ALCOA+ — What FDA Finds When It Opens Your Data Integrity records
When an FDA investigator opens your laboratory data system during an inspection, the first thing they are not looking for is whether your results pass specification — they are looking…
On this pageArticle overview
When an FDA investigator opens your laboratory data system during an inspection, the first thing they are not looking for is whether your results pass specification — they are looking for whether your data can be trusted at all.

A facility can have a spotless batch release history and still receive a data integrity Warning Letter that invalidates product release decisions across its entire operation — because the investigator determined the underlying records cannot be authenticated. ALCOA+ is the evidentiary standard FDA applies when it decides whether your quality system’s outputs mean anything at all. Every batch record, every chromatographic run, every audit trail timestamp is either evidence of control or evidence of its absence.
What ALCOA+ Actually Requires: The Regulatory Standard Beyond the Acronym
The FDA’s 2018 Guidance for Industry: Data Integrity and Compliance with Drug CGMP linked each ALCOA+ principle directly to existing obligations under 21 CFR Part 211, making clear that ALCOA+ failures are not documentation cosmetics — they are CGMP violations. The widely accepted definition of ALCOA is Attributable (every entry identifies the specific individual who performed the action and when), Legible (data must be readable and permanent), Contemporaneous (recorded at the time of the activity, not reconstructed afterward), Original (the first capture of data or a certified true copy), and Accurate (free from errors and bias).
The “plus” elements — Complete, Consistent, Enduring, and Available — carry equivalent regulatory force and are routinely underweighted in internal gap assessments. Complete means no selective reporting: every result generated, including voided runs, out-of-trend results, and failed injections, must appear in the record with documented disposition. Consistent means the internal chronology is coherent — an analyst cannot log into a chromatography system at 09:14 if the laboratory notebook records sample preparation as beginning at 10:47. Enduring (retained in durable, unalterable form for the required retention period), and Available (accessible for review and inspection throughout the retention horizon)..
Under 21 CFR 211.180, GMP records must be retained for a minimum of one year after the expiration date of the batch or three years after the date of distribution, whichever is longer — and Available means those records must be retrievable in legible, complete form across the entire retention horizon. The MHRA’s 2018 GMP Data Integrity Definitions and Guidance for Industry reinforced a principle FDA has adopted operationally: data integrity cannot be achieved by procedure alone. An organization can write a rigorous data integrity SOP and still fail an inspection because the system architecture permits unattributed entries or because the primary record designation in a hybrid paper-electronic system was never formally defined.
The Six Most-Cited ALCOA+ Failures in FDA Inspections and Warning Letters
Of the nine ALCOA+ principles, non-contemporaneous documentation generates more Warning Letter citations than any other [1] , and the mechanism is consistent: an analyst performs a test, records results in an uncontrolled scratch document, and transfers them into the official GMP system hours or days later. The FDA’s 2018 data integrity guidance makes clear that entries made after the fact, even when accurate, fail the contemporaneous standard because there is no way to authenticate that the recorded result reflects what actually occurred at the time of the activity. When metadata timestamps show a data entry at 16:32 on a Friday for a test the logbook records as completed Wednesday morning, the investigator does not need additional evidence — the inconsistency is the finding.
Shared instrument logins represent a second high-frequency failure that persists years after 21 CFR Part 11 remediation programs were supposed to have eliminated them. Under 21 CFR Part 11, electronic records must be maintained under systems that assign each individual a unique identifier, and electronic signatures must be linked to their respective records so as to render them forgeable only through the participation of two or more individuals. A single user ID shared among an analytical team of eight produces records that are non-attributable by definition, and FDA treats that as a systemic failure that calls every result generated under that login into question.
The six most-cited ALCOA+ failure patterns that recur consistently across facility types are:
Non-contemporaneous documentation – entries made after the fact from uncontrolled scratch documents, creating timestamp inconsistencies.
Shared instrument logins – generic or group accounts that make records non-attributable under 21 CFR Part 11.
Electronic raw data deleted or overwritten without audit trail capture – permanent loss of original records.
Laboratory notebooks used alongside electronic systems with no defined primary record designation – hybrid system ambiguity that destroys record authenticity.
Audit trails that are technically present but never reviewed as part of routine QA oversight – compliant architecture with zero operational monitoring.
System clocks not synchronized across instruments and servers – metadata inconsistencies that invalidate contemporaneity across entire datasets.
Each is an independent ALCOA+ violation, but in combination they produce a data integrity profile an FDA investigator will characterize as systemic rather than isolated. A systemic characterization in a Form 483 escalates to Warning Letter territory and, depending on the scope of affected records, triggers a product-by-product retrospective data review.
Data Falsification and Manipulation – The Most Egregious Class of Violations
Data falsification and manipulation represent the most severe and frequently cited violations in FDA warning letters, signaling an intent to hide or alter unfavorable results. Common examples include “testing into compliance” — running preliminary or “trial” analytical injections to see if a sample passes specifications, then deleting the initial runs and only reporting the final passing result. Other typical findings include the unauthorized deletion or alteration of electronic raw data without proper justification or audit trail capture, as well as backdating and falsifying records. When a warning letter includes findings of data falsification, the evidentiary weight against the facility’s entire quality system increases substantially — because intent undermines any claim that integrity failures were merely procedural or inadvertent.
