Blog
Quality Assurance Documentation: A 2026 Guide
By Multimod Labs.
A scientist finishes a wet-lab run, removes gloves, and realizes the notebook contains only a few hurried phrases. The exact time of a temperature change is uncertain. A pH adjustment was made, but the amount and reason were reconstructed from memory. The instrument file exists somewhere, while the deviation summary says only that the procedure was “followed with minor changes.” That record may look complete until another scientist, supervisor, or auditor tries to determine what happened.
Quality assurance documentation exists to prevent that gap. It connects planned work, bench activity, raw evidence, review, corrections, and final approval into a record that another person can retrieve and understand. The difficult part isn't creating more paperwork. It's preserving the truth of the experiment while the work is happening, then protecting that evidence as it moves through review and export.
Table of Contents
- The Moment Lab Documentation Falls Apart
- What Quality Assurance Documentation Actually Means
- Core Document Types and Their Purposes
- Regulatory Expectations Across FDA, WHO, and ISO 9001
- A Practical Workflow for Compliant Records
- Quick Reference for QA Document Types
- Closing the Bench-to-Record Gap
The Moment Lab Documentation Falls Apart
A senior analyst completes a time-sensitive assay and plans to finish the notebook entry after the remaining samples are processed. Hours later, the analyst reconstructs the sequence from memory. The deviation summary mentions an adjustment, but it misses a critical pH correction made during preparation. The reviewer notices that one result doesn't align cleanly with the stated procedure and follows the trail backward, from the summary to the raw data, then to a missing witness signature.
Nothing in the file says that the analyst intended to misrepresent the work. The problem is more ordinary and more dangerous. The record drifted away from the bench.
The missing detail may have started as a harmless interruption. A reagent behaved differently than expected. A timer was reset. A sample looked cloudy. A colleague was asked to confirm a reading and forgot to sign. Each event seemed small at the moment, but the final record no longer binds the scientific action to reliable evidence.
Practical rule: A record should be created close enough to the work that the scientist can distinguish observation from reconstruction.
That principle is the foundation of contemporaneous laboratory documentation. A contemporaneous note doesn't need to be elegant. It needs to show what happened, when it happened, who recorded it, and what source evidence supports it.
Quality assurance documentation therefore functions as a control system, not an inspection-day narrative. Policies define the expected process. Records show execution. Supporting evidence helps reviewers verify that the record reflects the work rather than a polished version written later.
The distinction matters across research, QC, biotech, chemistry, microbiology, and regulated manufacturing. A procedure can be current and approved while the work performed at the bench changes in response to real conditions. A strong system captures that change, identifies its effect, and preserves the decision path.
What Quality Assurance Documentation Actually Means
Quality assurance documentation is the connected set of policies, procedures, records, and supporting evidence that demonstrates work was planned, performed, reviewed, and controlled against defined criteria. It includes the instruction used before the experiment, the entries created during execution, the raw data produced by instruments or observations, and the review history that explains how the final record became approved.
The most useful lens for individual records is ALCOA+. The model includes five core attributes, Attributable, Legible, Contemporaneous, Original, and Accurate, plus Complete, Consistent, Enduring, and Available. WHO guidance for pharmaceutical quality control laboratories also emphasizes data integrity procedures, controlled changes, audit trails, and regular backups for electronic data.

Applying ALCOA+ at the bench
- Attributable: The record identifies the person who performed or entered the activity. A named, authenticated entry is stronger than an anonymous note.
- Legible: Another person can read or interpret the entry. A clear typed observation or readable original entry is preferable to an unclear shorthand phrase.
- Contemporaneous: The note is recorded when the activity occurs. A timestamped voice note made during a transfer is more reliable than an hourly transcription reconstructed later.
- Original: The record preserves the first captured source. An original chromatogram or instrument output carries more evidentiary value than a re-plotted overlay with no retained source file.
- Accurate: Values, units, sample identifiers, and descriptions match the work performed.
The added requirements extend the same discipline. Complete records retain all relevant observations, including an unexpected visual change or a failed step. Consistent records use a coherent sequence, identifiers, dates, and units. Enduring records remain preserved for the required period. Available records can be retrieved promptly when a supervisor, investigator, or auditor needs them.
