Web of Pharma · Data Integrity · Pharmaceutical Quality
ALCOA+ Checklist for Pharmaceutical Companies
A practical, audit-ready checklist for protecting pharmaceutical data from creation through review, retention, retrieval, and final disposition.
answer
An ALCOA+ checklist is a structured review tool used to verify that pharmaceutical data are attributable, legible, contemporaneous, original, accurate, complete, consistent, enduring, and available. It converts data-integrity expectations into evidence-based questions for people, processes, paper records, electronic systems, laboratories, manufacturing, and quality oversight.
Pharmaceutical companies rely on data to release batches, investigate deviations, evaluate stability, qualify equipment, approve suppliers, respond to complaints, and demonstrate compliance. A polished report cannot compensate for missing raw data, undocumented changes, shared logins, unreadable pages, or records that cannot be retrieved during an inspection.
The ALCOA+ framework provides a practical way to test whether data remain trustworthy throughout the data lifecycle. This checklist is designed for quality assurance, quality control, production, engineering, validation, information technology, regulatory affairs, auditors, and laboratory management.
Use it alongside your approved cGMP procedures and risk assessments. The broader ALCOA guide explains the framework in more detail; this article focuses on how to apply it as a repeatable company checklist.
What Is an ALCOA+ Checklist?
An ALCOA+ checklist is a documented set of questions and evidence requirements used to assess data integrity. It can be applied before implementation, during routine record review, during internal audits, after a deviation, or as part of periodic computerized-system and data-governance reviews.
The checklist is not a substitute for regulations, validation, quality risk management, or professional judgment. It is a consistent way to identify gaps, record objective evidence, assign owners, and verify that corrective actions are effective.
| Checklist field | Purpose | Example entry |
|---|---|---|
| Principle | Identifies the ALCOA+ characteristic being assessed. | Attributable |
| Question | Defines the control or behavior to verify. | Can every critical entry be traced to one authorized person? |
| Evidence | Records the objective proof reviewed by the assessor. | User-access report, training record, batch record, audit trail |
| Status | Shows the current result and supports trend analysis. | Compliant, partial, non-compliant, or not applicable |
| Risk and action | Connects the gap to impact, owner, due date, and follow-up. | High risk; system owner; effectiveness check required |
ALCOA+ Principles at a Glance
ALCOA describes the original five characteristics. The “plus” principles extend the review to completeness, consistency, endurance, and availability so that data remain reliable beyond the moment of entry.
How to Use This Pharmaceutical ALCOA+ Checklist
Define the scope
Select a process, system, record class, laboratory method, batch, study, vendor, or department for review.
Identify critical data
Map raw data, metadata, calculations, audit trails, approvals, interfaces, attachments, and the decisions they support.
Ask the questions
Use the principle-specific questions below and interview the people who create, review, administer, and archive the records.
Collect evidence
Review source records, system configuration, access lists, audit trails, training, procedures, logs, and previous findings.
Assess risk
Consider patient impact, product quality, data criticality, detectability, scope, recurrence, and regulatory significance.
Track and verify
Assign actions, document decisions, and use CAPA when a systemic weakness needs corrective and preventive action.
ALCOA+ Governance and Management Checklist
Management sets the conditions in which people create and protect data. The following questions test whether data integrity is governed as a quality-system responsibility rather than treated as an isolated laboratory or IT issue.
- Is there an approved data-integrity or data-governance policy covering the full data lifecycle?
- Are senior management, the quality unit, data owners, system owners, and process owners clearly accountable?
- Are critical data and critical records identified using documented, risk-based criteria?
- Are data flows mapped from generation through processing, review, reporting, retention, retrieval, and disposition?
- Are paper, electronic, hybrid, outsourced, cloud, and third-party records included in the governance scope?
- Are data-integrity risks included in quality risk management, validation, change control, and internal audit programs?
- Are resources available for controlled systems, secure storage, training, archive, backup, and periodic review?
- Are data-integrity metrics and recurring issues reviewed by management at defined intervals?
- Is there a protected process for employees to report errors, omissions, pressure, or suspected falsification?
- Are investigations focused on root causes and system design rather than automatically blaming individuals?
Attributable Checklist
Attributable data show who performed an action, who made an entry, who reviewed it, and when the action occurred. Attribution applies to manual entries, electronic transactions, approvals, corrections, configuration changes, and administrative activity.
- Are unique user IDs used for data creation, review, approval, and system transactions?
- Are shared accounts prohibited for actions that must be linked to an individual?
- Are handwritten initials and signatures linked to a controlled signature or initials register?
- Do electronic signatures remain securely linked to the signed record and the signer’s identity?
- Are system administrators independent from routine data generation and review where practical?
- Are access requests, approvals, changes, suspensions, and periodic reviews documented?
- Can the organization identify the person who created, changed, reviewed, approved, printed, or deleted a record?
- Are scribe arrangements controlled, justified, and clear about who performed and who recorded the activity?
Legible Checklist
Legible records can be read throughout their retention period and interpreted without guessing. Legibility includes handwriting, printed output, electronic displays, scanned images, metadata, units, abbreviations, and the readability of archived records.
- Are entries written in permanent ink or captured in an approved electronic system?
- Are records readable at the time of completion and after scanning, copying, printing, or migration?
- Are units, decimal places, symbols, abbreviations, and date formats unambiguous?
- Are corrections made without obscuring the original entry or the reason for change?
- Are printouts, labels, thermal records, and instrument outputs protected from fading or deterioration?
- Are scanned pages complete, in order, correctly oriented, and linked to the original record?
- Can the archive display electronic records with the context and resolution required for review?
- Are staff trained to report illegible entries instead of interpreting or rewriting them informally?
Contemporaneous Checklist
Contemporaneous recording preserves the real sequence of events. It prevents memory-based reconstruction, backdating, and informal notes that are later transcribed into an official record.
- Are observations, measurements, steps, and decisions recorded at the time the activity is performed?
- Are date and time settings synchronized and controlled across relevant systems and equipment?
- Are temporary worksheets, scrap paper, sticky notes, and unofficial electronic files prohibited or reconciled?
- Are delayed entries clearly identified, justified, dated, timed, and reviewed under an approved procedure?
- Do electronic systems save data at the appropriate step rather than only at the end of a sequence?
- Are aborted, incomplete, repeated, or failed activities retained and explained where they are part of the record?
- Can the chronology of sampling, testing, manufacturing, review, and approval be reconstructed?
- Do interviews and records confirm that entries are made at the point of activity?
Original and True-Copy Checklist
The original record is the first capture of information, whether paper or electronic. A verified true copy may be used when it preserves the content, context, structure, metadata, and history needed to reconstruct the activity.
- Is the official source record defined for each paper, electronic, or hybrid process?
- Are raw electronic files retained when the record is dynamic or can be reprocessed?
- Do copies preserve metadata, audit trails, signatures, attachments, calculations, and the record’s meaning?
- Is the scanning, copying, export, or migration process validated or verified for its intended use?
- Are original and copied records reconciled so missing pages, files, or attachments are detected?
- Are uncontrolled screenshots, spreadsheets, photographs, or printouts prevented from replacing source data without assessment?
- Can the organization demonstrate who created and verified a true copy?
- Are original records protected from premature destruction until copy integrity and retention are confirmed?
Accurate Checklist
Accurate data reflect what actually happened and are suitable for the decision being made. Accuracy depends on calibrated equipment, approved methods, controlled calculations, independent review, and honest correction of errors.
- Are instruments, balances, sensors, and software qualified, calibrated, and within their approved status?
- Are approved methods, specifications, formulas, worksheets, and master documents used?
- Are calculations independently checked or controlled by validated software?
- Are transcription, unit conversion, rounding, and dilution steps verified?
- Are unusual, atypical, invalidated, or repeated results retained with scientific justification?
- Are errors corrected transparently without deleting or concealing the original data?
- Do reviewers compare reported results with raw data and relevant metadata?
- Are reference standards, reagents, sample identity, equipment, and environmental conditions traceable?
Complete Checklist
Complete records include all data and metadata needed to understand the activity, including results that are out of specification, aborted, invalidated, repeated, or not selected for reporting. Completeness also includes associated documents and the history of changes.
- Are all raw observations, readings, injections, samples, and process steps retained?
- Are failed, aborted, invalidated, repeated, and excluded results included with justification?
- Are audit trails, system logs, electronic signatures, comments, and review history available?
- Are methods, sequences, calculations, formulas, specifications, and configuration settings retained?
- Are attachments such as chromatograms, images, labels, worksheets, certificates, and equipment logs linked?
- Are deviations, investigations, changes, approvals, and impact assessments connected to the record?
- Are blank forms controlled, issued, reconciled, and retained when required?
- Can an independent reviewer reconstruct the activity without relying on undocumented explanations?
Consistent Checklist
Consistent data follow a logical chronology and use stable conventions. Dates, times, units, identifiers, versions, and status changes should align across records and systems.
- Are date, time, time zone, number, unit, and naming conventions defined and used consistently?
- Are system clocks synchronized or their differences controlled and documented?
- Do batch, sample, equipment, method, material, and study identifiers match across related records?
- Are version numbers and effective dates consistent between procedures, forms, methods, and reports?
- Can the sequence of creation, processing, review, approval, and correction be understood?
- Are interfaces and data transfers checked for changes in units, formats, decimal places, or meaning?
- Are conflicting entries investigated rather than silently harmonized?
- Are templates, controlled vocabularies, and master data maintained under change control?
Enduring Checklist
Enduring records remain protected, readable, meaningful, and usable throughout the approved retention period. The plan should account for paper deterioration, media failure, software obsolescence, migration, vendor changes, and disaster recovery.
- Are retention periods, archive owners, storage locations, and disposition rules defined?
- Are paper records protected from heat, moisture, fading, pests, unauthorized removal, and physical damage?
- Are electronic files stored on durable media with suitable security and integrity monitoring?
- Are software, hardware, file formats, readers, certificates, and system dependencies monitored for obsolescence?
- Are migration and conversion plans documented, risk-assessed, validated, and verified?
- Do archived records retain raw data, metadata, audit trails, signatures, and relevant configuration?
- Are backup and restore procedures tested at defined, risk-based intervals?
- Are destruction and disposal activities authorized, documented, and checked for investigations or legal holds?
Available Checklist
Available data can be found, opened, read, and reviewed by authorized personnel when needed. Availability is not simply a login or a file on a server; it includes indexing, permissions, readable formats, context, and realistic retrieval testing.
- Can an authorized reviewer locate representative records using controlled identifiers or search fields?
- Are raw data, metadata, audit trails, calculations, attachments, signatures, and approvals retrievable together?
- Are archived records readable with supported software, hardware, media, or a validated viewer?
- Are access rights, user accounts, administrator privileges, and archive permissions periodically reviewed?
- Are retrieval, restore, migration, scanning, and true-copy tests documented and approved?
- Are vendor and cloud agreements clear about data ownership, retention, accessibility, and return?
- Can the organization produce records within a defined response time for an investigation or inspection?
- Are missing, inaccessible, damaged, or delayed records investigated and risk-assessed?
ALCOA+ Checklist for Laboratory Records
Laboratory data are often distributed across instruments, notebooks, worksheets, sample-management systems, spreadsheets, calculations, and reports. Review the complete data package rather than only the result page.
- Are sample receipt, preparation, dilution, weighing, instrument setup, testing, and disposal records attributable?
- Are laboratory notebooks and worksheets controlled, paginated, issued, reconciled, and retained?
- Are raw instrument files, sequences, methods, integrations, audit trails, and processing history preserved?
- Are out-of-specification, atypical, invalidated, repeated, and aborted analyses retained and investigated?
- Are calculations and spreadsheet formulas protected, version-controlled, and independently verified?
- Are reference standards, reagents, columns, instruments, analysts, and environmental conditions traceable?
- Does second-person review include raw data, calculations, audit trails, and reported results?
- Can the laboratory retrieve a complete record after system migration or instrument replacement?
ALCOA+ Checklist for HPLC and Chromatography
Chromatography systems generate dynamic records that may include raw signals, methods, sequences, integrations, calculations, reports, and audit trails. A signed chromatogram alone may not be a complete original record.
| Review area | Checklist question | Objective evidence |
|---|---|---|
| Access | Are user accounts unique and are administrator rights independent from routine testing? | User list, roles, access review, configuration record |
| Raw data | Are all injections, sequences, aborted runs, and source files retained? | Project folder, sequence history, raw-data inventory |
| Methods | Is the approved method and relevant processing method linked to the result? | Method version, approval, system record |
| Audit trail | Are integrations, reprocessing, changes, deletions, and invalidations reviewed and justified? | Audit-trail report, review record, investigation |
| Calculations | Are formulas, dilution factors, units, rounding, and transcription independently verified? | Worksheet, calculation check, approved template |
| Retention | Can the complete dynamic record be opened and understood after retention or migration? | Archive test, validated viewer, migration evidence |
ALCOA+ Checklist for Manufacturing Records
Manufacturing records connect people, materials, equipment, process parameters, in-process controls, yields, reconciliation, and release decisions. The checklist should include both paper and electronic records used on the shop floor.
