FDARegulatory IntelligenceGuidanceHIGH INSPECTION RISK
FDA DI & CGMP Q&A (2018)

Data Integrity and Compliance With Drug CGMP: Questions and Answers

FDA's final guidance (December 2018) answering eighteen questions on how data integrity fits within the drug CGMP regulations — Parts 210, 211, and 212. It defines data integrity, metadata, and audit trail; sets expectations for system access, blank-form control, audit-trail review, and true copies; and describes how FDA expects firms to address data-integrity problems. The US counterpart of the MHRA GxP data-integrity guidance.

LAST REVISED
December 2018
PRODUCT AREAS
SterileSolid DoseApiBiotech

What this does not cover

stated in the document's own scope
  • Interprets the drug CGMP regulations (Parts 210, 211, 212); it does not extend to GCP, GLP, or device quality-system records, which have their own regulations and guidance.
  • Explains how existing CGMP requirements apply to data; it creates no new requirements and is guidance, not a rule.
  • Addresses data integrity within manufacturing and laboratory operations; the criteria for electronic records and signatures themselves remain in 21 CFR Part 11.
SOURCE & PROVENANCE
ISSUING BODY
Food and Drug Administration
JURISDICTION
United States
DOCUMENT ID
FDA DI & CGMP Q&A (2018)
Official site — Food and Drug Administration

Always verify against the current published text before relying on it for a submission or inspection.

Overview

FDA's "Data Integrity and Compliance With Drug CGMP: Questions and Answers" is the agency's data-integrity guidance for drug manufacturers, finalised in December 2018. In eighteen questions and answers it explains how data-integrity expectations flow from the existing CGMP regulations: what the terms data integrity, metadata, and audit trail mean; when workflows on computerised systems must be validated; how access to CGMP systems should be restricted; why blank forms need control; how audit trails should be reviewed and by whom; what counts as a true copy; and how electronic data may be retained. It closes with FDA's expectations for addressing data-integrity problems, including scoping the failure and assessing its effect on product quality.

Scope & applicability

Drug manufacturers subject to the CGMP regulations for finished pharmaceuticals and APIs (21 CFR Parts 210, 211, and 212, and the ICH Q7 expectations FDA applies to APIs). The Q&As interpret existing CGMP requirements; they do not create new ones.

Legal basis & how it acquires force

A guidance for industry from the FDA Center for Drug Evaluation and Research and Center for Biologics Evaluation and Research, issued in final form in December 2018 and announced in the Federal Register on 13 December 2018. It interprets the current good manufacturing practice regulations in 21 CFR Parts 210, 211, and 212 — each answer cites the specific CGMP provision it rests on — and, like all FDA guidance, describes the agency's current thinking without itself creating binding requirements.

Document structure

PartCovers
Introduction and backgroundPurpose, the CGMP context, and why data integrity is foundational to the drug-quality system
Definitions (Q&A 1)Data integrity, ALCOA, metadata, audit trail, static and dynamic records, backup, and systems
System design and access controlsValidation of computerised workflows, restricting system access, and the problems with shared login accounts
Records controlsBlank-form control, audit-trail review and its frequency, true copies, and retention of electronic data
Training and remediationPersonnel training in detecting data-integrity issues, and how FDA expects firms to address identified data-integrity problems

Key requirements

  • Data integrity controls anchored to specific CGMP citations — the guidance maps each expectation to the underlying regulation
  • Computerised-system workflows validated for their intended use, not just the software in isolation
  • System access restricted and shared login accounts for CGMP records avoided
  • Blank forms controlled and reconciled so unofficial re-creation of records is detectable
  • Audit trails reviewed with a frequency and rigour tied to the record's CGMP role
  • Data-integrity problems addressed comprehensively: scope the failure, assess product risk, and remediate the quality system

Implementation tips

  • Treat the eighteen Q&As as an audit aid: each answer cites the CFR provision it interprets, which gives you the regulatory hook for every control
  • Read it beside the MHRA GxP DI guidance — FDA answers the CGMP-specific questions; MHRA supplies the cross-GxP definitions and governance vocabulary

Revision notes

Finalised December 2018, replacing the April 2016 draft. The final version expanded the discussion of audit-trail review and remediation expectations.

CHECKING ACCESS

Checking your Professional access…

Where this control fails

live FDA enforcement
See all FDA enforcement →

Live FDA recalls SPEQ maps to this standard’s topics — a SPEQ interpretation, not an FDA classification.

International alignment

The guidance is the US GMP member of the international data-integrity family: the MHRA GxP Data Integrity Guidance covers all GxP disciplines with shared definitions, PIC/S PI 041 gives inspectorates a common handbook, and WHO TRS 996 Annex 5 carries the same ALCOA(-plus) framework into WHO prequalification. FDA's version is the most tightly bound to regulation — every answer is anchored to a citation in 21 CFR Parts 210, 211, or 212 — and it complements 21 CFR Part 11, which governs electronic records and signatures.

FDA DI & CGMP Q&A (2018): frequently asked questions

Quick answers to common questions about FDA DI & CGMP Q&A (2018).

Is the FDA data-integrity guidance legally binding?

No. It is guidance describing FDA's current thinking on how the binding CGMP regulations — 21 CFR Parts 210, 211, and 212 — apply to data. The regulatory force comes from those underlying provisions, which each answer cites.

What does the guidance say about shared login accounts?

Access to CGMP computer systems should be restricted so that actions are attributable to a specific individual. Shared accounts for performing or approving CGMP operations defeat attributability, and system controls should ensure each user's actions are traceable to that user.

What is a "true copy" under the guidance?

An accurate reproduction of the original record that preserves its content and meaning — for dynamic electronic records, that includes the metadata and, where necessary for the record's meaning, its dynamic functionality. A printout that drops metadata needed to reconstruct the activity is not a true copy of a dynamic record.

How does the FDA guidance differ from the MHRA data-integrity guidance?

Scope and register. FDA's document is a Q&A interpreting the US drug CGMP regulations specifically. The MHRA guidance spans all GxP disciplines with a single set of definitions and data-governance expectations. Many firms use MHRA for cross-GxP vocabulary and FDA for the CGMP-specific regulatory hooks.