One inspection schedule that means the same thing at every site

Multi-site pharmaceutical inspection numbers fail to roll up because sites anchor intervals differently, apply different grace periods, use incompatible criticality scales and name equivalent equipment differently. Standardising means governing those four definitions centrally while allowing local execution, and doing it inside a system that satisfies electronic records expectations, because in this industry a missed inspection is a quality event.

A corporate quality lead asking for on-time inspection performance across eight sites usually receives eight defensible numbers that cannot be added together. One site schedules the next inspection from the original due date, another from the actual completion date, so identical behaviour produces different real intervals. One allows thirty days of grace, another allows the calendar month, a third allows none. Criticality is one to four here, A to C there. A purified water loop is called three different things. The result is a roll-up that measures naming conventions rather than compliance. The fix is master data governance with teeth: one interval anchoring rule, one grace definition per criticality class, one governed equipment taxonomy with site aliases, and one deviation trigger — enforced by the system, configurable per site only where a genuine regulatory or process difference exists, and every change to the master passing through change control.

Source: Regulations and guidance relied on: FDA current good manufacturing practice at 21 CFR Parts 210 and 211, including equipment cleaning and maintenance at 211.67, equipment logs at 211.182 and investigation of discrepancies at 211.192; electronic records and signatures at 21 CFR Part 11; EU GMP Annex 11 on computerised systems and Annex 1 for sterile manufacture; ISO 14644-1 and 14644-2 for cleanroom classification and monitoring; ICH Q9 quality risk management and ICH Q10 pharmaceutical quality system; ISPE GAMP 5 second edition and ASTM E2500 for computerised system and equipment verification; ASME Section VIII Division 1 and National Board Inspection Code NB-23 for pressure equipment; ASME BPE for bioprocessing equipment; USP General Chapter 1231 on water for pharmaceutical purposes; MHRA and FDA data integrity guidance for the ALCOA+ principles.

Technically reviewed by Anoop Rayavarapu — ASNT NDT Level III (UT, RT, MT, PT, VT, ET) · API 653 · ISO 9001:2015 Lead Auditor
Where multi-site pharmaceutical inspection programmes diverge, and the master-data decision that makes the numbers roll up
DivergenceHow it appears at site levelEffect on the corporate roll-upMaster-data decision required
Interval anchorOne site schedules the next inspection from the due date, another from the actual completion dateThe second site inspects its assets measurably less often at identical reported complianceA single anchoring rule applied by the system, with accumulated drift reported as a figure in its own right
Grace periodThirty days at one site, the same calendar month at another, none at a third'On time' means three different things inside one key performance indicatorOne grace definition per criticality class, with grace consumption visible before it is used
Criticality scaleOne to four at one site, A to C at another, high, medium and low at a thirdRisk-weighted completion cannot be computed at all, so it is quietly replaced by a raw countOne governed scale, mapped from local scales at ingest and never overwritten locally
Equipment taxonomy'WFI loop', 'PW distribution' and 'purified water skid 2' used for equivalent systemsLike-for-like comparison between sites becomes a manual exercise that each site disputesA governed equipment-type list held centrally with a site alias field for local familiarity
Deviation triggerOne site raises a deviation at the due date, another only when grace expiresDeviation counts read as a quality difference when they are a definition differenceOne trigger rule bound to the interval, with quality assurance notification generated automatically
Record content at closureSome sites store the report; others store report, raw data, calibration and technician credentialsA regulatory request produces a complete answer at some sites and a partial one at othersA defined minimum record set enforced at closure rather than discovered at audit
None of these six divergences involve anyone doing poor work. Each site's convention is internally consistent and locally defensible. That is exactly why the roll-up problem survives repeated attempts to fix it with reporting.

Why the corporate number is wrong even when every site is honest

The request arrives from corporate quality every quarter: what proportion of scheduled equipment inspections were completed on time across the network. Eight sites answer. Every answer is defensible against that site's own procedure, every answer has an owner who can explain it, and the total is meaningless. This is not a data collection failure and it will not be fixed by a better report. The sites are measuring different things and reporting them under the same label.

The divergences are unglamorous and they are always the same four. Sites anchor the next due date differently — some from the original due date, some from actual completion. Sites define grace differently, and some define it twice, once in the procedure and once in the spreadsheet. Sites use incompatible criticality scales, so anything risk-weighted cannot be computed at all. And sites name equivalent equipment differently, so comparison requires a human who knows both plants. Each of these arose for a reasonable local reason, usually a decade ago, and each is now defended as local practice.

The reason this survives repeated fixing attempts is that people keep attacking it as a reporting problem. Building a corporate dashboard on top of divergent definitions produces a fast, attractive and still meaningless number. The only durable fix is upstream: the definitions themselves have to be governed centrally and enforced by the system that issues the schedule, with local configuration permitted only where a real regulatory or process difference exists. That is a master data project wearing the costume of a scheduling project, and recognising that early saves a year.

