Written and maintained by CASRAI Editorial Board
Last updated
In December 2018, FDA finalized Data Integrity and Compliance With Drug CGMP: Questions and Answers — guidance from CDER, CBER, and CVM written, deliberately, as a running series of numbered questions rather than a single policy statement. Every page of it carries the standard “Contains Nonbinding Recommendations” header: the guidance does not create new legal obligations. What it does is explain how FDA reads the data-integrity expectations that were already embedded in 21 CFR Parts 210, 211, and 212 long before “data integrity” became its own inspection category. This guide works through what the document actually says, mapped back to the CFR sections it draws from, rather than repeating the ALCOA acronym without the regulatory teeth behind it.
If you landed here from a search for ALCOA+ or clinical-trial documentation practice, two adjacent CASRAI pages cover related ground and are worth reading alongside this one rather than instead of it: ALCOA+ (Clinical Trial Data Integrity Principles) explains the nine-attribute framework MHRA built on top of FDA’s original five, applied to GCP; Good Documentation Practices (GDP) in Clinical Trials applies much of the same underlying FDA thinking to trial source documents and CRFs. This page is the drug-manufacturing reading of the guidance — batch records, laboratory data, and audit trails under 21 CFR 211 and 212 — which is a different audience and a different set of records than either of those two pages covers.
What FDA’s Data Integrity Guidance Actually Is
The guidance is organized as a running set of numbered questions and answers — roughly eighteen of them — grouped loosely under the ALCOA attributes, metadata and audit trails, and data governance and behavior. It applies to firms that manufacture, process, pack, test, or hold human and animal drugs subject to CGMP, and to the CDER/CBER/CVM investigators who inspect them. FDA wrote it in direct response to a sharp rise in warning letters and Form 483 observations citing data manipulation, deletion, and unauthorized access during the mid-2010s — the document is best read as FDA making explicit the interpretive positions its investigators had already been applying in the field.
Two things the guidance is not: it is not itself a regulation (the binding requirements sit in 21 CFR 211 and, for positron emission tomography drugs, 212), and it is not limited to computer systems. Roughly half of its questions concern paper records — blank-form control, correction practice, notebook management — because data integrity failures in FDA’s own enforcement history are at least as often a paper problem as an electronic one.
FDA’s Definition of Data Integrity — and Why It’s ALCOA, Not ALCOA+
FDA’s own words: “data integrity refers to the completeness, consistency, and accuracy of data. Complete, consistent, and accurate data should be attributable, legible, contemporaneously recorded, original or a true copy, and accurate (ALCOA).” That is five attributes, and the guidance never uses the term “ALCOA+.” The four additional attributes many training decks tack on — Complete, Consistent, Enduring, Available — come from a different regulator entirely: MHRA’s GXP Data Integrity Guidance and Definitions (Revision 1, March 2018). Both documents describe the same underlying idea, but attributing “ALCOA+” to FDA in a submission or a training record is a citation error an inspector will notice.
For a manufacturing site operating under both FDA and MHRA (or another PIC/S-aligned) oversight, the practical answer is to build to the fuller ALCOA+ list — it is a superset — but to know, and cite correctly, which regulator said which part when a specific finding is being defended.
Where Each ALCOA Attribute Is Actually Written Into the CFR
The most useful single passage in the guidance is a footnote (footnote 5) that most summaries skip: it maps every ALCOA attribute to the specific CGMP sections that actually require it. That crosswalk is what turns “ALCOA is a framework” into “ALCOA is a citable requirement”:
| ALCOA attribute | Binding CFR sections FDA cites |
|---|---|
| Attributable | 211.101(d), 211.122, 211.186, 211.188(b)(11), 212.50(c)(10) |
| Legible | 211.180(e), 212.110(b) |
| Contemporaneously recorded | 211.100(b), 211.160(a) |
| Original or a true copy | 211.180, 211.194(a) |
| Accurate | 211.22(a), 211.68, 211.188, 212.60(g) |
That crosswalk is the practical answer to a question every new quality hire eventually asks: if ALCOA itself is guidance rather than regulation, what would an inspector actually cite? These sections, specifically.
Audit Trails: FDA’s Definition, and the Cross-Outs Analogy
FDA defines an audit trail as “a secure, computer-generated, time-stamped electronic record that allows for reconstruction of the course of events relating to the creation, modification, or deletion of an electronic record.” The single most useful sentence in the whole guidance for connecting electronic practice back to paper practice sits right next to that definition: “Audit trail review is similar to assessing cross-outs on paper when reviewing data.” An investigator who has spent a career reading initialed strike-throughs on batch records is being told, explicitly, to treat an electronic audit trail the same way — as the record of what changed, by whom, and (where the change is substantive) why.
