Laboratories · Data Integrity
Laboratory Data Integrity Consulting
The short answer
Laboratory data integrity is a question of whether every reported result can be reconstructed from complete, attributable, contemporaneous records. Findings almost never start as misconduct — they start with unreviewed audit trails, shared logins and a workload that makes shortcuts feel necessary.
Why this matters
- A data integrity finding calls the validity of prior results into question, which is why remediation scope expands so quickly.
- Chromatographic data systems are the highest-risk area because reprocessing, integration and injection sequencing are all discretionary acts.
- Controls that laboratories cannot sustain at real throughput will be bypassed, so review practice has to be designed around sample load.
Applicable regulations and standards
- 21 CFR 211.68 / 211.194
- Automatic equipment controls and complete laboratory records.
- 21 CFR Part 11
- Electronic records and signatures, audit trails and access controls.
- FDA Data Integrity and cGMP Guidance
- FDA's expectations for ALCOA attributes and audit trail review.
- MHRA GxP Data Integrity Guidance
- Widely used framework for data governance and criticality assessment.
What our consultants actually do
- Map data flows end to end — instrument, acquisition, processing, reporting, archive — for paper and electronic records
- Perform ALCOA+ gap assessment with criticality ranking so remediation is sequenced by risk
- Design audit trail review that is practical at your sample throughput, including what is reviewed by exception
- Correct system configuration: user roles, privileges, integration parameters, sequence and reprocessing controls
- Deliver training built on real laboratory scenarios rather than policy statements
- Lead or independently review remediation programs following a data integrity finding, including retrospective data review scoping
Across the product lifecycle
01 / DEVELOP
Method development data governed from the start, not retrofitted.
02 / SCALE
System configuration and roles reviewed as headcount grows.
03 / TRANSFER
Method transfer data handled under equivalent controls at both labs.
04 / VALIDATE
Computer system validation covering data lifecycle and audit trails.
05 / MANUFACTURE
Release and stability testing with contemporaneous recording.
06 / MAINTAIN
Periodic review, access recertification and audit trail metrics.
Problems we are usually called about
- Audit trails enabled but never reviewed, or reviewed only during investigations
- Shared analyst logins on standalone instruments
- Unofficial spreadsheets performing calculations outside the validated system
- Trial injections not documented, or sequences aborted without explanation
- Local administrator rights held by analysts who also process data
Typical deliverables
- Data flow maps and criticality assessment
- ALCOA+ gap assessment with risk-ranked remediation plan
- Audit trail review procedure and reviewer guidance
- System access and configuration remediation specification
- Scenario-based data integrity training and effectiveness assessment
Frequently asked
- How often must audit trails be reviewed?
- Audit trails that record GMP-relevant activity should be reviewed with the associated record — typically at result review — with a defined risk-based approach for what is reviewed routinely versus periodically. That approach must be documented and sustainable.
- Are standalone instruments acceptable?
- They can be, if user accounts are unique, data is protected from deletion, backups exist and audit trail functionality is enabled and reviewed. Standalone systems fail assessments because those controls are absent, not because they are standalone.
- What triggers a retrospective data review?
- Evidence that a control was absent or bypassed over a period, such as shared accounts or disabled audit trails. Scope should be defined by risk to product and patient, and the rationale documented before the review starts.
References
More for laboratories
GLP and GMP laboratory compliance, data integrity and analytical operations.
- GLP ComplianceGood Laboratory Practice under 21 CFR Part 58 governs nonclinical safety studies intended to support applications.
- GMP Laboratory ComplianceA GMP quality control laboratory is judged on laboratory controls: qualified instruments, validated methods, controlled reference standards, complete records and investigations that reach a conclusion.
- Method ValidationMethod validation demonstrates that an analytical procedure is suitable for its intended purpose.
Start a project
Tell us what you're working on.
Describe the product, the process or the problem. We will tell you honestly whether we are the right people to help, and who should be on the team if we are.