· DATA INTEGRITY

Data Integrity & ALCOA+

Data integrity is the assurance that a record is complete, consistent, and accurate across its whole lifecycle — and that it stays that way from the moment it is generated to the moment it is archived. It is not a documentation nicety; it is the evidence base for every quality decision, every batch release, and every regulatory submission. When integrity fails, nothing downstream can be trusted.

What an explainer is not

A topic explainer is SPEQ’s synthesis of what a practice involves, cited to the standards that govern it. It does not reproduce their text, and it does not determine which of them apply to your product or process.

[ POSITION IN THE FRAMEWORK ]

7 DIMENSIONS · 29 LINKS

Data integrity is fully cross-cutting: it applies to every lifecycle phase that generates a record, is enforced across the documentation, validation, and manufacturing disciplines, and is won or lost inside the computerized systems below.

06 · QUALITY MATURITY — DATA INTEGRITY & ALCOA+, REACTIVE TO ADAPTIVE

L1
Reactive

Integrity issues are found by the inspector. Shared logins persist; audit trails exist but nobody reviews them.

L2
Defined

A DI policy and ALCOA+ training exist. Audit-trail review is procedural but sampled inconsistently across systems.

L3
Controlled

Risk-based audit-trail review is scheduled and evidenced. Access roles are periodically recertified; data flows are mapped.

L4
Predictive

Review findings trend into leading indicators; anomalous edits and access patterns surface before batch disposition.

L5
Adaptive

Integrity by design: validated pipelines, exception-based review, and DI risk feeding system selection and change control.

SPEQ’s shared five-stage progression, labelled synthesis — not the FDA QMM rating scale. Where does your organization sit? Score your quality system →

07 · REGULATORY & EVIDENCE

GOVERNING STANDARDS · 5

Derived from the 5 standards SPEQ maps to this subject, across 4 regulatory bodies: FDA, EMA, MHRA, PIC/S.

RECORDS & OBJECTIVE EVIDENCE

  • System audit trails and their documented periodic review
  • User-access lists with role justification and recertification records
  • Data-flow maps for each GxP computerized system
  • Original/raw data retained per 21 CFR 211.68 and 211.180
  • Data-integrity risk assessments and remediation evidence

COMMON INSPECTION FINDINGS

  • Audit trails disabled, or enabled but never reviewed
  • Shared or generic user accounts on GxP systems
  • Testing into compliance — unreported trial injections
  • Original records destroyed after transcription to a summary
  • Backup and restore never verified for retained data
EVERY CHIP IS A DOOR · WALK THE FRAMEWORK FROM ANY SUBJECTHow SPEQ maps the framework →

ALCOA and ALCOA+ — the attributes of trustworthy data

ALCOA — Attributable, Legible, Contemporaneous, Original, Accurate — was articulated by the FDA in the 1990s as the minimum attributes of a reliable GxP record. The "+" attributes formalised by MHRA and PIC/S extend it: Complete, Consistent, Enduring, and Available. Together they define what "good data" means regardless of whether the record is a paper logbook entry or a chromatography audit trail.

The attributes are not a checklist to satisfy once. They apply to every record, at every step, for its entire retention period. A result that is accurate but recorded a shift later fails Contemporaneous; a spectrum that is reprocessed until it passes fails Original and Accurate; an audit trail that is disabled fails Complete. Inspectors read the attributes as a system, not a menu.

The data lifecycle

Integrity is governed across a lifecycle — generation, processing, review, reporting, retention, and disposal. The weakest link sets the ceiling: pristine acquisition means nothing if the review step never examines the audit trail, or if the record can be deleted without trace before archiving.

The highest-risk stage is almost always review. Second-person review that checks only the printed result — not the metadata, the audit trail, the integration, and the reprocessing history behind it — is the single most common gap regulators cite. Effective review is risk-based and metadata-aware.

Paper, hybrid, and electronic systems

Hybrid systems — electronic acquisition with a printed record treated as the "original" — carry the most integrity risk, because the electronic source and its audit trail can diverge from the paper that is actually reviewed and retained. The regulatory direction of travel is unambiguous: where a system generates electronic data, the electronic record and its metadata are the original, and controls must protect them.

