What is data integrity?

Data integrity is the extent to which data remains complete, consistent, accurate and traceable throughout its entire lifecycle, so that it is reliable enough to support decisions on product quality, safety or billing. In regulated environments under GxP, data integrity is assessed against the ALCOA+ principles. For OT this boils down to a few simple questions: who recorded a value, exactly when, is it the original, and could anyone have changed it without being noticed?


🧠 What do ALCOA, ALCOA+ and ALCOA++ mean?

The acronym ALCOA was coined in the early 1990s by Stan Woollen, then an inspector at the US FDA, as a memory aid for judging data quality during inspections. The European Medicines Agency (EMA) added four principles in 2010, in a reflection paper on electronic source data in clinical trials, giving ALCOA+. The EMA guideline on computerised systems in clinical trials, published in 2023, makes traceability explicit, which is commonly referred to as ALCOA++.

Principle Meaning OT example
Attributable Every record can be linked to a person or system Personal login on the HMI instead of a shared β€œoperator” account
Legible Data stays readable and understandable Units and tag descriptions are stored with every value in the historian
Contemporaneous Recorded at the time of the action A batch step is logged by the system immediately, not written on paper afterwards
Original The first record, or a certified true copy Raw sensor values are kept, not just averages
Accurate Correct and free from errors Calibrated instruments and validated calculations
Complete All data, including repeats and metadata Aborted batches and repeated measurements remain in the system
Consistent Logical, chronological sequence Timestamps of the PLC, historian and MES are synchronised
Enduring Retained for the full retention period Archive on managed storage, not on the local drive of an operator PC
Available Accessible for review and inspection Batch report and audit trail can be produced within a reasonable time
Traceable (++) Every change can be traced through metadata The audit trail shows old value, new value, who, when and why

πŸ“œ Which regulations and guidance apply to data integrity?

Data integrity is not a single law but an expectation set out in several guidance documents:

Document Issued by Year Focus
21 CFR Part 11 FDA 1997 Electronic records and electronic signatures
EU GMP Annex 11 European Commission 2011 Computerised systems in pharmaceutical manufacturing
GXP Data Integrity Guidance and Definitions MHRA (UK) 2018 Definitions, data criticality and a risk-based approach
Data Integrity and Compliance With Drug CGMP FDA 2018 18 questions and answers on audit trails, access and validation
PI 041-1 PIC/S 2021 Inspector guidance for GMP and GDP environments, in force since 1 July 2021
TRS 1033, Annex 4 WHO 2021 Global guideline on data integrity

On 7 July 2025 the European Commission and PIC/S published draft revisions of Annex 11 and Chapter 4 (Documentation), plus a new Annex 22 on artificial intelligence; the consultation ran until October 2025. Under the draft, audit trail review becomes part of routine data review rather than a separate, periodic check.


πŸ”„ What does the data lifecycle look like?

Data integrity does not only matter at the moment of recording; it applies to every phase:

  • Creation β€” a sensor, operator or instrument generates a value
  • Processing β€” the PLC, SCADA system or a calculation transforms the value
  • Transfer β€” data moves from OT to MES, LIMS or ERP through interfaces
  • Review and release β€” a second person checks batch data and the audit trail
  • Archiving β€” data is retained for the statutory retention period, including backups
  • Destruction β€” controlled and documented deletion once the period ends

Every transfer is a point of risk: an interface that rounds values or converts time zones incorrectly undermines integrity without anyone noticing.


⚠️ Which data integrity failures are common in OT?

Inspectors keep finding the same patterns on the factory floor:

  • Shared logins on HMIs β€” one account for the whole shift makes attribution impossible
  • Disabled audit trails β€” switched off to save performance or β€œbecause it was a nuisance”, leaving changes untraceable
  • Unsynchronised clocks β€” PLCs and servers without NTP drift minutes apart, so the order of events no longer adds up
  • Deleting trial injections β€” in laboratories, test runs were made and discarded until the desired result appeared; during a 2013 inspection at Sun Pharma, the FDA found more than 5,300 deleted chromatograms
  • Export via USB sticks β€” data is copied into Excel and edited there, outside any control; USB control helps to prevent this
  • Administrator rights for everyone β€” operators can change settings or data themselves

πŸ” How does data integrity relate to cybersecurity?

