REPORTREFERENCE OUTLINE

Data Integrity Breach Investigation Report

Investigation report for the case where the records themselves cannot be assumed true. Secures evidence before interviews, scopes by what the same person, system or practice could have touched rather than by what was found, determines error versus falsification rather than assuming, assesses impact on released product and submissions, and separates control causes from cultural ones. Maps to the MHRA GxP data integrity guidance and PIC/S PI 041-1.

What a template is not

A template is a document baseline to adapt inside your own quality system. SPEQ does not approve, validate, or take responsibility for what you issue from it, and using one is not evidence of compliance.

CHECKING ACCESS

Checking your Professional access…

REGULATIONS MAPPED
MHRA GxP DI (2018)PIC/S PI 041-1
DOCUMENT TYPE
Report
LAST UPDATED
August 2026
PURPOSE

A data integrity investigation differs from an ordinary deviation investigation in one decisive way: you cannot assume the records are true. The evidence you would normally reason from is the thing under question. The failures are sequencing — interviewing before securing evidence — and scoping to what was found rather than to everything the same person, system or practice could have touched.

What's Inside

Evidence securing, sequenced before any interview, covering systems, audit trails, records and backups
Scope by vector — the same person, the same system, the same practice, the same team
Timeline reconstruction from metadata rather than from the records whose reliability is itself in question
Error versus falsification determined from evidence, with the reasoning recorded whichever way it lands
Impact assessment on released product, on patients, and on data already submitted to authorities
Cause separated into control failure and cultural driver, because a technical fix will not address the second
Notification decisions, closure approval, and the signatures that make the conclusion attributable to named people

How to Use It

1Secure systems, audit trails, records and backups before anyone is interviewed; once people know, the record can still change
2Scope by what could have been affected rather than by what was found, or an inspector will reopen the investigation
3Rebuild the timeline from metadata, since reasoning from the records under question assumes the answer you are testing
4Determine error or falsification from the evidence — assuming error means a falsification investigation simply never happens
5Answer the already-released question early, because it decides whether this is an internal correction or a market action
6Name the cultural driver where one exists, as a technical control alone reproduces the same behaviour somewhere else
DOCUMENT CONTENTS

The full section structure of this template — every section and sub-section, so you can use it as a baseline for your own site document.

Document Control
Document InformationApproval SignaturesRevision HistoryDistribution List
1Evidence Securing — Before Anything Else
2Scope — By What Could Have Been Affected
3Error or Falsification
4Impact on Product, Patients and Submissions
5Cause — Control and Culture
6Notification and Closure
REGULATORY CONTEXT

MHRA GxP DI (2018) and PIC/S PI 041-1 set the expectations for data governance and for investigating data integrity issues, including the breadth of scope, the impact assessment on product already released, and the distinct treatment of falsification. Neither tells you when a finding crosses from error into falsification, whom to notify, or when the scope is wide enough — those determinations belong to the organisation and its quality unit. The evidence-first sequence is SPEQ practitioner synthesis.

MAPPED STANDARDS
MHRA GxP DI (2018)PIC/S PI 041-1
Browse the standards catalog →