GMP audit checklist: the batch record, the deviation, the change and the four other threads a GMP auditor pulls

A GMP audit is organised around a small number of threads that an auditor pulls, and a checklist that lists requirements without saying which thread each belongs to is why preparation feels endless. The threads are the batch, the deviation, the change, the complaint, the cleaning, the calibration and the person. Each one starts somewhere concrete and ends somewhere the auditor can verify, and each has a characteristic failure. Preparing thread by thread rather than clause by clause is faster, it mirrors what will happen on the day, and it finds the gaps that a clause-by-clause read reliably misses.

The batch thread, which is the whole audit in miniature

Pick a released batch and follow it: the master record it was made against, the materials with their receipt, testing and release, the equipment with its cleaning and calibration status at the time, the people who signed each step and their training on that step, the in-process results, the deviations raised and closed, and the final release decision by the named person. Almost every GMP finding can be reached from this one thread. Do it yourself on two batches before an auditor does it on one.

Deviations, and whether the investigation went anywhere

Deviation records fail in a predictable way: they are raised properly, investigated superficially, and closed with a corrective action that is a retraining event. The audit test is whether the investigation identified a root cause distinguishable from human error, whether the action addressed that cause, and whether effectiveness was checked afterwards. A folder of deviations all closed by retraining the same three people is not a compliant system, and it is visible in ten minutes to anyone who sorts the log by cause.

Change control, calibration and cleaning

Change control is tested by finding a change that happened and looking for its record, rather than by reading the change log and admiring it. Walk the floor, spot something that is not what the drawing or the procedure says, and ask when it changed. Calibration is tested by status labels and the dates behind them, including instruments found out of tolerance and what was done about the results taken since the last good calibration. Cleaning is tested by the validated method, the records, and whether the method covers the worst-case product changeover rather than the easy one.

Documentation practice, which decides the tone of the whole audit

Records that are contemporaneous, attributable, legible and permanent, with corrections struck through and initialled rather than overwritten, tell an auditor that the site takes data seriously. Pre-signed steps, entries in pencil, transcription from scrap paper and identical handwriting across a shift do the opposite, and they turn a routine audit into a deep one. This is the cheapest thing on the checklist to fix and the most expensive to be found failing, because it puts every other record in doubt.

Questions people ask about gmp audit checklist

How many batches should we self-audit before an inspection?

At least two, chosen for difficulty rather than convenience: one with a deviation in it and one made near a changeover. Auditors choose awkward batches, so rehearsing on the clean ones tells you little.

What is the most common GMP finding?

Investigations that do not reach a root cause, and documentation practice failures. Both are systemic rather than technical, which is why they recur across sites and why they attract disproportionate attention.

Does the checklist differ for a customer audit and a regulatory inspection?

The threads are the same. The difference is scope and consequence: a customer is deciding whether to keep buying, and will focus on the products they buy; a regulator is assessing compliance across the licensed operation.

How long should we allow to prepare?

Work it from the number of requirements in scope and the evidence each needs rather than from a rule of thumb. GMP scopes are evidence-dense, so the hours per requirement run higher than for most management system audits.

Sources

Related answers

Start Capanix ProKeep the findings, not the binder