Pharmaceutical laboratories operate under some of the most demanding regulatory frameworks in the testing industry. Unlike a general analytical laboratory where the primary compliance reference is ISO/IEC 17025, a pharmaceutical QC laboratory must simultaneously satisfy Good Manufacturing Practice regulations, pharmacopoeial test method requirements, equipment qualification obligations, data integrity principles, and — for any system that creates or manages electronic records — the requirements of FDA 21 CFR Part 11 or its international equivalents. The consequence of getting this wrong is not an assessment finding. It is a product recall, a warning letter, or a batch rejection affecting patient safety.
This article covers what pharmaceutical testing laboratories actually need to manage — from raw material testing through stability studies — and how purpose-built pharmaceutical lab management software supports the record-keeping and process control that GMP compliance requires.
The Pharmaceutical Testing Laboratory
Pharmaceutical laboratories exist across several contexts, each with a distinct testing scope.
What pharmaceutical laboratories test
The testing scope of a pharmaceutical QC laboratory typically spans the entire product lifecycle:
- Raw materials and starting materials — identity, purity, potency, and microbiological testing of active pharmaceutical ingredients (APIs) and excipients against pharmacopoeial monographs or internal specifications before release for manufacturing use
- In-process testing — blend uniformity, tablet hardness, dissolution sampling, and microbiological environmental monitoring conducted during manufacturing operations
- Finished product release testing — full specification testing against registration dossier-approved specifications, including assay, content uniformity, dissolution, related substances, microbial limits, and physical parameters
- Stability testing — accelerated and long-term stability studies conducted at ICH-specified conditions (25°C/60% RH, 40°C/75% RH for Zone IVb markets) to support shelf-life claims, with intervals defined in ICH Q1A(R2)
- Environmental monitoring — cleanroom air sampling, surface monitoring, and personnel monitoring for microbial contamination, with action and alert limits defined per ISO 14644 and GMP Annex 1
- Water testing — purified water and water for injection (WFI) testing for conductivity, total organic carbon, and microbial quality against Ph.Eur. 0169, USP <1231>, and BP monographs
Types of pharmaceutical testing laboratories
The regulatory obligations apply across three main laboratory types. In-house QC laboratories sit within a licensed pharmaceutical manufacturer — their records form part of the batch manufacturing record and are subject to direct GMP inspection. R&D and method development laboratories support formulation development and clinical batch manufacturing, and while they may operate under less stringent release-testing GMP during early development, they become increasingly subject to full GMP as products advance toward registration. Contract testing organisations (CTOs) provide testing services to pharmaceutical manufacturers under quality agreements that transfer defined GMP obligations to the contractor — including record retention, CAPA management, and audit access rights.
Regulatory Framework
Pharmaceutical laboratories in Australia and those serving global markets must navigate a layered regulatory framework. Understanding which regulations apply — and how they interact — is the first step in building a compliant management system.
TGA — Therapeutic Goods Administration (Australia)
The TGA regulates pharmaceutical manufacturing and testing in Australia under the Therapeutic Goods Act 1989 and the Therapeutic Goods (Manufacturing Principles) Determination. Australian GMP is aligned with the PIC/S Guide to GMP (PE 009), which is substantially harmonised with EU GMP. The TGA conducts GMP inspections of both domestic manufacturers and overseas manufacturers supplying the Australian market, and holds mutual recognition arrangements (MRAs) with the European Medicines Agency (EMA), UK MHRA, and several other regulatory authorities — meaning a TGA GMP clearance based on an overseas inspection is accepted for market access without a separate TGA inspection of the same facility.
FDA — 21 CFR Parts 210 and 211 (USA)
The US FDA's Current Good Manufacturing Practice regulations for pharmaceuticals are codified in 21 CFR Part 210 (general definitions) and 21 CFR Part 211 (CGMP for finished pharmaceuticals). Part 211 establishes requirements for laboratory controls (Subpart I, §211.160–§211.194), including specifications, sampling plans, test procedures, instrument calibration (§211.68), analyst qualification, record retention (§211.180), and the handling of OOS results (§211.192). For API manufacturers, ICH Q7 (Good Manufacturing Practice Guide for Active Pharmaceutical Ingredients) provides the corresponding GMP framework, which is adopted by FDA, EMA, and TGA.
