If an auditor asked you to prove exactly who changed the shaking speed on run 47, at what time, and why could your equipment answer that question on its own?
For a growing number of biopharma facilities, that question is no longer hypothetical. As bioprocessing scales from bench to GMP, the bar has quietly shifted. It's no longer enough for an instrument to hold temperature or shake reliably. It has to be able to prove, on demand, that it did: who ran it, what was changed, and whether the record has been touched since. Data integrity has moved from a "nice to have" to the baseline expectation for any equipment sitting inside a regulated or audit-facing workflow.
Here's what that standard actually looks like in practice, and what to check for when evaluating equipment against it.
It Starts with Who Touched the Instrument
Before a facility can trust its data, it has to be able to answer a simpler question: who had access to change it? This is where user access management earns its place as a compliance feature, not just a convenience one.
A well-designed system enforces this at the touch screen itself, through:
-
Multi-level user access, separating operator, maintainer, and administrator privileges so day-to-day users can run protocols without being able to alter critical system parameters
-
Password protection on critical settings and configuration, closing the door on unintended or unauthorized changes
-
Physical door locks, extending access control from the software layer to the physical sample itself
-
Mandatory login before any operation, with every action subsequently tied to the identity of the user who performed it
None of this is about slowing operators down. It's about making sure that when there’re changes, be it a setpoint, a program, a parameter, there's an unambiguous answer to who changed it. That single design choice is what turns a log file into an audit trail.
The Record Has to Survive the Bad Day
Every facility eventually has a power blip, a network drop, or an unplanned shutdown mid-run. The question is what happens to your data when it does.
Non-volatile, automatic data logging is built to answer that question before it's asked. Rather than relying on a user to manually save a run, the system continuously and automatically captures:
-
Operation logs, history curves, live curves, and alarm events in real time throughout the run
-
Settings retained in non-volatile memory, with automatic resumption and a power-interruption notification after any outage, so a blip doesn't quietly erase the record along with the run
This matters because the moments most likely to produce a deviation, e.g. a power flicker, a door left open, a sensor fault, are exactly the moments a fragile logging system is most likely to lose data. Non-volatile logging closes that gap by design, not by hoping the operator remembers to hit save.
Turning Logs into an Audit Trail
Logging data and maintaining an auditable record are related but not identical. The difference comes down to a few specific guarantees:
-
Automatic, time-stamped audit trails of operations, for example door closures, alarm events, parameter changes, captured without operator intervention, so the record can't quietly go missing
-
Non-editable electronic records, preserving the authenticity of the data after it's written
-
Selectable export formats (.csv or .pdf, non-editable) via USB, so records can leave the instrument for review without exposing them to alteration
-
Up to 10 years of long-term data storage, supporting retrospective audit and compliance review long after a run has ended
Taken together, these design principles align with the intent of 21 CFR Part 11, records that are attributable, time-stamped, and resistant to tampering after the fact. For facilities operating under GMP or preparing for regulatory inspection, that alignment isn't a marketing checkbox, it's the difference between a data set you can defend and one you can only hope holds up.
What to Look For
If you're evaluating shaking incubators, or any bioprocessing equipment, against this standard, a short checklist can save a lot of pain later:
-
Can the system enforce role-based access at the touch screen, not just at a network level?
-
Does it log continuously and automatically, or does it depend on a user remembering to save?
-
Does the record survive a power interruption without gaps?
-
Can records be exported in a non-editable format, with a timestamped audit trail attached?
-
How long is data retained on the instrument itself?
Instruments like the ZWYC-240B Ultra Elite Benchtop Cell Culture Shaking Incubator are built around exactly this set of principles: three-level access management, non-volatile automatic logging, and non-editable, time-stamped audit trails aligned with 21 CFR Part 11 principles, because in modern bioprocessing, the equipment's ability to prove what happened is becoming as important as its ability to make it happen in the first place.
For a closer look at how these features map to each compliance requirement, see the ZWYC-240B Technical Compliance & Data Integrity Guide.
Frequently Asked Questions
Q: What does "data integrity" mean in a bioprocessing context?
A: Data integrity means a record is attributable to a specific user, time-stamped, complete, and resistant to alteration after it's created. In practice, that means being able to show who changed a setting, when, and confirming the record hasn't been edited since.
Q: Why does user access management matter for compliance, not just convenience?
A: Without role-based access, any user can change critical parameters with no way to trace who did it. Multi-level user access includes separating operator, maintainer, and administrator privileges, with mandatory login, ties every action to an identifiable user, which is what turns a log file into an audit trail.
Q: What happens to logged data if the instrument loses power mid-run?
A: With non-volatile, automatic data logging, settings and run data are retained in non-volatile memory. The system automatically resumes after power is restored and issues a power-interruption notification, so the outage is recorded rather than leaving a gap in the data.
Q: Is this kind of audit trail 21 CFR Part 11 compliant?
A: The attributable, time-stamped, non-editable records - the design is built around the same principles referenced in 21 CFR Part 11. Full regulatory compliance also depends on a facility's own SOPs, validation, and quality systems, not the instrument alone.
Q: How long is run data retained on the instrument?
A: Instruments built to this standard, such as the ZWYC-240B, offer long-term data storage capability of up to 10 years, supporting retrospective audit and compliance review well after a run has ended.
Q: Can records be exported for external audit review?
A: Yes. Records can be exported via USB in selectable, non-editable formats (.csv or .pdf), so they can leave the instrument for review without exposing them to alteration.
Want the full technical breakdown of these compliance features? See full specification here or contact us to discuss how the ZWYC-240B fits into your facility's data integrity requirements.