For electronic systems this ties data integrity directly to computerised system validation and to electronic-records/electronic-signatures controls: user access management, audit trails that cannot be disabled by ordinary users, time-and-date stamps, and the prevention of unauthorised change or deletion.

Governance, not heroics

Data integrity is a property of the quality system, not of individual diligence. It is delivered by data governance: documented data ownership, a data-integrity risk assessment across systems, access and audit-trail controls proportional to risk, periodic audit-trail review, and a culture in which raising a discrepancy is safe. MHRA and PIC/S both frame governance and organisational culture — an open, non-punitive environment — as prerequisites, not add-ons.

WORKED EXAMPLE — SPEQ SYNTHESIS

A hypothetical QC laboratory runs an HPLC assay on a finished-product batch. The printed chromatogram meets specification and is signed by the analyst and a reviewer. A week later, a routine audit-trail review shows the sequence was integrated three times and that the first two integrations were deleted from the processing queue. Nothing on the paper record shows this.

  1. Establish which record is the original before deciding anything else

    The instrument generated an electronic record with metadata; the paper is a report of it. Treating the printout as the original is what made the deletions invisible, and it is the determination that has to be corrected first — every later step depends on which artifact the organisation holds as the source.

  2. Reconstruct what actually happened from the audit trail, not from recollection

    Pull the full audit trail for the sequence: who processed, when, what changed between integrations, and on whose account. Record what the trail shows and, equally, what it cannot show — an audit trail with gaps is a finding in its own right, and papering over the gap is worse than reporting it.

  3. Separate the data question from the result question

    Two distinct questions are live: is the reported result reliable, and is the record trustworthy? A reliable result on an untrustworthy record is still a data-integrity failure, and answering only the first is the most common way this investigation goes wrong.

  4. Assess the attributes against the whole record, one at a time

    Attributable, Legible, Contemporaneous, Original, Accurate, plus Complete, Consistent, Enduring and Available. Deleted integrations fail Complete and Original; a review that examined only the printout fails the review control rather than the data. State which attribute failed and where.

  5. Widen the scope before narrowing it

    Ask whether the same processing practice, the same permissions, and the same review procedure apply elsewhere — other analysts, other methods, other instruments. A single-sequence investigation that never asks this is how a systemic practice gets recorded as an isolated event.

  6. Fix the control that failed, not only the record that showed it

    The record is repaired by documenting the true processing history. The control is repaired by changing permissions, by making audit-trail review part of second-person review with a defined scope, or both — and by stating how effectiveness will be measured.

The organisation holds a documented reconstruction of what happened, an attribute-by-attribute assessment naming the specific failures, a scoped question about how far the practice extends, and a remediation aimed at the review control rather than at the analyst. It does not hold a conclusion that the batch is acceptable — that determination sits with the quality unit, on this evidence.

WHAT WOULD CHANGE THIS

  • If the system cannot produce a complete audit trail at all, the sequence above stops at step two: the question becomes whether the system is fit for GxP use, which is a validation and system-selection decision rather than an investigation.
  • If the deletions were made under a documented, approved reprocessing procedure with the rationale recorded contemporaneously, this is not an integrity failure and treating it as one damages the culture the governance depends on.
  • A paper-only laboratory has no audit trail to reconstruct from, so the equivalent investigation runs on controlled-copy issuance, error correction and retention records instead — a different evidence base with different weak points.

FREQUENTLY ASKED

What does ALCOA+ stand for?

Attributable, Legible, Contemporaneous, Original, and Accurate (ALCOA), plus Complete, Consistent, Enduring, and Available (the "+"). Together they define the attributes of trustworthy GxP data across its lifecycle.

Is ALCOA+ a regulation?

No. ALCOA+ is a set of data-quality attributes described in guidance (notably MHRA "GXP Data Integrity Guidance and Definitions" 2018 and PIC/S PI 041). The binding requirements sit in the predicate rules — e.g. 21 CFR 211, EU GMP, and 21 CFR Part 11 for electronic records — which ALCOA+ helps operationalise.

