Data Integrity & CSV

Data Integrity Risk Assessment Template (DIRA) Guide

A data integrity risk assessment (DIRA) is the documented evaluation that maps GxP data flows, rates their criticality and vulnerability, and defines proportionate controls. Template structure, step-by-step completion and typical mistakes per PIC/S PI 041-1, MHRA and FDA.

G GuideGxP 4 min read
✓ Official sources and references ✓ Practical approach ✓ For pharmaceutical professionals
GUIDEGXP · PRACTICAL GMP INSIGHTS
Illustrazione editoriale GuideGxP a colori sul tema GMP: data integrity risk assessment con matrice di rischio e flussi di dati di laboratorio.

Data integrity risk assessment (DIRA): three words that appear more and more often in FDA, EMA and MHRA inspection findings. The reason is simple: almost every company claims to "ensure data integrity", but few can demonstrate, documents in hand, that they have systematically assessed where their GxP data is truly vulnerable. That is exactly what a DIRA is: a documented, defensible risk assessment that maps data flows, rates data criticality and defines proportionate controls. In this article you will find the structure of a ready-to-use DIRA template, the steps to complete it and the mistakes inspectors know by heart.

What authorities expect from a data integrity risk assessment

No regulation mandates a form called "DIRA", but the principle is written everywhere. The MHRA "GXP Data Integrity Guidance and Definitions" (revision 1, March 2018) requires that the effort devoted to data governance be commensurate with the risk to product quality, and that the assessment consider both the criticality of the data and its vulnerability to alteration or loss. PIC/S guidance PI 041-1 "Good Practices for Data Management and Integrity in Regulated GMP/GDP Environments" (in force since 1 July 2021) goes further: it expects a risk-based approach centred on business processes, not just IT system functionality, with data flows mapped from acquisition to retention. The FDA, in its guidance "Data Integrity and Compliance With Drug CGMP: Questions and Answers" (December 2018), reiterates that data controls must derive from a risk assessment integrated into the quality system. The common message: without a formalised DIRA, every ALCOA+ compliance claim remains an unsupported statement.

The DIRA template structure: the fields you cannot skip

An effective DIRA is almost always a matrix: one row per data flow (or per system/process), one column per assessment dimension. The minimum template that survives an audit contains these fields:

Template fieldWhat to recordExample
Process / data flowThe business process and the data path, from origin to archivingSample weighing → balance → LIMS
System and data typeSystem involved; paper, electronic or hybrid recordHPLC with CDS, hybrid record
Data criticalityImpact of the data on product quality and release decisionsHigh: supports batch certification
VulnerabilityPossibility of modification, deletion, untracked retesting, shared accessShared administrator account in the lab
Existing controlsTechnical and procedural controls already in placeAudit trail enabled, periodic review
Residual riskRating (e.g. high/medium/low) after existing controlsMedium
Actions and priorityRemediation with owner and due date, ranked by riskIndividual user profiles by Q1

The rating scale (3×3 matrix, 5×5 or simplified FMEA) matters less than consistency: the Quality Risk Management tools of ICH Q9(R1) work perfectly well, provided the scoring criteria are defined before completion and applied the same way across all flows.

Topics like this — data integrity, Annex 11, audit readiness — are the daily bread of The Pragmatic GMP, GuideGxP's free weekly newsletter: every week one GMP topic explained in operational terms, no fluff. Subscribe here.

How to complete the DIRA step by step

  1. Inventory processes, not just systems. Start from the inventory of GxP processes (QC testing, production, warehouse, pharmacovigilance) and identify the data each generates. An inventory built only around IT systems forgets paper and hybrid records.
  2. Map the flow of every critical data item. Where the data is created, where it is processed, who can touch it, where it ends up archived. The data flow map is the explicit prerequisite of a credible assessment under PIC/S PI 041-1.
  3. Assess criticality and vulnerability separately. Data can be critical but well protected, or non-critical but trivially easy to alter: the two dimensions together determine priority.
  4. Capture existing controls before proposing new ones. Audit trail, user management, backups, review: the DIRA must give credit to what already works, otherwise it produces unrealistic remediation plans.
  5. Assign actions with an owner and a date. A DIRA without a remediation plan is an academic exercise; remediation without risk-based priorities is indefensible in front of an inspector.
  6. Make the DIRA a living document. Periodic review and updates at every relevant change (new system, new account, software upgrade), within the PQS change control.

The typical mistakes inspectors spot immediately

  • Vendor "photocopy" DIRA: generic assessments copied from vendor documentation, with no reference to the site's actual configuration.
  • Electronic systems only: lab notebooks, logbooks and hybrid records excluded from the assessment.
  • No link to the CAPA system: remediation actions living in an Excel file disconnected from the quality system, never verified.
  • Unjustified scores: "low" risks with no documented rationale, which turn into unanswered questions during an audit.
  • Assessment never updated: a DIRA dated three years ago, with systems replaced or upgraded in the meantime.

When to perform (and repeat) the DIRA

The best moment for the first DIRA is before anyone asks for it: typically within a data governance programme, as part of the periodic review of computerised systems, or in preparation for an inspection. But the initial assessment is only half the job. At least four triggers must reopen the document: the introduction or upgrade of a system generating GxP data; an organisational change affecting who accesses the data (new shifts, outsourcing, remote access); an internal or external data integrity finding, which by definition contradicts the declared residual risk; and the planned periodic review, with a frequency justified by risk. One often-overlooked detail: the DIRA must be versioned and approved like any GMP document, with QA sign-off. An anonymous spreadsheet found on a shared server, with no revision status, is worth as much as a non-existent document in an audit — and leaves the worst impression: that the assessment was done once, for the previous inspector.

GuideGxP recommendation

Treat the DIRA as the document that connects your data governance to Quality Risk Management: a matrix by data flows, scoring criteria defined up front, remediation tracked in the CAPA system and review at every change. Start from the processes supporting batch release: that is where an inspector looks first, and where unmanaged residual risk costs the most. And do not wait for the inspection to discover that your system inventory is out of date: a DIRA is only as solid as the inventory it rests on.

If you are building or revising your DIRA alongside system validation, GuideGxP's Operational Guide to Computer System Validation (CSV) in GxP includes ready-to-use Excel and Word templates for risk assessment, system inventory and Annex 11 audit readiness.

Official sources

THE PRAGMATIC GMP · EVERY MONDAY

The GMP topics that matter, in 7 minutes.

One GMP topic, one real-world example and one practical action, based on official sources and inspection trends.
Discover The Pragmatic GMP →