Risk-Based Life Cycle Management of Master Production and Control Records to Strengthen Data Integrity and GMP Inspection Readiness Part 2: Practical Considerations for CGMP Documentation Systems

Published on: 

This article discusses risk-based lifecycle governance, system implementation considerations, and the progression of batch record control from paper-based to fully electronic systems.

In Part 1 of this article, the regulatory framework, inspectional findings, and governance considerations for master production and control records (MPCRs) and batch production and control records (BPCRs) were evaluated, including the role of standardized templates and spreadsheet-based systems in supporting data integrity and compliance. Part 2 focuses on risk-based lifecycle governance, system implementation considerations, and the progression of batch record control from paper-based to fully electronic systems.

Risk-Based Governance and Lifecycle Implications for MPCR Systems

The findings of this evaluation demonstrate that the design, control, and lifecycle management of MPCRs and BPCRs are critical to ensuring consistent manufacturing operations and maintaining data integrity in current good manufacturing practice (CGMP)-regulated environments. Deficiencies in documentation completeness, standardization, and reproducibility highlight the importance of applying quality risk management (QRM) principles to manufacturing documentation systems.

From a risk management perspective, MPCRs and BPCRs serve as primary controls to ensure that manufacturing processes are executed consistently and in accordance with validated procedures. Incomplete or poorly controlled MPCR templates increase the risk of operator error, omission of critical process parameters, and inconsistent documentation practices. These risks may compromise batch traceability, impair manufacturing performance evaluation, and reduce confidence in product quality.

Application of structured documentation controls, including standardized templates, defined data-entry fields, calculation controls, and appropriate verification steps, reduces the likelihood of documentation errors and improves the reliability of production records. These controls represent the practical implementation of risk-based documentation design principles consistent with International Council for Harmonisation (ICH) Q9 expectations.1 The hierarchy of documentation controls is illustrated in Figure 1.

The evaluation also demonstrated that documentation format and system design significantly influence the effectiveness of documentation controls. Paper-based systems, particularly those relying on manually completed templates, were more frequently associated with legibility issues, transcription errors, and inconsistencies in record completion. Hybrid systems provided incremental improvements but required careful coordination between paper and electronic components. Fully electronic systems, when properly validated and implemented with appropriate access controls and audit trail functionality, demonstrated improved traceability, legibility, and documentation consistency in accordance with 21 CFR Part 11.2

Control of Paper-Based, Electronic Spreadsheet, and Fully Electronic Batch Records During Manufacturing Operations

Control of batch records during manufacturing is essential to ensure data integrity, traceability, and compliance with CGMP requirements. In paper-based systems, control is achieved through physical document management, including defined ownership, controlled movement between processing areas, and the use of operator initials linked to a signature manifestation page. The batch record must remain with the process to support contemporaneous documentation and prevent loss, unauthorized access, or retrospective entries.

In electronic spreadsheet-based systems, control is achieved through validated system functionality rather than physical handling. Batch records should reside within a secure, access-controlled environment, with operators entering data at the point of use using unique credentials. Audit trails must capture all data entries and modifications, and templates should be protected to prevent unauthorized changes. These controls ensure that electronic records are trustworthy, reliable, and equivalent to paper records, consistent with 21 CFR Part 11.

Fully electronic batch record systems (eg, manufacturing execution systems/electronic batch record systems [MES/EBR]) provide higher control through system-enforced workflows, real-time data capture, and integrated process controls.

MES/EBR systems functionality are database-driven platforms that manage manufacturing workflows and capture batch documentation in real time. Data entry is guided by predefined sequences that prevent out-of-order execution, enforce completion of required fields, and restrict user actions based on defined roles and permissions. Audit trails are automatically generated, secure, and non-modifiable, ensuring complete traceability.

While handwritten initials are acceptable in paper records, electronic systems require enhanced controls to ensure equivalent or greater accountability. In spreadsheet-based systems, operator initials may be used for routine entries when supported by authenticated access and audit trails; however, electronic signatures should be applied at defined critical process steps, verification activities, and approval points. In fully electronic systems, electronic signatures are embedded within system workflows and enforced at each required step.

A risk-based approach should define which steps require enhanced controls, such as material additions, weighing operations, and process-critical decisions. In spreadsheet-based systems, this may include step-specific re-authentication or electronic signature prompts. In fully electronic systems, such controls are inherently managed through workflow configuration, system validation, and role-based permissions. Any modification to critical data should require documented justification supported by audit trail entries, consistent with the FDA’s data integrity principles (attributable, legible, contemporaneous, original, accurate; ALCOA+).

