FDA

Food and Drug Administration

United StatesNorth AmericaNational / regional regulator

US federal regulator; issues the 21 CFR parts and FDA guidance that set cGMP, data-integrity, and clinical expectations for the US market.

What this page does not claim

SPEQ curates and cross-references these bodies. It is not affiliated with, accredited by, or endorsed by any of them, and a count of decoded standards is a measure of SPEQ’s coverage, not of a body’s importance.

WHAT FDA COVERS

The US Food and Drug Administration regulates drugs, biologics, medical devices, food, cosmetics, and veterinary products under the Federal Food, Drug, and Cosmetic Act, with biologics licensed under section 351 of the Public Health Service Act. Its requirements are codified in Title 21 of the Code of Federal Regulations, and the operational work is split across centres — CDER for drugs, CBER for biologics, CDRH for devices, CFSAN for food and cosmetics, and CVM for veterinary medicine.

WHAT FDA PUBLISHES

  1. 0121 CFR parts — the binding regulations (210/211 drugs, 820 devices, 58 GLP, 312 INDs, 11 electronic records)
  2. 02Guidance for Industry — FDA’s current thinking; non-binding, but the practical standard
  3. 03Form 483 observations and warning letters, both publicly posted
  4. 04Compliance Program Guidance Manuals and the Investigations Operations Manual used by investigators
  5. 05Recall and enforcement reports, and the FDA datasets built from them

HOW ITS REQUIREMENTS BITE

FDA enforces primarily through inspection. Pre-approval inspections test whether a site can actually make what an application describes; surveillance inspections are routine and risk-scheduled; for-cause inspections follow a signal. An inspection closes with a Form 483 listing observations, which can escalate to a warning letter, and from there to import alert, seizure, injunction, or consent decree. A drug not made in conformity with cGMP is deemed adulterated under §501(a)(2)(B) — the statutory hook behind most enforcement.

What practitioners get wrong

  • Guidance is explicitly non-binding — but departing from it means being ready to justify an alternative that achieves the same outcome.
  • The "c" in cGMP means the bar rises with industry practice; meeting the literal 1978 text of Part 211 is a weak defence.
  • Warning letters are the best free intelligence available on where FDA is currently focused — read them by theme, not one at a time.
  • Repeat observations from a prior inspection are treated as evidence the quality system failed to act, and escalate faster.
PROFESSIONAL · INSPECTION INTELLIGENCE · SPEQ SYNTHESIS

What an inspection under this authority actually probes

CHECKING ACCESS

Checking your Professional access…

WHERE IT SITS INTERNATIONALLY

FDA is a founding regulatory member of ICH and has been a PIC/S participating authority since 2011. It operates a Mutual Recognition Agreement with EU authorities covering GMP inspections of human medicines, which lets each side rely on the other’s inspection outcomes for many product types.

