Skip to main content
AI in GMP 13 september 2026

OOS Investigations Under 21 CFR 211.192: Where FDA Finds Phase I and Phase II Failures

FDA cites 21 CFR 211.192 in nearly every pharma inspection. Here's what auditors look for in OOS Phase I and Phase II investigations — and where programs fail.

SS
Sam Sammane
Founder & CEO, Aurora TIC | Founder, Qalitex Group

Out-of-specification test results are, in FDA’s own words, “findings that require investigation.” That sounds straightforward. But 21 CFR 211.192 is one of the most persistently cited regulations in pharmaceutical manufacturing inspections — and it has been for well over a decade. The reason isn’t that manufacturers don’t know OOS results require investigation. It’s that what “adequate investigation” actually means in practice is far more demanding than the regulation’s sparse text suggests.

The agency’s 2006 guidance document, Investigating Out-of-Specification (OOS) Test Results for Pharmaceutical Production, laid out a two-phase framework that has since become the de facto inspection standard. If your OOS procedure doesn’t map cleanly to that framework — or if your execution doesn’t hold up when an investigator starts pulling records — you’ll see a 483 observation. Possibly a warning letter.

What 21 CFR 211.192 Actually Requires (and What FDA Reads Into It)

The regulation itself is brief. Laboratory records shall include “a complete record of all data secured in the course of each test,” and any result outside specifications “shall be investigated.” The investigation must extend to “other batches of the same drug product and other drug products that may have been associated with the specific failure.”

That last clause is the one most manufacturers handle poorly. A single OOS result on Batch X is not just a batch-level problem. FDA expects you to ask whether Batches Y and Z — manufactured on the same equipment or the same shift — are also at risk. If your investigation closes at the batch level without a documented assessment of the broader population, an inspector will find it. Every time.

The 2006 guidance adds the structure the regulation doesn’t. It establishes Phase I as a laboratory investigation, focused exclusively on whether the OOS result is attributable to a laboratory error — instrument malfunction, analyst technique, calculation mistake, or sample integrity issue. Phase II kicks in only when Phase I concludes that no assignable laboratory cause exists, and it expands the scope to include the manufacturing process, raw materials, and historical batch data.

Here’s the number that should concern most quality teams: somewhere between 40–60% of OOS investigations we review through our regulatory compliance consulting work are closed at Phase I with language like “analyst error confirmed” — and the supporting documentation wouldn’t survive 10 minutes of inspector scrutiny. The conclusion exists; the evidence trail doesn’t.

Phase I vs. Phase II: Where the Line Blurs and FDA Gets Impatient

Phase I is not a fishing expedition. FDA’s 2006 guidance explicitly warns against what it describes as the “retesting loop” — running a sample repeatedly until a passing result appears, then treating the original OOS as an outlier. The 1993 United States v. Barr Laboratories decision, which still anchors FDA’s OOS framework more than 30 years later, made clear that repeat testing without first establishing an assignable cause is scientifically indefensible. Courts agreed. FDA hasn’t forgotten.

A valid Phase I investigation has four documented checkpoints: instrument calibration and performance at the time of the test, analyst qualification and technique, calculation and transcription accuracy, and sample integrity from collection through analysis. All four must be examined. If none yields a scientifically justifiable assignable cause, you cannot close the investigation there. The handoff to Phase II is mandatory, not discretionary.

Phase II requires a different set of competencies. Batch manufacturing records get pulled. Raw material COAs get cross-referenced against the affected lot. In-process data — blend uniformity, granulation moisture, dissolution profiles — gets compared against historical ranges. Environmental monitoring records sometimes become relevant for sterile products. And the “extend to other batches” requirement hits hardest here: a defensible Phase II investigation may require reviewing 12 to 24 months of process data to determine whether the OOS event represents an isolated occurrence or the visible tip of a process drift.

That data volume is where manual OOS processes break down. A mid-sized pharmaceutical manufacturer producing 300–500 batch records annually, each containing dozens of in-process data points, is generating more information than any investigation team can meaningfully review in the compressed timeframe FDA expects. The investigation gets narrowed. The lookback window shrinks. FDA finds the boundary and asks why you drew it there.

The Five OOS Deficiencies FDA Cites Most Consistently

Reviewing 483 observations and warning letters published between 2022 and mid-2026, the same failure patterns appear across facility types and product categories:

1. Phase I closure without objective evidence of an assignable cause. The investigation reads “analyst error” — but there’s no instrument logbook entry showing a recalibration event, no supervisor observation of the analytical run, no second-analyst verification. The conclusion is asserted; the evidence isn’t there.

2. Invalidating OOS results based on passing retests alone. If three retests pass and the original result fails, that’s not statistical proof the original was wrong. FDA expects a specific, documented laboratory reason for invalidation — not a majority outcome from repeat runs. This is one of the most direct echoes of the Barr Laboratories ruling, and investigators know the case.

