Data Integrity in Validation | GMP Record Control Checks

Learn how to maintain data integrity in validation records through ALCOA+, audit trails, controlled documentation and beat review practices.
Validation processes produce some of the key GMP evidence in a pharmaceutical plant. Qualification procedures, performed reports, raw data, calibration documentation, electronic documents, audit trails, calculations, deviations and approvals all together provide information on whether pieces of equipment, systems, procedures or their methods work properly.
Data Integrity in Validation
However, that evidence cannot be beneficial unless its integrity can be confirmed.

In Validation, Data Integrity meaning ensuring that validation records and data are kept complete, consistent, accurate, dependable, traceable and safe throughout their lifecycle. Even though a technically right validation testing is performed, it may turn out that the available records contain unexplained modifications, missing data, unregulated worksheets, incomplete audit trails or data not documented.

Validation Data Is More Than the Final Report

The frequent mistake people do is that they treat only the final validation report as important and deny the importance of all the records made during validation.

In reality, the validation report serves as the final documentation while the validation process involves the more complex evidence.

In relation to equipment qualification, the evidence might be as follows:
  • Validation plan and protocol documentation
  • Equipment identity and status details
  • Calibration records
  • Measurement logs
  • Logs of electronic resources
  • Communication logs
  • Calculations and tables
  • All documents describing discrepancies
If any part of the chain fails to provide reliable information, the validation process will lose its reliability.

Apply ALCOA+ to Validation Records

The principles that we commonly consider in association with the ALCOA+ criteria give us a helpful basis for assessing validation records. The records should comply with the criteria of being attributable, legible, contemporaneous, original or a true copy and accurate. In accordance with ALCOA+, there are other requirements that include completeness, consistency, permanence and availability.

While all requirements are important, "contemporaneity" is one of the requirements that may be particularly tricky for validation teams.

For instance, an operator carries out temperature mapping during operational qualification but records the results later from memory. While the final temperature values may seem appropriate, it does not give us the same level of confidence as that obtained in the records that were made contemporaneously.

The same concerns are relevant to backdating of entries using uncontrolled templates or writing the results in hindsight without any valid grounds.

Control the Original Data

Validation efforts include devices and automated systems that produce data.

A few examples of these devices are listed below:
  • Temperature and humidity sensors.
  • Records of autoclave cycles.
  • HPLC and GC systems for method validation.
  • SCADA and PLC systems.
  • Building administration systems.
  • Data recording instruments.
  • Electronic systems for the execution of manufacturing processes in the laboratory.
  • Equipment for automated cleaning.
The physical copy may not represent the entire original record.

Where raw data and metadata are generated from electronic systems, the organization must understand where originals are stored, who has the right to access them, how secure they are and how the audit-trail information is reviewed.

For instance, the physical copy of the temperature record may show the final result without exhibiting the complete electronic history of the run.

Here is the connection between validation data integrity and computerized system control and data governance.

Audit Trails Should Not Be Treated as an IT Exercise

Audit trails provide valuable information regarding the manner in which electronic validation data has been generated or modified.

The audit itself should be risk-based and suitable for the particular system and activity in question. Some questions to consider include:
  • Who has produced the record?
  • When was the record prepared?
  • Were some of the recorded values modified?
  • Who did the changes?
  • What was the reason for the modification?
  • Did the change was done properly?
The common pitfall is that there is an audit trail possibility, but a responsible process for audits has not been developed. The approach of saying that “the system has an audit trail” does not guarantee data integrity.

Spreadsheets and Calculations Need Attention

Validation teams frequently utilize applications such as Excel for their calculations, data aggregations, trends diagnoses and acceptance judgement.

The use of these applications may carry some risk that often goes unnoticed.

All spreadsheet validations must contain the proper safeguards in accordance with the process in question and the degree of risk. This should involve formula lockout, version management, restriction on access, review of calculations, monitoring of source data and prevention of accidental changes.

