You can outsource the work. You cannot outsource the responsibility. That principle has always been true under 21 CFR 211.22, but five warning letters issued in the first quarter of 2026 have made it viscerally clear what happens when an application holder treats it as optional.
Each of the five letters cited deliberate falsification at a contract laboratory or CRO. In every case, FDA held the application holder - not the contract facility - accountable for the failure. This article covers what a compliant contract manufacturing oversight programme actually requires, and what the 2026 enforcement data means for your quality agreements and audit programme.
Five separate warning letters in the first quarter of 2026 cited falsification of records at contract testing laboratories and contract research organisations - fabricated chromatography data, backdated batch records and deleted audit trail entries among the findings. None of the letters were addressed to the contract facility alone. Every one held the sponsor or application holder accountable for inadequate oversight.
Why 21 CFR 211.22 makes this the sponsor's problem
21 CFR 211.22 establishes the quality unit's responsibility and authority over every aspect of manufacturing, testing and release that affects a drug product - regardless of who physically performs the work. When a sponsor contracts manufacturing, testing or other GxP activities to a third party, the regulatory obligation does not transfer with the contract. It is shared, and in FDA's enforcement practice, the application holder carries the greater share.
This is codified explicitly in FDA's guidance on contract manufacturing arrangements, which states that the owner of the product - the party whose name appears on the application - retains ultimate responsibility for ensuring the product is manufactured in accordance with cGMP, irrespective of any contractual arrangement.
The practical consequence is that a sponsor cannot treat a signed quality agreement as the end of its obligation. The quality agreement establishes the framework. Ongoing oversight - audits, data review, trend analysis of contract facility performance - is what actually satisfies the regulatory requirement.
What the five Q1 2026 warning letters reveal
Data review that never actually reviewed the data
In several of the cited cases, the sponsor's quality agreement required periodic review of the contract facility's testing data, but the review that occurred was a documentation check - confirming a report existed - rather than a substantive review of the underlying data for signs of manipulation. Fabricated chromatography data and deleted audit trail entries went undetected for extended periods because nobody at the sponsor organisation was actually looking at the raw data behind the certificates of analysis.
Audits scheduled but not risk-based
Several sponsors had audit programmes that scheduled contract facility audits on a fixed calendar interval - annually, for instance - regardless of the facility's risk profile, prior findings or the criticality of the work being performed. FDA's expectation, reflected in current guidance, is that audit frequency and depth should be risk-based - a facility with prior data integrity concerns or one performing high-risk testing warrants more frequent and more rigorous scrutiny than a routine calendar-based audit provides.
Quality agreements that didn't specify data integrity controls
A number of the underlying quality agreements were found to be silent or vague on specific data integrity expectations - audit trail review requirements, electronic signature controls, backup and retention obligations for raw electronic data. A quality agreement that only addresses turnaround times and specifications, without addressing how data integrity will be assured and verified, leaves a gap that is difficult to close after a problem has already occurred.
What a defensible CMO oversight programme requires
Based on the enforcement pattern and existing FDA guidance, a contract manufacturing and contract testing oversight programme needs to address the following elements to withstand scrutiny.
- A quality agreement that specifically addresses data integrity - not just specifications and turnaround times, but audit trail review responsibilities, electronic record controls, and the sponsor's right to access raw data, not just summary reports
- Risk-based audit scheduling - audit frequency and depth calibrated to the facility's criticality, prior performance and any history of findings, rather than a uniform calendar interval applied to every contract partner
- Substantive data review, not documentation checks - periodic review that actually examines underlying raw data, audit trails and metadata for a sample of batches or test results, not just confirmation that a certificate of analysis was received
- A defined escalation path for findings identified during oversight activities, with documented follow-up and, where warranted, an increase in oversight intensity
- Ongoing supplier performance trending - tracking a contract facility's OOS rate, deviation rate, complaint rate and audit finding history over time to identify emerging risk before it becomes a data integrity event
None of this is a suggestion that contract manufacturing or outsourced testing is inherently risky or should be avoided. The pharmaceutical industry depends on a global network of contract facilities and this is not going to change. The point is narrower and more practical: the sponsor's oversight programme has to be substantive enough to actually catch the kind of falsification that occurred in these five cases, not just documented well enough to look substantive on paper.
Three questions worth asking about your own programme
When your quality agreements were last updated, did they explicitly address audit trail review, electronic record integrity and raw data access rights - or do they predate the current emphasis on data integrity? A quality agreement written five or more years ago may not reflect current FDA expectations even if it has never been formally deficient.
Is your audit schedule risk-based, or calendar-based? If every contract facility is audited on the same fixed interval regardless of risk profile, that is worth revisiting against current guidance.
When was the last time someone at your organisation actually reviewed raw data from a contract facility, rather than the summary report or certificate of analysis? If the honest answer is that this has never happened, or happened only during the initial qualification audit, that is the single highest-leverage gap to close first.
21 CFR 211.22 does not distinguish between work performed in-house and work performed by a contract partner. FDA's enforcement in Q1 2026 makes clear that this is not a technicality - sponsors were held accountable for falsification they did not commit and, in most cases, did not know about, because their oversight programme was not substantive enough to have caught it. A signed quality agreement is the beginning of the obligation, not the end of it.
Key regulatory references
- 21 CFR 211.22 - Responsibilities of quality control unit
- FDA Guidance for Industry - Contract Manufacturing Arrangements for Drugs: Quality Agreements
- Q1 2026 FDA Warning Letters citing contract laboratory and CRO data falsification
Our Contract Manufacturing Oversight course covers this in full
Quality agreement structure, risk-based audit programme design, data integrity oversight and the sponsor's obligations under 21 CFR 211.22. Certificate on completion.