- Are master production and control records approved, current, version-controlled, and issued through document control?
- Are operators identified for each critical step, addition, check, measurement, and line clearance?
- Are entries made at the time of activity with actual values rather than copied or estimated values?
- Are equipment status, cleaning, calibration, maintenance, alarms, and interventions traceable?
- Are material identity, lot, quantity, weighing, dispensing, yield, and reconciliation records complete?
- Are deviations, stoppages, rework, rejects, adjustments, and process interruptions documented and reviewed?
- Are electronic batch records, historian data, alarms, electronic signatures, and audit trails retained?
- Can the quality unit reconstruct the batch before release and during a later complaint or recall?
ALCOA+ Checklist for Stability Studies
Stability data must remain traceable over months or years. Availability and endurance are especially important because study conclusions may depend on historical chamber conditions, sample pulls, excursions, and trends.
- Are the protocol, product, batch, packaging, condition, time point, and sample map clearly identified?
- Are chamber qualification, calibration, monitoring, alarms, excursions, and maintenance records linked?
- Are sample placement, pull, receipt, preparation, testing, and disposal recorded contemporaneously?
- Are all results, chromatograms, calculations, observations, invalidations, and retests retained?
- Are changes to protocol, method, chamber, packaging, or schedule approved and traceable?
- Are trends, OOS/OOT investigations, excursions, and scientific conclusions supported by source data?
- Can the complete study record be retrieved after personnel, instrument, or system changes?
- Are final reports linked to the data package and reviewed by authorized quality personnel?
ALCOA+ Checklist for Electronic Systems
Computerized systems should be assessed according to their intended use, data criticality, configuration, interfaces, user roles, audit-trail capability, and lifecycle. Validation alone does not remove the need for operating controls and periodic review.
- Are user requirements, intended use, data flows, interfaces, and critical functions documented?
- Are system access, roles, privileges, passwords, electronic signatures, and administrator activities controlled?
- Are audit trails enabled, protected, reviewed, and retained with the record?
- Are data and metadata saved to durable media at the point required by the process?
- Are spreadsheets and configurable reports version-controlled, tested, protected, and approved?
- Are data transfers and migrations verified for content, context, meaning, calculations, and history?
- Are backup, restore, archive, disaster recovery, cybersecurity, and vendor responsibilities documented?
- Are periodic reviews performed after upgrades, changes, incidents, access changes, or new risks?
Audit Trail and Data Review Checklist
Audit trails can reveal corrections, reprocessing, deletions, changes in parameters, and administrative actions. Review should be risk-based, connected to the record review, and performed by trained personnel.
- Does the system generate a secure, time-stamped audit trail for creation, modification, and deletion?
- Does the audit trail identify the user, date, time, old value, new value, and reason where applicable?
- Can users disable, overwrite, or delete the audit trail without detection?
- Are audit-trail reviews assigned to trained personnel independent from unauthorized data manipulation?
- Is the review frequency justified by data criticality, process risk, controls, and regulatory requirements?
- Are exceptions, unexplained changes, repeated tests, reprocessing, and invalidations investigated?
- Are audit-trail reports retained and linked to the reviewed record or batch?
- Are audit-trail findings trended and escalated when they indicate a systemic control weakness?
Training and Human-Factors Checklist
People are more likely to preserve data integrity when systems, procedures, workload, and supervision make the correct action practical. Training should explain both the rule and the reason behind it.
- Do employees receive role-specific ALCOA+ and data-integrity training before performing critical work?
- Does training cover contemporaneous recording, corrections, raw data, audit trails, shared accounts, and reporting concerns?
- Are contractors, temporary staff, service providers, and senior managers included where their activities affect data?
- Is competency assessed through observation, practical exercises, record review, or examination?
- Are refresher and change-triggered training requirements defined?
- Do procedures provide enough time, equipment, access, and workspace to record data correctly?
- Are performance targets prevented from encouraging concealment, selective reporting, or unsafe shortcuts?
- Are errors treated as opportunities for learning while intentional falsification is escalated appropriately?
Retention, Retrieval, and Archive Checklist
Records should remain protected and usable for the full approved retention period. A retention procedure should define the record, owner, location, format, access, retrieval time, restoration method, and disposition approval.
- Are retention periods based on applicable regulations, product lifecycle, contracts, investigations, and legal holds?
