Blogs

COMMENTS 35

2025 GMP Audit Trends Report: The Most Common Compliance Gaps We’re Seeing Across FDA-Regulated Operations

At a Glance

At VeritasRx, we analyzed 33 GMP, GCP, GDP, and ISO audit engagements conducted between July and November 2025 across five countries and multiple FDA-regulated industries.

The encouraging takeaway?
There were zero critical findings across the entire dataset.

The concerning takeaway?
The same preventable quality and compliance gaps appeared repeatedly — regardless of company size, geography, or operational maturity.

The biggest risks were not catastrophic system failures. They were operational weaknesses that create inspection vulnerability over time:

  • Documentation and change control gaps
  • Delayed investigations and overdue CAPAs
  • Qualification delays during expansion and tech transfer
  • Weak supplier oversight and notification management
  • Incomplete APQRs and management reviews
  • Laboratory data integrity vulnerabilities
  • Complaint handling backlogs
  • Batch record documentation errors
  • Weak sampling procedures
  • Poorly defined deviation escalation timelines

These findings matter because regulators focus heavily on issues that are visible, auditable, and predictive of broader quality system health.

If your organization struggles to quickly produce:

  • Timely investigations
  • Approved extension records
  • Qualified utilities and equipment
  • Current supplier documentation
  • Complete APQRs
  • Clean batch records
  • Complaint handling metrics

…then there is a strong likelihood that inspection vulnerabilities already exist inside your quality system.

At VeritasRx, we believe these issues are best addressed before an FDA inspection — not during one.

What’s Included in This Dataset

This report reflects audit engagements completed between July and November 2025 across:

  • Pharmaceutical manufacturing
  • API and finished dosage suppliers
  • Clinical supply chains
  • Biologics and ADC operations
  • Packaging and labeling facilities
  • Medical device manufacturers
  • GDP and logistics providers
  • GLP-to-GMP laboratory transitions
  • Clinical trial oversight programs

The audits covered operations in:

  • United States
  • India
  • China
  • Ireland
  • Netherlands

Regulatory frameworks included:

  • 21 CFR Parts 210/211
  • 21 CFR Part 820
  • 21 CFR Part 58
  • ISO 13485
  • ISO 15378
  • EU GDP
  • ICH Q7, Q9, and Q10

All company names and identifying operational details have been anonymized to protect client confidentiality.

Audit Statistics and Trends at a Glance

Dataset Summary

  • 33 audits analyzed
  • 5 countries represented
  • Multiple FDA-regulated sectors reviewed
  • Zero critical findings recorded

Finding Severity Breakdown

  • Critical findings: 0%
  • Major findings: ~15%
  • Minor findings: ~60%
  • Recommendations: ~25%

Most Common Finding Categories

Finding Category% of Audits Affected
Documentation & Change Control70%
Supplier/Vendor Oversight45%
Investigation & CAPA Delays40%
Facility & Equipment Qualification35%
Complaint Handling Backlogs25%
Data Integrity Vulnerabilities25%
APQR & Management Review Gaps20%

Geographic Observations

  • China showed the cleanest outcomes overall
  • India demonstrated operational consistency with primarily administrative gaps
  • United States sites showed the widest performance variation
  • Ireland commonly showed procedural alignment issues
  • Netherlands logistics audits revealed minimal findings

1. Documentation and Change Control Remained the Largest Compliance Gap

Documentation deficiencies appeared in roughly 70% of audits reviewed.

Importantly, most companies had procedures in place. The issue was inconsistent execution, poor timeline management, and inadequate procedural detail.

Common Findings Included:

    • Overdue change controls without documented extensions
    • Retroactive extension approvals
    • Uncontrolled templates used for regulated activities
    • Missing signatures and approval dates
    • Incomplete cleaning records
    • Forms lacking attribution and audit trail details

    These findings matter because FDA investigators routinely review investigation and change control cycle times during inspections.

    Late records without extensions often suggest weak oversight and poor procedural discipline.

Key Recommendations

At VeritasRx, we recommend:

  • Building formal “stop-the-clock” rules into deviation and change control SOPs
  • Requiring extensions before deadlines expire
  • Linking SOPs directly to controlled templates
  • Conducting periodic documentation hygiene reviews
  • Escalating records approaching overdue status

Investigation and CAPA Timeliness Continues to Challenge Many Firms

  • Delayed investigations and CAPA weaknesses appeared in nearly half of the audits reviewed.

    In several cases, investigations were technically adequate — but timing failures created compliance risk.

