Data Governance
Data governance is the organisation's ability to ensure that the data its decisions rest on is trustworthy by design rather than by exhortation. It is the ownership structure, risk assessment, and system design that make the ALCOA+ attributes the path of least resistance: unique identities so every action is attributable, audit trails that capture change with reason, access rights that match roles, workflows that force contemporaneous recording, and a data lifecycle managed from creation through archival to destruction. MHRA's 2018 GxP data integrity guidance and PIC/S PI 041 define the governance frame; 21 CFR Part 11 and EU GMP Annex 11 define the controls electronic systems must carry.
What this page does not claim
A capability is something an organization must be able to do; it is not a maturity score and not an assessment domain. The scored domains measure how consistently capabilities are performed, they do not map one-to-one, and nothing on this page rates your organization.
What this capability is
Data governance is the organisation's ability to ensure that the data its decisions rest on is trustworthy by design rather than by exhortation. It is the ownership structure, risk assessment, and system design that make the ALCOA+ attributes the path of least resistance: unique identities so every action is attributable, audit trails that capture change with reason, access rights that match roles, workflows that force contemporaneous recording, and a data lifecycle managed from creation through archival to destruction. MHRA's 2018 GxP data integrity guidance and PIC/S PI 041 define the governance frame; 21 CFR Part 11 and EU GMP Annex 11 define the controls electronic systems must carry.
It differs from document and record control by altitude: record control governs individual documents and records, while data governance governs the systems, flows, and behaviours that produce them. Its working method is the data-flow map — knowing where critical data is created, transformed, and consumed, and where in that flow it is vulnerable — and its proportionality principle comes straight from the guidance: effort follows data criticality and risk, not a blanket over every system. Its cultural half is inseparable from the technical one: systems that make honest recording hard, or treat every error as misconduct, manufacture the integrity failures they claim to prevent.
WHY IT MATTERS
- Every decision in the quality system — release, disposition, trend, approval — is only as good as the data beneath it. Data integrity failures do not just invalidate records; they invalidate the decisions made on them, retrospectively and wholesale.
- Regulators treat data integrity failure as a trust event, not a records event. A single demonstrated manipulation puts every record from the same system and era in doubt, and the remediation — forensic review of years of data — costs more than governance ever would.
- Hybrid systems are the standing vulnerability: electronic originals printed, signed, and treated as the record while the dynamic data and its audit trail sit unexamined. The guidance is explicit that the original record is the one with the full information content, metadata included.
- Audit trails that exist but are never reviewed are a liability dressed as a control: they document, precisely and permanently, everything the organisation failed to look at.
[ POSITION IN THE FRAMEWORK ]
7 DIMENSIONS · 26 LINKSData governance is the capability that makes data integrity real: it owns the controls — access, audit-trail review, data-flow mapping, and retention — across every system that holds a GxP record and every phase that creates one.
06 · QUALITY MATURITY — DATA GOVERNANCE, REACTIVE TO ADAPTIVE
Data integrity is assumed rather than designed: shared logins persist, audit trails are off or unreviewed, blank forms are uncontrolled, and printouts stand in for electronic originals. Failures surface only when an inspector or auditor goes looking.
Policies define ALCOA+ expectations, shared accounts are eliminated, audit trails are enabled, and training covers the rules. Governance is policy-deep: no data-flow mapping, audit-trail review is a periodic formality, and new systems still arrive without integrity requirements attached.
Critical data flows are mapped and risk-assessed; audit-trail review is risk-based, focused, and evidenced; access and privileges are periodically reconciled to roles; and new systems must satisfy integrity requirements before acquisition, not after. Recording errors are treated as signals, not sins.
Governance is measured: integrity indicators — access anomalies, correction rates, review findings — are trended, technical controls replace procedural ones wherever the system can enforce what training used to beg, and a vulnerability found in one system triggers verification across the others.
