RISK ASSESSMENTREFERENCE OUTLINE

Data Criticality and Risk Assessment

Assessment separating the two questions regulators expect to be answered independently: how important the data is to a decision, and how vulnerable it is to alteration or loss. Includes a data map covering informal locations, criticality and vulnerability scored apart, combined control intensity, and audit trail review targeted by criticality rather than defined as comprehensive. Maps to the MHRA GxP data integrity guidance and PIC/S PI 041-1.

What a template is not

A template is a document baseline to adapt inside your own quality system. SPEQ does not approve, validate, or take responsibility for what you issue from it, and using one is not evidence of compliance.

CHECKING ACCESS

Checking your Professional access…

REGULATIONS MAPPED
MHRA GxP DI (2018)PIC/S PI 041-1
DOCUMENT TYPE
Risk Assessment
LAST UPDATED
August 2026
PURPOSE

Data integrity controls cost effort, and applying the same intensity everywhere means the controls that matter compete with the ones that do not. Regulators expect a risk-based approach built on two separate questions — how much a record matters, and how easily it could be altered or lost — and confusing them puts the wrong controls in the wrong places. Both scores remain your organisation’s judgement.

What's Inside

Data map covering creation, processing, storage and use, including the informal locations nobody owns
Criticality scored by the decision the data supports, not by the system it happens to live in
Vulnerability scored separately as a property of the system, its controls and the way it is handled
Combined control intensity with both input scores shown, so the reasoning can be challenged
Audit trail review targeted by criticality, with a defined scope and frequency per data set
The controls selected against each combination, so the assessment produces actions rather than scores
Version control with the triggers that require the assessment to be revisited

How to Use It

1Build the data map first and include informal locations — spreadsheets, local instrument drives and printouts are where the problems live.
2Keep criticality and vulnerability apart: how much the data matters and how easily it could be altered are independent questions.
3Score criticality from the decision the data supports, because a record’s importance comes from its use rather than from its system.
4Show both input scores beside the resulting control intensity, so a reviewer can challenge the reasoning and not only the conclusion.
5Define audit trail review by criticality with a specific scope and frequency — a review defined as comprehensive is one that does not happen.
6Name the revisit triggers, since a new system or a changed process silently invalidates the vulnerability half of the assessment.
DOCUMENT CONTENTS

The full section structure of this template — every section and sub-section, so you can use it as a baseline for your own site document.

Document Control
Document InformationApproval SignaturesRevision HistoryDistribution List
1Data Map
2Criticality — What Decision Does It Support?
3Vulnerability — A Property of the System
4Combined Control Intensity
5Targeted Audit Trail Review
6Assessment Control
REGULATORY CONTEXT

The MHRA GxP data integrity guidance (2018) sets the expectation for a risk-based approach built on data criticality and data risk, and PIC/S PI 041-1 gives the corresponding guidance for GMP and GDP inspectorates, including targeted audit trail review. Neither supplies your scoring scale, your thresholds, or the controls you attach to a given combination — those determinations are your organisation’s and must be justified rather than asserted. The assessment structure is SPEQ practitioner synthesis, and renders as a spreadsheet because it is a scoring matrix.

MAPPED STANDARDS
MHRA GxP DI (2018)PIC/S PI 041-1
Browse the standards catalog →