Pharma 101 /Data Integrity

ALCOA++ & GDP in pharma, explained

Two acronyms that show up on every FDA audit and EMA inspection. Here's what they mean, why they matter, and how they connect.

Why this matters

Data integrity is a regulatory requirement, not a best practice

Regulators like the FDA, EMA, and MHRA can reject an entire drug application — or shut down a manufacturing site — if the underlying data cannot be trusted. ALCOA++ and GDP are the two frameworks that define what "trustworthy data" actually looks like in a regulated pharma environment.

The framework

What does ALCOA++ stand for?

Each letter is a principle. Every data record in a GxP environment must meet all of them.

A
Attributable

It must be clear who recorded the data, and when.

Sign and date every entry. Electronic records need an audit trail linked to a unique user ID. No shared logins.

L
Legible

Data must be readable now and in the future.

Handwriting must be clear. Records stored on media (CDs, hard drives) must remain accessible for the full retention period.

C
Contemporaneous

Recorded at the time the activity happens — not later from memory.

Back-filling a lab notebook after the fact is a GDocP violation, even if the underlying data is accurate.

O
Original

The first capture of data — the source record.

Transcribing data onto a clean sheet and discarding the original is not allowed. Raw instrument printouts are original data.

A
Accurate

Data must be correct and truthful — free from errors or bias.

Corrections require a single strikethrough, initials, and date. A reason is required for significant changes or late entries. Never use correction fluid (Wite-Out).

++
The additions
Complete, Consistent, Enduring & Available
  • Complete — no missing data; all results recorded, including failures
  • Consistent — dates, times, and units agree across all records
  • Enduring — stored on durable media for the required retention period
  • Available — accessible to regulators upon request

Good Documentation Practices

What is GDP?

GDP is the set of rules that governs how you record, store, and manage documentation in a regulated GxP environment. ALCOA++ defines the standard; GDP is the practice.

The core GDP rules

1

Use black or blue indelible ink

Pencil, erasable ink, and correction fluid are prohibited. Paper records must be permanent.

2

Single strikethrough for corrections

Cross out the error with one line so the original is still readable. Add the correct value, your initials, and the date. Add a reason for significant changes or corrections made after the original entry date.

3

No blank spaces — use N/A or a diagonal line

An empty field could imply data was omitted. If a field doesn't apply, state it explicitly.

4

Record events as they happen

Retrospective data entry — filling in a form after the fact — is a critical GDocP failure and a red flag in audits.

5

Version control all documents

SOPs, batch records, and protocols must have version numbers and effective dates. Superseded versions must be retained but marked obsolete.

Where GDP applies (GxP environments)

Abbreviation Stands for Context
GMP Good Manufacturing Practice Drug production & quality
GCP Good Clinical Practice Clinical trials & patient data
GLP Good Laboratory Practice Non-clinical safety studies
GDP Good Distribution Practice Supply chain & cold chain
GDocP Good Documentation Practice All of the above — the rules for recording

GDocP (Good Documentation Practice) is often what people mean when they say "GDP" in a quality context.

How ALCOA++ and GDP connect

Think of it this way: GDP is the rulebook, ALCOA++ is the referee.

GDP sets the procedures

How to write, correct, store, retrieve, and retain documents — the operational how-to.

ALCOA++ sets the standard

The criteria a regulator uses to judge whether your data can be trusted — the quality benchmark.

Together they enable trust

A batch record written under GDP and meeting ALCOA++ can be defended in any inspection worldwide.

Audit red flags

Common ALCOA++ / GDP failures

These are the observations that show up most often in FDA Warning Letters and EMA inspection reports.

Back-dating entries

Recording a timestamp earlier than when the action actually occurred. Violates both Contemporaneous and Accurate.

Deleting electronic raw data

Discarding failed runs or only keeping "good" results. Violates Complete and Original — a critical data integrity breach.

Shared login credentials

Multiple users sharing one system account. Destroys Attributability — you can no longer identify who made a change.

Correction fluid (Wite-Out)

Concealing what was originally written. Violates Original and raises questions about what was being hidden.

Audit trail disabled or altered

Turning off system audit trails to hide edits. One of the most serious data integrity violations — often leads to Warning Letters.

Transcription without source retention

Copying data to a clean form and discarding the original worksheet. The "clean" copy is not Original data.

ALCOA++ quick-reference

Print this and stick it by your bench.

Letter Principle What it means in practice Common failure mode
A Attributable Sign & date; unique user IDs in systems Shared logins, unsigned entries
L Legible Clear writing; durable storage media Faded printouts, illegible handwriting
C Contemporaneous Record at the moment the task is done Back-filling notes hours or days later
O Original Keep the first capture; never transcribe and discard Discarding raw instrument output
A Accurate Correct errors with single strikethrough + initials Wite-Out, heavy obliteration
+ Complete All results recorded — including OOS and failures Selectively reporting only passing results
+ Consistent Dates, times, units agree across all records Time-stamp discrepancies between systems
+ Enduring Stored on durable media for retention period Saving only to a local USB drive
+ Available Accessible to regulators on request Archived records not retrievable in time

Sources & further reading

Where these expectations come from

ALCOA++ is a plain-language data-integrity shorthand; the binding requirements depend on the product, activity, and jurisdiction. These are useful starting points.

Keep learning every week

BioCircuit covers regulatory updates, data integrity enforcement actions, and the science behind drug development — delivered every Monday.