RISK ASSESSMENTREFERENCE OUTLINE

Data Integrity (ALCOA+) Assessment

System-and-record data integrity assessment against the ALCOA+ attributes, with audit-trail and access-control review and a risk-ranked remediation register. Maps to Part 11, MHRA DI (2018), and WHO TRS 996 Annex 5.

What a template is not

A template is a document baseline to adapt inside your own quality system. SPEQ does not approve, validate, or take responsibility for what you issue from it, and using one is not evidence of compliance.

CHECKING ACCESS

Checking your Professional access…

REGULATIONS MAPPED
21 CFR Part 11MHRA GxP Data Integrity (2018)WHO TRS 996 Annex 5
DOCUMENT TYPE
Risk Assessment
LAST UPDATED
January 2025
PURPOSE

An assessment of GxP records and the systems that hold them against the ALCOA+ attributes, producing a ranked register of the gaps most likely to become inspection findings. Data integrity failures are rarely a single broken control; they are a hybrid record with no defined original, an audit trail nobody reviews, and a shared login that predates the current team. This assessment is designed to find that pattern rather than to audit a system in isolation.

What's Inside

Scope and inventory of GxP records and the systems, instruments, and paper processes that hold them
ALCOA+ attribute evaluation per record type, with the evidence examined recorded against each attribute
Audit trail and metadata review, including whether trails are enabled, complete, and actually reviewed
Access control and segregation of duties, covering shared accounts, administrator rights, and leaver removal
Paper, hybrid, and true-copy risks, including which record is the defined original where both exist
Data lifecycle coverage — creation, processing, review, retention, retrieval, and disposal
Gap register with a risk-ranked remediation plan, owners, and interim controls where remediation will take time

How to Use It

1Inventory the records first and the systems second; a system-first assessment misses the records that live in spreadsheets
2Assess each record type against every ALCOA+ attribute, and record the evidence examined rather than a judgement alone
3Check that audit trails are reviewed, not merely enabled — an unreviewed trail is a finding in waiting
4Examine shared accounts, administrator rights, and leaver removal specifically; these are where access control usually fails
5For every hybrid record, establish which copy is the defined original and whether that definition is documented
6Rank gaps by patient and product risk, assign remediation owners, and record interim controls for gaps that cannot close quickly
DOCUMENT CONTENTS

The full section structure of this template — every section and sub-section, so you can use it as a baseline for your own site document.

Document Control
Document InformationApproval SignaturesRevision HistoryDistribution List
1Scope and System / Record Inventory
2ALCOA+ Attribute Evaluation
3Audit Trail and Metadata Review
4Access Control and Segregation of Duties
5Paper, Hybrid, and True-Copy Risks
6Gap Register
7Risk-Ranked Remediation Plan
REGULATORY CONTEXT

21 CFR Part 11 governs electronic records and signatures in the United States, and EU GMP Annex 11 governs computerised systems. The MHRA GxP Data Integrity guidance (2018) and WHO TRS 996 Annex 5 set out the ALCOA+ attributes assessed here and the expectation that data governance is designed rather than assumed. None of them ranks your gaps; the risk ranking and the remediation sequence in the output are the organisation's determination, and this assessment is the record of how it was reached.

MAPPED STANDARDS
21 CFR Part 11MHRA GxP Data Integrity (2018)WHO TRS 996 Annex 5
Browse the standards catalog →