Evidence Collection and Analysis in GMP Investigations

Evidence is the bridge between the event and the investigation conclusion.

A GMP investigation should not rely only on opinion, memory, or assumption. It should show what records, data, observations, interviews, and process information were reviewed, and how those items support the final decision.

This does not mean collecting every possible document. It means identifying the evidence needed to understand the event, evaluate impact, test possible causes, and support the investigation conclusion.

As discussed in GMP Investigation Lifecycle: Step-by-Step, evidence collection begins early and continues as the investigation develops. New evidence may change the scope, refine the root cause, or affect the product impact decision.

 

Start With the Investigation Question

Evidence collection should begin with the investigation question.

Before gathering records, the team should ask what the investigation needs to determine. For example:

  • What happened?

  • When and where did it happen?

  • What product, batch, system, record, equipment, or area may be affected?

  • Was the event isolated or potentially broader?

  • What controls should have prevented or detected it?

  • What possible causes need to be tested?

  • What product, process, or data impact decision needs support?

Evidence collection should follow the event, scope, and risk. A generic checklist may help prompt the team, but it should not replace investigation thinking.

For example, a documentation error may require batch record review, procedure review, workflow review, training record review, and interviews. An equipment alarm may require alarm history, equipment logs, maintenance records, process data, calibration status, and operator response review.

The right evidence depends on the event being investigated.

 

Identify Relevant Evidence Sources

Common evidence sources in GMP investigations include:

  • batch records

  • logbooks

  • equipment records

  • alarm records

  • audit trails

  • test results and raw data

  • chromatograms

  • environmental monitoring data

  • cleaning records

  • maintenance and calibration records

  • training records

  • material movement records

  • labels, components, or samples

  • procedures and specifications

  • process observations

  • SME interviews

  • prior deviations, complaints, OOS/OOT results, CAPAs, and trends

The investigation does not need every source for every event. The evidence should be relevant to the scope and the question being answered.

Evidence Type What It May Help Evaluate
Batch records and logbooks What was documented during execution, review, or control checks
Equipment and alarm records Whether equipment status, alarms, or interventions contributed
Audit trails and system data Timing, entries, changes, approvals, or data integrity concerns
Test results and raw data Whether quality attributes, specifications, or analytical results were affected
Procedures and specifications What was required and whether the requirement was clear
Training records Whether personnel were qualified for the task
Interviews and observations Process reality, sequence of events, handoffs, and task conditions
Prior deviations and trends Whether the event appears isolated, repeated, or part of a pattern

This step should be guided by the defined investigation scope. Defining Investigation Scope in GMP Deviations goes deeper into how scope should be set and justified.

 

Preserve Time-Sensitive Evidence Early

Some evidence can disappear, change, or become less reliable over time.

Examples include:

  • equipment status

  • alarm history

  • audit trail data

  • samples

  • labels, components, or packaging

  • room conditions

  • environmental monitoring context

  • access records

  • in-process observations

  • personnel recollection

If time-sensitive evidence is not preserved early, the investigation may be limited later.

For example, an equipment condition may change after maintenance. A room condition may no longer represent the condition at the time of the event. Personnel may not remember the sequence clearly after several days. Some system data may be overwritten or become harder to retrieve.

When evidence is unavailable, the investigation should document the limitation and assess its impact. The record should not ignore missing evidence if that evidence was important to the investigation question.

 

Connect Evidence to Claims

A strong investigation does not only list evidence reviewed. It explains what the evidence supports.

Weak wording:

Training records were reviewed.

Stronger wording:

Training records confirmed that the operator was qualified on SOP-123 before the batch was executed. However, training status alone did not explain why the reconciliation entry was missed.

Another weak example:

Equipment logbook reviewed; no issues noted.

Stronger wording:

The equipment logbook showed no alarms, interventions, or maintenance activity during the batch window. This supports the conclusion that an equipment interruption was not a likely contributor.

The difference is important. The stronger wording connects the evidence to the investigation claim.

Every major conclusion should be traceable to evidence. If the investigation states that the event was isolated, the record should show what historical review, related batch review, trend review, or similar-event search supports that statement.

If the investigation states that equipment was not a contributor, the record should show what equipment records, alarms, maintenance history, or process data were reviewed.

 

Analyze Evidence, Do Not Only Collect It

Evidence collection and evidence analysis are different activities.

