How do pharma, biotech and medtech companies safeguard their GxP compliance through structured audits?
We conduct GMP, GLP and GCP audits: internally, at suppliers and CDMOs, and in preparation for regulatory inspections. We assess against the EU GMP Guidelines, the OECD GLP Principles, ICH E6 (GCP) and 21 CFR. The real leverage rarely lies in the individual finding, but in how it connects: an audit finding that does not feed into a robust CAPA system will resurface at the next inspection.
- Pharma
- Biotech
- MedTech
- IVD
Overview
Which GxP challenges do companies face in practice?
GMP, GLP and GCP audits across the full spectrum · EU GMP Guidelines, OECD GLP, ICH E6 (R2), 21 CFR Part 210/211
Last updated: 2026-06-13
The GxP frameworks (GMP, GLP, GCP, GDP, GVP) apply to different activities and each follow their own requirements and audit approaches. In practice, audits break down less over individual provisions than over recurring structural gaps. The four most common:
- Suppliers and CDMOs are inadequately assessed against the EU GMP Guidelines (EudraLex Volume 4). Qualification of critical API producers and contract manufacturers is missing or limited to a questionnaire, without an on-site audit.
- Internal GxP audits are missing or not set up on a methodologically sound basis. The self-inspection process required under the EU GMP Guidelines exists on paper but does not deliver traceable findings.
- GxP-critical observations from past inspections are not fully remediated. Findings do not feed into a CAPA system with effectiveness checks and resurface at the follow-up inspection.
- Data integrity is underestimated in the audit. Electronic records under 21 CFR Part 11 and the ALCOA principles are not systematically checked against audit trails and access rights.
Services
How we support you
GMP audits for manufacturers & CDMOs
Assessment of the GMP status of production sites, contract manufacturers and API producers against the EU GMP Guidelines and 21 CFR Part 211. We review the QMS, batch records, validations, change management and the CAPA system. The result is an audit report with classified findings and a prioritized action list.
Learn more →GLP audits for laboratories & CROs
Audit of test facilities and CROs against the OECD GLP Principles and Directive 2004/10/EC. Review of study archives, archiving obligations, equipment qualification and qualification records. The result is an audit report to prepare for the GLP monitoring authority.
Learn more →GCP audits for clinical trials
Audit of investigator sites, CROs and sponsor systems against ICH E6 (R2) and the Clinical Trials Regulation (EU) No 536/2014. Review of informed consent, randomization, monitoring reports and the trial master file. The result is a documented audit report with finding classification.
Supplier audits & qualification programs
Structured audits of critical GxP suppliers with a supplier evaluation report, qualification program and multi-year audit plan. The result is a risk-based supplier list with re-audit intervals tailored to criticality.
Mock audits & inspection readiness
Trial audits under inspection conditions ahead of scheduled regulatory visits. Simulation of questioning, document requests and backroom logic, with a findings report and gap list to close before the inspection.
Learn more →CAPA & finding tracking
Transfer of audit findings into a CAPA system with root cause analysis and effectiveness checks. The result is a traceable CAPA list that can be demonstrated as closed at the follow-up inspection.
Learn more →How we work together
What it comes down to
GxP does not represent a single benchmark, but separate frameworks for separate activities: GMP under the EU GMP Guidelines (EudraLex Volume 4) and 21 CFR Part 211 for manufacturing, GLP under the OECD Principles for non-clinical laboratory studies, GCP under ICH E6 (R2) for clinical trials. A robust audit therefore begins with scoping: which framework applies, how critical is the area being audited, and where did the findings of the last review lie. Only this determination dictates whether the scarce audit time flows into batch records, into study archives or into the trial master file. Auditing without this prioritization means assessing breadth instead of depth and overlooking the critical finding.
The real bottleneck lies after the audit, not during it. A classified finding only delivers its value once it feeds, via a root cause analysis, into a CAPA system with an effectiveness check; without this chain, the action is formally counted as completed while the deficiency persists and is cited again at the next regulatory inspection. Likewise, the risk-based staggering of re-audit intervals determines whether supplier qualification commits capacity where criticality demands it. Finally, data integrity under 21 CFR Part 11 must be checked against actual audit trails and access rights, not against the system configuration alone, because otherwise precisely the gap that weighs heaviest at the inspection remains undetected until then.
