Dhwani F.
QA Manager
Pfizer, USA
Introduction
Every decision in the pharmaceutical industry rests on data. Whether a batch is released, a stability study supports a shelf life, or a dissolution profile shows two formulations are equivalent, someone is trusting that the numbers on the page are true. When that trust breaks, the consequences reach beyond the company: patients may receive medicines whose quality was never properly demonstrated.
This is why regulators treat data integrity as a core expectation of Good Manufacturing Practice (GMP). Inspectors around the world now scrutinise how data is generated, recorded, reviewed, and retained, as well as the results themselves. The most widely used framework for describing trustworthy data is ALCOA+.
This article explains what data integrity means, where ALCOA+ came from, what each principle requires in practice, and how pharmaceutical organisations can build systems and habits that satisfy it.
What Is Data Integrity?
The MHRA defines data integrity as the extent to which all data are complete, consistent, and accurate throughout the data lifecycle. The WHO and PIC/S use very similar language. In simple terms, data integrity means the data can be trusted: it is reliable, it has not been altered inappropriately, and it tells the true story of what happened.
Three points are often misunderstood.
Data integrity is not only about fraud. Deliberate falsification is the most serious breach, but many data integrity failures come from poor system design, weak procedures, inadequate training, or workload pressure. A shared login, an unvalidated spreadsheet, or a paper notebook filled in at the end of the day can all compromise integrity without anyone intending harm.
It applies to all data. Paper records, electronic records, and hybrid systems are all in scope. So are raw data, metadata, audit trails, printouts, and the results that appear in a certificate of analysis.
It covers the whole lifecycle. Data must be protected from the moment it is generated, through processing, review, reporting, and archiving, until the end of its retention period.
Because the lifecycle is long and involves many people and systems, a structured set of principles helps. That is what ALCOA+ provides.
The Origins of ALCOA
The acronym ALCOA is generally credited to Stan W. Woollen, an FDA official, who used it in the 1990s to describe the attributes of good quality records for Good Laboratory Practice and clinical inspections. The original five attributes were Attributable, Legible, Contemporaneous, Original, and Accurate.
As computerised systems spread, regulators and industry recognised that five attributes did not fully cover complex electronic data environments. The framework was extended to ALCOA+ by adding four more: Complete, Consistent, Enduring, and Available. Some organisations also refer to ALCOA++, which adds Traceable, and to ALCOA-C, which emphasises Complete and Consistent as separate attributes.
The FDA, MHRA, WHO, and PIC/S all reference these principles in their guidance, and they have become the common language of data integrity inspections.
The Five Original Principles
1. Attributable
Every piece of data must show who performed the action, what was done, and when. This applies to recording a result, changing a value, reviewing a record, or approving a batch.
On paper, attribution means a handwritten signature or initials with a date, backed by a signature log that identifies each person. In electronic systems, it means unique user accounts, with no shared or generic logins, and audit trails that capture the user ID against every action.
A common failure is the shared account, such as “Analyst1” or “Lab_User”, used by several people on one instrument. When the system cannot tell who did what, attribution is lost and every record from that account becomes questionable. Another is one person signing for work done by someone else. Even with good intentions, this undermines the reliability of the whole record.
2. Legible
Data must be readable and understandable throughout its retention period. Illegible handwriting, faded thermal paper, and corrupted files all fail this test.
Legibility also covers permanence. Pencil is unacceptable for GMP records. Thermal paper printouts, such as those from balances and some chromatographs, fade over time, so they should be photocopied and attached as certified true copies. Electronic records must remain readable as software and hardware evolve.
Corrections matter too. A legible correction is a single line through the original entry, so the original stays visible, with the new value, date, initials, and a reason. Overwriting, using correction fluid, or scribbling out entries destroys legibility and suggests something is being hidden.
3. Contemporaneous
Data must be recorded at the time the activity is performed. This is one of the most frequently cited weaknesses in inspections.
Recording from memory at the end of the shift, filling in a batch record the next morning, or transcribing results from scrap paper later all breach this principle. The longer the gap between the event and the record, the greater the risk of error, omission, or embellishment.
Contemporaneous recording depends on practical setup. Documents must be available at the point of use. Workstations and benches must be arranged so operators can record as they work. Clocks on instruments and computers must be synchronised and protected from unauthorised change, because system timestamps are the evidence that recording was timely. Pre-dating or post-dating entries is prohibited.