Regulated documentation and internal QA documentation overlap, but they aren't interchangeable. GMP batch records, validation protocols, approved SOPs, and controlled production records may carry defined approval and retention obligations. Internal documents such as training matrices, equipment logs, and CAPA records support the quality system while following the organization's own governance and review rules.
The practical test is simple. Can a reviewer trace the action from approved instruction to original evidence, identify the person and time involved, understand every correction, and retrieve the complete chain later? If not, the file may contain documents without providing dependable control.
Core Document Types and Their Purposes
A reviewer usually encounters QA documentation as a connected chain rather than as isolated files. Each document answers a different question, and each has an owner responsible for keeping that answer reliable.
Instructions and commitments
SOPs define how a recurring activity should be performed. QA typically owns document control, while subject-matter experts draft the technical content. A reviewer checks the effective version, approval history, distribution controls, training linkage, and whether the instructions are usable at the bench.
Protocols and study plans establish the work before execution begins. The study scientist or supervisor usually owns the draft, with QA or an authorized reviewer approving it. Reviewers look for a clear objective, defined materials, planned steps, acceptance criteria, responsibilities, and a version that was approved before the work started.
A protocol is a commitment. It doesn't prove that the commitment was followed.
Evidence of execution
Raw data records show what the instrument, analyst, or experiment produced. The analyst creates or captures the record, and a supervisor or QA reviewer examines it. Reviewers check sample and lot identifiers, instrument IDs, dates, units, calculations, attachments, and whether the original data remain available.
Batch production records connect manufacturing actions to a specific batch. Production personnel complete them, supervisors review them, and QA provides quality oversight. The review focuses on completed fields, initials, timestamps, material traceability, equipment references, yields or observations where applicable, and alignment between recorded values and specifications.
FDA guidance treats documentation as a core quality mechanism. It states that quality-related activities should be recorded when performed, and it describes controlled revision histories, legible original entries, and dated and signed corrections in FDA good documentation practice guidance.
Evidence of control when work changes
Deviation and investigation reports show that an issue was detected, described, assessed, and addressed. The person discovering the issue may initiate the report, the supervisor or quality unit may investigate, and QA usually reviews the conclusion. A reviewer checks the original observation, affected samples or batches, immediate actions, impact assessment, attachments, root-cause reasoning, and links to corrective or preventive actions.
Change control records prove that a modification was evaluated before it became standard practice. The process owner generally proposes the change, while QA coordinates or approves the quality assessment. Reviewers look for the reason, risk assessment, affected documents and systems, implementation plan, training impact, effective date, and evidence that the change was closed.
Evidence that systems and people are fit for use
Validation and qualification records demonstrate that equipment, software, or a process is suitable for its intended use. Validation, engineering, laboratory, and QA contributors may share ownership. Reviewers look for approved requirements, predefined acceptance criteria, executed tests, deviations, instrument and software identifiers, calibration status, and an explicit conclusion.
Training records demonstrate that people were prepared to perform assigned work. Training coordinators, supervisors, and QA may maintain different parts of the record. A reviewer checks the correct procedure version, trainee identity, completion date, trainer or assessor, outcome, and any retraining triggered by a change.
The chain is strongest when every file points to the next one. A batch record should connect to the relevant SOP, raw data, instrument, material lot, deviation, and review. A document that exists without those relationships may satisfy a filing habit while failing the more important question, whether the evidence can withstand scrutiny.
Regulatory Expectations Across FDA, WHO, and ISO 9001
FDA, WHO, and ISO 9001 don't require every organization to maintain an identical document library. Their common concern is whether the organization can demonstrate controlled work through reliable, retrievable evidence.
For FDA-regulated manufacturing, FDA's Q7A guidance for active pharmaceutical ingredients requires documents to be prepared, reviewed, approved, distributed, and retained through written procedures. It also treats revision, supersession, withdrawal, contemporaneous recording, and correction control as quality activities. For APIs, production, control, and distribution records must be retained for at least 1 year after batch expiry, or at least 3 years after complete distribution when the API has a retest date, as stated in the FDA guidance.
