Back to Blogs
Mindlabs Insights

Who Changed This Setpoint? The Audit Question Failing Good Pharma Plants

A fully wired, real-time monitoring system can still pick up a non-conformity. Not for a missing reading — for something quieter. Here's the audit shift QA teams are catching up to.

2026-08-03Mindlabs Team8 min read
Who Changed This Setpoint? The Audit Question Failing Good Pharma Plants

"Who Changed This Setpoint?" — The Audit Question Failing Good Pharma Plants

Why a fully wired, real-time monitoring system can still fail a Schedule M audit

If you run quality at a pharma plant, you already know the audits changed. It used to be enough to have the records — pull up the temperature logs, show the trend, done. Now the auditor turns the question around, and it catches good teams off guard.

A plant we know found this out the hard way. Their environmental monitoring was solid: fully wired, every cold room and chamber covered, temperature and humidity logged around the clock, real-time alerts going to the right people. On paper, exactly what a modern plant should have. And at their last audit, they still picked up a non-conformity.

Not for a missing reading. Not for a broken sensor. The auditor pointed at the monitoring system and asked one question: "This alarm setpoint — who changed it, and when?" And the room went quiet.

This article is about that question, why it has quietly become one of the most exposed points in Indian pharma manufacturing, and what "audit-ready" actually means now.

Industry Insight

Revised Schedule M became the binding legal requirement for all drug manufacturers in India from January 1, 2026. Regulators have been explicit: no further extensions, inspections are underway, and non-compliant units face suspension of manufacturing licences.

The shift: from "do you have records?" to "can you prove they're trustworthy?"

For years, Schedule M was read as a documentation exercise. Keep the logs, file the paperwork, be ready to produce it. The revised Schedule M — notified in December 2023 and now in force — changes the standard in a way many teams underestimate.

It no longer grades you only on whether records exist. It grades you on whether those records can be trusted. That shift is built directly into the text: revised Schedule M explicitly brings computerised systems and ALCOA+ data integrity into Indian GMP, requiring validated systems, controlled access, and meaningful audit trails, aligned with global CSV principles.

In plain terms, the question moved from "Show me the data" to "Prove nobody could have quietly changed it." And a surprising number of otherwise-strong monitoring systems have no good answer.

Why the setpoint question is so dangerous

A temperature reading is easy to show. A record of who changed the settings behind that reading is a different thing entirely — and it's where manual and semi-automated systems fall apart.

Think about how setpoints actually get changed on a plant floor. Over the years, someone adjusts an alarm threshold. A validation engineer nudges a limit during a study. A shift supervisor widens a band to stop nuisance alarms. Each change was probably justified at the time. But if the system captured the value and not the event — who made the change, when, and why — then there is nothing to show an auditor later.

That gap is precisely what the revised framework targets. A computerised storage system for recording data is now effectively mandatory, and it must carry an audit trail that captures every modification, the person responsible, and the date and time of the change. If your system logs temperature beautifully but treats a setpoint change as an invisible, untracked event, you have a data-integrity gap hiding in plain sight.

Real Data Insight

Data integrity — particularly around audit trails, electronic records, and computerised systems — is the most consistently cited category of non-compliance in FDA observations issued to Indian manufacturers. Recurring violations include inadequate audit trails and shared instrument access credentials.

"We have monitoring" is no longer the bar

Here's the uncomfortable part for a well-run QA team: a big, wired, real-time system can miss every one of the new expectations — not because it's neglected, but because it was built to log data, not to account for who touched it.

On that specific test, an expensive modern system can fail the same way a paper logbook would. Both can show you a number. Neither can prove, on its own, who changed the settings that produced it. The revised Schedule M closes exactly this loophole, which is why "we have monitoring" has stopped being a sufficient answer at inspection.

Reading the framework against a typical monitoring setup, four expectations stand out as the ones that catch teams:

A secure, tamper-evident audit trail on every configuration and setpoint change. Not just the reading — the change to the thing that governs the reading, captured automatically with who, when, and why.

Controlled, attributable access. The system must know who did what. Shared logins and generic administrator accounts are a recurring source of findings, and they collapse attributability the moment an auditor asks.

Documented, periodic trend review. It is no longer enough to collect data. There must be evidence that someone reviewed it on a defined frequency — not data that only surfaces when an inspector asks for it.