Interval anchoring and grace: the arithmetic that stretches twelve months into fifteen

Take a twelve-month inspection with a thirty-day grace period and an anchoring rule that sets the next due date from actual completion. A site that reliably completes late in the grace window runs a real interval of roughly thirteen months. After five cycles the asset is five months later than the programme intended. After ten cycles it has received ten inspections in a period during which eleven were due. Throughout, the site reports strong on-time performance, because it never breached its own rule. Nothing was concealed and nothing was falsified. The arithmetic did it.

Change one thing — anchor the next due date to the original due date rather than to completion — and the drift disappears entirely. The asset is inspected eleven times in the same period, grace is consumed as a buffer rather than as an entitlement, and the reported compliance figure now describes what actually happened. This is the highest-value single decision in a multi-site standardisation programme and it costs nothing but agreement, which is why it is usually the hardest to obtain.

Grace itself needs a definition per criticality class rather than a single site-wide number. A low-criticality utility inspection can absorb thirty days without consequence. An inspection on a system with direct product contact should probably have none, because grace on that asset is a decision to accept unmonitored risk on material being released. Making grace consumption visible before it is used — showing the planner that this task is about to enter grace and what class it belongs to — changes behaviour far more effectively than reporting the breach afterwards.

In pharma, overdue is a batch question rather than a backlog question

In most industries an overdue inspection joins a queue. In pharmaceutical manufacturing it raises a question about product. Equipment used in manufacture, processing, packing or holding must be maintained under 21 CFR Part 211, cleaning and maintenance are recorded under 211.67 and 211.182, and unexplained discrepancies require investigation under 211.192. When a scheduled integrity inspection on a system contacting product is missed, the honest question is what was made during the lapse and whether anything about that material is now uncertain.

That reframing has a direct scheduling consequence: the moment at which quality assurance is notified must be defined, automatic and identical across sites. If one site raises a deviation the day a task passes its due date and another waits for grace to expire, the network's deviation counts compare notification policies rather than quality performance. Worse, the site with the stricter trigger looks like the worse performer, which is a reliable way to teach an organisation to loosen its triggers.

It also changes what a good scheduling module must do at the moment of lateness. It should generate the notification, capture the reason, link to the affected equipment and its product contact status, and carry the record forward into whatever deviation and corrective action process the site operates — rather than simply turning a row red. The record of why an inspection was late, decided at the time by named people, is far more useful eighteen months later than a reconstruction assembled during an inspection by a regulator.

The assets that make pharmaceutical scheduling unlike anything else

Three asset families dominate and none of them behave like general process equipment. High-purity water systems — purified water and water for injection loops in 316L stainless, orbitally welded, with dead-leg and surface finish constraints reflected in ASME BPE and quality expectations described in USP General Chapter 1231 — degrade in ways that need periodic borescope examination of welds, assessment of rouging and verification of passivation. Taking a loop out of service is straightforward mechanically. Returning it to service requires sanitisation and a sampling period before release, so a two-hour inspection sits inside a multi-week return.

Sterilisers and clean steam generators are pressure equipment under ASME Section VIII Division 1 with in-service considerations under NB-23, and simultaneously qualified process equipment. Opening a chamber for inspection or repair means the equipment must be requalified before release, which typically involves thermal and biological challenge studies scheduled through validation rather than maintenance. A plant that schedules the inspection without booking the requalification has scheduled half the job, and the half it omitted is the longer one.

Cleanrooms are the third. Classification and monitoring under ISO 14644-1 and 14644-2, with the requalification frequencies expected in EU GMP Annex 1 — more frequent for the higher grades, less for the lower — put fixed dates on rooms rather than equipment. Any mechanical or inspection work inside a graded area consumes the room, and the room needs cleaning and environmental clearance before it comes back. When the inspection calendar and the requalification calendar are held in separate systems, a site takes the same suite down twice in a quarter for work that could have shared one shutdown.

The scheduling system is itself a GxP system

This surprises procurement teams more often than it should. If the schedule holds records used to satisfy GMP requirements — inspection completion dates, results, the identity of who performed and approved the work — then the system is part of the quality system and inherits its expectations. Under GAMP 5 second edition a configured commercial product typically falls in Category 4: a user requirements specification, a supplier assessment, a documented risk assessment, configuration management and verification proportionate to the risk it carries, consistent with the ASTM E2500 approach of testing what matters rather than everything equally.

