Data integrity in pharma: ALCOA+ and the case for digital records
In regulated pharmaceutical manufacturing, the record is as important as the product. A batch may have been manufactured flawlessly, but if the documentation cannot prove it, regulators will treat it as suspect. That is not a theoretical concern: data integrity observations appear consistently among the most cited deficiencies in FDA warning letters and MHRA inspection reports, spanning everything from misattributed entries to audit trails that had been disabled. The problem is not unique to any facility size or geography; it turns up in large multi-site manufacturers and small-molecule specialists alike.
The expectations are clearly set out in three key documents: the FDA’s guidance on Data Integrity and Compliance with Drug CGMP, the FDA’s regulation on electronic records and electronic signatures (21 CFR Part 11), and the MHRA’s GXP Data Integrity guidance. All three converge on the same requirement: records must be complete and trustworthy from the moment of creation through their entire retention period.
What ALCOA+ actually means
Regulators summarise the attributes of good data with the acronym ALCOA, first formalised by the FDA and since adopted across GxP frameworks worldwide. Each letter defines a distinct property that a record must satisfy:
- Attributable. The record identifies who performed or reviewed the action, and when. A shared login, an unsigned entry, or a batch record initialled by a supervisor rather than the operator who performed the step all fail this criterion.
- Legible. The data is readable and permanent. A smudged ink entry, pencil marks that can be erased, or a scanned image so degraded it cannot be read all represent failures of legibility.
- Contemporaneous. The record is created at the time the activity occurs, not reconstructed afterwards. This is one of the most frequently violated principles in practice: an operator finishes a series of steps and then fills in timestamps that are nominally “correct” but do not reflect when each step actually happened.
- Original. The first capture of the data is retained. Where a transcription is made from a rough note or a printer log, the original must also be kept. A recopied entry that discards the source is not original.
- Accurate. The value recorded reflects what actually occurred. Rounded readings, values copied from adjacent cells in a spreadsheet, or results back-calculated to fit a specification are all accuracy failures.
The “+” appended by later guidance (including the MHRA’s framework) adds four further attributes. Records should be Complete, containing all relevant data including any reprocessing or out-of-specification results. They should be Consistent, with internal dates and sequences that do not contradict each other. They must be Enduring, stored in a medium that persists for the required retention period without degradation. And they must be Available for review on request, which means both accessible and retrievable within a reasonable timeframe.
How paper batch records fail in ordinary conditions
It is tempting to frame data integrity failures as fraud. Some are. But the majority of observations regulators issue stem from ordinary operational pressure: a production line running close to deadline, an operator managing several tasks simultaneously, or a paper batch record system that was designed for a lower throughput than the facility now runs at.
Paper records are particularly vulnerable to non-contemporaneous entry. An operator performing ten sequential checks over an hour may record all ten at the shift’s end, filling in plausible-looking timestamps from memory. The data may be accurate in substance but it fails contemporaneity. There is no reliable way to verify the order of events after the fact.
Attribution is similarly fragile. Batch records that pass through several hands in a shift often carry the final countersignature but lack clear evidence of who performed each individual step. When audit questions arise, facilities must rely on shift schedules and supervisor recollection rather than direct evidence.
Transcription errors add a further layer of risk. When process data is recorded first on a printer tape, a pH meter readout strip, or an instrument log, and then transferred to the batch record by hand, each transcription step is an opportunity for the record to diverge from the original. Even when the transcription is honest, it is no longer original in the ALCOA+ sense.
The regulatory backdrop: 21 CFR Part 11 and MHRA GXP
21 CFR Part 11 sets out the technical and procedural controls that electronic records and signatures must satisfy to be accepted in place of paper by the FDA. The requirements cover audit trails that capture the date and time of operator entries and any changes to those entries, system controls that prevent deletion of records, and electronic signatures that are linked to the specific individual and cannot be transferred. A system that meets Part 11 does not automatically achieve ALCOA+, but a system that achieves ALCOA+ in a GxP context generally must meet Part 11 if it uses electronic records.
