Data Integrity in Pharmaceutical Industry: ALCOA+ Principles, FDA Guidance & Examples
Pharmaceutical decisions are only as reliable as the data behind them. Data integrity means that records remain complete, consistent, accurate, attributable, and trustworthy throughout their lifecycle—from the moment data are generated until they are reviewed, reported, retained, and retrieved.
In the pharmaceutical industry, data integrity is the assurance that data are reliable and remain trustworthy throughout their lifecycle. WHO describes the expected characteristics using ALCOA+: Attributable, Legible, Contemporaneous, Original or a true copy, Accurate, Complete, Consistent, Enduring, and Available. FDA expects firms to use meaningful, risk-based controls to prevent and detect data-integrity problems under CGMP.
- What Is Data Integrity in Pharma?
- ALCOA+ Principles Explained
- Why Data Integrity Matters
- Data Lifecycle & Data Governance
- Paper vs Electronic Data Integrity
- Audit Trails, Metadata & User Access
- Laboratory Data Integrity
- Practical Examples
- Common Data Integrity Failures
- How to Investigate a Data Integrity Concern
- Interview Knowledge
- FAQ
What Is Data Integrity in the Pharmaceutical Industry?
Data integrity is the degree to which pharmaceutical data remain complete, consistent, accurate, reliable, and trustworthy throughout the entire data lifecycle. The concept applies to paper records, electronic records, laboratory data, manufacturing records, batch documentation, stability data, equipment logs, computerized systems, and regulatory submissions.
FDA's data-integrity guidance explains that the agency expects all data to be reliable and accurate, and that firms should use meaningful and effective strategies to manage data-integrity risks based on process understanding, technology, and business models.
Data integrity is not limited to deliberate falsification. Weak procedures, poor system design, inappropriate access, incomplete records, uncontrolled worksheets, missing metadata, or inadequate review can all create data-integrity risk.
ALCOA+ Principles Explained
WHO uses the term ALCOA+ to describe the core characteristics expected of trustworthy pharmaceutical data. These principles apply across the data lifecycle, not only at the moment a result is written down.
| Principle | Meaning | Pharma Example |
|---|---|---|
| Attributable | It is clear who performed an action and when. | An analyst uses an individual login rather than a shared account. |
| Legible | Records can be read and understood throughout retention. | Handwritten entries are clear and permanent; electronic records remain readable. |
| Contemporaneous | Data are recorded when the activity occurs. | A balance weight is recorded at the time of weighing, not recreated later. |
| Original / True Copy | The first capture of data, or a verified true copy preserving context, is retained. | Raw chromatographic data and associated metadata are retained, not only a printed summary. |
| Accurate | Data correctly reflect the activity or result. | Calculations, integrations, transcriptions, and reported results are verified. |
| Complete | All relevant data are retained, including repeat, invalid, and failing data when applicable. | All injections and processing events are available for review. |
| Consistent | Data are recorded in a logical, traceable sequence. | Date/time sequence agrees with the actual order of sample preparation and analysis. |
| Enduring | Records are preserved in a durable form for the required retention period. | Data remain available on validated storage rather than only temporary instrument memory. |
| Available | Records can be accessed for review, inspection, and decision-making when needed. | Archived records can be retrieved promptly with their relevant metadata. |
Why Data Integrity Matters in Pharma
Pharmaceutical quality systems depend on data to make decisions about product release, batch rejection, process control, stability, validation, deviations, OOS investigations, CAPA, complaints, and regulatory submissions. If the underlying data cannot be trusted, the quality decision cannot be trusted either.
- Patient safety and product quality.
- Reliable batch-release decisions.
- Scientifically defensible OOS and deviation investigations.
- Accurate stability and shelf-life conclusions.
- Reliable validation and qualification evidence.
- Inspection readiness and regulatory compliance.
- Traceability of who did what, when, and why.
Data Lifecycle and Data Governance
Data integrity must be controlled across the entire lifecycle. A system can generate accurate data initially but still fail if records are later altered, lost, deleted, incompletely reviewed, or made inaccessible.
Data governance is the organizational framework used to control how data are generated, processed, reviewed, protected, retained, and used. It includes procedures, roles, training, system design, access controls, review practices, quality oversight, and management responsibility.
Paper vs Electronic Data Integrity
| Area | Paper Record Risk | Electronic Record Risk |
|---|---|---|
| Attribution | Missing signature/initials or unclear ownership. | Shared accounts or generic logins. |
| Changes | Overwriting, correction fluid, unexplained changes. | Unreviewed audit-trail changes, deletion, reprocessing without justification. |
| Original Data | Unofficial scraps or uncontrolled worksheets. | Keeping only PDF/printouts while losing dynamic raw data and metadata. |
| Retention | Damage, loss, poor filing, unreadable records. | Insufficient backup, unsupported formats, loss of system context. |
Audit Trails, Metadata, and User Access
Audit Trails
In computerized systems, an audit trail can provide a secure, computer-generated history of actions that create, modify, or delete regulated records. Appropriate audit-trail review helps determine whether critical changes were justified and whether the final reported result tells the complete story.
Metadata
Metadata provide context needed to understand the data. Examples include date/time, user identity, instrument ID, method information, processing parameters, sequence information, and change history. A record may look complete on paper while still being incomplete if critical metadata are missing.