Why is audit-trail review so important?

The audit trail is the metadata that shows whether a record was changed, reprocessed, or deleted. Reviewing only the final printed result — without the audit trail behind it — is the most commonly cited data-integrity gap, because it lets an altered or cherry-picked result pass second-person review unchecked.

What is the difference between data integrity and data quality?

Data quality asks whether data is fit for its purpose; data integrity asks whether it is complete, consistent, and accurate across its whole lifecycle and has not been altered without trace. Integrity is the precondition — data that lacks integrity cannot be assessed for quality at all.

DATA INTEGRITY — AT EVERY LEVEL

The same subject reads differently up an organisation. SPEQ synthesis of how ownership and the question being asked shift from the floor to the board — see the six organizational levels.

  1. Level 1 · Frontline operators & technicians

    A recording discipline — write it right, write it now, do not change it quietly.

    WHAT YOU OWN

    • Attributable, contemporaneous, accurate entries
    • Using the current form and the controlled system
    • Making corrections the visible, reasoned way

    EVIDENCE YOU TOUCH

    • The record you signed
    • The audit trail behind your entry
    • The correction, with its reason

    THE QUESTION YOU ASK · Am I recording what actually happened, when it happened, in a way no one could mistake for something else?

  2. Level 2 · Supervisors & team leads

    A review responsibility — the second person who actually looks.

    WHAT YOU OWN

    • Reviewing the record and its audit trail, not just the result
    • Catching the too-perfect or back-dated entry
    • Confirming the right people did the right steps

    EVIDENCE YOU TOUCH

    • The reviewed batch record
    • The audit-trail review evidence
    • Any discrepancy you raised

    THE QUESTION YOU ASK · Would my review catch a falsified or altered record, or am I only checking that a box is ticked?

  3. Level 3 · Managers & process owners

    A system-control problem — integrity is designed, not asked for.

    WHAT YOU OWN

    • Access control, unique logins, and audit-trail configuration
    • That audit-trail review is scheduled and evidenced
    • Data-lifecycle controls across the systems you own

    EVIDENCE YOU TOUCH

    • System configuration and access records
    • Documented audit-trail reviews
    • The data-integrity risk assessment

    THE QUESTION YOU ASK · Are my systems built so the record cannot be quietly changed, and can I prove review actually happens?

  4. Level 4 · Directors & site leaders

    An inspection-readiness signal — the first thing an inspector tests.

    WHAT YOU OWN

    • Site data-integrity posture across systems
    • Whether hybrid and legacy gaps are closed
    • The governance and culture behind the controls

    EVIDENCE YOU TOUCH

    • Site data-integrity metrics and audits
    • The remediation status of known gaps
    • Data-governance procedures

    THE QUESTION YOU ASK · If an inspector pulled any record today, would its history survive scrutiny across every system on this site?

  5. Level 5 · VPs & functional executives

    A network-integrity and technology-investment question.

    WHAT YOU OWN

    • Consistent data governance across sites and partners
    • Investment in systems that make integrity structural
    • Oversight of CDMO and lab data you rely on

    EVIDENCE YOU TOUCH

    • Cross-site and supplier data-integrity assurance
    • The systems-investment case
    • Partner audit outcomes

    THE QUESTION YOU ASK · Do I trust the data coming from every site and supplier, and am I investing so integrity is built-in rather than policed?

  6. Level 6 · CXOs & boards

    A regulatory-exposure and trust question — the data every claim rests on.

    WHAT YOU OWN

    • Board assurance that the data underpinning filings is sound
    • Exposure from a data-integrity finding
    • Fiduciary oversight of the evidence base

    EVIDENCE YOU TOUCH

    • Board risk dashboards
    • Regulatory-exposure summaries
    • Independent data-integrity assurance

    THE QUESTION YOU ASK · Could a data-integrity failure invalidate our submissions, releases, or reputation — and would we know before a regulator did?

PROFESSIONAL · INSPECTION PLAYBOOK · SPEQ SYNTHESIS

The inspection-readiness playbook for this topic

CHECKING ACCESS

Checking your Professional access…