The MHRA’s GXP Data Integrity guidance takes a risk-based approach, applying to both paper and electronic systems and asking facilities to demonstrate that their control environment makes it difficult for data integrity failures to occur undetected. It explicitly addresses hybrid systems, where paper originals are supplemented by electronic audit logs, and flags these as areas of particular attention because the original may be altered before scanning.
Both frameworks are explicit that intent to deceive is not a prerequisite for a data integrity citation. A system that makes accidental non-contemporaneous entry easy, or that lacks controls to detect it, is a data integrity risk regardless of operator intent.
Where digital execution changes the equation
Digital execution systems address ALCOA+ not by auditing records after the fact but by making compliant records the default output of doing the work. When a procedure runs step by step on a device and each step must be completed and verified before the next unlocks, contemporaneity is enforced structurally. The timestamp is captured by the system at the moment of action, not entered by the operator afterwards.
Attribution is handled by access controls: the operator who is logged in at the time of execution is recorded as the actor. Shared credentials, a chronic weakness in paper environments, are eliminated if the access policy requires individual authentication at each step.
Original data capture is straightforward for instrument readings that are pushed directly to the execution record rather than printed and transcribed. For steps that require human observation, the digital entry is itself the original, with no intermediary paper note that could diverge.
However, digital records only improve data integrity if the system meets the requirements of 21 CFR Part 11 and equivalent frameworks. That means validated software (developed or assessed under GAMP 5 principles, which categorise software by complexity and risk), role-based access controls, time-synchronised audit trails that are secure from modification, and a backup and recovery plan that satisfies the “enduring and available” requirements of ALCOA+. A digital system that lacks these controls does not solve the data integrity problem; it moves it into a new medium where it may be harder to detect. Computer System Validation (CSV) is not optional overhead; it is the mechanism by which a facility demonstrates to regulators that the electronic system is fit for its intended use.
Data integrity will remain a primary focus of GxP inspections for the foreseeable future, not because regulators are applying new standards but because the gap between what the standards require and what manual systems reliably deliver is wide in practice. Facilities that close that gap by design, through validated digital execution with enforced contemporaneity and individual attribution, are better positioned for routine surveillance inspections and better able to investigate deviations with confidence in the underlying record. That is increasingly the benchmark regulators expect, and the direction in which the industry is moving.
What is ALCOA+ and why does it matter in pharmaceutical manufacturing?
ALCOA+ is the regulatory standard for trustworthy GxP data: Attributable, Legible, Contemporaneous, Original, and Accurate, extended by Complete, Consistent, Enduring, and Available. It matters because regulators treat records as evidence that manufacturing steps were performed correctly. A batch that cannot be supported by ALCOA+-compliant documentation is a regulatory liability regardless of the product’s physical quality.
Why are data integrity observations so common even in well-run facilities?
Most data integrity failures are not fraudulent. They arise from ordinary operational pressures: operators recording multiple steps at once rather than one at a time, shared logins on shared workstations, or transcription errors when copying instrument printouts into a batch record. Paper-based systems make these failures easy to commit and difficult to detect. The regulatory expectation is that the control environment makes them hard, not just prohibited.
What is the relationship between 21 CFR Part 11 and ALCOA+?
21 CFR Part 11 specifies the technical and procedural requirements that electronic records and signatures must meet to be accepted by the FDA in place of paper equivalents. ALCOA+ is the broader standard for data quality that applies to both paper and electronic records. A system can meet Part 11 technically without fully achieving ALCOA+ if, for example, the audit trail is intact but entries are not being made contemporaneously. Both frameworks need to be addressed together.
What does “validated” mean in the context of digital execution systems?
Validation, governed in this context by the GAMP 5 framework and regulatory expectations for Computer System Validation (CSV), is the documented process of demonstrating that a software system consistently performs its intended function within defined parameters. For a digital execution system, this means showing that access controls, audit trails, data retention, and step sequencing all work as specified and cannot be bypassed. Without validation, a regulator has no basis to trust that the electronic records the system produces are reliable.
See a connected worker platform in action
Treedis turns your site into a digital twin, with every procedure, work order, and live reading pinned to the asset it belongs to.
Book a demo