In the pharmaceutical industry, some of the most important regulatory expectations are not always found in the main body of a guidance document. Occasionally, a seemingly modest footnote carries significant implications for the future of compliance. One such example appears in the MHRA GxP Data Integrity Guidance and Definitions (March 2018), which states:
“It is expected that GMP facilities with industrial automation and control equipment/systems such as programmable logic controllers should be able to demonstrate working towards system upgrades with individual login and audit trails (reference: Art 23 of Directive 2001/83/EC).”
At first glance, this statement may appear to be a UK-specific expectation applicable only to MHRA-regulated facilities. However, a closer reading of the guidance suggests much broader significance.
The MHRA explicitly states that the document was developed as a companion to international guidance and was harmonized, where possible, with publications from PIC/S, WHO, OECD, and EMA. Furthermore, the agency describes the document as setting out the “minimum expectation to achieve compliance” regarding data integrity. This means the footnote should not be viewed as an isolated national preference but rather as an expression of a broader global regulatory trend toward accountability, traceability, and attributable electronic records.
This creates a practical regulatory taxonomy:
- Article 23: Maintain state of scientific and technical progress
- EU GMP Annex 11: Define expectations for computerized systems
- Data Integrity Guidance: Provide clarity on regulatory current thinking on systems in place and in use.
The expectation aligns directly with one of the foundational principles of data integrity in that data must be attributable to the individual who performed the action. The MHRA guidance repeatedly emphasizes that organizations should be able to associate data and data changes with specific individuals, and that shared or generic user accounts should not be used for systems generating, modifying, or storing GxP data. Without individual user accounts, it becomes difficult to demonstrate who performed a specific action, modification, override, or alarm acknowledgement.
Likewise, audit trails are described as a critical form of metadata that records the “who, what, when, and why” of changes made to records. The guidance states that computerized systems should provide retained audit trails showing all changes to, or deletion of data while preserving the original record. Audit trails should be enabled, protected from unauthorized alteration, and available for review as justified by a risk assessment.
Many legacy industrial automation systems, including older PLCs, HMIs, SCADA platforms, and stand-alone control equipment, were originally designed for operational reliability rather than modern data integrity requirements. These systems often rely on shared passwords, generic operator accounts, alarms, or limited event logging capabilities. While such architectures may have been acceptable when installed, the regulatory environment in which they are operated in has evolved considerably. The MHRA acknowledges that legacy systems may not immediately possess audit trail functionality; however, it also states that organizations should demonstrate progress toward remediation through upgrades, compliant replacement systems, or add-on solutions. Failure to identify or implement remediation in a timely manner may result in regulatory deficiencies.
Importantly, this expectation is consistent with international GMP principles such as EU GMP Annex 11, PIC/S and WHO data integrity guidances. The MHRA footnote therefore reflects a broader regulatory consensus rather than a uniquely British requirement.
For pharmaceutical manufacturers, the key message is clear: legacy status is not a long-term justification for non-compliance. Regulators increasingly expect firms to have documented roadmaps demonstrating how industrial automation systems will evolve toward contemporary data integrity expectations. Even when immediate replacement is not feasible, organizations should perform risk assessments, implement interim procedural controls, and establish strategic upgrade plans that move systems toward individual user authentication and secure audit trails. Risk assessments should acknowledge the gaps and identify system upgrades and replacements as eventual actions – to be implemented in a reasonable timeframe and a documented rate of capital investment.
In Summary:
The MHRA footnote is best viewed as a regulatory signal of global expectation rather than a uniquely UK requirement. The UK may have left the EU, but the expectation lives globally. Not capable, does not mean exempt. Contact Lachman for practical advice and solutions at LCS@LachmanConsultants.com, and most importantly, always read footnotes, they are an integral part of any document.

