Data Integrity

Data Criticality

What a definition is not

A definition is SPEQ’s plain-language decode of how a term is used in practice, cited to the documents that define it. It is a practitioner reference, not legal or regulatory advice, it does not replace the definition in the source, and where a regulator’s wording differs the regulator’s wording governs.

A risk-based judgement of how much a given data point or record influences a product-quality or patient-safety decision, used to decide how tightly that data needs to be controlled — for example, how often its audit trail is reviewed, or how quickly an anomaly must be investigated — rather than applying one uniform control level everywhere.

Not every piece of data carries the same regulatory weight. A final assay result that determines batch release is data-critical; an informal bench note that never feeds a decision is not. Data criticality assessment asks, for each data point or record type, what decision it feeds and what the consequence would be if that data were wrong, missing, or manipulated.

The assessment typically considers the GxP impact of the decision the data supports, how directly the data feeds that decision, and the likelihood and detectability of an integrity failure at that point. High-criticality data — release testing, stability results, batch disposition — gets the tightest controls: mandatory second-person verification, frequent audit trail review, and restricted system access.

This is a practical necessity, not an excuse to under-control low-risk data — regulators expect the criticality assessment itself to be documented and defensible, because “we did not think it mattered” is not an acceptable answer if the record later turns out to matter.

KEY POINTS
  • Ranks data by the GxP decision it feeds and the consequence of it being wrong
  • Drives proportionate control — audit trail review frequency, verification level, system access
  • Must be documented and defensible, not an informal assumption
  • Complements, rather than replaces, uniform baseline controls like unique login and time synchronisation
REGULATORY BASIS

PIC/S PI 041-1; MHRA GXP Data Integrity Guidance (2018) — risk-based approach to data integrity

Frequently asked questions

What is Data Criticality?

A risk-based judgement of how much a given data point or record influences a product-quality or patient-safety decision, used to decide how tightly that data needs to be controlled — for example, how often its audit trail is reviewed, or how quickly an anomaly must be investigated — rather than applying one uniform control level everywhere.

Which regulations cover Data Criticality?

PIC/S PI 041-1; MHRA GXP Data Integrity Guidance (2018) — risk-based approach to data integrity