Build governance around data risk
Management should define ownership, escalation, resources and expectations for reliable records. A risk assessment should identify where data can be created, changed, deleted, excluded, reprocessed or reviewed without appropriate detection.
The assessment must include paper, hybrid and electronic workflows. Interfaces, temporary files, instrument local storage, spreadsheets, metadata and manual transcription are frequently overlooked.
Apply ALCOA+ through the record lifecycle
Records should be attributable, legible, contemporaneous, original and accurate, as well as complete, consistent, enduring and available. Controls must cover creation, processing, review, reporting, retention, retrieval and disposition.
Blank forms, worksheets and controlled templates require issuance and reconciliation. Electronic records require suitable access, audit trails, metadata retention, backup, restore testing and time controls.
Audit trails and review
Audit trails should be enabled where required, protected from ordinary users and capable of showing when, by whom and why critical records changed. Review procedures should define which trails are reviewed, by whom, at what point and how the review is documented.
A functioning audit trail is not enough if no one evaluates it. Review depth and frequency should follow the record’s quality and patient risk.
Investigate causes, not only individual errors
When unreliable data are found, assess product impact and determine the full scope across systems, methods, batches and time periods. Corrective action should address process design, incentives, training, workload, access and technical controls.
Sustainable remediation requires effectiveness checks and senior oversight. Repeating training without addressing weak workflows or uncontrolled privileges rarely prevents recurrence.
A defensible execution path
- 1Map critical data and failure modes
- 2Assess procedural and technical controls
- 3Remediate by patient and product risk
- 4Verify effectiveness and maintain oversight
Frequently asked questions
Does ALCOA+ apply only to electronic data?
No. The principles apply to paper, electronic and hybrid GxP records throughout their lifecycle.
Must every audit trail be reviewed for every record?
Review should be defined by the record’s risk and applicable requirements. Critical audit trails associated with data review and release decisions normally require documented review at an appropriate stage.
Is shared user access acceptable in a GxP system?
Shared credentials undermine attribution and accountability. Each user should normally have a unique identity with role-appropriate access, subject to documented exceptions and compensating controls where unavoidable.
Primary references
Use the current official publication and your applicable national requirements when approving a protocol or quality-system decision.
Need support applying this to your facility?
PHARPRO can scope the qualification, review your current documents or execute the work with your site team.
Explore the related service →