FDA Data-Integrity Warning Letter Trends and Spreadsheet Shortfalls Under 21 CFR Part 11

Data integrity has become the leading cause of FDA drug cGMP warning letters, creating direct compliance risk for quality and regulatory teams responsible for laboratory oversight, batch release, and inspection readiness. Understanding which failures FDA cites most frequently allows organizations to prioritize remediation efforts and avoid the enforcement actions that have resulted in import alerts and consent decrees.

The analysis below identifies the most commonly cited data-integrity failure patterns drawn from FDA warning letters, then examines the specific technical and procedural ways spreadsheet-based record systems fail to satisfy the requirements of 21 CFR Part 11 for electronic records and electronic signatures.

Want to ask Rhizome your own regulatory questions? Try it for free.

The data-integrity failures FDA cites most, and why spreadsheets keep failing Part 11

Data integrity is the dominant theme in FDA drug cGMP warning letters, and the same handful of failures recur across sites and years. Most citations cluster in the quality-control laboratory, especially around chromatography data systems (HPLC and GC), where firms cannot reconstruct what happened to raw data. FDA's recurring message is consistent: if the electronic record is not secure, attributable, complete, and protected from deletion or alteration, the reported result cannot be trusted, and neither can the batch disposition decision built on it 61467.

Below are the failure patterns FDA names most often, followed by the specific reasons spreadsheet-based records fall short of 21 CFR Part 11.

1. Disabled, missing, or unreviewed audit trails

The single most common finding is that the audit trail was off, absent, or never reviewed, so there is no independent record of who created, changed, or deleted data.

  • At Zhejiang Hisun Pharmaceutical, FDA found the audit trail on HPLC system #36 was disabled, supporting raw data had been discarded, and results were deleted from the hard drive before analyses were repeated and the repeat results submitted to FDA 61.
  • At Aarti Drugs, the audit-trail function for the chromatographic systems was disabled at inspection, so there was no record of data acquisition or modification, and analysts could delete data with no trace in the operating system 66.
  • At International Trading Pharm Lab, analysts could delete raw data files and alter timestamps on stand-alone HPLC/GC computers, and audit trails were not enabled, so manipulation could not be detected 4.
  • At Sri Krishna Pharmaceuticals (Unit II), analysts routinely turned HPLC audit trails on and off, and prior to October 2014 the GC instrument sent injection data to PCs without any audit trail at all 67.
  • At Intas Pharmaceuticals, the quality unit did not review audit trails as part of batch-record review, so discrepancies went undetected 72.

FDA treats an enabled, secure, contemporaneous audit trail, plus documented review of it, as the baseline. A printout is not a substitute, because it does not preserve the full dynamic electronic record 41315.

2. Shared logins, generic accounts, and uncontrolled access

The second recurring cluster is access control. Firms repeatedly allowed shared or generic credentials and gave analysts administrator rights, which breaks attributability and lets users delete or overwrite data.

  • Shared credentials: laboratory staff at Glint Cosmetics shared the QC Manager's login and password for the HPLC 46; at BBC Group, all GC users logged in as "System Administrator," which required no password 15.
  • No unique, attributable accounts: Nortec Quimica used a common username on stand-alone UV-Vis and IR computers with no Windows password and no software login 7; Laboratorio Magnachem and NWL Netherlands Services never established unique usernames and passwords, and staff held administrator rights allowing uncontrolled deletion or modification of instrument files 105054.
  • Inappropriate administrator privileges: FDA repeatedly cited firms where the people who reviewed or approved cGMP data also held full administrator access to edit, delete, or modify data and audit trails, including QC team leaders and, in one case, a Senior General Manager of Quality 21228.
  • Consequences of open access: at Nortec, investigators recovered more than 100 deleted files from recycle bins 7; at USV Limited, operators could delete files from instrument audit trails and all users could modify files on a microbial identification instrument and its backup drive 49.

FDA's expectation is unique, individually attributable accounts, access restricted to authorized personnel, and separation of administrator privileges from routine testing roles 571050.

3. Deletion, overwriting, and manipulation of raw data

Where access is uncontrolled, FDA typically finds the predictable result: original electronic data deleted or overwritten.

  • At Sun Pharmaceutical, investigators recovered 5,301 deleted chromatograms on one QC computer, many of them "trial" injections, and found deleted GC files replaced with identically named "official" chromatograms 59.
  • At Ipca Laboratories, an original GC injection was aborted without justification, the original result was automatically deleted on re-injection, and only the passing result was reported 60; at the Pithampur facility, the first several GC injections in multiple sequences were overwritten and deleted without justification 62.
  • At Zhejiang Hisun, an audit trail showed 61 injections while the release package reported only 44, with raw data for 17 injections deleted from the reported sequence and later recovered from a backup folder 61.
  • At Sharp Global, the lab's practice was to delete raw data files once chromatograms were printed, so complete electronic raw data was never retained 13.
  • These findings persist into recent letters: a 2026 letter to Ava cited a common username/password, analyst administrator rights to modify and delete data, and multiple deleted GC sequences recovered from the recycle bin, including system-suitability and stability analyses 51.

4. "Trial" injections and testing into compliance

A closely related and frequently cited practice is unofficial "trial," "test," or "demo" runs before the official test, with the initial data discarded and the sample retested until it passes.

