QA · Data Integrity

GMP Data Integrity Requirements: What Pharmaceutical Sites Must Control

Data integrity is the ability to trust that GxP records are complete, consistent and accurate throughout their lifecycle. It depends on governance, process design, system controls and management behaviour—not on a single SOP or software feature.

By Mohammad Awawdeh · Published and reviewed 24 August 2026

Build governance around data risk

Management should define ownership, escalation, resources and expectations for reliable records. A risk assessment should identify where data can be created, changed, deleted, excluded, reprocessed or reviewed without appropriate detection.

The assessment must include paper, hybrid and electronic workflows. Interfaces, temporary files, instrument local storage, spreadsheets, metadata and manual transcription are frequently overlooked.

Apply ALCOA+ through the record lifecycle

Records should be attributable, legible, contemporaneous, original and accurate, as well as complete, consistent, enduring and available. Controls must cover creation, processing, review, reporting, retention, retrieval and disposition.

Blank forms, worksheets and controlled templates require issuance and reconciliation. Electronic records require suitable access, audit trails, metadata retention, backup, restore testing and time controls.

Audit trails and review

Audit trails should be enabled where required, protected from ordinary users and capable of showing when, by whom and why critical records changed. Review procedures should define which trails are reviewed, by whom, at what point and how the review is documented.

A functioning audit trail is not enough if no one evaluates it. Review depth and frequency should follow the record’s quality and patient risk.

Investigate causes, not only individual errors

When unreliable data are found, assess product impact and determine the full scope across systems, methods, batches and time periods. Corrective action should address process design, incentives, training, workload, access and technical controls.

Sustainable remediation requires effectiveness checks and senior oversight. Repeating training without addressing weak workflows or uncontrolled privileges rarely prevents recurrence.

A defensible execution path

  1. 1Map critical data and failure modes
  2. 2Assess procedural and technical controls
  3. 3Remediate by patient and product risk
  4. 4Verify effectiveness and maintain oversight

Frequently asked questions

Does ALCOA+ apply only to electronic data?

No. The principles apply to paper, electronic and hybrid GxP records throughout their lifecycle.

Must every audit trail be reviewed for every record?

Review should be defined by the record’s risk and applicable requirements. Critical audit trails associated with data review and release decisions normally require documented review at an appropriate stage.

Is shared user access acceptable in a GxP system?

Shared credentials undermine attribution and accountability. Each user should normally have a unique identity with role-appropriate access, subject to documented exceptions and compensating controls where unavoidable.

Primary references

Use the current official publication and your applicable national requirements when approving a protocol or quality-system decision.

Need support applying this to your facility?

PHARPRO can scope the qualification, review your current documents or execute the work with your site team.

Explore the related service →

Explore this topic

Quality Assurance & Inspection Readiness

Continue with the related practical guides or discuss your site-specific requirements with PHARPRO.

QA and GMP assessment services →