Skip to content
Sinfony

ISO 22716 · Cosmetics GMP

Nowhere does ISO 22716 ask you to write more.

And yet that is the most common reading. An audit approaches, you add a procedure; a deviation occurs, you add a record. A few years later the document set has tripled and the same deviations keep coming back. The standard never asked for any of this. Let us go back to what it actually says.

17 chapters

Personnel, premises, equipment, raw and packaging materials, production, finished products, laboratory, out-of-specification product, waste, subcontracting, deviations, complaints and recalls, change control, internal audit, documentation. Not one of them sets a number of procedures.

The seventeen chapters of ISO 22716: sixteen describe practices, the last one documentation.1234567891011121314151617Chapters 1 to 16: practices.Chapter 17: documentation. Last.
Structure of ISO 22716:2007, guidelines on good manufacturing practices for cosmetics.

Read the table of contents again: documentation is the last chapter, not the first. The sixteen before it describe practices — how you train, how you clean, how you decide on a doubtful batch. Chapter 17 then says how those practices are recorded. The order is not decorative: it says the document follows the practice, and never the reverse.

The belief that costs you

"The more procedures I have, the better I am covered."

That sentence appears nowhere in the standard. It is nonetheless the silent engine behind most of the cosmetics document systems we open. It rests on a confusion: being able to show a document and being able to demonstrate a controlled practice are not the same thing. ISO 22716 asks for the second. A competent auditor does not count your procedures: they look at whether the operator does what those procedures say.

What the standard actually says

Three chapters that argue for less.

Chapter 3 — Personnel

The standard asks that staff be trained, that training match the tasks actually assigned, and that its effectiveness be appraised. Not that someone signed off having read a binder. A procedure the operator cannot apply as written is a chapter 3 problem before it is a documentation problem.

Chapter 13 — Deviations

A deviation must be documented, investigated, and closed by a reasoned decision. The text does not say "add a control". If your standard answer to a deviation is one more line in a procedure, you are not answering chapter 13: you are documenting your decision not to look for the cause.

Chapter 17 — Documentation

The requirements are about control: identifiable versions, approval, distribution, withdrawal of superseded versions, archiving. All of them hold up better with a small document set. Two hundred documents satisfy chapter 17 on paper and betray it in practice, because nobody can guarantee that no obsolete version is still circulating at the workstation.

Our conviction

One more document has never prevented an error.

And this conviction takes no liberties with ISO 22716: it is the strict reading of it. European Regulation 1223/2009 requires compliance with GMP, and applying ISO 22716 gives presumption of conformity. Neither sets a volume. Whatever you add beyond what is needed, you will have to maintain, distribute, train on and evidence — with no regulatory return whatsoever.

What you gain

Fewer documents, more compliance.

Audit

A small, coherent document set can be defended in interview. A sprawling one offers the auditor that many more chances to find two texts that contradict each other — and they will find them.

Training

Training cost is proportional to the volume people must read. Halving the document set halves the qualification effort, and shortens the time before a new joiner becomes autonomous.

Deviations

A significant share of deviations comes from a procedure that cannot be applied or is contradicted elsewhere. Removing the source brings deviations down without touching a single control.

So the question is not "am I allowed to remove this document?" but "can I trace why I removed it?". That is what chapter 17 is about, and it is entirely doable — we devote a whole article to it.

Frequently asked

ISO 22716, plainly.

Has your document set grown for good reasons?

Two days is enough to find out: what the standard requires, what was added out of caution, and what nobody reads any more.