Data integrity in GxP - ALCOA++ and data governance across the data life cycle
QFINITY · Service Areas · Data Integrity

Data Integrity in GxP-regulated Fields.

EU inspectorates and the FDA alike expect data integrity that is built into processes and systems, not checked after the fact. We bring your data to that level: ALCOA++-compliant across the entire lifecycle, with evidence you can present in an inspection.

Data Integrity

Data integrity is built by design.

Data integrity means data you can rely on across the entire lifecycle. The data are complete, unaltered and uniquely attributable to the person who acted or the generating system as well as to a point in time. Data integrity has to be designed into processes and systems from the start and applies to paper and electronic data alike. In the GxP environment, the integrity of data used for quality decisions on products or services must be assured end to end. End-to-end data flows begin in the process. Structured process management lays that groundwork.

An essential lever is to analyze data integrity risks in the risk assessment itself and to build in mitigating measures. Data integrity and the validation of computerized systems go hand in hand. Once systems are in routine operation, data integrity also belongs in the regular system and validation reviews.

Ensuring data integrity begins with correct and complete data capture, follows the flow of data through the processes and ends with proper filing and retention.
ALCOA++

Ten criteria for trustworthy data.

ALCOA++ is the measure for data integrity. It comprises the five core ALCOA criteria and the four criteria of the first "+". The second "+" of ALCOA++ stands for end-to-end traceability (Traceable). The criteria apply to every record that contributes to a quality decision.

CriterionGroupMeaning
AttributableALCOAEvery record is uniquely attributable to a person or the generating system and to a point in time.
LegibleALCOAData are permanently legible and comprehensible, even after years.
ContemporaneousALCOAThe record is created at the time of the activity, not retrospectively.
OriginalALCOAThe original record, or a verified true copy, is retained.
AccurateALCOAData are correct and free of undetected errors.
Complete+All data including repeats, metadata and audit trail are present.
Consistent+Records are chronological and free of contradictions.
Enduring+Data remain intact throughout the entire retention period.
Available+Data are accessible at all times for review, audit and inspection.
Traceable++Every change can be traced end-to-end through the audit trail.
The Chapter 4 draft counts its own attributes inconsistently.

The 2025 draft of EU GMP Chapter 4 lists ten attributes in its Table 1. Its glossary definition of Data Governance counts only nine and omits Traceable. Its definition of Data Integrity uses a third formula: attributable, legible, contemporaneously recorded, original or a true copy, accurate and traceable. Anyone who takes the Data Governance definition as a checklist leaves out Traceable, the very criterion the audit trail stands for. We check against the ten attributes from Table 1.

Data Life Cycle

Paper, electronic, hybrid.

Data integrity applies to every medium. The same requirement covers the air-conditioned, access-controlled server room and the paper archive alike. Only the implementation differs. What matters is the entire lifecycle, all the way to long-term archiving. The distinction between dynamic and static records links both guides: it appears in the FDA Data Integrity guidance and in the PIC/S guide.

  • Paper equals electronic

    The control measures still differ, for instance at hybrid paper-electronic transitions and at integrated interfaces.

  • Dynamic to static

    Proprietary raw data, for example from HPLC, are converted on a risk basis into non-proprietary formats that stay legible long term, without losing data or metadata.

  • No technological museum

    Archiving must not mean permanently keeping obsolete systems just to read old data.

  • Replacement scanning

    Destroy paper after a compliant, secure scan (e.g. per BSI TR-RESISCAN), once it has been verified to match the original.

Data Governance

Structures that protect data across the lifecycle.

Data integrity needs a Data Governance system: organizationally embedded in the QMS and technically implemented. Isolated measures do not secure it.

  • Data Governance system

    Roles, responsibilities and controls are anchored in the QMS and enforced in technology. That keeps the data ALCOA++-compliant across the lifecycle.

  • Data integrity assessment

    The systematic assessment of data integrity across manufacturing and quality control is the starting point and touchstone of a governance program.

Records and signatures are the mechanism.

Where governance describes the goal, electronic records and signatures deliver the concrete how: they bind every entry to a person or the generating system, and to a point in time. The audit trail makes every change traceable. Together, these mechanisms form the Part 11 / Annex 11 core of Attributable and Traceable.

