SEO title: Cannabis Documentation and Good Documentation Practice
Meta description: A practical guide to cannabis documentation and Good Documentation Practice, covering ALCOA+, SOPs, batch records, logbooks, document control, data integrity and inspection readiness.
Reading time: 15 minutes
Documentation is the evidence of control
In GMP, documentation is not administration added after the real work is finished. It is part of the control system. If an activity affects product quality, patient safety, traceability, regulatory compliance or batch release, the company needs reliable evidence that the activity was performed correctly, by trained personnel, using approved methods and within defined limits.
This is especially important for medical cannabis companies because the product lifecycle often includes biological starting material, variable active content, microbial and chemical risks, outsourced testing, international supply chains and evolving regulatory expectations. Without strong documentation, even a technically sound process can become difficult to defend during audit, inspection or Qualified Person review.
Good Documentation Practice, often abbreviated as GDocP, is the set of behaviours and controls that make records trustworthy. It supports EU GMP, data integrity, batch release, deviation investigations, change control, validation, supplier qualification and management review. It also protects the business: when records are clear, complete and traceable, decisions become easier to justify.
Why documentation matters in cannabis GMP
Medical cannabis companies may have strong practical knowledge, but GMP requires that knowledge to be translated into controlled instructions and reliable records. A regulator, auditor, QP or corporate partner cannot rely on verbal explanations alone. They need evidence that the system works repeatedly, not just when key individuals are present.
Documentation supports several critical purposes:
- Traceability: linking materials, equipment, personnel, batches, tests, deviations and release decisions.
- Consistency: ensuring activities are performed in the approved way across shifts, teams and sites.
- Accountability: showing who performed, checked, approved or reviewed an activity.
- Investigation: allowing deviations, complaints and out-of-specification results to be reconstructed accurately.
- Validation: proving that systems, equipment and processes were qualified or validated according to approved protocols.
- Batch release: giving QA and QP functions the evidence needed to make defensible release decisions.
- Inspection readiness: demonstrating that the company has control over its operations, not only over its final product.
- Good Documentation Practice (GDP)
In practice, weak documentation is one of the fastest ways for a cannabis company to lose confidence during audit. Missing signatures, uncontrolled forms, backdated entries, unclear corrections, incomplete batch records or unsupported decisions can create doubt about the entire quality system.
ALCOA+ principles
GDocP is closely connected to data integrity. The ALCOA principles are widely used to describe the expected qualities of reliable GMP data: Attributable, Legible, Contemporaneous, Original and Accurate. The extended ALCOA+ principles also include Complete, Consistent, Enduring and Available.
Attributable
It must be clear who performed an activity, who reviewed it and who approved it. Initials, signatures, electronic user IDs and audit trails should be controlled so that accountability cannot be confused or transferred informally.
Legible
Records must be readable throughout their retention period. If a batch record, logbook entry or correction cannot be understood, it cannot reliably support quality decisions.
Contemporaneous
Data should be recorded at the time the activity occurs. Recording later from memory creates risk, especially in activities involving weights, times, temperatures, equipment settings, environmental monitoring, cleaning or batch processing.
Original
The original record, or a certified true copy where applicable, should be preserved. Uncontrolled transcription from notebooks, scraps of paper or informal spreadsheets weakens data integrity.
Accurate
Records should reflect what actually happened. If an error occurs, it should be corrected transparently, with the original entry still visible where appropriate, the correction dated and attributable, and the reason recorded when needed.
Complete, consistent, enduring and available
Records should include all required information, follow a consistent format, remain durable throughout the retention period and be retrievable when needed. This matters for both paper and electronic systems.
Controlled documents versus GMP records
A common source of confusion is the difference between controlled documents and records. Both matter, but they serve different purposes.
Controlled documents tell people what to do. Examples include SOPs, policies, specifications, protocols, methods, forms, master batch records, validation plans and work instructions. They require version control, approval, distribution control, periodic review and retirement of obsolete versions.
