{
 "slug": "oos-invalidation-receipt",
 "topic_id": "TOPIC-125",
 "cluster": "Pharma, Biotech & Clinical Trial GxP Identity",
 "tier": "Tier A",
 "title": "Invalidating an out-of-specification result: the highest-stakes signature in the laboratory",
 "summary": "A failing result invalidated on assignable laboratory error decides whether a batch reaches patients. The record is a LIMS status change, a reason code and a free-text note — written by the laboratory that benefits from the invalidation.",
 "lede": "Every data integrity enforcement action of the last decade passes through the same door. Not falsified data — that is rarer than the headlines suggest. The door is the invalidated result: a failing test set aside on the grounds of assignable laboratory error, recorded by the laboratory that set it aside.",
 "date": "2025-10-28",
 "category": "Developer",
 "author_id": "margot-reyes",
 "tags": [
  "OOS",
  "out of specification",
  "data integrity",
  "LIMS",
  "quality control",
  "FDA inspection"
 ],
 "image": "https://cdn.twc.sh/images/igcache/OOS%20Invalidation%20Receipt/1500_900/blog.jpg",
 "schema": "Article",
 "key_takeaways": [
  "Invalidation is the single most scrutinised behaviour in pharmaceutical quality control, and its record is the least evidential artefact in the laboratory.",
  "An invalidation-drift control chart — invalidations per 1,000 tests, by analyst and by method — is computable from data every LIMS already holds.",
  "A dual-signed invalidation receipt binds two independent humans to the result hash, the assignable cause classification and the rationale."
 ],
 "body": [
  {
   "type": "h2",
   "text": "Why this one decision carries the weight"
  },
  {
   "type": "diagram",
   "kind": "flow",
   "alt": "A failing result, an investigation and an invalidation",
   "caption": "Every step is legitimate. The last one is the one that gets read closely.",
   "nodes": [
    {
     "label": "OOS result obtained",
     "note": "the fact"
    },
    {
     "label": "Phase I laboratory investigation",
     "note": "assignable cause?"
    },
    {
     "label": "Invalidation decided",
     "note": "workflow status",
     "bad": true
    },
    {
     "label": "Result excluded from the batch decision",
     "note": "",
     "bad": true
    }
   ]
  },
  {
   "type": "p",
   "html": "An out-of-specification result is not, by itself, a problem. Analytical methods produce outliers, instruments drift, and genuine laboratory error is a documented and expected phenomenon. Investigating an OOS and finding an assignable cause is normal science."
  },
  {
   "type": "p",
   "html": "The problem is structural. The party that investigates the failing result is the party inconvenienced by it. The determination that an error was assignable is made by people under schedule pressure, on a batch that may already be allocated. And the record of that determination is a status change in a system the laboratory controls."
  },
  {
   "type": "p",
   "html": "FDA guidance on investigating OOS results is detailed and good. It describes a phased investigation, requires laboratory error to be demonstrated rather than assumed, and prohibits retesting into compliance. What it cannot do is change who holds the evidence."
  },
  {
   "type": "h2",
   "text": "What the record contains, field by field"
  },
  {
   "type": "table",
   "head": [
    "Field",
    "Typical content",
    "Evidentiary weakness"
   ],
   "rows": [
    [
     "Status",
     "Valid → Invalidated",
     "A workflow state transition, alterable with database access"
    ],
    [
     "Reason code",
     "Selected from a picklist",
     "Coarse; the picklist was designed for reporting, not for evidence"
    ],
    [
     "Investigation reference",
     "Link to a QMS record",
     "Correct, but the QMS is the same custodian"
    ],
    [
     "Approver",
     "User id, Part 11 signature",
     "Knowledge factor; see the evidentiary ladder"
    ],
    [
     "Rationale",
     "Free text",
     "Unbounded, unhashed, and editable"
    ]
   ]
  },
  {
   "type": "p",
   "html": "Read that table as an investigator would. Every field is an assertion by the accused, and the most important one — the rationale — is the least constrained."
  },
  {
   "type": "h2",
   "text": "The chart that changes the conversation"
  },
  {
   "type": "p",
   "html": "Before discussing controls, build the baseline. Invalidation rate is a process metric and should be charted like one. The data is already in your LIMS."
  },
  {
   "type": "ol",
   "items": [
    "Export 24 months of tests: test id, method, analyst, result disposition, date.",
    "Compute invalidations per 1,000 tests, monthly, overall.",
    "Stratify by method and by analyst. Report the interquartile range, not the mean.",
    "Flag any analyst-method pair more than two standard deviations above the site median for that method.",
    "Plot the series with control limits. Look for step changes rather than points."
