OPENMHRA DI (2018)EU GMP Annex 1121 CFR Part 11

Data Integrity Risk Scorer

Rate a GxP system across record type, audit-trail capability, access control, criticality, and review maturity to get a transparent 0–100 data-integrity risk index and a low/medium/high band for prioritising remediation. A SPEQ heuristic anchored to MHRA data-integrity guidance, EU GMP Annex 11, and 21 CFR Part 11.

OUTPUT

Risk index (0–100) + band

TIME

~10 min

Limitations — read before you rely on this

  • The weights and band cut-points are SPEQ’s judgment, not a regulator scheme; a different, equally defensible weighting yields a different band, so the score ranks systems, it does not certify them.
  • A moderate composite can hide a single unacceptable failure; never let the total mask a critical factor such as an editable or disableable audit trail on a quality-decision system.
  • This calculator is transparent but it is not a validated system, and it assesses system controls, not the integrity of any particular dataset.
  • Reproduce the assessment in your own qualified system with a documented weight rationale before it drives a remediation plan or an audit response.

WHAT THIS CALCULATES

Produces a transparent 0–100 data-integrity risk index and a low/medium/high band for a GxP system by combining weighted factor scores across record type, audit-trail capability, access control, criticality, and review maturity.

THE METHOD

RiskIndex = 100 × Σ(w·s) / Σ(w·s_max) Band = Low <34 · Medium 34–66 · High >66
RiskIndex
The normalised composite risk score on a 0–100 scale; higher means greater data-integrity risk.
w
The weight assigned to each factor, reflecting its relative contribution to risk (SPEQ defaults, user-adjustable).
s
The selected risk score for a factor (0 = best controls up to s_max = worst).
s_max
The maximum possible per-factor score, used to normalise so the index always lands on 0–100.
Band
The categorical output (Low / Medium / High) derived from RiskIndex against SPEQ’s cut-points.

The factor set, the weights, and the 34/66 band cut-points are a SPEQ-defined heuristic, not a regulator scheme — MHRA, EU GMP Annex 11, and 21 CFR Part 11 define the controls, not a numeric score. The tool uses equal weights by default; the normalised form keeps the index within 0–100 for any weights.

THE INPUTS, AND WHAT THEY MEAN

Record type
Whether the record is paper, hybrid (paper + electronic), or fully electronic; hybrid systems often carry the highest risk because the paper–electronic linkage is where data breaks most easily.
Audit-trail capability
Whether the system captures a secure, computer-generated, time-stamped audit trail of create/modify/delete with attribution, and whether it can be disabled.
Access control
Whether accounts are unique per user with role-based privileges and no shared logins, versus shared or generic accounts that break attributability.
Data criticality
How directly the record supports a product-quality or patient-safety decision (batch release, clinical endpoint) versus a supporting record.
Review maturity
Whether audit-trail and data review is defined, risk-based, routine, and documented, versus ad hoc or absent.
[ DATA INTEGRITY · RISK SCORE ]

Rank a GxP system's data-integrity risk.

Rate the system across five factors. SPEQ combines them into a transparent 0–100 index and a low/medium/high band to prioritise remediation. The weights and cut-points are a SPEQ heuristic — the controls themselves come from MHRA data-integrity guidance, EU GMP Annex 11, and 21 CFR Part 11.

DATA-INTEGRITY RISK INDEX
6.67 / 100
Lower risk — keep the controls under periodic review.
BAND
LOW
Read the factor breakdown alongside the total — one critical factor can outweigh a moderate score.
PROFESSIONAL EXPORT

HOW TO READ THE OUTPUT

  • The band reflects SPEQ’s heuristic weighting, not a regulatory classification; regulators define the expected controls but not a numeric threshold, so the score is a prioritisation aid, not a compliance verdict.
  • A high index concentrates remediation attention, but a single critical failure — e.g. a disableable audit trail on a batch-release system — can be unacceptable regardless of a moderate overall score, so read the factor breakdown, not just the total.
  • Because weights are adjustable, two organisations can defensibly score the same system differently; the value is in the documented rationale for the weights.
  • A low score means "controls present", not "data verified" — the tool assesses system risk, not the integrity of any specific dataset.

WORKED EXAMPLE

Scoring a legacy hybrid QC balance log that feeds batch-release decisions, at equal weights.

Record type
hybrid (3/3)
Audit trail
present but disableable (2/3)
Access control
shared login (3/3)
Criticality
batch-release (3/3)
Review maturity
ad hoc (2/3)

RESULT

RiskIndex = 100 × 13 / 15 = 86.7 → High.

A high-criticality hybrid record with a disableable audit trail and shared logins is a textbook high-risk data-integrity target — it belongs at the top of the remediation and audit-trail-review priority list.

REGULATORY BASIS

MHRA ‘GXP’ Data Integrity Guidance (2018)
Defines the ALCOA+ expectations and the data-lifecycle, risk-based approach the factors operationalise.
EU GMP Annex 11
Requires audit trails, access control, and risk-based validation of computerised systems.
21 CFR Part 11
Governs audit-trail, access-control, and signature requirements for electronic GxP records in the US.
PROFESSIONAL · WORKED SCENARIOS · SPEQ SYNTHESIS

See this tool applied to real cases

CHECKING ACCESS

Checking your Professional access…