The FDA Group's Insider Newsletter

The FDA Group's Insider Newsletter

7 More Takeaways From Our Q2 2026 Audit Data

We extract a few more important insights from our Q2 audit reports.

The FDA Group's avatar
The FDA Group
Jul 28, 2026
∙ Paid

Our Q2 2026 trends analysis covered the themes that ran across the whole dataset, and the seven-takeaways version compressed them. Both leaned toward GMP manufacturing, because that’s where the major findings clustered.

If you missed it, it’s here in full for paid subscribers:

What Our Auditors Are Finding Lately: 7 Trends Across GMP, GLP, GCP, and Device Work (Q2 2026)

What Our Auditors Are Finding Lately: 7 Trends Across GMP, GLP, GCP, and Device Work (Q2 2026)

The FDA Group
·
Jul 23
Read full story

But 27 audits hold more than seven lessons, and some of the most useful ones sat in the audits we didn’t dwell on: the clinical work, the labs, the quieter minor findings that tell you exactly what an investigator notices.

Here’s the rest of it. Same rules as before, every example anonymized and pulled straight from the reports.

Talk to us if you need auditing, mock inspection, remediation, or other RA/QA/Clinical support.

1. The clinical audits had failure modes you won’t see on a manufacturing floor

We ran a sponsor-level mock BIMO audit and an investigational-device trial site audit last quarter, and both surfaced problems that have no GMP equivalent.

  • At one enrolling site, informed consent had been captured on an e-signature platform that wasn’t certified for the purpose, so a subject’s signature on the consent form sat on a system that couldn’t demonstrate Part 11 compliance. At the same site, a regulatory form authorizing the investigator had been signed on an expired version of the form.

  • At another site, a monitor had downloaded source records from the hospital’s electronic medical record onto a laptop during remote monitoring visits. Access was shut off afterward, but the quality event wasn’t written up for roughly three years.

The device trial site was cleaner, with all minor findings, but they pointed in the same direction: gaps in the delegation-of-authority log, weak version control on the IRB-approved consent form, and investigational device accountability that didn’t fully reconcile.

It was also a single-coordinator site with no trained backup, which is a continuity risk as much as a compliance one.

If you’re running remote or decentralized trials, make sure you’re validating the e-consent platform against Part 11 before a single subject signs, and confirm you’re on the current regulatory forms at activation rather than assuming.

Also, write down explicitly how monitors may and may not handle source data offsite. Treat the delegation log and consent version control as live documents at every site, not something you reconcile at close-out.

2. Exception handling was a soft spot

Across several audits, the routine process ran fine. The trouble showed up in how exceptions were investigated and recorded.

  • At a biologics drug-substance site, one of the two major findings was a backlog of laboratory investigations, with most of the Phase II investigations still open at the time of the audit. The site was generating deviations faster than it was closing them.

  • At a sterile site, a single environmental-monitoring location had failed across two separate out-of-specification events before a corrective action finally brought it back into range, and a separate batch had been filled without its non-viable particle data captured at all before being rejected.

  • At another sterile site, a registration batch had material repeatedly added to compensate for processing losses, with no clear explanation of why the losses kept happening. Compensating for lost material more than once in a batch you intend to file on is a process-control question, not a bookkeeping one.

We recommend tracking investigation aging as a metric your quality leadership actually sees, and setting a threshold that triggers escalation before things pile up. When the same location or the same failure recurs, treat the recurrence itself as the signal, not just each instance.

Also, hold registration and exhibit batches to tighter process control than routine production, since those are the batches your filing rests on.

3. Nobody was qualified to check cleaning

The second major finding at that biologics site is worth pulling out on its own because it’s easy to miss — we see it pretty frequently in our audits. There were no defined provisions for qualifying the operators who perform visual inspection of equipment after cleaning. People were doing the inspection, but nothing was established that they’d been trained to do it or could tell clean from not-clean to a defined standard.

It’s a good reminder that visual inspection is the last check between a cleaning process and the next product, and it rests entirely on the person doing the looking! If that competency isn’t qualified, the cleaning validation behind it is doing less than you think. It’s a quiet problem that doesn’t call attention to itself.

Qualify your visual-inspection operators against a defined standard, requalify them on a set interval, and document the acceptance criteria they’re inspecting against. If you can’t show who’s qualified to make the call, that’s a gap an auditor or investigator will find pretty quickly.

4. One person inspected the material and signed it off

At a medical-device contract manufacturer we audited, incoming inspection reports for purchased labeling and an adhesive material had been approved by the same person who performed the inspection. One signature, both roles, no independent review of the release decision.

Incoming material control is a release decision like any other, and a release decision with no second set of eyes isn’t much of a control. We saw a softer version of the same pattern elsewhere in how some control-sample withdrawals were signed off where the record showed the action but not an independent check on it.

This post is for paid subscribers

Already a paid subscriber? Sign in
© 2026 The FDA Group, LLC · Publisher Terms
Substack · Privacy ∙ Terms ∙ Collection notice
Start your SubstackGet the app
Substack is the home for great culture