· CROSS-CUTTING
GDocP

Good Documentation Practice

ALCOA+ data integrity and record governance.

What this page does not claim

Educational orientation — not a determination of regulatory applicability, compliance, validation scope, or organizational approval.

WHAT IT GOVERNS

Good Documentation Practice governs how GxP records and data are created, reviewed, corrected, stored, and retained — the ALCOA+ principles (Attributable, Legible, Contemporaneous, Original, Accurate, plus Complete, Consistent, Enduring, and Available) applied across both paper and electronic systems. It is the data-integrity discipline underneath every other GxP record.

WHY IT MATTERS

Data integrity is the foundation every other control rests on: in a GxP world, if it isn’t documented, it didn’t happen — and if the documentation can’t be trusted, none of the quality claims built on it can be either. Data-integrity failures (backdating, shared logins, deleted results, uncontrolled audit trails) are among the most severe findings a regulator can issue, up to import alerts and consent decrees.

KEY FOCUS AREAS

01

The ALCOA+ principles

Records that are attributable, legible, contemporaneous, original, and accurate — plus complete, consistent, enduring, and available — as the working definition of trustworthy data.

02

Contemporaneous recording & review

Recording at the time of the activity and independent second-person review, so entries are neither reconstructed after the fact nor self-certified.

03

Audit trails & electronic records

Secure, time-stamped audit trails that capture who did what and when, reviewed as part of the record — the electronic equivalent of an uncorrected logbook.

04

Record retention & archival

Controlled retention, protection from alteration or loss, and retrievability for the full required lifetime of the record.

WHAT INSPECTORS LOOK AT

  • Audit-trail review — is it enabled, complete, and actually reviewed?
  • Contemporaneousness of entries and how corrections are made and justified
  • Access controls, unique logins, and segregation of duties
  • Data governance policy and the lifecycle of both paper and electronic records

KEY REGULATORY BODIES

Derived from the 6 standards SPEQ decodes for this discipline.

RELATED DISCIPLINES

TOPIC EXPLAINERS ACROSS THIS DISCIPLINE
19 total
Data Integrity & ALCOA+
ALCOA+, the data lifecycle, and why integrity is the foundation every GxP claim rests on.
Computer System Validation & CSA
GAMP 5, the risk-based lifecycle, Part 11, and the shift from documentation to critical thinking (CSA).
Master Batch Record (MBR) & Batch Production Records
The approved manufacturing template and the contemporaneous execution record — 21 CFR 211.186/211.188, EU GMP Chapter 4, and the move to electronic batch records.
GLP Study Conduct: Study Director & QAU
What Good Laboratory Practice actually governs — the organisation, roles, and records that make a non-clinical safety study trustworthy and reconstructable, not the quality of its science.
Audit Trail Review
Having an audit trail is not reviewing it — the distinction regulators built an entire enforcement wave on, and how a risk-based review finds the deleted run instead of drowning in keystrokes.
EU GMP Annex 11 (2025 Revision)
The draft revision of the EU GMP computerised-systems annex — lifecycle validation, data integrity, cloud, AI, and cybersecurity as a core GMP requirement.
GDocP: Recording Defensible GxP Data
The GDocP rules — attributable, legible, permanent records — that turn a GxP activity into defensible evidence.
Contemporaneous Recording
The "C" in ALCOA — recording at the time of the activity — and why deferred entries are a data-integrity finding.
Correcting GxP Records
How to change a GxP record defensibly — single-line strike-through, reason, initials, date — on paper and in electronic systems.
21 CFR Part 11 — Electronic Records and Signatures
The FDA rule setting the criteria under which electronic records and electronic signatures are considered equivalent to paper records and handwritten signatures.
Identity & Access Management in GxP Systems
Unique identity, authority checks, segregation of duties, privileged access and periodic review — the controls that make a GxP record attributable.
Labelling, Artwork & Promotional Compliance
Approved labelling and its translations, artwork under change control, and the boundary between an authorised claim and promotion.
Data Privacy & Protection in GxP Environments
Where GDPR meets GxP record-keeping — the retention-versus-erasure conflict, health data as a special category, and encryption that survives an audit trail.
Study Closeout & Results Disclosure
Disclosure obligations are legal duties with deadlines, enforced independently of how the trial went.
Learning, Training & Effectiveness
Retraining a person who already knew the procedure addresses nothing — effectiveness evaluation is what separates a capability gap from a convenient CAPA.
Integration & Interoperability for GxP Data
Errors here are silent by construction — a successful transfer looks identical to a correct one.
Analytics & Decision Support in GxP
Self-service lets a good question be answered quickly and lets a wrong metric spread before anyone checks it.
Records, Content & Retrieval
A record that cannot be found within the time an inspection allows is functionally missing.
Protect vs Disclose — The Trade-Secret Seam
One obligation requires the method and the data behind a regulated product to be written down and filed; another says their commercial value is that they are not. Where the two meet, and which disclosure bites hardest.

GDocP: frequently asked questions

Reference answers on Good Documentation Practice — what it governs, what regulations define it, and what it requires.

What is Good Documentation Practice (GDocP)?

GDocP governs how GxP records and data are created, reviewed, corrected, stored, and retained across both paper and electronic systems. It is the data-integrity discipline underneath every other GxP record — the working principle that if something isn’t documented, it didn’t happen, and if the documentation can’t be trusted, the quality claims built on it can’t be either.

What is ALCOA+?

ALCOA+ is the set of data-integrity principles at the core of GDocP. Records must be Attributable, Legible, Contemporaneous, Original, and Accurate — plus Complete, Consistent, Enduring, and Available. Together they form the working definition of trustworthy GxP data.

What does GDocP require for audit trails and corrections?

GDocP requires contemporaneous recording at the time of the activity and independent second-person review. For electronic records, secure, time-stamped audit trails must capture who did what and when, and be reviewed as part of the record. Corrections must be made so the original entry stays legible, with the reason justified.