Service · Data Integrity

Data Integrity
(ALCOA+).

Data integrity fails when ownership, governance and day-to-day behaviours do not align with what the system is doing. We build defensible control models that work in BAU and hold up under inspection.

Governance that
operates in BAU.

Regulators test integrity through questions like: "Show me the last review." "Who owns this decision?" "How do you know this control is operating?"


The objective is not perfect documentation. The objective is evidence you can retrieve quickly and explain with confidence.

01
End-to-end control assessmentAcross process, system and people controls, with ALCOA+ applied in practice, not just on paper.
02
Risk-ranked remediationOwners, acceptance criteria and evidence expectations, prioritised by inspection risk and operational feasibility.
03
Logging and review controlsWhat is reviewed, how often, and documented rationale for why it is sufficient.
04
Supplier and SaaS oversightWhere evidence, responsibilities and control boundaries are shared, and need to be explicit.

Frequently asked.

What does ALCOA+ mean?
Attributable, Legible, Contemporaneous, Original, Accurate
…plus Complete, Consistent, Enduring and Available. These principles underpin all regulatory expectations for data integrity across GxP environments.
Common inspection findings
Access, audit trails and review
Incomplete audit trails, shared accounts, uncontrolled access and inadequate review controls. Regulators also check whether organisations can retrieve and explain data under questioning.
Are spreadsheets in scope?
Yes, if they support regulated activities
Version control, access restriction, validation where appropriate and documented review processes are all expected for spreadsheets that impact product quality or regulatory decisions.

Where the data
actually lived.

Based on a genuine engagement. Details are anonymised, and in some cases composited, to protect client confidentiality.

Situation

A pharmaceutical manufacturer under active FDA regulatory scrutiny identified a pattern of audit trail gaps across multiple laboratory systems during an internal gap review. Audit trail configuration had never been formally validated, and several GxP systems had been in routine use for years without a documented review process.

Challenge

Users held local administrator access on several critical GxP systems. Audit trail review had never been incorporated into routine quality oversight. The organisation faced a regulatory response deadline and needed a credible, evidenced remediation plan rather than a paper exercise.

Approach

A data integrity gap assessment was conducted across all laboratory GxP systems, producing a prioritised remediation register. User access structures were rationalised and formally documented. Audit trail review procedures were written, piloted and embedded into the site quality calendar. Privileged access controls were restructured with formal justification records.

Outcome

All critical findings were closed within 12 weeks. A CAPA response was submitted to the FDA within the agreed timeframe. The subsequent inspection raised no data integrity observations.

Data integrity concerns?
Let's look at the evidence.

Book a call to discuss your data landscape. We'll identify the gaps that matter and build a remediation plan that holds up.

Book a Call