An implementation checklist for documenting protocol deviations is a contemporaneous record of the run that did not follow the recipe, not a new filename. Write what changed, who knew, and what was used anyway before anyone signs. Prefer a dated entry that names the parent protocol, the actual step, the knower, and the material that still went forward. Reject a silent edit that makes the notebook look clean.
Protocol versus experiment record still owns the recipe-versus-run split. ELN sign-off readiness still owns pre-signature completeness. Per-entry ELN fields still own the ordinary close-out. This page only records the unfollowed step. Protocol versioning is a sibling job: a new controlled method gets a new ID. A deviation is what happened on this dated run while the old ID was still the parent. Software can hold the entry. Software alone does not complete 21 CFR Part 11.
Write What Changed Who Knew and What Was Used Anyway
The search asks how to document protocol deviations. The outcome is a record a later reader can use to reconstruct the actual run without interviewing the author. That reconstruction needs three facts that a tidy notebook likes to omit: the step that was not followed, the person who knew at the time, and the tubes, animals, cells, or files that were used anyway. If those facts are missing, the signature attests to a recipe that did not happen.

A deviation is not automatically misconduct. It is a mismatch between the controlled method and the run. Incubation ran forty minutes instead of thirty. A different lot was substituted. A step was skipped because a reagent was back-ordered. Those events are common. They become a quality problem when they are invisible. ALCOA-oriented documentation asks for attributable, contemporaneous records. That orientation is enough to require a named knower and a time. It is not a claim that one software product makes the laboratory compliant.
Walk the Deviation Fields
Write the entry on the day of the change, on the same experiment record that will be signed. Do not wait for a weekly cleanup.
- Name the parent protocol. Record the controlled ID and version that the run was supposed to follow. Checkpoint: a later reader can open that exact recipe.
- Name the change. Write the intended step and the actual step in operational language. Minutes, lots, temperatures, and skipped actions belong here. Checkpoint: a person who was not in the room can see what differed.
- Name who knew. Record who observed or authorized the change and when. If no one authorized it, write that. Checkpoint: the entry is attributable to a person, not to “the lab.”
- Name what was used anyway. List the samples, lots, animals, or files that continued under the changed step. Checkpoint: disposal or repeat decisions can point at those objects.
- Name the impact and the next action. State whether data from those objects remain in the study, are flagged, or are excluded, and who will review that decision. Checkpoint: sign-off cannot proceed if impact is “TBD” with no owner.
- Link the entry to the run. Keep the deviation on the experiment record, not in a private chat. Checkpoint: export of the record includes the deviation.
If a checkpoint fails, do not sign. A signature on a record that omits the change is a signature on a fiction. FDA’s Part 11 scope guidance discusses electronic records and signatures. It does not authorize a vendor claim that software completes Part 11.
A worked entry is short. Parent protocol CLN-014 version 3 said incubate 30 minutes at 37 °C. The actual run incubated 48 minutes because a water bath was late. Operator J. Lee recorded the change at 14:10. Samples A12–A15 continued. Impact: flag those four preps for a repeat digest; do not treat the gel as a protocol-normal result. Reviewer: the section lead before sign-off. That block can sit on the same experiment record as the ordinary fields. A filename CLN-014_v3b.pdf with no such block is not a deviation record.
Expected Result and Verification
The walk is done when a later reader can reconstruct the actual run from the record alone. Verification is not a prettier PDF.
- The parent protocol ID and version are present.
- The intended step and the actual step are both written.
- A named person and time are attached to the knowledge of the change.
- The objects that continued under the change are listed.
- Impact and reviewer are named, even if the decision is “repeat the run.”
Common failures are a filename bump (“_v2”) with no change text, a chat message that never enters the record, and a signature applied because the rest of the fields look complete. Sign-off readiness on the sibling page can still fail if this deviation block is empty. If verification cannot be completed, hold the signature. The run is not undocumented science. It is undocumented practice.
Hold the Entry After the Fields Exist
Hold the deviation on the same record that will be reviewed. After the fields exist, an electronic notebook such as ZettaNote can store a dated, attributable entry and keep it with the experiment. That is a record surface. It is not a compliance certificate. Software alone does not complete 21 CFR Part 11. Do not write a time-saved percentage. Do not treat a checkbox as proof that QA accepted the change.
If the lab still “fixes” deviations by making the notebook match the recipe after the fact, you do not have documentation. You have a cleaned story. Write the mismatch. Then sign. Then, if the method itself should change, version the protocol on a different page and a different ID.
A second refusal is useful when the method should change. Three runs in a row used 48 minutes because 30 minutes never worked on that water bath. That pattern is a reason to version the protocol, not a reason to keep writing the same deviation forever. Versioning creates a new controlled ID. The historical runs still keep their deviation blocks under the old ID. Do not collapse those two jobs into one renamed PDF. A reviewer who cannot tell which recipe governed which date cannot reconstruct the study. The sibling page owns the recipe-versus-run split. This walk only keeps the unfollowed step visible until that split is used.
Frequently Asked Questions
Is a new filename enough to document a protocol deviation?
No. Write the change the knower and the material still used. A new filename does not reconstruct the run.
Does an ELN entry complete 21 CFR Part 11 for a deviation?
No. A dated entry can support the record. Software alone does not make the lab compliant.