Usage Examples
- Audit trail review flagged three aborted injections that never appeared in the laboratory record.
- Shared logins on the HPLC break attributability, so that data cannot support a release decision.
- The 483 observation is a data integrity finding, not an out-of-specification result.
What is Data Integrity (DI)?
Data integrity is the property of regulated records being complete, consistent, and accurate across their full lifecycle, from first capture through retention, so a reviewer can reconstruct an activity without relying on the people who performed it.
Data integrity exists because an inspector cannot re-run the batch, re-inject the sample, or re-observe the study. The record is the only evidence that the work happened as described. When records are incomplete, back-dated, overwritten, or selectively reported, the regulator loses the ability to verify product quality, and every downstream conclusion built on that data becomes unsupportable.
Data integrity covers the full lifecycle of any GxP record: generation, processing, review, reporting, retention, and retrieval, in paper, electronic, and hybrid form, including the metadata and audit trails that give a result its meaning. Data integrity is not itself a regulation and not a property of software; it is an attribute of records. Vendors selling "data integrity compliance" are selling controls.
Data integrity is applied through four routine controls: unique user accounts with role-based privileges so every action stays attributable, audit trails that are switched on and actually reviewed, second-person review of the underlying data rather than only the summary report, and retention that keeps records readable and retrievable at the site for the full period. Each maps to an existing CGMP or Part 11 obligation.
Not to be confused with
- 21 CFR Part 11
- Part 11 sets the controls for electronic records and signatures; data integrity is the outcome those controls exist to protect. A validated, Part 11 conformant system holding unreviewed or incomplete data still fails on data integrity.
- Data quality
- data quality asks whether a result is fit for purpose: precise, within specification, scientifically sound. Data integrity asks whether the record of that result is complete, attributable, and unaltered. An accurate result captured on an unattributed scrap of paper is a data integrity failure, not a quality one.
- ALCOA+
- ALCOA+ is a mnemonic for the attributes records must have, not an enforceable rule. No observation is written against ALCOA+ itself; inspectors cite the underlying CGMP or Part 11 section that the missing attribute breaches.
- Computer system validation
- validation proves a system performs as intended at a point in time. Data integrity concerns what people do with the system afterwards. Fully validated systems still generate findings through shared logins and disabled audit trails.
Data integrity is not written as a standalone rule. These are the obligations inspectors actually cite.
What you must do
- 1Review and approve every production and control record against the approved written procedures before a batch is released, and thoroughly investigate any unexplained discrepancy whether or not the batch has already shipped21 CFR 211.192
- 2Keep laboratory records containing complete data from all tests, including failing, aborted, and repeated runs, not only the results you intend to report21 CFR 211.194(a)
- 3Generate secure, computer-generated, time-stamped audit trails that independently record the date and time of operator entries and actions creating, modifying, or deleting electronic records21 CFR 11.10(e)
- 4Maintain a backup file of data entered into computerised systems, except where the data is eliminated by the automated process itself21 CFR 211.68(b)
- 5Keep records readily available for authorised inspection throughout the retention period, at the establishment where the activity occurred21 CFR 211.180(c)
Common mistakes
Scoping data integrity to computerised systems only
Paper batch records, laboratory notebooks, and printed chromatograms carry the same obligations. 21 CFR 211.192 and 211.194(a) are medium-neutral, so a programme built around Part 11 alone leaves most of a small company's records uncontrolled and the gap surfaces in the first CGMP inspection.
Enabling audit trails but never reviewing them
An audit trail nobody reads detects nothing. The reviewable control is the review itself, and a QA release signature on a batch whose audit trail shows repeated aborted runs documents a failure to investigate an unexplained discrepancy, in writing, with a date on it.
Sharing system logins across an analytical team
Shared accounts destroy attributability at the point of capture, and no downstream review can reconstruct who ran what. Part 11 requires system access limited to authorised individuals and audit trails that record operator entries; one shared credential defeats both, and remediation means re-testing, not re-training.
When This Matters
- Audit trail review flagged three aborted injections that never appeared in the laboratory record.
- Shared logins on the HPLC break attributability, so that data cannot support a release decision.
- The 483 observation is a data integrity finding, not an out-of-specification result.
Frequently Asked Questions
ALCOA+ is the attribute checklist used to test records: attributable, legible, contemporaneous, original, and accurate, plus complete, consistent, enduring, and available. The original five come from ALCOA; the plus four were added by later international guidance. Both describe attributes, not a regulation you comply with. Inspectors cite the underlying regulation, not ALCOA.
Related Use Cases
- Pharma Use Cases
Cut NDA and sNDA prep time by 60% with AI-assisted drafting and automated readiness checks
- Biotech Use Cases
Compress IND prep from 8-12 weeks to under 3 weeks with AI-assisted drafting and validation
- Regulatory Affairs Workflows
Cut regulatory intelligence tracking from 10+ hours/week to automated, real-time alerts
- Quality/QA Workflows
Track GxP regulation changes and enforcement trends

