What the regulation says
The text is short. It requires that any unexplained discrepancy or the failure of a batch or its components to meet any of its specifications be thoroughly investigated, whether or not the batch has already been distributed. The investigation must extend to other batches of the same drug product and other drug products that may have been associated with the failure. It must be recorded in writing, and it must include the conclusions and follow-up.
That is four obligations in one paragraph: thorough, extended, written, concluded.
The regulation does not name a form, a template, a timeline, or a root-cause methodology. Those come from your own procedures. What it fixes is the content the record has to contain — which is why an investigation can follow your SOP exactly and still be thin against 211.192.
The four things, and what each looks like on the page
1. Thoroughly investigated
Thorough is not a length. A thorough investigation shows what was considered and ruled out, not only what was concluded. A record that names one cause and stops has not shown its work — a reader cannot tell whether alternatives were dismissed for a reason or never raised.
2. Extended to other batches
This is the requirement most often missing, and the one an investigator asks about first — because it is the question that decides whether product already released is affected. The record needs to say which other batches were considered, on what basis, and what was concluded. A single sentence asserting no impact is an answer without a reason.
Note what the second version gives a reader: a boundary, a method, a number of batches, and a place to check. None of that requires the conclusion to be different.
3. Recorded in writing
The obligation is the record, not the meeting. Discussion that happened but was never written is, to a reader, discussion that did not happen. This is where investigations lose their reasoning: the assessment was genuinely done, in a room, and the record captured only its output.
4. Conclusions and follow-up
A conclusion states what happened and why it was allowed to. Follow-up states what changes and how anyone will know it worked. An investigation that ends at a conclusion has satisfied half of the fourth requirement.
The swap test. Read the conclusion, then read the event title. If you could exchange one for the other and lose no information, the conclusion is restating the event rather than explaining it. That is the circular root cause pattern, and it is the single most common reason a 211.192 record reads as thin.
The four gaps, in the order they get found
- No other-batch reasoning. Present as a sentence, absent as an assessment.
- A conclusion that restates the event. "Root cause: analyst did not follow the sampling plan" for an event titled "Sampling plan not followed."
- Follow-up with no verification. An action is named; nothing says how anyone will know it worked, or when that gets checked.
- A procedure cited without a revision. "Performed per SOP-220" leaves the reader unable to tell whether the version in force on the event date is the version described.
Where this sits in Dry Run. The quality-event criteria pack checks the mechanical parts of this — whether a procedure is cited with a revision, whether scope is stated, whether a conclusion restates its event, whether follow-up names a verification. Each criterion carries its regulatory reference as fixed text written by a person; the model is instructed not to produce citations, because a citation is a checkable fact and generating one fresh per run means getting it right by coincidence.
What it cannot judge is whether your science is correct or your batch boundary is right. Those stay with the reviewer, and a screening that returns REVIEW on them is telling you the document did not contain enough to decide — not that the point is fine.
See it on sample data. The demo screens a canned deviation-style record and flags where an investigation is thin — including scope and follow-up.