Web of Pharma · Quality Control · Data Integrity
ALCOA+ Compliance in Laboratory Records
A practical guide to protecting QC laboratory notebooks, worksheets, raw data, calculations, audit trails, results, and approvals throughout the data lifecycle.
answer
ALCOA+ compliance in laboratory records means that every QC activity can be traced to an authorized person, recorded at the right time, preserved as original or verified true-copy data, reported accurately, and reconstructed from complete, consistent, enduring, and available records.
A laboratory result is only as reliable as the record supporting it. A passing assay without the original weighing, dilution, instrument sequence, processing method, calculation, or audit trail cannot fully demonstrate how the result was produced.
ALCOA+ compliance in laboratory records covers the entire QC data lifecycle: sample receipt, preparation, analysis, processing, review, reporting, investigation, archiving, retrieval, and disposition. It applies to paper notebooks, controlled worksheets, HPLC and GC systems, UV-Vis, FTIR, dissolution, balances, pH meters, microbiology, environmental monitoring, spreadsheets, LIMS, and outsourced laboratories.
Use this article with your approved cGMP procedures and the broader ALCOA data-integrity framework. The emphasis is practical: what to record, what to review, what evidence to retain, and how to respond when a laboratory record is incomplete.
What Does ALCOA+ Mean for Laboratory Records?
ALCOA+ is a set of data-integrity characteristics used to evaluate whether laboratory information remains trustworthy and usable. The original ALCOA principles are attributable, legible, contemporaneous, original, and accurate. The additional principles are complete, consistent, enduring, and available.
| Principle | Laboratory expectation | Example evidence |
|---|---|---|
| Attributable | Every observation, result, change, review, and approval is linked to a named person or controlled system. | Analyst ID, reviewer signature, user-access report, audit trail |
| Legible | Notebook entries, printouts, scans, displays, units, and metadata remain readable and understandable. | Original page, readable scan, approved format, archive check |
| Contemporaneous | Sampling, weighing, preparation, testing, and observations are recorded as the activity occurs. | Time-stamped transaction, notebook sequence, instrument record |
| Original | The first capture or a verified true copy preserves content, context, structure, and history. | Raw instrument file, controlled notebook, verified scan |
| Accurate | Results, calculations, transcriptions, units, and conclusions reflect what actually happened. | Raw data, formula check, calibration, second-person review |
| Complete | All raw data, failed or repeated work, audit trails, methods, calculations, and attachments are retained. | Data package, sequence, exceptions, investigation |
| Consistent | Sample IDs, dates, times, units, methods, versions, and processing history align across records. | Cross-reference, LIMS record, system comparison |
| Enduring | Records remain protected, readable, meaningful, and usable during the retention period. | Archive, backup, migration, restore, media check |
| Available | Authorized reviewers can locate, retrieve, open, and understand the complete record when needed. | Retrieval test, access matrix, archive index |
What Makes a Complete Laboratory Record?
A laboratory record is more than the final result. The complete data package should contain the information needed to reconstruct the sample’s journey from receipt through reporting and approval.
Sample identity
Product, batch, material, sample number, location, condition, quantity, receipt date, and chain-of-custody information.
Preparation evidence
Weights, volumes, dilutions, extractions, standards, reagents, glassware, preparation times, and analyst identity.
Instrument context
Instrument ID, calibration status, maintenance, system suitability, method version, sequence, run time, and equipment status.
Raw data
Original observations, chromatograms, spectra, readings, images, signals, files, and records generated by the system.
Processing and calculations
Integration, formulas, dilution factors, reference values, units, rounding, processing parameters, and calculation review.
Exceptions
Failed, aborted, invalidated, repeated, atypical, out-of-specification, or out-of-trend work with scientific justification.
Review and approval
Second-person review, audit-trail review, comments, signatures, dates, approvals, and investigation references.
Retention
Archive location, format, metadata, access controls, backup, retrieval method, and approved retention period.
Traceability
Links between sample, batch, method, instrument, analyst, result, report, deviation, and release or stability decision.
