls