Data integrity in GxP - ALCOA++ and data governance across the data life cycle
QFINITY · Service Areas · Data Integrity

Data Integrity in GxP-regulated Fields.

EU inspectorate or FDA - either way, authorities expect data integrity that is built into processes and systems, not checked after the fact. We bring your data to that level: ALCOA++-compliant across the entire lifecycle and robust in any inspection.

Data Integrity

Data integrity is built by design.

Data integrity means data you can rely on across the entire life cycle - complete, unaltered, and uniquely attributable to a person - or the generating technical system - and a point in time. It has to be designed into processes and systems from the start and applies to paper and electronic data alike - wherever data feeds a quality decision. End-to-end data flows begin in the process - structured process management lays that groundwork.

One essential tool: analyzing data integrity risks as part of the risk assessment itself and building in mitigating measures. Data integrity and the validation of computerized systems go hand in hand here - and in operation, this carries over into the regular system and validation reviews.

Ensuring data integrity begins with correct and complete data capture, follows the flow of data through the processes, and ends with proper filing and retention.
ALCOA++

Ten criteria for trustworthy data.

ALCOA++ is the benchmark for data integrity: the five core ALCOA criteria, plus four "+" criteria and - as the second "+" - end-to-end traceability (Traceable). They apply to every record that contributes to a quality decision.

CriterionGroupMeaning
AttributableALCOAEvery record is uniquely attributable to a person - or the generating system - and a point in time.
LegibleALCOAData are permanently legible and comprehensible - even after years.
ContemporaneousALCOAThe record is created at the time of the activity, not retrospectively.
OriginalALCOAThe original record, or a verified true copy, is retained.
AccurateALCOAData are correct and free of undetected errors.
Complete+All data including repeats, metadata and audit trail are present.
Consistent+Records are chronological and free of contradictions.
Enduring+Data remain intact throughout the entire retention period.
Available+Data are accessible at all times for review, audit and inspection.
Traceable++Every change can be traced end-to-end through the audit trail.
Data Life Cycle

Paper, electronic, hybrid.

Data integrity applies to every medium - the same requirement covers the air-conditioned, access-controlled server room and the paper archive alike; only the implementation differs. What matters is the entire life cycle, all the way to long-term archiving. The distinction between dynamic and static records is the common bridge - it comes from the FDA Data Integrity guidance and appears in the PIC/S guide as well.

  • Paper equals electronic

    The same integrity requirement, different control measures - from hybrid paper-electronic transitions to integrated interfaces.

  • Dynamic to static

    Convert proprietary raw data (e.g. from HPLC) into non-proprietary formats that stay legible long term - risk-based, and without losing data or metadata.

  • No technological museum

    Archiving must not mean permanently keeping obsolete systems just to read old data.

  • Replacement scanning

    Destroy paper after a compliant, secured scan (e.g. per BSI TR-RESISCAN) - verified to match the original.

Data Governance

Structures that keep data trustworthy.

Data integrity does not come from isolated measures but from a data governance system: anchored organizationally in the QMS and implemented in technology.

  • Data governance system

    Roles, responsibilities and controls for available, unaltered, ALCOA++-compliant data - anchored in the QMS and enforced in technology.

  • Data integrity assessment

    Systematic assessment of data integrity across manufacturing and quality control - the starting point and touchstone of every governance program.

Records and signatures are the mechanism.

Where governance describes the goal, electronic records and signatures deliver the concrete how: they bind every record to a person or the generating system and a point in time and make the audit trail legally sound - the Part 11 / Annex 11 core of Attributable and Traceable.

Audit Trail Review

How much audit trail review do the authorities expect?

Everything is recorded - the review is targeted: the scope, frequency and roles of audit trail review follow a documented risk assessment. That line runs from FDA guidance through the PIC/S guide PI 041 into the Annex 11 draft - and through the GAMP RDI guide Data Integrity - Key Concepts - QFINITY served on its core team.

No. The regulations consistently call for a targeted, risk-based review. Changes to data are also more often human error than falsification - investigating every single change is neither required nor effective.

The reason behind a change, and patterns: a recipe changed before the start of a batch and reverted afterwards, or alarm limits drifting during a batch, say more than a hundred individual entries.

Critical records in process, together with the data review - the electronic counterpart of checking cross-outs on paper. Systemic audit trails (configuration, role concept) are secured through change control and can justify a reduced frequency.

The draft opens a deliberate gap: in future, all manual interactions are captured - including changes to settings and access privileges or alarm acknowledgements - while the review is explicitly targeted and risk-based. Record more, review smarter.

Reviewing all entries in an audit trail record may not be effective. Reviews should be targeted, based on risk and adapted to local manufacturing processes.
From the draft of EU GMP Annex 11
Authority Expectation

Two worlds, one expectation.

What one inspector demands, the other demands too. With guide PI 041, PIC/S trains inspectors from both worlds and provides the shared basis for interpretation - your ALCOA++ standard holds up with an EU inspectorate and the FDA alike, even though the legal foundations differ.

EU · EMAGMP Annex 11 · Chapter 4
PIC/SPI 041 - the bridge
US · FDA21 CFR Part 11 · CGMP

Outlook: the biggest shift since 2011. In July 2025 the EU released the revised drafts of Annex 11 and Chapter 4 together with the new Annex 22 (Artificial Intelligence) for consultation; Annex 11 grows from five to around 19 pages and, for the first time, addresses cybersecurity, cloud and AI. Annex 22 will likely land before the Annex 11 revision and could shape it substantially - both drafts reach considerably deeper into the "how" than the deliberately principle-based Annex 11 has to date. Finalization is expected in 2026, with a phased rollout through 2027/2028 - we get you ready for that transition today.

Our Service

Data integrity, secured the risk-based way.

Strategy and implementation of the risk-based approach to optimize resource use
Data integrity assessments for manufacturing and quality control
Building a data governance system across QMS and technology
Analysis of data flows (end-to-end) and reduction of manual media breaks
Performing ALCOA++ analyses
Interpretation and implementation of EU GMP Annex 11 and Chapter 4
Interpretation of US FDA 21 CFR Part 11 and the FDA Data Integrity guidance
Preparation for the Annex 11 revision and the new Annex 22 (AI)
Concepts for audit trail and audit trail review
Good documentation practice for electronic data and computerized systems
Concepts for archiving, data migration and verification
Assessment and oversight of cloud and supplier solutions
Data Integrity & AI

Trustworthy AI begins with trustworthy data.

Artificial intelligence is increasingly entering GxP processes - and it is only as good as the data it is trained and operated on. "Garbage in, garbage out" applies doubly here: sound, ALCOA++-compliant data are the prerequisite for models whose outputs can be verified and explained in an audit. Data integrity is therefore the foundation of every AI-enabled system - and, conversely, the forthcoming Annex 22 demands exactly this data quality.

Training-data integrity ALCOA++ Annex 22 AI-enabled Audit Trail
More from our service areas

Data needs validated systems.

Data integrity you can prove - not just claim.

We start with a risk analysis of your critical data flows and an ALCOA++ check, then use the initial call to map your biggest gaps and sketch a risk-based roadmap. Free of charge, about 30 minutes.

Book an intro call