On 28 December 2023, the Ministry of Health and Family Welfare notified a revision to Schedule M of India’s Drugs and Cosmetics Rules, 1945 — published in the Gazette of India on 5 January 2024. It is, by a meaningful margin, the most consequential regulatory development being examined, and it is one most laboratories outside pharmaceutical manufacturing may not have fully registered yet.
To understand why it matters, it helps to first understand what was missing before it. A peer-reviewed comparative analysis published in the International Journal of Pharmaceutical Sciences in May 2026 mapped India’s regulatory framework directly against international standards — FDA 21 CFR Part 11, EU GMP Annex 11, the UK’s MHRA GxP Data Integrity Guidance, and WHO’s TRS 1033 Annex 4 — across eight distinct regulatory domains, including ALCOA+ implementation and computerised system validation. Its finding was blunt: historically, Schedule M contained limited explicit provisions governing electronic data, computerised system validation, audit-trail integrity, or the management of hybrid paper-and-digital systems.
That silence stood in sharp contrast to the FDA and EU frameworks, which had detailed electronic-records requirements in place for years, and it created real variation in how Indian manufacturers actually managed electronic data in practice — because the rules simply hadn’t caught up with how laboratories were already working.
The 2023 revision was built specifically to close that gap. It is worth being precise about what it is and isn’t: Schedule M is a Good Manufacturing Practice regulation, not a standalone data-integrity guidance document in the way the FDA’s 2018 “Data Integrity and Compliance with Drug CGMP” guidance is. But embedded within its broader GMP requirements — alongside new expectations for pharmaceutical quality systems, quality risk management, and product quality review — Revised Schedule M now explicitly mandates a computerised storage system for recording laboratory and manufacturing data, requiring an audit trail that captures every modification made, who made it, and precisely when. The revision brings Indian regulatory expectations for computerised systems substantially closer to international norms, explicitly aligning documentation practice with ALCOA+ principles.
What the Deadlines Actually Are
This is not a distant, theoretical requirement. Large manufacturers, defined as those with turnover above ₹250 crore, were required to achieve compliance by mid-2024. Micro, small, and medium enterprises were given a longer transition window, extended to 31 December 2025 for those that formally applied for the extension through the prescribed form within the stipulated time. India’s Drugs Controller General has indicated no further extensions will be granted after 2026 — meaning the compliance runway most Indian pharmaceutical manufacturers had is now effectively closed or closing.
What “Audit Trail” Actually Means, Mechanically
It’s worth spelling out precisely what an audit trail is, because the term gets used loosely even by people who rely on one daily. An audit trail is not simply a log file or a backup. Properly implemented, per the ALCOA+ framework this regulation now formally aligns with, it is a secure, computer-generated, time-stamped record that independently captures who performed an action, what the action was, and when it happened — created automatically, not manually, and structured so that it cannot be edited or deleted without that edit itself being recorded. ALCOA+ breaks the standard down into its component expectations: data must be Attributable to a specific person, Legible, Contemporaneous (recorded at the time the activity actually happened, not reconstructed afterward), Original, and Accurate — the original five principles — extended by the “+” to also require that records be Complete, Consistent, Enduring, and Available when a regulator asks to see them.
This is precisely where the Dabur case examined in Section 1 of this Cover Story becomes relevant again, not as a separate cautionary tale but as a direct illustration of these exact principles failing in practice: records that were not contemporaneous, because they were created after the fact to conceal how equipment had actually been used, and therefore neither attributable to the truth of the situation nor original in any meaningful sense.
Where NABL Fits — and Where It Doesn’t
A common point of confusion worth resolving directly: NABL, the National Accreditation Board for Testing and Calibration Laboratories, is sometimes discussed as though it maintains its own independent data-integrity rules, separate from CDSCO’s. That’s not quite accurate. NABL’s accreditation authority derives from ISO/IEC 17025:2017, the international standard governing laboratory competence — and it is ISO/IEC 17025 itself, not a separate NABL-specific rule, that contains the operative requirement: laboratories must ensure the integrity, confidentiality, and security of their data, with controls preventing unauthorised access, alteration, or loss, across both physical and electronic records. NABL accreditation matters enormously in practice — CDSCO, FSSAI, and the Central Pollution Control Board all require NABL-accredited results for legal acceptance — but its data-integrity authority is inherited from an international standard India has adopted, not a standalone domestic invention.
Why This Section Is the Piece’s Backbone
Every other section of this Cover Story ultimately routes back to what’s described here. The interoperability failures examined in Section 4 matter because a migration error can produce exactly the kind of audit-trail discrepancy Schedule M and ALCOA+ now explicitly govern. The workforce gap examined in Section 5 matters partly because the hybrid skills laboratories increasingly need include the literacy required to maintain compliant audit trails, not just operate new software. And the open questions examined in the next section — around AI decision-making, vendor lock-in, and data protection — all ultimately test against the same underlying standard this section has just laid out: can a laboratory produce a record that is attributable, contemporaneous, original, and available, regardless of what generated it or what software is managing it.
Regulation, in other words, is not the boring compliance chapter of this story. It is the specification against which everything else in this Cover Story is being measured.
– Kumar Tataji


