Analysis of 47 FDA Form 483 observations and warning letters for infrared spectrometers reveals a spectrum of data integrity problems and a lack of laboratory procedures for the technique. Is this your laboratory?
Since the Able Laboratories data falsification case in 2005 (1), there has been a regulatory focus on the lack of data integrity with chromatography data systems. This scrutiny has focused on inappropriate access privileges with conflicts of interest, deletion of data files, failure to configure the application, testing into compliance, and failure to review audit trail entries (2). More recently, inspection focus has moved to the use of peak integration to integrate into compliance and masking potential impurities (3). There have been many warning letters as a result of these noncompliances and poor data management practices; this is due to chromatography being a major technique that can comprise between 40–70% of a laboratory's workload. You may ask, "Why the focus on chromatography in a publication on spectroscopy?" Just think of chromatography as sample preparation for spectroscopy!
In contrast, there are relatively few FDA warning letters involving spectroscopic techniques. An analysis of FDA warning letters citing infrared spectrometers was published in 2014 (4).
Originally, we were going to write a column looking at some of the data integrity issues that could occur with Fourier transform infrared spectroscopy (FT-IR) analysis, with a few regulatory citations to illustrate each point. However, given the bonanza of Form 483 observations and warning letters that have been issued by the FDA, we realized that an analysis of these would provide a great overview of the current regulatory problems facing the technique, before discussing specific topics in the future.
In this column, we present an analysis of 47 Form 483 observations and warning letters issued between 2012 and 2018 (5–51). It should be noted that many of these Form 483 observations are not generally available publicly. Therefore, these observations, the regulatory focus on infrared, and the conclusions we have drawn may be new to laboratories that only review FDA warning letters. We have taken each citation or observation and broken it down into one or more data integrity areas; therefore, a single observation can have one or more data integrity noncompliances. For example:
Therefore, there is not a one-to-one correlation between all non-compliances analyzed and the data classification presented here.
The noncompliances have resulted in a total of 104 separate citations for IR analysis that have been classified and discussed below. Some of these are self-explanatory, and will not be discussed in part due to space considerations and because the solution is obvious (such as no software validation, for example). In the references, we have included the FDA Facility Establishment Identifier (FEI), which is the way the FDA identifies a specific site in a company. Where there are different FEI numbers for the same organization, this means that two sites or facilities were inspected.
Our main challenge in this analysis is to interpret a regulatory citation, because we don't know all the circumstances at the time of the observation by an inspector. For example, we don't know the functionality of the application software, so the observation of no system audit trails available as shown above could be a true software design limitation, or, more likely, it could be that the users did not enable this function. We have used our experience and best judgement in classifying each citation in this analysis.
We do not claim that this noncompliance review reflects the total number of 483 observations issued, but, based on the significant number, it is reasonably comprehensive to draw firm conclusions on regulatory gaps involving IR analysis. Enjoy reading about the calamities of others. If any noncompliance mentioned here applies to your laboratory, what are you going to do? We suggest that you remediate the problem before you are included in a future update of this article!
One of the surprises of our analysis is that 42% of the 483 citations occur before the instrument and the associated software application are supposed to become operational. You may doubt this statement, but look at both Table I and Figure 1 and you will see two main areas: inadequate software architecture, and design and failure to qualify, calibrate, or validate the system. The interpretation of these nonconformance data is based on the wording of the 483 observations.
The biggest area, at 37% of the total noncompliances, appears to be due to inadequate architecture and design of the application software that has been purchased by the regulated laboratories. The main problems with the application software are that, as implemented, there are inadequate controls for ensuring data integrity, no audit trail, and the architecture where data files are stored in directories within the operating system and users can delete data without any record in the data system. Again, this is based on the wording inspectors included in each Form 483 report, which represents a high level conclusive summary of the inspection findings, and not a detailed analysis of the root cause associated with each observation. In particular, this represents the inspector's interpretation of what was found about how software was implemented, and not the full compliance capabilities of each software package. In line with FDA warning letters, in many instances, the manufacturer and name of the software was included in many of the examples we reviewed, but we have redacted these in this column.
Figure 1: Infrared spectroscopy Form 483 citations occurring before operational use of the instrument and software.
Some of the citations for poor software design are:
The use of directories in the operating system for data storage where a user can delete spectral files without any record in the application software (assuming there is a function capable of this) gave rise to 17 citations out of 104, or 16%.
The first problem is that regulated laboratories are purchasing IR application software that appears not to have any or inadequate data integrity controls. For example, all data should be saved, and there must be an audit trail built into the system which, once implemented, cannot be turned off. However, suppliers are market driven, and if users don't ask for these features, or help into how to implement them, then they won't be delivered. The responsibility of the supplier to help customers implement a compliant solution is becoming increasingly important. There is also the overall market that a supplier is developing its software for both regulated and unregulated industry sectors. What should occur is that suppliers should be selling configurable software, and also providing assistance in the form of white papers informing users how to configure the software or providing professional services to help implement compliant solutions. The second issue is the overall architecture of the system: Almost all IR software is designed for standalone operation, or can be implemented as a standalone system. Many standalone systems involve files storage in directories in an operating system, and not a database. If the software is designed to support networked implementation, using database storage on a secure network server, this should be implemented. This would remove many of the limitations of standalone systems, such as backup, as this would be performed by the IT department.