FDA explicitly treats falsification as a systemic rather than an isolated issue. In one recent warning letter, the agency noted that “company analysts deleted and manipulated data in order to make it appear that drugs were meeting specifications.” When such practices are identified, the agency typically requires a comprehensive review of all data records, a risk assessment of the potential effects on product quality, and a global corrective action and preventive action plan covering the entire facility’s operations. A facility that cannot rule out intentional data manipulation has lost the foundational assumption of data integrity — and FDA will require it to rebuild that evidentiary chain from the ground up, often at a cost measured in years of remediation and millions of dollars.
Why Electronic Systems Create New ALCOA+ Vulnerabilities Your SOPs Don’t Address
The transition to electronic laboratory systems was framed as a data integrity improvement — and architecturally it was, provided those systems were configured with compliant audit trails, enforced user authentication, and locked raw data files. The problem is that most GMP electronic systems were designed around operational efficiency, with ALCOA+ requirements retrofitted through SOPs rather than through system configuration. The result is a generation of LIMS, chromatography data systems, and manufacturing execution systems that are 21 CFR Part 11 compliant on paper but operationally non-compliant because audit trails are unreviewed, user authentication is not enforced at the instrument level, and raw data file architecture permits overwriting.
Under ICH Q10, the Pharmaceutical Quality System is expected to include a data governance framework establishing accountability for data integrity across the product lifecycle. In most facilities, that governance was never formally scoped as a QMS element — it exists as a fragmented collection of Part 11 SOPs, instrument validation reports, and access management procedures written at different times by different functions and never integrated into a coherent architecture. An FDA investigator trained in forensic data review does not read your SOPs first — they open your audit trail, check user IDs, and look at timestamps, and if what they find is inconsistent with your paper records, the SOP is irrelevant.
The Instrument Logbook: The Missing Link Between Equipment, Data, and Second-Person Review
An ALCOA+ framework that focuses exclusively on electronic audit trails and laboratory notebooks misses a critical piece of the data integrity architecture: the instrument logbook. Under 21 CFR 211.182 , a written record of major equipment cleaning, maintenance, and use must be maintained in individual equipment logs, showing the date, time, product, and lot number of each batch processed, with entries in chronological order and double-checked by a second person.[reference:3]
EU GMP Chapter 4.31 similarly requires logbooks for major or critical analytical testing and production equipment, recording any use, calibrations, maintenance, cleaning, or repair operations in chronological order, including the dates and identity of personnel.[reference:4]
The logbook is the essential link between the instrument and the work performed—qualification and requalification, routine operation, repairs, and preventative maintenance.[reference:5] It is the physical trace that a second-person reviewer uses to verify that the data attributed to an instrument on a given date and time is consistent with the instrument’s documented use and maintenance history.
A second-person reviewer who finds a chromatographic run timestamped at 09:14 but an instrument logbook showing a calibration failure at 08:30 or a maintenance operation covering that same timeframe has identified a data integrity gap that a standalone audit trail review would miss.[reference:6] The FDA and EU requirements for second-person verification of the logbook itself are not optional—they are the mechanism that ensures data integrity is not merely asserted but evidenced.
The XGene ALCOA+ Diagnostic Framework has been expanded to include a fifth step: Instrument Logbook Integrity Verification . For every GMP-critical instrument, verify that a controlled, paginated logbook exists, that entries are chronological and attributable, that the logbook is reviewed by a second person at a defined frequency, and that the logbook content is consistent with electronic metadata timestamps from the instrument’s data system. Without this verification, any claim of data integrity is incomplete.
▣ FRAMEWORK BOX: Building an ALCOA+ Audit Program That Survives a Forensic FDA Data Review
The XGene ALCOA+ Data Integrity Diagnostic Framework is an 8-point structured assessment that evaluates data integrity architecture as an evidentiary system — not as a compliance checklist — producing a Data Integrity Risk Register with prioritized remediation actions mapped to specific CFR and guidance citations.
The output of the XGene ALCOA+ Diagnostic is not a gap list — it is a Data Integrity Risk Register that assigns each finding a severity tier, maps it to the applicable CFR subsection or guidance reference, and specifies the exact remediation action, system configuration change, or retrospective data review required to close the exposure before an FDA investigator finds it.
The cost of a data integrity Warning Letter is not measured in remediation budget alone — it is measured in consent decree risk, import alert exposure, commercial distribution disruption, and the reputational consequence of a public finding that your quality system’s outputs cannot be trusted. Companies that receive these letters did not lose control of their data on the day of the inspection; they lost it incrementally through system architecture decisions and audit trail review gaps that accumulated undetected over years. Addressing ALCOA+ as a system property rather than a documentation property is the only intervention that closes the structural exposure. (For the foundational CMC quality system framework within which data integrity operates, see the XGene Practitioner Intelligence series — W01.)
Open the audit trail for any five recent batch release records in your LIMS and check whether every data entry, edit, and voided run has an attributed user ID, timestamp, and documented reason — if any entry is missing any of these three elements, you have an ALCOA attributability gap that an FDA investigator will find.
