SCADA
Supervisory Control and Data Acquisition
What a definition is not
A definition is SPEQ’s plain-language decode of how a term is used in practice, cited to the documents that define it. It is a practitioner reference, not legal or regulatory advice, it does not replace the definition in the source, and where a regulator’s wording differs the regulator’s wording governs.
The supervisory layer above controllers that visualises plant state, issues setpoints, records data and manages alarms across multiple systems. Because it is usually where GMP records are created and retained, it carries data-integrity obligations the controllers beneath it may not.
SCADA is the supervisory layer above the controllers: it visualises plant state, issues setpoints, manages alarms and — critically — records and retains the data. That last function is what gives it regulatory weight disproportionate to its control role, because the GMP record of what happened is usually created here rather than in the PLC beneath it.
So the data-integrity expectations land on this layer. Unique user accounts, role separation between operator and engineer, an audit trail covering parameter and recipe changes that users cannot disable, and a retention and backup arrangement that survives the server it runs on. The controllers underneath frequently have none of these, which is the intended arrangement — but only if the supervisory layer actually captures what they do.
The seam between the two is where assurance is commonly lost. A parameter changed at the controller rather than through SCADA, a forced input, or a local override may never reach the record, and the system will show a clean history of an event it never saw. Verifying that the supervisory layer captures controller-level changes is part of validating it.
- —Supervisory layer: visualisation, setpoints, alarms, and the data record.
- —Usually where the GMP record is created, so data-integrity expectations land here.
- —Needs unique accounts, role separation and an audit trail users cannot disable.
- —Controllers beneath it often have no audit trail — by design, if SCADA captures them.
- —Changes made at the controller may never reach the record; verify that seam.
EU GMP Annex 11 (§9 audit trails, §12 security); 21 CFR Part 11; ISPE GAMP 5 (2nd ed., 2022); MHRA GxP Data Integrity Guidance (2018).
Frequently asked questions
What does SCADA stand for?
SCADA stands for Supervisory Control and Data Acquisition.
What is SCADA?
The supervisory layer above controllers that visualises plant state, issues setpoints, records data and manages alarms across multiple systems. Because it is usually where GMP records are created and retained, it carries data-integrity obligations the controllers beneath it may not.
Which regulations cover SCADA?
EU GMP Annex 11 (§9 audit trails, §12 security); 21 CFR Part 11; ISPE GAMP 5 (2nd ed., 2022); MHRA GxP Data Integrity Guidance (2018).