Electronic systems should not replicate paper practices but enhance control through authentication, audit trails, and structured workflows. Fully electronic, database-driven systems provide the highest level of control by integrating process execution with data capture and review, thereby reducing opportunities for error and improving inspection readiness. When properly implemented, all 3 approaches (paper-based, spreadsheet-based, and fully electronic) can support compliant manufacturing operations; however, fully electronic systems offer the most robust and sustainable solution for data integrity and lifecycle management. Figure 2 illustrates the progression of batch record control from paper-based to fully electronic systems.

These observations are consistent with established pharmaceutical quality system principles emphasizing lifecycle management, change control, and continual improvement.3 MPCRs represent controlled manufacturing instructions that must remain accurate and current throughout the product lifecycle. Effective change management processes ensure that revisions to manufacturing processes, equipment, materials, or procedures are appropriately reflected in MPCR templates and consistently implemented during BPCR execution.

Systems that support controlled template revision, version management, and documented approval processes facilitate compliance with lifecycle management expectations described in ICH Q10.3 The risk-based lifecycle governance model illustrating the development, approval, execution, review, and change-controlled maintenance of MPCRs within the pharmaceutical quality system is shown in Figure 3.

The model integrates lifecycle management principles described in ICH Q10 with QRM principles described in ICH Q9, supporting structured documentation governance and continuous improvement throughout the manufacturing documentation lifecycle.

The findings also underscore the importance of quality unit (QU) oversight in ensuring the completeness and accuracy of production records. Consistent with 21 CFR 211.22 and 211.192,4 the QU is responsible for reviewing and approving production records and investigating discrepancies. Structured documentation systems that incorporate standardized formats, structured data entry, and controlled template governance facilitate efficient and thorough QU review.

Electronic documentation systems, including spreadsheet-based and database-driven approaches, demonstrated the potential to improve documentation consistency and reduce transcription errors when implemented with appropriate validation and governance controls. However, implementation must include validation, access controls, audit trails, and electronic signatures to ensure compliance with 21 CFR Part 11. 2

Independent research has shown that spreadsheet errors are common when governance controls are inadequate.5,6 These findings reinforce the importance of structured validation, lifecycle management, and governance controls. When properly controlled, spreadsheet systems can support reliable documentation and maintain data integrity consistent with CGMP and ICH Q7/Q10 principles.3,7

Spreadsheet governance controls, summarized in Table 4 of Part 1, represent the practical implementation of ICH Q9 risk-based control principles and ICH Q10 lifecycle management expectations as applied to MPCR template design, validation, and maintenance.

These controls support documentation consistency, improve reproducibility, and strengthen data integrity throughout the documentation lifecycle. An example of a standardized MPCR spreadsheet template is shown in Figure 4a and 4band provided in Supplementary File S1 (see Part 1 of this article).

Advertisement

Previous FDA Laboratory Information Bulletins describing spreadsheet design, verification, validation, lifecycle management, and the implementation of 21 CFR Part 11 controls provide practical examples of these governance principles.14–16

Supplementary File S1 presents a representative example of a standardized spreadsheet-based MPCR template illustrating structured documentation design, template governance, and lifecycle management controls.

From a lifecycle management perspective, documentation systems must support ongoing process improvements, manufacturing changes, and continued process verification. Flexible documentation systems that allow controlled updates while maintaining appropriate validation and change control enable continual improvement, consistent with ICH Q10 lifecycle management principles.3 The ability to maintain accurate, controlled, and reproducible MPCR templates throughout the product lifecycle is essential for ensuring consistent manufacturing performance and regulatory compliance. A validated MPCR approval and BPCR execution workflow is shown in Figure 5.

Effective batch documentation systems must maintain clear traceability between MPCR instructions, executed BPCR entries, supporting production and laboratory records, and QU review activities. A representative documentation traceability framework is presented in Table 1.

Overall, these findings support the application of a risk-based approach to MPCR and BPCR development and lifecycle management. Implementation of structured documentation controls, standardized templates, validated electronic systems, and effective QU oversight strengthens documentation reliability, enhances data integrity, and supports consistent manufacturing operations in accordance with CGMP requirements and internationally harmonized pharmaceutical quality system principles.1-4, 7

From a regulatory perspective, effective governance of MPCRs represents a critical control mechanism within the pharmaceutical quality system. MPCR templates translate validated manufacturing processes into controlled operational instructions and serve as the foundation for the execution of BPCRs. When documentation systems incorporate standardized template structures, defined data-entry controls, and change-controlled lifecycle management practices, they support reliable documentation, improve QU oversight, and reduce the risk of transcription errors or incomplete records. The integration of quality risk management principles described in ICH Q9 with lifecycle management expectations described in ICH Q10 provides a structured framework for maintaining accurate and reproducible manufacturing instructions while supporting continuous improvement of documentation systems.

Strategic Importance of Risk-Based MPCR Lifecycle Management

MPCRs and BPCRs are foundational elements that ensure consistent manufacturing operations and data integrity. The findings presented in this article demonstrate that deficiencies in MPCR design, standardization, and lifecycle management can contribute to documentation errors, increased compliance risk, and inefficiencies in production and QU review processes.

