FDA Data Integrity Guidance and CGMP Compliance

The FDA data integrity guidance requires every piece of manufacturing and testing data a drug maker generates to be attributable, legible, contemporaneous, original, and accurate — the ALCOA principles — and to stay that way from the moment it is captured until it is disposed of.1Food and Drug Administration. Data Integrity and Compliance With Drug CGMP Questions and Answers These expectations sit inside the CGMP regulations at 21 CFR Parts 210, 211, and 212, and they apply to any firm making drugs for the U.S. market, wherever the facility is located. Violations have led to warning letters, import alerts, consent decrees, and criminal prosecution.

What the FDA Means by Data Integrity

The FDA defines data integrity as the completeness, consistency, and accuracy of data throughout its lifecycle — creation, use, retention, archival, and disposal.1Food and Drug Administration. Data Integrity and Compliance With Drug CGMP Questions and Answers The definition is deliberately broad because it has to cover everything from an analyst’s notebook entry to a chromatography data file. Every number in a batch record, every test result, every audit-trail entry has to be trustworthy enough for the agency to rely on it when deciding whether a drug is safe and effective.

The requirements apply the same way to paper and electronic records. A firm cannot avoid scrutiny by staying on handwritten logbooks; the regulatory expectations do not change with the medium. The underlying rules are codified at 21 CFR Part 211 for finished pharmaceuticals and Part 212 for PET drugs, and the FDA has said the same principles are consistent with CGMP guidance for active pharmaceutical ingredients.2eCFR. 21 CFR Part 211 – Current Good Manufacturing Practice for Finished Pharmaceuticals

The ALCOA+ Principles

The FDA’s expectations for data quality are captured in ALCOA+: five foundational attributes plus four that address modern data management. Together they define what trustworthy regulated data looks like.3FDA. Quality Essentials: Inspectional Coverage of QMS and Data Integrity

Metadata, Static and Dynamic Records, and True Copies

A data point on its own is meaningless. The number “23” tells you nothing without the unit of measurement, who recorded it, when, and on which instrument. The FDA calls that surrounding context metadata, and firms must preserve the relationship between data and its metadata for the entire retention period so any CGMP activity can be reconstructed later.1Food and Drug Administration. Data Integrity and Compliance With Drug CGMP Questions and Answers

The guidance also distinguishes static from dynamic records. A static record is fixed, like a paper printout or scanned image. A dynamic record lets the user interact with the content — a chromatography file where baselines can be adjusted and peaks reprocessed is the classic example. A printed copy of a dynamic record does not satisfy retention requirements, because printing strips out the very capability that made the original meaningful. An FT-IR spectral file, for instance, can be reprocessed; a printout cannot. When the original is dynamic, firms must keep it in its native electronic format or as a true copy that preserves the dynamic content.1Food and Drug Administration. Data Integrity and Compliance With Drug CGMP Questions and Answers If a chromatogram is reprocessed, every version has to be kept, not just the final result.

When a firm cannot retain the original — or needs a copy elsewhere — the copy must be a certified true copy: an exact replica containing the same information and attributes as the original, confirmed by a dated signature.4U.S. Food and Drug Administration. Guidance for Industry – Computerized Systems Used in Clinical Trials For dynamic electronic records, the copy has to preserve the original format or the ability to reconstruct content and meaning, and suitable reader and copying equipment must be readily available.1Food and Drug Administration. Data Integrity and Compliance With Drug CGMP Questions and Answers

Electronic Systems and 21 CFR Part 11

Data that lives in a computer system pulls in a second layer of regulation. 21 CFR Part 11 sets the criteria for electronic records and electronic signatures to be considered trustworthy and equivalent to paper.5eCFR. 21 CFR Part 11 – Electronic Records; Electronic Signatures Four controls do most of the work.