FDA STANDARDS SPEQ DECODES · 46

21 CFR Part 211HIGH INSPECTION RISK
Current Good Manufacturing Practice for Finished Pharmaceuticals
21 CFR Part 11HIGH INSPECTION RISK
Electronic Records; Electronic Signatures
21 CFR Part 210
Current Good Manufacturing Practice in Manufacturing, Processing, Packing, or Holding of Drugs — General
21 CFR Part 820HIGH INSPECTION RISK
Quality Management System Regulation (QMSR) — 21 CFR Part 820
FDA Aseptic Processing GuidanceHIGH INSPECTION RISK
Guidance for Industry — Sterile Drug Products Produced by Aseptic Processing
FDA Process Validation Guidance (2011)
Guidance for Industry — Process Validation: General Principles and Practices
21 CFR Part 312HIGH INSPECTION RISK
Investigational New Drug Application (IND)
21 CFR Part 50HIGH INSPECTION RISK
Protection of Human Subjects (Informed Consent)
21 CFR Part 56
Institutional Review Boards (IRBs)
21 CFR Part 58HIGH INSPECTION RISK
Good Laboratory Practice for Nonclinical Laboratory Studies
21 CFR 314.80HIGH INSPECTION RISK
Postmarketing Reporting of Adverse Drug Experiences
21 CFR Part 117HIGH INSPECTION RISK
Current Good Manufacturing Practice, Hazard Analysis, and Risk-Based Preventive Controls for Human Food
21 CFR Part 111HIGH INSPECTION RISK
Current Good Manufacturing Practice for Dietary Supplements
21 CFR Part 226
Current Good Manufacturing Practice for Type A Medicated Articles
21 CFR Part 225
Current Good Manufacturing Practice for Medicated Feeds
21 CFR Part 1271
Human Cells, Tissues, and Cellular and Tissue-Based Products (HCT/Ps)
21 CFR Part 606
Current Good Manufacturing Practice for Blood and Blood Components
21 CFR Part 803HIGH INSPECTION RISK
Medical Device Reporting (MDR)
21 CFR Part 1, Subpart L
Foreign Supplier Verification Programs (FSVP)
21 CFR Part 121
Mitigation Strategies to Protect Food Against Intentional Adulteration
21 CFR Part 507
Current Good Manufacturing Practice and Preventive Controls for Food for Animals
MoCRA (FD&C Act Ch. VI)
Modernization of Cosmetics Regulation Act of 2022
21 CFR Part 700
Cosmetics — General
FD&C Act §503AHIGH INSPECTION RISK
Pharmacy Compounding — Conditions for Exemption
FD&C Act §503BHIGH INSPECTION RISK
Outsourcing Facilities — Registration and cGMP
DSCSA (FD&C Act §§581–585)HIGH INSPECTION RISK
Drug Supply Chain Security Act
21 CFR Part 4HIGH INSPECTION RISK
Regulation of Combination Products (cGMP Requirements)
FDA CSA Guidance (2026)HIGH INSPECTION RISK
Computer Software Assurance for Production and Quality Management System Software
FDA DI & CGMP Q&A (2018)HIGH INSPECTION RISK
Data Integrity and Compliance With Drug CGMP: Questions and Answers
21 CFR 600.80HIGH INSPECTION RISK
Postmarketing Reporting of Adverse Experiences (Biological Products)
FDA GPSV (2002)HIGH INSPECTION RISK
General Principles of Software Validation
FDA Premarket Cybersecurity (2026)HIGH INSPECTION RISK
Cybersecurity in Medical Devices: Quality Management System Considerations and Content of Premarket Submissions
FDA PCCP for AI-Enabled DSF (2024)
Marketing Submission Recommendations for a Predetermined Change Control Plan for Artificial Intelligence-Enabled Device Software Functions
21 CFR Part 830
Unique Device Identification
21 CFR Part 806HIGH INSPECTION RISK
Medical Devices; Reports of Corrections and Removals
21 CFR Part 123
Fish and Fishery Products (Seafood HACCP)
21 CFR Part 112
Standards for the Growing, Harvesting, Packing, and Holding of Produce for Human Consumption
21 CFR Part 106HIGH INSPECTION RISK
Infant Formula Requirements: Current Good Manufacturing Practice, Quality Control Procedures, and Quality Factors
21 CFR Part 558
New Animal Drugs for Use in Animal Feeds
21 CFR Part 610HIGH INSPECTION RISK
General Biological Products Standards
21 CFR Part 630HIGH INSPECTION RISK
Requirements for Blood and Blood Components Intended for Transfusion or for Further Manufacturing Use
21 CFR Part 3
Product Jurisdiction
21 CFR Part 201HIGH INSPECTION RISK
Labeling
21 CFR Part 202
Prescription Drug Advertising
21 CFR Part 207
Requirements for Foreign and Domestic Establishment Registration and Listing for Human Drugs, Including Drugs That Are Regulated Under a Biologics License Application, and Animal Drugs
21 CFR Part 807
Establishment Registration and Device Listing for Manufacturers and Initial Importers of Devices

