· COMPREHENSIVE

Data Integrity

ALCOA+ enforced across GxP systems — because every quality claim rests on it.

QMM · Advanced Pharmaceutical Quality SystemGDocPGood Documentation Practice
Assess this domain →
WHY IT MATTERS

Every quality claim ultimately rests on data integrity: a result is only as trustworthy as the record and metadata behind it. Disabled audit trails, shared logins, and review of the printed result without the audit trail are precisely the observations that escalate to warning letters and import alerts — this domain is the foundation the whole system stands on.

WHAT GOOD LOOKS LIKE

The observable evidence a practitioner — or an inspector — would expect at each maturity level. Drawn from the assessment questions themselves.

How are ALCOA+ data-integrity principles enforced across GxP systems?

1Foundational

Data integrity is not formally addressed

2Defined

A policy exists, but controls vary by system and area

3Managed

DI governance with audit trails, review, and access controls across GxP systems

4Quantified

DI risk assessments, audit-trail review by exception, and periodic DI audits

5Optimized

Data integrity by design: continuous automated DI monitoring, predictive risk detection, and audit-by-exception across all GxP systems

How are computerised-system audit trails reviewed?

1Foundational

Audit trails are available but rarely reviewed

2Defined

Audit trails are reviewed only during investigations

3Managed

Routine risk-based audit-trail review with a documented cadence

4Quantified

Audit-trail review by exception, supported by tooling and metrics

5Optimized

Automated continuous audit-trail surveillance with anomaly detection and predictive exception management

COMMON INSPECTION FINDINGS
  • Audit trails disabled, not configured, or never reviewed — the result is reviewed but not the metadata behind it.
  • Shared or generic logins; inadequate access control and segregation of duties.
  • Ability to delete or overwrite original records without trace; hybrid systems where paper is treated as the "original".
  • No data-integrity risk assessment or governance across the GxP system landscape.
RECOMMENDED SPEQ RESOURCES
STANDARD21 CFR Part 11STANDARDEU GMP Annex 11
WHAT IT LOOKS LIKE WHEN IT FAILS — LIVE FDA RECALLS

Recent FDA recalls whose reason SPEQ maps to this domain — a SPEQ editorial interpretation of the recall reason, not an official FDA classification.

2026-07-15Class IIMedtronic MiniMed, Inc.

A software anomaly can occur when the pump is paired with the Instinct sensor. Under certain circumstances, the pump unexpectedly stops delivering insulin and displays two error messages back-to-back: Pump Error 53 followed immediately by Pump Error 23. Insulin delivery will stop which may lead to delayed therapy and an increased risk of hyperglycemia or diabetic ketoacidosis (DKA).

2026-07-15Class IICMR SURGICAL LIMITED

Secure Boot was mistakenly not enabled at manufacturing time, which presents a potential cybersecurity risk.

2026-07-01Class IIIPG Medical Corporation

Software anomaly that causes a false display of error code 5018.

2026-06-24Class IIMedtronic Navigation, Inc.-Boxborough

Potential for image artifacts caused by an anomaly in the O-arm O2 Imaging System s detector panel firmware.

All recalls SPEQ maps to this domain →
ALL DOMAINS
Every maturity domain, decoded →
FDA QMM
How this rolls up to Advanced Pharmaceutical Quality System →
THE FRAMEWORK
Where this domain sits in the operating model →