Written and maintained by CASRAI Editorial Board
Last updated
A GxP training programme that consists of one generic onboarding deck and a shared read-and-understand folder will not survive an inspection. Every GxP framework — Good Manufacturing Practice, Good Laboratory Practice, Good Clinical Practice — ties personnel qualification directly into the regulation itself, not into a separate HR policy. 21 CFR Part 11 makes electronic training records subject to the same integrity requirements as any other GxP record, and an inspector who finds a training gap treats it the same way as a missing signature on a batch record: as a system failure, not a paperwork oversight.
This guide covers what an auditor actually checks — the regulatory basis for training as a personnel-qualification requirement, how to build a curriculum around what a QA, production, or lab role each actually does rather than one shared course, which delivery method fits which task, how to prove a person can do the task rather than just that they sat through material, and what a training record has to contain to survive being pulled at random three years later.
The regulatory basis: training is a personnel-qualification requirement, not a courtesy
Every major GxP framework states this the same way, just in different section numbers. 21 CFR 211.25 (GMP personnel qualifications) requires that everyone involved in manufacturing, processing, packing, or holding a drug product have “education, training, and experience, or any combination thereof, to enable that person to perform the assigned functions,” and specifically that training be given “in the particular operations that the employee performs and in current good manufacturing practice… conducted by qualified individuals on a continuing basis and with sufficient frequency to assure that employees remain familiar with CGMP requirements applicable to them.” 21 CFR 58.29 (GLP personnel) requires the same education/training/experience standard for anyone conducting or supervising a nonclinical laboratory study, and adds a specific documentation requirement: the facility must maintain “a current summary of training and experience and job description for each individual.” ICH E6(R2) states the GCP version of the same principle at Principle 2.8: “Each individual involved in conducting a trial should be qualified by education, training, and experience to perform his/her respective task(s).”
Three things follow directly from that shared structure, and they are the three things a programme built as a generic course misses:
- Training has to be tied to the specific function a person performs, not to their job title in the abstract. 211.25 says “in the particular operations that the employee performs” — a training record that just says “GMP training completed” with no reference to which procedures or tasks doesn’t answer the question an inspector asks.
- “Current” is a standing requirement, not a one-time event. 58.29’s “current summary” language and 211.25’s “continuing basis” language both assume the record gets updated as a person’s duties, and the procedures governing them, change.
- The training has to be documented well enough to reconstruct — not just that training happened, but what was trained, against which document version, and by whom.
See CASRAI’s GxP compliance overview for how these frameworks relate to each other more broadly; this guide stays specifically on the training-programme design question.
Build the curriculum from the role, not from a template
The most common structural mistake is designing one core GxP course and layering role-specific add-ons on top, when the underlying requirement (211.25’s “particular operations that the employee performs”) actually points the other direction: curriculum should start from what the role does and build outward, with only the genuinely universal material (site GxP fundamentals, data integrity basics, code of conduct) shared across roles. In practice this means maintaining a role-to-procedure training matrix — a table mapping each job role to the exact list of SOPs, work instructions, and competency checks it requires — rather than a fixed curriculum a new curriculum owner has to remember to update by hand.
QA role
QA training centers on judgment and system oversight rather than task execution: deviation handling and escalation criteria, CAPA process steps and how to distinguish a real corrective action from a correction, root-cause analysis technique selection, batch/record review authority and what makes a review defensible, ALCOA+ data integrity principles applied at the review stage (not just the generation stage), audit-trail review responsibilities, and change-control impact assessment. QA also typically needs training on the site’s document control procedure itself, since QA is usually the function that owns document approval and effective-date management.
Production / manufacturing role
Production training is task- and equipment-specific: the exact SOPs and work instructions for the equipment and process steps the person actually operates, in-process control checks and their acceptance criteria, line-clearance procedure, contemporaneous documentation practice (recording at the time the work is done, not from memory afterward), and deviation reporting — recognizing and escalating an unexpected result — which is a materially smaller scope than the deviation investigation training QA needs. Gowning and aseptic technique training belongs here when the role touches a controlled or classified area, and is one of the clearest cases in this guide for assessed rather than read-and-understand delivery (see below).