Data integrity aligned to ALCOA+. Records must be attributable, legible, contemporaneous, original, and accurate — and, just as importantly, complete, consistent, enduring, and available on demand. Manual and hybrid systems tend to pass the first five and quietly fail the rest.

Self-inspection is now the point

There's a second shift that compounds the first, and it's easy to miss. Revised Schedule M requires robust self-inspection and internal audit programmes — sites are expected to identify and correct their own weaknesses proactively, not wait for CDSCO or state inspectors to point them out.

That changes what a monitoring system is for. If you can't easily surface your own gaps — an unlogged setpoint change, an overnight drift, a stretch of data nobody reviewed — then your self-inspection can't find them either. A system that only produces data on demand makes honest self-inspection almost impossible. A system that continuously surfaces trends and changes makes it routine.

This is also why regulators increasingly describe weak or cosmetic self-inspection as a root cause of recurring findings. The plant that can answer "who changed this setpoint six months ago" instantly is usually the same plant whose self-inspection actually works.

What audit-ready monitoring looks like

Closing this gap does not require ripping out your facility or requalifying your process. Environmental monitoring is an add-on layer, not a rebuild — it sits on top of the cold rooms, chambers, and warehouses you already run, regardless of how old they are.

The difference between a system that fails the setpoint question and one that passes it is architectural:

Mindlabs Monitoring Devices for Audit-Ready Compliance

Mindlabs Anchor (Facility Monitoring)

Mindlabs Anchor - Facility Monitoring Device

Mindlabs Anchor provides continuous temperature and humidity monitoring for pharmaceutical cold rooms, warehouses, and laboratories — built around exactly the requirements Schedule M now grades on.

  • Tamper-evident audit trail for every setpoint, threshold, and calibration change — who made it, when, and why
  • Individual, attributable user access — no shared logins
  • Trends and alerts surface automatically on the cloud dashboard, so periodic review happens on its own

Learn more about Mindlabs Anchor

Industry Insight

The goal isn't to log more data. Logging everything proves you're monitoring. Proving who changed what is what actually passes the audit — and it's the specific thing manual and semi-automated systems can't do.

A practical path to audit-ready

You don't have to become fully system-driven everywhere overnight. A realistic rollout looks like this.

Start with your highest-risk rooms. Begin with the storage areas holding your most sensitive or highest-value product — prove the audit trail where a finding would hurt most.

Layer over existing equipment. Deploy wireless sensors on the chambers and cold rooms you already run. No conduit, no line disruption, no process requalification.

Make the audit trail non-optional. Ensure every setpoint and configuration change is captured automatically, with individual logins — the two failures inspectors probe first.

Build the review habit. Use automatically surfaced trends to establish documented, periodic review — the evidence Schedule M expects and the thing manual systems consistently miss.

The bottom line

The audits changed the question, and a lot of good plants haven't caught up. It's no longer "Do you have the records?" It's "Can you prove they're trustworthy?"

An excursion, you can catch. A missing reading, you can explain. But a setpoint someone changed with no record? There's no talking your way out of that one. So it's worth asking honestly about your own plant: if an auditor walked in tomorrow and asked who changed a setpoint six months ago — would your system have an answer?

Conclusion

Logging everything used to feel like enough. Under revised Schedule M, it isn't. The standard is no longer whether data exists, but whether you can prove — down to the setpoint — who touched it, when, and why. The good news is that closing this gap doesn't require a new plant or a disruptive overhaul. It requires the right layer: continuous monitoring with a tamper-evident audit trail on every change, attributable access, and trends that surface on their own so review actually happens. That's the difference between "we have monitoring" and "we can prove it" — and only one of them passes the audit.

See how Mindlabs' 21 CFR Part 11 compliant monitoring maps directly to this standard, clause by clause.

Wondering whether your current setup could answer the setpoint question? Talk to the Mindlabs team about layering audit-ready monitoring over your existing facility — without the overhaul.

MT

Written by

Mindlabs Team

Sharing practical guidance on IoT monitoring, cold chain visibility, and compliance for regulated industries.

Keep Reading

Related Blogs

View All Blogs

Ready to Transform your Monitoring?

IoT-powered monitoring that ensures quality, compliance, and control across storage, manufacturing, and transit.