Skip to content
CellHood
← Back to the journal
Lab practice15 min read

How to Maintain Compliance and Quality in Cell Culture: A Practical Guide

Build quality into the way culture work is planned and recorded.

A failed regulatory inspection rarely comes down to bad science. More often, it comes down to a missing signature, an undocumented deviation, or a passage record that nobody can trace back to its source. Cell culture compliance is not just about doing the right things in the lab; it is about being able to prove you did them, every time, to anyone who asks.

The stakes are significant. According to a review published in Frontiers in Public Health, Good Manufacturing Practices (GMP) require that medicinal products, including cellular therapies, consistently meet predefined standards for identity, strength, quality, and purity. For teams working towards clinical translation or regulatory submission, a quality system is not optional infrastructure; it is the foundation the entire programme rests on.

This guide covers the core pillars every cell culture team needs to address:

  • Regulatory frameworks: GLP, GMP, and GCCP — what applies to your work

  • Documentation and data integrity: the ALCOA+ standard and what it means in practice

  • Quality control: contamination prevention, cell line authentication, and in-process testing

  • SOPs and training: how to write and maintain procedures that actually get followed

  • Deviation management and CAPA: turning problems into process improvements

  • Digital tools and audit trails: moving beyond paper-based records

Key principle: Quality in cell culture is not a checkpoint at the end of an experiment. It is a continuous system built into every step, from thaw to harvest.

Step 1: Understand Which Regulatory Framework Applies to Your Work

Not all cell culture work is governed by the same rules. The framework that applies depends on your setting, your end use, and your regulatory jurisdiction. Getting this wrong at the outset creates costly rework later.

The Three Main Frameworks

Framework Full Name Applies To
GLP Good Laboratory Practice Non-clinical safety studies submitted to regulators (FDA, EMA, OECD)
GMP Good Manufacturing Practice Products intended for human use, clinical trials, commercial manufacture
GCCP Good Cell and Tissue Culture Practice Research and academic cell culture; the baseline standard for all labs

GLP is the standard for non-clinical safety studies. If your cell culture work feeds into a regulatory submission, OECD GLP guidelines govern how you design facilities, train staff, and manage data.

GMP applies when your output is destined for human use. The EU implements a combined GMP/GLP approach for products entering clinical trials, covering continuous monitoring of culture conditions, contaminant control, and full traceability of materials. In GMP environments, cleanrooms must meet ISO 14644 classification standards, with Grade A/ISO 5 conditions required for the highest-risk aseptic operations.

GCCP is the baseline for all cell culture work, regardless of setting. The GCCP 2.0 guidance document establishes six operational principles: understanding your system, using appropriate materials and methods, documenting everything, protecting people and the environment, complying with laws and ethics, and providing adequate training.

Why This Distinction Matters

A research team in an academic setting may only need to meet GCCP. A CRO supporting IND-enabling studies must satisfy GLP. A biotech manufacturing a cell therapy for a Phase I trial is operating under GMP. The documentation burden, facility requirements, and audit expectations differ significantly across these tiers.

The practical starting point: identify your regulatory context before designing your quality system. Retrofitting GMP-level documentation onto a lab that was set up for research-grade work is one of the most common and expensive compliance mistakes in the industry.

Step 2: Build Your Documentation System Around ALCOA+

Documentation is where most compliance failures actually happen. Not because teams are doing the wrong science, but because records are incomplete, reconstructed after the fact, or impossible to trace. Regulators assess data integrity first; the science second.

The gold standard for GMP documentation is the ALCOA+ framework, which defines nine properties that every record must satisfy:

  • Attributable — who performed each activity, identified by signature or secure electronic authentication

  • Legible — readable and understandable for the entire retention period

  • Contemporaneous — created at the time of the activity, not reconstructed later

  • Original — the first capture of data, or a certified true copy

  • Accurate — correct, complete, and truthful, including unexpected results

  • Complete — all data included, with no selective omission

  • Consistent — coherent across all related records

  • Enduring — preserved throughout required retention periods

  • Available — accessible when needed for review or inspection

The most violated principle in practice is "contemporaneous." Filling in batch records at the end of the day, or reconstructing passage notes from memory, is a data integrity failure regardless of whether the underlying data is accurate.

