0% found this document useful (0 votes)
11 views14 pages

Validation Model

The document discusses the importance of validation in analytical instruments and production equipment to ensure data integrity in pharmaceutical manufacturing. It outlines a Data Integrity Model with three levels, emphasizing the need for qualified instruments, validated procedures, and a robust quality management system. Additionally, it highlights regulatory concerns regarding data integrity, focusing on issues stemming from poor management practices rather than outright falsification.
Copyright
© All Rights Reserved
We take content rights seriously. If you suspect this is your content, claim it here.
Available Formats
Download as PDF, TXT or read online on Scribd
0% found this document useful (0 votes)
11 views14 pages

Validation Model

The document discusses the importance of validation in analytical instruments and production equipment to ensure data integrity in pharmaceutical manufacturing. It outlines a Data Integrity Model with three levels, emphasizing the need for qualified instruments, validated procedures, and a robust quality management system. Additionally, it highlights regulatory concerns regarding data integrity, focusing on issues stemming from poor management practices rather than outright falsification.
Copyright
© All Rights Reserved
We take content rights seriously. If you suspect this is your content, claim it here.
Available Formats
Download as PDF, TXT or read online on Scribd

Validation Model

Failure to ensure that an analytical instrument or production equipment is adequately qualified or


computerised system adequately validated means that all work in the two levels of the Data Integrity
Model above is wasted. 2.2.4 Level 2: Right Manufacturing Process and Analytical Procedure for the Job
Following completing qualification of analytical instruments and validating software, the analytical
procedure is developed and validated. There are several published references for this from ICH Q2(R1) [Ref
13] and respective chapters in the European Pharmacopoeia (EP) and United States Pharmacopoeia (USP).
However, the focus of these publications is on validation of an analytical procedure already developed.
Method development, which is far more important as it determines the overall robustness or ruggedness of
the procedure, receives scant attention in these publications. However, this analytical world is changing,
following the publication in 2012 by Martin et al [Ref 14] of a proposed revision of the USP General
Chapters on this topic. An informational general chapter that will focus on validation best practice is being
drafted for launch 2018. This means that “good” scientifically sound method development that results in
having defined the procedure’s design space now becomes important, as changes to a validated method
within the design space would be deemed to be validated per se. Similarly, there needs to be a validated
manufacturing process which has been the subject of major regulatory change in recent years both in the
USA [Ref 25] and the EU [Ref 26] GMP regulations. Activity 1 Activity 2 Activity 3 Activity 4 Activity 5
Business Process Application Software Application & Configuration Records Data, Metadata & Information
Top – Down Validation: Process and Application Focus Bottom – Up Validation Record and Data Integrity
Focus Defining Raw Data as Paper Configuration not Documented E-Records Vulnerable – Deletion, Clock,
etc Analytical Quality Control Working Group IT Compliance Group Page 14 of 89 For Level 2 and Level 3
functions to be effective, the lower layers of the Data Integrity Model must be in place and demonstrably
functioning for this layer to work correctly. 2.2.5 Level 3: Right Production for Right Batch - Right Analysis
for Right Reportable Result. Finally, at Level 3 of the Data Integrity Model, actual pharmaceutical work will
be performed: making a batch or analysing a sample. The analysis of a sample must be undertaken using
the right method and right data system, generated by staff working in an environment that enables data to
be generated, interpreted and the reportable result to be calculated in a secure, accurate, legible,
contemporaneous, original and attributable manner. Staff should be encouraged to admit any mistakes and
there must be a no-blame culture in place. It is also important not to forget the importance of the overall
quality management system. 2.2.6 Role of the Quality A quality function for oversight of compliance of all
the operations performed at the three levels is essential. The tasks here include;  Quality oversight of
regulatory requirements  Quality oversight of policies and procedures  Compliance checks of records of
tasks performed  Data integrity audits including relevant aspects of data governance  Data integrity
investigations 2.2.7 The Big Manufacturing Picture Figure 6 shows an example for a system landscape which
is used in most pharmaceutical companies acting globally. The detailed manufacturing landscape usually on
the basis of the ISA 95 approach is outlined in section 9. Figure 6: Example for a typical System Landscape
Analytical Quality Control Working Group IT Compliance Group Page 15 of 89 Beside the specific
manufacturing systems, the QC and QA applications there are two other very complex applications strongly
supporting Data Integrity: the ERP (e.g. SAP) system and the Master Data Management System (MDMS).
Most critical data in the ERP system is usually the release status of each product batch. The major
advantage of the MDMS is to provide one global database for all Master Data: all specifications and limits
are residing in one location with interfaces to a large number of applications. This is facilitating the
cumbersome change control during the product lifecycle. 2.2.8 The Big Analytical Picture Figure 7 shows
the four layers of the Data Integrity Model in a column down the left hand side against the various tasks in
an analytical process.  The foundation shows an outline of what is required at the corporate layer with
management leadership, culture, ethics and data integrity policies, procedures and training. Above the
Foundation is an analytical process with the various requirements at the three Levels of the Data Integrity
Model.  Level 1 shows qualification of an analytical balance as well as analytical instrument such as a
spectrometer coupled with the validation of computerised system that controls it. In addition, we have the
regulatory requirements for calibration, maintenance and use logs.  Level 2 is represented by the
preparation of reference standard solutions, sample preparations, and the development and validation of
the analytical procedure.  Level 3 is expanded and shows the application of a validated analytical
procedure from sampling, transporting the sample to the laboratory, sample management, analysis,
calculation of the reportable result as well as out of specification investigation etc. This diagram shows far
better how the layers of the laboratory Data Integrity Model interact. Without the Foundation, how can the
three other levels hope to succeed? Without qualified analytical instruments and validated software how
can you be assured of the quality and integrity of the data used to calculate the reportable result? It is less
important where an individual activity is placed in the various levels. The primary aim of this Model is to
visualise for analytical scientists how data integrity is achieved in practice. Analytical Quality Control
Working Group IT Compliance Group Page 16 of 89 Figure 7: The Analytical Process and the Data Integrity
Model Analytical Quality Control Working Group IT Compliance Group Page 17 of 89 3 Background 3.1 Brief
history of data governance & integrity issues Data integrity in GMP regulated laboratories is the current hot
topic with regulatory agencies either due to falsification of data or poor data management practices. Data
integrity is not just confined to a single country or continent but is a global issue, as many data integrity
problems are based on poor and/or outdated working practices rather than a minority of cases involving
data falsification. Data integrity in the GMP laboratory can be traced to Barr Laboratories in the early
1990s. Here an issue in production was tracked to the Quality Control laboratory where it was found that
the laboratory was retesting and resampling until the batch passed. Following the resulting court case the
judge ruled that outliers could not be rejected unless allowed by the United States Pharmacopoeia (USP)
[Ref 1]. The FDA also responded by issuing a guide on Inspection of Pharmaceutical Quality Control
Laboratories in 1993 [Ref 2]. This guidance still is relevant as many processes in regulated laboratories are
still paper based or use hybrid systems and this document should be read as it provides valuable insights
into how regulators will conduct an inspection of a Quality Control laboratory. In 2005, the Able
Laboratories fraud case was a major issue where manipulation or falsification of data to pass was found [3].
