What a role map is not
A role map is orientation — not a job description, a competency framework, or a statement of what any employer expects of you.
You make sure the numbers the company relies on are the numbers that were actually produced, and that anyone can later see who produced them, when, and from what.
You apply ALCOA+ across paper and electronic records, assess systems for audit-trail adequacy and review-by-exception, govern shared logins and privilege separation, and run the data-integrity element of investigations. MHRA’s 2018 GxP guidance and PIC/S PI 041 are your working references, with 21 CFR Part 11 and EU GMP Annex 11 as the binding requirements.
Data integrity failures are almost never fraud. They are ordinary systems that made the truthful path harder than the convenient one, which makes this a design responsibility rather than a policing one.
YOUR NEIGHBOURHOOD, IN ONE CONNECTED SYSTEM
Across every function that generates a GxP record — laboratory, manufacturing, clinical and quality — rather than inside any one of them.
- System design and configuration decisions
- Procedures that define how a record is made
- Regulatory submissions built on the data
- Batch release and clinical decisions that rely on it
- System owners who can explain what their audit trail actually captures
- IT for privilege management and time synchronisation
- Quality assurance for the procedural framework the controls sit in
- Every inspector who asks how a result was produced
- Investigators reconstructing what happened during a deviation
- Regulatory affairs, whose submissions inherit the credibility of the underlying data
- The data-integrity risk assessment and its criticality ranking
- The audit-trail review expectation — what is reviewed, by whom, how often
- The judgement that a control gap is or is not acceptable pending remediation
- The systems themselves, which belong to their business owners
- IT infrastructure and backup execution
- The disciplinary outcome where a falsification is found
- The quality head, where a gap affects data already used for release or submission
- Senior management, where remediation requires a system to be taken out of use
- Data-integrity risk assessments and system-level gap analyses
- Audit-trail review records and the exceptions they raised
- Remediation plans with interim controls stated, not implied
WHAT THIS ROLE CAN EVIDENCE · 1
Mapped to this role in the published registry. Nothing on this site assesses them yet, so this is what the standard says the work involves — never a claim about you.
A role map is Locate, moment 2 of 5: what surrounds your work, what you own, and what you escalate. It does not teach the practice or test it. Next is Learn — the Computer System Validation pathway, then Practise in a scenario, then what any of it evidences. Skip any of them — the order does not change.
The regulations and standards this pathway anchors on. SPEQ decodes and cites each one; the authoritative text lives at the official source.
- 21 CFR Part 11Electronic Records; Electronic SignaturesFDA · last revised 1997-08-20
- EU GMP Annex 11Computerised SystemsEMA · last revised 2011-06-01
- ICH Q9(R1)Quality Risk ManagementICH · last revised 2023-01-18
- ISPE GAMP 5 (2022)Good Practice Guide: Compliant GxP Computerised SystemsISPE · last revised 2022-04-01