GMP records show what was done. Examples include completed batch records, executed cleaning records, logbook entries, training records, deviation reports, change controls, test results, environmental monitoring records, calibration records, executed validation protocols and audit reports. Records should be complete, attributable and protected from unauthorised alteration.
In a mature system, controlled documents and records are connected. A batch record should reference approved procedures and specifications. A cleaning record should refer to the approved cleaning method. A validation report should link back to the approved protocol. This linkage is what turns a document set into an evidence system.
SOP lifecycle
SOPs are often the first documents a cannabis company creates, but they are also easy to overproduce. A good SOP should describe a real process clearly enough for trained personnel to follow it consistently. It should not be a copy of another company's procedure or a theoretical description of what the organisation wishes it did.
The SOP lifecycle normally includes drafting, technical review, QA review, approval, training, effective date, periodic review, revision and retirement. Each step should be controlled.
Drafting
The best SOPs are written with input from the people who perform or own the process. QA should not be expected to invent every operational procedure alone. Production, QC, engineering, validation, warehouse and regulatory functions all need ownership of the procedures that govern their work.
Review and approval
Review should confirm technical accuracy, GMP alignment, role clarity and practical usability. Approval confirms that the document is authorised for use. For critical procedures, approvers should have appropriate authority and competence.
Training and implementation
An SOP should not become effective before relevant personnel are trained. Training may be simple for low-risk administrative procedures, but critical GMP procedures may require practical demonstration, supervisor confirmation or periodic requalification.
Periodic review
Procedures should be reviewed periodically to ensure they remain current. However, periodic review should not be a mechanical date exercise. It should consider deviations, audit findings, changes, process improvements and user feedback.
Batch records
Batch records are among the most important GMP documents because they connect manufacturing activity to product disposition. For cannabis products, batch records may include cultivation or harvest references, incoming material details, extraction or processing steps, equipment used, critical process parameters, yields, reconciliation, in-process controls, packaging details, deviations, sampling, testing and QA review.
A good batch record should be clear enough to guide execution and detailed enough to reconstruct the history of the batch. It should avoid unnecessary complexity, but it must capture critical information. If a parameter matters to quality, it should be recorded in a controlled way.
Common batch record weaknesses include incomplete fields, unapproved handwritten changes, unexplained yield differences, unclear equipment identification, missing line clearance evidence, poor reconciliation, late entries and deviation references that do not match the investigation record.
Batch record design is also important. Poorly designed records create errors. If operators repeatedly miss fields or write comments to explain confusing instructions, the form may need redesign rather than repeated retraining.
Logbooks, forms and templates
Logbooks provide continuity of use for equipment, rooms, utilities and recurring activities. They may record equipment operation, cleaning, maintenance, calibration checks, room use, temperature monitoring, balance use, environmental monitoring setup or other routine GMP activities.
Forms and templates standardise recurring records. Examples include cleaning records, line clearance forms, material receipt checks, deviation forms, change request forms, training records, risk assessments and supplier evaluation forms.
These documents should be controlled like any other GMP documentation. Uncontrolled forms are a common weakness. If personnel print old templates from local drives or reuse unofficial forms, the company loses control over what information is captured.
The best forms are designed around the decision they need to support. A deviation form should help investigators understand what happened and what risk exists. A change control form should help the company assess impact before implementation. A training record should help demonstrate competence, not just attendance.
Electronic documentation and hybrid systems
Many cannabis companies operate hybrid systems: paper batch records, Excel trackers, shared drives, e-signature tools, LIMS outputs, equipment printouts and cloud-based QMS platforms. Hybrid systems can work, but they need clear rules.
Important questions include:
- Which record is the official record?
- Who can create, edit, approve or delete documents?
- Are user access rights controlled?
- Are audit trails available and reviewed where needed?
- How are electronic signatures controlled?
- How are backups and retention managed?
- How are spreadsheets protected from uncontrolled changes?
- How are printouts linked to the batch or activity?
Electronic systems that support GMP decisions may require validation or documented assurance that they are fit for intended use. The level of control should be proportionate to the risk and the system's impact on quality decisions.
