The FDA's enforcement posture has shifted significantly. In 2025, Warning Letters issued to pharmaceutical, biotech, and medical device manufacturers increased by 34% compared to the prior year — the highest rate since 2018. For regulated manufacturers, this is not a statistic to file away. It is a direct signal that current compliance programs are falling short.

The Top Citation Categories

Three categories dominate 2025 FDA Warning Letters:

1. Data Integrity Failures — Missing audit trails, shared user accounts, and backdated records continue to top the list. FDA inspectors now specifically look for audit trail review SOPs and evidence of periodic review. If your team cannot produce a dated, signed audit trail review for the past 12 months, expect a citation.

2. Inadequate Computer System Validation — Systems placed into GxP use without formal validation documentation remain a persistent finding. FDA's 2022 Computer Software Assurance (CSA) guidance shifted focus from documentation volume to critical thinking — but many manufacturers are still producing checkbox compliance documents that satisfy neither the old standard nor the new one.

3. Failure to Follow Written Procedures — SOPs exist but aren't followed. Change control procedures bypassed. Deviation records incomplete. This finding is entirely preventable and reflects a training and culture gap rather than a documentation gap.

What Happens After a Warning Letter

A Warning Letter is not the end of the process — it is the beginning of a much more expensive one. Companies that receive Warning Letters face mandatory response deadlines (typically 15 business days), third-party audit requirements, potential import alerts that block products from US markets, and in severe cases, consent decrees requiring FDA-approved oversight of all manufacturing operations.

The average cost of responding to and remediating a Warning Letter — including consultant fees, internal resource allocation, and potential revenue loss — ranges from $500,000 to $5 million depending on the severity and scope.

What Your Team Should Do Now

Conduct an internal gap assessment against the top citation categories before FDA does it for you. Focus specifically on audit trail completeness and review frequency, user access controls and shared account elimination, and CSV documentation for all GxP-critical systems.

Run a mock FDA inspection using current inspection protocols. The questions inspectors ask have become highly predictable — preparation is entirely possible.

Review your 21 CFR Part 11 posture. If your electronic records system was validated more than three years ago and has not been reviewed since, assume it has gaps.