DISCIPLINES IN FDA’S REMIT

TOPIC EXPLAINERS CITING FDA STANDARDS
Data Integrity & ALCOA+
ALCOA+, the data lifecycle, and why integrity is the foundation every GxP claim rests on.
Computer System Validation & CSA
GAMP 5, the risk-based lifecycle, Part 11, and the shift from documentation to critical thinking (CSA).
Contamination Control & Annex 1
The Contamination Control Strategy, cleanroom classification, and the 2022 Annex 1 revision.
Process Validation Lifecycle
The three-stage lifecycle — design, qualification, continued verification — and the science behind it.
The Pharmaceutical Quality System (ICH Q10)
ICH Q10, the four elements, the two enablers, management responsibility, and the lifecycle model of quality.
Cleaning Validation
Documented proof that cleaning removes residues below health-based limits — HBEL/PDE, MACO, and the shift from arbitrary limits.
Medical Device Quality System (ISO 13485 / QMSR)
ISO 13485, the FDA QMSR harmonisation with 21 CFR 820, device risk management (ISO 14971), and software (IEC 62304).
Media Fill & Aseptic Process Simulation
How aseptic process simulation validates that a sterile process keeps product sterile — design, acceptance criteria, and the interventions that decide the result.
Master Batch Record (MBR) & Batch Production Records
The approved manufacturing template and the contemporaneous execution record — 21 CFR 211.186/211.188, EU GMP Chapter 4, and the move to electronic batch records.
HACCP & Preventive Controls
The seven principles of Hazard Analysis and Critical Control Points, the Codex framework, ISO 22000, and how FSMA preventive controls extend it.
RABS & Isolators — Aseptic Barrier Systems
How restricted access barrier systems and isolators separate operators from the sterile core — open vs closed RABS, isolators, and what EU GMP Annex 1 now expects.
Software as a Medical Device (SaMD)
Software that is itself a medical device — the IMDRF definition, IEC 62304 lifecycle, ISO 14971 risk, EU MDR Rule 11, and how AI/ML changes the picture.
Pharmacovigilance Signal Management
How a safety signal is detected, validated, assessed, and acted on — the GVP process that turns individual case reports into a change to a medicine’s benefit-risk balance.
GLP Study Conduct: Study Director & QAU
What Good Laboratory Practice actually governs — the organisation, roles, and records that make a non-clinical safety study trustworthy and reconstructable, not the quality of its science.
Informed Consent & Ethics Oversight
The two structural safeguards that make a clinical trial ethical — independent ethics review before it starts, and a genuine informed-consent process for every participant — and why consent is a process, not a signature.
Periodic Safety Reporting: PSURs & PBRERs
The scheduled aggregate safety reports through which a marketing-authorisation holder periodically re-evaluates a medicine’s benefit-risk balance — the periodic complement to continuous signal management.
Serialization & Falsified Medicines
How a unique identifier on every saleable pack, plus tamper-evidence and interoperable verification, keeps falsified product out of the legitimate supply chain — and why regulators specify the outcome while GS1 specifies the syntax.
CAPA: Corrective & Preventive Action
The three words the industry uses interchangeably and shouldn’t — correction, corrective action, preventive action — and why most "CAPAs" are none of the last two.
Change Control
The process that evaluates and approves a change to a validated state before it is made — and why "before, not after" is the entire point that separates it from a deviation.
Deviation Management
What to do when reality departs from the approved state: how a deviation is classified, investigated to a real root cause, and turned into a CAPA — and the timing that separates it from change control.
Product Quality Review (PQR / APR)
The annual look back that is supposed to find the trend before it becomes a recall — why PQR and APR are the same idea under two names, and how a real one differs from a copy-paste template.
Audit Trail Review
Having an audit trail is not reviewing it — the distinction regulators built an entire enforcement wave on, and how a risk-based review finds the deleted run instead of drowning in keystrokes.
Design Controls
The traceable process that proves a device design is right before it is built — why verification and validation are not the same question, and how the QMSR transition folds 21 CFR 820.30 into ISO 13485 §7.3.
Complaint Handling & Device Vigilance
Every complaint is not a reportable event, and every reportable event is not a recall — the three decisions a device maker must keep distinct, and why under-reporting is a classic finding.
ICSRs & Expedited Reporting
The atomic unit of pharmacovigilance and the clock attached to it — the four things that make a case valid, why "serious" is not "severe", and what actually triggers a 15-day report.