What Records Your Lab Must Maintain

The documentation burden scales with your regulatory tier, but the core record types are consistent across all settings:

Record Type Purpose Key Requirements
Standard Operating Procedures (SOPs) Define how activities are performed Version control, periodic review, training sign-off
Batch Production Records Document actual production activities Complete traceability, signatures, deviation documentation
Test Records Document QC results Raw data, calculations, analyst signatures, OOS investigations
Equipment Logs Track equipment use and maintenance Calibration records, preventive maintenance, cleaning logs
Training Records Document personnel competency Training completion, assessments, qualification status
Deviation/Investigation Reports Address non-conformances Root cause analysis, impact assessment, CAPA, effectiveness check

Record Retention: Longer Than You Think

Retention requirements vary by product type and jurisdiction, but they are consistently longer than most labs expect. For cell banks used in clinical products, records must typically be retained for 5 to 30 years beyond the last product distribution. Paper records require controlled environmental storage; electronic records require validated archival systems.

The practical implication: build your documentation system with long-term accessibility in mind from day one. Choosing a system that will be obsolete in five years creates a compliance problem you cannot easily fix retroactively.

Step 3: Implement a Robust Quality Control Programme

Quality control in cell culture has two primary failure modes that account for the majority of reproducibility problems: cell line misidentification and mycoplasma contamination. A systematic QC programme addresses both, alongside broader contamination prevention and in-process monitoring.

As Glyn N Stacey of the International Stem Cell Banking Initiative puts it: "Quality control is a key part of assuring reproducibility of scientific quality in research as well as assurance of the quality and safety of cell culture-derived products. These topics are currently very much in the minds of journal editors, research funders and regulators."

Cell Line Authentication

Cell line misidentification is a documented, pervasive problem. Studies have estimated that between 15% and 20% of cell lines in use across research settings are either misidentified or cross-contaminated with another line. The consequences range from wasted experiments to retracted publications.

Authentication steps to implement:

  1. Authenticate all new cell lines upon receipt using short tandem repeat (STR) profiling

  2. Re-authenticate lines after any cryopreservation event or following unexpected phenotypic changes

  3. Maintain records of authentication results linked to each cell line's passage history

  4. Compare results against reference databases such as ATCC or the European Collection of Authenticated Cell Cultures (ECACC)

Mycoplasma Testing Protocol

Mycoplasma contamination is invisible to the naked eye and does not cause the turbidity associated with bacterial contamination. It alters cell metabolism, gene expression, and growth characteristics, silently invalidating experimental results. A three-year systematic study at the National Centre for Advancing Translational Sciences (NCATS) demonstrated the critical importance of continuous mycoplasma surveillance across all cell lines in active culture.

A compliant mycoplasma testing schedule requires:

  • Testing all incoming cell lines before they are introduced to the main culture area

  • Monthly testing of all lines in regular culture

  • Testing immediately before any high-throughput screening or critical assay execution

  • Immediate destruction of confirmed-positive lines and quarantine of ambiguous results pending re-test

Contamination Prevention: The Environmental Layer

Beyond cell line integrity, contamination prevention depends on physical controls and behavioural practices:

  • Separate cell culture work from general laboratory activities and high-traffic areas

  • Quarantine all new cell lines for a minimum observation period before integration

  • Maintain routine biosafety cabinet testing and cleaning schedules

  • Implement daily microscopic observation of cultures to catch morphological changes early

  • Enforce a strict aseptic technique regime with documented training for all users

Prevention is more cost-effective than remediation. A contamination event that destroys a master cell bank can set a programme back by months. The upfront investment in rigorous contamination controls consistently outperforms the cost of recovery.

Step 4: Write SOPs That Teams Actually Follow

Standard Operating Procedures are the backbone of any quality system. The problem is that most labs have SOPs that sit in a folder, get signed off during onboarding, and are never consulted again. An SOP that nobody reads is not a quality control; it is a liability document.

Effective SOPs share three characteristics: they are specific enough to be actionable, simple enough to be followed under real working conditions, and maintained closely enough to reflect current practice.

What Every Cell Culture SOP Must Cover

For SOPs to meet GLP and GMP requirements, each document must include:

  • Purpose and scope — what the procedure covers and what it does not

  • Roles and responsibilities — who performs the procedure and who reviews it

  • Required materials and equipment — with specific lot or model references where relevant

  • Step-by-step instructions — detailed enough that a competent but unfamiliar operator could follow them

  • Documentation requirements — what must be recorded, where, and by whom

  • References — links to related SOPs, specifications, or regulatory guidance

Priority SOPs for Cell Culture Operations

At minimum, SOPs should cover:

  1. Cell thawing and initial passage procedures

  2. Routine passaging and feeding schedules

  3. Media preparation and quality control

  4. Cryopreservation and cell banking

  5. Mycoplasma and sterility testing

  6. Equipment operation, cleaning, and maintenance

  7. Deviation reporting and investigation

  8. Document control and record retention

Keeping SOPs Current

An outdated SOP is worse than no SOP. When teams follow a procedure that no longer reflects actual practice, every execution creates a documented deviation. Version control is non-negotiable: each SOP must carry a unique identifier, a version number, an effective date, and a review cycle (typically annual).

