Skip to content

25.18 — Audits and Inspections

Two inspectors arrive at reception at nine in the morning. They present credentials and a notice of inspection. Nobody outside the quality department knew they were coming, and in some countries nobody is entitled to know.

For the next four to ten days, two people with the power to stop the site from shipping product will walk the floor, read records, interview operators, and follow anything that interests them. What they write at the end can cost the company a product, a plant, or in the worst cases its ability to sell in that country at all.

Every procedure, every signature and every audit trail in this Part exists to make that week survivable. This chapter is what actually happens in it, and the exact ladder of consequences that follows.

Three kinds of visit, with different powers

Internal audits — called self-inspections in Europe — are the company auditing itself on a schedule, covering every area over a defined cycle. They are required by GMP. Their whole value depends on being genuinely independent and genuinely uncomfortable: an internal audit that never finds anything is not evidence of excellence, it is evidence of a weak audit programme. Findings from internal audits are generally protected from disclosure to regulators in most jurisdictions, precisely so that companies are not punished for looking hard at themselves.

Supplier and vendor audits are the company auditing organisations it depends on — an active ingredient manufacturer, a contract laboratory, a packaging supplier, a software vendor hosting a GxP system. The rule underneath is that you can outsource an activity but not the responsibility for it (Chapter 25.9), so the customer must know their supplier is competent and must periodically verify it. If your company hosts or operates a system for a life sciences client, you will be audited, and how you handle that audit is a commercial event, not a formality.

Regulatory inspections are conducted by government agencies with statutory powers. They cannot be refused without serious consequence, and refusing to permit an inspection is itself grounds for treating products as adulterated in the United States.

The kinds of regulatory inspection you will hear named

Pre-approval inspection. Before a product is approved, the agency inspects the site that will make it, to confirm it can actually produce what the application describes and that the data in the application matches what exists on site. A finding here delays an approval, which is why these are treated as company-wide events.

Routine surveillance inspection. Periodic, risk-based checks of a registered site's compliance.

For-cause inspection. Triggered by something specific: a complaint pattern, a recall, a whistleblower, a suspicious data set, or a previous poor inspection. These are narrower, deeper and less friendly, and the inspectors usually arrive knowing what they are looking for.

Bioresearch monitoring inspections. These target clinical trials rather than factories — trial sites, sponsors, contract research organisations and ethics committees — to verify that the data supporting an application was genuinely collected as described (Chapter 25.9).

Pharmacovigilance inspections. These examine the safety system: whether cases were captured, assessed and reported on time, whether the safety database is validated, and whether signals were detected and acted on (Chapter 25.22).

What an inspection week actually looks like

Understanding the mechanics helps because a services engineer is quite often in the building, and occasionally in the room.

Arrival and opening meeting. Credentials and a written notice are presented. The inspectors state the scope and what they want to start with. The company presents a short site overview.

The tour. Inspectors walk the areas in scope, watching work as it happens. This is not ceremonial: an inspector who sees a logbook filled in at the end of a shift, an unlabelled container, or an operator working from an uncontrolled printed copy has found something more telling than any document could show.

Document review, which is the bulk of the time. Batch records, deviations, CAPAs, change controls, training records, calibration records, validation packages, audit trails. Requests are made continuously and the company is expected to produce documents quickly — a delay of hours to find a record is itself read as a control weakness.

Interviews. Inspectors ask the person who did the work, not the manager. The correct answer is the true answer, stated plainly, within your own area of knowledge, and nothing more. Speculation about areas you do not own is the most common way a small issue becomes a large one.

Daily wrap-ups, where inspectors indicate concerns and the company has a chance to provide evidence that resolves them before they become written observations. A great deal of the outcome is decided here.

And behind all of it, the room the visitors do not see. Most companies run a front room where the inspection happens and a back room that finds requested documents, checks them for completeness, tracks every request and answer, prepares subject matter experts before they go in, and drafts responses. The back room is a genuine information-retrieval operation, and it is one of the clearest places where good systems show their value: the difference between retrieving a five-year-old audit trail in four minutes and four hours is visible to the inspector.

Close-out meeting. The inspectors present their observations, discuss them, and — where the American agency finds significant issues — issue them in writing.

What comes out, and the exact ladder that follows

This is the part worth memorising, because the terms carry very different weights and people use them interchangeably when they should not.

