GDocP: Recording Defensible GxP Data
Good Documentation Practice (GDocP) is the set of rules that governs how GxP records are created, corrected, controlled, and retained so that a record can be trusted as evidence of what actually happened. It is the operational floor beneath data integrity: ALCOA+ defines the attributes a good record must have, and GDocP is the day-to-day behaviour — how you sign, how you correct, how you contemporaneously record — that produces those attributes. A perfect quality system on paper collapses the moment its documentation cannot be trusted.
What an explainer is not
A topic explainer is SPEQ’s synthesis of what a practice involves, cited to the standards that govern it. It does not reproduce their text, and it does not determine which of them apply to your product or process.
[ POSITION IN THE FRAMEWORK ]
7 DIMENSIONS · 29 LINKSGDocP is the operational floor beneath data integrity across the documentation, quality-system, and GMP disciplines: the daily rules — how you sign, correct, and contemporaneously record — that make a GxP record defensible evidence.
06 · QUALITY MATURITY — GDOCP: RECORDING DEFENSIBLE GXP DATA, REACTIVE TO ADAPTIVE
Records are found blank, back-dated, or corrected with fluid; documentation is treated as clerical, not as the evidence of what happened.
GDocP rules and training exist, but controlled-form issuance/reconciliation is loose and blanks and late entries persist.
Attributable, contemporaneous, legible records are the norm; controlled documents are issued and reconciled, and corrections follow convention.
Correction and blank-field patterns are trended in data-integrity governance; documentation weaknesses surface before an inspector finds them.
Records are trustworthy by design — durable media, retrievable with context and audit trail across the full retention period, paper and electronic alike.
SPEQ’s shared five-stage progression, labelled synthesis — not the FDA QMM rating scale. Where does your organization sit? Score your quality system →
07 · REGULATORY & EVIDENCE
GOVERNING STANDARDS · 4
Derived from the 4 standards SPEQ maps to this subject, across 3 regulatory bodies: FDA, MHRA, PIC/S.
RECORDS & OBJECTIVE EVIDENCE
- Controlled-document issuance and reconciliation records for blank forms
- Completed records that are attributable, legible, contemporaneous, and permanent
- Correction records following the single-line or audit-trailed convention
- Retention schedules mapped to GxP domain and jurisdiction
- Evidence that retained records and audit trails remain retrievable and readable
COMMON INSPECTION FINDINGS
- Blank fields left with no value, N/A, or justification
- Entries in pencil or erasable ink, or corrections obscuring the original
- Batch records pre-signed before the step was performed
- Uncontrolled or obsolete forms in circulation generating 'compliant' wrong records
- Records or audit trails not retrievable or readable for their retention period
What GDocP actually requires
GDocP is not a single regulation; it is a discipline distilled from the recordkeeping expectations of GMP, GCP, GLP, GDP, and GVP. In the GMP world its anchors are the documentation controls of the US predicate rules (records must be complete and retained) and the EU GMP Chapter 4 Documentation requirement that records be made contemporaneously — made or completed at the time each action is taken. The core demand is simple to state and hard to sustain: every entry must be attributable to a real person, legible, made at the time, permanent, and traceable to the activity it describes.
GDocP applies equally to paper and electronic records. On paper it manifests as ink rules, no gaps, single-line corrections, and signatures with dates; in electronic systems it manifests as unique logins, enforced audit trails, and controlled corrections. The behaviours differ; the principle — a faithful, unalterable-without-trace account of the work — does not.
The mechanics practitioners get wrong
The most-cited GDocP failures are mundane: blank fields left without a justification or an "N/A"; entries in pencil or erasable ink; corrections that obscure the original entry; back-dating; shared or generic logins on electronic systems; and forms filled in retrospectively from memory or from a scrap of paper. Each of these breaks a specific ALCOA+ attribute, and inspectors read them as symptoms of a system that does not control its own evidence.
The rule for blanks is worth stating plainly: a field left empty is ambiguous — was the step skipped, or was it done and not recorded? GDocP resolves the ambiguity by requiring every field to be completed, with a documented reason where a value does not apply. The rule for signatures is equally strict: a signature attests that the signer performed or verified the specific action, so pre-signing a batch record before the step is done is a data-integrity finding, not a paperwork slip.
Controlled documents vs. records
GDocP distinguishes two families. Controlled documents — procedures, specifications, master batch records, forms — are approved, version-controlled, and issued; they say how work should be done. Records — completed batch records, logbooks, results, deviations — capture what was actually done. The control set (issue, retrieval of superseded copies, prevention of unauthorised copies) protects the first; the integrity set (contemporaneous entry, correction conventions, retention) protects the second.
A failure of document control seeds a failure of record integrity: if an obsolete method stays in circulation, operators generate perfectly "compliant" records against the wrong instruction. This is why GDocP treats issuance and reconciliation of controlled forms — knowing exactly how many copies of a blank batch record exist and accounting for each — as a first-class control, not clerical housekeeping.
Retention, archiving, and availability
A record is only evidence if it survives and can be produced. GDocP therefore extends to retention periods, legible durable media, protection from loss or deterioration, and the ability to retrieve a record — and its metadata and audit trail — throughout its retention life. Retention periods vary by GxP domain and jurisdiction; the discipline is knowing which period applies and being able to demonstrate the record is intact and available for it — for example, the GMP batch-record retention minimum (typically one year past expiry).
SPEQ synthesis: the durability test is a useful design lens. Ask of any record, "if this were requested five years from now, could we produce it — complete, with its context, and readable on media that still exists?" If the honest answer is no, the GDocP gap is architectural, not behavioural, and no amount of operator training will close it.
FREQUENTLY ASKED
What is the difference between GDocP and data integrity?
Data integrity (ALCOA+) defines the attributes a trustworthy record must have — attributable, legible, contemporaneous, original, accurate, plus complete, consistent, enduring, available. GDocP is the operational practice that produces those attributes: how you sign, correct, date, and control documents. GDocP is the behaviour; data integrity is the outcome you are trying to guarantee.
Is GDocP a specific regulation?
No. GDocP is a discipline distilled from the recordkeeping expectations embedded across GMP, GCP, GLP, GDP, and GVP, reinforced by data-integrity guidance from MHRA, PIC/S, and FDA. There is no single "GDocP regulation" to cite; you cite the underlying predicate rules and the data-integrity guidance that operationalise it.
Why can’t I leave a field blank on a GMP form?
A blank field is ambiguous — it does not distinguish "step not performed" from "step performed but not recorded." GDocP requires every field to be completed, with a documented reason (such as N/A and a justification) where a value genuinely does not apply, so the record is unambiguous evidence of what happened.