Data Integrity and the ALCOA+ Principles in GxP - GxP Compliance Framework
Data Integrity and the ALCOA+ Principles in GxP
(Chapter 7 of GxP Compliance Framework)
Executive Summary: Chapter Overview
IF4ITThe Bottom Line
Core Concepts
| Concept | Definition & Strategic Role |
|---|---|
| Data Integrity | The GxP requirement that recorded data be complete, consistent, and accurate throughout its entire lifecycle — from initial creation through final archiving or disposition. |
| ALCOA+ | The nine-principle framework — Attributable, Legible, Contemporaneous, Original, Accurate, Complete, Consistent, Enduring, Available — that regulators use to evaluate whether a given data record can be trusted as genuine evidence. |
| True Copy | A certified duplicate of an original record, verified to be an exact and complete reproduction, that GxP recognizes as an acceptable substitute for the original when the original itself is unavailable. |
| Data Lifecycle | The complete span of a data record’s existence — creation, processing, review, reporting, retention, and eventual archiving or destruction — across which ALCOA+ principles must hold continuously, not just at the moment of capture. |
Quick Q&A
Question: Why did ALCOA expand into ALCOA+?
Question: Does ALCOA+ apply only to electronic records, or to paper records too?
Read More Below
Overview
Data Integrity is the GxP requirement that every recorded data point — a test result, a batch record entry, a software configuration change — be trustworthy enough to stand on its own as evidence, without requiring anyone’s testimony to back it up. The industry-standard framework for evaluating this is ALCOA+: data must be Attributable, Legible, Contemporaneous, Original, and Accurate, and additionally Complete, Consistent, Enduring, and Available across its entire lifecycle.
This chapter builds directly on the previous two: “Standard Operating Procedures (SOPs): The Documented-Process Foundation of GxP” establishes what is supposed to happen; “Traceability and Audit Trails Across GxP Disciplines” proves what actually did happen. ALCOA+ defines the quality bar the resulting data itself must clear. Two of its principles will already feel familiar: Attributable and Contemporaneous are, in effect, those same traceability and audit trail requirements, restated as properties data itself must possess rather than properties of the system that captures it.
The ALCOA framework has a specific, traceable origin. It was coined by Stan W. Woollen of the FDA’s Office of Enforcement in the early 1990s, and formally articulated in FDA guidance titled Computerized Systems Used in Clinical Trials (FDA, April 1999). Around 2010, the framework was expanded to ALCOA+ with four additional principles — Complete, Consistent, Enduring, and Available — extending its focus from the moment of data capture to the data’s entire lifecycle. ALCOA+ is now referenced directly in FDA’s guidance Data Integrity and Compliance With Drug CGMP: Questions and Answers (FDA, December 2018), the UK’s GxP Data Integrity Guidance and Definitions (Medicines and Healthcare products Regulatory Agency, March 2018), and the World Health Organization’s Guidance on Good Data and Record Management Practices (WHO Technical Report Series No. 996, Annex 5, 2016) — making it a globally harmonized standard rather than an FDA-only expectation.
Understanding the Nine ALCOA+ Principles
| Principle | What It Requires |
|---|---|
| Attributable | The record clearly shows who performed the action or created the data, and when — no shared logins or unattributed entries. |
| Legible | The record is readable and permanent for its entire required retention period, whether handwritten, printed, or electronic. |
| Contemporaneous | The record is created at the time the activity is actually performed — not reconstructed or backfilled afterward. |
| Original | The record is the first capture of the data, or a verified True Copy, not a re-transcription or summary. |
| Accurate | The record correctly reflects what was actually observed or performed, free of undisclosed errors or alterations. |
| Complete | All data is present, including repeated or failed tests and any associated metadata — nothing selectively omitted. |
| Consistent | Data is recorded in a logical, chronological sequence with dates and, where relevant, timestamps that don’t conflict with each other. |
| Enduring | The record remains intact and unaltered for its full required retention period, not just until the next system upgrade. |
| Available | The record can be retrieved, reviewed, and reproduced on demand — including by an inspector — throughout its retention period. |
A record that fails even one of these nine principles is treated as unreliable evidence, regardless of whether the underlying result it describes was actually correct. This is a recurring theme across the domain-specific chapters later in this Framework — Clinical Development, Manufacturing, and Supply Chain each depend on ALCOA+-compliant data as the foundation their entire compliance posture rests on.

Best Practice: Advance Maturity Deliberately for GxP Data Integrity
Data integrity controls scale meaningfully with enterprise maturity, and organizations should advance deliberately rather than skip stages or over-invest before they’re ready.
At the Crawl stage, data integrity relies primarily on manual discipline and periodic self-inspection — staff are trained on ALCOA+ principles and expected to apply them consistently, with data integrity issues typically caught through scheduled internal audits rather than continuous monitoring. This is a legitimate starting point, but it depends heavily on individual diligence and carries real risk of undetected drift between audits.
At the Walk stage, organizations introduce structured data integrity checks into existing quality processes — periodic risk assessments targeting specific systems, documented data integrity self-inspection programs, and formal review checkpoints built into SOPs rather than relying solely on general staff training.
At the Run stage, data integrity is enforced by system design rather than by policy alone — validated computerized systems with built-in ALCOA+ controls (enforced unique logins, system-generated timestamps, locked audit trails), continuous data integrity monitoring rather than periodic sampling, and systematic trend analysis across audit trail data to proactively surface integrity risks before they become findings.
Organizations should know which stage their data integrity controls currently operate at, and treat advancement as a deliberate, resourced decision rather than something that happens automatically as systems age.
Best Practice
Build ALCOA+ verification into the design of every GxP-relevant process and system from the start, rather than treating it as a checklist applied after the fact. When evaluating any new tool, system, or process change, explicitly test it against all nine principles — a system that satisfies eight of nine still produces unreliable data in a regulator’s eyes. Never treat a “true copy” designation casually; verify and document that a copy is genuinely complete and accurate before relying on it in place of an original.
Benefit(s)
ALCOA+-compliant data gives an organization defensible evidence during inspection — the data speaks for itself rather than requiring staff to explain or reconstruct what “really” happened. It also catches quality problems earlier: a data integrity control designed around Consistency and Completeness often surfaces a process failure before that failure would otherwise be noticed. Finally, it protects the organization’s regulatory standing directly — data integrity findings are treated with particular severity by regulators precisely because they undermine confidence in every other record the organization has ever submitted, not just the one record in question.
How to cite this page
When referencing this page in academic work, internal standards, or external publications, include the page title, IF4IT as author and publisher (The International Foundation for Information Technology (IF4IT), LLC), the URL, and your access date.
Example (informal web citation):
The International Foundation for Information Technology (IF4IT), LLC. Data Integrity and the ALCOA+ Principles in GxP | GxP Compliance Framework. https://if4it.org/best-practices/gxp-compliance-framework/data-integrity-and-the-alcoa-principles-in-gxp/ (accessed 2026-09-08).
See About Us for content governance and site-wide citation guidance.
Copyright for The International Foundation for Information Technology (IF4IT), LLC: 2008 - Present
Legal Disclaimers