- Are official records and true copies clearly distinguished from convenience copies or temporary working files?
- Are archive indexes searchable by batch, sample, product, study, method, equipment, or quality event?
- Are archived paper and electronic records protected from loss, damage, unauthorized change, and premature disposal?
- Are representative retrieval and restore tests performed and documented?
- Are obsolete systems, file formats, media, readers, and vendor support assessed before they fail?
- Are archive access requests, retrievals, returns, and copies traceable?
- Are destruction records approved by the owner and checked for open investigations, complaints, recalls, or holds?
Outsourcing and Vendor Data-Integrity Checklist
Contract laboratories, manufacturers, consultants, cloud providers, and equipment vendors may create or store GxP data. The contract giver remains responsible for understanding the data flow and verifying that controls are effective.
- Does the quality or technical agreement define data ownership, access, retention, review, and return?
- Are the vendor’s systems, procedures, training, audit trails, and archive controls assessed according to risk?
- Can the contract giver obtain raw data, metadata, audit trails, calculations, and supporting records?
- Are subcontractors, cloud hosting, remote access, and data-transfer arrangements disclosed and controlled?
- Are vendor deviations, audit findings, data-integrity incidents, and changes communicated promptly?
- Are vendor records available in readable formats throughout the required retention period?
- Are data migration, termination, business continuity, and record-return responsibilities defined?
- Are supplier audits and performance reviews documented and escalated when controls are inadequate?
Common ALCOA+ Violations in GMP
Shared credentials
Actions cannot be attributed to one person when users share passwords or generic operator accounts.
Backdated entries
Records are completed later without identifying the delay, reason, actual time, or reviewer assessment.
Unofficial worksheets
Temporary paper or local spreadsheets are discarded after values are transcribed to the official record.
Missing raw data
Only a final result or report is retained while source files, audit trails, methods, or calculations are absent.
Uncontrolled corrections
Original entries are erased, overwritten, or changed without a traceable reason and approval.
Selective reporting
Invalid, atypical, repeated, or aborted tests are omitted rather than retained and scientifically investigated.
Unreviewed audit trails
Changes, reprocessing, deletions, or configuration actions are not reviewed with the associated record.
Unverified migration
Data are transferred to a new system without confirming metadata, formulas, relationships, and history.
Unretrievable archives
Records are stored but cannot be located, opened, read, or reconstructed when requested.
ALCOA+ Self-Inspection Scoring
A simple status system helps teams compare assessments without hiding the underlying evidence. Choose categories that match your quality system and avoid turning a score into a substitute for risk judgment.
| Status | Meaning | Recommended response |
|---|---|---|
| Compliant | Control is defined, implemented, effective, and supported by objective evidence. | Continue monitoring and retain the evidence reviewed. |
| Partially compliant | Control exists but has limited scope, inconsistent execution, weak evidence, or an open improvement. | Document the gap, assess risk, assign an owner, and set a due date. |
| Non-compliant | Required control is absent, ineffective, or contradicted by records or observed practice. | Contain the risk, investigate impact, and escalate through the quality system. |
| Not applicable | Principle or control does not apply to the defined scope, with documented justification. | Record the rationale and revisit if the process or system changes. |
Criticality should be considered separately. Missing HPLC raw data, an uncontrolled manufacturing calculation, and a low-risk formatting inconsistency should not be treated as equivalent simply because each receives one “finding.”
How to Respond to an ALCOA+ Checklist Finding
Protect the evidence
Secure source records, audit trails, system images, samples, equipment status, and relevant access logs before they are changed.
Define the impact
Identify affected products, batches, studies, methods, systems, time periods, users, and decisions.
Investigate the cause
Use interviews, record review, data-flow mapping, system assessment, and evidence testing instead of assumptions.
Apply containment
Prevent further loss or alteration while maintaining necessary operations through approved interim controls.
Correct the system
Address procedure, training, configuration, access, workload, vendor, equipment, and governance causes.
Check effectiveness
Use representative sampling, repeat audits, retrieval tests, and trend review to confirm the action prevents recurrence.
