An FDA inspection starts with a knock, a badge, and a form. The investigator's authority to walk through your door comes from Section 704 of the Food, Drug and Cosmetic Act, and the visit almost always opens with a Form FDA 482, Notice of Inspection. What happens in the hours after that handshake is where I think most companies discover what their quality system actually is, as opposed to what they believed it was on paper.
I've come to think the inspection itself doesn't change much based on your recordkeeping. The investigator asks the same categories of questions whether you're on paper or software. What changes is how long it takes you to answer, how confident you sound when you do, and whether the record you hand over matches the story you just told out loud. That gap between story and record is where most Form 483 observations are born.
This piece walks through what FDA is actually evaluating during an inspection, why paper systems tend to create friction at exactly the wrong moment, and what genuinely changes when your records are structured and searchable from the start. I'll also be honest about what a digital system doesn't fix, because software has never been the whole answer.
What FDA Is Actually Evaluating
For device manufacturers, FDA investigators typically work from the Quality System Inspection Technique (QSIT), laid out in FDA's Guide to Inspections of Quality Systems, published in August 1999, which organizes the visit around four subsystems: corrective and preventive action, design controls, production and process controls, and management controls. CAPA is usually the door investigators walk through first, because a company's own corrective action file tends to tell them where the real problems are before they ask a single question.
Drug manufacturers get a related but distinct framework. CDER's Compliance Program Guidance Manual 7356.002, Drug Manufacturing Inspections, organizes the visit around six systems: quality, facilities and equipment, materials, production, packaging and labeling, and laboratory controls. If an investigator finds a deficiency in the quality system itself, the program directs them to expand into at least one additional system before closing out. That's worth sitting with: a weak quality system doesn't just cost you one observation, it invites a second look everywhere else.
Underneath both frameworks sits the same basic ask, repeated in different regulatory language depending on whether you're under 21 CFR Part 820 or Part 211: show me the procedure, show me the record that proves you followed it, and show me what you did when the record showed a deviation. Everything else is detail.
Where Paper Falls Apart in the Room
Paper-based systems don't fail because the paperwork is wrong. They fail because of timing. Under 21 CFR 211.180(c), records have to be retained and made available, and in practice investigators read "available" as available now, not available by end of week. When a batch record lives in a filing cabinet three buildings over, or a training file is missing a signature that has to be tracked down from someone on vacation, the delay itself becomes the story the investigator writes down. A 483 observation rarely says "the record didn't exist." It usually says the record couldn't be produced, or produced complete, when asked.
I've watched this play out the same way more than once. Someone goes to pull a batch record and finds the signature page was filed separately from the production data. Someone else goes looking for a calibration certificate and finds three versions of it, none clearly marked as the current one. None of this means the company had a quality problem. It means the company had a retrieval problem, and retrieval problems look exactly like quality problems to an investigator standing in the room with a stopwatch running in their head.
Version control compounds this. If your SOP binder has a hand-initialed change on page 12 that never made it into the master copy on the shelf, you don't have one problem, you have a data integrity question, and data integrity questions escalate faster than almost anything else in an inspection.
What Actually Changes With a Digital Record
The single biggest shift I've seen isn't speed, though speed matters. It's that the record and the story become the same document. When a quality manager describes what happened during a deviation, they can pull up the actual record on screen, timestamped, attributed to a specific person, with every subsequent action logged underneath it. There's no gap between what's said and what's shown, because the system that generated the record is the same one being queried in real time.
Electronic signatures carry this weight because of 21 CFR Part 11, in effect since August 1997, which is what allows a digital signature on a batch record to carry the same legal standing as a handwritten one. A well-built digital QMS doesn't just store a signature, it stores the full context around it: who signed, when, under what credential, and what the record looked like at that moment. That audit trail is the part paper structurally cannot produce, because paper has no memory of its own history beyond what someone chose to write down.
Search is the other piece that's easy to undersell. An investigator asking for every deviation tied to a specific supplier over the last eighteen months is a five-minute query in a structured system and can be a multi-day archive dig on paper. The company isn't smarter in the digital scenario. It's just not spending the inspection window doing archaeology instead of answering questions.
Paper vs. Digital, During the Inspection Itself
| What Happens During Inspection | Paper-Based System | Digital QMS |
|---|---|---|
| Investigator requests a specific batch record | Manual retrieval from physical files, minutes to hours | Searchable and retrievable in seconds |
| Investigator asks for all deviations linked to one supplier | Manual cross-reference across binders | Filtered query across the full record set |
| Verifying a signature's authenticity and timing | Dependent on handwriting and manual date entry | Timestamped, attributed, tied to a specific credential under 21 CFR Part 11 |
| Confirming the SOP in use matches the approved version | Requires manually checking binder against master list | Version history and current-effective status shown automatically |
| Demonstrating CAPA closure and effectiveness checks | Requires assembling documents from multiple files | Full CAPA lifecycle visible in one linked record |
| Producing training records for a specific employee | Requires locating individual paper files | Pulled instantly, tied to competency and curriculum history |
None of this changes what FDA is looking for. It changes how long it takes you to prove you have it, and in an inspection, the delay itself is data.