What was a major concern for the Food and Drug Administration (FDA) was that the issue was not found by
their inspectors but from a company whistle-blower. Unfortunately for the FDA, Able Laboratories had
seven successful pre-approval inspections (PAI). As a direct result, the FDA completely rewrote the
Compliance Program Guide (CPG) 7346.832 [4] for Pre Approval Inspections in order to be able to detect
similar issues during PAI. The updated CPG became effective in May 2012. The new version of the CPG has
three objectives: 1. Readiness for Commercial Manufacturing 2. Conformance to the Application 3. Data
Integrity Audit At first glance, the focus for laboratory data integrity is objective 3. However close reading
of the CPG [Ref 4], one realises that laboratory and production data integrity permeates all three objectives
and to focus only on objective 3 for laboratory data is not sufficient. Objective 3 lists some advice for the
inspectors undertaking a PAI:  Compare raw data, hardcopy or electronic, such as chromatograms,
spectrograms, laboratory analyst notebooks, and additional information from the laboratory with summary
data filed in the CMC section.  Raw data files should support a conclusion that the data/information in the
application is complete […]. Analytical Quality Control Working Group IT Compliance Group Page 18 of 89 
Lack of contextual integrity include the failure by the applicant to scientifically justify non submission of
relevant data, such as aberrant test results or absences in a submitted chromatographic sequence [Ref 4].
Reiterating, the advice above, this document should be read in conjunction with the 1993 guidance on
Inspection of QC Laboratories [Ref 2] to gain an overall perspective of a regulatory inspection for any
regulated laboratory working to a GMP discipline. Looking wider than the FDA, PIC/S have an aide memoire
for inspectors on the Inspection of Quality Control Laboratories [Ref 5] as well as their guidance on
Computerised Systems in GxP environments [Ref 6]. The former publication has a section on
documentation where there are small sub-sections on data traceability and computerised systems which
can be used understanding data integrity [Ref 5]. The latter has sections 23 and 24 covering inspections of
computerised systems; section 23 is a general approach to inspections and section 24 has six checklists for
systems. However, there is not a specific focus on data integrity which reflects the age of the document as
it is based on old version of Annex 11 and GAMP 4 principles [Ref 6]. However, together these four
regulatory guidance documents give a more comprehensive approach to auditing both computerised
systems and paper records for data integrity issues. In addition, there is level 2 guidance on the FDA’s web
site for some aspects of data integrity such as: shared user log-ins, why paper cannot be raw data from a
computerized system, and using samples as SST injections. Questions and Answers on Current Good
Manufacturing Practices, Good Guidance Practices, Level 2 Guidance - Records and Reports [Ref 7]. 3. How
do the Part 11 regulations and predicate rule requirements (in 21 CFR Part 211) apply to the electronic
records created by computerized laboratory systems and the associated printed chromatograms that are
used in drug manufacturing and testing? (posted in 2010) Draft FDA Data Integrity and Compliance with
CGMP Guidance for Industry Guidance Question 5. Why is FDA concerned with the use of shared login
accounts for computer systems? Question 13. Why has the FDA cited use of actual samples during “system
suitability” or test, prep, or equilibration runs in warning letters? 3.2 Summary of Data integrity issues
arising from Regulatory experience Currently data integrity is a major concern within all regulatory agencies
in all GxP disciplines. Although falsification and fraud make the headlines it is in a minority of cases. The
main data integrity issues are due to poor management leadership, poor data management practices such
as reliance on paper as raw data where this is not sufficient, poor training (specifically for data integrity),
failure to configure systems correctly to protect records, failure to validate the system for intended use,
failure to back up records, and ineffective internal audits. Analytical Quality Control Working Group IT
Compliance Group Page 19 of 89 A summary of FDA warning letter citations pertaining to data integrity can
be seen in Figure 8 [Ref 25], the majority of the citations can be classified into three areas:  Equipment: 21
CFR 211.68(b)  Laboratory Controls: 21 CFR 211.160 – 165  Laboratory Records: 21 CFR 211.194 (a) – (e)
Figure 8: A Summary of FDA Warning Letter Citations for Lack of Laboratory Data Integrity [Ref 21] 3.3 Poor
Practices versus Falsification Although data falsification, which has mainly focused in laboratory analysis, is
a major issue with data integrity it constitutes only about 5% of the regulatory citations. The remainder of
data integrity problems are caused by companies having poor data management practices. We consider
both of these areas in this section. 3.3.1 Data Falsification Data falsification and fraud is essentially testing
into compliance and is a practice that is intended to deceive: batches or material are passed as within
specification with a combination of the following activities:  Recording a result on paper without any
corroborating documented evidence  Continuing testing until an acceptable result is obtained that passes.
This may be accompanied by deletion of earlier failed test results or the use of samples as system suitability
test injections to see what the result is before committing the run for analysis Quality Management System
Citations Laboratory Records Citations §211.194 a – e Automatic & Electronic Equipment Citations
§211.68(b) Laboratory Controls Citations §211.160 – 165  Shared user identities: for both CDS & Windows
 No lock out of the OS  Inappropriate user access privileges  No separation of system administrator
functions  No backup procedure  Data deleted  Data lost  Data not consistently archived to network
server  No SOP for management of raw data files  No CDS software to rerun data  Impact of numerous
power outages not investigated  Unofficial testing  Work not contemporaneously documented 
Overwriting of data  Removal of instruments / CDS during inspection  Requires computer life cycle SOP
 Audit trail turned off  Audit trail not reviewed  Trial / test injections to determine if batch passed 
Complete data not available  Reintegration to pass  No saving of the processing method  Deletion of
data  Falsification of sample weights  No standard / solution preparation details  Lack of batch
information  Signature of tester omitted  Signature of reviewer omitted  Senior & line management
responsible  QMS not robust  Internal audit failure  All lab data questioned Analytical Quality Control
Working Group IT Compliance Group Page 20 of 89  Copying a passing result file from one batch into a
new batch without doing the actual analysis  Doing an analysis and then calculating what the weight of
sample should be to pass and then fabricating the balance data  Performing “chromatographic analysis”
without any physical chromatographs, merely reintegrating and printing the same sets of data using a
chromatography data system  Manually integrating chromatograms into compliance by skimming or
enhancing peaks of standard chromatograms but not the sample ones or vice versa 3.3.2 Poor Data
Management Practices The remaining 95% of data integrity citations are due to poor data management
practices. For example, these can include: Attributable  Failure to sign the results as a tester  Failure to
review and sign the results documentation package as a reviewer  Saving money on user licences and
sharing accounts so that an individual performing work cannot be identified  Generic shared user accounts
Legible  Using standalone workstations that are not connected to a network  Failing to back up electronic
records Contemporaneous  Pre-dating/back-dating records Original  Using an analytical balance without
an attached printer and just recording measurements by observation  Defining raw data as paper when
using a computerised system either in a hybrid or electronic mode  Deleting electronic records Accurate 