4. Original
The record must be the first capture of the data, or a certified true copy of it. The original, also called source data, is where the data first appears, such as a handwritten entry in a notebook, a chromatogram file on an instrument, or a balance printout.
In practice, data should not be recorded on informal scraps and later copied into the official record. If transcription is unavoidable, the original must be retained, and a second person should verify the transcription.
For electronic systems, the original is typically the dynamic electronic record, including its metadata and audit trail. A PDF printout of a chromatogram is not the original if the electronic data allows reprocessing and review. Regulators expect companies to retain the raw electronic data, because a static printout can hide reprocessing, deleted injections, or altered integration parameters.
5. Accurate
Data must be correct, truthful, and free from error, and must reflect what actually occurred. Accuracy is supported by calibrated and qualified equipment, validated methods, validated computerised systems, and trained personnel.
Accuracy is also a matter of honesty. Results must not be rounded selectively, invalid data must not be excluded without justification, and unfavourable results must not be replaced with more acceptable ones. Any amendment must be documented, justified, and traceable, never hidden.
Validated calculations are an important part of accuracy. Spreadsheets used for GMP calculations must be validated, locked to prevent alteration of formulas, and controlled for version and access. An unprotected spreadsheet with editable formulas is a well-known source of inspection findings.
The “+” in ALCOA+
6. Complete
All data must be present, including repeat analyses, reprocessing, invalidated results, and any data from failed or aborted runs. There should be no gaps that could hide a problem.
The classic failure is “testing into compliance”: running a sample repeatedly until an acceptable result appears, then reporting only that one. A complete record includes every injection, every test, and the justification for any result not reported. Audit trails must be enabled and reviewed so that deletions and modifications are visible. Incomplete data creates the impression that the truth is being selectively presented, even when it is not.
7. Consistent
Data should be recorded in a logical, chronological, and standardised way. Dates and times should follow the same format, sequences of events should make sense, and the same information should agree across records.
For example, a batch record should not show a sample being tested before it was collected, and the time on a chromatogram should not conflict with the time in the logbook. Consistency also covers the use of standard units, approved templates, and controlled terminology. Inconsistencies are often the first clue an inspector follows to uncover deeper problems, so a consistent record set builds confidence.
8. Enduring
Data must be recorded on durable media and preserved for the entire required retention period, often many years beyond product expiry. Regulations specify the period, and it can be long for batch records and stability data.
For paper, this means bound notebooks with numbered pages, quality paper, permanent ink, and controlled archives protected from fire, water, pests, and unauthorised access. For electronic data, it means validated backup and restore procedures, protection from obsolescence, and migration plans when systems change. Storing critical data only on a local hard drive or a removable USB stick is a serious risk. Data that cannot outlive the system that created it is not enduring.
9. Available
Data must be accessible for review, audit, and inspection throughout its retention period. It must be possible to retrieve records promptly, in a readable form, along with the metadata and audit trails that give them context.
Availability is tested every time an inspector asks for a record. If the organisation cannot find a record, cannot open an old file format, or cannot restore archived data, inspectors may conclude that it does not control its data. Good indexing, archive management, and periodic retrieval tests help ensure that data is not merely stored but can be found.
10. Traceable (ALCOA++)
Some guidance adds Traceable, meaning the full history of the data, including every change, can be reconstructed. Audit trails, version control, and change control records make it possible to see what was changed, by whom, when, and why, without obscuring the original value.
Putting ALCOA+ into Practice
Applying these principles involves more than a training slide. It requires integrated controls across procedures, systems, and behaviours.
Paper-based records
- Use controlled, numbered, pre-issued forms and bound notebooks, with reconciliation of issued and returned pages.
- Require permanent ink, single-line corrections with date, initials, and reason, and no use of correction fluid.
- Maintain signature and initials registers.
- Ensure blank forms are controlled so nobody can reprint and replace a page.
- Review and approve records promptly through an independent second person.
Electronic systems
- Validate computerised systems for their intended use, following the principles of EU GMP Annex 11, 21 CFR Part 11, and GAMP 5.
- Assign unique user IDs and role-based access, separating administrator rights from operational rights so that analysts cannot alter settings, delete data, or change the system clock.
- Enable audit trails and review them as part of routine data review, not only during investigations.
- Control data processing and reprocessing through written procedures, with justification recorded.
- Establish backup, disaster recovery, and archiving processes, and test them.