Common Issues Observed

      • NCR investigations remaining open for months
      • OOS results not recognized in real time
      • QA review failures not triggering CAPAs
      • Deviations closed without meaningful corrective action
      • Long-running investigations with unclear ownership

      These are exactly the types of deficiencies frequently cited in FDA Warning Letters.

Key Recommendations

  • Organizations should:

    • Track investigation cycle times as formal KPIs
    • Create escalation triggers before deadlines are missed
    • Train analysts on immediate OOS recognition
    • Define mandatory CAPA triggers for QA oversight failures
    • Review deviation-to-CAPA ratios regularly

    A very low CAPA ratio often signals CAPA avoidance rather than effective quality management.

3. Qualification Gaps Continue During Expansion and Tech Transfers

  • Qualification-related findings appeared in approximately 40% of audits.

    Most issues were linked to rapidly growing facilities, startup operations, or commercial transition activities.

Common Findings Included

  • Incomplete HVAC qualification programs
  • Delayed environmental monitoring qualification
  • Incomplete media fill programs
  • Missing equipment identification labels
  • Preventive maintenance backlogs
  • Weak labeling controls
  • Missing environmental monitoring baselines

The most common problem was not lack of effort — it was lack of coordination.

Many organizations were managing multiple qualification activities simultaneously without centralized planning.

Key Recommendations

VeritasRx recommends:

  • Consolidating qualification activities into a formal Quality Plan
  • Defining ownership and dependencies clearly
  • Standardizing durable labeling systems
  • Establishing escalation procedures for delayed qualification activities
  • Reviewing PM and calibration backlogs proactively

4. Supplier and Vendor Oversight Was Frequently Underdeveloped

Supplier oversight gaps appeared in roughly 35% of audits.

The issue was rarely initial supplier qualification. The larger risk involved ongoing supplier management and change notification practices.

Common Findings Included

  • Quality agreements not aligned with SOPs
  • Missing client notification timelines
  • Suppliers used while still “under evaluation”
  • Major changes not communicated to customers
  • Logistics providers missing from Approved Supplier Lists
  • Missing transportation validation studies

These gaps create both regulatory and contractual risk.

Key Recommendations

Companies should:

  • Align SOPs directly with quality agreement requirements
  • Define stage-specific client notification rules
  • Formalize supplier escalation procedures
  • Validate transportation and distribution processes
  • Ensure all active suppliers appear on Approved Supplier Lists

5. APQRs and Management Reviews Were Frequently Late or Incomplete

Approximately 30% of organizations showed weaknesses in APQR execution or management review effectiveness.

Common Findings Included

  • APQRs performed by product strength rather than overall product family
  • Complaint trends omitted from reviews
  • OOS events excluded from summaries
  • Misaligned review periods
  • Management reviews never formally conducted
  • Uncontrolled PowerPoint documentation

These findings raise concerns about leadership visibility into quality system performance.

Common Findings Included

Organizations should:

  • Treat APQR timelines as compliance-critical
  • Review trends across all strengths and markets
  • Align all supporting datasets within the same review period
  • Conduct documented management reviews before inspections
  • Include complaint aging and CAPA effectiveness metrics

6. Data Integrity Risks Were Mostly Procedural — Not Fraudulent

Laboratory and data integrity vulnerabilities appeared in roughly 30% of audits.

Importantly, most concerns involved procedural weaknesses rather than deliberate misconduct.

Common Findings Included

  • Missing analytical validation SOPs
  • Incomplete audit trail review programs
  • Missing signature logs
  • Weak sample labeling practices
  • Poor system classification decisions
  • Unsynchronized equipment clocks

Procedural gaps create the conditions where larger data integrity issues can go undetected.

Key Recommendations

VeritasRx recommends:

  • Establishing formal analytical validation procedures
  • Expanding audit trail review programs
  • Implementing signature attribution controls
  • Strengthening sample labeling requirements
  • Reviewing all computerized systems for data integrity risk

7. Complaint Handling and QA Oversight Need Stronger Controls

Complaint handling issues appeared in approximately 25% of audits.

The most common issue was backlog management.

Common Findings Included

  • Complaints submitted late to QA
  • Large volumes of overdue complaints
  • Incomplete complaint documentation
  • Missing QA follow-up sections
  • Complaint aging metrics absent from management reviews

FDA investigators frequently review complaint aging during inspections because it is one of the clearest indicators of QA system stress.