Part of the problem is that many software applications require a range of expertise to implement compliant solutions, so that an expert in the analytical technique, someone with a detailed understanding of the software capabilities and strong IT and Part 11 knowledge, is required. From the number of Form 483 observations, it is clear that this multidisciplinary collaboration has not occurred.
The second area for noncompliance before operational use of the instrument (6%) is due to failure to qualify or calibrate the instrument or validate the software. This is a fairly straightforward area, and we were not going to discuss this, with the exception of two citations about the performance qualification of an IR instrument, one of which is:
No Performance Qualification (PQ) is required before use to ensure the performance of the <redacted> FT-IR; only the . . . operation qualification is performed. In addition, the SOP # <redacted> does not require such a test.
United States Pharmacopoeia (USP) general chapter <1058> on Analytical Instrument Qualification (AIQ) was recently updated (52), and contains new requirements compared with the 2008 version. The key issues are that:
The difference between an instrument OQ and PQ is typically the area of greatest discussion when considering analytical instrument qualification. It is important to first understand that, because an OQ and PQ test different attributes of instrument performance, both are required.
Uniquely for FT-IR, the subject of calibration also needs to be considered because of confusion that can arise around interpretation of this word. First, in simple terms, the instrument performance attributes that are associated with an OQ and PQ are:
The reader must consider what these terms mean for an FT-IR instrument, and be able to defend this interpretation during regulatory inspections.
For an FT-IR instrument, apart from replacing the internal desiccant that removes water vapor from sealed instrument enclosure, there are typically no user serviceable components. Therefore, it would be more appropriate to label regular testing of instrument as performance verification checks for wavelength accuracy, resolution, and signal-to-noise, rather than calibration. However, for an FDA inspector, calibration is most likely to be the name used for instrument performance checks, because this is specified in the Good Manufacturing Practice regulations in 21 CFR 211.160(b)(4) (53).
Tests performed on analytical instruments during qualification typically fall under the following categories:
We will return to this topic in a later "Focus on Quality" column, where we will address OQ and PQ requirements for FT-IR in more detail.
The main citations for IR systems found by FDA inspectors during the operational phase are listed in Table II, and shown diagrammatically in Figure 2. In general, these citations mirror those found with chromatography data systems (CDS) such as:
Figure 2: Infrared spectroscopy Form 483 observations as found by FDA inspectors during operational work.
In addition, there are the following gems of noncompliance:
Some of the factors that contributed to the observations reported in this article are:
Historically, the IT departments in many companies had a policy that made it harder for laboratories to attach instrument control computers to the corporate network. In principle, this was to protect the network, but the outcome can be proliferation of standalone systems, irrespective of the system capability. A busy laboratory can follow the path of least resistance, and implement standalone systems with the consequential impact of poor data backup and access control, for example. Some of the principal reasons for originally writing this article was the data integrity risks of identification by FT-IR spectroscopy; in particular, because there is a skill associated with the manual task of sample preparation, it will always be a higher risk from a data integrity perspective. How are decisions made about the quality of the sample preparation recorded and differentiated from identification failure?
Analysts in busy laboratories have tended to move away from specialist skills (in IR spectroscopy, for example), toward being more generalists. This trend contributes to some of the citations in this article, such as inappropriate and unscientific use of the technique. The difference between an IR spectroscopist and a part-time user was well documented over 20 years ago (57).
Another contributory factor, which is compounded by the deskilling of analysts, is the lack of harmonization of the pharmacopeia general chapters on identification by IR spectroscopy.
Where there is a lack of harmonization, the simplest route can be to ignore specific pharmacopeia requirements.
The fundamental challenge for identification by infrared (either IR or FT-IR spectroscopy) is the decision about how the comparison should be made. If spectra are compared by algorithms, the library and the limits used need to be validated. Ironically, if the decision is based on manual comparison of sample and reference spectra, this can be best accomplished using large printed spectra, with the investment focus on analyst training compared to library and algorithm validation. Although there are some other citations, as seen in Table II, we have chosen not to discuss them as they are single observations and may not be indicative of a trend.
In this column, we have taken 104 regulatory noncompliances for infrared analysis issued by the FDA and analyzed them for trends. Interestingly, 42% of noncompliances can occur before an instrument is operational, due to the purchase of poor software functions, or failure to validate, qualify, or calibrate the system. Noncompliances when an instrument is operational vary widely, but mirror those found with CDS, such as inadequate access control, data falsification, lack of complete data, inadequate backup, and no audit trail review.
Based on this review and the non-conformance findings in the Form 483 observations, it is apparent that identification by FT-IR spectroscopy is an area of focus during laboratory audits, and that it is a high-risk area with poor implementation of compliant solutions. As an example of this regulatory focus, Yunnan Hande received an FDA warning letter in 2015. The Form 483 observations include a range of data integrity observations, but the warning letter only focuses on identification by infrared (58).