Sponsor Oversight of Clinical Trials
A sponsor can outsource the work of a trial to a CRO but never the responsibility for it — what real oversight looks like beyond signing a contract, and what ICH E6(R3) changed.
RBM vs RBQM: Monitoring vs Quality Management
Vendors use them as synonyms; they are not. One is how you oversee a trial, the other is the lifecycle discipline that contains it — and ICH E6(R3) put the larger one at the centre of GCP.
Quality Tolerance Limits (QTLs) & KRIs
A QTL is not a site metric and a KRI breach is not a QTL breach — the two get set at the wrong level constantly, and a QTL crossing is not automatically a protocol deviation.
SDV vs SDR: Source Data Verification & Review
SDR is not "lite SDV" — they catch different failures. 100% SDV will never find the unreported adverse event sitting in the medical record, because there is no CRF entry to compare against.
Source Data, eSource & Direct Data Capture
Source data is the information; source documents are the containers — and under direct data capture the eCRF *is* the source, which makes source-data verification conceptually impossible.
Protocol Deviations & Serious Breaches
Deviation → important deviation → serious breach looks like one escalating ladder. It is not — a serious breach is a different axis with a statutory reporting clock, and a systemic GCP failure with no protocol departure can be one.
The Trial Master File (TMF) & TMF Reference Model
The document set that lets a trial be reconstructed and its GCP compliance proven — why "the TMF was complete at the end" misses the point, and who actually stewards the Reference Model now.
OOS & OOT Investigations
A result outside specification is not a failing batch — it is a question. The two-phase investigation that decides whether the result or the process was wrong, and why "invalidate and retest" is the classic finding.
Stability Testing & Shelf Life
How a shelf life is actually justified — real-time and accelerated conditions, the ICH climatic zones, and why you cannot simply average three batches to a number.
Analytical Method Lifecycle (ICH Q2/Q14)
Validation is not a one-time gate at the end — ICH Q14 reframed a method as something developed, validated, and managed across a lifecycle, and it changed what a post-approval method change requires.
Pharmaceutical Water & WFI
Water is the most-used ingredient in pharma and it cannot be released like an ingredient — the system is validated and monitored so the water is trusted as it is used, and why WFI is a category apart.
Extractables & Leachables (E&L)
Extractables are what a container could release under stress; leachables are what actually migrates into the product in real life — and confusing the two is why E&L programs over- or under-test.
Container Closure Integrity (CCI)
The sterile barrier has to hold for the whole shelf life, not just pass a test at release — why modern CCI is a deterministic, validated measurement and the 2022 Annex 1 pushed it past the dye-bath.
Literature Monitoring in Pharmacovigilance
The scientific literature is a legally-mandated source of adverse-event cases — a systematic, documented search with defined databases and a weekly rhythm, not an occasional look.
RMP vs REMS: EU & US Risk Management
The EU requires a risk management plan for essentially every new medicine; the US imposes a REMS only when a specific safety problem demands it — a default-on system versus an exception-based one.
Nitrosamine Impurities
The contamination saga that has run since 2018 — why nitrosamines forced a whole-industry risk assessment, where they come from, and why this is a living page tied to the intelligence feeds, not a fixed limit.
ATMPs: Cell & Gene Therapy Manufacturing
When the batch is one patient, the process is the product, and starting material is a living donation, the classical GMP model bends — why advanced therapies needed their own rulebook.
EU GMP Annex 11 (2025 Revision)
The draft revision of the EU GMP computerised-systems annex — lifecycle validation, data integrity, cloud, AI, and cybersecurity as a core GMP requirement.
Decentralized Clinical Trials
How DCT elements — remote visits, telehealth, DTP shipping and eConsent — fit the GCP quality-by-design framework.
AI/ML Validation in GxP
Validating machine-learning and AI systems in regulated environments — data provenance, model lifecycle, and the static-vs-adaptive distinction.
FDA QMSR Transition
FDA's Quality Management System Regulation harmonizes 21 CFR 820 with ISO 13485 — what changes and what stays.
Elemental Impurities (ICH Q3D)
Controlling metal impurities in drug products through PDE-based risk assessment across identified elements and routes of administration.
Parametric Release
Releasing terminally sterilized product on validated process data instead of the sterility test — when it is permitted and what it demands.
