How to Perform a Data Integrity Assessment
Find where your records could be altered, deleted, or fabricated — before an inspector does.
What a how-to is not
A how-to is SPEQ’s practitioner method, not a procedure. It does not replace your own SOP, it is not a validated approach, and the judgement calls in it belong to your quality unit.
A data integrity assessment evaluates whether your records are Attributable, Legible, Contemporaneous, Original, and Accurate (ALCOA+) across their lifecycle, and where they are vulnerable to undetected alteration, deletion, or fabrication. It covers paper and electronic systems, and is now a standard part of inspection readiness because data-integrity failures are among the most serious findings.
- 1
Map the data lifecycle
Map the data lifecycle for each system and process in scope — where data is generated, how it is processed, who reviews it, how it is reported, where it is retained, and how it is eventually disposed of. The map is the assessment’s foundation, because a control can only be judged against the stage it protects, and the stages nobody mapped are the ones with no controls.
- 2
Assess against ALCOA+
Assess each stage against ALCOA+ explicitly, asking at each point whether the record is attributable, legible, contemporaneous, original and accurate, and whether it remains complete, consistent, enduring and available. Working stage by stage rather than principle by principle is what surfaces the weak link, since the weakest stage sets the ceiling for the whole lifecycle.
- 3
Examine system controls
Examine the system controls that make the answers true: unique accounts, role separation, audit trails that users cannot disable, backup and restore that has been tested, and the configuration that determines whether records can be altered or deleted without trace. Verify these as configured rather than accepting the supplier’s description of the capability.
- 4
Look for the risk behaviours
Look for the behaviours that indicate pressure rather than the violations that indicate intent: transcription from informal notes, spreadsheets running alongside validated systems, repeat analyses without documented reason, audit trails nobody has read, and forms that cannot be completed as written. Each is a design signal, and finding them requires observation rather than interview.
- 5
Rate risk and remediate
Rate the risk for each gap by what it could allow rather than by how hard it is to fix, and remediate accordingly — with interim controls where the permanent fix takes time. A remediation plan ordered by ease produces early progress on the least consequential items and is a recognisable pattern.
- 6
Re-assess periodically
Re-assess periodically and after significant change, because the answer degrades: systems are upgraded, people leave, workloads rise, and a workaround introduced under pressure becomes normal practice. An assessment performed once is a statement about a date.
- !Assessing systems in isolation rather than following the data across its whole lifecycle.
- !Treating audit trails as present-and-therefore-fine without checking that they are actually reviewed.
- !Ignoring uncontrolled spreadsheets and standalone instruments — a frequent real-world gap.
- !Shared logins that break attributability, left unaddressed.
How to Perform a Data Integrity Assessment: frequently asked questions
Common questions on perform a data integrity assessment.
What is ALCOA+?
ALCOA stands for Attributable, Legible, Contemporaneous, Original, and Accurate — the core attributes of reliable records. The "+" adds Complete, Consistent, Enduring, and Available. Together they define what data integrity means and give an assessment its criteria.
What are the most common data-integrity failures?
Shared or generic logins (breaking attributability), disabled or unreviewed audit trails, "testing into compliance" (repeating a test until it passes), uncontrolled spreadsheets, records completed non-contemporaneously, and the ability to alter or delete original data without a trace.
Does data integrity apply to paper records?
Yes. ALCOA+ applies to both paper and electronic records. For paper, the assessment looks at controlled forms, contemporaneous completion, proper correction practices (no obscuring originals), and independent review — not just at computer systems.
Why is audit-trail review important?
An audit trail only protects integrity if someone reviews it. Regulators expect risk-based review of audit trails (especially for critical data) as part of the record review before release — an audit trail that is captured but never examined provides little assurance.