Audit Trail Review

How much audit trail review do the authorities expect?

Events are recorded completely in the audit trail, and the entries are reviewed in a targeted way. The scope, frequency and roles of audit trail review follow a documented risk assessment. That regulatory line runs from FDA guidance through the PIC/S guide PI 041 to the Annex 11 draft. The GAMP RDI guide Data Integrity - Key Concepts sets it out methodically. QFINITY served on the authors' core team.

No. What is required is a review that looks where the risk sits. Changes to data are also often due to human error, not only to falsification. Investigating every single change is neither required nor effective. A practical complication: the current Annex 11 requires a risk-based audit trail for GMP-relevant changes and deletions. Yet with complex systems it is often unclear which entries qualify, so everything gets recorded across the board. This common approach conflates audit trail and data logging and makes targeted review harder.

For the reason behind a change, and for patterns: a recipe changed before the start of a batch and reverted afterward, or alarm limits drifting during a batch, tell you more than a hundred individual entries.

Critical records are reviewed on an ongoing basis, together with the data review. That is the electronic counterpart of checking crossed-out entries on paper. Systemic audit trails (configuration, role definitions) are secured through change control and allow a reduced review frequency.

The draft separates recording from review: going forward, all manual interactions are captured, including changes to settings and access privileges or alarm acknowledgments. The review is explicitly targeted and risk-based. Record more, review smarter.

Reviewing all entries in an audit trail record may not be effective. Reviews should be targeted, based on risk and adapted to local manufacturing processes.
From the draft of EU GMP Annex 11
Authority Expectation

Two worlds, one expectation.

The EU inspectorate and the FDA examine the same thing on different legal foundations. The shared basis for interpretation is PI 041, the guide PIC/S uses to train inspectors from both worlds.

EU · European CommissionGMP Annex 11 · Chapter 4
PIC/SPI 041, the bridge
US · FDA21 CFR Part 11 · CGMP

Outlook: the biggest shift since 2011. In July 2025 the EU released the revised drafts of Annex 11 and Chapter 4 together with the new Annex 22 (Artificial Intelligence) for consultation; Annex 11 grows from five to around 19 pages and, for the first time, addresses cybersecurity and cloud. Annex 22 looks set to precede the Annex 11 revision and is likely to shape it substantially. The Annex 11 and Annex 22 drafts reach considerably deeper into the "how" than the deliberately principle-based Annex 11 has to date. When they will be finalized is still open, as are the transition periods. We get you ready for that transition today.

Our Service

Data integrity, secured on a risk basis.

Strategy and implementation of the risk-based approach to optimize resource use
Data integrity assessments for manufacturing and quality control
Development of a data governance system across QMS and technology
Analysis of data flows (end-to-end) and reduction of manual paper-electronic transitions
ALCOA++ analyses
Interpretation and implementation of EU GMP Annex 11 and Chapter 4
Interpretation of US FDA 21 CFR Part 11 and the FDA Data Integrity guidance
Preparation for the Annex 11 revision and the new Annex 22 (AI)
Concepts for audit trail and audit trail review
Good documentation practice for electronic data and computerized systems
Concepts for archiving, data migration and verification
Assessment and oversight of cloud and supplier solutions
Data Integrity & AI

Trustworthy AI begins with trustworthy data.

Artificial intelligence is increasingly entering GxP processes. A model inherits the quality of its training and operating data. Without origin, point in time and change history, a model result cannot be explained in an audit. ALCOA++-compliant data are therefore the prerequisite for every AI-enabled system in GxP use. For test data, the Annex 22 draft provides for access control, an audit trail and a record of which data were used, when and how many times.

Training-data integrity ALCOA++ Annex 22 AI-enabled Audit Trail

Last updated:

More from our service areas

Data needs validated systems.

Data integrity you can demonstrate, not just claim.

We start with a risk analysis of your critical data flows and an ALCOA++ check, then use the initial call to put your biggest gaps and the risk-based roadmap into context. Free of charge, about 30 minutes.

Book an intro call