Trustworthiness is architectural: data flows without manual transcription, integrity controls are designed in at acquisition, review is continuous and increasingly automated, and the organisation can demonstrate the reliability of any critical record on demand — with the metadata to prove it.
SPEQ’s shared five-stage progression, labelled synthesis — not the FDA QMM rating scale. Where does your organization sit? Score your quality system →
07 · REGULATORY & EVIDENCE
GOVERNING STANDARDS · 5
Derived from the 5 standards SPEQ maps to this subject, across 4 regulatory bodies: FDA, EMA, MHRA, PIC/S.
RECORDS & OBJECTIVE EVIDENCE
- A data-governance policy and the current data-integrity risk assessment
- Per-system data-flow and data-lifecycle maps, from creation to disposal
- Audit-trail review schedules with evidenced, risk-based execution
- Access-control matrices with periodic role recertification records
- Retention and disposal schedules tied to each record type
COMMON INSPECTION FINDINGS
- No data-flow map, so raw-data locations and copies are unknown
- Audit-trail review undefined or unevidenced for critical systems
- Access not recertified — leavers and shared accounts still active
- Dynamic data retained only as static printouts (metadata lost)
- Backups taken but restoration never tested against retained data
HOW YOU’D SEE WHERE YOU SIT
- Watch a login on the shop floor or in the laboratory: whose credentials are used, and whether the person who acts is the person the record will name.
- Ask to see the last audit-trail review for a critical system: what was actually examined, what was found, and what changed — a review with no findings ever is a review in name only.
- Follow one critical result from instrument to decision and count the manual transcriptions — each one is an integrity risk the architecture chose to keep.
- How a recording error is corrected, and what happens to the person who made it — the answer predicts whether the next error will be corrected or concealed.
- Where blank forms and worksheets come from, and whether an uncontrolled copy would ever be detected.
Observable behaviours, not a self-rating — what a capability looks like from the outside, the same way SPEQ’s Quality Culture assessment reads behaviour rather than felt safety.
FREQUENTLY ASKED
What is the difference between data integrity and data governance?
Data integrity is a property of the data: the extent to which records are attributable, legible, contemporaneous, original, and accurate — ALCOA+ — throughout their lifecycle. Data governance is the arrangement that produces that property: the ownership, policies, risk assessments, system designs, training, and oversight that make trustworthy data the default output of everyday work. The MHRA guidance draws exactly this line — integrity is the outcome, governance is the system that delivers it. The distinction is practical: an organisation with an integrity problem does not fix data, it fixes governance, because untrustworthy records are the symptom of a system that permitted them.
Why are hybrid systems considered such a data integrity risk?
Because they create two candidate versions of the truth and quietly promote the weaker one. In a typical hybrid arrangement an electronic system generates the result, a printout is signed and filed, and the paper is treated as the record — while the dynamic electronic original, with its metadata, audit trail, and any reprocessing history, sits unexamined. The guidance is clear that the original record is the one carrying the full information content, which the flattened print never does. Hybrids are sometimes unavoidable, but a governed hybrid names the true original, controls it, reviews its audit trail, and treats the print as a convenience copy — not the other way round.
How is data governance measured in the maturity assessment?
Through the Data Integrity domain, which scores the observable state governance produces: whether actions are attributable in practice, whether audit trails are genuinely reviewed, whether errors surface and are corrected openly. That division of labour is the capability-versus-domain distinction: data governance is the function — the designed system of ownership, controls, and flows described on this page — while the assessment domain measures how consistently that system delivers trustworthy data day to day. An organisation can own beautiful governance documents and still score poorly, which is precisely the gap the behavioural questions are built to expose.
MEASURED THROUGH THE MATURITY ASSESSMENT
This capability is about what you must be able to do. How consistently you do it is what the maturity assessment scores — through the domain below.
Contributes to the FDA QMM practice area Advanced Pharmaceutical Quality System (a SPEQ mapping).
Score your quality system →