· DATA INTEGRITY

Data Integrity & ALCOA+

Data integrity is the assurance that a record is complete, consistent, and accurate across its whole lifecycle — and that it stays that way from the moment it is generated to the moment it is archived. It is not a documentation nicety; it is the evidence base for every quality decision, every batch release, and every regulatory submission. When integrity fails, nothing downstream can be trusted.

Explore the standards library →Assess your quality system →

ALCOA and ALCOA+ — the attributes of trustworthy data

ALCOA — Attributable, Legible, Contemporaneous, Original, Accurate — was articulated by the FDA in the 1990s as the minimum attributes of a reliable GxP record. The "+" attributes formalised by MHRA and PIC/S extend it: Complete, Consistent, Enduring, and Available. Together they define what "good data" means regardless of whether the record is a paper logbook entry or a chromatography audit trail.

The attributes are not a checklist to satisfy once. They apply to every record, at every step, for its entire retention period. A result that is accurate but recorded a shift later fails Contemporaneous; a spectrum that is reprocessed until it passes fails Original and Accurate; an audit trail that is disabled fails Complete. Inspectors read the attributes as a system, not a menu.

The data lifecycle

Integrity is governed across a lifecycle — generation, processing, review, reporting, retention, and disposal. The weakest link sets the ceiling: pristine acquisition means nothing if the review step never examines the audit trail, or if the record can be deleted without trace before archiving.

The highest-risk stage is almost always review. Second-person review that checks only the printed result — not the metadata, the audit trail, the integration, and the reprocessing history behind it — is the single most common gap regulators cite. Effective review is risk-based and metadata-aware.

Paper, hybrid, and electronic systems

Hybrid systems — electronic acquisition with a printed record treated as the "original" — carry the most integrity risk, because the electronic source and its audit trail can diverge from the paper that is actually reviewed and retained. The regulatory direction of travel is unambiguous: where a system generates electronic data, the electronic record and its metadata are the original, and controls must protect them.

For electronic systems this ties data integrity directly to computerised system validation and to electronic-records/electronic-signatures controls: user access management, audit trails that cannot be disabled by ordinary users, time-and-date stamps, and the prevention of unauthorised change or deletion.

Governance, not heroics

Data integrity is a property of the quality system, not of individual diligence. It is delivered by data governance: documented data ownership, a data-integrity risk assessment across systems, access and audit-trail controls proportional to risk, periodic audit-trail review, and a culture in which raising a discrepancy is safe. MHRA and PIC/S both frame governance and organisational culture — an open, non-punitive environment — as prerequisites, not add-ons.

ANCHOR STANDARDS · 5
Open the library →
21 CFR Part 211FDAHIGH INSPECTION RISK
Current Good Manufacturing Practice for Finished Pharmaceuticals
21 CFR Part 11FDAHIGH INSPECTION RISK
Electronic Records; Electronic Signatures
EU GMP Annex 11EMAHIGH INSPECTION RISK
Computerised Systems
MHRA GxP DI (2018)MHRAHIGH INSPECTION RISK
MHRA 'GxP' Data Integrity Guidance and Definitions
PIC/S PI 041-1PIC/SHIGH INSPECTION RISK
Good Practices for Data Management and Integrity in Regulated GMP/GDP Environments
SITS ACROSS THESE DISCIPLINES
KEY REGULATORY BODIES
FDAEMAMHRAPIC/S

Derived from the 5 standards that anchor this topic.

FREQUENTLY ASKED

What does ALCOA+ stand for?

Attributable, Legible, Contemporaneous, Original, and Accurate (ALCOA), plus Complete, Consistent, Enduring, and Available (the "+"). Together they define the attributes of trustworthy GxP data across its lifecycle.

Is ALCOA+ a regulation?

No. ALCOA+ is a set of data-quality attributes described in guidance (notably MHRA "GXP Data Integrity Guidance and Definitions" 2018 and PIC/S PI 041). The binding requirements sit in the predicate rules — e.g. 21 CFR 211, EU GMP, and 21 CFR Part 11 for electronic records — which ALCOA+ helps operationalise.

Why is audit-trail review so important?

The audit trail is the metadata that shows whether a record was changed, reprocessed, or deleted. Reviewing only the final printed result — without the audit trail behind it — is the most commonly cited data-integrity gap, because it lets an altered or cherry-picked result pass second-person review unchecked.

What is the difference between data integrity and data quality?

Data quality asks whether data is fit for its purpose; data integrity asks whether it is complete, consistent, and accurate across its whole lifecycle and has not been altered without trace. Integrity is the precondition — data that lacks integrity cannot be assessed for quality at all.

RELATED TOPICS
CSV / CSAComputer System Validation & CSAQUALITY RISK MANAGEMENTQuality Risk Management (ICH Q9)
Weekly Briefing

Get the Weekly GxP Briefing

Curated regulatory intelligence — enforcement, recalls, guidance, and quality signals — in one practitioner-grade email each week. Free.

Read a past issue →