System Validation

Every computerized system used for regulated activities must be validated to confirm it works as intended: producing accurate results, performing consistently, and detecting invalid or altered records.5eCFR. 21 CFR Part 11 – Electronic Records; Electronic Signatures Validation is not one and done. Whenever the system changes, validation status has to be re-established through fresh analysis and regression testing.6Food and Drug Administration. General Principles of Software Validation

Access Controls and Electronic Signatures

System access must be limited to authorized users, each with a unique identification code and password. Shared credentials are one of the most frequently cited inspection deficiencies because they destroy attribution.5eCFR. 21 CFR Part 11 – Electronic Records; Electronic Signatures Authority checks have to ensure users can only reach functions appropriate to their role; an analyst should not have administrator rights to delete records. Electronic signatures must use at least two distinct identification components, such as a user ID paired with a password, to carry the same weight as a handwritten signature.

Audit Trails

Audit trails are where integrity becomes verifiable. The rule requires secure, computer-generated, time-stamped audit trails that independently record every action creating, modifying, or deleting an electronic record, and changes must not obscure the previously recorded entry.7eCFR. 21 CFR 11.10 – Controls for Closed Systems Audit trail records have to be retained at least as long as the electronic records they document, and they must be available for FDA review and copying. An HPLC audit trail, for example, should capture the user name, the date and time of each run, the integration parameters used, and any reprocessing details.1Food and Drug Administration. Data Integrity and Compliance With Drug CGMP Questions and Answers

Backup and Protection

Electronic records must be protected so they can be retrieved accurately throughout retention.5eCFR. 21 CFR Part 11 – Electronic Records; Electronic Signatures Under CGMP, backup files must be maintained and must be exact, complete, and secure from alteration, inadvertent erasure, or loss.8eCFR. 21 CFR 211.68 – Automatic, Mechanical, and Electronic Equipment Firms also have to be able to generate accurate, complete copies in both human-readable and electronic formats for FDA inspection.

How Long Records Must Be Kept

For finished pharmaceuticals, production, control, and distribution records for a specific batch must be retained for at least one year after the batch’s expiration date.9eCFR. 21 CFR 211.180 – General Requirements Certain over-the-counter products exempt from expiration dating carry a longer default: three years after batch distribution.

Medical device manufacturers work off a different formula. Under 21 CFR Part 820, records must be retained for a period equivalent to the design and expected life of the device, with a two-year floor from the date of commercial release.10eCFR. 21 CFR 820.180 – General Requirements For an implantable device with a 10-year expected life, that means a decade of records.

Retention alone is not enough. Records have to remain accessible and readable across the entire window. Data stranded on obsolete media or inside a decommissioned system is, from a compliance standpoint, lost.

Vendors, Contract Labs, and Cloud Providers

Outsourcing data storage or lab work does not outsource regulatory responsibility. The FDA’s guidance treats cloud infrastructure as part of the “computer or related systems” covered by CGMP, and it holds the manufacturer accountable for the integrity of all data regardless of who hosts or processes it.1Food and Drug Administration. Data Integrity and Compliance With Drug CGMP Questions and Answers

Firms using third-party IT platforms, contract labs, or contract manufacturers need quality agreements that spell out data integrity responsibilities: backup and security, documentation timing, record retention, completeness, review procedures, and audit trail requirements. The FDA points firms to its separate guidance on contract manufacturing quality agreements for expectations on auditing contract facilities.1Food and Drug Administration. Data Integrity and Compliance With Drug CGMP Questions and Answers If the vendor’s system cannot produce the audit trails, access controls, and backups CGMP demands, using it creates a compliance gap that belongs to the manufacturer.

Management, Training, and Reporting Falsification

Data integrity failures are rarely purely technical. The FDA’s guidance places direct responsibility on management to build and resource a quality system that prevents them: adequate staffing, functional equipment, training, and a workplace culture where people report errors honestly instead of hiding them.1Food and Drug Administration. Data Integrity and Compliance With Drug CGMP Questions and Answers

Unrealistic production quotas and punitive responses to mistakes are the two biggest cultural drivers of data falsification. When an analyst knows a failed test will trigger a shift-long investigation and possible discipline, adjusting the result becomes tempting. The FDA recommends eliminating those incentives and setting up anonymous reporting channels so employees can flag potential breaches without fear of retaliation.1Food and Drug Administration. Data Integrity and Compliance With Drug CGMP Questions and Answers

Training is a regulatory requirement. Every person involved in manufacturing must receive continuing CGMP training tied to their specific functions, conducted by qualified individuals with enough frequency to keep employees current.11eCFR. 21 CFR 211.25 – Personnel Qualifications For data integrity specifically, that means documentation practices, audit trail expectations, and the consequences of shortcuts.

