Regulators decide whether a medicine is safe and effective largely by reviewing data: batch records, laboratory results, stability reports and equipment logs. If that data cannot be trusted, neither can the product. This is why data integrity has become a central focus of GMP inspections worldwide, and why a single serious finding can lead to warning letters, import restrictions or loss of certification.
The good news is that data integrity is not mysterious. It rests on a small set of clear principles, supported by sensible systems and, most importantly, a culture where people feel safe reporting problems.
What Regulators Mean by Data Integrity
Data integrity means that data is complete, consistent and accurate throughout its lifecycle, from the moment it is created to the moment it is archived or destroyed. Key references include the WHO guideline on data integrity, PIC/S guidance on good practices for data management and integrity in regulated GMP and GDP environments, EU GMP Annex 11 on computerised systems, and US 21 CFR Part 11 on electronic records and signatures.
The ALCOA+ Principles
| Principle | What it means in practice |
|---|---|
| Attributable | Every entry shows who performed the action and when |
| Legible | Records are readable and permanent throughout retention |
| Contemporaneous | Data is recorded at the time the activity is performed |
| Original | The first capture of data, or a verified true copy, is retained |
| Accurate | Data correctly reflects what happened, with no unrecorded edits |
| Complete | All data including repeats, reruns and failures is kept |
| Consistent | Sequence and time stamps follow a logical order |
| Enduring | Records survive for the full retention period |
| Available | Data can be retrieved for review and inspection when needed |
Common Data Integrity Failures Seen in Inspections
- Shared login credentials on laboratory instruments and software
- Audit trails disabled, not reviewed or not available
- Trial or “test” injections on chromatography systems that are not reported
- Results recorded on loose paper or scrap notes and transcribed later
- Back dating or pre filling of batch record entries
- Deleted or overwritten electronic files without justification
- Uncontrolled blank forms that allow records to be rewritten
- Out of specification results invalidated without a proper investigation
Most data integrity problems are not caused by bad people. They are caused by pressure, poor system design and a culture where bad news travels slowly.
A Practical Roadmap to Strong Data Integrity
1. Assess the Current State
Map every GMP data flow, paper and electronic, from creation to archive. Identify which systems generate critical data and where the risks lie.
2. Fix Computerised Systems
- Assign unique user IDs and role based access; remove shared and generic accounts
- Enable and protect audit trails so they cannot be switched off by users
- Synchronise system clocks and restrict date and time changes
- Validate systems and set up secure, tested backup and restore
3. Control Paper Records
- Issue numbered, controlled forms and reconcile them after use
- Follow good documentation practice: permanent ink, single line corrections with reason, initials and date
- Remove uncontrolled notebooks and loose sheets from GMP areas
4. Review Data, Not Just Results
Second person review should include audit trails and metadata for critical tests, not only the final printed report. Define which audit trail entries must be reviewed and how often.
5. Build the Right Culture
Leadership must make it safe to report errors and failures. Train staff on why data integrity matters, reward transparency and ensure that production targets never outweigh honest reporting.
6. Monitor and Improve
Include data integrity in internal audits, track metrics such as audit trail review completion and repeat deviations, and run periodic mock inspections focused on data.
Preparing for a Data Focused Inspection
- Prepare an inventory of computerised systems with validation status.
- Be ready to demonstrate audit trails live on laboratory systems.
- Ensure that all raw data for recent batches can be retrieved quickly.
- Brief analysts and supervisors on how to answer questions openly.
- Close out previous data integrity CAPAs with evidence of effectiveness.
Risk Based Prioritisation
Not every system carries the same data integrity risk. Prioritise systems that generate data used for batch release, stability and regulatory submissions, such as chromatography data systems, dissolution testers, balances connected to software, environmental monitoring and manufacturing execution systems. Assess each system for access control, audit trail capability, data storage and backup, then remediate the highest risks first.
For legacy standalone instruments that cannot generate compliant audit trails, consider interim controls such as controlled logbooks, printouts attached to records and restricted access, while planning upgrades or replacement.
Metrics That Show Progress
- Percentage of critical systems with unique user access and active audit trails
- Audit trail reviews completed on time
- Number of data related deviations and repeat findings
- Training completion for data integrity and good documentation practice
Sharing these metrics in management review keeps data integrity visible at leadership level and demonstrates to inspectors that the organisation is actively managing the topic.
Handling Data Integrity Findings Honestly
If an internal review uncovers a data integrity problem, the response matters as much as the finding. Investigate the scope thoroughly, determine the root cause, assess the impact on product quality and previously released batches, and implement corrective and preventive actions. Where products or submissions may be affected, involve senior management and consider whether regulators need to be informed. Inspectors consistently view transparent, well documented remediation far more favourably than issues discovered during an inspection that were known but not addressed.
Document lessons learned and share them across sites so that the same weakness is fixed everywhere, not just where it was found.
Quick Self Check
- Can every critical record be traced to a named individual and time?
- Are audit trails switched on, protected and reviewed?
- Are all results, including failures and repeats, retained and visible?
- Would staff feel safe reporting a mistake to their supervisor today?
If any answer is uncertain, that area is the right place to start improving.
Data integrity is achieved through three layers working together: systems that make it hard to do the wrong thing, procedures that make the right thing routine, and a culture that makes honesty the norm.
How Zanax Healthcare Supports Your Compliance Journey
Our regulatory and quality specialists carry out data integrity gap assessments, computerised system reviews, staff training and mock inspections aligned to WHO, PIC/S and EU expectations. Talk to us before your next inspection.
