A GxP audit tests one thing: whether the way you actually work matches the way your documents say you work. Everything else — the checklists, the room preparation, the binder of procedures — is in service of that single question. Teams that understand this prepare very differently from teams that treat an audit as a document-production exercise.
This is a practical guide to GxP audit preparation: what auditors examine and in what order, what to do in the weeks beforehand, the findings that recur most often, how to run the days themselves, and how to answer a question when you do not know the answer.
What a GxP audit actually examines
Auditors work by sampling and tracing. They pick a thread — a batch, a study, a change, a deviation — and follow it end to end through your records. If the thread holds, they sample another. If it breaks, they pull harder in that area.
The threads they pull most often:
- A recent deviation. Was it detected promptly, investigated to root cause, assessed for product impact, and closed with effective action? Weak investigations are the richest source of findings in any GxP audit.
- A recent change. Was it assessed before implementation, approved by the right people, and did validation status get reassessed where required?
- A training record against an SOP. Is the person performing the task trained on the current version — and is the current version the one they are actually following?
- A computerised system. Is it validated, is the validation current, who has administrator access, and can you produce an audit trail review?
- A data point in a final report, traced back to its raw source. This is the ALCOA+ test in practice, and it is where data integrity problems surface.
Note what is not on that list: the quality manual, the policy statements, the organisational chart. Auditors read those in the first hour and then spend the rest of the audit testing whether they are true.
The weeks before: what to do
Four to six weeks out
- Run your own trace exercises. Pick three threads at random and follow them yourself, exactly as an auditor would. Whatever breaks is what will break in the audit.
- Close the closable. Overdue CAPAs, unreviewed audit trails, expired training, deviations open past their target date — each of these is a finding available for free.
- Confirm your system inventory is current and that each entry has a documented GxP-relevance rationale. Auditors frequently start here.
- Check document currency. An effective SOP whose periodic review lapsed eighteen months ago is a finding that takes ten seconds to generate.
Two weeks out
- Brief the people who will be in the room. Not scripting — the opposite. They need to know the scope, who owns which answer, and that saying "I don't know, let me find out" is correct behaviour.
- Assemble the first-request pack: quality manual, org chart, system inventory, SOP index, training matrix, deviation and CAPA logs, change log, validation summary reports. Have these ready rather than searched for.
- Decide who is the single point of contact and who runs the back room retrieving documents. Improvising this during the audit wastes hours.
The week before
- Walk the areas in scope with fresh eyes. Uncalibrated equipment in use, unlabelled samples, a logbook with gaps — these are visible in seconds.
- Do not start new remediation you cannot finish. A half-completed corrective action is worse evidence than a documented, dated plan to address a known gap.
Findings that recur most often
- Investigations that stop at the symptom. "Operator error" as a root cause, with retraining as the action. Auditors treat this as a signal that the investigation process itself is weak, and they will sample more of them.
- Audit trails never reviewed. The system records them; nobody looks. Both Part 11 and Annex 11 expect review of GxP-relevant audit trail data, and "the system captures it" is not an answer to "who reviews it, how often, and where is the record".
- Uncontrolled spreadsheets performing GxP calculations. Extremely common, rarely validated, always found.
- Administrator access held by people who also perform the work. A segregation-of-duties failure that undermines the integrity of every record in the system.
- Validation that stopped at go-live. No periodic review, no reassessment after supplier updates, no record that validated status still holds.
- Training completed after the task was performed. Date comparison makes this trivially detectable.
- CAPA effectiveness never verified. Actions closed on completion rather than on evidence that the problem stopped recurring.
Every item on that list is detectable by you, before the audit, using your own records. That is the entire argument for continuous readiness over episodic preparation — covered further in inspection readiness.
Running the days themselves
Answer the question asked. Not the adjacent question, not the question you prepared for. Volunteering extra context is the most reliable way to open a new line of enquiry. Brevity is not evasion; it is precision.
Never guess. "I don't know, I'll find out and come back to you" is a completely acceptable answer and an auditor hears it as honesty. A confident wrong answer that the records later contradict damages credibility across the entire audit.
Log every request. What was asked for, when, who retrieved it, what was provided. This log is how you write the response afterwards, and it tells you in real time which areas are being probed.
Debrief daily. A short end-of-day session to review what was asked and what was observed lets you prepare properly for the next morning rather than being surprised at the closing meeting.
Clarify observations before the closing meeting. If an auditor has misread a record, the time to say so is while they are still in the building — politely, with the evidence in hand. Disputing a written finding afterwards is far harder.
After the audit
Respond on time, always. A late response converts a manageable finding into a question about your quality system's reliability.
For each finding, separate three things: correction (fix this instance), corrective action (stop it recurring), and effectiveness check (prove it stopped). Responses that address only the first are the most common reason a finding stays open through the next audit cycle.
Then look for the pattern. Three findings in different areas that all trace to weak change control are one problem, not three. Systems that maintain traceability continuously — the model behind GxP software and, for the documentation-heavy parts, GxP AI — make that pattern visible without a manual analysis exercise.
Where to go next
Explore GxP Copilot for AI-native validation, TraceDraft for source-traceable clinical documentation, or book a demo to see either on your own data.