Changes to SOPs require formal change control. This means documenting the change, the rationale, an impact assessment, appropriate review and approval, and communication to all affected personnel before the new version takes effect.

The test of a good SOP: hand it to a new team member on their first day and observe whether they can complete the procedure safely and correctly without additional guidance. If they cannot, the SOP needs revision.

Step 5: Manage Deviations and Build a CAPA System

Deviations are inevitable in any laboratory operation. The question is not whether they will happen, but whether your team has a system to detect, document, investigate, and resolve them before they become recurring problems or regulatory findings.

A deviation is any departure from an approved procedure or specification. This includes process deviations (a step performed out of sequence), material deviations (a reagent used past its expiry date), and equipment deviations (an incubator temperature excursion). All three require the same response: immediate documentation and a structured investigation.

The Deviation-to-CAPA Workflow

A compliant deviation management process follows a defined sequence:

  1. Detect and document — record the deviation immediately, including date, time, operator, and a factual description of what occurred

  2. Contain — assess whether the affected batch or culture is still fit for purpose; quarantine if in doubt

  3. Investigate — determine the root cause using structured analysis (5 Whys, fishbone diagram, or similar)

  4. Assess impact — evaluate whether other batches, cell lines, or processes may have been affected

  5. Implement CAPA — define Corrective Actions (to fix the immediate problem) and Preventive Actions (to stop recurrence)

  6. Verify effectiveness — confirm that the CAPA resolved the root cause through follow-up monitoring

Common Root Cause Categories in Cell Culture

Understanding where deviations typically originate helps teams build more targeted preventive measures:

  • Personnel — inadequate training, fatigue, unclear instructions

  • Process — SOP gaps, ambiguous steps, unrealistic timelines

  • Equipment — calibration drift, maintenance failures, inadequate qualification

  • Materials — reagent quality variability, incorrect storage, lot-to-lot inconsistency

  • Environment — temperature excursions, contamination ingress, facility failures

The CAPA system only works if it is closed-loop. Many labs document the corrective action but never verify whether it actually prevented recurrence. Scheduling a formal effectiveness check at a defined interval (typically 30 to 90 days after implementation) is a regulatory expectation, not a recommendation.

A well-managed deviation is a compliance asset. Inspectors are not looking for a lab with zero deviations; they are looking for a lab that detects problems, investigates them thoroughly, and demonstrates continuous improvement. A CAPA history that shows root cause analysis and verified resolution is evidence of a mature quality system.

Step 6: Establish Full Traceability from Thaw to Harvest

Traceability is the ability to reconstruct the complete history of a cell line or batch at any point in time. For regulatory purposes, this means being able to answer, with documented evidence, who worked with a culture, when, what materials were used, and what happened at every passage.

For cell lines specifically, traceability must span the entire lifecycle:

  • Origin documentation — source, supplier, lot number, certificate of analysis, date received

  • Incoming QC — authentication results, mycoplasma test results, initial viability assessment

  • Passage history — passage number, date, operator, media lot used, cell count, viability

  • Feeding records — date, media lot, volume, operator

  • Cryopreservation events — date, passage number, vial count, storage location

  • Thaw events — date, source vial, operator, post-thaw viability

  • Deviation records — any departures from protocol, linked to the relevant passage or batch

Material Lot Traceability

Traceability extends beyond the cells themselves to every material used in culture. Media lots, serum batches, reagents, and consumables all need to be linked to the cultures they touched. This is not just a regulatory formality; it is how teams investigate root causes when results are anomalous.

A practical example: if a batch of cultures shows unexpected growth inhibition, the ability to cross-reference the media lot used across multiple cultures can determine within hours whether the issue is lot-specific. Without that linkage, the investigation can take weeks and may never reach a definitive conclusion.

Traceability in Multi-User Environments

In shared labs and CROs, traceability becomes more complex because multiple operators work with the same cultures. Clear ownership assignment, individual user authentication, and timestamped records are essential. Shared login credentials, a common shortcut in busy labs, create an audit trail that is legally and regulatorily worthless.