Lab / analytical role
Lab training is method- and instrument-specific: the analytical methods and SOPs the analyst actually runs, instrument operation tied to that instrument’s qualification status (an analyst shouldn’t be trained to operate equipment that hasn’t completed IQ/OQ/PQ), out-of-specification and out-of-trend result handling, sample chain-of-custody, and — where the lab uses a chromatography data system, LIMS, or other GxP computerized system — the system-specific training that 21 CFR Part 11 effectively requires alongside the method training itself, since an analyst untrained on audit-trail review or e-signature meaning in the software is not fully trained on the method.
A person moving between roles, or picking up a second role, is retrained against the new role’s matrix entry — the matrix, not the individual’s memory of what they’ve previously covered, is the record of what training is actually still required.
Choosing the delivery method: read-and-understand, instructor-led, or assessed
Not every SOP needs the same training intensity, but the three tiers are not interchangeable, and picking the wrong one for a given task is a recurring inspection finding:
- Read-and-understand (R&U) — the trainee reads the document and signs an acknowledgment. Appropriate for low-risk, low-complexity procedures with an established track record and infrequent revision, and for minor administrative revisions to a procedure the person is already qualified on. Not appropriate as the sole method for a task where a mistake creates GxP risk — R&U proves exposure to the text, not comprehension or competence.
- Instructor-led (classroom or virtual) — appropriate for new-hire onboarding, complex or multi-step procedures, procedures with a history of deviations or CAPAs traced back to a training gap, and any material that benefits from Q&A with a subject-matter expert before the trainee is expected to perform the task independently.
- Assessed / competency-based — a written test, a practical demonstration under observation, or both, with a documented pass criterion. This is the method for anything where R&U alone cannot demonstrate the person can actually do the task correctly: aseptic technique, complex analytical methods, audit-trail review, electronic signature use, and any task directly tied to a prior deviation or CAPA. Competency-based training is also the method that produces a defensible answer to the auditor question “how do you know this person can actually do this,” rather than only “how do you know this person was exposed to the material.”
Assigning the delivery tier is itself a documented decision that belongs in the training matrix or an associated training-needs assessment, not an ad hoc call made by whoever happens to be running the training that week — consistency here is part of what makes the programme defensible.
Training before the effective date, not after
CASRAI’s document control procedure guide covers this from the document-control side: the gap between a document’s approval date and its effective date exists specifically so affected staff can be trained before the new or revised version governs their work, and setting an effective date without confirming training actually completed first is a common finding in its own right. From the training-programme side, this means the training matrix has to be the trigger for a document’s effective date, not the other way around — when a procedure is revised, the change-control or document-control process should identify every role in the matrix that requires retraining, and the effective date should not be set until a realistic training-completion date for that group is known. A revised SOP going into effect on a date nobody was actually trained by is functionally the same failure as never training the affected staff at all.
Verifying training effectiveness, not just attendance
A signature on a training log answers “did this person encounter the material,” not “can this person do the task.” A programme that stands up to inspection has a separate, documented mechanism for the second question, matched to the delivery tier chosen above:
- For assessed training, the pass/fail result and score (where applicable) is itself part of the effectiveness record.
- For instructor-led training on a task with hands-on execution, a direct-observation competency checklist — a qualified observer confirms the person actually performs each critical step correctly, signed and dated — is the standard mechanism.
- For lower-risk R&U material, effectiveness verification can be lighter (a short comprehension check), but “none at all” is the gap auditors flag most often on R&U-heavy programmes.
Effectiveness checks also have to run on a periodic basis, not only at initial qualification: a defined requalification or refresher cadence for high-risk tasks, and specific retraining triggers that fire outside the normal cycle — an SOP revision, a deviation or CAPA whose root cause traces back to a training gap, or an extended absence from performing the task. A CAPA that identifies “operator error” and closes with generic “retraining” as the corrective action, with no update to what specifically changed in the training content or delivery method, is itself a finding — retraining on the exact same material that didn’t prevent the error the first time is not a corrective action.
