Data Integrity and ALCOA+: Turning Audit Trail Review into a Real Control

Data integrity findings rarely arise because a company set out to falsify anything. They arise because nobody was looking. A system generates an audit trail, the audit trail records every change, and for three years no one reads it. When an inspector does, the history is all there — including the parts you would have wanted to know about first.

ALCOA+ in plain terms

PIC/S guidance PI 041-1, adopted in 2021, sets out the framework most EU inspectors work from. Data must be Attributable, Legible, Contemporaneous, Original and Accurate, with four further attributes added: Complete, Consistent, Enduring and Available. The principles apply to every format — paper, electronic, hybrid, chromatograms, photographs — and they apply to metadata as much as to the result itself.

Two of the nine attributes cause most of the trouble in practice. Attributable collapses the moment a shared login exists. Contemporaneous collapses the moment results are recorded on scrap paper and transcribed later.

Why audit trail review is the pivot point

An audit trail that exists but is never reviewed provides evidence against you and assurance to nobody. Regulators have been consistent on this: the control is not the trail, it is the review. The review has to be routine, documented, and performed by someone with the standing to act on what they find.

A workable programme answers four questions:

  • What gets reviewed? Not everything. Focus on changes to critical data and metadata — results, integration parameters, sample sequences, date and time settings, user privileges.
  • How often? Review tied to the release decision for batch-critical data; a periodic cycle for system-level events such as privilege changes and failed logins.
  • By whom? Someone independent of the person who generated the data. Reviewing your own audit trail is not a control.
  • What happens then? A defined route into the deviation and CAPA system, so that an anomaly produces an investigation rather than a shrug.

The structural problems that create findings

Most data integrity gaps are architectural rather than behavioural, which is why training alone never closes them:

  • Generic or shared accounts, still common on standalone laboratory instruments
  • Analysts holding administrator rights on the systems that hold their own data
  • Audit trail functionality present but disabled, or configurable by users
  • Hybrid systems where a signed paper printout is treated as the record while the electronic original goes unmanaged
  • Local data stored on an instrument PC that is never backed up
  • System clocks that individual users can change

None of these require intent to cause a critical finding. They simply make it impossible to demonstrate that the record is complete.

What is coming next

The draft revision of EU GMP Annex 11, published for consultation by EMA and PIC/S on 7 July 2025 alongside a revised Chapter 4 on documentation and a new Annex 22 on artificial intelligence, strengthens expectations considerably on audit trails, identity and access management and supplier oversight, and introduces cybersecurity as an explicit GMP concern. Final texts are expected from mid-2026. Companies still relying on informal, undocumented review practices have a limited window to formalise them.

How PQRA helps

PQRA conducts data integrity gap assessments across GMP, GDP, GCP and pharmacovigilance environments: system inventories, ALCOA+ assessment of critical data flows, design of risk-based audit trail review programmes, remediation planning for legacy instruments and hybrid records, and preparation for inspection questioning on these topics.

If you want to know what your audit trails would show an inspector before an inspector reads them, talk to PQRA.

CATEGORIES:

Uncategorized

Tags:

No responses yet

Leave a Reply

Your email address will not be published. Required fields are marked *