Key Recommendations

Organizations should:

  • Implement complaint intake alerts and escalations
  • Track complaint aging formally
  • Prevent closure of incomplete complaint forms
  • Investigate QA oversight failures as CAPAs
  • Include complaint metrics in management review discussions

8. Batch Record Documentation Weaknesses Persisted

Batch record issues appeared in roughly 25% of audits.

Most findings were minor individually — but collectively they signaled weak GDP discipline.

Common Findings Included

  • Missing BOF/MOF/EOF documentation
  • Missing timestamps
  • Material reconciliation gaps
  • Handwritten variable label data
  • Fragmented electronic batch records

Even small documentation omissions can create broader concerns about operational control.

Key Recommendations

VeritasRx recommends:

  • Reinforcing GDP training with operational context
  • Using structured batch review checklists
  • Eliminating handwritten label variables where possible
  • Consolidating electronic batch record systems

9. Sampling Procedures Often Failed to Meet Regulatory Expectations

Sampling deficiencies appeared in approximately 20% of audits.

Common Findings Included

  • Supplier-selected samples used for testing
  • Identification testing not performed across all containers
  • Sampling plans lacking statistical justification

These practices can conflict directly with 21 CFR 211.84 requirements for representative sampling.

Key Recommendations

Companies should:

  • Require representative sampling from received materials
  • Document statistical justifications for reduced sampling
  • Avoid relying solely on supplier-provided samples
  • Strengthen warehouse and laboratory sampling controls

10. Deviation and CAPA Timeline Escalation Procedures Need Improvement

Several firms lacked escalation structures for delayed investigations and deviations.

Common Findings Included

  • No client reporting timelines
  • Quality agreement obligations absent from SOPs
  • No management escalation for repeated delays

The operational issue is often not the delay itself — it is the lack of formal governance surrounding delayed investigations.

Key Recommendations

Organizations should:

  • Define client reporting timelines formally
  • Align SOPs with contractual quality agreement obligations
  • Create escalation procedures for chronically overdue deviations
  • Review investigation resource allocation regularly

A Quick Recap: What These Findings Mean

Across this dataset, the same patterns appeared repeatedly:

  • Documentation discipline weaknesses
  • Slow investigations
  • Qualification delays
  • Supplier oversight gaps
  • Weak APQR execution
  • Complaint handling backlogs
  • Data integrity procedural vulnerabilities

These are not isolated operational problems.

They are the exact areas FDA investigators examine first because they reveal the overall health of a quality system.

The encouraging news is that most organizations were fundamentally operationally sound.

The challenge is that recurring “minor” issues eventually become major inspection observations when they are repeated, systemic, or left unresolved over time.

Pressure-Test Questions Every Quality Team Should Be Able to Answer

Before your next inspection, ask yourself:

  • Can you demonstrate timely change control extensions approved before due dates?
  • Can you show role-based training completion for every employee?
  • Can you prove OOS investigations were initiated immediately?
  • Can you verify current qualification and calibration status for all critical systems?
  • Are all active suppliers covered by current quality agreements?
  • Are APQRs current across all strengths and markets?
  • Are complaint aging metrics actively reviewed by management?
  • Can every laboratory signature and initial be attributed clearly?
  • Would a randomly selected batch record be fully complete?
  • Are all complaint investigations documented and tracked within required timelines?

If the answer to any of these is unclear, your organization may already have inspection vulnerabilities worth addressing proactively.

How VeritasRx Can Help

VeritasRx supports FDA-regulated organizations with practical, operationally grounded quality and compliance expertise.

We help organizations identify and close compliance gaps through:

Auditing Services

  • GMP, GDP, GCP, and ISO audits
  • Supplier qualification audits
  • Internal quality audits
  • Global vendor assessments

Mock Inspections

  • FDA-style mock inspections
  • Pre-approval inspection preparation
  • Surveillance readiness assessments
  • BIMO and device inspection support

Remediation and QA Support

  • CAPA remediation
  • SOP development and revision
  • Staff augmentation
  • Training and QMS strengthening
  • Investigation and deviation support

Whether you need a single SME or a full audit and remediation team, VeritasRx provides practical support grounded in how regulated organizations actually operate.

The best time to identify compliance vulnerabilities is before regulators do.

 

Related Posts

How We Can

Help You!

VeritasRx helps pharmacy, pharmaceutical, and healthcare businesses navigate complex challenges with expert advisory, compliance, and transaction support. From business growth and operational strategy to mergers & acquisitions and regulatory guidance, we provide tailored solutions designed to protect your operations, maximize value, and support long-term success.