Lack of complete data  Using an analytical balance without an attached printer and just recording
measurements by observation  Defining raw data as paper when using a computerised system either in a
hybrid or electronic mode Complete  Not to include incomplete records Consistent  Referencing missing
attachments Enduring  Using thermal paper without attached copy Available  Records are archived in a
way that it takes more than 24 hours to retrieve them Further information on regulatory citations can be
seen on the FDA’s web site. All form 483 observations from all of the FDA inspections are collated and
published each fiscal year by the Office of Regulatory Affairs. An FDA web page of Inspections, Compliance,
Enforcement, and Criminal Investigations [Ref 2] provides a spreadsheet of all citations made using an FDA
software application and made available in an annual spreadsheet for each FDA fiscal year starting from
2006. However, be prepared: Analytical Quality Control Working Group IT Compliance Group Page 21 of 89
 Each spreadsheet needs to be carefully reviewed to highlight the area you are interested in as they
contain citations for all areas that the FDA regulates but within each spreadsheet there is a tab for medical
devices, pharmaceutical etc. This way you avoid having to wade through citations dealing with food,
although the Capitol Cake Company warning letter from August 2008 can be a diverting and surprising
source of entertainment.  When you open the tab dealing with pharmaceutical companies, the citations
need to be sorted to find the area of the CFR you are interested in.  These spreadsheets are not a
comprehensive listing of all inspectional observations as only 483s prepared using Turbo EIR are included in
the listings, therefore data is not comprehensive but give a representative “snapshot” of compliance or
rather non-compliance in the pharmaceutical industry. 3.3.3 Manufacturing Records The area of the CFR
that of interest is the section covering batch production and control records or §211.188. §211.192 covers
production record review. §211.188 is divided into two clauses covering the following topics:  (a) Accurate
reproduction  (b) Documentation The phrases “complete information” applies to §211.188 (and so to
§211.192) and “complete records” is a consistent requirement for the §211.188. In addition, EU GMP Part I
Chapter 4 and 4.20, Part II chapter 6 and 6.5, and Annex 11 have similar requirements. Table 1: Number of
All FDA 483 Citations for §211.188 and §211.192 Non-Compliances 2006 – 2016 CFR Section Topic 2006
2007 2008 2009 2010 2011 2012 2013 2014 2015 2016 Total (%) §211.188+ §211.188(a)+ §211.188(b) All
Batch production and control records 204 181 147 154 170 152 137 114 74 112 102 1547 (100%) §211.188
Batch production and control records 60 47 42 66 61 61 56 56 43 56 31 579 (37%) §211.188(a) Accurate
reproduction 12 15 4 4 8 4 4 2 0 4 9 66 (4%) §211.188(b) Documentation 132 119 101 84 101 87 77 56 31
52 62 902 (58%) §211.192 Production record review 231 207 181 235 252 299 233 239 209 250 227 2563
(100%) Note to the table: Percentage figures are rounded to the nearest whole number which accounts for
66 and being equivalent to 4% of the citations Analytical Quality Control Working Group IT Compliance
Group Page 22 of 89 Table 1 presents eleven fiscal years of 483 observations from the downloaded
spreadsheets 2006 - 2016 for the number of citations against the clauses in §211.188 and §211.192. 
There was a total of 1547 citations against any clause of §211.188 over the eleven years, with the number
of citations for non-compliances in any one year ranging from 74 to 204.  There was a total of 2563
citations against any clause of §211.192 over the eleven years, with the number of citations for non-
compliances in any one year ranging from 181 to 299.  However, the distribution of the non-compliances
per clause was more interesting. The clear area where there were the most problems was §211.188(b)
documentation which constitutes 58% of the non-compliances.  Also, the review of the records exhibits
1/3 more observations for the review than for the records themselves. There is no obvious connection
between the observations per year, min/max does not seem to be connected.  There is no obvious trend
or standardization to be seen. However, there is also no indication that it is going to be better or worse. 
When interpreting the data in the table one needs to consider that the mix of citations does probably not
fully reflect the market composition of small and big companies. A further analysis of the data within the
data shows that three of the major causes of regulatory citations in this area are:  Failure to identify the
test method used adequately  Failure to record sample weights taken during the analysis  Failure to have
the initials of signature of the reviewer In essence, these citations are a fundamental failure of either the
tester or the reviewer to do their respective jobs correctly and contrast with the FDA focus on “data
integrity” as documented in the scope of the laboratory audit (objective 3) of the Compliance Policy Guide
7346.832 on pre-approval inspections [Ref 4]. 3.3.4 Laboratory Records The area of the CFR that of interest
is the section covering laboratory records or §211.194. §211.194 is divided into five clauses covering the
following topics:  (a) Testing Records  (b) Test Method Modification Records  (c) Reagents & Standards
Testing Records  (d) Laboratory Equipment Calibration Records  (e) Stability Testing Records Analytical
Quality Control Working Group IT Compliance Group Page 23 of 89 The phrases “complete data” applies to
§211.194(a) and “complete records” is a consistent requirement for the remaining clauses of §211.194
from sub sections (b) to (e) inclusive. In addition, EU GMP Chapter 6, 6.16 and 6.17, and Annex 11 have
similar requirements. Complete data and raw data is essentially the same terms and for computerised
systems includes review of audit trail entries regardless if the system is used as a hybrid or electronic
application. The focus of an audit trail review for second person review should be a review by exception, if
the application supports this approach. Review by exception, a risk based approach to data integrity, is to
only review applicable audit trail entries of there are GMP-relevant modifications or deletions that are
notified by the system to the reviewer. The way this function works can be colour coding data, check boxes
or annotations, etc. Regardless of the approach taken by a supplier, to be able to use a review by exception
approach a company must:  Specify the function in a user requirements specification  Document any
application configuration  Verify that the function works correctly in the user acceptance testing
(Performance Qualification) phase  Ensure that the configuration settings are unaltered though routine
data integrity audits and / or periodic reviews Table 2: Number of All FDA 483 Citations for §211.194 Non-
Compliances 2006 – 2016 CFR Section Topic 2006 2007 2008 2009 2010 2011 2012 2013 2014 2015 2016
Total (%) §211.194 All Laboratory Records 142 114 100 104 145 125 122 83 83 110 109 1237 (100)
§211.194(a) Testing Records 104 83 78 80 108 98 98 70 67 94 97 977 (79) §211.194(b) Test Method
Modification Records 4 7 1 9 4 7 9 2 4 5 3 55 (4) §211.194(c) Reagents & Standards Testing Records 9 11 11
3 12 9 5 4 8 5 4 81 (7) §211.194(d) Laboratory Equipment Calibration Records 20 10 9 12 15 8 7 4 4 6 4 99
(8) §211.194(e) Stability Testing Records 5 3 1 0 6 3 3 3 0 0 1 25 (2) Trend Test Records in % of All 73 72 78
77 75 78 80 84 81 85 89 (79) Table 2 presents eleven fiscal years of 483 observations from the downloaded
spreadsheets 2006 - 2016 for the number of citations against the clauses in §211.194. Analytical Quality
Control Working Group IT Compliance Group Page 24 of 89  There was a total of 1237 citations against any
clause of §211.194 over the eleven years, with the number of citations for non-compliances in any one year
ranging from 83 to 145.  However, the distribution of the non-compliances per clause was more
interesting. The clear area where there were the most problems was §211.194(a) testing records which
constitutes 80% of the non-compliances.  When interpreting the data in the table one needs to consider
that the mix of citations probably does not fully reflect the market composition of small and big companies.
