Data Integrity

Data Governance

What a definition is not

A definition is SPEQ’s plain-language decode of how a term is used in practice, cited to the documents that define it. It is a practitioner reference, not legal or regulatory advice, it does not replace the definition in the source, and where a regulator’s wording differs the regulator’s wording governs.

The complete system of policies, procedures, organisational structures, roles, training, and system controls a company puts in place to ensure that GxP data remains complete, consistent, accurate, attributable, and available throughout its entire lifecycle, from the moment it is created to the moment it is finally disposed of.

Data governance is the umbrella term regulators use for the organisation-wide framework that makes data integrity achievable in practice rather than aspirational. It assigns clear ownership for each data source, defines who may create, modify, or delete a record, and sets the quality-culture expectations — leadership commitment, resourcing, and a no-blame reporting culture — that let staff raise integrity concerns without fear of punishment.

A mature data governance programme is risk-based: it applies the tightest controls to the data with the greatest impact on product quality or patient safety, and it periodically self-assesses through internal audit, computerized-system inventories, and gap analyses rather than waiting for an inspection finding to reveal a weakness.

Inspectors increasingly ask to see the governance framework itself — the policy, the training records, the self-inspection findings — not just a single clean audit trail, because a strong culture and system of controls is what prevents data integrity failures across a whole site, not one well-behaved instrument.

KEY POINTS
  • Assigns clear ownership and accountability for every GxP data source
  • Sets the quality-culture conditions — leadership commitment, resourcing, no-blame reporting — that data integrity depends on
  • Applies controls in proportion to data criticality and risk
  • Is self-assessed through internal audit and periodic gap analysis, not only tested at inspection
  • Covers the full data lifecycle, not a single system or step
REGULATORY BASIS

MHRA GXP Data Integrity Guidance and Definitions (2018); PIC/S PI 041-1; WHO Technical Report Series — Annex on Guidance on Good Data and Record Management Practices

Frequently asked questions

What is Data Governance?

The complete system of policies, procedures, organisational structures, roles, training, and system controls a company puts in place to ensure that GxP data remains complete, consistent, accurate, attributable, and available throughout its entire lifecycle, from the moment it is created to the moment it is finally disposed of.

Which regulations cover Data Governance?

MHRA GXP Data Integrity Guidance and Definitions (2018); PIC/S PI 041-1; WHO Technical Report Series — Annex on Guidance on Good Data and Record Management Practices