Evidence Collection and Analysis in GMP Investigations
Evidence is the bridge between the event and the investigation conclusion.
A GMP investigation should not rely only on opinion, memory, or assumption. It should show what records, data, observations, interviews, and process information were reviewed, and how those items support the final decision.
This does not mean collecting every possible document. It means identifying the evidence needed to understand the event, evaluate impact, test possible causes, and support the investigation conclusion.
As discussed in GMP Investigation Lifecycle: Step-by-Step, evidence collection begins early and continues as the investigation develops. New evidence may change the scope, refine the root cause, or affect the product impact decision.
Start With the Investigation Question
Evidence collection should begin with the investigation question.
Before gathering records, the team should ask what the investigation needs to determine. For example:
What happened?
When and where did it happen?
What product, batch, system, record, equipment, or area may be affected?
Was the event isolated or potentially broader?
What controls should have prevented or detected it?
What possible causes need to be tested?
What product, process, or data impact decision needs support?
Evidence collection should follow the event, scope, and risk. A generic checklist may help prompt the team, but it should not replace investigation thinking.
For example, a documentation error may require batch record review, procedure review, workflow review, training record review, and interviews. An equipment alarm may require alarm history, equipment logs, maintenance records, process data, calibration status, and operator response review.
The right evidence depends on the event being investigated.
Identify Relevant Evidence Sources
Common evidence sources in GMP investigations include:
batch records
logbooks
equipment records
alarm records
audit trails
test results and raw data
chromatograms
environmental monitoring data
cleaning records
maintenance and calibration records
training records
material movement records
labels, components, or samples
procedures and specifications
process observations
SME interviews
prior deviations, complaints, OOS/OOT results, CAPAs, and trends
The investigation does not need every source for every event. The evidence should be relevant to the scope and the question being answered.
| Evidence Type | What It May Help Evaluate |
|---|---|
| Batch records and logbooks | What was documented during execution, review, or control checks |
| Equipment and alarm records | Whether equipment status, alarms, or interventions contributed |
| Audit trails and system data | Timing, entries, changes, approvals, or data integrity concerns |
| Test results and raw data | Whether quality attributes, specifications, or analytical results were affected |
| Procedures and specifications | What was required and whether the requirement was clear |
| Training records | Whether personnel were qualified for the task |
| Interviews and observations | Process reality, sequence of events, handoffs, and task conditions |
| Prior deviations and trends | Whether the event appears isolated, repeated, or part of a pattern |
This step should be guided by the defined investigation scope. Defining Investigation Scope in GMP Deviations goes deeper into how scope should be set and justified.
Preserve Time-Sensitive Evidence Early
Some evidence can disappear, change, or become less reliable over time.
Examples include:
equipment status
alarm history
audit trail data
samples
labels, components, or packaging
room conditions
environmental monitoring context
access records
in-process observations
personnel recollection
If time-sensitive evidence is not preserved early, the investigation may be limited later.
For example, an equipment condition may change after maintenance. A room condition may no longer represent the condition at the time of the event. Personnel may not remember the sequence clearly after several days. Some system data may be overwritten or become harder to retrieve.
When evidence is unavailable, the investigation should document the limitation and assess its impact. The record should not ignore missing evidence if that evidence was important to the investigation question.
Connect Evidence to Claims
A strong investigation does not only list evidence reviewed. It explains what the evidence supports.
Weak wording:
Training records were reviewed.
Stronger wording:
Training records confirmed that the operator was qualified on SOP-123 before the batch was executed. However, training status alone did not explain why the reconciliation entry was missed.
Another weak example:
Equipment logbook reviewed; no issues noted.
Stronger wording:
The equipment logbook showed no alarms, interventions, or maintenance activity during the batch window. This supports the conclusion that an equipment interruption was not a likely contributor.
The difference is important. The stronger wording connects the evidence to the investigation claim.
Every major conclusion should be traceable to evidence. If the investigation states that the event was isolated, the record should show what historical review, related batch review, trend review, or similar-event search supports that statement.
If the investigation states that equipment was not a contributor, the record should show what equipment records, alarms, maintenance history, or process data were reviewed.
Analyze Evidence, Do Not Only Collect It
Evidence collection and evidence analysis are different activities.