When the qualification report, for example, is estimating the temperature mapping statistics using the spreadsheet, the verifier must be able to trace back-filed coordinates to the original measurements and ensure the accuracy of the methods of calculating them.

What Happens When Validation Data Is Missing or Altered?

A case of missing value or a change that lacks explanation should not simply be regarded as being a documentation adjustment.

The first objective is to understand what has occurred.

Qualitative Assessment and Validation have to be able to find out whether that case is an isolated issue or can have a systemic nature. The inquiry may require the examination of relevant records, auditing of systems, training, equipment history, validation researches and other activities performed by either the same staff or via the same machine.

Then it is necessary to evaluate any eventual influence of the invalidated data on validation conclusions.

Thus, when one point of temperature mapping is missing, depending on the place, the kind of mapping, importance of that point, surrounding data and set criteria, the consequences for missing value are not the same.

QA Review Should Challenge the Evidence

QA must go beyond reviewing signatures and filled forms. For a complete review, it is important to prove that there is a trail of evidence confirming the findings.

Certain questions should be considered:
  • Does the raw data confirm the results?
  • Is it clear who made the records?
  • Were the records made at the same time the work was performed?
  • Are the explanation of the corrections available and clear?
  • Is there a control of electronic records and metadata?
  • Were audit trails checked?
  • Are calculations subject to independent verification?
  • Are deviations connected to the validation data?
  • Can the entire validation process be demonstrated?
While making the inspection, an inspector can request for the initial data instead of the final validation report. An organization must have all necessary documents at hand.

Avoid "Clean Documentation" That Hides the Event

The other thing that is important to bear in mind is that the documentation of what has been done must correspond to the reality of the case.

A deviation, undesired result, equipment alarm, unsuccessful test or procedural error should not be overlooked just because the validation documents are pristine.

Striving for perfect documentation can lead to a more severe data integrity issue than the issue being resolved in the validation first place.

If something has happened, record it, investigate it, find the impact and state the rationale for the decision made at the end.

Incorporate Data Integrity into Validation Approach

The process of validation planning should involve data integrity considerations.

The validation strategy should feature content regarding the information that is going to be produced, the method of its production, the various duties concerning the task of information generation and assessment, types of electronic documentation applicable and the requirements for retaining information.

In the case of computerized areas, validation team members should have knowledge of the interaction between validation, access, audit trail, backup, information retention and operational aspects.

A Practical Final Check

Prior to giving my stamp of approval on any validation report, I would ask myself the following question.

“Would an outside party be able to understand what happened from the records available?”

If the answer is no, it might be time to carry out another review of the validation package, as the best validation documentation is able to tell not only that the acceptance criteria were met, but also that the data were generated, kept, reviewed and used to arrive at the conclusion.

The essence of data integrity in validation lies in the trust placed in proof. A qualification or validation study will be useful only if the records of the performed actions and yielded results are reflective of the reality.

This means for pharmaceutical companies that it is important to control the paper and electronic documents, take care of primary data integrity, monitor the audit trails when required, keep supporting evidence of every step of a process, report deviations and make sure that the final reports are backed up with data.

When the records of validation can be precisely re-constructed, a company will be much better prepared to prove its regulation control during audits, inspections and regular quality checks.

Get ready to use editable Validation Protocols in MS-Word FormatView List





is a prominent Pharmaceutical Quality Assurance expert, consultant and the founder of Pharmaguideline. With over 22 years of hands-on experience in cGMP-compliant manufacturing environments, he specializes in establishing validation protocols, sterile area controls and data integrity systems. Ankur routinely interprets international regulatory frameworks (including FDA, EMA and ICH guidelines) to help global pharmaceutical professionals ensure strict regulatory compliance and operational excellence. Connect with Ankur on LinkedIn. Need Help: Ask Question

No comments:

Post a Comment

Please don't spam. Comments having links would not be published.