EU GMP Annex 11 — Computerised Systems
EU GMP Annex 11 (Computerised Systems) addresses the specific requirements for computer systems used in GMP-regulated environments. It covers risk management, validation, data integrity, audit trails, electronic signatures, business continuity, and archiving for any system that creates, processes, or stores GMP-relevant records. Annex 11 is the EU/PIC/S equivalent of FDA 21 CFR Part 11, and both must be considered by laboratories supplying both markets. Key obligations include: validation of the computerised system prior to use (Annex 11, clause 4), a complete and computer-generated audit trail (clause 9), controls over access levels and user authentication (clause 12), and change control for any modifications to validated systems (clause 10).
Pharmacopoeias
Test methods used in pharmaceutical laboratories are predominantly drawn from pharmacopoeial monographs. The primary references are:
- USP (United States Pharmacopeia) — referenced in 21 CFR Part 211 and widely used globally for US-registered products; general chapters include <1> Injections and Implanted Drug Products, <61> Microbial Examination of Nonsterile Products, <621> Chromatography, <711> Dissolution, <905> Uniformity of Dosage Units
- BP (British Pharmacopoeia) — the reference pharmacopoeia for Australian registered products under TGA, with monographs updated annually
- Ph.Eur. (European Pharmacopoeia) — the reference for EU GMP; BP is aligned with Ph.Eur. for most monographs
- IP (Indian Pharmacopoeia) — relevant for manufacturers supplying the Indian market or where Indian-source APIs are tested against IP specifications
When a test method is drawn from a pharmacopoeia, the specific edition and monograph reference must be recorded in the test record alongside the result. Use of a superseded edition without documented justification is a finding.
WHO GMP guidelines
The World Health Organization's GMP guidelines (WHO Technical Report Series, Annex 2) are the reference standard for manufacturers supplying products through the UNICEF procurement system, to low- and middle-income country markets, and for WHO prequalification programmes. WHO GMP aligns broadly with PIC/S GMP and is increasingly required for pharmaceutical manufacturers in India, Southeast Asia, and Africa serving global health markets — including Australian-based companies with emerging market supply ambitions.
GMP Record Requirements
The pharmaceutical laboratory record burden is substantially greater than that of a general analytical or calibration laboratory. The records must not only capture the test result and support traceability — they must demonstrate that the entire testing process was conducted in accordance with approved, validated methods by qualified analysts using qualified equipment.
Batch and test records
Every test conducted in support of a batch release decision must be captured in a record that links the result unambiguously to the product batch, the sample, the method (including pharmacopoeial edition and section), the instrument, the analyst, the reagents and reference standards used, and the date and time of testing. Under 21 CFR §211.194, laboratory records must include the complete data derived from all tests — not just passing results. Incomplete records, or records where failing results were not included before a passing result was obtained, constitute data integrity violations.
Method validation records
Non-pharmacopoeial test methods and pharmacopoeial methods used outside their intended scope must be validated before use. ICH Q2(R2) defines validation parameters: specificity, linearity, range, accuracy, precision (repeatability and intermediate precision), detection limit, quantitation limit, and robustness. Validation records must be retained for the life of the method and referenced in the test procedure. For compendial methods, verification (rather than full validation) may be required to confirm the method performs adequately in the laboratory's hands and with the specific matrix — this is increasingly required by both FDA and TGA.
Analyst qualification records
Only analysts who have been formally qualified to perform a specific test method may generate results used for batch release decisions. Qualification records must document the training received, the qualification testing performed, and the authorisation sign-off by a competent supervisor. Under 21 CFR §211.68 and PIC/S GMP Chapter 2, responsibilities must be assigned to named, qualified individuals. Qualification authorisations must be current — expired authorisations create the same problem as overdue instrument calibrations.
Reference standard and reagent records
Primary reference standards (certified reference materials traceable to national or pharmacopoeial sources) must have records of receipt, certification data, certificate of analysis, storage conditions, expiry dates, and usage logs. Secondary (working) reference standards must have records of their assignment, standardisation against the primary, assigned potency, and re-standardisation intervals. Reagent and solution records must document preparation, standardisation (where applicable), expiry, and the analyst who prepared them. A commonly cited GMP finding is the use of a working standard beyond its re-standardisation date, or use of a reagent solution after its assigned expiry.
