Evidence-backed answers
Training Records During Validation FAQs
20 questions covering who needs training, what records must contain, mid-project gaps, and inspection expectations.
Section 01
Who needs training, and when
Which roles require documented training before touching a validation activity, and who is responsible for checking training status before execution begins.Can someone execute a validation protocol if their SOP training record isn't up to date?
No — a person whose training record on the relevant SOP or protocol is not current should not execute, review, or approve steps in a validation activity, because their signature implies they were qualified to perform the work at the time they performed it.
If this is discovered after the fact, the usual response is a deviation covering the affected steps, a retrospective training-currency check, and a QA-led assessment of whether the results are still credible or need re-execution by a currently trained person.
Does everyone who signs a validation protocol need formal training, or just the person executing the tests?
Everyone whose signature appears on a validation protocol — executor, reviewer, and approver — needs documented training appropriate to their role, not only the person physically performing the test steps.
- Executors need training on the specific test method, equipment, or software being used.
- Reviewers need training on the acceptance criteria and how to identify a deviation.
- Approvers need training on the validation lifecycle and their sign-off authority under the site quality system.
Do contractors and temporary staff need the same training documentation as employees before executing validation activities?
Yes — contractors and temporary staff must have training records equivalent in content and rigor to employees' before they execute, review, or approve any GxP validation activity; employment status does not lower the training bar.
In practice this is usually documented through the contracting company's own training records, cross-referenced and verified by the host site, or through host-site-delivered onboarding training completed before the contractor is added to the approved signatory list for the project.
What's the difference between being "trained" and being "qualified" to execute validation activities?
Training documents that a person has completed the required instruction on an SOP, system, or method; qualification is the broader confirmation — usually including demonstrated competence, not just attendance — that the person can reliably perform the activity to the required standard.
A training record alone, such as a signature confirming a course or SOP was read, is often treated as necessary but not sufficient for high-risk activities. Many quality systems require an additional competency check, such as a supervised first execution, before someone is added to the approved executor list.
Who is responsible for checking training currency before a protocol execution starts — QA, the trainer, or the executor?
The executor is responsible for confirming their own training is current before starting, but QA is accountable for having a system — typically a training matrix or LMS check — that catches it if someone starts work without current training.
Relying solely on individual self-certification is a common gap; the more robust control is a training-status check built into protocol issuance itself, so a protocol cannot be released for execution to someone whose training record shows a gap.
Section 02
What the training record must actually contain
The minimum content, SOP-version linkage, and format expectations that make a training record credible evidence during an inspection.Does a training record need to reference the exact SOP version, or just the SOP title?
A training record should reference the exact SOP version and effective date, not just the SOP title, because training on an outdated version does not demonstrate competence on the procedure actually in effect when the validation activity was performed.
This matters most when an SOP has been revised between when someone was trained and when they executed a protocol. Without the version reference, an inspector cannot confirm the person was trained on the process they actually followed.
What's the minimum content a training record needs to survive inspection scrutiny?
An inspection-ready training record should let a reviewer confirm exactly who was trained, on what document and version, by what method, when, and who verified the training was effective.
- Trainee name and role.
- SOP, method, or system name and version or effective date.
- Training method: read-and-understand, classroom, on-the-job, or assessment-based.
- Date training was completed and, if applicable, when it becomes due for refresh.
- Signature or system confirmation of the trainee and, where required, the trainer or approver.
Do auditors expect training records to reference the specific protocol someone executed, or just general curriculum completion?
Auditors increasingly expect a traceable link between an individual's training record and the specific protocol they signed, not just evidence that a general curriculum was completed at some point in the past.
The strongest position is a training matrix that maps each person to the specific SOPs and systems relevant to the protocols they are approved to execute, checked at the point of protocol issuance rather than reconstructed after the fact when an inspector asks.
How should on-the-job training for validation execution be documented so it holds up as evidence?
On-the-job training should be documented with the trainee's name, the trainer's name, the specific task or system covered, the date, and a statement of how competence was confirmed — such as supervised execution of a representative test step — not just a general note that shadowing occurred.
Can training records be fully electronic, or is a wet-ink signature still expected anywhere?
Training records can be fully electronic provided the system meets 21 CFR Part 11 and EU GMP Annex 11 requirements for electronic signatures — unique user identification, an audit trail, and a controlled link between the signature and the specific record. A wet-ink signature is not required by regulation once those controls are in place.