In the CIA Triad, the I stands for integrity: protection against unauthorised modification. Data integrity in the GxP sense is broader, because it also covers human error, poor procedures and missing context. Even so, the two disciplines reinforce each other.

IEC 62443-3-3 addresses integrity in FR3 System Integrity, including SR 3.1 (communication integrity) and SR 3.4 (software and information integrity). FR2 contains SR 2.8 (auditable events) and SR 2.11 (timestamps). Stuxnet, which covertly drove frequency converters while showing operators recorded normal values, shows that a loss of integrity in OT can have direct physical consequences. Central logging and access control therefore serve both compliance and IEC 62443 security.


🏭 Is data integrity only relevant to pharma?

No. The pharmaceutical sector faces the strictest scrutiny, but the same principles apply elsewhere:

  • Food β€” temperature records at critical control points under HACCP must be complete and attributable
  • Energy metering β€” instruments under the European Measuring Instruments Directive (MID, 2014/32/EU) must protect legally relevant software and data; WELMEC Guide 7.2 sets out how, including an event logger
  • Production performance β€” an OEE figure is only meaningful if downtime reasons are entered completely and promptly; reasons filled in by hand at the end of the shift are a classic integrity problem
  • Environment and emissions β€” emission measurements for permits require original, unaltered data

πŸ› οΈ How do you assess data integrity on a production system?

  1. Map the data flows β€” which data is created where, and which decisions rely on it (batch release, billing, reporting)?
  2. Determine criticality β€” data that determines product quality or safety gets the strictest controls
  3. Check each system against ALCOA+ β€” use the table above as a checklist for the HMI, historian, MES and LIMS
  4. Review access and roles β€” personal accounts, separation between operator and administrator, no shared passwords
  5. Review the audit trail β€” is it enabled, protected against modification and reviewed regularly?
  6. Check time synchronisation β€” all systems synchronised via NTP to one trusted time source, with monitoring for drift
  7. Assess interfaces and exports β€” are values passed on unchanged during transfer?
  8. Embed it in procedures β€” change management, backup and restore tests, and a periodic audit

❓ Frequently asked questions

What does ALCOA stand for?

ALCOA stands for Attributable, Legible, Contemporaneous, Original and Accurate. The acronym was coined at the FDA in the early 1990s as a tool for inspectors. ALCOA remains the foundation of data integrity in regulated industries today.

What is the difference between ALCOA+ and ALCOA++?

ALCOA+ adds four principles to the original five: Complete, Consistent, Enduring and Available. ALCOA++ adds Traceable, so that every change can be traced through metadata and an audit trail. Both variants are used in the pharmaceutical sector as a framework for assessing data integrity.

What is an audit trail?

An audit trail is a secure, system-generated log that records who created, changed or deleted which data, when, and why. For data integrity the audit trail is essential, because it makes changes traceable. Missing or disabled audit trails are among the findings the FDA cites most often in data integrity warning letters.

Is data integrity the same as integrity in the CIA triad?

Not quite. In the CIA triad, integrity means protection against unauthorised modification, mainly by attackers. Data integrity in the GxP sense also covers completeness, context, timeliness and human error, which makes it broader than information security alone.

Why is time synchronisation important for data integrity?

Without synchronised clocks, timestamps from the PLC, historian and MES do not line up, so the sequence of events cannot be reconstructed. That breaches the Contemporaneous and Consistent principles of ALCOA+. Synchronising via NTP to a trusted time source is therefore a basic data integrity control.

Does data integrity apply outside the pharmaceutical industry?

Yes. Data integrity also matters in the food industry, in energy metering under the Measuring Instruments Directive, and for production performance metrics such as OEE. Wherever decisions or billing rely on data, that data must be complete, accurate and traceable.


πŸ“Œ In summary

Data integrity ensures that production data stays complete, accurate and traceable from sensor to archive, assessed against the ALCOA+ principles. In OT it comes down to personal accounts, active audit trails, synchronised clocks and controlled interfaces: measures that strengthen compliance and cybersecurity at the same time.