Ready to fix validation chaos? Book Review
Data Integrity

ALCOA+ Data Integrity: A Validation Checklist

ALCOA+ data integrity means records are attributable, legible, contemporaneous, original, accurate, complete, consistent, enduring, and available. A validation review should test how those qualities work in the real process.

What does ALCOA+ mean?

ALCOA is a practical way to describe reliable data. Records should be Attributable, Legible, Contemporaneous, Original, and Accurate. The plus adds that data should be complete, consistent, enduring, and available throughout its required lifecycle.

Data integrity is not only a database property. It depends on system configuration, user behaviour, procedures, interfaces, review, backup, and change control.

ALCOA+ checklist for validation

PrincipleValidation question
AttributableCan the record be tied to the person or system that created or changed it?
LegibleCan authorised reviewers read and understand the record over time?
ContemporaneousIs the record created when the activity occurs, with reliable timestamps?
OriginalIs the original record preserved, or is the copy demonstrably complete?
AccurateAre inputs, calculations, transfers, and outputs correct?
CompleteAre required records, metadata, audit trails, and exceptions retained?
ConsistentDo dates, sequences, identities, and states make sense together?
EnduringWill the record remain protected and readable for the retention period?
AvailableCan authorised people retrieve it promptly for operations or inspection?

How should access controls be tested?

Start with roles and intended use. Identify who may create, approve, modify, delete, export, or administer records. Then test both allowed and prohibited actions. Access review should cover real role combinations, not only the default administrator account.

  • Test unique user accounts and authentication rules.
  • Test least-privilege permissions for critical functions.
  • Review joiner, mover, and leaver processes.
  • Check periodic access review and timely removal.
  • Separate administration from approval where the process requires it.

What should an audit trail review cover?

An audit trail should show relevant creation, change, and deletion events. Review whether it captures the old and new value where appropriate, the responsible user, the date and time, and the reason or linked change record.

Do not assume that an audit-trail switch being enabled proves it works. Test the event, inspect the stored record, check permissions around the trail, and confirm that the history can be retained and retrieved.

How do you validate data migration?

Migration validation should define the source, target, mapping rules, transformation rules, reconciliation method, exception handling, and acceptance criteria. Sample checks are useful, but critical fields may require complete reconciliation.

  1. Profile the source data and known quality issues.
  2. Approve mapping and transformation rules.
  3. Run a controlled migration in a representative environment.
  4. Reconcile counts, totals, key fields, and relationships.
  5. Investigate exceptions and retain evidence.
  6. Approve the final migration and protect the source record.

What procedures support data integrity?

Procedures should explain how people create, review, correct, export, back up, restore, and retire records. Include incident escalation, audit-trail review, access review, training, and change control.

Important: never rely on an informal workaround to correct regulated data. Use the approved correction process and preserve the original record and reason for change.

Common ALCOA+ failure patterns

  • Shared accounts that make actions impossible to attribute.
  • Backdated entries without a documented reason.
  • Audit trails that users can disable or alter.
  • Uncontrolled exports treated as the official record.
  • Data transfers with no reconciliation evidence.
  • Backups that exist but have never been restored in a test.

How should data integrity risks be prioritised?

Start with the data that drives a regulated decision or demonstrates that a critical activity occurred. Map where it is created, changed, calculated, transferred, reviewed, stored, and retired. Then assess the controls at each handoff. This exposes risks that a screen-by-screen test can miss.

Include people and procedures in the assessment. A system may technically enforce a control while a manual export, shared workstation, or undocumented correction creates a different risk in practice. Test the complete data flow, not only the feature that stores the final value.

  • Prioritise critical records and metadata.
  • Test unusual and exception paths.
  • Review privileged access separately.
  • Confirm that retained records remain searchable and readable.

FAQ

Is ALCOA+ only for laboratory data?

No. It applies wherever regulated decisions, records, or evidence depend on data, including quality, manufacturing, clinical, safety, and validation processes.

Is a timestamp enough to prove contemporaneous data?

No. The timestamp should be reliable and the process should show that the record was created during the activity rather than reconstructed later.

What is the difference between a backup and an enduring record?

A backup is a recovery copy. An enduring record also needs protection, readability, retention, and controlled access over its required lifecycle.

How often should audit trails be reviewed?

The frequency should reflect process risk, change, anomalies, and organisational procedures. Critical workflows may need review as part of routine release or quality activities.

Can a vendor provide the evidence?

Vendor evidence can support assurance, but the regulated organisation still needs to assess intended use, configuration, process controls, and supplier responsibilities.

Conclusion

ALCOA+ is a behaviour and control model, not a slogan. Validate the system in its real process, test access and audit trails, reconcile migrations, and retain evidence that remains usable.

Make data integrity evidence easier to defend

Connect controls, tests, audit trails, and approvals across the validation lifecycle.

Discuss data integrity controls →