Collecting evidence means gathering records, data, interviews, and observations. Analyzing evidence means determining what those items show.
Evidence analysis may include:
comparing records to the event timeline
checking consistency between different sources
identifying conflicts or missing information
determining whether evidence supports or rules out possible causes
deciding whether scope needs to expand
evaluating whether product or process impact changes
documenting uncertainty where it remains
A large evidence package does not make an investigation stronger if the report does not explain what the evidence means.
For example, attaching batch records, training records, and equipment logs may show that documents were collected. But the investigation still needs to explain how those records support the final conclusion.
Writing Defensible Investigation Reports explains this from a reporting perspective. The report should show how the evidence was used, not only that evidence was gathered.
Handle Conflicting or Incomplete Evidence
Not every investigation has perfect evidence.
Records may not fully align. Interviews may conflict. Audit trails may show timing differences. A log may be incomplete. A sample may no longer be available. Historical review may be limited.
The investigation should not ignore these issues.
When evidence conflicts, the investigation should explain how the conflict was evaluated. For example:
Which source is more reliable?
Is there a timing difference?
Was one record created closer to the event?
Does system data confirm or challenge interview information?
Does the conflict affect product impact or root cause?
Is additional evidence needed?
Evidence gaps do not always make an investigation unacceptable. But they should be visible and assessed.
A defensible investigation explains what is known, what is not known, and why the final decision remains appropriate.
Use Interviews as Evidence Carefully
SME interviews can be valuable evidence, especially when they explain process flow, task conditions, decision points, handoffs, or actual execution.
However, interviews should be handled carefully.
The investigation should document:
who was interviewed
why they were interviewed
what process knowledge they provided
what facts they confirmed
what remains opinion or interpretation
whether interview information was checked against records or data
Interviews can support an investigation, but they should not replace available records or objective data.
For example, an operator may describe that a task was interrupted during processing. That information may be important. But the investigation should also check batch record timing, room entry logs, process sequence, supervisor notes, or other available evidence where relevant. Interviewing SMEs for GMP Investigations goes deeper into this topic.
Evidence and Root Cause Analysis
Evidence should guide root cause analysis.
The investigation should show:
which causes were considered
what evidence supported each possible cause
what evidence ruled out certain causes
which root cause was selected
whether contributing causes were identified
what uncertainty remains, if any
A common RCA weakness is selecting the cause first and then looking for evidence that supports it. This creates confirmation risk.
The stronger approach is to let the evidence test the possible causes.
For example, if a Fishbone diagram identifies people, procedure, equipment, material, measurement, and environment as possible categories, the investigation should not treat all listed causes as conclusions. Each relevant pathway still needs evidence.
RCA tools are useful only when the reasoning is supported by evidence as discussed in When Root Cause Analysis Goes Wrong.
QA Review Questions for Evidence
QA review should test whether evidence supports the investigation logic.
| QA Review Question | What the Investigation Should Show |
|---|---|
| Was the evidence appropriate for the event? | Evidence sources match the event type, scope, and risk |
| Was time-sensitive evidence preserved? | Critical records, data, samples, or conditions were secured, or limitations were documented |
| Are major claims supported? | Conclusions can be traced to records, data, interviews, or observations |
| Were conflicts addressed? | Inconsistent evidence was reconciled, or uncertainty was documented |
| Were causes ruled out with evidence? | Excluded causes have a rationale, not just a statement |
| Are evidence gaps visible? | Missing or unavailable evidence is acknowledged and assessed |
| Does evidence support impact? | Product, process, data, or recurrence risk decisions are evidence-based |
QA should be able to see how the investigation moved from event facts to conclusion. If the record lists evidence but does not explain how it was used, the investigation may need strengthening before closure.
QA Review Perspective
A strong GMP investigation uses evidence to explain what happened, what may be affected, which causes are supported or ruled out, and why the final quality decision is justified.
The best investigations connect evidence to claims. They make conflicts visible. They explain limitations. They avoid using evidence only after the conclusion has already been selected.
Evidence collection supports the investigation, but evidence analysis supports the decision.
Explore more on Investigations & CAPA Excellence
Browse VerethiQ resources on deviation handling, root cause analysis, investigation quality, CAPA design, effectiveness checks, recurrence prevention, and investigation governance.