Most GDP-regulated organisations do not lack procedures. They have procedures for supplier approval, temperature control, deviations, returns, recalls, training and outsourced activities. The harder question is whether those procedures operate as a connected control system—and whether the organisation can demonstrate that clearly when challenged.
This is where inspection readiness often becomes difficult. The evidence may exist, but it sits across spreadsheets, emails, meeting minutes, quality records, warehouse systems and supplier files. The Responsible Person may have provided oversight, but the evidence of that oversight is fragmented. Decisions may have been made correctly, but the rationale and follow-up are not easy to retrieve.
The regulatory expectation goes beyond having procedures
The EU GDP Guidelines require a documented quality system that sets out responsibilities, processes and risk-management principles. Distribution activities should be clearly defined and systematically reviewed, and the effectiveness of the quality system should be monitored.
The Guidelines also give the Responsible Person clearly defined authority and responsibility. The RP may delegate duties, but not responsibility, and should perform the role in a way that enables the wholesale distributor to demonstrate GDP compliance. The listed responsibilities cover the quality system, records, supplier and customer approval, outsourced activities, self-inspection, recalls and product-disposition decisions.
For the Responsible Person (import), MHRA guidance is similarly evidence-led. The RPi must implement a system confirming that the required QP certification—and, where applicable, independent batch-release certification—has taken place. Checking activity may be delegated, but the RPi remains responsible for assuring that the system and delegated checks are effective.
In practical terms, the expectation is not simply that a procedure exists. The organisation needs a reproducible record showing that the control was performed, exceptions were identified, decisions were made by the right people and weaknesses were followed through.
Why evidence becomes disconnected
The gap usually develops gradually. Operational teams complete their individual tasks, while the control story across those tasks remains implicit.
- Supplier approval is documented, but ongoing performance and emerging risk are reviewed elsewhere.
- Temperature excursions are investigated individually, but repeat patterns are not made visible to the RP.
- RP-I certification checks are completed, but exceptions, delegated activity and effectiveness monitoring are held in separate records.
- CAPAs are marked complete, but the evidence demonstrating sustained effectiveness is weak.
- Management review lists activity, but does not show the decisions, ownership or escalation arising from the data.
None of these necessarily means the underlying work was poor. The problem is that the organisation cannot easily demonstrate how evidence moved through assessment, judgement and follow-up.
A practical evidence chain
A more dependable approach is to structure material GDP activity around five connected elements:
Define the regulatory expectation, control requirement, event, trend or oversight question that requires attention.
Identify the records, data, observations and source information used to understand the position. Record gaps and uncertainty rather than filling them with assumptions.
Show who assessed the evidence, what conclusion was reached and why the decision was proportionate to the risk.
Translate the judgement into containment, correction, CAPA, escalation or monitoring with clear accountability and target dates.
Confirm whether the action achieved the intended result and ensure material outcomes remain visible through oversight and management review.
This chain does not replace the organisation’s QMS records. It provides a consistent way to connect them. The controlled evidence remains in the organisation’s authorised systems; the operating model makes the relationship between those records clearer.
What an inspector may test
The MHRA explains that GDP inspections involve interviews, document review and site visits across activities including stock control, storage, temperature monitoring, returns, purchasing, sales and transportation. That means the organisation must be able to explain both the designed process and the way it operated in real cases.
A useful readiness test is to select a recent material example and ask:
- What requirement or risk triggered attention?
- What evidence was reviewed, and where is it controlled?
- Who made the decision, and was their authority clear?
- What action followed, who owned it and how was it escalated?
- How was effectiveness assessed?
- Where was the outcome made visible to the RP, RPi or senior management?
If those questions require several people to reconstruct the story from memory, the organisation may be operationally compliant but not yet inspection-ready.
Start with the areas that create the most exposure
Do not try to reorganise every GDP record at once. Begin with the activities where fragmented evidence creates the greatest risk or the most difficult inspection explanation: supplier and 3PL oversight, RP delegation and cover, import certification assurance, temperature events, significant deviations, CAPA effectiveness, recall readiness and management review.
For each area, define the expected evidence set, decision ownership, escalation threshold, review frequency and effectiveness measure. Then test the model using a recent real example. This turns inspection preparation into a check of the operating system rather than a last-minute search for documents.
Put the approach into practice
Use the GDP Maturity Index™ to identify where oversight and evidence are weakest. Then use the Inspection Pack to connect the relevant records, ownership, open risks and inspection narrative.
Primary references
Use boundary: This article provides practical implementation thinking, not legal advice or a determination of compliance. Confirm the current requirements applicable to your licence, products, territories and activities. Decisions and controlled records remain within your organisation’s authorised quality system.
RegOpsPro™