Data Criticality and Risk Assessment
Assessment separating the two questions regulators expect to be answered independently: how important the data is to a decision, and how vulnerable it is to alteration or loss. Includes a data map covering informal locations, criticality and vulnerability scored apart, combined control intensity, and audit trail review targeted by criticality rather than defined as comprehensive. Maps to the MHRA GxP data integrity guidance and PIC/S PI 041-1.
What a template is not
A template is a document baseline to adapt inside your own quality system. SPEQ does not approve, validate, or take responsibility for what you issue from it, and using one is not evidence of compliance.
Data integrity controls cost effort, and applying the same intensity everywhere means the controls that matter compete with the ones that do not. Regulators expect a risk-based approach built on two separate questions — how much a record matters, and how easily it could be altered or lost — and confusing them puts the wrong controls in the wrong places. Both scores remain your organisation’s judgement.
What's Inside
How to Use It
The full section structure of this template — every section and sub-section, so you can use it as a baseline for your own site document.
The MHRA GxP data integrity guidance (2018) sets the expectation for a risk-based approach built on data criticality and data risk, and PIC/S PI 041-1 gives the corresponding guidance for GMP and GDP inspectorates, including targeted audit trail review. Neither supplies your scoring scale, your thresholds, or the controls you attach to a given combination — those determinations are your organisation’s and must be justified rather than asserted. The assessment structure is SPEQ practitioner synthesis, and renders as a spreadsheet because it is a scoring matrix.