A further analysis of the data within the various sub-clauses of §211.194(a) shows that three of the major
causes of regulatory citations in this area are:  Failure to identify the test method used adequately 
Failure to record sample weights taken during the analysis  Failure to have the initials of signature of the
reviewer In essence, these citations are a fundamental failure of either the tester or the reviewer to do
their respective jobs correctly and contrast with the FDA focus on “data integrity” as documented in the
scope of the laboratory audit (objective 3) of the Compliance Policy Guide 7346.832 on pre-approval
inspections [Ref 11]. Analytical Quality Control Working Group IT Compliance Group Page 25 of 89 4
Regulatory References, Guidance and Requirements An overview of regulatory guidance that is available
for GMP environments is shown in Figure 9. Figure 9: Overview of Data Integrity Guidance from Regulatory
Authorities 4.1 MHRA (UK) GMP Data Integrity Initiatives The MHRA (Medicines and Healthcare products
Regulatory Agency) has been involved with data integrity since December 2013 when they announced on
their web site [Ref 11] that stating from January 2014: The MHRA is setting an expectation that
pharmaceutical manufacturers, importers and contract laboratories, as part of their self-inspection
programme must review the effectiveness of their governance systems to ensure data integrity and
traceability. This was an extension of self-inspections (internal audits) that needs to be carried out under
Chapter 9 of EU GMP [Ref 12]. However, in addition to the pharmaceutical company itself it was also an
expectation that the data integrity of a company’s suppliers (e.g. API suppliers, contract manufacturing and
contract laboratories, etc.) were included in these assessments as well. In March 2014, the MHRA wrote to
suppliers of chromatography data systems to request a copy of their software and documentation to
understand how each system worked. The indirect message was to understand how data can be falsified
using a specific CDS application. The next month, MHRA and other European inspectors received training in
data integrity from one of the trainers to the FDA on the subject. In Data Integrity Guidance from
Regulatory Bodies European Regulators World Health Organisation Pharmaceutical Inspection Co-operation
Scheme Food and Drug Administration Guidance on Good Data and Record Management Practices Good
Practices for Data Management and Integrity in Regulated GMP/ GDP Environments EMA Questions and
Answers: GMP Data Integrity MHRA GMP Data Integrity Definitions and Guidance for Industry MHRA GxP
Data Integrity Definitions and Guidance for Industry Inspection of Pharmaceutical QC Laboratories CPG
7346.832 on Pre-Approval Inspections Level 2 Guidance on the FDA Web Site Data Integrity and cGMP
Compliance Guidance Industry Guidance Documents GAMP Guide Records and Data Integrity Analytical
Quality Control Working Group IT Compliance Group Page 26 of 89 January 2015, MHRA released a
guidance for industry on data integrity [Ref 13], after industry feedback MHRA issued a second version in
March 2015 [Ref 14]. The document consists of three pages of discussion about various data integrity topics
followed by 13 pages of definitions with meaning and regulatory expectations. This document has been
critiqued in a four-part review [Refs 15-18]. The main concepts introduced in this guidance are:  Data
governance  Data lifecycle  Design of systems  Definitions and regulatory expectations In presenting the
definitions, there is no logic of the order and indeed some of the definitions are wrong as equating data
with information, when in fact information is abstracted from data. 4.2 Draft MHRA GxP Data Integrity
Guidance for Industry In July 2016, the MHRA issued a draft GxP data integrity guidance for industry
comment [Ref 29]. This was an extension of the earlier GMP guidance into the GLP and GCP areas that the
regulatory is also responsible for in the UK. In essence, there is similar content and scope from a GMP
perspective as the March 2015 guidance. 4.3 WHO Guidance on Good Data and Records Management
Practices In 2016 the WHO issued a guidance document on Good Data and Records Management Practices
was published [Ref 19]. The main sections of the WHO guidance [Ref 19] are:  Aims and Objectives 
Principles  Quality Risk Management to Ensure Good Data Management  Management Governance and
Quality Audits  Contracted Organizations, Suppliers, and Service Providers  Training in Good Data and
Record Management  Good Documentation Practices (Appendix 1 provides further detail of ALCOA+
requirements for data integrity, see below)  Designing Systems to Assure Data Quality and Reliability 
Managing Data and Records Across the Data Lifecycle  Addressing Data Reliability Issues Holistically, this
guidance has a greater scope that is covered in more depth than any other regulatory guidance on data
integrity. There is much good advice that can be used within the regulated laboratory Analytical Quality
Control Working Group IT Compliance Group Page 27 of 89 regardless if GMP, GCP or GLP is applicable.
Other chapters in this guide cover data governance, data integrity audits and issues of poor data
management practice or falsification. However, from the perspective of data integrity in the laboratory,
Chapter 9 on Good Documentation Practices and Appendix 1 is most applicable. In this section the five
ALCOA (Accurate, Legible, Contemporaneous, Original and Attributable) data integrity principles are each
defined followed by the expectations for both paper and electronic records, in addition, for each criterion
there is a discussion of special risk factors to be considered. 4.4 FDA Draft Guidance on Data Integrity and
Compliance with CGMP In April 2016 the FDA released a new Guidance [Ref 36] document emphasizing on
flexible and risk-based strategies to prevent and detect data integrity issues. As usual with FDA guidance
documents it describes the Agency’s current thinking on the DI topic and should be viewed for the time
being only as a recommendation, certainly until the guidance becomes final. The FDA guidance is unlike
those from the WHO and MHRA guidance documents [Refs 1, 3] in that it is presented in the format of 18
questions and answers. The FDA document does not have the more encompassing scope of the MHRA and
WHO guidance documents that consider topics such as data governance, the role of management and the
extension of data integrity to an organisation’s suppliers. Instead, the FDA guidance is complimentary and is
entirely focussed on interpretation of the 21 CFR 211 regulations for current Good Manufacturing Practice
for specifically to ensure the integrity of data generated in pharmaceutical manufacturing [8]. The problem
with US regulations, unlike those in the European Union, is that (with one exception) they have not been
updated since 1978. As such there is no explicit reference that is specific for ensuring the integrity of data –
it is the interpretation of the regulations that is the key. As a result, there are multiple references to the
different sections of 21 CFR 211 to support the 18 questions. Of particular interest is question 1e which
illustrates the “current” in cGMP [Ref 2]. Backup is now interpreted by the FDA as long term archive for
records retention rather than simply creating a copy of records on tape or disk for disaster recovery
purposes.  Static versus Dynamic Data: Question 1d talks about static and dynamic data which are perhaps
not the best of terms to use. Static data is typically discrete values such as temperature and pH that cannot
be interpreted or as the guidance mentions a paper printout or image. In contrast, dynamic data requires
human interpretation or processing such as chromatography or spectroscopic data files and this type of
data is of major concern to the FDA and other regulators for manipulating data and testing to pass.  Q4
and Q5: Access to Computerised Systems: In short, there must not be any generic or shared log-on
accounts for access to a computerised system as each person must be uniquely identified and their actions
within a system tracked and audit trailed. User types need to be established that separate administrator
privileges from those involved with generating, processing and reviewing Analytical Quality Control
Working Group IT Compliance Group Page 28 of 89 data. Ideally an independent function, typically the IT
department need to control the administration rather than the laboratory. However, with standalone
systems this may be impossible to achieve and therefore as noted in the MHRA data integrity guidance [Ref
3] an alternative option may be for a laboratory user to have two user types. The first would be as an
administrator with no user access rights and the second as a user with no administrator privileges to avoid
conflict of interest. The FDA guidance and EU GMP Annex 11 §12.3 also recommends maintaining a list of
authorised individuals with their access privileges. This should cover both current and historical users of a
system. In case you think this is an FDA rabbit out of the hat, this has been the stated Agency position since
2007. It is contained in the guidance for industry on Computerised Systems Used in Clinical Investigations
[Ref 9] under Recommendations, Section E on External security safeguards: You should maintain a
cumulative record that indicates, for any point in time, the names of authorized personnel, their titles, and
a description of their access privileges. This is good advice as it allows quality assurance, auditors or
inspectors to see at any point in time the access privileges that any individual has had for a system e.g.
trainee, analyst or supervisor.  Q12 & Q2: When Do Data Become a GMP Record and Can I Exclude GMP
Data? Now we come to probably the most contentious part of the FDA Guidance: Question 12. At the
beginning of Q12 is a simple statement of fact: When generated to satisfy a GMP requirement, all data
become a GMP record. This is simply a confirmation and restatement of the GMP requirement in 21 CFR
211.194(a) for complete data secured in the course of testing [Ref 8]. The guidance then continues: You
must document at the time, or save, the data at the time of performance to create a record in compliance
with GMP requirements ….. FDA expects processes to be designed so that quality data required to be
created and maintained cannot be modified. For example, chromatograms should be sent to long-term
storage (archiving or permanent record) upon run completion instead of at the end of a day’s runs. There is
a problem here, if a spectroscopy or chromatography file cannot be modified how can we interpret it?
