A shared login may seem harmless until an FDA investigator asks who changed a result. A missing chromatographic file, an unexplained reintegration, or an altered worksheet can cast doubt on far more than one test. It may undermine the evidence used to approve or reject an entire batch, as emphasized in the US FDA Data Integrity Guidance, which requires complete, accurate, and traceable records to support every CGMP decision.
FDA expects CGMP records to remain complete, consistent, accurate, traceable, and reconstructable throughout the data lifecycle. Enforcement has become more active. In fiscal year 2025, 112 warning letters describing violations of 21 CFR Part 211 appeared on the FDA website, the highest total reported in more than two decades. Deficiencies involving written procedures and batch records remained among the leading citations.ALCOA+ helps you translate these expectations into daily controls, but it is n
ot a separate FDA regulation. The sections ahead explain its 9 principles, applicable FDA requirements, paper and electronic record controls, audit trail review, risk assessment, remediation, and inspection preparation.
Key Takeaways
- A trustworthy CGMP record must show the full history behind a decision, not just the final approved result.
- ALCOA+ becomes meaningful only when it is built into access rules, system settings, reviews, investigations, and record retention.
- Original files, metadata, audit trails, failed tests, repeated runs, and changes may all form part of the evidence FDA expects to see.
- Controls should be strongest where data affects batch release or patient safety, can be altered easily, or is difficult to verify later.
- Data integrity is an ongoing management and quality responsibility that also extends to laboratories, vendors, cloud providers, and other third parties.
What Is Data Integrity Under US FDA CGMP?
As defined in the US FDA data integrity guidance, data integrity under FDA CGMP means you can trust the information used to make a quality or manufacturing decision. The record must be complete, consistent, and accurate from the moment the data is created until it is archived or disposed of. It is also essential for FDA submissions, as regulators rely on complete and reliable records to evaluate product quality, safety, effectiveness, and regulatory compliance.
An FDA investigator should be able to follow the record and understand what happened without depending on someone’s memory. They should be able to see who performed the activity, when it took place, which method or system was used, and whether anyone changed the result later. When a value is updated, the record should preserve the original entry, show the new value, and explain the reason for the change.
The full record often contains more than the final report. Raw data, metadata, audit trails, calculations, instrument settings, processing parameters, system configurations, and investigation records may all be needed to understand how the reported result was produced.
Data integrity applies during creation, capture, processing, review, reporting, transfer, storage, retrieval, and final disposition. Weak controls at any point can affect the reliability of the record.
What Are the Nine ALCOA+ Principles?
Aligning with the US FDA data integrity guidance ALCOA originally covered five qualities of reliable data: attributable, legible, contemporaneous, original, and accurate. The plus adds four more: complete, consistent, enduring, and available. Together, these principles help you check whether CGMP records can be trusted during review, batch release, or an FDA inspection.
Principle |
Meaning |
Supporting controls |
Evidence an inspector may request |
Common failure |
Attributable |
Every entry, review, action, and change can be traced to the person or system responsible. | Unique user IDs, controlled signatures, role-based access, account creation and termination procedures, service account governance | User lists, access matrices, login histories, electronic signature records, privileged user reports | Shared analyst accounts, generic administrator IDs, borrowed credentials |
Legible |
Records remain readable and understandable for the full retention period. | Permanent entries, controlled templates, readable exports, data dictionaries, migration and restoration testing | Original records, archived copies, exported reports, restored files | Faded thermal printouts, unreadable scans, unsupported file formats |
Contemporaneous |
Information is recorded when the work takes place. | Automatic timestamps, point of use recording, synchronised system clocks, controlled delayed entry procedures | System timestamps, equipment logs, worksheets, audit trails | End of shift recording, backdating, unofficial notes copied later |
Original |
The first capture of the information, or a verified true copy, is retained. Original data does not always mean paper. | Native raw data retention, verified true copy procedures, metadata preservation, validated scanning and migration | Native files, metadata, source records, verification records for copied data | Keeping a summary PDF while deleting the dynamic chromatographic data |
Accurate |
The record correctly reflects the observation, calculation, activity, or result. | Validated calculations, calibration, independent review, controlled exception handling, spreadsheet verification | Calibration records, formula checks, review evidence, configuration records | Manual calculation errors, undocumented edits, incorrect instrument settings |
Complete |
All relevant information is retained, including failed, repeated, aborted, deleted, and invalidated records. | Sequence reconciliation, audit trails, deletion restrictions, exception reports | Full test sequences, audit trail records, invalidation documents, investigation files | Keeping passing tests while leaving out failed or aborted runs |
Consistent |
Records follow a logical timeline and use the correct approved process. | Time synchronisation, version control, standard date formats, controlled sequence numbering | Method histories, sample logs, timestamps, document versions | Results entered before sample receipt, conflicting timestamps, mismatched method versions |
Enduring |
Records remain preserved on durable and controlled media for the required period. | Validated archives, backup and restoration testing, disaster recovery planning, media and format migration | Backup logs, restoration results, archive validation records, recovery procedures | Local drive storage, overwritten files, unsupported storage media |
Available |
Records can be retrieved, opened, understood, and matched to the correct batch when needed. | Indexed archives, tested restoration, record to batch linkage, retrieval procedures | Retrieved batch records, restored files, archive indexes, retrieval test results | A stored file that cannot be opened, searched, restored, interpreted, or linked to the batch |
ALCOA+ helps you look past the final number and examine the record behind it. A result may appear acceptable, but it still raises concerns when the original file is missing, the user cannot be identified, or the supporting data cannot be retrieved.
What Does FDA Expect From a Data Integrity Control System?
To meet the core expectations of the US FDA data integrity guidance, ALCOA+ principles need to be built into daily procedures, system access, record review, and data retention. FDA expects the full record behind a CGMP decision to remain available for review. FDA Cybersecurity Guidance also requires manufacturers to protect electronic records and systems from unauthorized access and data tampering.
Complete Records, Metadata, and Context
A final reported value may not be the complete record. Reviewers may also need the metadata that shows how the result was created and changed, including:
- User identity
• Date and time
• Instrument ID
• Method version
• Processing parameters
• Sequence information
• Original and changed values
• Reason for each change
For example, a printed HPLC assay result may show only the final value. It may not reveal:
- Reintegration
• Reprocessing
• Aborted injections
• Changes in sequence order
• Modified processing parameters
The native electronic file may therefore be required to reconstruct the analysis. Keeping only a printout or summary PDF may be insufficient when it leaves out metadata, audit trails, or the processing history.
Original Records and Verified True Copies
A copy may replace an original record only when the company can show that it is a verified true copy. The copying process must preserve:
- Content
• Meaning
• Context
• Metadata
• Links between related records
For electronic records, a flat image may leave out details needed to review the activity. A PDF of a laboratory result, for example, may not preserve audit trails, formulas, processing history, or connections to other files.
Scanning, file conversion, and system migration may require validation to confirm that no information was lost or changed. The verification should be documented and performed according to an approved procedure.
A scan or PDF is not automatically a true copy. Its acceptability depends on whether it faithfully preserves the complete record and can be checked against the original.
Static and Dynamic Electronic Records
A static record is a fixed version of the data, such as a printout or PDF. It shows the information as it appeared at a particular time, but it may not allow the reviewer to examine how the result was produced.
A dynamic record keeps the electronic functions needed to interact with the underlying data. Depending on the system, this may allow a reviewer to reprocess results, inspect calculations, filter entries, review integration, or trace links between related records.
In line with the US FDA data integrity guidance, dynamic retention may be necessary when the reviewer needs to verify:
- Calculations
• Peak integration
• Processing history
• Method application
• Relationships between data files
For example, a static chromatogram may show the final result but not the integration settings or earlier processing steps. Keeping only that output could remove information needed to assess the analysis.
Companies should use a documented risk assessment to identify which records lose important context or review functions when converted into a static format.
Audit Trails and Change History
When an electronic record changes, the system should preserve enough detail to show what changed, who made the change, and when it occurred. An audit trail provides that history through a secure, computer-generated, time-stamped record of data creation, modification, or deletion.
A useful audit trail review procedure should answer four questions:
- Scope: Which fields, actions, and changes could affect a GxP decision?
• Timing: Should the review happen before release, at set intervals, or after a defined event?
• Reviewer: Does the reviewer understand the process and have enough independence to challenge unusual activity?
• Follow up: Which entries require an explanation, investigation, or escalation?
FDA does not expect every audit trail to be checked each day. Nor does every keystroke need to generate an audit trail entry. The review should focus on changes that can affect the quality, reliability, or interpretation of CGMP data.
A risk-based review model may classify events as follows:
| Risk level | Review approach |
| High risk | Review before batch disposition |
| Moderate risk | Review periodically or through exception reports |
| Low risk | Monitor through sampling, system administration checks, or security reviews |
High-risk events can include:
- OOS or OOT results
• Reintegration or reprocessing
• Deleted or aborted records
• Specification changes
• Actions performed by privileged users
• Changes to electronic batch records
Simply enabling an audit trail is not enough. The company must also define who reviews it, which events matter, and what happens when the review finds unexplained activity.
Access and Administrator Controls
System access affects who can create, change, delete, or approve GxP data. For that reason, it is a CGMP control, not just an IT concern.