HPLC column qualification records
HPLC columns used in pharmaceutical testing must have qualification records that confirm the column is fit for use with the specific method. Column qualification typically includes system suitability testing (theoretical plates, tailing factor, resolution) against the method's acceptance criteria, using the validated stationary phase type. Column usage logs — recording every analytical run, the sample matrix, and the mobile phase — support assessment of column lifetime and replacement decisions. Unrecorded column use, or use of an unqualified column as a substitute for the qualified specification, is a GMP finding.
Equipment Qualification and Calibration in Pharma Labs
Equipment used in pharmaceutical laboratories must be qualified before use and maintained in a qualified state throughout its operational life. The qualification framework — IQ, OQ, PQ — applies to all equipment whose performance directly affects the validity of test results used in batch release or regulatory submission decisions.
IQ/OQ/PQ — the qualification lifecycle
Installation Qualification (IQ) documents that the equipment has been installed in the intended environment in accordance with the manufacturer's specifications: utilities connected, environmental conditions within range, and a complete inventory of components and documentation established. Operational Qualification (OQ) demonstrates that the equipment operates within defined limits across its specified operating range — for an HPLC system, this includes flow rate accuracy, gradient accuracy, detector linearity, wavelength accuracy, and injector precision. Performance Qualification (PQ) demonstrates that the equipment consistently delivers acceptable performance under representative conditions — using the actual test methods and sample types for which the equipment will be used. All three stages require documented protocols approved before execution, and documented reports with conclusion and approval sign-off after execution. Changes to the equipment configuration or software version require a change control assessment and may trigger re-qualification.
Analytical balance calibration
Balances used in pharmaceutical weighing operations must be calibrated at defined intervals using certified weights traceable to national measurement standards (NATA-accredited calibration in Australia), with records of the calibration result, the tolerance applied, and the outcome (pass or fail). Most pharmaceutical facilities perform daily balance checks in addition to periodic external calibration — records of these checks must be retained. Under 21 CFR §211.68, automatic, mechanical, or electronic equipment (including balances) must be calibrated, inspected, and checked according to a written program designed to ensure performance accuracy and precision.
Dissolution apparatus qualification
Dissolution testing is one of the most GMP-scrutinised areas in pharmaceutical QC. USP <711> specifies apparatus dimensions and tolerances; the Pharmacopoeial Forum has issued guidance on mechanical calibration versus chemical calibration. FDA guidance recommends that all dissolution apparatus used for regulatory testing undergo mechanical qualification covering basket or paddle dimensions, rotation speed accuracy, vessel dimensions, temperature control, and vibration assessment. Records of each qualification run, calibration results, and the acceptance criteria applied must be maintained and linked to the instrument identifier used in each batch test record.
Temperature monitoring and calibration traceability
Stability chambers, refrigerators, incubators, and water baths used in pharmaceutical testing must have temperature monitoring records that demonstrate the required conditions were maintained throughout the period the samples were stored or the test was conducted. Continuous monitoring with calibrated temperature loggers — calibrated traceable to national standards — is standard practice. Excursion records (temperature deviations outside the specified range) must be documented and risk-assessed for impact on the samples affected. This is a commonly inspected area during TGA and FDA inspections of stability and microbiological testing areas.
FDA 21 CFR Part 11 — Electronic Records and Signatures
For pharmaceutical laboratories that have replaced paper records with electronic systems — which is now the large majority — FDA 21 CFR Part 11 compliance is not optional. It applies to any electronic record used in place of, or in addition to, paper records required under FDA regulations, and to any electronic signature used in place of a handwritten signature on such records.
What Part 11 requires
21 CFR Part 11 Subpart B (Electronic Records) requires that electronic records systems include:
- Validation — the system must be validated to ensure accuracy, reliability, consistent intended performance, and the ability to discern invalid or altered records (§11.10(a))
- Audit trail — a computer-generated, time-stamped audit trail that independently records the date and time of operator entries and actions that create, modify, or delete electronic records; changes to records should not obscure previously recorded information (§11.10(e))
- Access controls — system access limited to authorised individuals, with unique user identities and controls to prevent unauthorised access (§11.10(d))
- Operational system checks — controls to enforce permitted sequencing of steps and events (§11.10(f))
- Authority checks — controls to ensure only authorised individuals can use the system and access specific record types (§11.10(g))
- Record retention — the ability to generate accurate and complete copies of records in both human-readable and electronic form suitable for inspection, review, and copying by the FDA (§11.10(b))
Electronic signatures under Part 11 Subpart C must be unique to each individual, applied only by their genuine owner, and linked to the specific electronic record being signed in a manner that renders the signature invalid if the record is subsequently altered.