Electronic records add another layer. Under 21 CFR Part 11-style expectations, an audit trail should preserve the prior value, new value, person making the change, time of change, and reason for the edit, with the trail retained at least as long as the underlying record. CASRAI's electronic laboratory notebook guidance describes these audit-trail elements.

Three frameworks, one evidence problem
WHO guidance frames laboratory records around ALCOA+ qualities and expects procedures for data integrity, computerized-system changes, amendments, audit trails, and backups. That emphasis applies to paper and electronic work. A laboratory with limited automation still needs records that identify the actor, preserve the original, show timing, and remain available.
ISO 9001's documentation model is deliberately less prescriptive than older editions. The 1987 first edition established the series, the 1994 edition is described as the documentation peak with around 20 documented procedures, the 2000 revision reduced that to 6 documented procedures, and the 2015 edition removed mandatory requirements for a quality manual and fixed documented procedures. This historical shift is summarized in ISO 9001's documented-information evolution.
The lesson isn't that documents became unimportant. ISO moved from prescribing document types toward requiring documented information that supports process control and demonstrated performance.
Reviewer's question: Can the organization prove what was done, under which approved conditions, using evidence that remained accurate through correction, review, retention, and retrieval?
That question explains why document count is a weak measure of quality. Auditors test effective versions, retention, amendment history, traceability, access, and the connection between source data and approved conclusions. A short, well-controlled record can be stronger than a large collection of procedures that doesn't reflect work as performed. Further practical context on these expectations appears in GxP documentation requirements.
A Practical Workflow for Compliant Records
A dependable workflow begins before the scientist enters the laboratory. It should make the approved plan visible, capture changes at the moment they occur, and preserve the relationship between source evidence and final record.
1. Author the protocol with version control
The study owner drafts the objective, materials, procedure, observations to capture, acceptance criteria, and responsibilities. The document receives a unique identifier and version, then moves through pre-approval before execution. A template should prompt the operator to record sample IDs, lot numbers, instrument IDs, units, and expected decision points.
2. Prepare the approved execution package
The supervisor confirms that the operator has the effective SOP, current protocol, required materials, calibrated equipment, and relevant training. The package should make it difficult to confuse a draft instruction with the approved version. It should also identify where raw files, images, calculations, and deviations will be stored.
3. Capture bench activity as it happens
The operator records observations, timing, adjustments, and unexpected events while the work is underway. Typed notes, images, timers, and voice capture can each serve a different purpose. Voice is useful when hands are occupied, but the method should be selected based on the evidence needed.
A voice entry should still identify the sample, lot, step, and observation. An image should retain source context. A timer should connect to the time-sensitive activity rather than float separately from the record.
Verbex, made by Multimod Labs, is one example of a private, on-device iPhone lab documentation app that supports voice notes, typed notes, timers, and images. Users select a section such as Objective, Materials, Procedure, Observations, or Conclusion before capturing information, and the app preserves source context and timestamps for human review.

4. Reconcile the run before memory replaces detail
At the end of the run, the operator compares the protocol with the source captures and raw outputs. Each completed step should be accounted for. Deviations should be flagged where they occurred, not hidden inside a later summary.
A useful reconciliation asks:
- Identity: Do sample, lot, instrument, and operator identifiers agree across files?
- Sequence: Do timestamps and procedure steps follow a coherent order?
- Exceptions: Does every change, failed step, unexpected observation, or repeat have an explanation?
- Evidence: Are original files, images, calculations, and attachments retained?
- Decision: Does the conclusion match the recorded observations and approved criteria?
5. Review revisions and approval history
The reviewer checks whether edits preserve the original meaning and whether the reason for each change is visible. In a validated system, controlled redlines, audit trails, electronic signatures, and access controls may form part of the approved workflow. A standalone exported file shouldn't be treated as proof of those controls unless the governing system validates and approves that use.
Teams assessing digital capture should also consider privacy, device management, access control, retention, and export handling. A practical security design review checklist can help structure that assessment.
