You do not prepare for an FDA inspection when you receive the notification. You prepare for it every day — and when notification arrives, you verify that your preparation holds. This guide provides the 90-day playbook that validation and quality leaders use to move from "we think we are ready" to "we know we are ready, and here is the evidence." It covers the systems, documents, people, and processes that inspectors examine, in the order they typically examine them.
Days 1–14: System and documentation inventory
The first two weeks are about confirming what you have, not fixing what you do not. Start with the system inventory: every GxP-critical computerised system, its validation status, its last periodic review date, and its change control history since the last review. Produce a one-page summary per system. Then move to documentation: the VMP, site master file, SOPs, training records, and deviation/CAPA logs. Confirm that every document is current, approved, and accessible from the DMS — not filed in someone's inbox.
- Run a validation status report from GxP Copilot or your validation management tool. Flag any system overdue for periodic review.
- Pull the last 12 months of change control records. Confirm every change has a completed impact assessment and, where required, regression testing evidence.
- Verify that your approved supplier list is current and every GxP software vendor has a completed audit or assessment.
- Confirm that your training matrix is current and all personnel in GxP roles have completed required training.
Days 15–30: Gap closure sprint
Take the findings from the inventory and close gaps aggressively. Prioritise by inspection risk: items that result in 483 observations, not items that are merely imperfect.
- Overdue periodic reviews. Complete them now. A periodic review does not need to be a major exercise — it confirms that the system still operates as validated, changes have been controlled, and the risk assessment is still current.
- Open deviations past their due date. Close them or document a justified extension. Open, overdue deviations are one of the most common 483 triggers.
- CAPA effectiveness checks not completed. Verify that completed CAPAs actually achieved their intended outcome. This is the step most teams skip, and inspectors know it.
- Training gaps. Any GxP role missing required training is a finding. Complete the training and document it before the inspection window.
- Audit trail review. Run an audit trail review for your highest-risk systems. Look for patterns that inspectors flag: repeated login failures, after-hours modifications, data deletions followed by re-entries.
Days 31–60: Mock audit
The mock audit is the most valuable activity in inspection preparation. It simulates the inspector's walkthrough using the same techniques, questions, and evidence requests that real inspectors use.
- Select your mock auditor. This should be someone who has seen real FDA inspections — either an internal audit team member with inspection experience or an external consultant. The mock auditor should not have been involved in the gap closure sprint.
- Scope the mock audit. Cover the same ground an inspector would: the system inventory, validation records for 2–3 systems, the change control process, training records, deviation/CAPA management, and data integrity.
- Run it realistically. The mock auditor requests documents, interviews staff, reviews audit trails, and follows deviation threads to their conclusion. Time the document retrieval — if it takes more than 15 minutes to produce a requested record, that is a readiness gap.
- Debrief and remediate. The mock audit should produce a report with findings categorised by severity. Remediate critical findings immediately. Track minor findings as improvement actions.
audit readiness provides the mock-audit protocol framework, and GxP Copilot's audit readiness dashboard shows the current status of every system's validation records, periodic reviews, and change control history in real time.
Days 61–90: Readiness lock and team preparation
In the final 30 days, the focus shifts from systems and documents to people. Inspectors interview staff at every level — from operators to QA managers. Everyone who might interact with an inspector needs to know three things: what their role involves, where the evidence of their work lives, and how to respond to questions honestly without volunteering unnecessary information.
- Conduct brief interview preparation sessions for all GxP-facing staff. Practice answering common inspector questions: "Show me how you handle a deviation," "Walk me through a recent change control," "How do you know this system is validated?"
- Establish the inspection logistics: designated rooms, escort procedures, document request workflow, real-time communication protocol for the inspection team.
- Run a final readiness check against all 60 items in the compliance checklist. Every item should be green. Any amber or red items should have documented remediation timelines.
- Freeze non-critical changes. Do not deploy system upgrades, SOP revisions, or process changes in the 30 days before a known or anticipated inspection unless they are required to close a compliance gap.
The five most common 483 observations and how to prevent them
| Rank | 483 Category | Root Cause | Prevention |
|---|---|---|---|
| 1 | Procedures not followed | SOP too complex or outdated | Simplify SOPs, verify training, audit compliance |
| 2 | Inadequate investigation of failures | Root cause analysis skipped or superficial | Train on RCA methods, require QA review of investigations |
| 3 | Equipment not properly maintained | PM programme gaps or missed schedules | Automated PM scheduling, calibration tracking |
| 4 | Laboratory controls inadequate | OOS investigation, data integrity, method validation | data integrity (ALCOA+) programme, audit trail review, method validation |
| 5 | Buildings/facilities not properly maintained | Environmental monitoring, cleaning validation gaps | Environmental monitoring programme, cleaning validation |
Where to go next
Explore GxP Copilot for AI-native validation, TraceDraft for source-traceable clinical documentation, or book a demo to see either on your own data.