Lyophilization (Freeze-Drying)
Sterile freeze-drying — the process, its critical parameters, and the aseptic and validation controls that govern it.
Continued Process Verification
Stage 3 of process validation — ongoing monitoring, trending and statistical control that proves the process stays validated.
GDocP: Recording Defensible GxP Data
The GDocP rules — attributable, legible, permanent records — that turn a GxP activity into defensible evidence.
Contemporaneous Recording
The "C" in ALCOA — recording at the time of the activity — and why deferred entries are a data-integrity finding.
Correcting GxP Records
How to change a GxP record defensibly — single-line strike-through, reason, initials, date — on paper and in electronic systems.
The EU Risk Management Plan (RMP)
The structure of the EU-RMP — safety specification, pharmacovigilance plan, risk-minimisation — and how it evolves across a product’s life.
Additional Monitoring & Black Triangle
The inverted black triangle, the EU additional-monitoring list, and why "▼" means report every suspected reaction.
PV Audits & Inspections
How the PV system is assured — risk-based internal audit, the CAPA loop, and what a GVP inspection actually examines.
Returns & Recalls in Distribution
How distributors handle returned medicines, execute recalls, and keep falsified product out of the legitimate supply chain.
Bioanalytical Method Validation
Validating the assays that measure drug in biological matrices — selectivity, calibration, accuracy, precision, and stability.
Aseptic Processing
How sterile drug products are filled and assembled without a terminal sterilization step, and the contamination controls that make it possible.
Sterilization Methods Overview
A comparative map of the sterilization technologies used across sterile manufacturing — moist heat, dry heat, filtration, irradiation, and gas — and how a manufacturer chooses among them.
Depyrogenation
Removing or inactivating bacterial endotoxin from containers, components, and equipment surfaces before they meet a sterile product.
Bacterial Endotoxins Test
The LAL-based assay used to detect and quantify bacterial endotoxin in parenteral products, water systems, and components.
Sterility Testing
The compendial test used to verify the absence of viable microorganisms in a sterile product batch, and why a pass does not prove sterility assurance.
Visual Inspection & Particulates
The 100% and statistical inspection programs that catch visible particulate matter and container defects before a sterile product is released.
Aseptic Gowning & Technique
How personnel are qualified to enter classified aseptic environments without becoming the contamination source they are being protected from.
Filter Integrity Testing
The non-destructive tests — bubble point, diffusive flow, and pressure hold — that confirm a sterilizing-grade filter actually retained its rated bacterial challenge.
Blow-Fill-Seal
The advanced aseptic technology that extrudes, fills, and seals a plastic container in one continuous, largely automated cycle.
Blend and Content Uniformity
The tests and sampling strategy used to demonstrate that active ingredient is distributed evenly through a powder blend and, ultimately, through every finished dosage unit.
Excipient GMP
Why pharmaceutical excipients — the “inactive” majority of most formulations — are governed by an industry-consensus GMP guide rather than a single binding global regulation.
Bioequivalence and Bioavailability
The pharmacokinetic comparison used to demonstrate that a test drug product performs the same in the body as a reference product — the scientific foundation of most generic drug approvals.
Reference Standards and Reagents
The characterized materials every identity, purity, and potency result is measured against — and why their qualification and lifecycle management are as GMP-critical as the test method itself.
Qualified Person Batch Release
The EU regulatory checkpoint that certifies each batch of medicinal product before it reaches the market.
GxP Training and Competency
The documented process that establishes and maintains that personnel are qualified, by education and training, for the GxP tasks they perform.
Quality Metrics Program
The set of trended indicators an organisation tracks to know whether its quality system is actually working, before a regulator has to tell it otherwise.
GAMP 5 Software Categories
The risk-based classification scheme, from GAMP 5, that determines how much validation effort a given piece of GxP software actually needs.
Computer Software Assurance (CSA)
FDA’s 2022 guidance shifting device production and quality-system software assurance from documentation-heavy CSV toward critical-thinking, risk-based testing.
21 CFR Part 11 — Electronic Records and Signatures