6. Export only through an approved path
Completed records may be exported to PDF, DOCX, or Markdown for archiving or transfer, but export isn't the same as validation. The receiving ELN, archive, or QMS should define which format is authoritative, how metadata is preserved, how attachments are linked, and how reviewers confirm completeness.
If the organization uses hashing or signature verification, those controls should be implemented through an approved system and procedure. Raw exports and PDF renders shouldn't become inspection evidence merely because they look complete.
For teams formalizing approvals, controlled document approval workflows can help separate drafting, review, approval, release, and archival responsibilities.
Quick Reference for QA Document Types
A document's value depends on the question it answers and the evidence attached to it. The table below gives a practical starting point for assigning ownership and review attention.
| Document Type | Primary Purpose | Typical Owner | What a Reviewer Checks |
|---|---|---|---|
| SOP | Defines an approved recurring method | QA and subject-matter owner | Effective version, approvals, training, usability |
| Protocol or study plan | Establishes the planned work and criteria | Scientist or supervisor | Pre-approval, scope, steps, acceptance criteria |
| Raw data record | Preserves evidence of execution | Analyst or instrument system | Original files, identifiers, units, timestamps |
| Batch production record | Connects actions to a batch | Production and supervisor | Completed fields, initials, materials, equipment |
| Deviation report | Documents and assesses an unexpected event | Operator, supervisor, or QA | Original observation, impact, investigation, actions |
| Change control | Governs a proposed modification | Process owner and QA | Risk, affected documents, training, implementation |
| Validation or qualification record | Demonstrates fitness for use | Validation, engineering, laboratory, and QA | Requirements, tests, criteria, deviations |
| Training record | Shows personnel competence | Supervisor, training coordinator, or QA | Procedure version, identity, completion, outcome |
A reviewer shouldn't assume that a signed document is complete. The review must include attachments, source data, linked identifiers, correction history, and evidence that the record reflects the work performed.
Closing the Bench-to-Record Gap
Documentation quality is decided at the bench before QA ever sees the file. A laboratory can improve its system by standardizing capture routines, requiring same-day reconciliation, controlling export channels, and training scientists to identify themselves and preserve original entries.
The most effective routine is usually simple. The operator starts with the approved protocol, records each meaningful action or observation during execution, labels evidence with the relevant sample or lot, flags deviations inline, and completes a review while the sequence is still familiar. The supervisor then checks the record against raw outputs, attachments, instruments, and material identifiers.
On-device voice capture can support this workflow when the environment makes typing difficult. A spoken observation made during a transfer can preserve timing and context that a reconstructed notebook entry may lose. Typed notes remain useful for precise values and structured fields, while images can preserve visual evidence and timers can document time-sensitive procedures.
The method doesn't remove scientific judgment. It protects the conditions under which judgment can be reviewed. A scientist still decides whether an observation represents a deviation, whether a result is valid, and how the conclusion should be written. The capture tool should preserve source context, not independently decide scientific meaning.

Verbex is designed for that narrow role. It processes captures on the iPhone without an account, cloud AI, cloud storage, advertising, analytics, or tracking. Review & Complete creates a source-backed organized draft, and supported devices may offer an additional ELN-style draft when local Apple Intelligence processing succeeds. The scientist reviews and edits the record before completion, then can export it as PDF, DOCX, or Markdown for an existing documentation workflow.
Verbex isn't an official ELN, validated system, LIMS, QMS, inventory system, or autonomous scientific system. It doesn't provide regulatory sign-off or guarantee compliance. Used within an approved laboratory process, it can support better contemporaneous documentation and help preserve a clearer path from bench reality to a reviewable record.
Audit readiness should emerge from faithful recording, not from a separate inspection project. When the record captures what changed, preserves the source, explains the decision, and remains retrievable, quality assurance documentation becomes evidence of control rather than paperwork assembled after the fact.
For teams that need to preserve bench observations before transferring them into an official ELN, Verbex provides private, on-device capture through voice notes, typed notes, timers, and images, followed by human review and export. Visit the app site to evaluate whether its source-backed experiment capture workflow fits the laboratory's existing documentation and review procedures.