Data Integrity Assessment Guide: ALCOA+ in Practice
ALCOA+ provides the framework. Applying it to pharmaceutical manufacturing and quality control environments requires practical interpretation. This guide walks through each principle with examples of controls that demonstrate compliance and gaps that typically fail inspection.
ALCOA+ is not a regulatory document, it is a set of principles derived from regulatory guidance issued by FDA, MHRA, PIC/S and EMA. Understanding how each principle translates into specific system requirements and procedural controls is the basis for a meaningful data integrity assessment.
Attributable
It must be possible to determine who performed an action and when.
In practice: Individual user accounts for all systems, no shared logins. Electronic systems must capture user identity in audit trails. Paper records must be signed and dated by the individual performing the activity, not countersigned after the fact by a supervisor. When a record is attributed to a person, that person must have performed the activity and be able to confirm they did so.
Common gap: Shared login credentials ("Lab1", "QC_Generic") remain the most common attributability failure. Group accounts are never acceptable for GMP activities regardless of practical convenience.
Legible
Records must be readable and permanent throughout their retention period.
In practice: Electronic records must be stored in formats that remain readable without dependence on specific software versions that may not be available at the time of retrieval. Paper records must be written in permanent ink. Thermal paper, used in many legacy instruments and balances, is not acceptable for direct use as a GMP record because the image fades over time.
Common gap: Printouts from thermal-paper instruments affixed to batch records without any action to ensure permanence. The regulatory expectation is that thermal printouts are either printed on permanent paper or the data is transcribed to a durable record with appropriate verification.
Contemporaneous
Records must be made at the time the activity is performed.
In practice: Batch record entries must be made at the time of the activity, not reconstructed from memory at the end of a shift. Electronic systems must capture the time of data entry using a trusted time source, a server-controlled clock, not a local workstation clock that can be changed by the user. Where there is a difference between system time and actual time, this must be documented.
Common gap: Backdating entries to match expected timelines. In electronic systems, this manifests as entries made outside working hours, entries made after events that should have prompted them, or metadata time stamps inconsistent with other records.
Original
The first capture of data must be retained; copies of original records must be verified.
In practice: Raw data, the first capture of an observation, measurement or result, must be retained and must be the basis for decisions. Re-integration of chromatography data, manual integration replacing electronic integration without documented justification, and re-running samples without retaining the original failing result are all original data failures. The raw data for an HPLC analysis is the chromatogram, not the printed summary.
Common gap: "Working copies" of records that replace originals. In laboratories, the practice of discarding original integration files and retaining only the final manually integrated result is a critical data integrity failure regardless of whether the manipulation was intended to change the outcome.
Accurate
Records must be a truthful and complete representation of what was observed or done.
In practice: Accuracy requires that data reflects what actually happened. Transferring results between systems must be verified, whether manually (with a second-person check) or electronically (with a validated transfer process). Calculated results must use correct formulae and correct input values. Rounding conventions must be defined and applied consistently.
Common gap: Selective reporting: recording passing results while discarding or not reporting failing results. This is the most serious data integrity failure, it is not a documentation deficiency but a GMP fraud. Any system that allows results to be selectively retained requires robust procedural and technical controls.
Complete
All data, including invalidated data and failed runs, must be retained.
In practice: Completeness requires that the full data set, including every test performed, every result obtained and every record created, is retained and reviewable. Deleted records, aborted runs without documentation, and laboratory notebooks with pages removed are completeness failures. Electronic systems must retain all entries including those that were subsequently revised, with audit trail showing both the original and revised values.
Common gap: Incomplete audit trails resulting from system configuration errors. Some systems allow audit trail capture to be disabled; others have audit trail functions that must be explicitly enabled. System configuration should be verified to confirm audit trail is active and capturing all required activities.
Consistent
Data and activities must follow a defined, documented sequence.
In practice: Processes must be performed in the sequence defined in procedures. Chronological consistency must be verifiable from records, start times before end times, review after completion, approval after review. Time stamps across related records (batch records, instrument records, laboratory notebooks) must be consistent with each other and with the documented procedure.
Common gap: Time stamp inconsistencies between linked systems that are not synchronised to a common time source. Where multiple systems are involved in a workflow, time synchronisation across systems must be verified and documented.
Enduring
Records must be retained for the required period in a retrievable format.
In practice: Data retention requires not just that records are kept but that they can be retrieved and read. Electronic records must be backed up, backup integrity must be verified and recovery must be tested. Migration to new systems must include verification that data migrated completely and accurately. Access controls must ensure records cannot be deleted or modified during the retention period.
Common gap: Backup systems that have never been tested for recovery. The existence of a backup does not guarantee data can be recovered. Recovery testing, actually retrieving data from backup and verifying it matches the original, must be performed and documented periodically.
Available
Records must be accessible for review throughout the retention period.
In practice: Data must be available on request, including to regulatory inspectors. Data stored on obsolete systems that cannot be accessed, records held off-site without a retrieval process, or data requiring specific software no longer available are availability failures. For computerised systems, the ability to query and export data in a human-readable format must be maintained throughout the retention period.
Common gap: Data locked in legacy systems that the organisation has migrated away from without ensuring continued access. When migrating to a new LIMS or manufacturing execution system, a data migration validation must ensure all historical data is accessible in the new system or maintained accessibly in the old one.
ALCOA+ Principles
- AAttributable
- LLegible
- CContemporaneous
- OOriginal
- AAccurate
- +Complete
- +Consistent
- +Enduring
- +Available
Independent Data Integrity Assessment
Sthira Assure conducts ALCOA+ assessments against MHRA, FDA and PIC/S guidance across pharmaceutical and laboratory environments.