Skip to main content
v2026.11,772 entries · CC-BY 4.0

What Is Data Integrity?

A plain-language guide to what data integrity means for regulated research and lab data, the ALCOA+ principles, and how it relates to data quality, security, and 21 CFR Part 11.

Ask CASRAI · included with Regulatory Radar

Ask about What Is Data Integrity?

Ask CASRAI answers research-administration questions and cites the passages behind every claim — and says so when the corpus does not cover something, instead of guessing. It comes with a Regulatory Radar subscription at $29 a month, alongside the daily digest of regulatory changes and the dashboard of what changed.

150 questions a day, on this site, over the API, or inside your own tools through the CASRAI MCP server.

Everything CASRAI publishes — this page, the dictionary, the guides and the news — stays free to read, with no account and no card.

Written and maintained by CASRAI Editorial Board

Last updated

In a regulated research or laboratory context, data integrity means that data is complete, consistent, and accurate throughout its entire lifecycle — from the moment it is first generated or captured, through every processing, transfer, review, and analysis step, to long-term retention and eventual disposition. It is not a single technical control. It is a property of the record: can a regulator, auditor, or another scientist trust that what they are looking at is the whole, original, unaltered story of what actually happened, generated by who it says generated it, when it says it was generated?

That question matters because regulatory and scientific decisions — a drug approval, a device clearance, a clinical trial conclusion, a published research finding — are only as trustworthy as the data underneath them. Paper and electronic records alike can be backdated, silently overwritten, selectively deleted, or fabricated outright. Data integrity is the set of principles and controls that make a record’s trustworthiness verifiable, rather than simply asserted.

Who Data Integrity Rules Apply To

Data integrity expectations reach any organization that generates, captures, or maintains data subject to regulatory scrutiny in the life sciences: pharmaceutical and biotech manufacturers, clinical trial sponsors, sites, and CROs, medical device makers, contract testing and analytical labs, and academic or institutional labs running FDA- or sponsor-regulated protocols. The underlying principles are useful more broadly — any research organization that wants its data to hold up to outside scrutiny benefits from the same discipline, even without direct FDA jurisdiction.

The ALCOA+ Principles

The most widely used framework for evaluating data integrity is ALCOA+. The original five attributes — Attributable, Legible, Contemporaneous, Original, Accurate — trace back to FDA’s own articulation in its CGMP-context guidance, Data Integrity and Compliance With Drug CGMP: Questions and Answers (draft 2016, finalized December 2018). The UK’s MHRA later published its own “GXP” Data Integrity Guidance and Definitions (Revision 1, March 2018), adding four more attributes — Complete, Consistent, Enduring, Available — giving the industry-wide “ALCOA+” acronym now used across GxP domains, including good clinical practice (GCP) trial data.

  • Attributable — it’s clear who (or what system) generated or changed the data, and when.
  • Legible — the record can be read and understood for as long as it needs to be retained.
  • Contemporaneous — recorded at the time the work was actually performed, not reconstructed later.
  • Original — the first, or a verified true copy of the first, capture of the data — the “source.”
  • Accurate — free of error, and reflecting what actually happened, with any correction itself traceable.
  • Complete — includes all data generated, including repeat or reanalysis results and any associated metadata.
  • Consistent — chronologically dated, sequenced, and internally coherent across related records.
  • Enduring — recorded and retained on a durable medium for the required retention period.
  • Available — retrievable and reviewable, including by regulators, throughout the retention period.

For the fuller operational definition, worked examples, and how each attribute gets assessed in practice, see the ALCOA+ dictionary term.

Why It Matters: Regulatory Scrutiny and Audit Trails

FDA and comparable regulators (MHRA, EMA, and others) treat data integrity failures as some of the most serious findings an inspection can surface — they call into question not just one result, but the reliability of an entire dataset or study. Consequences can include warning letters, import alerts, clinical holds, rejection of submitted study data, or invalidated batches, well beyond what a routine documentation gap would trigger.

The audit trail is the foundational control underneath most of ALCOA+: a timestamped, system-generated record of who created, modified, or deleted what, and when — one that cannot be turned off or edited by the user in a properly validated system. In the U.S., the regulatory backbone for electronic records and audit trails is 21 CFR Part 11, FDA’s electronic records and electronic signatures regulation, which sets validation, access-control, and audit-trail requirements for electronic systems used to create, modify, or store records that predicate rules (GMP, GLP, GCP) require. See the sibling guide, What Is 21 CFR Part 11?, for what the regulation actually requires and where it applies.

How Data Integrity Differs From Adjacent Concepts

“Data integrity” gets used loosely, which causes real confusion for anyone searching the term. A few distinctions worth being precise about:

Data integrity vs. data quality. Data quality is about whether a measurement or value is scientifically correct and fit for purpose. Data integrity is about whether the record of that value can be trusted — attributed, unaltered without trace, complete, and retrievable. A dataset can technically have accurate values entered into a system with no audit trail (high quality, weak integrity), or a rigorously audit-trailed record of a flawed measurement (strong integrity, poor quality). The two properties are related but not the same thing, and a compliance program needs both.