When a firm receives a tip or internal complaint about possible falsification, the FDA expects a full investigation inside the documented CGMP quality system. Handling reports informally, outside the system, is unacceptable.1Food and Drug Administration. Data Integrity and Compliance With Drug CGMP Questions and Answers The investigation has to assess impact on patient safety, product quality, and data reliability, identify root cause, and drive corrective action. Individuals who want to report concerns directly to the agency can email DrugInfo@fda.hhs.gov with “CGMP data integrity” in the subject line.

What Enforcement Looks Like

The FDA enforces data integrity requirements through facility inspections. When an investigator observes conditions that may violate the FD&C Act or CGMP regulations, they issue a Form FDA 483 at the close of the inspection listing the specific deficiencies.12U.S. Food and Drug Administration. FDA Form 483 Frequently Asked Questions A 483 is not a final determination that a violation occurred, but firms are strongly encouraged to respond in writing with a corrective action plan within 15 business days.

If the response is inadequate, or the violations serious enough, the FDA escalates to a Warning Letter, which gives firms 15 days from receipt to respond in writing.13U.S. Food and Drug Administration. Inspections, Compliance, Enforcement, and Criminal Investigations Follow-up inspections check whether the promised corrections actually got made.14U.S. Food and Drug Administration. Types of FDA Inspections

Import Alerts

For foreign manufacturers, data integrity findings can trigger an import alert with detention without physical examination. Every shipment from a listed firm is automatically detained and refused entry unless the importer can affirmatively show the products do not have the violations described in the alert.15U.S. Food and Drug Administration. Import Alerts Removal from the list requires proving the underlying problems have been resolved, which can take months or years. The FDA can also pursue product seizure and deny or delay approval of pending drug applications.

Consent Decrees and Criminal Penalties

The FDA has explicitly identified consent decrees as a data integrity enforcement tool.1Food and Drug Administration. Data Integrity and Compliance With Drug CGMP Questions and Answers A consent decree is a court-supervised agreement that typically forces a firm to halt manufacturing, bring in independent experts, and demonstrate compliance before resuming operations.

Data falsification can also cross into criminal territory. Under 21 U.S.C. § 333, a first-time violation of the FD&C Act’s prohibited acts carries up to one year in prison and a $1,000 fine. If the violation involves intent to defraud or mislead, which deliberate falsification almost always does, the maximum rises to three years in prison and a $10,000 fine.16Office of the Law Revision Counsel. 21 USC 333 – Penalties For knowing and intentional adulteration that creates a reasonable probability of serious health consequences or death, the ceiling is 20 years in prison and a $1,000,000 fine.

Fixing a Data Integrity Failure

Patching the specific finding an inspector cited is never enough. The FDA expects a comprehensive retrospective assessment: how far back the problem extends, which products are affected, and whether any release decisions rested on compromised data. Remediation has to include root cause analysis and a CAPA plan that addresses the systemic conditions, not just the individual instance.

Recommended strategies include retaining a third-party auditor, creating anonymous reporting mechanisms, and establishing data governance roles and guidelines, with documented evidence of the systemic changes provided to the agency.1Food and Drug Administration. Data Integrity and Compliance With Drug CGMP Questions and Answers The quality unit should be routinely reviewing production records, audit trails, and laboratory data on an ongoing basis, so problems surface before the next inspection does.2eCFR. 21 CFR Part 211 – Current Good Manufacturing Practice for Finished Pharmaceuticals Firms that treat remediation as a paperwork exercise tend to end up with a second warning letter, or something worse.