Data integrity and ALCOA+
Data integrity has become the dominant inspection focus for both FDA and TGA in pharmaceutical laboratory audits over the past decade. The ALCOA+ principles — Attributable, Legible, Contemporaneous, Original, Accurate, plus Complete, Consistent, Enduring, and Available — define what constitutes a trustworthy record. Specific data integrity violations found in pharmaceutical laboratory inspections include: test results entered in scratch notebooks and only transcribed to official records selectively; instrument clocks set incorrectly or reset to obscure the timing of testing; shared login credentials that make it impossible to attribute records to specific analysts; and the use of system administrator accounts to delete or overwrite audit trail entries. EU GMP Annex 11 clause 9 requires that audit trails be reviewed as part of the batch release process — a requirement that is difficult to fulfil without purpose-built software that makes audit trail review a structured, searchable activity rather than a manual examination of raw system logs.
Computer system validation (CSV)
For a LIMS or laboratory QMS platform to be used in a GMP pharmaceutical environment, it must be validated. Computer system validation (CSV) — governed by EU GMP Annex 11, GAMP 5 guidance, and FDA's guidance on computerised systems in clinical investigations — requires that the system's intended use, user requirements, functional requirements, and design are documented; that installation, operational, and performance testing is conducted and documented; and that ongoing change control ensures re-validation when the system changes. In practice, this means the software vendor must provide a documented validation support package and the laboratory must execute laboratory-specific validation testing against defined acceptance criteria before the system is used for GMP-regulated activities.
Non-Conformance, OOS and CAPA in Pharma QMS
Out-of-specification results are one of the most consequential events in a pharmaceutical testing laboratory. The regulatory framework for handling them is well-established and heavily inspected.
What constitutes an OOS result
An out-of-specification (OOS) result is any analytical result that falls outside the acceptance criteria specified in the approved product specification, pharmacopoeial monograph, or in-process limit. This is distinct from an out-of-trend (OOT) result, which falls within specification but shows a trend that, if continued, would lead to an OOS result — OOT results trigger investigation under ICH Q10 and WHO stability guidelines even if they do not require the same immediate escalation path as a formal OOS.
Phase I and Phase II investigations
FDA's 2006 guidance on investigating OOS test results (updated 2022) defines a two-phase investigation process. Phase I is a laboratory investigation conducted by the analyst and supervisor, focused solely on determining whether an assignable laboratory error occurred — incorrect sample preparation, instrument malfunction, analyst error, or a transcription mistake. Phase I does not involve retesting and must be completed promptly, without extending the investigation beyond what is needed to identify a clear root cause. If a laboratory error is identified and confirmed, the result may be invalidated and a new sample may be prepared and retested. If no assignable cause is identified in Phase I, the investigation advances to Phase II — a full-scale investigation that may include review of the batch manufacturing record, additional testing under a statistically justified protocol, and involvement of the quality unit and manufacturing team. The entire investigation, including all decisions and the basis for any invalidation of results, must be documented contemporaneously.
CAPA — Corrective and Preventive Action
When an OOS investigation identifies an assignable cause — whether a laboratory error or a genuine product quality failure — a CAPA record must be raised. Under 21 CFR §211.192 and ICH Q10, the CAPA system must capture the root cause, the corrective actions taken to address the specific failure, preventive actions taken to prevent recurrence, the person responsible for each action, a target completion date, and a verification step that confirms the actions were effective. CAPA effectiveness reviews are a specific area of FDA and TGA inspection focus — it is not sufficient to close a CAPA on the basis that the corrective action was implemented; there must be evidence that it worked.
Change control and deviation management
Changes to validated systems, approved test methods, specifications, or qualified equipment configurations must pass through a documented change control process before implementation. Change control records must identify the proposed change, the technical and regulatory impact assessment, the validation or re-qualification activities required, approvals, and the effective date. Deviations — unplanned departures from an approved procedure that occur during a manufacturing or testing operation — must be documented at the time of occurrence, investigated, and closed with appropriate corrective action before the affected batch is released. A change made without passing through change control — even a minor one — is a significant GMP finding because it undermines the assurance that the validated or approved process is the one actually operating.