Our approach
Our approach
Step
Result
Audit scoping & risk assessment
Defined audit scope by GxP type and criticality, agreed audit plan and agenda.
Document review (in advance)
Reviewed QMS, SOPs, prior audit and inspection reports; identified focus areas for the on-site audit.
On-site audit
Audit conducted against the applicable framework, with documented observations and findings.
Finding classification & report
Audit report with classified findings (critical / major / other) and recommendations.
CAPA support
Findings transferred into a CAPA system, with root cause analysis and actions defined with deadlines.
Effectiveness check & re-audit
Confirmed effectiveness of actions, updated qualification status and re-audit interval.
Common pitfalls
Where projects commonly fail
Findings are closed but not effectively remediated.
An action without an effectiveness check in the CAPA system is formally counted as completed, yet the underlying deficiency persists and is cited again at the next regulatory inspection.
Suppliers are qualified by questionnaire instead of by audit.
Under the EU GMP Guidelines, a completed self-declaration does not replace an on-site audit of critical API producers or contract manufacturers; the lack of audit depth becomes apparent during the inspection.
Re-audit intervals are not assigned on a risk basis.
A blanket three-year cycle for all suppliers underestimates highly critical manufacturers and over-monitors non-critical ones; what is required is a staggering by criticality.
Data integrity is treated as an IT topic only.
Audit trails, access rights and ALCOA conformity under 21 CFR Part 11 must be checked against actual records, not only against system configurations; otherwise the gap remains undetected until the inspection.
The audit is mistaken for the regulatory inspection.
A GxP audit is a voluntary or contractual review; treating it as a mere box-ticking exercise, rather than closing the findings before the official inspection by the EMA, FDA or BfArM, squanders the only lead time available.
FAQ
Frequently asked questions
Sources
- EU GMP Guidelines (EudraLex Volume 4) - primary text, incl. chapters on self-inspection and supplier evaluation
- OECD Principles of Good Laboratory Practice (ENV/MC/CHEM(98)17) and Directive 2004/10/EC
- ICH E6 (R2) Good Clinical Practice and Regulation (EU) No 536/2014
- 21 CFR Part 210/211 and 21 CFR Part 11 - primary text
- https://theentourage.de/expertise/gxp-audits/ (existing page content, revised)
Life Science Journal
Regulatory updates, straight to your inbox.
New requirements, authority decisions and practice notes. Once a month, unsubscribe any time.
Case Studies
What this looks like in practice
Related insights
All insights →Regulations & standards considered
- EU GMP Guidelines (EudraLex Volume 4)
- Directive (EU) 2017/1572 (GMP principles, supplementing Directive 2001/83/EC)
- OECD Principles of Good Laboratory Practice (OECD GLP, ENV/MC/CHEM(98)17)
- Directive 2004/10/EC (GLP principles)
- ICH E6 (R2) Good Clinical Practice
- Regulation (EU) No 536/2014 (Clinical Trials Regulation)
- 21 CFR Part 210/211 (cGMP for Finished Pharmaceuticals)
- 21 CFR Part 11 (Electronic Records, Electronic Signatures)
- ISO 13485:2016 (QM system for medical devices)
Related topics
Inspection Readiness →
Preparation for official regulatory inspections by the EMA, FDA and BfArM
Mock Audits →
Trial audits under inspection conditions ahead of scheduled regulatory visits
ISO Audits (13485 & 9001) →
Standards-based QM audits against ISO 13485:2016 and ISO 9001 as a complement
CAPA Management →
Transfer of audit findings into a traceable CAPA system
Have a concrete project?
Briefly outline your situation. We'll respond with an initial assessment, usually within one business day.
Prefer direct? +49 89 4161170-0
info@theentourage.de
- Reply usually within one working day
- 4 offices: DE · CH · IT · US
- 100% life sciences