Perhaps what is meant is that the data or the computer file created cannot be changed but the data
contained within it can be interpreted? The requirement about removing chromatograms immediately to
long term storage is not practicable. I appreciate what the Agency is trying to achieve – to ensure that
electronic records generated by data systems of all types are protected especially for standalone systems
that do not have databases. This actually reflects on how instrument suppliers design and laboratories
select data systems that are sub-standard for Analytical Quality Control Working Group IT Compliance
Group Page 29 of 89 regulated laboratories. To put this into perspective, virtually all software currently in
use in laboratories was designed before the current focus on data integrity. For too long laboratories have
accepted spectroscopic applications running on standalone workstations that generate data files that are
stored in directories in the operating system. Quite simply, these systems are not fit for use in a regulated
environment. To illustrate this point, McDowall and Burgess recently wrote a series of four papers
describing the ideal chromatography data system (CDS) for regulated GxP laboratories in LC-GC North
America [Refs 11-14]. Although focussed on CDS, most of the principles and recommendations outlined in
these papers are also applicable to spectroscopic data systems. In the part on system architecture [Ref 12]
the point was made that standalone workstations and using directories in the operating system for file
storage were not fit for purpose. Instead data must be acquired directly to network storage and that all
data systems must use a database. In these ways the intent of the FDA’s requirement would be met but in a
more practical way. Correctly designed data systems are the main way laboratories will comply with the
protection of records other than implementing a scientific data management system (SDMS). Not using a
database means to mimic the functionality procedurally with much more effort and risk. Question 12
progresses through the next statement in the document for paper records, which must have been copied
verbatim from a GxP documentation class 101. However as judging from the citations in many warning
letters there appear to be usage of temporary scraps of paper in regulated laboratories that necessitated
the statement; It is not acceptable to record data on pieces of paper that will be discarded after
transcription into a permanent laboratory notebook There then follows the electronic equivalent which is
more contentious: Similarly, it is not acceptable to store data electronically in temporary storage, in a
manner that allows for manipulation, before creating a permanent record. Electronic data that are
automatically saved into temporary memory do not meet cGMP documentation or retention requirements
This section has probably caused more discussion than any other in the whole draft data integrity guidance.
Obviously, the Agency does not want people taking a file then interpreting it multiple times without saving
it as this is testing or rather over-interpreting into compliance. It is unlikely that the Agency intended or
wanted keystroke loggers on all systems used for regulated analysis. The process in all data systems should
be to save the data first and monitor the interpretation. However, this is where science and compliance
meet, often in a head on collision. The controls required, especially technical ones rather than procedures
need to be designed and implemented. In some systems, especially those close to research end of the R&D,
may be designed with minimal regulatory compliance controls. There needs to be a fundamental rethink by
software suppliers how Analytical Quality Control Working Group IT Compliance Group Page 30 of 89 their
software is designed and operated in compliance with the applicable regulations. It should be noted that
the recent UK MHRA guidance includes the statement: … it is expected that GMP facilities should upgrade
to an audit trailed system by the end of 2017 Question 2 discusses if GMP data can be excluded from
decision making? It notes that: Any data created as part of a GMP record must be evaluated by the quality
unit as part of release criteria and maintained for GMP purposes. Electronic data generated to fulfil GMP
requirements should include relevant metadata. The answer is that data (paper, hybrid or electronic) can
only be excluded if there is a justified and documented scientific rationale e.g. out of specification result
following a laboratory investigation. The corollary is that data should not be deleted, even if it is excluded,
as this is part of complete data collected in the course of testing under 21 CFR 211.194(a) [Ref 8]. .  Q3:
Does Each Workflow on a Computer System Need Validating?: Yes, is the answer in the FDA guidance [2]. If
a workflow is configured or customised then it needs to be specified, built or configured in the software
and then tested for intended use. So far, so good and the ECA IT Working Group has no problem with this
approach. However, what if you have standard workflows in a system that you don’t use and can’t turn
them off? As the question is written and answered, the data integrity guidance implies that they all need to
be validated which is a compliance overhead and not in the spirit of a risk-based approach. There is also a
clash of FDA guidance documents. There is the small matter of the 2002 General Principles of Software
Validation which states in section 6.1 [Ref 16]: For example, a manufacturer who chooses not to use all the
vendor-supplied capabilities of the software only needs to validate those functions that will be used and for
which the manufacturer is dependent upon the software results as part of production or the quality
system. Or put simply, only validate those software functions you use. However, if you only validate
functions that you use you either have to train users to avoid using non-validated functions or restrict
access using technical controls.  Q6 Control of Blank Forms: At the back of many procedures in regulated
laboratories are blank forms designed to ensure compliance with the work contained in the SOP and to
collect the required data. Question 6 of the FDA guidance raises the question of how these blank forms
should be controlled [Ref 2]. The FDA wants each copy of such form to be uniquely numbered and
accounted for. This is simply a restatement of their position from the 1993 guidance on Inspection of QC
Laboratories [Ref 5] as noted in Section 13 on documentation that: Analytical Quality Control Working
Group IT Compliance Group Page 31 of 89 We expect raw laboratory data to be maintained in bound, (not
loose or scrap sheets of paper), books or on analytical sheets for which there is accountability, such as
prenumbered sheets. The requirement for control of blank forms has also been presented in the recent
MHRA and WHO guidance documents [Refs 1, 3]. Furthermore, this topic is covered in the PIC/S and EMA
regulatory guidance documents. The rationale for this approach is that uncontrolled blank forms present an
opportunity for data falsification or testing into compliance. An approach to the control of blank forms is
presented in Section 9 in this guidance.  Importance of the Second Person Review: A problem with the FDA
data integrity guidance is that there is only a focus on audit trail review with Questions 7 and 8 and with
question 16 on the need for personnel to be trained to detect data integrity issues [Ref 2]. As such, the
draft guidance misses the point and an opportunity. If we are serious about data integrity and compliance
with the regulations, surely the focus both here and in our laboratories should be on a series of questions
covering the second person review of analytical data. As currently written, we are scratching the surface
with simply a focus on a computerised system audit trail (if used) and that people should be trained to
detect poor data management practices 4.5 PIC/S PI-041 Data Integrity Guidance In August 2016 the PIC/S
Working Group on Data Integrity has published a first draft guidance document on Good Practices for Data
Management and Integrity in Regulated GMP/GDP Environments. It sets out basic expectations for good
data governance and refers to the influence of organisational behaviour and global supply chain challenges.
