Data Integrity and Compliance With Drug CGMP: Questions and Answers
FDA's final guidance (December 2018) answering eighteen questions on how data integrity fits within the drug CGMP regulations — Parts 210, 211, and 212. It defines data integrity, metadata, and audit trail; sets expectations for system access, blank-form control, audit-trail review, and true copies; and describes how FDA expects firms to address data-integrity problems. The US counterpart of the MHRA GxP data-integrity guidance.
What this does not cover
stated in the document's own scope- Interprets the drug CGMP regulations (Parts 210, 211, 212); it does not extend to GCP, GLP, or device quality-system records, which have their own regulations and guidance.
- Explains how existing CGMP requirements apply to data; it creates no new requirements and is guidance, not a rule.
- Addresses data integrity within manufacturing and laboratory operations; the criteria for electronic records and signatures themselves remain in 21 CFR Part 11.
Always verify against the current published text before relying on it for a submission or inspection.
Overview
FDA's "Data Integrity and Compliance With Drug CGMP: Questions and Answers" is the agency's data-integrity guidance for drug manufacturers, finalised in December 2018. In eighteen questions and answers it explains how data-integrity expectations flow from the existing CGMP regulations: what the terms data integrity, metadata, and audit trail mean; when workflows on computerised systems must be validated; how access to CGMP systems should be restricted; why blank forms need control; how audit trails should be reviewed and by whom; what counts as a true copy; and how electronic data may be retained. It closes with FDA's expectations for addressing data-integrity problems, including scoping the failure and assessing its effect on product quality.
Scope & applicability
Drug manufacturers subject to the CGMP regulations for finished pharmaceuticals and APIs (21 CFR Parts 210, 211, and 212, and the ICH Q7 expectations FDA applies to APIs). The Q&As interpret existing CGMP requirements; they do not create new ones.
Legal basis & how it acquires force
A guidance for industry from the FDA Center for Drug Evaluation and Research and Center for Biologics Evaluation and Research, issued in final form in December 2018 and announced in the Federal Register on 13 December 2018. It interprets the current good manufacturing practice regulations in 21 CFR Parts 210, 211, and 212 — each answer cites the specific CGMP provision it rests on — and, like all FDA guidance, describes the agency's current thinking without itself creating binding requirements.
Document structure
| Part | Covers |
|---|---|
| Introduction and background | Purpose, the CGMP context, and why data integrity is foundational to the drug-quality system |
| Definitions (Q&A 1) | Data integrity, ALCOA, metadata, audit trail, static and dynamic records, backup, and systems |
| System design and access controls | Validation of computerised workflows, restricting system access, and the problems with shared login accounts |
| Records controls | Blank-form control, audit-trail review and its frequency, true copies, and retention of electronic data |
| Training and remediation | Personnel training in detecting data-integrity issues, and how FDA expects firms to address identified data-integrity problems |
Key requirements
- Data integrity controls anchored to specific CGMP citations — the guidance maps each expectation to the underlying regulation
- Computerised-system workflows validated for their intended use, not just the software in isolation
- System access restricted and shared login accounts for CGMP records avoided
- Blank forms controlled and reconciled so unofficial re-creation of records is detectable
- Audit trails reviewed with a frequency and rigour tied to the record's CGMP role
- Data-integrity problems addressed comprehensively: scope the failure, assess product risk, and remediate the quality system
Implementation tips
- Treat the eighteen Q&As as an audit aid: each answer cites the CFR provision it interprets, which gives you the regulatory hook for every control
- Read it beside the MHRA GxP DI guidance — FDA answers the CGMP-specific questions; MHRA supplies the cross-GxP definitions and governance vocabulary
Revision notes
Finalised December 2018, replacing the April 2016 draft. The final version expanded the discussion of audit-trail review and remediation expectations.
Where this control fails
live FDA enforcementLive FDA recalls SPEQ maps to this standard’s topics — a SPEQ interpretation, not an FDA classification.
International alignment
The guidance is the US GMP member of the international data-integrity family: the MHRA GxP Data Integrity Guidance covers all GxP disciplines with shared definitions, PIC/S PI 041 gives inspectorates a common handbook, and WHO TRS 996 Annex 5 carries the same ALCOA(-plus) framework into WHO prequalification. FDA's version is the most tightly bound to regulation — every answer is anchored to a citation in 21 CFR Parts 210, 211, or 212 — and it complements 21 CFR Part 11, which governs electronic records and signatures.
FDA DI & CGMP Q&A (2018): frequently asked questions
Quick answers to common questions about FDA DI & CGMP Q&A (2018).
Is the FDA data-integrity guidance legally binding?
No. It is guidance describing FDA's current thinking on how the binding CGMP regulations — 21 CFR Parts 210, 211, and 212 — apply to data. The regulatory force comes from those underlying provisions, which each answer cites.
What does the guidance say about shared login accounts?
Access to CGMP computer systems should be restricted so that actions are attributable to a specific individual. Shared accounts for performing or approving CGMP operations defeat attributability, and system controls should ensure each user's actions are traceable to that user.
What is a "true copy" under the guidance?
An accurate reproduction of the original record that preserves its content and meaning — for dynamic electronic records, that includes the metadata and, where necessary for the record's meaning, its dynamic functionality. A printout that drops metadata needed to reconstruct the activity is not a true copy of a dynamic record.
How does the FDA guidance differ from the MHRA data-integrity guidance?
Scope and register. FDA's document is a Q&A interpreting the US drug CGMP regulations specifically. The MHRA guidance spans all GxP disciplines with a single set of definitions and data-governance expectations. Many firms use MHRA for cross-GxP vocabulary and FDA for the CGMP-specific regulatory hooks.
This standard in practice
Recall domain is a SPEQ mapping of this standard’s topics, not an FDA classification.