Managing Pharmaceutical Lab Records with Software
The record volume, the interconnection between records, and the data integrity requirements of a GMP pharmaceutical laboratory make paper-based and spreadsheet-based management systems inadequate — not in theory, but in practice and in the findings of pharmaceutical regulatory inspections worldwide. Purpose-built pharmaceutical laboratory software addresses each of these areas systematically.
Test records and result capture
OMS captures test results in structured electronic records that link each result to the sample, the batch, the test method (including document version and pharmacopoeial reference), the instrument identifier, the analyst, and the timestamp. Fields required for GMP compliance are enforced — records cannot be submitted without the required attributes. Result entries are time-stamped and attributed to the logged-in user, with the audit trail created automatically at point of entry. Previous values and amendment reasons are retained in full, satisfying the ALCOA+ principle of original and attributable data.
Equipment calibration and qualification tracking
Every instrument in OMS carries a qualification status — IQ/OQ/PQ completion records, calibration due dates, and calibration history. The platform sends automated alerts before calibration due dates, and can be configured to prevent assignment of jobs to instruments whose qualification or calibration status is not current. Calibration records include the calibration result, the tolerance applied, the external calibration provider, and the calibration certificate reference — supporting the traceability chain required under 21 CFR §211.68 and PIC/S GMP Chapter 3.
OOS investigation and CAPA workflow
When a test result falls outside specification, OMS automatically flags the result as OOS and initiates the investigation workflow. Phase I fields capture the analyst review, instrument check, and standard/reagent verification. If Phase I is inconclusive, the record escalates to Phase II with additional fields for extended investigation, retesting authorisation, and quality unit involvement. CAPA records are linked directly to the OOS investigation — root cause, corrective actions, responsible persons, due dates, and effectiveness review are all captured in connected records. The complete OOS-to-CAPA chain is available as a searchable, linked audit trail — the kind of documentary completeness that FDA and TGA investigators look for as evidence of a functioning quality system.
Document control for GMP procedures
Test methods, SOPs, qualification protocols, and validation reports in OMS are version-controlled through a formal approval workflow. A new version of a test procedure cannot be used until it has been reviewed, approved, and released in the system. Previous versions are automatically archived — removed from active use — and the complete version history with approval records is retained for the life of the document. Analysts receive notification when a document they are authorised to use is updated, and their acknowledgement is recorded before they can proceed with testing under the new version. This directly satisfies EU GMP Annex 11 clause 8 (data storage) and 21 CFR §211.68 requirements for written programs governing laboratory operations.
Personnel qualification records
OMS maintains a qualification matrix for each analyst: the test methods they are authorised to perform, the instruments they are qualified to operate, the date of qualification, and the expiry of any time-limited authorisation. When a qualification approaches expiry, the platform sends an alert. When an analyst's qualification lapses, the system prevents them from being assigned to tests within that scope. This addresses one of the most frequently recurring GMP findings — work performed by an analyst who was not demonstrably qualified for the specific method at the time of testing.
Stability testing records
Stability studies in OMS are managed against a defined study plan — time points, storage conditions, test parameters, and acceptance criteria established at study initiation. The system generates pull notifications for each scheduled test point as it falls due, ensuring stability intervals are not missed. Results are captured against the study plan with automatic comparison to acceptance criteria, and OOT trending is visible across the study timeline. Stability chamber temperature records — either entered manually or linked from monitoring systems — are stored against the study period, supporting the temperature excursion documentation requirements under ICH Q1A(R2).
Audit readiness
When a TGA inspector or FDA investigator arrives, the most time-consuming part of any laboratory inspection is record retrieval — locating the records the investigator requests, in full, in a form that demonstrates completeness and control. In OMS, any test record, equipment calibration history, OOS investigation, CAPA record, analyst qualification, or document version can be retrieved in seconds by batch number, sample ID, instrument identifier, analyst name, date range, or method reference. The audit trail for any record is immediately visible — every entry, every modification, every approval, with timestamps and user attribution. This is not just about passing the inspection. It is about demonstrating the kind of systematic control that GMP regulations are designed to ensure is genuinely operating — not constructed for the purpose of an inspection visit.
