What the inspector wrote
The chromatography data system in QC laboratory 2 was accessed using a shared account 'QCLAB' whose password was known to all analysts. Electronic signatures applied under this account could not be attributed to an individual. The audit trail showed 214 result approvals under the shared account in the review period.
Cited against EU GMP Annex 11, 12.1 and 12.4; Chapter 4, 4.20
Why it was cited
Every data integrity principle rests on attributability. A shared account means no action in the system can be tied to a person, so the audit trail, the electronic signatures and the second-person review are all void at once.
Sites usually know this is wrong and do it anyway for convenience: licence costs, shift handovers, a legacy system. None of these are accepted as justification.
What would have prevented it
- Unique accounts for every user on every GMP system, without exception, with role-based permissions.
- Periodic user access review by QA, with evidence of leavers being removed.
- Include audit trail review in batch and result review procedures, performed by someone other than the data originator.
Written from the deficiency categories published by EU and UK regulators. Details are illustrative and do not describe a specific named site.