Pharmaceutical manufacturing documentation requirements do not change dramatically year to year, but they do evolve, and 2025 brought several guidance updates relevant to how quality teams structure and maintain their records. None of these are sudden reversals of established requirements. Most are clarifications of existing principles applied to evolving documentation practices, particularly around hybrid paper-electronic systems, data integrity expectations, and the use of technology in documentation workflows.
What follows is a summary of the most operationally relevant updates, focused on what quality teams need to address. This is not a comprehensive regulatory survey; it is a working overview for people making practical decisions about their documentation systems.
Data integrity guidance: the ALCOA+ framework applied more specifically
FDA and EMA have both continued to develop their positions on data integrity, building on the foundational principles of ALCOA (Attributable, Legible, Contemporaneous, Original, Accurate) and the additional ALCOA+ elements (Complete, Consistent, Enduring, Available). The 2025 updates from both agencies have moved toward more specific expectations around how manufacturers demonstrate that data was recorded at the time of the event (contemporaneous) and by the person performing the action (attributable) in electronic systems.
The specific area that received the most attention in 2025 is the audit trail for electronic data capture systems: not just that an audit trail exists, but that it is reviewed on a defined schedule, that reviews are documented, and that findings from audit trail review feed back into the deviation and CAPA process. FDA 483 observations from 2024 and early 2025 show a pattern of citing audit trail review gaps even in facilities that have technically compliant audit trail functionality. The message is that generating the audit trail is necessary but not sufficient; demonstrating that it is actively used as a control is required.
Hybrid system clarity
A significant proportion of pharmaceutical manufacturing operations still operate hybrid documentation systems: some records paper, some electronic, with various forms of cross-referencing between them. The 2025 guidance updates from both FDA and EMA provide more explicit direction on what hybrid means from a regulatory perspective, and where the boundaries of Part 11 or Annex 11 scope sit in hybrid environments.
The clarification that has the most practical impact is on the question of true copies. When a paper record is scanned and the electronic scan is used as the basis for release decisions, the scan is within scope for data integrity requirements. Specifically, the metadata associated with the scan, the system that stores it, and the access controls on it must meet the same requirements as an electronic record used in its own right. This is not a new requirement, but the 2025 guidance makes explicit that it cannot be escaped by treating scans as "supporting documentation" rather than "electronic records."
For quality teams operating hybrid systems, this means the data integrity framework needs to extend all the way to the document management system that stores scanned records, including audit trail review for that system. If the document management system is a generic DMS not designed for GMP use, an assessment of whether it meets the applicable requirements is warranted.
Risk-based approaches to documentation control
Both FDA and EMA have signaled a continued preference for risk-based approaches to documentation control, particularly in the context of which records require what level of control. The ICH Q10 pharmaceutical quality system framework, which provides the overarching structure for quality systems in major regulated markets, has been read alongside the 2025 updates to identify where risk classification of documentation should inform control requirements.
The practical implication is that quality teams should be able to articulate why their documentation controls are calibrated the way they are: why a batch record gets one level of review, why a logbook entry gets another, why a cleaning record is controlled differently than a deviation record. If the documentation control system is one-size-fits-all (every record gets the same review, signature, and retention treatment regardless of its regulatory significance), that is not inherently wrong, but it may represent a resource misallocation that a risk-based review could optimize.
We are not saying the risk-based approach is a cost-cutting mechanism. We are saying that a documented risk classification of your documentation types, with control levels mapped to regulatory significance and data integrity risk, makes the system more defensible at inspection than a uniform approach that does not acknowledge the difference between a batch release record and a cafeteria maintenance log.
Electronic master batch records and version control
Version control for master batch records in electronic systems received updated guidance attention in 2025, particularly around the requirement that the batch record used to manufacture a specific batch is traceable to a specific version of the master, and that the version in use at the time of manufacture is retrievable, unaltered, for the full retention period.
This is straightforward in concept but technically demanding to implement correctly. When a master batch record is revised, the manufacturing operations system needs to link the new version to future batches and preserve exact copies of previous versions that were used for batches already in process or completed. Changes to the MBR during a manufacturing campaign for a batch that has not yet been released are a specific area of concern: if the MBR version changed after manufacturing started, the released batch needs to show which version governed which operations.
Quality teams implementing or upgrading EBR systems should verify explicitly how the system handles MBR version control during active campaigns, not just how it manages version history in steady state. This is a PQ test case worth including specifically.
What quality teams need to address operationally
From a practical standpoint, the 2025 updates translate into three operational priorities. First, if you do not have a documented audit trail review procedure with defined frequency and scope, write one and implement it. If you have the procedure but are not executing it consistently, address the execution gap before the next inspection. FDA and EMA have both made this a priority area and it shows in inspection outcomes.
Second, if you operate hybrid systems with scanned paper records, conduct a scoping assessment to determine whether the document management system that holds those scans meets applicable data integrity requirements. This is not necessarily a large project, but it is one that is frequently deferred until an inspection brings it into focus at the worst possible time.
Third, if your documentation control system does not have a documented risk classification of record types, develop one. This does not require redesigning your system; it requires documenting the rationale for the controls you already have, or identifying where the controls are not well calibrated to risk and making targeted adjustments.
A note on regulatory divergence
FDA and EMA have moved closer to each other on data integrity expectations over the past several years, but they have not converged completely. Manufacturers with products in both markets who operate documentation systems that need to satisfy both agencies should review the 2025 updates from each agency separately rather than assuming that satisfying one fully covers the other. The MHRA, which post-Brexit maintains its own guidance program, has also continued to publish data integrity expectations that are broadly consistent with FDA and EMA but carry specific UK regulatory context. Operations with UK manufacturing sites or UK marketing authorizations should include MHRA guidance in their review.
The goal of all three agencies on documentation is the same: trustworthy records that accurately reflect what happened during manufacturing, created in real time by the people doing the work, and maintained in a way that makes them retrievable and auditable for the full retention period. The 2025 updates reinforce that goal at specific points where practice has drifted from principle. Getting the practice right is the quality team's job; understanding where the drift has occurred is the starting point.
See how Katalyze AI performs on your documentation
Talk to the team about your batch records and deviation history. We will show you a working demo configured to your product type.
Request a Demo