For the underlying computer-system requirements an audit trail depends on — validation status, access controls, electronic signatures — see CASRAI’s 21 CFR Part 11: Electronic Records & Signatures and Computer System Validation (CSV): GAMP 5, IQ/OQ/PQ, and 21 CFR Part 11.
How Often — and By Whom — Audit Trails Actually Get Reviewed
The guidance does not create a new, separate audit-trail-review role. It ties audit trail review directly to whatever record-review requirement already exists for the underlying data. In practice that means two decision rules, both traceable to specific CFR sections:
- Frequency follows the underlying record. Where CGMP already prescribes a review cadence for the data itself, the audit trail is reviewed on that same cadence — after each significant manufacturing step under 211.188(b), or before batch release under 211.22. Where no cadence is prescribed for a given record type, the firm sets one from a risk assessment that weighs data criticality and the strength of the surrounding control mechanisms.
- The reviewer is whoever already reviews the record. Because the guidance frames audit trail review as an extension of ordinary record review — “similar to assessing cross-outs on paper” — it is performed by the same function that reviews the underlying batch, laboratory, or production record under the applicable CGMP requirement (for example, the second-person review already required under 211.188 or 211.194(a)(8)), at the same time as that review, rather than by a separately designated audit-trail specialist.
What this rules out: a system configured so no one reviews the audit trail unless something has already gone wrong. If the underlying record gets reviewed, its audit trail gets reviewed with it.
Metadata: The Context That Makes a Number Meaningful
A raw value — a weight, a pH reading, a peak area — is not itself a CGMP record; the metadata around it is what makes the value attributable, contemporaneous, and reconstructable in the first place. That metadata includes, at minimum: who generated the value and when, what instrument and software version produced it, the run or method parameters in effect, the sample or batch identifier it belongs to, and any calculation or processing applied before a final result was reported. Deleting or failing to retain that context — keeping only a final printed result while discarding the underlying electronic data file — is one of the specific failure patterns the guidance calls out, because a result without its metadata cannot be reconstructed or independently verified later, which defeats the point of keeping records at all.
Blank and Spoiled Forms — the Control Failure Inspectors Keep Finding
Paper practice gets its own extended treatment. FDA’s position on a form filled in incorrectly: “Incomplete or erroneous forms should be kept as part of the permanent record along with written justification for their replacement,” and more broadly, “all data required to recreate a CGMP activity should be maintained as part of the complete record.” A spoiled form does not get thrown away; it gets marked void, dated, initialed, and retained alongside whichever form replaced it.
The guidance also recommends two specific control practices that show up repeatedly in inspection findings when they’re absent: using bound, paginated notebooks stamped by document control — because gaps or unofficial pages are easy to detect in a bound, numbered notebook and very hard to detect in loose sheets — and issuing blank forms in numbered sets that are reconciled on completion, so a missing or extra form is itself a detectable event rather than an invisible one. The underlying CFR basis: 211.100, 211.160(a), 211.186, 211.192, 211.194, and, for PET drugs, 212.20(d), 212.50(a), and 212.60(g).
When CGMP Data May Be Excluded From a Decision — and What “Invalidated” Actually Requires
The guidance also addresses a narrower and higher-stakes question than a documentation correction: when can a piece of CGMP data be excluded from a decision entirely — treated as if it does not count? The standard is consistent with the rest of the document: exclusion is only defensible with a documented, scientifically sound justification, established through an investigation, not by unilateral judgment at the bench. A result cannot simply be discarded because it is inconvenient, and it cannot be invalidated on the strength of a second, passing measurement alone — “testing into compliance” by retesting until a result you like appears is precisely the pattern FDA investigators are trained to look for.
Where this becomes most concrete is an out-of-specification (OOS) laboratory result, which has its own dedicated investigation framework and its own body of FDA guidance beyond the data integrity Q&A — that mechanics-level procedure deserves its own treatment rather than a summary here. The point that belongs on this page is the standard the data integrity guidance itself sets: no CGMP result gets excluded from a decision without a documented, defensible reason that would hold up to someone reading the record after the fact with no other context. That is the practical form of “if it isn’t documented, it didn’t happen” — the standard is not just that the work has to have actually happened, but that a stranger reading only the record has to be able to reconstruct that it did.
