Regulatory Record

Consent Decree

On January 25, 2012, the Department of Justice (DOJ), acting at the request of the Food and Drug Administration (FDA), filed a consent decree of permanent injunction against generic drug manufacturer Ranbaxy…

Record focus

Inside Ranbaxy’s Consent Decree: What the Terms Reveal About FDA’s Enforcement Standard and the Manufacturing System It Will Accept

Open Source ↗
Warning Letter cover for Consent Decree
01Primary sourceRegulatory authority record
02Evidence contextOrganization and inspection context
03Traceable recordSource details retained with the record
04Decision supportInterpret the record alongside related XGene analysis.

Source Context

Record typeWarning Letter
PublishedAug 22, 2026
On this recordRecord overview

    Regulatory Event

    On January 25, 2012, the Department of Justice (DOJ), acting at the request of the Food and Drug Administration (FDA), filed a consent decree of permanent injunction against generic drug manufacturer Ranbaxy Laboratories Ltd. and its U.S. subsidiary Ranbaxy Inc. in the U.S. District Court for the District of Maryland (Case No. JFM-12-250). No new pharmaceutical consent decree was identified in FDA’s or the Department of Justice’s public enforcement record during this reporting window, so this article revisits Ranbaxy fourteen years later — not as breaking news, but because it remains the single most instructive data integrity consent decree in generic pharmaceutical history, and because, as the record below shows, its obligations outlived not just the initial remediation period but the company itself as an independent entity. The decree covered Ranbaxy’s Paonta Sahib, Batamandi, and Dewas facilities in India and the Ohm Laboratories facility in Gloversville, New York, and it was, in DOJ’s own words at the time, “unprecedented in its scope.”

    The decree did not arrive without warning, and the warning history is itself the first lesson. FDA issued a Warning Letter to Ranbaxy’s Princeton, New Jersey office in 2002, followed by a Warning Letter to the Paonta Sahib facility in 2006. By September 2008, FDA had issued Warning Letters covering both the Dewas and Batamandi (Paonta Sahib Unit II) facilities and placed drugs from both on Import Alert the same day — meaning Ranbaxy had not imported product from those sites into the United States for more than three years before the consent decree was even filed. In February 2009, FDA escalated further, invoking its Application Integrity Policy against the Paonta Sahib plant, a rarely used tool that allows the agency to stop reviewing a facility’s pending applications until data reliability is independently restored. A second U.S.-facility Warning Letter followed in December 2009, this time for Ohm Laboratories in Gloversville. By the time DOJ filed the consent decree in January 2012, FDA had spent roughly a decade escalating through warning letters, an import alert, and an application integrity action — the standard enforcement ladder — before concluding that court oversight was the only remaining option.

    What the Record Documents

    What made this case different from a typical Current Good Manufacturing Practice (CGMP) manufacturing failure was the nature of the underlying conduct. According to DOJ’s January 2012 announcement, the government’s investigation found that Ranbaxy failed to keep written records showing drugs had been manufactured properly, failed to investigate evidence that drugs did not meet specifications, failed to adequately separate penicillin from non-penicillin production to prevent cross-contamination, and ran an inadequate stability testing program. But the finding that drove the consent decree’s unusual scope was that Ranbaxy had submitted false data in drug applications to FDA, including backdated tests and test data for samples that did not exist. This is a materially different problem than a facility with poor environmental controls: it is not a question of whether the manufacturing system was capable of producing quality product, but whether anything the company told FDA about that system could be trusted. That distinction is why the decree’s remedies went beyond facility remediation — Ranbaxy was required to hire an outside expert to conduct a thorough internal review of the affected facilities and audit every application containing data from them, withdraw any application found to contain false data, establish a separate internal office of data reliability, and retain an outside auditor for ongoing verification. FDA was not asking Ranbaxy to fix a process; it was asking Ranbaxy to prove which of its historical regulatory submissions could still be believed.

