ALCOA+ principles (ALCOA Plus) are the nine data integrity attributes GMP authorities expect for every quality-relevant record: Attributable, Legible, Contemporaneous, Original, Accurate, plus Complete, Consistent, Enduring and Available. This is not an abstract concept: MHRA, PIC/S, FDA and WHO all reference it in their guidance documents, and inspectors use it as a practical grid to assess batch records, laboratory notebooks, chromatography data and audit trails. In this article we look at what each principle means, where it is formalised, and the failures that most often end up as inspection findings.
What the ALCOA+ principles mean for GMP data integrity
The ALCOA acronym originated within FDA in the 1990s as a summary of good documentation practices, and was later adopted by the main international data integrity references. The "Plus" version extends the five historical attributes with four additional ones, made explicit for example in PIC/S PI 041-1 (§7.4): Attributable, Legible, Contemporaneous, Original and Accurate are joined by Complete, Consistent, Enduring and Available.
The essential point, often misunderstood: ALCOA+ is not just about computerised systems. It applies to paper, electronic and hybrid records, across the entire data lifecycle — from generation through recording, processing and retention to controlled destruction. A lab notebook filled in with pencil breaches ALCOA+ just as much as a shared login on a CDS with the audit trail switched off.
The five ALCOA principles
- Attributable: it must always be clear who generated the data or performed the action, and when. In practice: signatures and initials traceable to identified people, named user accounts, no shared logins.
- Legible: data must remain readable and unambiguous for the whole retention period. Corrections are made with a single line, dated and signed, without obscuring the original value.
- Contemporaneous: recording happens at the time the activity is performed. Writing up a "fair copy" at the end of the shift, or backdating a check, is a classic violation.
- Original: keep the first-capture record (raw data) or a verified true copy, not a transcription. For electronic systems this includes metadata and acquisition files, not just the PDF report.
- Accurate: data faithfully reflects what happened, with no unjustified modifications; calibrated instruments, validated methods and second-person verification support accuracy.
The four "Plus" attributes
- Complete: all generated data is part of the record, including repeats, reprocessing and rejected results with their justification. The classic non-conformity is "testing into compliance" with undocumented trial injections.
- Consistent: the sequence of records is logical and chronologically ordered (synchronised date/time stamps, no unexplained gaps in sample or page numbering).
- Enduring: data is recorded on controlled media and preserved so that it survives the full retention period — no sticky notes, loose sheets or unmanaged rewritable media.
- Available: data can be retrieved and reviewed whenever needed — for reviews, investigations and inspections — even after system migrations or software retirement.
If you work in QA, QC or CSV, something touching data integrity changes almost every week: subscribe to The Pragmatic GMP, GuideGxP's free weekly newsletter, to get regulatory updates and practical tools straight to your inbox.
The 9 principles at a glance: key question and GMP examples
| Principle | Key question | Operational example |
|---|---|---|
| Attributable | Who did it, and when? | Named CDS accounts, signatures recorded in the initials log |
| Legible | Can it be read today and in 10 years? | Single-line correction with date, initials and reason |
| Contemporaneous | Was it recorded at the time? | Weight recorded at the balance, not reconstructed at end of shift |
| Original | Is it the first-capture record? | Acquisition files and metadata retained, not just the PDF report |
| Accurate | Does it reflect what happened? | Calibrated instrument, double-checked calculations |
| Complete | Is everything there, including what was rejected? | Analytical repeats documented with justification |
| Consistent | Is the sequence logical and ordered? | Synchronised system clocks, complete injection sequences |
| Enduring | Will it survive the retention period? | Verified backups, controlled notebook archive |
| Available | Can it be retrieved when needed? | Data still readable after system migration |
Where they are formalised: MHRA, PIC/S, FDA and WHO
Anyone defending their system in an audit should know four main references. The MHRA "GXP Data Integrity Guidance and Definitions" (Revision 1, March 2018) defines the key terms — raw data, metadata, audit trail, data lifecycle — and is the most cited document for definitions. PIC/S PI 041-1 "Good Practices for Data Management and Integrity in Regulated GMP/GDP Environments" (1 July 2021) is the most complete operational reference for inspectorates: it explicitly lists the nine ALCOA+ attributes and dedicates specific chapters to paper-based systems, computerised systems and outsourced activities. FDA consolidated its position in the guidance "Data Integrity and Compliance With Drug CGMP: Questions and Answers" (December 2018), in Q&A format. Finally WHO, with its "Guideline on data integrity" (TRS 1033, Annex 4, 2021), updated its approach in line with ALCOA+ and risk management.
Within the EU GMP framework, these requirements interlock with Chapter 4 (documentation) and Annex 11 for computerised systems: audit trails, access management and periodic data review are where ALCOA+ becomes a verifiable requirement. For a hands-on approach to audit trail review, see our audit trail review checklist.
The most frequent inspection findings
- Shared or generic user accounts on laboratory instruments and production systems: the data stops being attributable.
- Audit trails disabled or never reviewed: the system records, but nobody looks; in an inspection this equals a non-existent control.
- Non-contemporaneous records: scratch sheets, end-of-day transcriptions, inconsistent dates across linked documents.
- Incomplete data: trial injections, rejected results without justification, electronic recycle bins full of "test" files.
- Administrator rights for operational users: whoever generates the data can also modify or delete it, with no segregation of duties.
GuideGxP recommendation
Do not treat ALCOA+ as a poster to hang in the lab. The most effective way to use it is to turn the nine principles into verification questions inside your existing processes: in the data integrity risk assessment of your systems, in the self-inspection checklist, in periodic audit trail review and in initial staff training. Three practical moves to start: map your GMP-critical systems and data flows, classify the gaps against the nine attributes, and define a risk-based remediation plan with owners and deadlines. And remember that data integrity is first of all a matter of culture and governance: if management measures only productivity, pressure on data follows.
To move from theory to operations, our operational guide "Data Integrity in GMP" — governance, audit trail review and QC laboratories includes ready-to-use tools to build a data integrity programme you can defend in audit.
Official sources
- MHRA — 'GXP' Data Integrity Guidance and Definitions, Revision 1 (March 2018)
- PIC/S PI 041-1 — Good Practices for Data Management and Integrity in Regulated GMP/GDP Environments (1 July 2021)
- FDA — Data Integrity and Compliance With Drug CGMP: Questions and Answers (December 2018)
- WHO — Guideline on Data Integrity, TRS 1033 Annex 4 (2021)