  • FDA calls using an actual sample in trial, preparation, or equilibration runs a violative practice because it can disguise testing into compliance, and it has cited this at Aspire Pharmaceuticals, Fresenius Kabi Oncology (chromatograms labeled "test," "demo," and "trial" before official injections), and Hospira Spa (trial injections in a "Test" folder, later deleted) 737576.
  • At Sun Pharmaceutical, the firm frequently performed "unofficial testing," ignored the results, and reported results from additional tests; in one stability example a sample was tested six times and the data deleted 59.
  • FDA's governing principle is that all data, including failing, passing, and suspect results, must be retained in the cGMP records and evaluated in an out-of-specification investigation before any result is invalidated 74.

5. Backdating, non-contemporaneous entry, and fabrication

FDA also cites outright falsification: records completed after the fact, signatures backdated, and results fabricated.

  • Backdating clocks and records: in one lab an analyst set a GC computer clock back seven months, ran five injections, deleted the first four backdated results, and reported only the fifth as passing 80. In another case a technical director backdated his signature to the date the quality unit released the product even though he was not in the facility on those dates 18.
  • Non-contemporaneous entry: analysts pre-signed blank or partially completed batch records and later filled in data 87; a refrigerator temperature log was completed after an inspector had already reviewed it, at a supervisor's direction 81.
  • Fabrication: firms fabricated environmental-monitoring results for samples never taken and altered results that would otherwise have failed 82; a QC employee fabricated data for untested products by renaming files from previously tested lots 93.

These findings map directly to the ALCOA expectation that records be attributable, legible, contemporaneous, original, and accurate 262745.

Where spreadsheet-based records fall short of Part 11

Spreadsheets (typically Excel) are a specific and recurring target because firms use them for cGMP calculations, including assay results and final batch-release decisions, without the controls Part 11 requires of any electronic record. The failures fall into four categories that line up cleanly against the regulation.

Part 11 / cGMP requirementWhat the rule requiresHow spreadsheets typically failWarning-letter example
Validation (21 CFR 11.10(a))System validated for accuracy, reliability, and consistent intended performance; ability to discern altered records 117Calculation workbooks used in production but never validated; formula errors go undetectedTismor Health failed to validate the Excel spreadsheet used for the assay calculation, and an investigator found an incorrect averaging formula for the internal-standard peak area 55; Specialty Process Labs used a non-validated Excel spreadsheet for API assay calculations across all validation lots 5657
Audit trail (21 CFR 11.10(e))Secure, computer-generated, time-stamped audit trail of creation, modification, and deletion, not obscuring prior entries 117Standard spreadsheets have no audit trail; edits leave no independent, time-stamped recordBBC Group's electronic spreadsheets were uncontrolled and vulnerable to manipulation, overwriting, or erasure, with no protection 15
Access and authority controls (21 CFR 11.10(d), (g))Access limited to authorized individuals; authority checks on who can alter a record 117Files openly editable; users hold administrator rights allowing alteration or deletionUnipack analysts had administrator rights that let them alter and delete data, files, and folders, including the spreadsheet used for assay calculations 58
Accurate copies and retention (21 CFR 11.10(b), (c))Generate accurate, complete copies in human-readable and electronic form; protect records for retrieval throughout retention 117Results printed and the working file not saved; no original or master workbook retainedSpecialty Process Labs printed the spreadsheet formulas and outputs at the time of calculation but did not save them and could not produce the original or master spreadsheet at inspection 5657

The common thread is that a spreadsheet used to generate a reportable cGMP result is an electronic record, so it must meet the same expectations as any validated computerized system. When FDA finds unvalidated assay workbooks, it also directs firms to assess all spreadsheets supporting cGMP operations for incorrect formulas and other deficiencies and to prevent recurrence 565755.

What Part 11 and cGMP actually require (the benchmark)

The findings above are measured against explicit requirements. Under 21 CFR Part 11, electronic-record systems must be validated for accuracy and reliability; must use secure, computer-generated, time-stamped audit trails that record and do not obscure changes and are retained at least as long as the underlying records; must limit access to authorized individuals and apply authority checks over who can sign, alter, or operate the system; must be able to generate accurate and complete human-readable and electronic copies for the agency; and must protect records for retrieval throughout the retention period. Signed electronic records must display the signer's printed name, the date and time of signing, and the meaning of the signature 117120.

The cGMP predicate rules reinforce this. 21 CFR 211.194 requires complete laboratory records, including a complete record of all data from each test, all graphs, charts, and spectra, all calculations, and a second-person review of the original records for accuracy and completeness 128. 21 CFR 211.68 permits computers and automated equipment only with controls that ensure changes are made by authorized personnel, that input and output are checked for accuracy, that backups are maintained, and that hard-copy or equivalent secure backups protect data from alteration, erasure, or loss 129.

What FDA expects for remediation

When data-integrity problems are cited, FDA does not accept an isolated fix. The letters consistently ask for three things: a comprehensive, retrospective investigation covering all laboratories, systems, and operations (often by a qualified independent third party with relevant expertise), a risk assessment of the impact on distributed product and patients, and a management-owned CAPA plan that restores quality-unit authority and demonstrates senior-management ownership of ongoing control 2324294244. Firms are frequently asked to remediate documentation so records are attributable, legible, contemporaneous, original, and accurate, to implement audit-trail and access controls, and in the most serious cases to appoint an empowered data-integrity leader and commit to annual independent audits 2325283942.

For a regulatory team, the practical takeaway is narrow and durable: enable and review audit trails, enforce unique attributable accounts with restricted privileges, retain original dynamic data rather than printouts, investigate every result including failures before invalidating any, and treat any spreadsheet that produces a reportable cGMP value as a validated, access-controlled, audit-trailed electronic record, not a convenience tool.