Complete traceability is the difference between a contained incident and a programme-level crisis. When something goes wrong, the ability to trace it precisely limits the scope of the investigation, reduces the number of batches affected, and demonstrates to regulators that the quality system is functioning as designed.

Step 7: Move Beyond Paper-Based Records

Paper-based record-keeping is the single largest operational risk in cell culture compliance. Records get misfiled, damaged, or lost. Handwriting is illegible. Cross-referencing between a passage log, a media lot record, and a deviation report requires manual effort that teams rarely complete under time pressure. And when an audit happens, reconstructing a complete history from folders of paper is both slow and error-prone.

Electronic systems address all of these problems, but they introduce their own compliance requirements. Under FDA 21 CFR Part 11 and EU GMP Annex 11, electronic records used in GMP environments must be validated. Validation means demonstrating that the system:

  • Is fit for purpose and produces accurate, reliable results

  • Includes appropriate access controls with unique user IDs

  • Maintains complete, tamper-evident audit trails of all data creation and modification

  • Protects data against loss through backup and disaster recovery

  • Prevents unauthorised access or tampering

What to Look for in a Cell Culture Management System

Not all laboratory software is built with compliance in mind. When evaluating digital tools for cell culture management, the key capabilities to assess are:

Capability Why It Matters
Per-user authentication Supports ALCOA+ attributability; eliminates shared login risk
Timestamped audit trails Provides contemporaneous, tamper-evident records
Passage and lineage tracking Maintains complete cell line history across operators
Media lot linkage Enables rapid root cause investigation
Scheduled task management Reduces missed feeds and passage events
Role-based access control Limits data modification to authorised personnel
Exportable records Supports regulatory submissions and inspections

The Transition from Paper to Digital

Moving an established lab from paper to digital records requires planning. The key steps are:

  1. Define which records will move to the digital system and which (if any) will remain on paper during transition

  2. Validate the electronic system before using it for GMP-critical records

  3. Migrate historical data with appropriate controls, or maintain parallel records for a defined period

  4. Train all users before go-live, with documented sign-off

  5. Establish a data backup and recovery schedule from day one

The business case is straightforward. Digital records reduce the time spent on documentation, make audits faster and less disruptive, and dramatically reduce the risk of data loss. For growing teams and organisations approaching regulatory milestones, the transition is not a question of whether, but when.

Building a Quality Culture, Not Just a Quality System

Every step in this guide describes a process, a framework, or a tool. But the most common reason quality systems fail is not a missing SOP or an inadequate CAPA form. It is a culture where compliance is treated as overhead rather than as integral to the science.

The labs that consistently pass inspections and produce reproducible results share a common trait: quality is owned by the people doing the work, not delegated entirely to a QA function. Scientists understand why each record matters. Lab managers review deviations as learning opportunities. New team members are trained on the reasoning behind procedures, not just the steps.

Three practices that build quality culture over time:

  1. Review quality metrics regularly — track deviation rates, CAPA closure times, and overdue SOP reviews as operational indicators, not just compliance checkboxes

  2. Make reporting easy — if raising a deviation feels bureaucratic or punitive, teams will underreport; design the process to reward transparency

  3. Connect quality to outcomes — when a well-documented deviation prevents a batch failure or speeds up an investigation, make that connection visible to the team

Compliance and quality in cell culture are not competing priorities with scientific productivity. They are the infrastructure that makes productivity sustainable. The time invested in building robust systems upfront is consistently less than the time lost to contamination events, failed audits, and irreproducible results.

For teams ready to digitise their cell culture workflows and build a connected, audit-ready quality system, CellHood offers a 30-day free trial with no credit card required.

Sources and further reading

  1. Referenced sourcereview published in Frontiers in Public Health

    www.frontiersin.org

  2. Referenced sourceISO 14644 classification standards

    www.iso.org

  3. Referenced sourceGCCP 2.0 guidance document

    www.crolasa.com

  4. Referenced sourceInternational Stem Cell Banking Initiative

    www.technologynetworks.com

  5. Referenced sourceATCC

    www.atcc.org

  6. Referenced sourcethree-year systematic study at the National Centre for Advancing Translational Sciences (NCATS)

    pmc.ncbi.nlm.nih.gov

  7. Referenced sourceFDA 21 CFR Part 11

    www.ecfr.gov

  8. Referenced sourceEU GMP Annex 11

    health.ec.europa.eu

PUT IT INTO PRACTICE WITH CELLHOOD

Make your culture records easier to review

Explore CellHood’s culture timelines and audit history as part of your documentation process. Discuss regulated-use requirements and validation needs with your quality lead.