ALCOA+ Compliance for Sample Receipt and Chain of Custody
Integrity begins before the first test. A weak sample-receipt record can make later laboratory data difficult to connect to the correct product or batch.
- Record sample identity, product or material, batch or lot, quantity, condition, and source.
- Assign a unique laboratory or sample number before preparation and analysis.
- Document receipt date, time, receiver, storage condition, seal status, and any discrepancy.
- Maintain chain-of-custody or transfer records when samples move between rooms, laboratories, or vendors.
- Record sampling plan, location, sampler, sampling equipment, and representative-sample justification where applicable.
- Investigate damaged, missing, mislabeled, expired, insufficient, or temperature-excursed samples.
- Link the sample record to the test request, specification, method, batch record, and final report.
- Prevent relabeling or replacement of samples without a documented, approved, traceable process.
ALCOA+ Compliance in Laboratory Notebooks and Worksheets
Paper notebooks and worksheets should make the first capture of an observation easy, accountable, and permanent. Controlled pages also help detect missing entries and unofficial records.
- Use bound, paginated, numbered, or otherwise controlled notebooks and worksheets for critical data.
- Issue forms through document control and reconcile unused, damaged, cancelled, or replaced forms.
- Record observations, weights, volumes, times, instrument readings, and calculations at the point of activity.
- Use permanent ink and approved correction practices that preserve the original entry, reason, date, and person.
- Do not use loose paper, desk calendars, sticky notes, or personal notebooks as undisclosed raw data.
- Reference attachments, chromatograms, spectra, photographs, printouts, and calculations to the source page.
- Document deviations, unusual observations, failed preparations, and repeated work rather than removing them.
- Ensure reviewer signatures and dates show what was reviewed and when the review occurred.
ALCOA+ Compliance for Laboratory Instruments
Instrument records include more than a displayed result. The laboratory should define what constitutes raw data for each instrument and retain the metadata and system context needed to interpret it.
| Instrument or activity | Records to preserve | Key ALCOA+ control |
|---|---|---|
| Balance and weighing | Sample or standard ID, balance ID, calibration status, weight, unit, date/time, analyst, and printout or electronic record. | Record the actual weight at the time of weighing and retain the original output. |
| pH meter | Sample, meter ID, buffer details, calibration, temperature, reading, analyst, and observation. | Link calibration and measurement records; do not transcribe only a preferred value. |
| UV-Vis | Raw spectra, method, wavelength, scan settings, cuvette or sample details, calculations, and report. | Retain dynamic source data when the spectrum can be reprocessed or examined. |
| FTIR | Original spectrum, background, library search, instrument status, method, sample preparation, and result. | Do not rely only on a static printout when dynamic data are needed for review. |
| Dissolution | Apparatus ID, vessel and position, medium, temperature, speed, sampling time, sample ID, readings, and calculations. | Record actual conditions and link sample, apparatus, method, and results. |
| HPLC or GC | Raw files, sequence, method, processing, integrations, audit trail, system suitability, calculations, and report. | Review the complete data set, including aborted, repeated, and reprocessed injections. |
ALCOA+ Compliance in HPLC and Chromatography Records
Chromatography is a high-risk area because a dynamic data system can allow changes to integration, methods, sequences, processing parameters, and reported results. A signed chromatogram should be supported by the complete original data package.
HPLC record checklist
- Use individual accounts and confirm that access privileges match the analyst’s role.
- Retain all injections, sequences, aborted runs, invalidated injections, reinjections, and repeat analyses.
- Preserve instrument ID, analyst, date/time, method version, column, system suitability, and sequence context.
- Retain raw signals, chromatograms, processing methods, integration parameters, calculations, and final reports.
- Review audit trails for reprocessing, changes, deletions, method changes, and data exclusions.
- Document scientific reasons and approvals for reprocessing, reinjection, invalidation, or repeat testing.
- Prevent analysts from deleting or overwriting source files without a controlled, detectable record.
- Test that archived data can be opened and understood with the available software or validated viewer.
