Data Integrity

Review by Exception

What a definition is not

A definition is SPEQ’s plain-language decode of how a term is used in practice, cited to the documents that define it. It is a practitioner reference, not legal or regulatory advice, it does not replace the definition in the source, and where a regulator’s wording differs the regulator’s wording governs.

A data-review approach in which reviewers rely on validated software logic to flag anomalies, out-of-expected-range values, or metadata and audit trail changes, and examine only those flagged exceptions rather than manually inspecting every individual data point — acceptable only where the underlying exception-detection logic has itself been validated and challenged.

As computerized systems generate ever larger volumes of data, manually reviewing every raw data point line by line becomes impractical. Review by exception uses validated software rules — statistical limits, expected ranges, configuration checks — to surface only the records that need human attention, letting reviewers focus effort where risk actually is.

The approach is only as trustworthy as the logic behind it: the exception rules themselves must be specified, validated, and periodically challenged with known bad data to confirm they actually catch what they are meant to catch, and the audit trail of who changed those rules must itself be reviewed.

Review by exception does not remove the requirement to review audit trails and metadata for the underlying records — it changes how that review is targeted, not whether it happens, and it must be justified through a documented risk assessment rather than adopted purely to save reviewer time.

KEY POINTS
  • Uses validated software logic to flag anomalies for review, not to eliminate review
  • The exception-detection logic itself must be validated and periodically challenged
  • Must be justified by documented risk assessment, not adopted only to reduce workload
  • Changes to the exception rules must themselves be controlled and auditable
REGULATORY BASIS

PIC/S PI 041-1; MHRA GXP Data Integrity Guidance (2018)

Frequently asked questions

What is Review by Exception?

A data-review approach in which reviewers rely on validated software logic to flag anomalies, out-of-expected-range values, or metadata and audit trail changes, and examine only those flagged exceptions rather than manually inspecting every individual data point — acceptable only where the underlying exception-detection logic has itself been validated and challenged.

Which regulations cover Review by Exception?

PIC/S PI 041-1; MHRA GXP Data Integrity Guidance (2018)