   ]
  },
  {
   "type": "p",
   "html": "This is not a fishing expedition against analysts, and it should not be framed that way internally. A high rate for one method across all analysts is a method problem. A step change following an instrument change is an instrument problem. Only a persistent analyst-specific divergence across methods raises a personnel question, and even then the first hypothesis should be training."
  },
  {
   "type": "callout",
   "title": "Why an honest laboratory wants this chart.",
   "html": "If an inspector raises invalidation practice and you can produce 24 months of charted rates with documented investigations of every signal, you have moved the conversation from suspicion to evidence. Laboratories that cannot produce the chart spend that conversation on the back foot regardless of their actual conduct."
  },
  {
   "type": "h2",
   "text": "The OOS Invalidation Receipt"
  },
  {
   "type": "p",
   "html": "Two signatures over one canonical statement. The analyst who performed the investigation and the QA approver each sign the identical object, from distinct credentials on distinct authenticators."
  },
  {
   "type": "code",
   "text": "{\n  \"type\": \"manav-stmt/1\",\n  \"action\": \"invalidate_oos_result\",\n  \"render\": [\n    \"Result: [test id] — [method] — [value] [unit] vs spec [range]\",\n    \"Instrument: [id]  Column/lot: [id]  Analyst: [name]\",\n    \"Assignable cause: [classification]\",\n    \"Basis: [rationale as written]\",\n    \"Investigation: [QMS reference, phase]\"\n  ],\n  \"constraints\": { \"distinct_credential\": true, \"distinct_aaguid\": true }\n}"
  },
  {
   "type": "p",
   "html": "Both parties sign the rationale as written, which means the rationale becomes immutable at the moment of signing. That single property removes the most common evidentiary criticism of an invalidation record, and it costs nothing operationally."
  },
  {
   "type": "h2",
   "text": "What the receipt does not do"
  },
  {
   "type": "p",
   "html": "It does not make the assignable cause determination correct. A laboratory can sign, with full cryptographic rigour, an invalidation that a reviewer would disagree with. Evidence of who decided is not evidence that the decision was sound."
  },
  {
   "type": "p",
   "html": "What it does is separate two questions that are currently entangled. Today, an inspector who doubts an invalidation is simultaneously doubting whether the record is accurate and whether the judgement was right. With a signed receipt, the first question is settled and only the second remains — which is the scientific argument the laboratory should want to have."
  },
  {
   "type": "h2",
   "text": "Sequencing the work"
  },
  {
   "type": "ol",
   "items": [
    "Build the invalidation-drift chart first. It costs nothing and it tells you whether you have a story to defend.",
    "Fix the reason-code taxonomy if it is coarse. A receipt over a bad classification scheme preserves a bad classification scheme.",
    "Add dual signing to the invalidation step only. Do not attempt to instrument every LIMS approval at once.",
    "Run one quarter in parallel and present both evidence packages at your next internal audit."
   ]
  },
  {
   "type": "h2",
   "text": "What an inspector reconstructs"
  },
  {
   "type": "table",
   "caption": "Questions asked about an invalidation",
   "head": [
    "Question",
    "Usual answer quality"
   ],
   "rows": [
    [
     "Who decided?",
     "An account in a LIMS"
    ],
    [
     "On what evidence?",
     "Free text, sometimes templated"
    ],
    [
     "Was an assignable cause identified?",
     "Recorded, quality varies"
    ],
    [
     "<strong style=\"font-weight:600\">What did they review before deciding?</strong>",
     "<strong style=\"font-weight:600\">Not recorded</strong>"
    ],
    [
     "Has the pattern changed over time?",
     "Computable, rarely computed"
    ]
   ]
  },
  {
   "type": "p",
   "html": "The last row is worth doing before an inspector does it. An invalidation rate that drifts upward, or clusters around particular products or analysts, is a finding waiting to be made."
  },
  {
   "type": "h2",
   "text": "Objections and honest limits"
  },
  {
   "type": "p",
   "html": "<strong style=\"font-weight:600\">“Our OOS procedure follows the guidance closely.”</strong> Procedure quality is the first thing checked and the easiest to demonstrate. What is harder is showing that a specific decision applied that procedure to that data."
  },
  {
   "type": "p",
   "html": "<strong style=\"font-weight:600\">“Invalidations are reviewed by quality.”</strong> By a second account, recorded the same way. A review that leaves the same artefact as the decision does not add evidence, only a second name."
  }
 ],
 "faq": [
  {
   "q": "Does this suggest laboratories routinely falsify results?",
   "a": "No. The overwhelming majority of invalidations are legitimate and well investigated. The argument is that the record cannot currently demonstrate the difference, which disadvantages honest laboratories most."