Form 483. At the end of an American inspection, significant objectionable conditions are listed on a Form FDA 483, issued to management. It is a list of the investigator's observations, not a final agency determination, and it is a normal part of many inspections. The company should respond in writing, and responding within 15 business days is what ensures the response is considered before the agency decides whether further action is needed. A good response addresses each observation with the correction made, the corrective action, the timeline, and evidence — and, critically, addresses the systemic question behind the observation rather than only the example the inspector happened to find.

Establishment Inspection Report and classification. After the inspection the agency writes its own report and classifies the outcome: no action indicated, voluntary action indicated, or official action indicated. That last classification is the one that leads to enforcement, and it also blocks approvals of pending applications made at that site.

Warning Letter. Issued when violations are significant and the agency judges the response inadequate. It states that the products are considered adulterated or misbranded, demands specific corrections, and is published on the agency's website — which means competitors, customers, investors and journalists all read it. A warning letter also freezes new approvals from the affected site and often triggers customer audits from every client the company supplies.

Import Alert. For foreign sites, the agency can detain products at the border without physical examination — in practice a trade block on that site's products until it proves compliance. This is one of the most commercially damaging actions available and it is used regularly on overseas manufacturing sites.

Seizure and injunction. Court actions to take possession of product or to stop a company operating.

Consent decree. A court-approved agreement in which a company operates under supervision: independent experts verify remediation, production may be restricted or suspended, and substantial payments may be required. These run for years and have ended businesses.

And two specific tools aimed at people rather than companies. Debarment bars an individual from working in the drug industry. The Application Integrity Policy allows the agency to halt review of all of a company's applications when it believes data submitted was unreliable or fraudulent. These exist because the failure being addressed is dishonesty rather than incompetence, and the industry treats data integrity as an existential matter for exactly this reason (Chapter 25.20).

Europe's ladder is shaped differently but functionally similar. Findings are graded critical, major or minor; a site with critical findings can receive a statement of non-compliance published in the European GMP database, which effectively removes its ability to supply the Union; and inspection outcomes are shared among the mutual-recognition partners described in Chapter 25.14.

What inspectors actually find, year after year

The published record is remarkably consistent, and this list is essentially the syllabus for anyone building systems for a regulated client.

Investigations that are not thorough. The cause was not established, the scope was not extended to other batches, or the conclusion is not supported by the evidence gathered.

Procedures not followed, or procedures that do not exist for an activity that is being performed.

Laboratory controls — invalidated results without justification, unqualified methods, ignored trends.

Data integrity failures — records completed after the fact, shared logins, audit trails disabled or never reviewed, original data deleted (Chapter 25.20).

Equipment and facility issues — inadequate cleaning validation, poor maintenance, environmental monitoring excursions without proper follow-up.

Complaint handling and CAPA — complaints not investigated, CAPAs closed without effectiveness verification, repeat problems never escalated.

Training — people performing tasks without documented training, or training records that do not match the work performed.

Notice that almost none of these are about the science being wrong. They are about the process not being followed and the evidence not existing. Which is the same conclusion as Chapter 25.9 reached for clinical trials, and it is the central fact about this industry for a software engineer: your systems are not judged on features, they are judged on the evidence they can produce under questioning.

Preparing, and what your systems have to do

**Companies prepare with mock inspections — an internal or external team runs a realistic inspection, including the interviews, and the findings are treated as real. Sites due a pre-approval inspection do this routinely, and it works.

From a systems perspective, inspection readiness comes down to five capabilities, and it is worth designing for them deliberately.

Retrieval speed. Any record, any audit trail, any version of a document, produced in minutes with the retrieval itself controlled.

Completeness. Nothing important lives outside a controlled system in a spreadsheet on somebody's drive, which is where a great many findings originate.

Traceability. From a batch to its materials, equipment, people, deviations and release decision, and back again in both directions.

Reporting. The metrics from Chapter 25.17 available on demand rather than assembled overnight in a panic.

And restricted, logged access, so that showing an inspector one thing does not accidentally expose something else, and so that everything the company retrieved during the inspection is itself recorded.

One cultural note that will make you far more useful than technical skill alone. Never help a client make a record look better than it was. Amending a record to improve an inspection outcome converts a compliance problem into a fraud problem, and the ladder above is deliberately steepest at that end. The correct answer is always to present what happened, together with the honest assessment of it and the plan to fix it.

Next: Chapter 25.19, the discipline underneath every investigation in this Part — how to find a root cause properly, with the tools by name and the ways each one is misused.