Hybrid systems
Hybrid systems, where an instrument generates electronic data but the record is a signed paper printout, are especially risky. Regulators expect the paper and electronic components to be linked and both controlled. Organisations should define which one is the raw data, ensure complete printouts are attached, and retain the electronic files. In many cases, moving to fully electronic workflows reduces risk.
Data review
A data review that looks only at the final result is not enough. Reviewers should examine the raw data, the metadata, and the audit trail, asking whether the sequence of events is logical and whether any injections, tests, or results are missing. This is where the Complete, Consistent, and Traceable principles are verified.
Common Data Integrity Failures
Inspection reports and warning letters from regulators around the world repeatedly highlight similar patterns:
- Shared logins and poor access control on laboratory instruments.
- Deleted or overwritten data, including files moved to hidden folders or sample injections performed and never reported.
- Testing into compliance, such as unjustified repeat testing or reprocessing until a passing result appears.
- Backdating or pre-dating entries, and recording activities that did not occur when stated.
- Disabled audit trails, or audit trails that exist but are never reviewed.
- Unvalidated spreadsheets and unlocked calculation templates.
- Uncontrolled paper records, including unofficial notebooks, scrap paper, and loose sheets.
- Inadequate investigation of out-of-specification results, with results invalidated without scientific justification.
Most of these are preventable. They often originate in production pressure, unrealistic timelines, limited resources, or a fear of reporting bad news, and these are organisational issues as much as technical ones.
Building a Culture of Data Integrity
Systems and procedures are necessary, but they are not sufficient. The FDA, MHRA, and WHO all stress the role of quality culture and management responsibility.
Leadership sets the tone. When senior managers reward speed above all else or react badly to deviations, staff learn that hiding problems is safer than reporting them. When leaders respond to errors with curiosity and correction instead of blame, people report them early, and that protects patients.
Training must be practical. Staff should understand why each principle exists, not only what the procedure says. Case studies from real inspection findings make ALCOA+ concrete and memorable.
Processes should be designed to be right. If the compliant way of working is slow or awkward, people will look for shortcuts. Good design, such as placing documents and instruments near each other, using validated electronic systems that enforce workflow, and setting realistic schedules, makes the right way the easy way.
Risk-based oversight helps. Data governance should focus effort where the risk to patient safety and product quality is highest, using periodic reviews, self-inspections, and metrics to detect problems before an inspector does.
Speaking up must be safe. Clear channels for raising concerns, protection for those who report, and prompt, fair follow-up are hallmarks of a mature data integrity programme.
Conclusion
ALCOA+ is a practical checklist for asking whether data can be trusted. Attributable, Legible, Contemporaneous, Original, and Accurate establish the basics of a good record. Complete, Consistent, Enduring, and Available ensure the record is whole, coherent, and usable for as long as it is needed, and Traceable completes the history.
Data integrity is ultimately about people making honest, careful decisions in systems designed to support them. Regulators have made clear that they expect companies to understand their data lifecycle, control it, and be able to demonstrate that control. Organisations that embed ALCOA+ in their procedures, technology, and culture will be better prepared for inspections, and more importantly, will be able to assure patients that the medicines they take are supported by truthful, reliable evidence.
Guideline References
- MHRA (UK). ‘GXP’ Data Integrity Guidance and Definitions. Medicines and Healthcare products Regulatory Agency, Revision 1, March 2018.
- U.S. FDA. Data Integrity and Compliance With Drug CGMP: Questions and Answers – Guidance for Industry. December 2018.
- WHO. Guidance on Good Data and Record Management Practices. WHO Technical Report Series No. 996, Annex 5, 2016.
- PIC/S. Good Practices for Data Management and Integrity in Regulated GMP/GDP Environments (PI 041-1). Pharmaceutical Inspection Co-operation Scheme, July 2021.
- European Commission. EudraLex Volume 4, EU GMP Guidelines, Annex 11: Computerised Systems.
- European Commission. EudraLex Volume 4, EU GMP Guidelines, Chapter 4: Documentation.
- U.S. FDA. 21 CFR Part 11: Electronic Records; Electronic Signatures, and 21 CFR Parts 210 and 211: Current Good Manufacturing Practice.
- ISPE. GAMP 5 Guide: A Risk-Based Approach to Compliant GxP Computerized Systems (Second Edition), 2022.
- OECD. Advisory Document of the Working Group on GLP: Application of GLP Principles to Computerised Systems, OECD Series on Principles of GLP and Compliance Monitoring, No. 17.