The aim of this document is to develop a guidance for Health Authority Inspectors. The 44-page PIC/S draft
guidance details the various deficiencies linked to data integrity failures that may impact product quality
with risk to patient health. 4.6 ISPE Records and Data Integrity Guide The Guide published in 2017 is a
companion to the GAMP5®. It utilized the same principles as the other guidelines and provides more
details. There is a Good Practice Guide providing even more details due for publication in 2018. [Ref 37]
Analytical Quality Control Working Group IT Compliance Group Page 32 of 89 5 Data Governance 5.1
Corporate Management Leadership for Data Governance and Data Integrity The principles of data integrity
are not limited to compliance with regulatory requirements but extend to the general state of awareness
mind set and culture of all staff regarding data integrity and prevention of issues. The pictorial overview is
shown in Figure 1: Overview of the Components of Data Governance mapped to ICH Q10 Quality
Management System Model. This can be achieved by establishing a data governance program within the
overall pharmaceutical quality system focusing on I. Management Leadership II. Procedural (Policies):
Establishing the general polices and procedural practice for data handling III. Behavioural (Culture):
Introducing/teaching/practicing appropriate organisational behaviour when handling data IV. Technical
(Process): Having appropriate processes for handling, recording, processing, archiving and decommissioning
of data V. Assessment and remediation of existing processes and systems for generating, interpreting,
reporting and storing data It is essential that senior management is engaged in establishing the foundation
for data governance by assuring that policies, training and technical systems are in place. Further, senior
manager under the EU GMP Chapter 1 is responsible for the overall quality system and that includes data
integrity. 5.2 Policies and Procedures Figure 10: Data Governance Model; Technical and Procedural Controls
for Data Integrity Section Analytical Quality Control Working Group IT Compliance Group Page 33 of 89 To
ensure that general handling of data is aligned with data integrity principles, procedures should be
established and maintained using a Quality Risk Management (QRM) approach by taking into account the
data criticality (what is the data used for?) and the inherent risk of the data (how complex is the process by
which the data is generated?). The criticality of data is determined by what the data is used for – examples
of highly critical data is critical process control data, long-term stability data and data to determine batch
release decisions. Data categorisation practices can be a valuable tool in securing handling of data based on
criticality and in securing resources are spent where they are of most use. Policies and procedures should
be applicable for  Both paper and electronic data. The general Good Documentation Practices (GDocP)
principles that apply for paper records should also be established for electronic records (see also 21 CFR
Part 11).  To contract givers (our company) and contract acceptors (CMOs, Contract Laboratories and
other Service Providers). Contract givers are responsible for the decision making based on data provided by
contract acceptors, while contract acceptors are responsible for establishing data governance programs to
assure reliability of provided data. 5.3 Expected Culture and Behaviours Figure 11: Data Governance Model;
Ethical Culture & Corporate management Practices Section Quality Culture – Senior management is
responsible for providing the environment to establish, maintain and continually improve the quality
culture, providing for the transparent and open reporting of deviations, errors or omissions at all levels of
the organization. Code of Conduct – Senior management is committed to educating and ensuring
adherence to the Code of Conduct, including honesty and full disclosure in all aspects of data reporting, and
disclosure and escalation when these practices are found not to meet company standards, policies or
procedures. Analytical Quality Control Working Group IT Compliance Group Page 34 of 89 5.4 Quality
Management System Figure 12: Data Governance Model; Quality Management System Section Senior
Management is responsible for establishing an effective quality management system with appropriate use
of the Pharmaceutical Quality System (ICH Q10) elements and enablers, including quality risk management.
It should include appropriate organizational structure with adequate segregation of duties, written policies
and procedures (e.g., good documentation practices), key performance indicators (KPI) and processes to
monitor the timely and accurate entry of data (e.g., self-inspection, management reviews), and systems to
enable informed decisions to prevent and detect situations that may impact data integrity. 5.5 Risk
Management Risk management should be applied throughout the lifecycle of the data
collection/generation, processing, analysis, review and reporting, taking into account data integrity,
product quality and patient safety; the assessment of risks should include both manual and electronic data
operations. As part of a risk management system, decisions on the extent of validation and data integrity
controls should be based on a justified and documented risk assessment of the system. The inherent risk of
data is determined by how the data is generated and recorded. The inherent risk is depending upon the
degree to which data generated by the specific process can be configured and therefore also potentially
manipulated. Simple systems such as pH-meters and balances have a lower inherent risk than more
complex analytical systems such as High Performance Liquid Chromatography (HPLC) systems and Gas
Chromatography (GC) systems. Procedures regarding data handling should take into account both the
criticality and the inherent risk of data generated from the specific system in its specific setting. The degree
of effort and resource applied to the organizational and technical control of data lifecycle elements should
be commensurate with its criticality in terms of impact to product quality attributes as well as quality (e.g.
product release) and GxP decisions. The inherent risks to data integrity may differ depending upon the
degree to which data (or the system generating or using the data) can be configured, and therefore
potentially manipulated. Analytical Quality Control Working Group IT Compliance Group Page 35 of 89 5.6
Training Senior Management is committed to ensure training of its personnel in data integrity policies and
procedures, including measures to prevent and detect data integrity issues across the data lifecycle.
Personnel should be trained in data integrity policies and procedures, and agree to abide by them.
Management should ensure personnel are trained to understand and distinguish between proper and
improper conduct, including deliberate falsification, and potential consequences. In addition, key
personnel, including managers, supervisors and quality unit personnel, must be trained in measures to
prevent and detect data integrity issues. 5.7 Roles and Responsibilities 5.7.1 Senior Management Senior
Management should take responsibility for ensuring appropriate data governance program is in place.
Elements of management governance should include  allocating the necessary human and technical
resources to ensure and enhance infrastructure for performing QRM, training, implementation of systems
and procedures, internal audits and quality metrics. Active engagement of management in this manner
remediates and reduces pressures and possible sources of error that may increase data integrity risks 
establishing a quality culture within the company that encourages personnel to be transparent about
failures so that management has an accurate understanding of risks and can then provide the necessary
resources to meet data quality standards  ensuring that all site personnel are kept up to date about the
GMP principles of ALCOA and that they are understood and applied  applying modern QRM and sound
scientific principles throughout the data lifecycle  setting expectations according to the true capabilities of
a process, a method, an environment, personnel, or technologies  establishing procedures for mapping
and monitoring of data processes  implementing and validating computerized systems and the necessary
controls so that the probability of occurrence of errors in the data is minimized  training of personnel who
use computerized systems and review electronic data in basic understanding of how computerized systems
work and how to efficiently review the electronic data, which includes metadata and audit trails  defining
and managing of appropriate roles and responsibilities for quality agreements and contracts, regarding data
governance by the contract acceptor on behalf of the contract giver;  modernizing quality assurance
inspection techniques and gathering of quality metrics to efficiently and effectively identify risks and
opportunities to improve data processes. Analytical Quality Control Working Group IT Compliance Group
Page 36 of 89 5.7.2 Data Owner It is important to realise that data integrity (can you trust the numbers?)
