Data Integrity Risk Scorer
Rate a GxP system across record type, audit-trail capability, access control, criticality, and review maturity to get a transparent 0–100 data-integrity risk index and a low/medium/high band for prioritising remediation. A SPEQ heuristic anchored to MHRA data-integrity guidance, EU GMP Annex 11, and 21 CFR Part 11.
OUTPUT
TIME
Limitations — read before you rely on this
- The weights and band cut-points are SPEQ’s judgment, not a regulator scheme; a different, equally defensible weighting yields a different band, so the score ranks systems, it does not certify them.
- A moderate composite can hide a single unacceptable failure; never let the total mask a critical factor such as an editable or disableable audit trail on a quality-decision system.
- This calculator is transparent but it is not a validated system, and it assesses system controls, not the integrity of any particular dataset.
- Reproduce the assessment in your own qualified system with a documented weight rationale before it drives a remediation plan or an audit response.
WHAT THIS CALCULATES
Produces a transparent 0–100 data-integrity risk index and a low/medium/high band for a GxP system by combining weighted factor scores across record type, audit-trail capability, access control, criticality, and review maturity.
THE METHOD
RiskIndex = 100 × Σ(w·s) / Σ(w·s_max) Band = Low <34 · Medium 34–66 · High >66- RiskIndex
- The normalised composite risk score on a 0–100 scale; higher means greater data-integrity risk.
- w
- The weight assigned to each factor, reflecting its relative contribution to risk (SPEQ defaults, user-adjustable).
- s
- The selected risk score for a factor (0 = best controls up to s_max = worst).
- s_max
- The maximum possible per-factor score, used to normalise so the index always lands on 0–100.
- Band
- The categorical output (Low / Medium / High) derived from RiskIndex against SPEQ’s cut-points.
The factor set, the weights, and the 34/66 band cut-points are a SPEQ-defined heuristic, not a regulator scheme — MHRA, EU GMP Annex 11, and 21 CFR Part 11 define the controls, not a numeric score. The tool uses equal weights by default; the normalised form keeps the index within 0–100 for any weights.
THE INPUTS, AND WHAT THEY MEAN
- Record type
- Whether the record is paper, hybrid (paper + electronic), or fully electronic; hybrid systems often carry the highest risk because the paper–electronic linkage is where data breaks most easily.
- Audit-trail capability
- Whether the system captures a secure, computer-generated, time-stamped audit trail of create/modify/delete with attribution, and whether it can be disabled.
- Access control
- Whether accounts are unique per user with role-based privileges and no shared logins, versus shared or generic accounts that break attributability.
- Data criticality
- How directly the record supports a product-quality or patient-safety decision (batch release, clinical endpoint) versus a supporting record.
- Review maturity
- Whether audit-trail and data review is defined, risk-based, routine, and documented, versus ad hoc or absent.
Rank a GxP system's data-integrity risk.
Rate the system across five factors. SPEQ combines them into a transparent 0–100 index and a low/medium/high band to prioritise remediation. The weights and cut-points are a SPEQ heuristic — the controls themselves come from MHRA data-integrity guidance, EU GMP Annex 11, and 21 CFR Part 11.
HOW TO READ THE OUTPUT
- The band reflects SPEQ’s heuristic weighting, not a regulatory classification; regulators define the expected controls but not a numeric threshold, so the score is a prioritisation aid, not a compliance verdict.
- A high index concentrates remediation attention, but a single critical failure — e.g. a disableable audit trail on a batch-release system — can be unacceptable regardless of a moderate overall score, so read the factor breakdown, not just the total.
- Because weights are adjustable, two organisations can defensibly score the same system differently; the value is in the documented rationale for the weights.
- A low score means "controls present", not "data verified" — the tool assesses system risk, not the integrity of any specific dataset.
WORKED EXAMPLE
Scoring a legacy hybrid QC balance log that feeds batch-release decisions, at equal weights.
- Record type
- hybrid (3/3)
- Audit trail
- present but disableable (2/3)
- Access control
- shared login (3/3)
- Criticality
- batch-release (3/3)
- Review maturity
- ad hoc (2/3)
RESULT
A high-criticality hybrid record with a disableable audit trail and shared logins is a textbook high-risk data-integrity target — it belongs at the top of the remediation and audit-trail-review priority list.
REGULATORY BASIS
- MHRA ‘GXP’ Data Integrity Guidance (2018)
- Defines the ALCOA+ expectations and the data-lifecycle, risk-based approach the factors operationalise.
- EU GMP Annex 11
- Requires audit trails, access control, and risk-based validation of computerised systems.
- 21 CFR Part 11
- Governs audit-trail, access-control, and signature requirements for electronic GxP records in the US.