G-PDR8S3N2ZG
top of page

Top Data Integrity (ALCOA+) Reference Guides


Data integrity sits at the center of every Good Practice (GxP) activity. Whether you work in pharmaceutical manufacturing, clinical research, laboratories, or medical devices, the reliability of your data determines whether decisions about product quality, patient safety, and regulatory compliance can be trusted.

The good news is that regulators and industry bodies have done a lot of the heavy lifting already. Several agencies have published detailed, practical guidance on ALCOA+ principles, and many of these documents explicitly reference one another, which means they largely agree on the fundamentals even as each brings its own regional or sector-specific detail.


Here are six reference guides worth bookmarking if data integrity is part of your quality system.


What does ALCOA+ mean?


ALCOA+ is the acronym regulators use to describe the attributes that trustworthy data should have throughout its lifecycle. The core ALCOA principles, consistently defined across FDA, MHRA, WHO, OECD, and PIC/S guidance, are:

  • Attributable – traceable to the person (or system) that generated it

  • Legible – readable and permanent

  • Contemporaneous – recorded at the time the activity took place

  • Original – the first record, or a verified true copy

  • Accurate – free from error, reflecting what actually happened

The "+" adds four further expectations that data governance systems should maintain throughout the data lifecycle:

  • Complete – the full data set, nothing omitted

  • Consistent – free from contradiction across records

  • Enduring – retained and readable for as long as required

  • Available – accessible for review or inspection when needed

Every source below builds on this same foundation. Where they differ is in the level of detail, the regulatory sector they focus on (GMP, GLP, GCP, and so on), and how they translate these principles into day-to-day practice.


1. FDA – Data Integrity and Compliance With Drug CGMP: Questions and Answers

Published in December 2018 by the FDA's Center for Drug Evaluation and Research, Center for Biologics Evaluation and Research, and Center for Veterinary Medicine, this Q&A-style guidance walks through core concepts like metadata, audit trails, backup requirements, and electronic signatures in the context of CGMP for drugs, including biologics.


2. MHRA – Guidance on GxP Data Integrity

The UK's Medicines and Healthcare products Regulatory Agency published this guidance in March 2018 and updated it in September 2021. It covers data governance, computerized system transactions, audit trails, electronic signatures, and data retention across GLP, GCP, GMP, GDP, and GPvP.


One nuance worth knowing: for Good Laboratory Practice specifically, the OECD's 2021 Advisory Document on GLP Data Integrity now takes precedence over this MHRA guidance, due to the UK's membership in the OECD's Mutual Acceptance of Data system. The MHRA document remains a strong resource for Good Clinical Practice (GCP), Good Manufacturing Practice (GMP), Good Distribution Practice (GDP), and Good Pharmacovigilance Practice (GPvP) contexts.



3. OECD – Advisory Document on GLP Data Integrity

Issued in September 2021 as Number 22 in the OECD Series on Principles of Good Laboratory Practice and Compliance Monitoring, this document is the current authority on data integrity specifically within GLP environments. It covers data governance, computerized system transactions, audit trails, and access controls in detail, and should be read alongside OECD Documents No. 1, 15, 16, and 17 for fuller context on GLP principles and computerized systems.



4. WHO – Guideline on Data Integrity

Published in 2021 as Annex 4 of WHO Technical Report Series No. 1033, this guideline replaced WHO's earlier 2016 guidance and explicitly adopts ALCOA+ terminology throughout. It covers data governance, quality risk management, good documentation practices, and computerized systems, with a scope that extends across GMP, GCP, GLP, and Good Trade and Distribution Practices.



5. PIC/S – Good Practices for Data Management and Integrity in Regulated GMP/GDP Environments

This is the finalized version (PI 041-1) from the Pharmaceutical Inspection Co-operation Scheme, adopted in June 2021 and in force since July 2021. It offers detailed, practical guidance for both paper-based and computerized systems, including sections on outsourced activities and how regulators classify and respond to data integrity deficiencies during inspections.



6. ISPE – GAMP RDI Good Practice Guide: Data Integrity — Key Concepts

Published by ISPE in October 2018, this 196-page guide is the one entry on this list that is not free. It requires ISPE membership or purchase. That said, it's one of the most respected industry-standard references for translating data integrity principles into practical implementation, particularly for computerized systems.




A note on how these fit together: five of these six documents are free, and several explicitly cross-reference one another. WHO's 2021 guideline cites both the FDA and MHRA documents as sources it harmonized with, and the OECD document is designed to be read alongside other OECD GLP guidance. This convergence is reassuring: it means the core ALCOA+ principles are consistently applied across major regulatory bodies, even as each document adds detail suited to its own regulatory context.


This list reflects publicly available guidance as of the time of this blog's writing. Regulatory documents are periodically revised, so readers working on a specific compliance project should confirm they are referencing the current version directly from the source.

Comments


bottom of page