{domain:"www.qualitydigest.com",server:"169.47.211.87"} Skip to main content

        
User account menu
Main navigation
  • Topics
    • Customer Care
    • Regulated Industries
    • Research & Tech
    • Quality Improvement Tools
    • People Management
    • Metrology
    • Manufacturing
    • Roadshow
    • QMS & Standards
    • Statistical Methods
    • Resource Management
  • Videos/Webinars
    • All videos
    • Product Demos
    • Webinars
  • Advertise
    • Advertise
    • Submit B2B Press Release
    • Write for us
  • Metrology Hub
  • Training
  • Subscribe
  • Log in
Mobile Menu
  • Home
  • Topics
    • Customer Care
    • Regulated Industries
    • Research & Tech
    • Quality Improvement Tools
    • People Management
    • Metrology
    • Manufacturing
    • Roadshow
    • QMS & Standards
    • Statistical Methods
    • Supply Chain
    • Resource Management
  • Login / Subscribe
  • More...
    • All Features
    • All News
    • All Videos
    • Contact
    • Training

What FDA Warning Letters Reveal About Records, Spreadsheets, and AI

A spreadsheet, a site visit, and two garbage bags

Ardinnnn :)/Flickr

Kendall Kunz

Appenate

Wed, 09/30/2026 - 12:03
  • Comment
  • RSS

Social Sharing block

  • Print
Body

On March 3, 2026, the U.S. Food and Drug Administration (FDA) issued a warning letter to Tentamus India Private Limited. The inspection it describes started the way most do, with one difference. At the initiation of the inspection, the agency’s investigator observed the firm attempting to remove two large garbage bags from the site. The bags were later determined to contain analytical documents, torn up. Among them were impurity method validation spreadsheets, on paper. The firm’s own procedure called for those originals to be retained.

ADVERTISEMENT

That letter is worth reading in full, and so are the four others like it from the same quarter. Between February and the end of March 2026, the FDA issued five warning letters involving falsified or destroyed records:
• A. Nelson & Co. Ltd. (Feb. 12)—CGMP records improperly discarded, including an out-of-trend result recorded on a sticky note.
• Tentamus India (March 3)—the aforementioned garbage bags.
• Patcos Cosmetics (March 12)—deliberate alteration of original data to conceal out-of-specification results, cited under 21 CFR 211.194.
• Xiamen Kang Zhongyuan Biotechnology (March 23)—the firm’s chief quality officer admitted to providing false documents related to finished product testing. A logbook requested on Aug. 13 was produced on Aug. 15 carrying information that had not been on it two days earlier.
• Intas Pharmaceuticals (March 30)—electronic batch record changes made through the software vendor and never captured in the audit trail, an employee ID swapped in a “Dispensed by” field, and an initial out-of-specification result treated as discarded and left out of final reporting.

A sixth, to Microbiological Testing & Consulting on March 16, carries a full data integrity remediation section after the contract lab told the FDA it had conducted only one out-of-specification and one out-of-limit investigation in two years, while records from one of its own clients showed it had reported several out-of-limit results in the same period.

Five letters in seven weeks is a cluster, and it would be easy to oversell one. What the letters have in common is more useful than the count: In each one, the record that would have settled the question either never existed or could be changed by the person it implicated.

What a review of FDA warning letters says about documentation

QBench, an LIMS vendor, analyzed every warning letter the FDA issued in 2025 and published the results as “Inside 470 FDA Warning Letters From 2025”. It built the analysis by writing a program that automatically pulled data from the FDA’s public list of warning letters, then used pattern-matching software to scan the text and pick out relevant findings, with a person checking the results by hand afterward.

QBench admits this kind of automated text-scanning isn’t perfect. Of the 470 letters issued between Jan. 2 and Dec. 30, 99% contained citations related to documentation, records, or written procedures. Of the full 470, 148 went to regulated labs in pharma, biotech, research, and medical devices.

That 99% is not a falsification rate. Only 14 of the 470 letters cited data integrity violations specifically, and the recurring lab findings underneath the number are ordinary rather than dramatic: failure to investigate out-of-specification results (34%), inadequate procedures (29%), and validation gaps (27%).

Documentation shows up in nearly every letter because documentation is how a firm demonstrates anything at all. The falsification cases are the tail of that distribution, and the tail is where the records were weakest to begin with.

Why an SOP alone isn’t a control

A written instruction that says “do not delete rows” feels like governance. But in a spreadsheet where any authorized analyst can modify or delete a value, it governs nothing an investigator can verify afterward. The Patcos letter describes deliberate alteration of original data to conceal out-of-specification (OOS) results. The Intas letter describes changes to an electronic batch record, made through the software vendor, that the audit trail never captured; in the FDA’s words, the firm “lacks controls to assure the integrity of electronic batch record data.” In both, the citation lands on the firm’s control over the record.

21 CFR Part 11 has been on the books since March 20, 1997, though how it’s enforced surprises people. Since the FDA’s 2003 Scope and Application guidance, the agency exercises enforcement discretion over much of Part 11 (validation, audit trails, record retention, record copying) and pursues those expectations through the predicate CGMP rules instead, mainly 21 CFR 211.68 and 211.194. An investigator is less likely to cite Part 11 by number than to cite a failure to investigate an OOS result you can no longer reconstruct.