The FDA rule setting the criteria under which electronic records and electronic signatures are considered equivalent to paper records and handwritten signatures.
Human Factors and Usability Engineering (IEC 62366-1)
The engineering discipline, and the standard behind it, for designing medical devices so that intended users can operate them safely and effectively.
Medical Device Cybersecurity
The engineering and regulatory discipline for securing connected medical devices against cyber threats across their design, submission, and post-market lifecycle.
Design Verification vs. Design Validation
The two distinct, commonly confused design-control activities that confirm a device was built right, and that the right device was built.
Post-Market Surveillance for Medical Devices
The proactive, systematic collection and analysis of real-world device performance data that a manufacturer runs for as long as the device is on the market.
MDR Vigilance Reporting
The threshold-triggered obligation to report device-related serious incidents and field safety corrective actions to regulators within defined timelines.
OT & ICS Security in Regulated Manufacturing
Securing the PLCs, DCS, SCADA and historians that run regulated production — where availability outranks confidentiality and a patch is a change.
Software Supply-Chain Security & SBOM
Third-party components, software bills of materials, vulnerability intake, and supplier assurance for the software a regulated organisation did not write.
Identity & Access Management in GxP Systems
Unique identity, authority checks, segregation of duties, privileged access and periodic review — the controls that make a GxP record attributable.
Cyber Incident Response for Regulated Records
What happens to GxP records, batch disposition and reporting clocks when a security incident lands — and why containment is only half the response.
Regulatory Classification & Pathway Strategy
What the product legally is in each market, which authorisation route follows, and why the rationale has to be written down.
Health-Authority Engagement
Meetings, scientific advice, questions and responses — and why every undertaking given becomes a commitment the organisation is held to.
Regulatory Submission Strategy & Planning
The CTD, the eCTD, and how a dossier plan built on dependencies rather than document counts survives contact with a filing date.
Establishment Registration & Licensing
The permissions the business actually runs on — registrations, manufacturing and wholesale licences, importer roles — and why they lapse quietly.
Labelling, Artwork & Promotional Compliance
Approved labelling and its translations, artwork under change control, and the boundary between an authorised claim and promotion.
Cybersecurity Governance in Regulated Organisations
Who owns cyber risk, what residual risk the business has actually accepted, and how an ISMS meets a pharmaceutical quality system.
Vulnerability & Patch Management Under Change Control
Most compromises exploit something known and unpatched — and in validated environments the window between disclosure and remediation is structurally wider.
Business Continuity & Recovery
Ransomware made recovery the primary control — and in regulated manufacturing a system that is running again is not yet back in a validated state.
Process Instrumentation & Measurement
Every control action and recorded value begins at an instrument — and a correctly calibrated one can still be wrongly installed.
Alarm Management & Safety Instrumented Systems
An alarm asks a person to act; a safety instrumented function acts itself. Collapsing the two removes the independence the risk assessment assumed.
Management Accountability & Decision Rights
Regulators hold an organisation to decisions, not intentions — and "everyone assumed someone else had checked" is a decision-rights failure.
Manufacturing Strategy & Operating Model
Campaign or dedicated, in-house or contract — each model concentrates a different risk, and the control burden follows the choice.
Operational Excellence in Regulated Manufacturing
Most waste in regulated manufacturing is rework, investigation and delay caused by poor control — so improvement and compliance rarely trade off.
Operational Readiness, Startup & Ramp-Up
The deviation rate during ramp-up is the highest the process will ever see — and that is the clearest information about it anyone will get.
Control System Assurance
Where a small configuration change has a direct physical consequence — and can be made by someone whose role is not framed as regulated.
Maintaining the Validated State
Validation is a claim about the present, maintained by work nobody sees — and most loss of validated state is cumulative and undramatic.
Process Characterisation & Design Space
Process understanding is what makes validation an argument rather than a demonstration.
Protocol Design, Estimands & Study Design