3. Failure to extend to other batches in scope. The 211.192 text is explicit. An OOS investigation closed at the batch level, with no documented assessment of whether other lots manufactured on the same equipment or within the same timeframe are affected, will almost always draw an observation. “No other batches impacted” is not a conclusion — it’s a starting point that requires supporting data.

4. OOS investigations aging without documented interim actions. FDA doesn’t publish a hard closure deadline, but investigators read your investigation logbook. An average open time exceeding 45 days — particularly if multiple investigations are simultaneously open — signals a systemic capacity problem. We’ve reviewed firms with 12 open OOS investigations, some stretching past 60 days, with no documented escalation or interim containment decision. Those become exhibit A in the investigator’s narrative.

5. A poorly documented handoff between Phase I and Phase II. The two phases should be logically and chronologically sequential. Phase I rules out lab error; therefore Phase II begins. When the investigation record doesn’t clearly show that sequence — when Phase II appears to have started before Phase I concluded, or both phases are blurred into a single narrative — FDA reads that as a procedural breakdown in your quality system.

How AI-Augmented Analysis Is Changing OOS Investigation Quality

The OOS process has always been documentation-heavy and judgment-intensive. Which makes it a difficult fit for manual, retrospective quality review. By the time a Phase II investigation reaches its conclusion, the analyst who ran the original test may have forgotten details that weren’t captured in real time. Manufacturing has moved on to other priorities. The investigation record becomes a reconstruction rather than a contemporaneous account.

AI-augmented tools are beginning to address this structurally. When a result flags as OOS, decision-support systems can automatically pull the relevant instrument maintenance and calibration records, cross-reference the analyst’s qualification status against the method’s requirements, and check environmental monitoring data for the relevant area and timeframe. Within minutes, the Phase I checklist is partially pre-populated with objective, time-stamped source data — not narrative summaries.

For Phase II, tools like DeepGMP can scan batch manufacturing records across a configurable lookback window and surface correlations between process parameters and the current OOS event. That kind of pattern recognition across hundreds of batch records isn’t feasible manually. An algorithm trained on your own historical process data can identify whether the current excursion correlates with a specific raw material lot, a particular piece of equipment, or a process parameter that has been drifting at the boundary of specification for three months — information that would take a human analyst days to compile, if they looked at all.

The audit implication is significant. FDA investigators evaluating OOS investigations aren’t just reading conclusions — they’re evaluating the quality of the data supporting those conclusions. AI-generated, time-stamped documentation with clear source attribution is materially harder to challenge than a narrative written by a quality technician several days after the investigation began.

That said, AI doesn’t replace scientific judgment, and it shouldn’t. A system that surfaces a correlation between a process parameter and an OOS result isn’t making the determination that one caused the other. A qualified person still has to evaluate the evidence, apply process knowledge, and document the rationale. What AI changes is the scope and speed of the data available to that person — compressing the time-to-data from days to minutes and expanding what’s actually reviewed. Both matter when FDA is assessing whether your investigation was thorough.

Building an OOS Program That Holds Up Under Inspection

A few structural markers that separate programs FDA respects from programs FDA cites:

Your Phase I procedure should specify who conducts the laboratory review and require a second-person sign-off before closure — not just an analyst and a peer, but a supervisor with documented method-specific training. The second reviewer’s role and qualifications should be defined in the SOP, not improvised.

Your Phase II trigger should be automatic when Phase I finds no assignable cause. Not “quality director judgment call.” Not “case-by-case basis.” Automatic. This removes ambiguity from your own records and from what an inspector reads about your system’s design intent.

Your “extend to other batches” assessment needs a documented rationale — a written explanation of how far back you looked and why that window is appropriate. “Reviewed the last 12 months of Batch X manufacturing records; no similar OOS events identified” is far more defensible than “other batches reviewed; no issues found.”

And your open investigation tracking needs internal escalation triggers. If an investigation exceeds 30 days without a documented interim decision, someone at the director level should be formally notified and the record should show it. FDA wants to see that open investigations are actively managed, not accumulating passively while other priorities crowd the queue.

The 21 CFR 211.192 citation rate isn’t declining. If anything, FDA’s scrutiny of investigation documentation — particularly data integrity within investigation records — has intensified over the past three inspection cycles. Getting your OOS program structurally sound, before the next unannounced inspection, is one of the higher-return investments a pharmaceutical quality team can make.


Written by Sam Sammane, Founder & CEO, Aurora TIC | Founder, Qalitex Group. Learn more about our team

Reserve early access to our AI audit tools — including DeepGMP for OOS investigation analysis. Contact us

Hulp nodig bij het kiezen van het juiste laboratorium?

Aurora TIC koppelt fabrikanten en merken aan geaccrediteerde testlaboratoria — snel, gratis en afgestemd op uw product.

Offerte aanvragen