Scientists moving from an academic laboratory into a regulated one usually arrive with a reasonable assumption: that Good Laboratory Practice is a standard for doing good science. It is not, and the misunderstanding causes months of friction before it resolves. GLP is a framework for making a study traceable. It governs who was responsible, what was done, when, with what materials, and whether the record proves it. It says almost nothing about whether the experiment was well designed.
This sounds like a criticism and is not. The framework was built to solve a specific problem that had nothing to do with experimental design, and it solves that problem well. Regulators receiving safety data on chemicals and medicines needed to be able to reconstruct a study years later from its records alone, without trusting the sponsor’s summary. That requires an unbroken documentary chain from the animal or sample to the number in the report, and it requires that the chain be independently verifiable. GLP is the machinery for producing such a chain.
Understanding what the framework covers, and what it deliberately leaves alone, makes the daily requirements far less arbitrary. A newcomer irritated by having to initial and date a correction is applying an academic standard of what matters. A regulator reading that page in five years, trying to establish whether a value was altered before or after the results were known, is applying a different one.
Key takeaways
- GLP governs traceability, documentation and responsibility, not experimental design or scientific merit.
- It grew out of regulatory inspections that found safety studies could not be reconstructed from their records.
- The study director is a single named individual with defined accountability for the whole study.
- Raw data means the first recording of an observation, and what counts as first depends on the instrument.
- A compliant study can still be scientifically weak; compliance and quality are separate judgements.
Where the Framework Came From
The framework has a specific origin in regulatory inspection rather than in scientific philosophy. In the 1970s, regulators in the United States examined laboratories submitting safety data on chemicals and pharmaceuticals and found serious problems. Records were incomplete or absent. Some studies could not be reconstructed at all. In some cases the reported results could not be reconciled with what documentation existed.
The critical realisation was that these failures were largely undetectable from the outside. A submitted report is a summary written by the party with an interest in the outcome. Without records that an inspector can trace back independently, a regulator has no way to distinguish a carefully executed study from a carelessly executed one, or from one whose inconvenient findings were quietly dropped. The response was a set of regulations specifying not what science should be done but how it must be recorded and controlled.
The framework spread internationally, and the OECD principles of Good Laboratory Practice became the reference document that national systems align to, supporting mutual acceptance of data so that a study conducted in one member country can be accepted by regulators in another without repetition. That mutual acceptance is the practical payoff, and it explains the framework’s emphasis on uniformity and inspectability.
The scope is narrower than the name implies. GLP applies to non-clinical safety studies intended for regulatory submission: toxicology, and studies of how a substance behaves and persists in a body or in the environment. It does not apply to basic research, to clinical trials in humans, which are governed by Good Clinical Practice, or to routine manufacturing quality control, which falls under Good Manufacturing Practice. Analytical or diagnostic laboratories usually work to accreditation standards instead, which have a different emphasis.
Study Directors and Defined Responsibilities

The central organisational feature of GLP is that every study has exactly one study director, named in advance, who carries overall responsibility for its conduct and for the final report. This is not a formality. It is the mechanism that makes accountability locatable, and it is the single biggest cultural difference from academic work, where responsibility is distributed across a group and often ambiguous.
The study director approves the plan before work begins, ensures that procedures are followed, that deviations are documented and their impact assessed, and that the report reflects the raw data. Signing the report is a specific statement: that the study was conducted in compliance with the principles and that the data are accurately represented. There is one director at a time, and a handover to a replacement is itself a documented event.
Around that role, the framework specifies others. Management appoints the study director and provides the resources, personnel and facilities required, and is responsible for ensuring that a quality assurance programme exists. Principal investigators take responsibility for delegated phases conducted at other sites, reporting to the study director. Personnel are individually responsible for following procedures and recording their work, and the framework requires that their training and qualifications be documented, so that an inspector can establish that whoever performed a task was competent to perform it.
The wider consequence is that responsibility is written down before the work starts rather than reconstructed afterwards. That single change eliminates a large class of ambiguity that academic laboratories live with routinely.
Standard Operating Procedures in Daily Use
A standard operating procedure describes how a recurring activity is performed, in enough detail that someone competent could follow it and get the same result. SOPs exist for the technical work and equally for the infrastructure around it: equipment operation and maintenance, calibration, reagent preparation and labelling, animal husbandry, sample handling, data recording, and the writing and revision of SOPs themselves.
Two properties distinguish an SOP from a protocol pinned above a bench. It is controlled, meaning it has a version, an approval, an effective date and a distribution, so that the version in use at any moment is knowable and superseded versions are withdrawn but retained. And it is binding, meaning that departing from it is a deviation that must be recorded, assessed for impact and reported, rather than an informal improvement.
That second property is what newcomers find hardest, because the academic instinct is to optimise as you go. In a GLP study, an undocumented improvement destroys the correspondence between the record and what happened, which is the entire asset the framework exists to protect. If a change is genuinely better, the route is to amend the SOP through its own procedure, not to adopt it silently.
| Aspect | Academic laboratory | GLP-regulated study |
|---|---|---|
| Method record | Notebook entry, group protocol | Version-controlled, approved SOP |
| Deviations | Adjusted and often unrecorded | Documented, assessed, reported |
| Responsibility | Distributed, often informal | One named study director |
| Data corrections | Overwritten or erased | Struck through, initialled, dated, reason given |
| Independent checking | Peer review after submission | Quality assurance audit during conduct |
| Record retention | Variable, often lost with staff | Defined archive period and archivist |
Raw Data and What Counts as Original
Raw data is the framework’s most precisely defined and most frequently misunderstood term. It means the original records and documentation, or verified copies of them, that result from the original observations. It is the first recording, whatever form that takes.
Identifying it is straightforward for a manual observation: the notebook page written at the bench is the raw data, and a later transcription into a spreadsheet is not. For instruments it takes more thought. Where a balance prints a slip, that slip is raw data. Where a chromatography system stores a signal file, the electronic file is raw data and the printed chromatogram is a copy, which is why the data system and its audit trail fall inside the compliance boundary. Where an instrument only displays a value that a person writes down, the written record becomes the raw data by default, which is a weaker arrangement and one that inspectors probe.
The associated recording rules follow directly. Entries are made at the time of the observation, not reconstructed later. They are made in indelible ink in a bound notebook or in a validated electronic system. Corrections do not obliterate the original: a single line through the entry, the new value beside it, the initials of whoever made the change, the date, and a reason. The reason matters more than it looks, because it distinguishes a transcription error corrected immediately from a value revised after the analysis suggested it was inconvenient.
Electronic systems must therefore provide what paper provides naturally: a record of who did what and when, that cannot be silently altered. That is the function of the audit trail, and it is why administrative privileges, system clocks and user account management become compliance concerns in a way that surprises people arriving from academia. Data integrity expectations are often summarised as requiring records to be attributable, legible, contemporaneous, original and accurate, a formulation that captures the whole set neatly.
Quality Assurance Units and Their Audits
The framework requires a quality assurance function that is independent of the people conducting the study. Independence is the essential feature: QA does not report to the study director and has no stake in the outcome, which is what makes its findings meaningful.
The unit’s work has three strands. It inspects studies while they are running, observing critical phases as they happen and checking that what is being done matches the plan and the SOPs. It audits the final report against the raw data, verifying that the numbers in the report can be traced to their sources and that the report describes what actually occurred. And it inspects the facility itself, examining equipment records, training files, archive conditions and the SOP system, on a schedule rather than in response to problems.
QA also maintains the master schedule, a register of all studies with their directors, dates and status. This unglamorous document is one of the first things an inspector asks for, because it establishes what the facility has been doing and makes it difficult for a study to be quietly abandoned when its results prove unwelcome.
A QA statement accompanies the final report, listing the inspections performed and the dates on which findings were reported to management and the study director. The distinction between QA and quality control deserves emphasis: quality control checks the product, running standards and replicates to confirm that a measurement is performing, while quality assurance checks the system that produced it.
Archiving Requirements After a Study
A study is not finished when the report is signed. Everything supporting it must be retained, in defined conditions, for a defined period, under the control of a named archivist. This receives little attention in training and a great deal in inspections.
What goes to the archive is broad: the plan and its amendments, the raw data in all its forms, samples and specimens where their stability allows retention, the final report, and the records establishing the context, including equipment calibration and maintenance, training files, environmental monitoring and the SOPs in the versions that were current during the study. That last inclusion is easy to miss and important, since a study cannot be reconstructed against a procedure that has since been revised three times.
The archive itself must be secure and environmentally controlled, with access restricted and logged, and material may be removed only through a documented process. Retention periods are set by the regulations applying to the submission and are typically long, often outlasting the careers of the people who did the work.