Where the records are electronic and used in place of paper, 21 CFR Part 11 and EU GMP Annex 11 expectations follow: a secure, computer-generated audit trail that cannot be altered by the user, access control tied to individual identity, retention through the required period, and appropriate controls where electronic signatures are applied. The ALCOA+ principles from the MHRA and FDA data integrity guidance describe the practical bar — records that are attributable, legible, contemporaneous, original, accurate, complete, consistent, enduring and available.

The consequence for standardisation is the one nobody plans for. Once the system is validated, every change to the shared global master configuration is a change subject to change control, and its impact reaches every site using that master. Adding a criticality class or altering an interval rule stops being a five-minute configuration edit and becomes an assessed, approved and verified change. Programmes that do not design for this discover it at the first change request and lose months. Programmes that do design for it define which layers are global and change-controlled and which are local and lighter, before the first site goes live.

Standardising without freezing every site into one workflow

The failure mode at the other extreme is just as expensive. A corporate team, having correctly identified that definitions must be governed, proceeds to specify one workflow for everyone: the same approval roles, the same planning cadence, the same forms, the same reporting rhythm. Sites with genuinely different regulatory contexts, different equipment ages, different languages and different staffing models then spend two years explaining why the standard does not fit, and the programme acquires a reputation that outlives the people who started it.

The workable division is between definitions and execution. Definitions are global: interval anchoring, grace by criticality class, the criticality scale itself, the equipment taxonomy, the deviation trigger, and the minimum record set required at closure. Those are the things that must mean the same everywhere or the numbers do not add. Execution is local: who plans, when they plan, which crews and contractors are used, how work orders are dispatched, which local approver signs, what the printed record looks like and in which language.

A useful discipline is to require a written justification for every requested local deviation, tested against a single question — does a regulation or a physical process compel this difference. Local jurisdictional pressure equipment intervals compel it. A national language requirement compels it. Preferring the calendar month to a thirty-day grace does not. In practice around four fifths of requested exceptions dissolve when that question is asked in writing, and the remaining fifth are real and should be granted quickly and visibly, because granting them is what makes the standard credible to the sites that have to live inside it.

How to evaluate a multi-site inspection scheduling module

Ask the vendor to demonstrate the divergence, not the ideal. Configure two sites with deliberately different legacy conventions and show the roll-up. Can the system apply one interval anchoring rule while displaying each site's historical drift? Can grace be defined per criticality class rather than per site? Can a governed equipment taxonomy carry a site alias so local staff keep the names they use while the corporate report groups correctly? Can a local criticality scale be mapped at ingest without any site being able to overwrite the governed value?

Then test the record layer. Is the audit trail computer-generated, attributable to an individual, and beyond the reach of the user who created the record? Can closure be blocked until the defined minimum record set exists — report, raw data where applicable, calibration record, technician qualification? Does the vendor supply a validation package, and can they describe how a change to the global master is assessed and verified across sites without a full revalidation each time? A vendor who has not thought about that last question has not yet deployed a multi-site pharmaceutical customer.

Finally, ask about the migration, which is where these programmes actually fail. Legacy schedules carry decades of drift. Re-anchoring every task to the correct interval on day one will place a large number of assets immediately overdue, and in this industry immediately overdue means immediately in deviation. A credible vendor will describe a staged re-anchoring with a defined catch-up plan, agreed with quality in advance, rather than presenting the cliff as evidence that the new system found problems the old one was hiding.

What Atlantis configures for multi-site pharmaceutical clients

We start with the four definitions, because everything else is downstream of them. One interval anchoring rule, grace defined by criticality class, one governed criticality scale with mappings from each site's legacy scale, and a governed equipment taxonomy carrying site aliases so local teams keep familiar names. The deviation trigger is bound to the interval and generates quality assurance notification automatically, so deviation counts across the network compare performance rather than notification policy.

The record layer is built for the expectations that apply: attributable, computer-generated audit trail, access control by individual identity, a defined minimum record set enforced at closure, and configuration held under change control with a documented separation between the global master and permitted site configuration. Qualification tails are modelled as scheduled work, so a water loop inspection carries its sanitisation and sampling period and a steriliser inspection carries its requalification, rather than both appearing as short tasks that surprise production.

Because the platform is built on Odoo, the inspection programme sits alongside the asset register, contractor and technician qualification records, calibration control and procurement rather than in an isolated tool. It is affordable, accessible and fully customisable to a network's own governance model. If you would like to see two of your sites' real conventions modelled side by side, with the roll-up they currently produce and the roll-up a governed master would produce, request a demonstration or a scoped consultation at info@atlantisndt.com.

How does interval anchoring quietly stretch a twelve-month inspection?

Suppose a twelve-month task with thirty days of grace, and the next due date is set from the completion date. If the site habitually completes near the end of grace, the effective interval becomes about thirteen months. Over five cycles the asset drifts five months later than the programme intended, and by the tenth cycle it has received ten inspections where eleven were due. The site reports high on-time compliance throughout, because it never breached its own grace rule. The arithmetic, not the behaviour, produced the gap.