User Access
Access should be appropriate to the user's role. Shared accounts weaken attribution. Users should not have unnecessary privileges that allow them to modify system configuration, delete records, or bypass controls without detection.
If a critical action can occur in the system, ask whether it is authorized, attributable, traceable, reviewable, and retained.
Data Integrity in the QC Laboratory
- Individual user accounts for computerized systems.
- Controlled analytical methods and approved processing parameters.
- Retention of original raw data and relevant metadata.
- Review of complete sequences, not only the final selected result.
- Appropriate audit-trail review.
- Controlled standards, reagents, and worksheets.
- Documented investigation of unexpected events and OOS results.
- Controlled reprocessing, reintegration, retesting, and repeat injections.
- Backup and archival controls.
This connects directly with our guide to OOS in Pharmaceutical Industry. An OOS investigation is only as strong as the raw data, metadata, audit trails, and records available for review.
Practical Data Integrity Examples
Example 1: Shared HPLC Login
Problem: Several analysts use one generic instrument account.
Risk: Actions cannot be reliably attributed to an individual user.
Control: Unique user IDs, role-based privileges, and appropriate review of system activity.
Example 2: Rewriting a Weight Later
Problem: An analyst records a sample weight on scrap paper and later copies it into the controlled worksheet.
Risk: The official record is not contemporaneous and the original observation may be lost.
Control: Record the observation directly in the controlled record or validated electronic system at the time of the activity.
Example 3: Deleted Failed Injection
Problem: An undesirable chromatographic injection is deleted and only the passing injection is retained.
Risk: The record is incomplete and may hide relevant evidence.
Control: Preserve complete raw data and investigate unexpected results or system events according to procedure.
Example 4: Unexplained Manual Integration
Problem: A chromatographic peak is manually reintegrated to obtain a more favorable result without documented scientific justification.
Risk: The reported result may not reflect an objective, controlled analytical process.
Control: Define integration practices, restrict privileges, retain processing history, and require documented scientific review.
Common Data Integrity Failures
How to Investigate a Data Integrity Concern
- Secure relevant records and electronic evidence.
- Define what occurred and when it occurred.
- Identify affected data, batches, systems, methods, and products.
- Review audit trails, metadata, access history, raw data, and paper records as applicable.
- Assess product-quality and regulatory impact.
- Determine root cause rather than stopping at “operator error.”
- Evaluate whether the problem is isolated or systemic.
- Define CAPA when justified and verify effectiveness.
- Document conclusions and Quality Unit oversight.
If the event is managed as a deviation, see our Deviation in Pharmaceutical Industry guide. When systemic corrective action is required, our CAPA in Pharmaceutical Industry guide explains the next step.
Data Integrity vs Good Documentation Practices
Good Documentation Practices (GDocP) support data integrity, but the terms are not identical. GDocP focuses heavily on how records are created, corrected, controlled, retained, and reviewed. Data integrity is broader and includes the reliability of data across paper and electronic systems, metadata, audit trails, access control, data processing, backup, archival, and governance.
Good Documentation Practices are one important part of a larger data-integrity system.
Data Integrity Knowledge for Pharma Interviews
“Data integrity means ensuring data remain complete, consistent, accurate, attributable, and trustworthy throughout their lifecycle. In practice, I would expect controlled documentation, contemporaneous recording, unique user access, complete raw data, appropriate audit-trail review, backup and archival controls, and independent quality oversight.”
Frequently Asked Questions
What does ALCOA+ mean in pharma?
ALCOA+ means Attributable, Legible, Contemporaneous, Original or true copy, Accurate, Complete, Consistent, Enduring, and Available.
Does data integrity apply only to electronic records?
No. Data-integrity principles apply to both paper and electronic records. The risks and controls differ, but both must remain trustworthy and traceable.
What is an audit trail?
An audit trail is a computer-generated record of system activities that can help show who performed an action, what changed, and when the change occurred. Its exact content depends on the system and intended use.
Why are shared passwords a data-integrity problem?
Shared credentials make it difficult or impossible to reliably attribute actions to an individual user.
Is data integrity the same as 21 CFR Part 11?
No. Data integrity is a broader quality concept. 21 CFR Part 11 addresses certain FDA requirements for electronic records and electronic signatures. A compliant data-integrity program also depends on CGMP requirements, procedures, governance, system controls, review, and lifecycle management.
Related Pharma Quality Guides
- GMP in Pharmaceutical Industry
- Quality Assurance vs Quality Control in Pharma
- OOS in Pharmaceutical Industry
- Deviation in Pharmaceutical Industry
- CAPA in Pharmaceutical Industry
- Change Control in Pharmaceutical Industry
Official and Authoritative Sources
- FDA — Data Integrity and Compliance With Drug CGMP: Questions and Answers
- WHO — Guideline on Data Integrity, Technical Report Series 1044
- Electronic Code of Federal Regulations — 21 CFR Part 11
Data integrity is not a documentation slogan. It is a quality-system requirement built into how pharmaceutical data are generated, controlled, reviewed, protected, retained, and used. ALCOA+ provides a practical framework for asking whether the data can truly be trusted.




Comments
Post a Comment