The Quality System Gap Behind Most FDA Data Integrity Findings
- Jul 29
- 4 min read
Most data integrity findings are read as a people problem. A record was altered, a result was retested until it passed, an audit trail was switched off. It is tempting to treat each one as an isolated act by an individual who cut a corner. Inspectors rarely see it that way. When the same category of finding appears across very different sites, the common thread is not character. It is a quality system that never made honest data the easy path.

That is the gap. Data integrity findings cluster where the quality system delegated integrity to individual behaviour instead of designing it into how work is done, reviewed and governed. Understanding that shifts the response from disciplining people to fixing the system that let the problem happen. This is the difference between a site that keeps repeating the same 483 observation and one that closes it for good.
The gap is ownership, not honesty
Ask who owns data integrity at a site and the answer is often everyone, which in practice means no one. Quality assurance assumes the laboratory manages it, the laboratory assumes IT controls the systems, and IT assumes quality sets the rules. The gap sits in the space between those assumptions.
A quality system that prevents data integrity findings names an owner for the governance of data across its full lifecycle, from creation to disposal. That owner is accountable for the controls, the review process and the periodic assessment. Without a named owner, controls exist in fragments and no one is responsible for the whole. Inspectors notice the absence quickly, because the answers to their questions keep pointing somewhere else in the room.
Where the quality system gap becomes data integrity findings
The gap shows up in predictable places. Shared logins that make it impossible to attribute an action to a person. Audit trails that exist but are never reviewed, so a change could sit unnoticed indefinitely. System access that lets an analyst both run and delete a result. Paper records that are the true original while the electronic system is treated as a formality, or the reverse.
None of these require a dishonest employee to become a problem. They are structural weaknesses that make the wrong outcome possible and the right outcome harder than it should be. A GMP remediation effort that only retrains staff, without changing these structures, leaves the same gap open for the next inspection.
What inspectors actually expect
FDA expectations around data integrity are built on the ALCOA principles, that data be attributable, legible, contemporaneous, original and accurate, with the extension to complete, consistent, enduring and available. Inspectors do not expect a perfect record. They expect a system that makes each of these principles the default rather than a matter of goodwill.
That means access controls that tie every action to an identified user, audit trails that are switched on and genuinely reviewed, a defined understanding of what the original record is for each system, and a review process that looks at the data and its metadata together. Where a site can show these are designed in and monitored, an isolated error reads as an exception. Where they are absent, the same error reads as a symptom.
Closing the gap before an audit
Closing a data integrity gap is a quality system exercise, not a laboratory clean up. It starts with a data integrity assessment that maps every system that generates GMP data, identifies where records are created and stored, and tests each point against the ALCOA principles. From that map, the site can rank risks and prioritise the controls that matter most.
The steps that consistently close the gap are:
Assign clear ownership for data governance across the full data lifecycle.
Map every system and record, and define the original record for each.
Test each point against ALCOA and rank the gaps by risk.
Fix the structural controls: unique logins, appropriate access limits, audit trail review.
Build data and metadata review into routine batch and result approval.
Reassess periodically, so the system is governed rather than fixed once.
Sites that work through these in order stop treating each finding as a surprise. The controls are designed in, the review catches problems early, and the governance keeps the system honest as people and software change. That is what regulatory readiness looks like when data integrity is part of it.
Frequently asked questions
What is a data integrity finding?
A data integrity finding is an inspection observation that GMP data cannot be fully trusted, because it was not properly attributable, complete, contemporaneous, original or accurate. It can involve altered records, unreviewed audit trails, shared logins or unclear original records, and it undermines confidence in the decisions built on that data.
Are most data integrity findings caused by fraud?
No. Most trace back to structural weaknesses in the quality system, such as unclear ownership, weak access controls and audit trails that are never reviewed. These make the wrong outcome possible without requiring anyone to act dishonestly.
What are the ALCOA principles?
ALCOA stands for attributable, legible, contemporaneous, original and accurate, often extended to include complete, consistent, enduring and available. Regulators use these principles as the benchmark for whether data can be relied upon.
How can a site prevent data integrity findings?
By assigning clear ownership for data governance, mapping every system and its original records, testing each against ALCOA, fixing structural controls such as unique logins and audit trail review, and building data and metadata review into routine approval. The aim is a system that makes honest data the default.
Kieran Falvey is Founder and Managing Director of Pharmalliance Consulting Ltd and the creator of Contamination Control by Design (CCbD). He has more than 20 years designing, building and running pharmaceutical facilities worldwide, across FDA, EMA, TGA, PIC/S and Indian FDA (CDSCO) jurisdictions. Global expert in cGMP Compliance, Remediation and Contamination Control, helping Sterile, Non-Sterile, ATMP and Cosmetic companies navigate cGMP compliance issues.
Pharmalliance Consulting is a GMP compliance consultancy serving pharmaceutical, sterile, non-sterile, OSD, ATMP and cosmetic manufacturers in Ireland, the UK, the EU and the US. It helps sites identify and remediate GMP risks across facilities, quality systems and contamination control, aligned with HPRA, MHRA, EMA and FDA expectations, turning findings into defensible, inspection-ready practice.
If the same data integrity observations keep returning, the gap is in the system, not the people. Talk to Pharmalliance about GMP remediation or contact our team.




Comments