Section 03
Handling training gaps and mid-project SOP changes
What to do when an SOP changes mid-project, a training gap is discovered after execution, or too much time has passed since training was completed.What happens if an SOP changes in the middle of an ongoing validation project — does everyone need retraining before continuing?
If an SOP is revised mid-project in a way that affects how the remaining protocol steps must be performed, everyone still executing, reviewing, or approving those steps needs to be retrained on the new version before continuing; steps already completed under the prior, correctly-trained version generally do not need to be redone.
The change control record for the SOP revision should explicitly assess and document this impact on any in-flight validation activities, rather than leaving it to individual discovery partway through a protocol.
Can training be completed retroactively to fix a documentation gap discovered after a protocol was already executed?
Retroactive training can close the documentation gap going forward, but it cannot retroactively qualify the person for the work they already performed — the correct response is a deviation assessing whether the already-executed steps are still scientifically valid despite the training gap, not backdating a training record.
What triggers a need for retraining during a validation project that's already underway?
Retraining is typically triggered by an SOP or method revision, a deviation traced back to a training or competence gap, a significant time gap since the person last performed the activity, or the person moving to a new system, equipment, or role within the project.
- The governing SOP or test method is revised.
- A deviation investigation identifies a training or competence gap as a root cause.
- A long gap since the person last performed the activity, per the site's training-currency policy.
- A new system, module, or equipment variant is introduced into the project scope.
Is there a maximum allowed gap between completing training and executing the protocol it covers?
No universal regulatory limit exists, but most quality systems set an internal training-currency period — commonly one to two years for general SOP training — after which a refresher is required before the person can be listed as an approved executor.
What happens if a deviation is found and the person who executed the step turns out to have a training gap?
The deviation investigation should explicitly assess whether the training gap contributed to the deviation, document the corrective action — typically completing the training and updating the training matrix — and evaluate whether other work performed by that person during the gap period needs a similar review.
A single training gap traced to one deviation often prompts a broader look-back: has this person executed other protocols during the same gap window that also need reassessment? Scoping that look-back correctly is usually the harder part of the corrective action, not completing the missed training itself.
Section 04
Retention, scope, and inspection expectations
How long training records must be kept, whether documentation requirements scale with GAMP category, and what inspectors actually check.How long must training records supporting a validation activity be retained?
Training records supporting a validation activity should be retained for at least as long as the records generated by the activity itself, and in many organisations for the individual's full employment period plus a defined period after — commonly aligned to the site's document retention policy rather than a fixed regulatory number.
Do GAMP 5 category 3 (off-the-shelf) and category 5 (custom/bespoke) systems require different levels of training documentation?
Yes — higher-risk, more complex systems under GAMP 5 category 5 generally warrant deeper, more system-specific training documentation than lower-risk category 3 off-the-shelf systems, because the complexity of custom functionality creates more ways for an inadequately trained user to introduce error.
For category 3 systems, standard vendor training plus site SOP training is often sufficient. For category 5 systems, training curricula typically need to address the specific configuration, custom code, and workflows unique to that implementation, which a generic vendor course will not cover.
What training is required before someone can review or approve a validation deviation?
A deviation reviewer or approver needs documented training on the site's deviation management SOP, root cause analysis principles, and the validation lifecycle context of the system involved — not just general validation training.
This is a frequently missed training category: organisations often train people thoroughly to execute protocols but overlook the separate training needed to critically assess a deviation and judge whether proposed corrective actions are adequate.
Does training documentation need to be maintained separately for each system, or can one curriculum cover multiple systems?
One training curriculum can cover multiple systems where the underlying procedure genuinely is the same across them, but each system-specific element — configuration, custom workflows, or system-unique risks — needs its own documented training rather than being assumed to be covered by a generic SOP course.
A common shortfall is treating a single "computerised systems overview" training as sufficient for every GxP system a person touches, when high-risk systems actually need dedicated, system-specific training beyond that baseline.
What do inspectors actually check when they review training records tied to a validation project?
Inspectors typically pick a signed protocol at random, trace every signatory back to their training record, confirm the training predates the execution date and matches the SOP version in effect at the time, and check whether the training itself was verified as effective rather than just attended.
A frequent finding is a training date that comes after the execution date, or a training record referencing a superseded SOP version — both immediately raise questions about whether the person was actually qualified to perform the work they signed for.