Application of QRM principles, as described in ICH Q9, supports a systematic approach to identifying and mitigating documentation-related risks by focusing controls on critical data elements, process parameters, and verification steps.1 Poorly structured or inconsistently controlled MPCR templates increase the likelihood of operator error, omission of critical information, and variability in record execution. Conversely, standardized and well-governed documentation systems reduce these risks and improve the reproducibility of batch records.

Lifecycle management principles outlined in ICH Q10 further emphasize the importance of maintaining MPCRs as controlled, current, and effective manufacturing instructions throughout the product lifecycle.3 Effective change management, version control, and documentation governance are essential to ensure that process changes are accurately reflected in MPCR templates and consistently implemented during BPCR execution.

The evaluation identified that documentation format and system design materially influence documentation quality and operational efficiency. Word-processing-based batch record templates, commonly used to generate paper-based records, were more frequently associated with formatting inconsistencies, manual transcription errors, legibility challenges, and extended review times. In contrast, spreadsheet-based batch record templates demonstrated functional characteristics that supported improved standardization, structured data entry, and calculation accuracy. These attributes facilitated more consistent execution of BPCRs and improved efficiency in documentation review and maintenance.

Database-driven systems provide strong control but require greater implementation, validation, and lifecycle effort, particularly when managing changes that involve system modification and revalidation, compared with more flexible template-based approaches. These factors may affect implementation timelines and resource allocation, particularly in environments where manufacturing processes evolve throughout the product lifecycle.

When implemented within controlled and validated environments, electronic documentation systems—including spreadsheet-based and database-driven approaches—supported improved traceability, enhanced documentation control, and strengthened data integrity. Fully electronic implementations require appropriate validation, access controls, audit trail functionality, electronic signatures, and change management to ensure compliance with electronic records and signatures requirements under 21 CFR Part 11.2

To further illustrate the practical application of lifecycle-based batch documentation principles, an example MPCR template is provided in Supplementary File S1. The template demonstrates how regulatory requirements under 21 CFR 211.186 and 211.188 can be operationalized within a structured, inspection-ready documentation framework. By integrating data integrity safeguards, critical process parameter oversight, in-process control documentation, and deviation tracking, the model highlights how modern MPCR systems can support proactive compliance and sustained GMP performance. While simplified for publication clarity, the template reflects current FDA inspection expectations and emphasizes the importance of disciplined documentation control throughout the product lifecycle.

Overall, these findings support the application of a risk-based approach to MPCR and BPCR development and lifecycle management. Documentation systems that incorporate standardized templates, structured data capture, effective change management, and appropriate validation and security controls can enhance documentation reliability, strengthen data integrity, and promote consistent manufacturing performance. Alignment of documentation practices with CGMP requirements and internationally harmonized guidance, including ICH Q7, ICH Q9, and ICH Q10, further reinforces regulatory compliance and supports continued assurance of product quality throughout the manufacturing lifecycle.1,3,4,7

Alignment with FDA Inspectional Expectations and International GMP Standards

MPCRs and BPCRs are essential documentation controls required under current CGMP regulations, including 21 CFR 211.186 and 21 CFR 211.188, to ensure consistent manufacturing operations and reliable documentation of production activities.4 The findings presented in this article highlight the importance of applying risk-based documentation design, lifecycle management, and effective change control to maintain the accuracy, completeness, and reproducibility of manufacturing records.

This evaluation demonstrates that deficiencies in documentation structure, standardization, and governance can increase the risk of data integrity issues, documentation errors, and inefficiencies in production and QU review processes. Implementation of structured documentation controls, standardized templates, and validated electronic systems can support improved traceability, enhance documentation reliability, and facilitate compliance with regulatory requirements, including electronic records and electronic signatures requirements under 21 CFR Part 11.2FDA data integrity guidance further emphasizes the importance of complete, consistent, and accurate documentation to support CGMP compliance.8

Alignment of MPCR and BPCR lifecycle management practices with internationally harmonized guidance—including ICH Q7, Q9, and Q10—supports a systematic and risk-based approach to documentation control.1,3,7 These principles emphasize lifecycle governance, effective change management, and continual improvement, which are crucial for maintaining accurate manufacturing instructions and ensuring consistent execution of validated processes.

These documentation principles are also consistent with master-formula and GMP expectations described in WHO, European Union, PIC/S, and Health Canada guidance.9–13

Acknowledgment

The author acknowledges Tyson Mew, President of Ofni Systems Inc., for technical consultation regarding spreadsheet-based electronic documentation systems and implementation considerations related to electronic records, audit trails, and data integrity controls. His technical perspective contributed to the practical context discussed in this article. The author also acknowledges his former colleagues at the U.S. Food and Drug Administration for their dedication to advancing pharmaceutical quality, regulatory compliance, and data integrity practices.

