Test Result Documentation in Regulated Labs: From Raw Data to CoA

A test result in a regulated lab is not the number on the CoA. It is the chain from sample identity through raw data, calculations, review, and the certificate or batch record entry that quality uses to release. 21 CFR 211.194 requires laboratory records to include complete data derived from all tests necessary to assure compliance with established specifications.
If an investigator can reconstruct the result from the file without interviewing the analyst, the documentation is doing its job.
What 211.194 is asking for
Laboratory records should include, as applicable:
- A description of the sample received, source, quantity, lot or batch, date, and the test performed
- A statement of the method used
- A statement of the weight or measure of sample used
- Complete data: graphs, charts, spectra, and other recordings from instruments
- Calculations and comparison to specifications
- The initials or signature of the person who performed the test and the date
- The initials or signature of a second person showing that the original records were reviewed for accuracy, completeness, and compliance with standards
Device labs working under QMSR / ISO 13485 follow the same completeness idea even when the citation number differs: you cannot defend a result you cannot reconstruct.
Raw data versus reported result
Raw data are the first-capture records: chromatograms, weigh-boat printouts, plate reader files, instrument audit trails, original notebooks. Derived data are calculations, averages, and rounded values. The CoA is a summary for the customer or the batch record. Rounding on the CoA must follow a written rule. Do not re-integrate a peak to make 99.4 become 99.5 after you saw the spec.
If you discard an injection, the file must show it happened and why (SST failure, obvious sample prep error under a predefined rule). Silent deletes are data-integrity failures, not housekeeping.
Path from bench to CoA
- Sample accountability. Unique ID, chain of custody, storage condition.
- Method and version. The SOP that was actually used, not "HPLC assay."
- System suitability. Passed before samples are reported.
- Sequence / run. Standards, samples, blanks, bracketing as required.
- Processing. Integration parameters locked or justified.
- Calculation. Spreadsheet or LIMS validated for that use; formula visible.
- Comparison to specification. Including units and any rounding.
- Analyst sign-off. Date contemporaneous with the work.
- Second-person review. Against raw data, not only the typed summary.
- CoA / LIMS release field. Same value, same units, same spec.
A CoA generated while step 9 is still open is a release risk.
Electronic systems
Part 11 audit trails apply when the record is electronic. Review of processing method changes belongs with the result, not in an IT ticket six weeks later. Printed chromatograms that omit the processing method and audit-trail excerpt are incomplete if the electronic original can still be changed.
OOS and retests
FDA's OOS guidance expects the original result to remain in the record even if a retest is justified. Averaging a failing result with passing retests to "pass the lot" is a classic citation. Document Phase I laboratory checks before you reach for a new aliquot.
Certificates of analysis from suppliers
If you accept a supplier CoA in lieu of full testing, 21 CFR 211.84 still expects appropriate validation of the supplier's results at intervals, plus at least an identity test in many drug cases. File the CoA, the identity result, and the qualification rationale together.
What auditors pull first
The CoA for a released lot, the specification, the raw chromatogram or plate, the calculation, the second-person signature, and any OOS or invalidation memo. Gaps between those six items are where warning letters start.
Systems
A validated quality and compliance platform can keep LIMS results, review tasks, and CoA generation on one record if analysts still cannot overwrite history.
Sources
21 CFR 211.194 Laboratory records. 21 CFR Part 211. FDA CGMP Q&A on records and reports: FDA records and reports Q&A. Example of incomplete laboratory records: FDA warning letter citing 211.194(a).
Units, significant figures, and LIMS maps
If the spec is 98.0-102.0% and LIMS stores 99.96, the CoA rounding rule must be written. Mapping errors (mg/mL reported as %) create false OOS events. Validate the LIMS calculation the same way you validate a spreadsheet.
Microbiology and plate counts
Complete data include plate IDs, dilutions, incubator, times in and out, and colony counts before any averaging rule. Photographs of plates help when counts are disputed. TNTC still needs the dilution that got you there.
Contract labs
The quality agreement should require complete data packages, not only a CoA. Your second-person review may be of the package, but you still need the raw files on request. If the contract lab invalidates a run, you should see that invalidation.
Retention
Keep laboratory records for the batch-record retention period, which for many drugs is at least one year after expiry. Electronic files need a readable format for that entire time.
Training signal
If new analysts generate most documentation deviations, the issue is the SOP and the buddy review, not human error as a permanent root cause.
About Cloudtheapp
Cloudtheapp is an AI-Powered Configurable Validated Cloud Platform built to provide the most configurable, easy-to-use Quality Management and Regulatory Compliance SaaS software on the market.
We believe that having a single platform to manage compliance and transformation needs is essential for businesses in the modern world. We've created an innovative configurable cloud platform built for the compliance world so you can easily implement ready-made applications with no additional installs or infrastructure required – and without writing a single line of code!
Our experienced professionals have over three decades of software development experience between them, giving us unparalleled insight into how to build powerful solutions to address real challenges.
We have created an interconnected ecosystem where everyone involved in this process can collaborate successfully while minimizing disruption of any sort as well as ensuring entire organization's data remains visible always for better use making sure businesses always stay compliant.
We excelled in creating the most configurable, easy-to-use Quality Management and Regulatory Compliance SaaS software that requires light administration, so your staff has time to focus on streamlining their compliance process, innovate faster and minimize risk associated with non-compliance.
We will continue to strive towards engineering smarter tools for administrative staff so they can focus on building safe and quality products.
With years of experience in the industry, we are committed to providing our customers with reliable and secure solutions enabling them to be agile and move ahead confidently.