and data quality (can you use the numbers?) begin at the point of data acquisition by the system and not in
the data centre. Therefore, the data owner’s responsibilities for a regulated computerised system from the
business side include:  Definition of what is required of system in terms of data quality, data integrity and
data security. This will result either in inputs to the configuration specification for the setting of application
policies, writing of SOPs for using the system or the agreement with IT to support the system (e.g. backup,
account management, etc.)  Assessment of the system to determine if there are vulnerabilities of the
records contained therein. Although a system may be validated, record vulnerabilities may exist which have
to be managed, for more detail see the discussion in Section 9.1 which will probably be executed by a
technical team consisting of IT and data stewards  Development of a remediation plan with the data
stewards and IT for any remediation to secure the records and reduce or eliminate data vulnerabilities
following the assessment  Approve access to the system for new users and changes in access privileges for
existing ones for IT administrators to implement  Approval or rejection of change control requests 
Approval for archiving data and removing them from the system Receive feedback from the data stewards
of the system of issues involving quality, integrity and security of the CDS data and implement any
modifications of procedures, etc. for the data stewards to implement. 5.7.3 Data Steward – Power User –
Department Administrator We mentioned above that integrity and quality of data starts in e.g. the
laboratory and the data owner of a networked system is typically the head of a department such as a
laboratory and is similar for manufacturing systems. This individual will probably will not have the time or
the training to implement the requirements for data integrity and quality that they have mandated. This is
where power users or department administrators of the networked system come in and be involved as
data stewards for the system. The power users are the first point of contact for user questions for help with
the system. They will be instrumental in ensuring the smooth running of the system and maintaining state
of CSV. Also they are further developing the system by e.g. custom reports or custom calculations. Of
course they have to be controlled e.g. specified and validated for correct function. As data stewards, expert
users of the system, they will be responsible for ensuring that the requirements for data integrity and data
quality set by the data owner have been implemented and are working. They are also responsible for data
queries and monitoring data integrity from a system perspective e.g. regular review of system level audit
trails for system related issues rather than data integrity problems. For the more mundane work they
would also be responsible for rebooting the laboratory data servers when needed. In monitoring the
system from the business perspective they can raise issues for discussion with the data owner to resolve as
noted earlier. Analytical Quality Control Working Group IT Compliance Group Page 37 of 89 5.7.4 Second
Person Reviewer Second person review normally begins from taking the samples from the storage areas,
through sample preparation, instrument set-up, chromatographic analysis, integration, calculation of
individual values and reporting the work. Reviewers need to be trained to detect falsification and therefore
processes and transfers need to be as transparent and automated as possible. The scope of the second
person review should cover the whole analytical process from sample storage to reportable result and must
not be confined to the boundaries of a specific system. Scope of the review:  Original records (or true
copies) are to be reviewed  Records can be paper, electronic or hybrid.  In case of hybrid and “mixed“
records (e.g. electronic records with signatures on the associated paper printouts) is has to be ensured that
the paper record is linked to the ER (example see 9.7 Spreadsheets). For media change see 9.6.5 Media
Change.  This mixture of record formats will be typical for many laboratories when reviewing CDS data,
even if the system is configured for electronic working.  Records must be accurate or where data have
been changed it meets GMP requirements  Records must be complete  Instrument and column log books
must match data within the system and other records outside of it  Audit trail events must be reviewed as
part of the second person review and include items such as change history of finished product test results,
changes to sample run sequences, changes to sample identification.  Records generated must comply with
the applicable procedures for the CDS and laboratory activities Note, if the second person review is focused
on a specific system then data integrity issues can fall between the cracks between the applications and not
be detected e.g. data transfer between applications. There must obviously be a procedure and training for
staff who will be conducting the second person review. 5.8 Identifying and Empowering Data Owners and
Data Stewards 5.8.1 Identifying the Data Owner of a System or Process Both MHRA and WHO data integrity
guidance documents [Refs 8, 11] require that data owners are appointed for processes and systems. The
question is who should be a data owner of a computerised system or process? The answer lies in EU GMP
Annex 11 that defines a process owner as a person in the business who is responsible for the overall system
[Ref 49]. For a networked system, the process owner would usually be the head of the department or the
head of the functional unit if served across multiple departments. Therefore, it would make logical sense if
the process owner was also the data owner – being a single point of responsibility for the system. Analytical
Quality Control Working Group IT Compliance Group Page 38 of 89 One potential area of confusion
concerns the name “data owner”, which implies that an individual rather than the organisation that owns
the system and the data generated by it. This is not so, the organisation owns the data, the data owner is
merely the custodian of the data in the system who acts on behalf of the organisation. 5.8.2 The Business is
Responsible for the Data Data quality and data integrity are often thought of as an IT issue, this is wrong as
these areas are the responsibility of the business as they generate the data. IT merely manage and backup
the data and information contained in a system according to the agreement they have with the business.
5.9 CMOs and Contract Laboratories The principles of this guideline apply to contract manufacturers,
contract laboratories and service providers. Every company is ultimately responsible for the accuracy of all
decisions made based on GMP data, including those that are made based on data provided to them by
contractors. A pharmaceutical company therefore should perform periodic scheduled audits with data
integrity on the agenda according to quality agreements to assure that contractors have in place
appropriate programs to ensure the veracity, completeness and reliability of provided data. Analytical
Quality Control Working Group IT Compliance Group Page 39 of 89 6 Policies, Procedures & Processes 6.1
Corporate Data Integrity and Ethics Policy Senior Management must assure appropriate data and record
management controls across the entire data lifecycle of company products to ensure data integrity and
trustworthiness. This guidance describes the key general principles regarding company’s good data
management strategies for GMP records. More specific guidance for the application of these principles will
be provided in detailed documents by the ECA (Data Integrity Policy, Data Integrity Principles, Audit Trail
Review SOP) to be published soon. Employees shall notify responsible management if they become aware
of any potential issue that impacts data integrity such as those attributable to errors, omissions, or
wrongful acts regardless of the cause. For example, employees shall immediately notify management if
they become aware of or have reason to suspect others have falsified data, made unauthorized changes,
destroyed data or other conduct that calls into question the integrity of data. The notification shall follow
the general “speak-up” procedures established in applicable policies, standards, procedures, or other
documents. 6.2 Good Documentation Practices Controls must be in place to ensure integrity of the records
throughout their lifecycle for both paper and electronic records. The controls should include the following:
 Secure controls for ensuring data reliability, authenticity, integrity and confidentiality  A GMP record
must have only one Official Record.  GMP records must have a defined Record Owner (either function or
person), type and retention period.  The record management inventory must list the Record Owners,
retention period and record type. This inventory must be approved by the corresponding Quality group and
be stored in the eDMS (Electronic Document Management System). It compares to the CSV inventory.  A
local procedure for changes of the ownership, location, archival, or destruction of a GMP record must be in
place.  A record retention schedule or specific retention rules must be identified for all GMP records. GMP
records must be maintained and be readily available throughout their lifecycle.  GMP records that are
revised must have version control.  For types of documentation see EU GMP chapter 4 (Instruction type
and record/report type) 6.3 Understanding Complete Data and Raw Data 6.3.1 Traceability of Actions
Analytical Quality Control Working Group IT Compliance Group Page 40 of 89 Throughout the whole
process of the creation of a primary analytical record or complete data for an analytical procedure there
must be explicit linkage to key items to support data integrity criteria such as identification of:  Individual
analytical personnel are uniquely identified and their actions are accurately time and date stamped 
Samples analysed are linked to the material batch numbers or a stability or study plan  Instruments used
to generate data are identified  Name and version numbers of software used to acquire and process data
and report results are documented on the reports  There is a link to the raw data and metadata from the
analysis from which the reportable result has been obtained  The analytical procedure and version used to
acquire data is documented  Time and date stamps on all raw data files, processed data files and the
contextual metadata must be consistent and have a trustworthy storyline. 6.3.2 Understanding Complete
Data Let us take the chromatographic process using a CDS to explain the process of generating analytical
data: there are some common elements that need to be highlighted for a CDS:  Complete data is not a
single record but a collection of data, metadata, information and knowledge that are acquired from the
setting up of the chromatograph, the analytical run, integration and interpretation of the run data, all data
generated during the calculation of analytes in individual aliquots and the reportable result.  Audit trail
entries are acquired throughout the initial data acquisition and the conversion of data to information and
then to knowledge Figure 13: Complete Data / Raw Data or Primary Analytical Record for a
Chromatography Data System [Ref 22] Analytical Quality Control Working Group IT Compliance Group Page
41 of 89 Figure 13 illustrates the generation of raw data and the process of creating other records as data is
processed and converted to knowledge. This illustrates the principle of EU GMP Chapter 4 [Ref 24] that
Records include the raw data which is used to generate other records.  In addition, there will be other
records associated with the analysis that may be recorded on paper printouts (e.g. sample weights) or in
laboratory notebooks or on controlled analytical worksheets for which accountability are components of
complete data. 6.3.3 Understanding Raw Data and Equating it to Complete Data Raw data is mentioned in
EU GMP Chapter 4 but there is no definition of the term in GMP which makes for multiple interpretations.
