FDA Data Integrity Training Online - ALCOA, the 18 Questions and What Inspectors Find

Data integrity is consistently the second most cited area in FDA drug warning letters, behind only quality system failures broadly. The December 2018 FDA guidance - Data Integrity and Compliance With Drug CGMP: Questions and Answers - remains the definitive reference, structured as eighteen specific questions and answers that address the regulatory interpretations pharmaceutical professionals encounter most often in practice.

This guide explains what the guidance actually covers, what ALCOA and its extensions mean in practical terms and where manufacturers most commonly fall short according to current enforcement data.

What data integrity means under FDA guidance

FDA defines data integrity as the completeness, consistency and accuracy of data throughout the data lifecycle - from generation through processing, review, analysis and reporting, all the way to final disposition. This is a broader scope than most professionals initially assume. It is not limited to laboratory data. It applies to batch records, environmental monitoring data, cleaning records, training records and every other piece of data generated within a GxP system.

The foundational framework for evaluating data integrity is ALCOA - a mnemonic FDA has used for decades and formalised in the 2018 guidance.

A
Attributable
L
Legible
C
Contemporaneous
O
Original
A
Accurate

Industry practice and subsequent guidance have extended ALCOA to ALCOA+ and in some frameworks ALCOA++, adding Complete, Consistent, Enduring and Available. Each addition addresses a specific failure mode FDA has observed repeatedly: incomplete records missing required entries, inconsistent data across related records, data that degrades or becomes unreadable over time, and data that cannot actually be retrieved and reviewed when requested during an inspection.

What the eighteen questions in the FDA guidance actually cover

The December 2018 guidance is structured as eighteen specific Q&A pairs, and effective training needs to work through the substance of each rather than treating the document as background reading. The questions cluster around several practical themes that generate the most real-world confusion.

Audit trails and metadata

Several questions address what constitutes an adequate audit trail, when audit trail review is required, and how frequently it must occur. FDA's position is that audit trail review should be part of routine data review, not a separate activity performed only during investigations or inspections. A system with a technically functioning audit trail that nobody actually reviews does not satisfy the requirement in practice.

Shared logins and system access

The guidance directly addresses the use of shared login credentials, making clear that each individual who generates or modifies GxP data must have a unique, attributable system identity. Shared credentials that prevent attributing a specific data entry, edit or deletion to a specific individual are a data integrity violation regardless of whether any actual manipulation occurred - the inability to attribute the action is itself the deficiency.

Backdating and data manipulation

Several questions address the practice of backdating records, testing into compliance by retesting until a passing result appears without documented justification, and excluding data from reported results without a documented and scientifically valid basis. These are treated as some of the most serious data integrity violations because they represent deliberate misrepresentation rather than a systems or process gap.

Electronic versus paper records and true copies

The guidance clarifies what constitutes a true copy of an electronic record and addresses the common practice of printing electronic data to paper as the official record - which FDA generally does not accept when the electronic system is the original source of the data, since a printout can omit metadata, audit trail information and other elements that were part of the original electronic record.

A pattern worth training on specifically

FDA's guidance and subsequent enforcement have been consistent that data integrity failures are frequently systemic rather than isolated. When an inspector finds one instance of inappropriate data manipulation, current inspection practice is to expand the scope significantly - reviewing a much larger sample of records, often across a longer time period, to determine whether the finding reflects an isolated event or a systemic quality culture problem. Training that treats each ALCOA principle as an isolated checklist item, rather than connecting them to this systemic risk, understates the real stakes.

What effective data integrity training needs to include

Based on the guidance content and current enforcement patterns, training that actually prepares pharmaceutical professionals for real situations - not just guidance recall - should include the following elements.

Direct coverage of the eighteen FDA Q&A pairs, not a paraphrased summary. The specific language and examples FDA uses are what inspectors reference during inspections, and training built from the actual guidance text is more defensible and more useful than a generic overview of data integrity principles.

ALCOA and ALCOA+ applied to real record types - batch records, laboratory data, environmental monitoring records, cleaning logs - not just as an abstract acronym. Learners should be able to identify a specific ALCOA gap in a specific type of record they actually work with.

Current enforcement data showing where data integrity citations actually occur most frequently, since this focuses training time on the areas of genuine current risk rather than treating all eighteen questions as equally likely to generate a finding.

Quality culture context, not just technical mechanics. Data integrity failures often originate from production pressure, unclear escalation paths for legitimate issues, or a culture where reporting a problem feels riskier than concealing it. Training that addresses only the technical requirements without this context misses why violations occur in the first place.

Who needs this training

Quality assurance and quality control professionals are the most obvious audience, but data integrity training has a genuinely broad reach given how the 2018 guidance defines data integrity across the full data lifecycle. Manufacturing operators who complete batch records, laboratory analysts who generate and review test data, IT and system administrators who configure audit trail settings and user access controls, and quality unit personnel who conduct data review and investigation all need role-appropriate training on this topic.

The bottom line

Data integrity is not primarily a technical topic about audit trails and electronic signatures, though those elements matter. It is fundamentally about whether the data generated within a quality system can be trusted to represent what actually happened. The December 2018 FDA guidance remains the authoritative reference for what that trust requires in practice, and training built directly from its eighteen questions - connected to current enforcement patterns - is what prepares professionals to meet that standard rather than simply describe it.

Key regulatory references

  • FDA Guidance for Industry - Data Integrity and Compliance With Drug CGMP: Questions and Answers, December 2018
  • 21 CFR Part 11 - Electronic Records and Electronic Signatures
  • 21 CFR 211.68 - Automatic, mechanical and electronic equipment
  • 21 CFR 211.180 to 211.198 - Records and reports

Our FDA Data Integrity and cGMP Compliance course covers this in full

All eighteen questions from the December 2018 guidance, ALCOA and ALCOA+ applied to real record types, audit trail requirements and current enforcement data. Certificate on completion.

View course →