From an Ordinary Documentation Error to a Data Integrity Finding
Not every mistake is a data integrity problem, and the guidance does not publish a bright-line threshold separating the two — no regulator does. What can be derived from the guidance’s own language, applied to a manufacturing record rather than a clinical one, is a working framework built around four questions: Can the event be reconstructed from what was retained (a corrected value with no date, author, or reason cannot)? Was the record truthful at the time it was made, even if later found wrong (an honest transcription error is not the same category of problem as a backdated entry)? Is this isolated or a pattern — one analyst, one instrument, one shift, or spread across the operation? And was it self-detected through the firm’s own review process, or found only by an outside inspector? A single, promptly corrected, properly documented error tends to stay a documentation error. Backdating, deleting a result rather than correcting it, or a pattern that recurs across multiple records or personnel is what escalates a finding from “fix the SOP” to “data integrity investigation.”
If FDA Does Find a Data Integrity Problem: What “Effectively Remediated” Means
The guidance sets a specific bar for what counts as an adequate response once a real data integrity problem is identified, whether by the firm itself or by FDA: the firm must demonstrate it has “effectively remediated” by “investigating to determine the problem’s scope and root causes, conducting a scientifically sound risk assessment of its potential effects (including impact on data used to support submissions to FDA), and implementing a management strategy, including a global corrective action plan that addresses the root causes.” Depending on severity, that response can include retaining a third-party auditor and removing individuals responsible for the lapse from positions where they can influence CGMP-related or application data — language that deliberately mirrors FDA’s Application Integrity Policy rather than an ordinary CAPA.
Who This Guidance Actually Governs
The guidance speaks directly to drug and biologic manufacturers, contract manufacturing organizations, and contract testing laboratories operating under 21 CFR 211 (human drugs) or 212 (PET drugs). It is not itself the governing document for medical device quality systems (21 CFR 820 / the QMSR) or for clinical trial conduct (ICH E6/GCP) — though, as the cross-links throughout this page show, its underlying ALCOA and audit-trail reasoning gets borrowed into both of those adjacent domains regularly, which is exactly why it is worth being precise about which document you are actually citing.
For the broader facility and quality-system context this guidance sits inside, see CASRAI’s cGMP Facility Requirements guide and the GMP vs. cGMP comparison; for the computerized-system side specifically, see Electronic Lab Notebook Validation Under 21 CFR Part 11 and GxP and, for sites also operating under EU GMP, EU Annex 11 vs. 21 CFR Part 11. This page’s cluster hub is CASRAI’s lab compliance pillar.
Frequently Asked Questions
Is FDA’s ALCOA the same thing as ALCOA+?
No. FDA’s December 2018 guidance defines data integrity around five attributes — Attributable, Legible, Contemporaneous, Original (or a true copy), Accurate — and never uses the term ALCOA+. The four additional attributes (Complete, Consistent, Enduring, Available) come from MHRA’s GXP Data Integrity Guidance. Both are worth building to; only one is FDA’s own language.
Does this guidance only apply to electronic records?
No. A substantial share of the guidance addresses paper practice directly — correction procedure, blank-form control, spoiled forms, notebook management — because paper-record failures are as common a finding as electronic ones in FDA’s own enforcement history.
Who is actually supposed to review audit trails, and how often?
The same function that already reviews the underlying batch, laboratory, or production record under CGMP, at the same frequency that record review already happens — typically after each significant step (211.188(b)) or before batch release (211.22). Where no cadence is prescribed, it is set from a risk assessment based on data criticality. FDA does not require a separate, dedicated audit-trail-only reviewer.
Can I throw away or reprint a form I made a mistake on?
No. FDA’s guidance expects an incomplete or erroneous form to be kept as part of the permanent record, marked void with a written justification, alongside whichever form replaced it — not discarded or reprinted as if the error never happened.
Can an out-of-specification result just be invalidated and retested?
Not on its own. Excluding any CGMP result from a decision requires a documented, scientifically sound investigation and justification. A second, passing result by itself is not sufficient grounds to invalidate the first — that pattern is exactly what FDA investigators are trained to look for.
Is this guidance legally binding?
No, not directly — it carries FDA’s standard “Contains Nonbinding Recommendations” header. What is binding is 21 CFR 211 (and 212 for PET drugs); the guidance is FDA’s explanation of how it reads those existing requirements, and inspectors apply it as the working interpretation in practice.