Data integrity vs. data security/cybersecurity. Security is about protecting data from unauthorized access, loss, or breach. Integrity overlaps with security — access controls are one of the ALCOA+ controls — but integrity is broader: it also covers internal falsification, backdating, and selective deletion by authorized users, not just outside threats.

Data integrity vs. 21 CFR Part 11 compliance. Part 11 is a specific FDA regulation governing electronic records and electronic signatures. It is one of the main regulatory mechanisms that operationalizes several ALCOA+ attributes (validation, audit trails, access limitation, record retrievability) for FDA-regulated electronic systems, but “data integrity” is the broader principle; Part 11 compliance is necessary, not sufficient, for genuine data integrity, and integrity expectations also apply to paper records and to GxP domains Part 11 does not directly cover.

It’s also worth flagging a pure naming collision: an RNA Integrity Number (RIN) is an unrelated molecular-biology sample-quality metric that happens to share the word “integrity” — it has nothing to do with record-keeping data integrity.

Existing CASRAI Coverage: Where to Go Deeper

This page is the broad, definitional starting point. For deeper, more specific coverage already live on this site:

Where the underlying system matters: a laboratory information management system (LIMS) is the informatics backbone most labs rely on to actually enforce data integrity day to day — attributing entries to users, timestamping them, generating audit trails, and controlling who can change what. Choosing and validating a LIMS is, in large part, a data-integrity decision.

Practical Relevance for Research Administration

For research-administration, quality assurance, and compliance staff, data integrity underlies a wide range of everyday trust: it’s what IRB/IACUC oversight and sponsor audits are ultimately checking when they review source documents, it’s the substance behind an FDA inspection’s data-integrity findings (including Form 483 observations), it shapes how a funder or IRB expects a data management plan to describe custody and change control, and it’s increasingly what journals and publishers mean when they ask whether underlying research data is available and unaltered. Getting the fundamentals right — attribution, contemporaneous recording, audit trails, retention — reduces risk across all of these simultaneously, rather than being a narrow FDA-only concern.

Frequently Asked Questions

What are the ALCOA+ principles?
ALCOA+ is a nine-attribute framework for evaluating data integrity: Attributable, Legible, Contemporaneous, Original, and Accurate (the original FDA “ALCOA” five), plus Complete, Consistent, Enduring, and Available (added by MHRA’s 2018 GXP Data Integrity Guidance). See the section above for what each attribute means in practice.

Is data integrity the same as data quality?
No. Data quality asks whether a value is scientifically correct; data integrity asks whether the record of that value can be trusted — attributed, unaltered without trace, complete, and retrievable throughout its lifecycle. A program needs both, but they are assessed differently.

Does 21 CFR Part 11 define data integrity?
Not directly. Part 11 is FDA’s regulation for electronic records and electronic signatures — it sets validation, audit-trail, and access-control requirements that operationalize several ALCOA+ attributes for electronic systems, but data integrity as a principle is broader and also applies to paper records and to GxP domains outside Part 11’s scope.

Does data integrity only apply to FDA-regulated pharmaceutical work?
The regulatory teeth are strongest in FDA- and MHRA-regulated pharmaceutical, device, and clinical-trial settings, but the same principles apply usefully to any lab or research organization that wants its records to withstand outside scrutiny — sponsor audits, journal data-availability checks, or internal quality review — even without direct FDA jurisdiction.

Follow CASRAI

Research-administration guidance, standards updates and independent tool reviews.

Referenced across the research world

University of Cambridge logoColumbia University logoCrossref logoUniversity of Edinburgh logoHarvard University logoUniversity of Oxford logoPrinceton University logoStanford School of Medicine logoUniversity College London logoORCID logoUniversity of Cambridge logoColumbia University logoCrossref logoUniversity of Edinburgh logoHarvard University logoUniversity of Oxford logoPrinceton University logoStanford School of Medicine logoUniversity College London logoORCID logo
  • University of Cambridge logo
  • Columbia University logo
  • Crossref logo
  • University of Edinburgh logo
  • Harvard University logo
  • University of Oxford logo
  • Princeton University logo
  • Stanford School of Medicine logo
  • University College London logo
  • ORCID logo

View CASRAI adoption →

Regulatory Radar

Stop finding out after the fact

$29/month, cancel anytime. Daily digest updates from our analysis, a dashboard holding the same items, and a cited assistant for everything they raise.

  • Federal Register, Federal Register+, Grants.gov, Regulations.gov, NSF News, UKRI, plus CASRAI’s own published content.
  • 72,264 indexed passages, and every answer cites the ones it drew on.