Good Practices for Data Management and Integrity in Regulated GMP/GDP Environments
The PIC/S data integrity guidance (adopted 1 July 2021), written for inspectorates — which makes it the closest public view of how data integrity is actually inspected. Covers data governance, paper-based and computerised systems, hybrid situations, outsourced activities, and how deficiencies should be classified and remediated.
What this does not cover
stated in the document's own scope- Covers data integrity in GMP and GDP environments; it is not a computerised-system validation methodology — that role belongs to GAMP 5 and Annex 11.
- Written to guide inspection, not to serve as a binding regulation; the legal requirement remains the member authority’s own GMP/GDP rules.
- Addresses record integrity generally, not the electronic-signature specifics of 21 CFR Part 11, which is a distinct US regulation.
Always verify against the current published text before relying on it for a submission or inspection.
Overview
PIC/S PI 041 is the data-integrity guidance the PIC/S inspectorates wrote for their own inspectors. Because its audience is the people who conduct GMP and GDP inspections, it is the closest public description of how data integrity is examined in practice. It sets out data-governance expectations, applies the ALCOA principles (attributable, legible, contemporaneous, original, accurate) across paper, computerised, and hybrid systems, and addresses outsourced activities and how deficiencies should be classified and remediated proportionately to the risk they create for patients.
Scope & applicability
GMP and GDP environments inspected by PIC/S participating authorities. Structured as inspection guidance, so each section pairs expectations with the way an inspector should probe them.
Legal basis & how it acquires force
PI 041 is a PIC/S guidance document — a recommendation to the participating authorities, not a statute. It acquires force through the national GMP/GDP frameworks of the PIC/S members, whose inspectors apply it when assessing whether records meet the data-integrity requirements already implicit in GMP. Its status is aid-to-inspection: it interprets existing obligations rather than creating new legal duties, which is why it reads as expectations and classification guidance rather than as binding clauses.
Document structure
| Part | Covers |
|---|---|
| Data governance | The organisational framework for data integrity and management’s responsibilities |
| ALCOA and data lifecycle | The data-integrity principles applied across generation, processing, retention, and retrieval |
| Paper-based systems | Controls for handwritten records, forms, and true copies |
| Computerised systems | Access control, audit trails, and configuration for electronic records |
| Hybrid and outsourced | Mixed paper/electronic workflows and data integrity across contracted activities |
| Remediation and classification | How deficiencies are weighed and how remediation is expected to proceed |
Quick reference · ALCOA+ — the data integrity test
The nine attributes PIC/S PI 041-1 expects of GMP/GDP data, whether paper or electronic.
- Attributable — who recorded the data or performed the action, and when
- Legible — readable and permanent for the record’s entire lifecycle
- Contemporaneous — recorded at the time the work is performed
- Original — the first capture, or a verified true copy of it
- Accurate — correct, truthful, complete, valid and reliable
- Complete — all data, including any repeats, reanalyses or reprocessing
- Consistent — sequenced and date/time-stamped in the expected order
- Enduring — recorded on controlled, durable media — not scrap paper
- Available — retrievable for review and inspection throughout the retention period
PI 041-1 is written for inspectors, so it also expects data-integrity risk to be governed proportionately to data criticality, and deficiencies to be classified and remediated.
Source: PIC/S PI 041-1, Good Practices for Data Management and Integrity. Verify against the current text before relying on it for a submission.
Key requirements
- Implement a documented data governance system with clear management ownership
- Apply risk-based controls across paper, electronic, and hybrid records
- Control user access, privileges, and audit trails in computerised systems
- Extend data integrity expectations to outsourced activities and suppliers
- Classify and remediate data integrity deficiencies with a risk-based methodology
Implementation tips
- Self-inspect against PI 041 section by section — it is literally the inspection script
- Use its deficiency-classification examples to calibrate your internal audit grading
- Fold supplier data integrity questions into quality agreements and audit checklists
- Treat the maturity ladder as a roadmap: procedural compliance first, then embedded behaviour
Revision notes
PI 041-1 was adopted 1 July 2021 after several draft rounds. It consolidates the PIC/S position alongside the MHRA (2018) and WHO data integrity guidances and is referenced by many national inspectorates.
Where this control fails
live FDA enforcementLive FDA recalls SPEQ maps to this standard’s topics — a SPEQ interpretation, not an FDA classification.
International alignment
PI 041 is closely aligned with the other major data-integrity guidances — the MHRA ‘GXP’ Data Integrity guidance and the WHO Annex on good data and record management practices — and complements GAMP 5 on the computerised-system side. Because the PIC/S members include the FDA, EMA national authorities, Health Canada, and many others, its ALCOA framing is effectively the common reference for GMP/GDP data integrity worldwide.
PIC/S PI 041-1: frequently asked questions
Quick answers to common questions about PIC/S PI 041-1.
What does ALCOA stand for in PIC/S PI 041?
Attributable, Legible, Contemporaneous, Original, and Accurate — the core attributes a record must have. PI 041 applies these across paper, electronic, and hybrid systems throughout the data lifecycle.
Is PIC/S PI 041 a regulation?
No. It is guidance written for PIC/S inspectors. It interprets data-integrity expectations already implicit in GMP/GDP; the binding requirement is each member authority’s own GMP or GDP framework.
Why is PI 041 considered especially useful?
Because it was written for the inspectors themselves, it is the most direct public account of how data integrity is assessed and how deficiencies are classified — which is why practitioners read it as a window into inspection.
This standard in practice
Recall domain is a SPEQ mapping of this standard’s topics, not an FDA classification.