Collecting evidence means gathering records, data, interviews, and observations. Analyzing evidence means determining what those items show.

Evidence analysis may include:

  • comparing records to the event timeline

  • checking consistency between different sources

  • identifying conflicts or missing information

  • determining whether evidence supports or rules out possible causes

  • deciding whether scope needs to expand

  • evaluating whether product or process impact changes

  • documenting uncertainty where it remains

A large evidence package does not make an investigation stronger if the report does not explain what the evidence means.

For example, attaching batch records, training records, and equipment logs may show that documents were collected. But the investigation still needs to explain how those records support the final conclusion.

Writing Defensible Investigation Reports explains this from a reporting perspective. The report should show how the evidence was used, not only that evidence was gathered.

 

Handle Conflicting or Incomplete Evidence

Not every investigation has perfect evidence.

Records may not fully align. Interviews may conflict. Audit trails may show timing differences. A log may be incomplete. A sample may no longer be available. Historical review may be limited.

The investigation should not ignore these issues.

When evidence conflicts, the investigation should explain how the conflict was evaluated. For example:

  • Which source is more reliable?

  • Is there a timing difference?

  • Was one record created closer to the event?

  • Does system data confirm or challenge interview information?

  • Does the conflict affect product impact or root cause?

  • Is additional evidence needed?

Evidence gaps do not always make an investigation unacceptable. But they should be visible and assessed.

A defensible investigation explains what is known, what is not known, and why the final decision remains appropriate.

 

Use Interviews as Evidence Carefully

SME interviews can be valuable evidence, especially when they explain process flow, task conditions, decision points, handoffs, or actual execution.

However, interviews should be handled carefully.

The investigation should document:

  • who was interviewed

  • why they were interviewed

  • what process knowledge they provided

  • what facts they confirmed

  • what remains opinion or interpretation

  • whether interview information was checked against records or data

Interviews can support an investigation, but they should not replace available records or objective data.

For example, an operator may describe that a task was interrupted during processing. That information may be important. But the investigation should also check batch record timing, room entry logs, process sequence, supervisor notes, or other available evidence where relevant. Interviewing SMEs for GMP Investigations goes deeper into this topic.

 

Evidence and Root Cause Analysis

Evidence should guide root cause analysis.

The investigation should show:

  • which causes were considered

  • what evidence supported each possible cause

  • what evidence ruled out certain causes

  • which root cause was selected

  • whether contributing causes were identified

  • what uncertainty remains, if any

A common RCA weakness is selecting the cause first and then looking for evidence that supports it. This creates confirmation risk.

The stronger approach is to let the evidence test the possible causes.

For example, if a Fishbone diagram identifies people, procedure, equipment, material, measurement, and environment as possible categories, the investigation should not treat all listed causes as conclusions. Each relevant pathway still needs evidence.

RCA tools are useful only when the reasoning is supported by evidence as discussed in When Root Cause Analysis Goes Wrong.

 

QA Review Questions for Evidence

QA review should test whether evidence supports the investigation logic.

QA Review Question What the Investigation Should Show
Was the evidence appropriate for the event? Evidence sources match the event type, scope, and risk
Was time-sensitive evidence preserved? Critical records, data, samples, or conditions were secured, or limitations were documented
Are major claims supported? Conclusions can be traced to records, data, interviews, or observations
Were conflicts addressed? Inconsistent evidence was reconciled, or uncertainty was documented
Were causes ruled out with evidence? Excluded causes have a rationale, not just a statement
Are evidence gaps visible? Missing or unavailable evidence is acknowledged and assessed
Does evidence support impact? Product, process, data, or recurrence risk decisions are evidence-based

QA should be able to see how the investigation moved from event facts to conclusion. If the record lists evidence but does not explain how it was used, the investigation may need strengthening before closure.

 

QA Review Perspective

A strong GMP investigation uses evidence to explain what happened, what may be affected, which causes are supported or ruled out, and why the final quality decision is justified.

The best investigations connect evidence to claims. They make conflicts visible. They explain limitations. They avoid using evidence only after the conclusion has already been selected.

Evidence collection supports the investigation, but evidence analysis supports the decision.

 

Explore more on Investigations & CAPA Excellence

Browse VerethiQ resources on deviation handling, root cause analysis, investigation quality, CAPA design, effectiveness checks, recurrence prevention, and investigation governance.

 
 
Next
Next

GMP Investigation Lifecycle: Step-by-Step