Uncontrolled paper is the problem; paper itself isn’t. A bound, paginated, signed notebook is a defensible record, and the FDA’s own data integrity guidance treats it as one. A procedural control paired with a technical one is fine, too. What keeps turning up in the letters is a record the person it implicated could alter or discard. In an electronic system, that failure mode is the procedural control standing alone—an SOP as the only thing between an analyst and a value they can change without trace.

AI in documentation: The Purolea Cosmetics Lab letter and a new risk vector

On April 2, 2026, the FDA issued warning letter 320-26-58 to Purolea Cosmetics Lab of Livonia, Michigan. It carries a section heading that doesn’t appear in earlier letters: “Inappropriate Use of Artificial Intelligence in Pharmaceutical Manufacturing.” It’s widely reported as the first FDA warning letter to name AI use as a violation.

The firm used AI agents to create drug product specifications, procedures, and master production and control records, then put those documents into use. The FDA’s language is direct: “You must review the AI-generated documents.... Your failure to do so is a violation of 21 CFR 211.22(c).” That section is the quality unit’s duty to review and approve procedures affecting product quality.

One exchange in that letter is worth quoting exactly. Investigators noted the firm hadn’t performed process validation before distributing product. The letter records the response: “You replied that you were not aware of the legal requirement, as the AI agent you used (b)(4) never told you it was required.”

The FDA’s next sentence acknowledges that the firm has ceased drug production. The letter never engages the reasoning.

One letter to one firm is a thin basis for generalizing. The FDA’s only general guidance on AI in this space is a January 2025 draft aimed at regulatory decision-making, with different scope. What the Purolea letter establishes is narrower and still useful: AI-generated documents entering the quality system are documents the quality unit is required to review, and 211.22(c) is the hook.

The parallel to the spreadsheet problem is close. An unvalidated spreadsheet leaves a gap between what the data say and what happened. An unreviewed AI-generated procedure leaves a gap between what the document claims and what a qualified person would have confirmed. Both are documentation failures with an existing regulation attached.

What the 7356.002F revision changed

Separately, the FDA revised compliance program 7356.002F—“Active Pharmaceutical Ingredient Process Inspection,” on Aug. 1, 2025, with implementation from Sept. 2. The program itself isn’t new. It has governed routine API CGMP inspections since 2006. The revision brings in elements of ICH Q9(R1) quality risk management, Q10, and Q12, along with control of hazardous impurities, which the document’s own footnotes frame around nitrosamines and mutagenic impurities.

It sharpens what investigators are told to look at during routine API inspections. It doesn’t create a new inspection type or mandate more of them. If your API-side documentation is already thin, a revised program that directs more attention to risk management and impurity control isn’t the moment you want to find out.

Five steps to documentation defensibility

Map your spreadsheet exposure. List every spreadsheet that records, calculates, or reports quality-critical data. Flag the ones that allow unrestricted editing, have no version control, or are the only record of a result.

Ask whether each control is procedural or technical. For every critical workflow: Does the system prevent the change, or does an SOP ask people not to make it? Where the answer is “SOP only” and the record is electronic, add the technical control or move the workflow to a system that enforces the field instead of asking people to. Structured capture tools, Appenate among them, apply the constraint at the entry point through required fields and controlled option lists.

Treat AI output as a draft. If AI tools help draft SOPs, specifications, or certificate-of-analysis language, put a documented human review between the tool and the quality system. The Purolea letter is the citation to hand your quality unit.

Look at what you discard. Three of the Q1 letters turn on data that were set aside: an OOS treated as discarded, originals binned against the firm’s own procedure, an out-of-trend result on a discarded sticky note. Discarded data are still data, and an investigator will ask where they went.

Reconstruct one data point end to end. Pick a result. Ask a colleague to retrieve its complete history (entry, corrections, approval) using only what your system produces. If they can’t assemble that chain, you’ve found your gap before the FDA did.

Many of these data still start on a clipboard: environmental monitoring rounds, equipment checks, sampling logs, line clearances. The gap opens before any of them reach a validated system, because transcription is where records quietly become approximations. Appenate closes that step by capturing the reading where it’s taken, with defined fields and required values, so the record enters the system once instead of being rekeyed from a sheet of paper hours later. Validating that record for your own process is still work you own, and it’s work that starts from a better position.

None of the firms in these letters set out to build an indefensible record system. They inherited one, a workbook and a logbook at a time, and it held up until the day someone asked to see the version that existed on a Wednesday in August.

Top Stories
AI May Be Making Your Quality Problem Worse
What I Discovered About Quality Concepts by Watching My Newborn Granddaughter
Your AI Model Is Drifting Right Now. Would You Know?
AI Layoffs Need Evidence, Not Executive Storytelling
The Art of Forecasting: Part 1

Add new comment

The content of this field is kept private and will not be shown publicly.
About text formats

© 2026 Quality Digest. Copyright on content held by Quality Digest or by individual authors. Contact Quality Digest for reprint information.
“Quality Digest" is a trademark owned by Quality Circle Institute Inc.

footer
  • Home
  • Print QD: 1995-2008
  • Print QD: 2008-2009
  • Videos
  • Privacy Policy
  • Write for us
footer second menu
  • Subscribe to Quality Digest
  • About Us
  • Contact Us