Frequently Asked Questions
- What GMP regulations apply to pharmaceutical laboratories in Australia?
- Australian pharmaceutical laboratories are primarily governed by the Therapeutic Goods Administration (TGA), which enforces Good Manufacturing Practice under the Therapeutic Goods (Manufacturing Principles) Determination. This aligns closely with the Pharmaceutical Inspection Co-operation Scheme (PIC/S) PE 009 GMP guide and, for manufacturers supplying the US market, FDA 21 CFR Parts 210 and 211. Contract testing laboratories that support TGA-licensed manufacturers are subject to the same GMP obligations as the manufacturer's own QC laboratory. Where laboratories hold ISO/IEC 17025 accreditation through NATA, both frameworks apply simultaneously, and the more stringent requirement governs in any area of overlap.
- What is FDA 21 CFR Part 11 and does it apply to laboratory software?
- FDA 21 CFR Part 11, issued by the US Food and Drug Administration, establishes requirements for electronic records and electronic signatures used in pharmaceutical manufacturing and testing environments where paper records are replaced or supplemented by electronic systems. It applies to any computer system used to create, modify, maintain, archive, retrieve, or transmit records required by FDA regulations — including LIMS, laboratory data acquisition systems, chromatography data systems, and QMS platforms. Key requirements include a complete and computer-generated audit trail, unique user identification with role-based access controls, time-stamped entries that cannot be deleted or overwritten without a traceable record, and electronic signature controls that link the signature unambiguously to the signer and the record being signed. For laboratories operating outside the US but supplying data to US-registered products, Part 11 compliance is commonly required by customers or included in contractual quality agreements.
- What is an out-of-specification (OOS) result and how must it be handled?
- An out-of-specification (OOS) result is any test result that falls outside the established acceptance criteria for a pharmaceutical product — whether a raw material specification, in-process limit, or finished product release specification. FDA guidance (2006, revised 2022) and ICH Q6A require a documented Phase I laboratory investigation to rule out assignable laboratory error before any product decision is made. Phase I covers analyst error, instrument malfunction, and sample preparation issues. If no assignable cause is found in Phase I, a Phase II full-scale investigation is required, which may include retesting additional samples under a statistically justified protocol. All steps — the original result, Phase I findings, any retesting, the root cause conclusion, and the final product disposition decision — must be documented and retained. Invalidating an OOS result without documented assignable cause is a significant regulatory violation.
- What equipment qualifications are required in a GMP pharmaceutical laboratory?
- GMP regulations (21 CFR Part 211.68, EU GMP Annex 15, and PIC/S equivalent) require that laboratory instruments and equipment are qualified before use in testing activities that support product release decisions. Qualification follows a four-phase model: Design Qualification (DQ) — confirmation that the proposed design is fit for purpose; Installation Qualification (IQ) — confirmation that the equipment is installed correctly according to specifications; Operational Qualification (OQ) — confirmation that the equipment operates within defined parameters across its expected operating range; and Performance Qualification (PQ) — confirmation that the equipment consistently performs within acceptance criteria under representative conditions. Common equipment requiring full IQ/OQ/PQ documentation in pharmaceutical labs includes analytical balances, HPLC systems, dissolution apparatus (USP Apparatus 1 and 2), Karl Fischer titrators, UV-Vis spectrophotometers, and stability chambers. Calibration records must be traceable to national measurement standards and retained for the full lifetime of the equipment plus any required post-use retention period.
- How can laboratory software help with TGA or FDA audit preparation?
- During TGA or FDA laboratory inspections, investigators request records that demonstrate the laboratory operates under documented, controlled, and data-integrity-assured conditions. Purpose-built pharmaceutical laboratory software accelerates audit preparation by maintaining a complete, searchable electronic record of all test results with their associated instrument, analyst, method, and approval records; by providing a complete audit trail for every record (who created it, who modified it, what was changed, and when); by maintaining calibration and qualification status for all instruments with due-date visibility; by tracking OOS investigations and CAPA actions through to verified closure; and by holding current controlled copies of all SOPs and method documents. When an investigator asks for a specific batch record, test result, or equipment qualification, the records can be located in seconds rather than hours of manual file searching — which itself demonstrates the kind of controlled, traceable environment that GMP inspections are designed to assess.