ALCOA+ Audit Questions for Pharmaceutical Companies
| Audit theme | Questions to ask | Evidence to sample |
|---|---|---|
| People | Who performed, recorded, reviewed, approved, configured, or changed the activity? | Training, access records, signatures, audit trails, interviews |
| Process | Does the approved procedure make contemporaneous and complete recording practical? | SOP, forms, logbooks, observations, deviations |
| Systems | Can the system prevent, detect, and record unauthorized changes? | Configuration, validation, audit trail, access review |
| Raw data | Can the reported conclusion be traced back to original observations and processing? | Raw files, methods, calculations, attachments, reports |
| Review | Did the reviewer examine the complete record, including exceptions and audit trails? | Review checklist, approvals, audit-trail review, comments |
| Lifecycle | Will the record remain readable, secure, and retrievable through retention? | Archive index, backup, restore, migration, retrieval tests |
Regulatory Context for the ALCOA+ Checklist
ALCOA+ is a practical data-integrity framework rather than a standalone regulation. Its principles help organizations demonstrate that records required by applicable GMP rules are reliable, complete, traceable, secure, and reviewable.
The FDA Data Integrity and Compliance With Drug CGMP guidance discusses attributable, legible, contemporaneous, original or true-copy, and accurate data, as well as complete and consistent records across the data lifecycle. It also addresses access controls, shared logins, audit trails, true copies, dynamic records, and record review.
The MHRA GxP data-integrity guidance describes core elements of data governance across GxP sectors, including data lifecycle controls, access, retention, archive, retrieval, and risk-based oversight. Always apply the checklist with the current regulations, regional expectations, approved procedures, and quality-unit decisions relevant to your site.
Key Takeaways
- An ALCOA+ checklist turns data-integrity principles into repeatable questions, evidence, ownership, and follow-up.
- All nine principles should be considered: attributable, legible, contemporaneous, original, accurate, complete, consistent, enduring, and available.
- Review raw data, metadata, audit trails, calculations, exceptions, attachments, approvals, and retention—not only final reports.
- Apply the checklist to paper, electronic, hybrid, laboratory, manufacturing, stability, validation, and outsourced records.
- Use risk-based sampling and distinguish a minor documentation weakness from a critical loss of source evidence.
- Protect evidence, investigate causes, contain risk, implement corrective action, and verify effectiveness when gaps are found.
Conclusion
An ALCOA+ checklist gives pharmaceutical companies a practical way to test whether their data can be trusted from creation to final disposition. It helps teams look beyond polished reports and examine the people, systems, records, metadata, audit trails, controls, and behaviors that support each quality decision.
Used consistently, the checklist strengthens GMP compliance, laboratory reliability, manufacturing traceability, inspection readiness, and the pharmaceutical quality system. The strongest programs use the checklist as a living control: they update it when risks change, support every answer with objective evidence, and use findings to improve the process rather than simply close an audit.
Frequently Asked Questions
1. What is an ALCOA+ checklist?
It is a structured review tool that tests whether pharmaceutical data meet the nine ALCOA+ characteristics and whether controls are supported by objective evidence.
2. Who should use an ALCOA+ checklist?
Quality assurance, quality control, production, validation, engineering, IT, regulatory, auditors, laboratory managers, and trained process owners can use it.
3. Is ALCOA+ a regulation?
No. ALCOA+ is a widely used data-integrity framework that helps organizations demonstrate compliance with applicable GMP and electronic-record requirements.
4. What evidence should accompany a checklist answer?
Examples include source records, raw data, metadata, audit trails, access reports, training records, procedures, validation documents, archive tests, and review approvals.
5. Does the checklist apply to paper records?
Yes. It covers controlled forms, permanent entries, corrections, pagination, signatures, storage, scanning, indexing, retrieval, and protection from physical damage.
6. Does a final report satisfy ALCOA+?
Not always. A complete record may also require raw data, metadata, audit trails, methods, calculations, exceptions, attachments, and approval history.
7. How often should companies perform an ALCOA+ review?
Frequency should be risk-based and defined by the quality system. Reviews may be routine, event-driven, periodic, pre-implementation, or triggered by system and process changes.
8. How should checklist findings be classified?
Use documented categories such as compliant, partially compliant, non-compliant, and not applicable, then assess patient, product, data, regulatory, and recurrence risk separately.
9. What is a common ALCOA+ violation?
Common examples include shared logins, backdated entries, discarded worksheets, missing raw data, unreviewed audit trails, uncontrolled corrections, and inaccessible archives.
10. When should a finding be managed through CAPA?
Use CAPA when a gap is systemic, recurring, high risk, or requires changes to procedures, systems, training, equipment, governance, or oversight.
Related ALCOA+ Resources
Use these internal resources to connect the checklist with your broader pharmaceutical quality and data-integrity program:
