For years, running statistical process control out of an Excel spreadsheet was good enough — the operator logged readings, a macro drew the control chart, and the binder went on a shelf. In a GMP-regulated pharma plant, that era is over. Excel's Track Changes doesn't satisfy the 21 CFR Part 11 audit-trail requirement, its access can be shared, its version control can't prove the sheet in use is the validated one, and a formula error or a quiet cell edit leaves no trace. When the FDA is issuing warning letters over data-integrity gaps, a spreadsheet is no longer an audit-defensible system of record for SPC. The question isn't whether to automate — it's which features make it compliant. You can book a demo to see them in a working system.
Manual SPC in Excel Isn't Audit-Defensible Anymore — Here's What to Require Instead
The must-have features of automated SPC software for a GMP-regulated pharma plant — real-time capture, tamper-evident audit trails, automated rule detection, and validation — so your process control holds up to an FDA inspection, not just to a chart review.
Excel Doesn't Fail at Statistics — It Fails at Data Integrity
The problem with Excel-based SPC in a regulated plant isn't the math; a spreadsheet can compute a control limit perfectly well. The problem is everything the regulation demands around the number: proof of who recorded it, that it hasn't been altered, that the version in use is the validated one, and that any change is captured with a reason. Excel provides none of that in a way an inspector accepts, which is why a spreadsheet that looks fine on screen fails as a GMP system of record.
Part 11 requires a secure, computer-generated, time-stamped audit trail that records who changed what, when, and why — and that users can't alter their own entries. Excel's Track Changes meets none of those bars and is trivially turned off.
Spreadsheets are routinely opened under a shared login or passed between people, so a reading can't be reliably tied to the individual who took it — breaking the attributable-and-secure foundation Part 11 is built on.
With multiple copies of a workbook in circulation, you can't demonstrate that the version being used is the validated version — a version-control failure that's a common data-integrity citation on its own.
A broken formula, an overwritten cell, or a deleted row leaves no mark. Excel has no mechanism to detect or flag data modification, so an error can propagate through a control chart entirely unseen.
Data Integrity Is the Feature Everything Else Sits On
Before any SPC-specific capability, an automated system for pharma has to get data integrity right, because that's what an inspector examines first and what a warning letter most often cites. These are the data-integrity features that aren't optional — they're the baseline that makes the rest of the software worth evaluating.
Secure, computer-generated, and time-stamped, capturing the original value, the new value, who made the change, when, and the reason for it — recorded independently so a user cannot edit their own audit entries, tamper-evident, and retained as long as the record itself. This is the single feature that most separates a compliant system from a spreadsheet.
Data that is Attributable, Legible, Contemporaneous, Original, and Accurate — plus complete, consistent, enduring, and available. The system should enforce these properties automatically rather than relying on procedure, so integrity happens by design, not by heroic manual effort.
Individual secure logins with role-based permissions, and Part 11 electronic signatures on the decisions that matter — an out-of-control disposition, a limit change, a batch-relevant sign-off — with each signature bound to the record and non-repudiable.
Any system managing GxP electronic records must be validated, so the software should come with the IQ, OQ, and PQ documentation and a GAMP 5-aligned approach that make validation a scoped project rather than an open-ended one.
Start From the Integrity Layer, Not the Charts
iFactory's SPC is built on a Part 11 audit trail, ALCOA+ enforcement, role-based e-signatures, and validation support — so the data behind every chart is inspection-grade before you draw a single control limit.
Once the Data Is Trustworthy, These Are the Capabilities to Demand
With integrity as the foundation, the SPC-specific features are what turn compliant data into actual process control. This is where automated software pulls decisively ahead of any spreadsheet — not by charting differently, but by capturing, detecting, and reacting in real time.
Readings flow directly from instruments, LIMS, and the historian rather than being hand-keyed, which removes the transcription error a spreadsheet invites and makes the chart live rather than a next-day reconstruction.
Western Electric and Nelson rules applied automatically to every point, alarming the moment a run, trend, or out-of-limit condition appears — so an out-of-control signal triggers action in the moment instead of being spotted at a weekly review.
X-bar and R, individuals, attribute charts, and capability indices — Cp, Cpk, Pp, Ppk — computed correctly and consistently, with the short-term versus long-term distinction handled properly rather than fudged in a formula.
When a point signals out of control, the system routes it for investigation and disposition with an e-signature, so the reaction is documented and closed rather than noticed and forgotten — the loop a chart alone can't enforce.
SPC data has to connect to the systems around it, so a signal links to its batch, its instrument, and its context — and results flow into release decisions rather than living in an isolated file.
Because every reading is captured consistently, the platform can trend a characteristic across batches, lines, and sites — surfacing the slow drift that a per-batch spreadsheet review would never connect.
The Difference Between Catching Drift and Documenting It
The deepest reason to leave manual SPC behind isn't compliance — it's timing. A spreadsheet updated at end of shift tells you a process went out of control after the batch is already made; automated SPC alarms while the process is still running, when an operator can still act. That shift from retrospective to real-time is what turns SPC from a record-keeping exercise into actual process control.
- Readings hand-keyed, often after the run
- Out-of-control signal spotted at review, days later
- Rule violations found by eye, inconsistently
- The batch affected by the drift is already made
- Audit trail absent or unaccepted by inspectors
- SPC is a record you keep, not a control you use
- Readings captured live from instruments
- Out-of-control condition alarms in the moment
- Western Electric and Nelson rules applied to every point
- The operator acts before the next unit is affected
- Every point carries a tamper-evident audit trail
- SPC becomes real process control, and it's audit-ready
SPC Sits Squarely in the Data-Integrity Crosshairs
SPC data is GxP data, so it falls under exactly the electronic-records scrutiny that dominates modern GMP inspections. Knowing which regulations and expectations apply is how you evaluate whether a system is genuinely compliant or just marketed as such.
The FDA rule for electronic records and signatures — secure time-stamped audit trails, access controls, and validated systems. Data-integrity gaps in electronic records are a recurring theme in FDA warning letters.
The European counterpart, requiring a risk-based approach to audit trails for GMP-relevant changes and deletions in computerized systems — increasingly aligned with Part 11 expectations.
The framework for validating computerized systems on a risk basis, which shapes how an SPC system should be qualified — and how a vendor should support that qualification.
ALCOA+ is the data-integrity framework regulators expect enforced, and emerging guidance like Annex 22 extends computerized-system expectations to AI and machine learning in pharma manufacturing.
Compliant Data First, Real Process Control on Top
iFactory's SPC is built for a GMP plant from the data layer up: a Part 11 audit trail and ALCOA+ integrity underneath, real-time capture and automated rule detection on top, and validation support so the whole system qualifies cleanly. It's the difference between a chart that looks right and a control system an inspector trusts.
What Pharma Operations Teams Ask About SPC Software
Make Your SPC Audit-Defensible, Not Just Statistically Correct
iFactory delivers pharma SPC on a Part 11 audit trail with ALCOA+ integrity, real-time capture, automated rule detection, and validation support — so your process control holds up to an FDA inspection and catches drift while it still matters.