Complexity added in the protocol multiplies across every participant at every visit — and falls on people who had no part in writing it.
Site Feasibility, Startup & Management
Sites are where the protocol meets reality — and a site activated before it is ready produces the deviations that consume the study.
Study Closeout & Results Disclosure
Disclosure obligations are legal duties with deadlines, enforced independently of how the trial went.
Medical Information & Inquiry Handling
A high-volume front door through which adverse events and complaints arrive disguised as questions.
Safety Systems & Partner Data Exchange
Every exchange with a partner is a place a case can be delayed or lost — and reconciliation only works if it is periodic and two-way.
Materials, Components & Packaging Controls
A specification that omits an attribute the process depends on will be met by material that does not work — and the supplier will be right.
Quality & Technical Agreements
It decides who does what when something goes wrong — written while nothing has.
Shortage Prevention & Supply Continuity
Most shortages trace to a single site or upstream supplier — which makes them foreseeable from the network map long before they occur.
Workforce Planning & Critical Skills
Qualification takes months, so staffing gaps cannot be closed at the speed they open.
Learning, Training & Effectiveness
Retraining a person who already knew the procedure addresses nothing — effectiveness evaluation is what separates a capability gap from a convenient CAPA.
Human Performance & Work Design
Human error is an outcome, not a cause — treating it as a cause ends the investigation where the useful information starts.
Sampling Plans, Specifications & Standards
A result describes the sample — and the sample describes the batch only if the plan makes it representative.
Metrology & Calibration Management
A calibration failure is retrospective by nature — which is why the as-found condition matters more than the as-left one.
Laboratory Capacity, Flow & Turnaround
A laboratory running permanently at capacity has no slack for an investigation — which is exactly when it will be asked to do one.
Digital Strategy & Application Portfolio
Regulated organisations accumulate systems faster than they retire them, and each carries a validation obligation for life.
Integration & Interoperability for GxP Data
Errors here are silent by construction — a successful transfer looks identical to a correct one.
Platforms, Cloud & Infrastructure for GxP
Moving to a managed platform moves the work, not the accountability.
Analytics & Decision Support in GxP
Self-service lets a good question be answered quickly and lets a wrong metric spread before anyone checks it.
Records, Content & Retrieval
A record that cannot be found within the time an inspection allows is functionally missing.
Digital Service Management in Regulated Operations
The validated state is maintained or lost in routine service management, not in projects.
Demand, Capacity & Scenario Planning
Forecast error becomes either shortage or write-off — and the shortage side carries patient harm.
Biosafety & Biological Containment
Containment protects people from the product; cleanroom design protects the product from people — and they impose opposite pressure regimes.
Physical Security & Site Protection
Someone in the room can defeat most logical controls — and controlled substances carry federally prescribed security, not risk-based security.
Protect vs Disclose — The Trade-Secret Seam
One obligation requires the method and the data behind a regulated product to be written down and filed; another says their commercial value is that they are not. Where the two meet, and which disclosure bites hardest.

FDA: frequently asked questions

Reference answers on Food and Drug Administration’s mandate, what it publishes, and how its requirements acquire force.

What does the FDA regulate?

The US Food and Drug Administration regulates drugs, biologics, medical devices, food, cosmetics, and veterinary products under the Federal Food, Drug, and Cosmetic Act, with biologics licensed under section 351 of the Public Health Service Act. The operational work is split across centres — CDER, CBER, CDRH, CFSAN, and CVM.

Is FDA guidance legally binding?

No. Guidance for Industry states FDA’s current thinking and is explicitly non-binding; the binding requirements are the regulations in Title 21 of the Code of Federal Regulations. In practice, departing from guidance means being ready to justify an alternative approach that achieves the same outcome.

What is an FDA Form 483?

A Form 483 is the list of observations an investigator issues at the close of an inspection. It can escalate to a warning letter, and from there to import alert, seizure, injunction, or consent decree. A drug not made in conformity with cGMP is deemed adulterated under §501(a)(2)(B).