Electronic records make this harder rather than easier. Retaining a file for decades is trivial; retaining the ability to read it meaningfully is not, because instrument software becomes obsolete, file formats fall out of support, and a proprietary data file without its application may be unreadable well before the retention period ends. Facilities address this by migrating data with documented verification, by retaining readable copies in durable formats alongside the originals, or by maintaining legacy systems. All three approaches cost money, which is why the problem is often deferred until it is expensive.
What Compliance Does Not Guarantee
The framework’s boundaries are where the most useful understanding sits, because a great deal of confusion comes from expecting it to certify things it never addressed.
GLP does not assess whether a study was well designed. If a protocol specifies too few animals to detect the effect of interest, or an inappropriate control, or an exposure route that does not reflect real use, a fully compliant study will execute that design meticulously, document it thoroughly, and produce a traceable but uninformative result. Design quality is judged by the regulatory reviewers assessing the submission and by the scientific standards of the discipline, not by the compliance framework.
Nor does it validate the underlying method. Whether an assay measures what it claims to measure is established by method validation, a separate body of work with its own criteria. GLP requires that a validated method be used and that the validation be documented; it does not perform the validation.
It does not guarantee that results are correct. It guarantees that they can be traced to their source and that any alteration is visible. Those are different claims, and the second is what a regulator can actually verify from outside.
Finally, compliance does not by itself prevent misconduct, though it makes it markedly harder and easier to detect. Contemporaneous records, audit trails, independent QA inspection and long retention all raise the cost of fabrication considerably. Determined fraud has still occurred in compliant facilities, and inspection regimes exist precisely because the paperwork alone is not self-enforcing.
Frequently asked questions
Is GLP the same as ISO 17025 accreditation?
No, though both are quality frameworks and both involve documentation and audits. GLP applies to non-clinical safety studies submitted to regulators and is organised around the study as a unit, with a study director, a plan and a final report. ISO 17025 is an accreditation standard for testing and calibration laboratories, organised around the competence of the laboratory to produce valid results for particular methods, with heavy emphasis on measurement uncertainty, traceability of calibration and proficiency testing. A contract laboratory may hold both, applying each to different parts of its work.
Does GLP apply to academic research?
Generally not. Basic research is outside its scope, and applying the full framework to exploratory work would be expensive and would not improve it, because the framework’s benefits are about regulatory traceability rather than discovery. The situation changes if academic work is intended to support a regulatory submission, in which case the relevant studies must be conducted under GLP in an appropriately monitored facility. Several documentation habits from GLP are worth borrowing regardless, particularly contemporaneous recording, version-controlled protocols and disciplined correction of entries.
What happens when something goes wrong during a study?
It is documented as a deviation, and that is the expected response rather than a failure. The record states what departed from the plan or SOP, when, why, and what was done, and the study director assesses whether it affects the integrity of the study or the interpretation of results. Deviations are reported in the final report so that a reviewer can judge their significance. The serious failure is not the deviation itself but an undocumented one, because it breaks the correspondence between the record and reality that the whole framework rests on.
Who inspects laboratories for GLP compliance?
National monitoring authorities designated by each country carry out inspections of test facilities and audits of individual studies, and their findings underpin the mutual acceptance of data between countries. Facilities are inspected on a routine cycle and may also be inspected in connection with a particular submission. This is separate from the internal quality assurance unit, which inspects continuously from inside and reports to management. Sponsors commonly conduct their own audits of contract laboratories as well, before placing work and during it.
How long do records have to be kept?
It depends on the regulations governing the submission and the jurisdiction, and periods are long, commonly measured in years beyond the approval or discontinuation of the product concerned. The practical consequence is that archiving must be planned as part of the study rather than handled afterwards, particularly for electronic data, where the retention period may outlast the software that created the files. Facilities that treat the archive as an afterthought discover the problem when an inspector asks to see a study conducted a decade earlier.
The reframing that helps most is to stop reading GLP as a claim about quality and start reading it as a claim about verifiability. A compliant study is one whose conduct can be reconstructed by someone who was not there and does not trust anyone who was. That is a genuinely valuable property, and it is not the same as the study being informative, well designed or correct. Those remain matters of scientific judgement, and no amount of documentation supplies them. What the framework does is ensure that when that judgement is applied, it is applied to a record of what actually happened.