What a training record has to contain
The record an auditor pulls at random has to answer, on its own, without anyone’s memory filling in gaps:
- Which specific document (SOP, work instruction, protocol) and which version/revision number the training was against.
- Which delivery method was used (R&U, instructor-led, assessed) and, for assessed training, the result.
- Who delivered or verified the training, and that person’s own qualification to do so — 211.25 requires GMP training to be “conducted by qualified individuals,” so the trainer’s own credentials have to be traceable too.
- The completion date, and specifically that it precedes the document’s effective date.
- A durable link to the person and role at the time of training — a training matrix that isn’t version-controlled itself becomes unreliable as roles and procedures change under it.
Retention periods follow the underlying regulation, not a single universal number. Under GMP, 21 CFR 211.180 requires production, control, and distribution records to be retained “at least 1 year after the expiration date of the batch” (or, for products without expiration dating, at least 3 years after distribution), and specifically allows records to be stored remotely if they “can be immediately retrieved from another location by computer or other electronic means” — relevant if training records live in an LMS rather than on paper at the site. Under GLP, 21 CFR 58.195 sets retention at the longer of roughly 2 years past FDA approval, 5 years past submission of study results, or 2 years past study completion for studies never submitted — and explicitly extends the same retention timeline to quality assurance records, training summaries, and equipment maintenance and calibration documentation, not just raw study data. In practice, most sites retain training records for the individual’s full tenure plus the retention period of the last record type their training supported, since a training record can be relevant evidence years after the training itself occurred.
Common findings this structure prevents
- A generic “GMP training” record with no reference to which specific SOPs or tasks it covered.
- Read-and-understand used as the sole method for a high-risk task (aseptic technique, complex analytical methods, e-signature/audit-trail use).
- No effectiveness check beyond a signature, for any delivery tier.
- SOP effective dates set before affected staff completed training against the new version.
- No defined mechanism for identifying who needs retraining when a procedure changes.
- Training records that cannot be retrieved within the retention window, or that don’t survive an LMS migration with their audit trail intact.
Frequently asked questions
How often does GxP training need to be renewed?
The regulations themselves don’t set a fixed interval — 211.25 requires GMP training “on a continuing basis and with sufficient frequency” to keep employees current, which is a risk-based standard, not a calendar rule. In practice, sites define a periodic refresher cadence (commonly annual for core GxP/data-integrity fundamentals) plus event-driven retraining triggers: an SOP revision, a training-related deviation or CAPA, or an extended absence from the task.
Is read-and-understand training enough for GMP compliance?
It’s acceptable for the lower-risk end of the curriculum — stable, low-complexity procedures with no history of deviations — but not as the sole method for a task where an error creates GxP risk. 211.25’s standard is that training enable the person to actually “perform the assigned functions,” and R&U alone doesn’t demonstrate that for a complex or high-risk task.
How long do GxP training records need to be kept?
It depends on which regulation governs the underlying work: GMP records generally follow 21 CFR 211.180’s retention period (at least 1 year past the relevant batch’s expiration date), while GLP training summaries explicitly follow 21 CFR 58.195’s retention schedule alongside the study data they support. Most sites retain training records for an employee’s full tenure plus the applicable regulatory retention period, since a training record can become relevant evidence long after the training itself took place.
Who is allowed to deliver GxP training?
21 CFR 211.25 requires GMP training to be “conducted by qualified individuals” — the regulation doesn’t specify a credential, but the trainer’s own qualification to teach the specific material has to be documented and traceable, the same way the trainee’s qualification is. A subject-matter expert who has never been qualified as a trainer, or who is training on a procedure they aren’t themselves currently qualified on, is a gap an inspector can find quickly.
What happens if someone performs a GxP task before completing the required training?
It’s treated as a deviation in its own right, separate from any error the untrained work might have caused — the work performed during that gap is typically subject to a documented impact assessment (was anything produced, tested, or recorded during the gap, and does it need review or requalification), and the root cause has to address why the training-before-work control failed, not just retrain the individual after the fact.








