Data Integrity
ALCOA+ enforced across GxP systems — because every quality claim rests on it.
Every quality claim ultimately rests on data integrity: a result is only as trustworthy as the record and metadata behind it. Disabled audit trails, shared logins, and review of the printed result without the audit trail are precisely the observations that escalate to warning letters and import alerts — this domain is the foundation the whole system stands on.
The observable evidence a practitioner — or an inspector — would expect at each maturity level. Drawn from the assessment questions themselves.
How are ALCOA+ data-integrity principles enforced across GxP systems?
Data integrity is not formally addressed
A policy exists, but controls vary by system and area
DI governance with audit trails, review, and access controls across GxP systems
DI risk assessments, audit-trail review by exception, and periodic DI audits
Data integrity by design: continuous automated DI monitoring, predictive risk detection, and audit-by-exception across all GxP systems
How are computerised-system audit trails reviewed?
Audit trails are available but rarely reviewed
Audit trails are reviewed only during investigations
Routine risk-based audit-trail review with a documented cadence
Audit-trail review by exception, supported by tooling and metrics
Automated continuous audit-trail surveillance with anomaly detection and predictive exception management
- ›Audit trails disabled, not configured, or never reviewed — the result is reviewed but not the metadata behind it.
- ›Shared or generic logins; inadequate access control and segregation of duties.
- ›Ability to delete or overwrite original records without trace; hybrid systems where paper is treated as the "original".
- ›No data-integrity risk assessment or governance across the GxP system landscape.
Recent FDA recalls whose reason SPEQ maps to this domain — a SPEQ editorial interpretation of the recall reason, not an official FDA classification.