The problem is that raw data is a Good Laboratory Practice (GLP) term and is defined in the US GLP
regulations (21 CFR 58.3(k)) as:  Raw data means any laboratory worksheets, records, memoranda, notes,
or exact copies thereof, that are the result of original observations and activities of a nonclinical laboratory
study and are necessary for the reconstruction and evaluation of the report of that study. From this
definition, raw data is not just the original observations alone. Once data have been acquired, raw data also
includes any transformation records, calculation of individual results and finally the reportable result plus
any applicable audit trail requirements. This is consistent with GLP definition that includes the journey from
original observations to the final report. As raw data includes data acquisition, data transformation, audit
trail entries, calculation of results and the certificate of analysis this can now be equated to complete data.
Sequence File Acquisition Method Initial Chromatographic Data: Raw Data Files Instrument Control File
Processed Chromatographic Data: Baselines and Peak Areas SSTs ok? Manual Reintegration Parameters
Post Run Calculations Automatic Integration Method Individual Results SSTs ok? Audit Trail Entries For
Analytical Run Life Cycle Data Acquisition Phase Integration, Calculation and Reporting Phase Reportable
Result Range ok? Data: Raw Data, Metadata and Processed Data Information Knowledge Analytical Run
Specific Metadata Analytical Quality Control Working Group IT Compliance Group Page 42 of 89 In the
manufacturing areas raw data is generated on the instrumentation field level (ISA 95) or directly by
embedded systems, i.e., by complex machines. Such production equipment can be found widely in the
manufacturing and packaging processes of pharmaceutical dosage forms. Considering data integrity the
operator of these machines has very limited or no influence at all on the raw data and may only change raw
data by modifications of the very narrow range of parameters which are accessible for her/him. 6.4
Chromatographic Integration Control of chromatographic integration is a major regulatory topic but does
not feature by name in any of the regulatory guidance documents. The FDA guidance comes the closest to
this in Question 12 – when does electronic data become a cGMP record. The issue is when brought into
memory how many times can a data file be reintegrated without trace? This is a system design function
that is outside of the scope of this guidance. However, chromatographic integration is a key regulatory
issue and is discussed in Section 9.8. Analytical Quality Control Working Group IT Compliance Group Page
43 of 89 7 Criteria for Data Integrity and Security of Records based on ALCOA+ Principles The critical issue is
knowing the data and metadata that comprise complete data (or raw data or primary analytical record) so
that it can be subject to a data lifecycle. For example Burgess and McDowall [Ref 22] have defined
complete data, primary analytical record or raw data for a QC laboratory chromatography data system. 7.1
Definition of ALCOA+ Figure 14: The ALCOA+ elements Overlaying the data lifecycle and the complete data
/ primary analytical record should be the nine ALCOA+ data integrity elements applicable over the data
lifecycle [Ref 23] are defined as:  Attributable: Identification of the individual who performed an activity 
Legible: Can you read the electronic data together with any associated metadata or all written entries on
paper? Legible should also extend to any original data that has been changed or modified by an authorised
individual so that the original entry is not obscured.  Contemporaneous: Documented (on paper or
electronically) at the time of an activity  Original: A written observation or printout or a certified copy
thereof or an electronic record including all metadata of an activity  Accurate: No errors in the original
observation(s) and no editing without documented amendments / audit trail entries by authorised
personnel. Accuracy is ensured and verified by documented review including review of audit trails. 
Complete: All data from an analysis including any data generated including original data, data before and
after repeat testing, reanalysis, modification, re-calculation, re-integration and deletion. For hybrid
systems, the paper output must be linked to the underlying electronic records used to produce it. Data
Integrity Contempor aneous Original Accurate Available Consistent Enduring Complete Attributable Legible
Analytical Quality Control Working Group IT Compliance Group Page 44 of 89 Analytical Quality Control
Working Group IT Compliance Group Page 45 of 89  Consistent: All elements of the primary analytical
record such as the sequence of events are in sequence and do not contradict each other (i.e. documented
chronologically). Data files are date (all processes) and time (when using paper, a hybrid or electronic
systems) stamped in the expected order.  Enduring: Recorded on authorised media e.g. laboratory
notebooks, numbered worksheets for which there is accountability or electronic media that can last
throughout the record retention period  Available: The complete collection of records can be accessed or
retrieved for review and audit or inspection over the lifetime of the record. These first five criteria were
developed initially by the FDA (ALCOA) and the additional criteria by the European Medicines Agency when
discussing integrity criteria for electronic source data from clinical studies ALCOA+ [Ref 23]. 7.2 Access /
Security/ Segregation of Duties Physical and/or logical controls should be in place to restrict access to
authorized persons for data managed electronically and manually. Systems must be configured in a way
that system operators who work with the system cannot change data or system settings (e.g. inactivate
audit trails, delete data, delete files, etc.). System Administrator rights (permitting activities such as data
deletion, database amendment or system configuration changes) should not be assigned to individuals with
a direct interest in the data (data generation, data processing, data review or approval). The role model
should be designed as such that no user has all access rights, e.g. the administrators should not be able to
delete audit trails (but maybe archive them). 7.3 Validation Validation must consider the intended use of
the data throughout its lifecycle. The validation of a computer system must address the implementation
and maintenance of the controls to enable integrity, including data entered manually or automatically
acquired. If records are transferred to another format, the qualification must include checks that the new
format has not altered the value or meaning nor context during the migration process. Validation should
address the necessary controls to ensure the integrity of data, including original electronic data and any
printouts or electronic reports from the system. In particular, the approach should ensure that Good
Documentation Practices will be implemented and that data integrity risks will be properly managed
throughout the data lifecycle. For critical systems, there should be an up-to-date system description (See
EU GMP Annex 11) detailing the physical and logical arrangements, and interfaces with other systems or
processes to identify data flows.  Ensure relationships between data and metadata are maintained intact
and traceable throughout data lifecycle. Analytical Quality Control Working Group IT Compliance Group
Page 46 of 89  SOPs and training; validation activities should ensure adequate training and procedures are
developed prior to release of the system for GMP use.  Configuration and design controls; the validation
activities should ensure configuration settings and design controls for good documentation practices are
enabled 7.4 Audit Trail Review One of the most controversial issues of Data Integrity is the Audit Trail
Review. 21 CFR Part 11 mentions the audit trail together with the requirements to establish the function
frequently, but without the need of its review. The 2011 version of the EU Annex 11 explicitly requires the
review of audit trails, but without providing any details. European Health Authority Inspectors specify the
Release of Batches by the QP as the most critical function, limiting the audit trail review on the QC/QA part
of the pharmaceutical value chain. Recent Warning Letters by the US FDA mention the lack of audit trail
review as one of the critical deficiencies when inspecting QC labs.

You might also like