Data Integrity Is the Real Test
If there's one area where digital systems get evaluated more, not less, harshly, it's data integrity. FDA's December 2018 final guidance, "Data Integrity and Compliance With Drug CGMP Questions and Answers," makes clear that moving to electronic records doesn't lower the bar, it raises the specificity of what investigators check. They want to know whether your system prevents backdating, whether audit trails are actually reviewed as part of batch release rather than just generated and ignored, and whether access controls actually limit who can alter a record after the fact.
This is where a lot of companies get a false sense of security from simply digitizing. A PDF of a paper form with a typed signature is not a compliant electronic record under Part 11, it's a picture of a paper problem. The requirement isn't digital for its own sake. It's contemporaneous, attributable, legible, and durable. A system built for compliance treats the audit trail as a first-class part of the record, rather than a byproduct nobody looks at until something goes wrong. In my view, this is the single most common gap between companies that adopted software and companies that actually became audit-ready: the first group digitized the form, the second group digitized the accountability behind it.
What a Digital System Doesn't Fix
I want to be honest about the limits here, because I think overstating what software does is its own kind of risk. A digital QMS doesn't fix:
- A weak CAPA process — it just makes the weak process easier to see, faster.
- A culture where deviations get quietly closed without real root cause analysis.
- Undertrained staff.
- A company that hasn't decided what its actual procedures are before trying to configure them into a system.
What it does is remove the friction that turns a minor documentation gap into a credibility problem in front of an investigator. Readiness was never really about the software. It's about whether your quality system tells a consistent, provable story on any given day, whether someone asks about it or not. The system just determines how fast, and how completely, you can show your work. For a longer look at what "paperless" actually needs to mean to satisfy FDA expectations rather than just feel modern, I wrote about that directly in how to get to a paperless QMS without enterprise software.
The honest version of readiness is less dramatic than most vendors make it sound. It isn't a switch you flip before an inspection. It's the accumulated effect of every record being complete, attributable, and retrievable on the ordinary Tuesday nobody expected a knock on the door. If you want to see how that structure gets built rather than bolted on afterward, the Nova QMS platform overview walks through the underlying approach.
Frequently Asked Questions
Does having a digital QMS reduce the number of FDA Form 483 observations?
Not automatically. A digital system doesn't eliminate the underlying quality issues that generate observations, like inadequate CAPA effectiveness checks or gaps in process validation. What it tends to reduce are observations rooted in recordkeeping failures, incomplete records, missing signatures, unclear version control, because those specific failure modes are structurally harder to produce in a well-built system.
How much time does FDA give a company to produce records during an inspection?
The regulations don't specify an exact number of hours. The closest anchor is 21 CFR 211.180(c), which requires drug manufacturers to make records available on request; device manufacturers face the same expectation under 21 CFR Part 820 without a stated number either. In practice, what turns a slow retrieval into an observation isn't a missed deadline, it's the investigator losing confidence, mid-visit, that the record existed at all. There's no formal grace period written into either rule, which is why retrieval speed ends up mattering as much as record accuracy.
Is a scanned PDF of a paper form considered an electronic record under 21 CFR Part 11?
Generally no, if it's simply a static image of a manually completed form. Part 11 compliance depends on the system's ability to control and audit the record's full lifecycle, including who created and altered it and when. A scanned image with a typed name is not the same as a system-generated, attributable, time-stamped electronic signature tied to a specific user credential.
Do FDA investigators inspect the QMS software itself, or just the records it produces?
They can do both. If a company relies on software to generate GMP records, investigators may ask about validation of that system, including whether it was qualified for its intended use and whether access controls and audit trail functionality work as claimed. This is part of why vendor and system validation documentation matters as much as the records the system produces day to day.
What's the difference between the device inspection framework and the drug inspection framework?
Device manufacturers are typically inspected against FDA's Quality System Inspection Technique, built around four subsystems: CAPA, design controls, production and process controls, and management controls. Drug manufacturers are inspected under CDER's Compliance Program Guidance Manual 7356.002, Drug Manufacturing Inspections, built around six systems: quality, facilities and equipment, materials, production, packaging and labeling, and laboratory controls. Both frameworks start by evaluating the quality system itself before expanding into operational areas.
Last updated: 2026-08-31
Jared Clark
Founder, Nova QMS
Jared Clark is the founder of Nova QMS, building AI-powered quality management systems that make compliance accessible for organizations of all sizes.