Key controls include:
- Unique user accounts
• Access limited to job responsibilities
• Prompt account removal after role changes or departure
• Regular access reviews
• Separation of user and administrator rights
• Monitoring of privileged activity
Administrators should not routinely approve or review their own GxP actions.
Service accounts need a clear owner and limited permissions. Vendor access should be approved, monitored, and removed after use. Emergency access should be documented and reviewed afterward.
Validation of Computerised Systems and Interfaces
Vendor testing does not show that the system will work correctly in your own environment. Validation must cover the configured process, including:
- Intended use
• System settings
• User roles and permissions
• Calculations and reports
• Interfaces and data transfers
• Exception handling
• Audit trails
APIs, middleware, laboratory interfaces, and automated data transformations also need testing. Reconciliation or other verification should confirm that transferred data remain complete, accurate, and linked to the correct source record.
Backup, Archive, and Retrieval
| Record type | Main purpose |
| Production record | Active record used during operations |
| Archive | Controlled retention for the required period |
| Backup | Recoverable copy used to protect data |
| Disaster recovery replica | Supports system restoration after disruption |
| Temporary cache | Short-term copy used during processing |
| Export | Extracted version that may not retain full context |
| Certified true copy | Verified copy that preserves required content and meaning |
Having a backup does not prove that records are available. The company must be able to restore the data, open it in a compatible format, retain the required metadata, and connect it to the correct batch or activity.
Restoration tests should confirm that records remain complete and readable. Archives also need clear indexing and retrieval procedures so that requested data can be produced during an inspection.
OOS, Repeated, Aborted, and Invalidated Results
The US FDA data integrity guidance explicitly highlights that a failed or discarded result does not disappear from the CGMP record. Even after invalidation, the site should retain the original data, related metadata, investigation, scientific rationale, and final quality decision.
Repeat testing needs a documented reason. Running additional tests until one passes, without explaining the first result, can amount to testing into compliance. FDA may then question whether the batch decision was based on science or on selecting a preferred outcome.
During an inspection, the site should be ready to answer one direct question:
Can you produce every original, repeated, aborted, invalidated, and reported result linked to the released batch?
How to Build an FDA Compliant Data Integrity Programme
1. Assign Governance and Quality Unit Responsibility
Start by deciding who owns each part of the programme. Senior management, quality assurance, laboratory teams, manufacturing, IT, and system owners should have defined responsibilities.
The quality unit must be able to review original data, audit trails, investigations, and system reports without relying on the department under review to filter the records first.
You also need a clear route for reporting:
- Missing records
• Suspicious changes
• Deleted data
• Unexplained test activity
• Concerns about record reliability
Targets and workplace pressure matter too. Staff are less likely to report mistakes when delays are punished, or production goals are unrealistic. Management should make accurate reporting more important than keeping a schedule.
2. Inventory GxP Data, Records, and Systems
List every place where GxP data is created, changed, transferred, or stored, including:
- Laboratory instruments
• Manufacturing systems
• Spreadsheets and paper records
• Hybrid workflows
• Local and cloud storage
• SaaS applications
• Interfaces and APIs
• Contract laboratories and CMOs
For each system, record the owner, location, data type, retention period, administrator, and audit trail capability.
3. Map the Data Lifecycle
Trace each record from the point it is created until it is archived or disposed of. Document where data is temporarily stored, transcribed, calculated, reviewed, transferred, and reported. The map should also flag weak points such as loose paper, unofficial worksheets, local drives, temporary files, editable exports, manual transcription, and interfaces that are not reconciled.
4. Rank Data Integrity Risk
Use this model:
Data integrity risk = data criticality × vulnerability × difficulty of detection
1. Criticality
Check whether the data supports:
- Batch release
• Patient safety
• Regulatory submissions
• Stability studies
• Investigations
• Validation
2. Vulnerability
Review whether users can:
- Overwrite or delete records
• Disable audit trails
• Use shared accounts
• Reprocess data without control
• Change records through administrator access
3. Detectability
Consider whether:
- Improper changes appear in reports
• Audit trails are reviewed
• QA can retrieve original records independently
• Missing or deleted sequences are reconciled
You may use your own scoring scale, provided the rationale, risk rating, and required controls are documented.
5. Implement Controls Based on Risk
Apply stronger controls to records and systems that carry greater risk. Depending on the process, controls may include controlled paper forms, permanent entries, role-based access, audit trail settings, independent review, synchronised clocks, data transfer checks, validated spreadsheets, archive testing, and monitoring of privileged users. They also strengthen cybersecurity risk management by reducing the risk of unauthorized access and data manipulation.
Legacy systems need added safeguards when they cannot provide reliable audit trails. Restrict access, reconcile printouts or sequence records, require independent review, and tighten written procedures. The site should also keep a documented plan for replacing systems that cannot support adequate data integrity controls.
6. Train Employees by Role and Workflow
Training should reflect what each person actually does. Analysts, reviewers, administrators, supervisors, and contractors face different data integrity risks, so one general ALCOA+ session is not enough.
Use role-specific examples such as delayed entries, reprocessing, password sharing, unofficial notes, missing data, OOS investigations, and administrator changes. Employees should also know how to report mistakes, document corrections, and raise concerns without hiding what happened.
7. Monitor Programme Effectiveness
Track whether controls continue to work after implementation. Useful indicators include:
- High-risk systems with active audit trails
• Audit trail reviews completed on time
• Shared, inactive, or orphaned accounts
• Unexplained aborted or deleted records
• Successful archive restoration tests
• Critical interfaces that are reconciled
• Repeat documentation errors
• Delayed entries
• Recurring data integrity deviations
• Repeated CAPA failures
• Overdue legacy system actions
Use these measures to spot weakening controls early. A low deviation count should not be treated as success when staff may be avoiding or underreporting problems.
Preparing for an FDA Data Integrity Inspection and Remediating Failures
Inspection Readiness
During an audit conducted under the US FDA data integrity guidance, FDA may trace one batch, test, or electronic transaction from start to finish. Be ready to provide original data, metadata, audit trails, access records, repeated or invalidated tests, transfer checks, backup restoration results, archived records, quality reviews, investigations, and CAPA files.
Contract laboratories, CMOs, cloud providers, and software vendors must also be covered. Outsourcing does not remove your oversight responsibility.
Remediating a Data Integrity Failure
First, preserve the records and stop further loss. Then contain the weakness, assess product and patient risk, and define the affected systems, batches, sites, and time period.
Use an independent review when internal records are incomplete or unreliable. Investigate technical, procedural, management, and cultural causes, then apply CAPA across the wider system.
CAPA closure alone is not enough. Confirm effectiveness through restoration tests, access reviews, audit trail trends, lower recurrence, and independent verification.
How Qualysec Can Help Protect GxP Systems and Sensitive Data
As a CREST-accredited cybersecurity company, Qualysec provides penetration testing for web applications, APIs, mobile applications, cloud environments, external networks, and IoT systems.
Penetration testing does not replace FDA compliance, system validation, quality oversight, or an ALCOA+ programme. It helps identify security weaknesses that could expose regulated systems and data to unauthorised access, alteration, disclosure, or disruption.
Qualysec can support regulated organisations by testing:
- APIs that transfer GxP data
• Cloud platforms that host sensitive records
• Laboratory and quality system portals
• Web and mobile applications used for data collection
• Authentication and access controls
Its hybrid approach combines automated testing with manual validation to uncover technical and business logic flaws. Reports include severity-based findings, reproduction steps, remediation guidance, executive summaries, and retesting support.
Conclusion
FDA data integrity compliance guidance depends on whether your records can still be trusted, traced, and reconstructed long after the original activity took place. Knowing the ALCOA+ terms is only the beginning. Each principle must be reflected in system access, metadata retention, audit trail review, validation, investigations, archival, and quality unit oversight.
Controls should be stronger where data is critical, easy to alter, or difficult to verify after the fact. Treat data integrity as part of daily quality management and governance, not as a set of records prepared only when an inspection is approaching.
Contact Qualysec for a penetration testing consultation or security assessment of the applications and infrastructure supporting your critical data.
FAQs
1. What is the FDA data integrity requirement?
FDA wants companies to be able to trust the records used for manufacturing, testing, release, and investigations. The data should show what happened, who did it, when it was done, and whether anything changed later. If the original record is missing or the history cannot be checked, the result may not be reliable.
2. What are the 5 principles of data integrity?
The original ALCOA principles are attributable, legible, contemporaneous, original, and accurate. They help answer simple questions. Who created the record? Can it still be read? Was it entered at the right time? Is the first record still available? Does it reflect what actually happened?
3. What is 21 CFR for data integrity?
There is no single 21 CFR section called US FDA data integrity guidance. Drug manufacturers usually rely on Parts 210 and 211 for CGMP record requirements. Part 11 also matters when electronic records or electronic signatures are used.
4. What are the guidelines for data integrity?
Companies should control access, keep original data and metadata, review important changes, validate systems, investigate unusual activity, and ensure they can still open records years later.
The point is to keep enough evidence for someone else to follow the work from beginning to end.
5. What are the 4 types of data integrity?
This wording usually comes from database management. The four types often list themselves as entity integrity, referential integrity, domain integrity, and user-defined integrity. They are not the same as FDA data integrity expectations for GxP records.
6. What are the 5 pillars of data integrity?
People usually mean the five ALCOA principles when they use the phrase five pillars. FDA does not formally use that label, but it is common in training and quality discussions.