  },
  {
   "q": "Is a second signature not already required?",
   "a": "QA approval is typically required, but both signatures are Part 11 knowledge-factor signatures applied through the same system, frequently from the same terminal. The distinctness constraints are what make the second signature independent."
  },
  {
   "q": "What is a reasonable invalidation rate?",
   "a": "There is no universal figure, and any article quoting one should be treated sceptically. The useful comparison is your own method-stratified rate over time, against your own history."
  },
  {
   "q": "Would this survive an inspection challenge?",
   "a": "The receipt is verifiable offline by the inspector against a published key, without access to your LIMS. That is a materially stronger position than a status change, though no artefact guarantees an inspection outcome."
  },
  {
   "q": "Why is invalidation so heavily scrutinised?",
   "a": "Because it converts a failing result into one that never counted, and a pattern of invalidations is a recognised inspection finding."
  },
  {
   "q": "What is usually missing from the record?",
   "a": "What the decider reviewed. The result and the justification are recorded; the data they were looking at is not."
  },
  {
   "q": "What should a site compute itself?",
   "a": "Its invalidation rate over time, by product and by analyst, before an inspector computes it."
  }
 ],
 "sources": [
  {
   "t": "FDA — Investigating Out-of-Specification Test Results guidance",
   "u": "https://www.fda.gov/regulatory-information/search-fda-guidance-documents/investigating-out-specification-test-results-pharmaceutical-production"
  },
  {
   "t": "MHRA GxP Data Integrity Guidance and Definitions."
  },
  {
   "t": "EudraLex Volume 4 — EU GMP guidelines",
   "u": "https://health.ec.europa.eu/medicinal-products/eudralex/eudralex-volume-4_en"
  },
  {
   "t": "21 CFR Part 11 — Electronic Records; Electronic Signatures",
   "u": "https://www.ecfr.gov/current/title-21/chapter-I/subchapter-A/part-11"
  },
  {
   "t": "FIDO Alliance specifications",
   "u": "https://fidoalliance.org/specifications/"
  }
 ],
 "related": [
  {
   "slug": "part-11-signature-evidentiary-ladder",
   "title": "A username and a password: what a GxP signature proves",
   "category": "AEO"
  },
  {
   "slug": "scope-of-review-statement",
   "title": "Review by exception: what did the release signature attest to?",
   "category": "Developer"
  },
  {
   "slug": "cross-boundary-oversight-chain",
   "title": "Sponsor oversight across the CRO and CDMO boundary",
   "category": "Compliance"
  }
 ],
 "wordcount": 1129,
 "url": "/blog/oos-invalidation-receipt.html",
 "reading_time": "5 min read",
 "image_title": "OOS Invalidation Receipt",
 "seo_title": "Invalidating an out-of-specification lab result",
 "meta_description": "A failing result invalidated on assignable laboratory error decides whether a batch reaches patients.",
 "hub": {
  "slug": "topics/gxp-identity",
  "title": "Pharma and GxP identity"
 },
 "answer": "Invalidating an out-of-specification result. It converts a failing result into one that never counted, and it is the single decision most likely to be examined in an inspection or a consent decree. The record is typically a workflow status and a free-text justification.",
 "answer_q": "What is the highest-stakes signature in a laboratory?",
 "glossary": [
  {
   "term": "Out-of-specification",
   "def": "A result outside established acceptance criteria, triggering a defined investigation."
  },
  {
   "term": "Assignable cause",
   "def": "An identified laboratory error justifying invalidation — the finding the whole decision turns on."
  },
  {
   "term": "Phase I investigation",
   "def": "The initial laboratory review determining whether an assignable cause exists."
  }
 ],
 "checklist": {
  "title": "Making an invalidation defensible",
  "id": "oos",
  "desc": "Four steps.",
  "steps": [
   {
    "name": "Render the data being invalidated.",
    "text": "The result, the specification, the investigation findings."
   },
   {
    "name": "Sign that rendering.",
    "text": "Not a workflow transition."
   },
   {
    "name": "Require structured cause, not free text.",
    "text": "Categories a trend can be computed over."
   },
   {
    "name": "Compute your invalidation rate quarterly.",
    "text": "Before someone else does."
   }
  ]
 },
 "cta": {
  "title": "Where this fits in Manav",
  "html": "Manav binds the signer to the exact record being certified, on a credential under their sole control, and produces a receipt an inspector can verify years later without access to the manufacturing system.",
  "href": "../docs.html",
  "label": "See signature binding"
 }
}