    The parallel criminal and civil track that followed is the detail General Counsels and Board members should study most closely, because it is what distinguishes a consent decree from a corporate crisis. In May 2013, Ranbaxy USA Inc. pleaded guilty to three felony Food, Drug and Cosmetic Act counts and four felony counts of knowingly making material false statements to FDA, admitting that batches of Sotret (isotretinoin), gabapentin, and ciprofloxacin manufactured at Paonta Sahib in 2005 and 2006 were adulterated, and that the company knew as early as January 2003 that a Sotret batch had failed a stability test yet continued distributing it for another thirteen months. The company also admitted to filing false Annual Reports with FDA in 2006 and 2007 misrepresenting when stability testing on several cephalosporin and penicillin-class antibiotics was actually performed. The resolution totaled $500 million: a $130 million criminal fine plus $20 million forfeiture, and a $350 million False Claims Act settlement resolving a qui tam action brought by former Ranbaxy executive Dinesh Thakur, who received approximately $48.6 million of the federal recovery as the whistleblower. At the time, DOJ and the U.S. Attorney for the District of Maryland described it as the largest False Claims Act case ever prosecuted in that district and the largest financial penalty a generic drug manufacturer had paid for Food, Drug and Cosmetic Act violations — a reminder that a civil consent decree and a criminal Department of Justice (DOJ) prosecution are not alternative outcomes but can run on entirely separate, simultaneous tracks arising from the same underlying facts.

    Technical and Quality Context

    What happened after 2013 is the part of this case least discussed publicly, and it is the most useful data point for anyone trying to estimate how long a consent decree’s obligations actually last. The decree’s reach was not static: FDA issued a violation-of-consent-decree letter for Ranbaxy’s Mohali, India facility in September 2013 and simultaneously barred that plant from manufacturing FDA-regulated drugs, then issued a second violation letter for the Toansa, India facility in January 2014, again halting production there. Sun Pharmaceutical Industries Ltd. announced its acquisition of Ranbaxy in 2014 and completed the merger in March 2015 — meaning the consent decree’s obligations transferred to Ranbaxy’s corporate successor rather than resolving with the change of ownership. FDA inspected the Mohali facility again in November 2016, issued a Resume Operations letter to Sun Pharma in March 2017, and — most notably — issued a Consent Decree Correspondence/Non-Compliance Letter to Sun Pharma regarding Mohali as recently as May 4, 2023, eleven years after the decree was entered. FDA’s own official index of Ranbaxy/Sun Pharma actions does not show a lifting or termination order for the original 2012 decree as of its most recent published update, and this compilation could not independently confirm status beyond that point — a limitation worth stating plainly rather than assuming resolution that has not been publicly documented.

    That longevity is worth holding against the two comparison cases most often cited alongside Ranbaxy. The Hi-Tech Pharmacal decree, entered in 2006 for sterile manufacturing failures at its Amityville, New York facility, required a court-appointed expert to review batch records before release and audit the site semi-annually; that expert reviewed more than 200 batch records over four years before FDA agreed to a modified order. Able Laboratories sits at the opposite extreme: its 2005 consent decree, following systematic deletion of dissolution test failures at its Toms River, New Jersey facility, ended in the company’s closure because the cost of compliance exceeded its ability to keep operating. Ranbaxy landed between those outcomes — the company survived, but its obligations under the original injunction outlasted its existence as an independent entity, persisted through a change in corporate control, and generated new violation findings at facilities not even named in the original 2012 filing.

    Decision Relevance

    For any manufacturer, General Counsel, or Board currently modeling data integrity risk, the Ranbaxy record answers a question most consent decree coverage never addresses: what does “unprecedented in scope,” in DOJ’s own 2012 language, actually cost over a decade, not just at signing. It is not simply the $500 million criminal and civil resolution, though that figure alone should reframe how boards price data integrity exposure relative to a routine CGMP finding. It is that a data integrity consent decree does not close when the initial facilities are certified — it extends to newly identified sites, survives mergers and acquisitions, and generates fresh FDA correspondence more than a decade after the ink dried. Every manufacturer currently managing a data-integrity-driven Warning Letter, including the pattern XGene has tracked this year at Huons Co., Ltd. and Wizcure Pharmaa Private Limited, and the FDA and European Medicines Agency (EMA) dual enforcement action against Zenzi Pharmaceutical Industries, is looking at an earlier stage of the same escalation logic this case illustrates at its most severe and longest-running endpoint.

    XGene Consulting supports quality, regulatory, and legal teams at each stage of that continuum: Warning Letter and 483 remediation built around root-cause and data integrity assessment rather than a paper CAPA (Corrective and Preventive Action) response; consent decree readiness assessment ahead of DOJ/FDA negotiation; and third-party expert support, including the technical documentation an independent auditor will need to certify data reliability under decree terms. If your organization is carrying data integrity risk anywhere in its ANDA (Abbreviated New Drug Application) or NDA (New Drug Application) portfolio, the Ranbaxy case is worth studying in full before a regulator studies it for you.

    Primary regulatory references

    From record to action

    Use the evidence in context.

    Continue into related XGene analysis or discuss the technical implication when the issue needs action.

    Discuss a Project