Companies should be especially careful with uncontrolled spreadsheets. A spreadsheet used for informal planning is not the same as a spreadsheet used to calculate release results, trend deviations or manage stability commitments. Where spreadsheets support GMP decisions, controls over formulas, access, versioning and review become important.
Common documentation mistakes in cannabis companies
- Too many SOPs, not enough process design. Procedures multiply, but the process remains unclear.
- Copied documents. Templates from pharmaceutical companies are used without adapting them to the cannabis process or company size.
- Uncontrolled forms. Teams use old versions, local copies or informal spreadsheets.
- Backdated entries. Records are completed after the event instead of contemporaneously.
- Weak corrections. Errors are overwritten, obscured or corrected without date, initials or reason.
- Missing traceability. Records do not clearly link materials, equipment, personnel, room, time, batch and test result.
- Training records without competence. Signatures exist, but there is no evidence the person can perform the task correctly.
- Document control without ownership. QA controls the archive, but process owners do not maintain content quality.
- Electronic systems treated as automatically compliant. A cloud system does not guarantee data integrity unless configuration, access and use are controlled.
A practical documentation implementation roadmap
- Map the document hierarchy. Define policies, SOPs, forms, records, protocols, reports, specifications and master documents.
- Identify critical GMP records. Prioritise batch records, cleaning records, training records, deviations, change controls, QC records and validation records.
- Define document control rules. Set expectations for numbering, versioning, approval, effective dates, periodic review and archival.
- Train personnel in GDocP. Cover real examples such as corrections, late entries, blank fields, signatures, dates and attachments.
- Redesign high-error forms. If forms repeatedly generate mistakes, improve the form instead of only retraining users.
- Control electronic storage. Define where official documents and records are stored, who has access and how changes are controlled.
- Audit documentation routinely. Review completed records for legibility, completeness, contemporaneous entries and traceability.
- Trend documentation errors. Repeated errors may indicate training gaps, poor form design, unrealistic procedures or workload issues.
Frequently asked questions
Is Good Documentation Practice the same as data integrity?
They are closely connected but not identical. GDocP focuses on how documents and records are created, completed, corrected, controlled and retained. Data integrity is broader and includes the trustworthiness of all data, including electronic data, audit trails, calculations and system controls.
Do small cannabis companies need formal document control?
Yes, if they are operating in or moving towards GMP. The system can be simple, but it still needs version control, approval, effective dates and control of obsolete copies.
Can we use Excel for GMP records?
Excel may be acceptable for some controlled uses, but the risk depends on the function. Spreadsheets used for GMP decisions may require protection, version control, formula checks, access control and review.
What is the biggest documentation risk?
The biggest risk is not usually one missing signature. It is a pattern of unreliable records that makes the company unable to reconstruct what happened or justify quality decisions.
Should SOPs be very detailed?
They should be detailed enough to ensure consistent execution by trained personnel. Excessive detail can make procedures hard to follow, while too little detail can create variation. The right level depends on task risk and personnel competence.
Key takeaways
- Documentation is part of GMP control, not an administrative extra.
- GDocP and ALCOA+ principles help ensure records are reliable, traceable and inspection-ready.
- Controlled documents tell people what to do; records prove what was done.
- Batch records, logbooks, forms and electronic records should be designed around quality decisions.
- Strong documentation supports deviations, CAPA, validation, QP review and continuous improvement.
References
- European Commission, EudraLex Volume 4, Chapter 4: Documentation.
- European Commission, EudraLex Volume 4, Chapter 1: Pharmaceutical Quality System.
- European Commission, EudraLex Volume 4, Annex 11: Computerised Systems.
- MHRA guidance on GxP data integrity expectations.
- WHO guidance on good data and record management practices.
What to do next
If your documentation system is not yet mature, start with the free GMP Lite Assessment, then use the documentation checklist to identify the highest-risk gaps before building a full document control system.
Take GMP LiteNext: CAPA Explained