Why is a missed inspection a bigger event in pharma than in other industries?

Because it reaches product. In most industries an overdue inspection is a maintenance backlog item. Under 21 CFR Part 211 the equipment used to manufacture, process, pack or hold drug product must be maintained, and an unexplained discrepancy triggers investigation under 211.192. A missed inspection on a system contacting product therefore raises a question about material made during the lapse, and answering it requires an impact assessment. Scheduling accuracy stops being a maintenance metric and becomes a batch disposition input.

Does the scheduling system itself need to be validated?

If it holds GMP records or drives GMP decisions, yes. Under GAMP 5 a configured commercial application typically sits in Category 4, requiring a user requirements specification, a risk assessment, configuration control and documented verification proportionate to risk, in line with ASTM E2500 thinking. Where it holds electronic records used to satisfy predicate rule requirements, 21 CFR Part 11 and EU GMP Annex 11 expectations apply: secure audit trail, record retention, access control and, where signatures are used, appropriate signature controls.

How much local variation should a global standard actually allow?

Allow variation where a regulatory or process difference genuinely exists, and nowhere else. Site-specific inspection methods, local jurisdictional pressure equipment intervals, national language on printed records and local approver roles are legitimate. Different interval anchoring, different grace arithmetic, different criticality scales and different deviation triggers are not — they are historical accidents defended as local practice. The test is simple: if the difference cannot be tied to a rule or a physical process, it belongs in the global master rather than in a site's configuration.

What makes water systems and sterilisers hard to schedule around?

Their revalidation tail. Taking a purified water or water for injection loop out of service for weld inspection or rouge assessment triggers sanitisation and a period of microbiological and chemical sampling before it can be released back to production. A steriliser opened for chamber or jacket examination usually requires requalification studies before release. In both cases the inspection is hours and the return to service is weeks, so the schedule must model the qualification tail as work rather than as an afterthought.

How do cleanroom requalification dates interact with the inspection calendar?

They compete for the same access. Cleanroom classification and monitoring under ISO 14644-1 and 14644-2, with the requalification periods expected in EU GMP Annex 1, put fixed dates on grade A and B areas at one frequency and grades C and D at another. Any mechanical or inspection work inside those areas consumes the room and is followed by cleaning and environmental clearance. Scheduling inspections without visibility of the requalification calendar produces two separate room shutdowns where one would have served.

Request a consultation

Built for any business that runs on operations

Most companies do not fail at their craft. They lose time, margin and goodwill in the gaps between the tools they use to run the place — a quoting spreadsheet that does not talk to the job sheet, a job sheet that does not reach accounts, and a compliance folder nobody can search when a client asks. Atlantis closes those gaps by putting the whole operation on one platform, so information is entered once and everything downstream stays in step.

What you can run on it

  • Sales and CRM — leads, quotes, follow-ups and the pipeline that tells you what next month looks like.
  • Projects and job costing — plan the work, track the hours and materials against it, and see the margin while the job is still live rather than at final account.
  • Field and service teams — dispatch, schedules, mobile capture that works with no signal, and sign-off from site.
  • Inventory and purchasing — stock, suppliers, reorder points and goods receipt, joined to the jobs that consume them.
  • People — records, qualifications and licences with renewal reminders, timesheets, leave and payroll.
  • Quality and documents — procedures and forms under revision control, with the audit trail an inspection or accreditation body actually asks for.
  • Accounts — invoicing, expenses, multi-currency and the reporting your accountant stops chasing you for.

Affordable, accessible, fully customizable — and we mean each word

Affordable because the whole suite is included rather than sold to you a module at a time, and because implementation is done by people who have run operations rather than by a chain of subcontractors. Accessible because it runs in a browser and on a phone, works for a small team on day one, and does not need a specialist on staff to keep it alive. Fully customizable because your process is the thing that makes you competitive — the software should bend to it, not the other way round.

Industries we configure for

Service businesses and contractors, manufacturing and fabrication, trading and distribution, laboratories and testing houses, engineering consultancies, construction and facilities, and asset owners across energy, marine, aerospace and infrastructure. Inspection and testing is where we started, and it remains the sector we go deepest in — but the platform underneath is general-purpose, and most of what it does has nothing to do with inspection at all.

What happens when you get in touch

A short conversation, not a sales sequence. We ask how the business runs today and where it hurts, show you the platform doing that work, and send a written quote shaped to your region, your team size and the scope you actually need. No obligation, nothing to install first, and no pressure to decide on the call. Reach out and tell us what you are trying to fix.

Related: business management platform · inspection management software · choosing the right category of software · modules · by industry · asset integrity platform. Book a free consultation.