Conflict of Interest

The author declares no conflicts of interest.

Disclaimer

The views expressed in this article are those of the author and do not represent the official position of the U.S. Food and Drug Administration.

References

  1. International Council for Harmonization.ICH Q9(R1): Quality Risk Management. January 18, 2023. Accessed February 23, 2026 https://database.ich.org/sites/default/files/ICH_Q9%28R1%29_Guideline_Step4_2023_0126_0.pdf
  2. U.S. Food and Drug Administration. Code of Federal Regulations, Title 21, Part 11: Electronic Records; Electronic Signatures. Accessed April 7, 2026. https://www.ecfr.gov/current/title-21/chapter-I/subchapter-A/part-11
  3. International Council for Harmonization. ICH Q10: Pharmaceutical Quality System. June 2008. Accessed February 23, 2026. https://database.ich.org/sites/default/files/Q10%20Guideline.pdf
  4. U.S. Food and Drug Administration. Code of Federal Regulations, Title 21, Parts 210 and 211: Current Good Manufacturing Practice for Finished Pharmaceuticals. Accessed April 7, 2026.
    https://www.ecfr.gov/current/title-21/chapter-I/subchapter-C/part-210
    https://www.ecfr.gov/current/title-21/chapter-I/subchapter-C/part-211
  5. Panko R R. Spreadsheet errors: What we know and what we think we can do. Proceedings of EuSpRIG 2000. Accessed April 7, 2026. https://arxiv.org/pdf/0802.3457
  6. Panko R R. Spreadsheet Research Website. Accessed April 7, 2026. https://panko.com/ssr/Ray%27sPublications.html
  7. International Council for Harmonization.ICH Q7: Good Manufacturing Practice Guide for Active Pharmaceutical Ingredients. November 10, 2000. Accessed February 23, 2026 https://database.ich.org/sites/default/files/Q7%20Guideline.pdf
  8. U.S. Food and Drug Administration. Data Integrity and Compliance with Drug cGMP: Questions and Answers - Guidance for Industry. December 2018. Accessed April 7, 2026. https://www.fda.gov/media/119267/download
  9. World Health Organization. Quality Assurance of Pharmaceuticals: Guide to Master Formulae. Geneva, Switzerland, 2011. Accessed April 7, 2026. https://www.scribd.com/document/487319885/guide-to-master-formulae-final2021-pdf
  10. World Health Organization. Good Manufacturing Practices for Pharmaceutical Products: Main Principles. WHO Technical Report Series No. 908, Annex 4, 2003. Geneva, Switzerland. Accessed April 7, 2026. https://gmpua.com/World/WHO/Annex4/trs908-4.pdf
  11. European Commission. EudraLex Volume 4: EU Guidelines for Good Manufacturing Practice for Medicinal Products for Human and Veterinary Use, including Chapter 4 (Documentation). Current consolidated version. Brussels, Belgium. Accessed April 7, 2026. https://health.ec.europa.eu/medicinal-products/eudralex/eudralex-volume-4_en
  12. Pharmaceutical Inspection Co-operation Scheme. Guide to Good Manufacturing Practice for Medicinal Products (PE 009-17), Part I and Part II. Effective August 25, 2023. Geneva, Switzerland. Accessed April 7, 2026. https://picscheme.org/docview/6606
  13. Health Canada. Good Manufacturing Practices (GMP) Guidelines (GUI-0001). Health Products and Food Branch Inspectorate, Government of Canada. Accessed April 7, 2026. https://www.canada.ca/en/health-canada/services/drugs-health-products/compliance-enforcement/good-manufacturing-practices/guidance-documents/gmp-guidelines-0001/document.html
  14. Cantellops D. Spreadsheet design and validation for multi-user applications in chemistry laboratories, Part I. Laboratory Information Bulletin (LIB) No. 4317. U.S. Food and Drug Administration, 2003. Accessed April 7, 2026. https://www.spreadsheetvalidation.com/pdf/LIB_Design_Multi-User2A.pdf
  15. Cantellops D. Spreadsheet design, verification, validation, use, and storage of single-user workbook files in FDA laboratories, Part II. Laboratory Information Bulletin (LIB) No. 4349. U.S. Food and Drug Administration, 2005. Accessed April 7, 2026. https://www.spreadsheetvalidation.com/pdf/LIB_Part_II_Single-User.pdf
  16. Cantellops D. Evaluation of ExcelSafe to implement 21 CFR Part 11 requirements in FDA analyst workbook files. Laboratory Information Bulletin (LIB) No. 4524. U.S. Food and Drug Administration, 2012. Accessed April 7, 2026. https://www.ofnisystems.com/LIB-4524-FDA-431-and-ExcelSafe.pdf