ALCOA+ Compliance in Microbiology and Environmental Monitoring
Microbiological records may include manual observations, plate counts, incubation conditions, photographs, identifications, environmental locations, and electronic monitoring data. The review should preserve both the observation and the context in which it was made.
- Identify sample location, room, activity, date, time, sampler, medium, and incubation conditions.
- Record colony counts, growth observations, identifications, photographs, and calculations contemporaneously.
- Retain plates, images, worksheets, instrument files, and environmental-monitoring system data where required.
- Document damaged plates, contamination, unreadable labels, missed locations, and sampling deviations.
- Link bioburden, endotoxin, sterility, preservative-effectiveness, and environmental results to the sample and method.
- Review atypical, out-of-trend, or alert/action-level results through the approved investigation process.
- Ensure incubator, autoclave, particle counter, and other equipment status is current and traceable.
- Protect photographs and electronic images from uncontrolled replacement or editing.
ALCOA+ Compliance for Calculations and Spreadsheets
Calculations can change a laboratory result even when the raw reading is correct. Spreadsheet and worksheet controls should protect formulas, document inputs, and make review reproducible.
- Use approved, version-controlled templates for calculations that affect GMP results.
- Protect formulas, critical cells, macros, worksheets, and reference tables from unauthorized change.
- Identify the creator, reviewer, date, purpose, and version of each calculation tool.
- Retain input data, intermediate values, formulas, units, dilution factors, rounding, and final outputs.
- Independently verify critical calculations or use validated software with appropriate checks.
- Document changes to formulas, templates, limits, constants, and reference values through change control.
- Prevent personal or local spreadsheets from becoming undisclosed sources of record data.
- Test the spreadsheet with boundary, error, and representative cases before use and after changes.
OOS, OOT, Retest, and Invalidated Data
Laboratory investigations must not become a mechanism for selecting only results that support release. All relevant data should be retained, and a result should be invalidated only through a scientifically justified, documented investigation.
Retain the first result
Keep the original OOS, OOT, atypical, failed, aborted, or unexpected result with its complete raw data.
Define the hypothesis
Use evidence to test sampling, preparation, instrument, method, analyst, calculation, and process causes.
Control retesting
Follow an approved plan with justified sample numbers, acceptance criteria, authorization, and documented execution.
Review audit trails
Check changes, reprocessing, deleted files, integrations, sequence history, and user activity.
Assess product impact
Consider batch release, other batches, stability, complaints, method performance, and data reliability.
Link the conclusion
Connect the investigation, scientific rationale, approvals, CAPA, and final report to the original data.
When a laboratory record shows a recurring investigation weakness or data-integrity failure, use CAPA to address the underlying system, process, training, or governance cause.
Second-Person Review and Laboratory Approval
Independent review should evaluate the complete record rather than only checking that a signature is present. The reviewer should be sufficiently trained, independent for the decision, and able to access the raw data and metadata.
- Confirm sample identity, method, specification, instrument, analyst, date, and result are consistent.
- Compare reported values with raw readings, chromatograms, spectra, images, worksheets, and calculations.
- Review system suitability, calibration, standard preparation, sample preparation, and equipment status.
- Check audit trails, reprocessing, repeat injections, deleted or invalidated records, and exceptions.
- Confirm OOS/OOT, deviations, retests, and investigations are complete and scientifically justified.
- Verify reviewer identity, date, comments, approval, and escalation of unresolved questions.
- Record review findings rather than correcting the analyst’s source record informally.
- Confirm that the complete data package is linked to the report, batch, stability study, or quality event.
Electronic Laboratory Systems and Audit Trails
LIMS, CDS, ELN, instrument software, and laboratory spreadsheets should be governed across their lifecycle. Validation supports intended use, but daily controls, user access, review, and audit-trail oversight remain essential.
| Control area | Questions for the laboratory | Evidence to retain |
|---|---|---|
| Access | Are accounts individual, roles appropriate, and administrator privileges controlled? | Access matrix, approvals, periodic review, disabled-user report |
| Audit trail | Does the system record who, what, when, and why for relevant changes? | Configuration, audit-trail report, review record |
| Data saving | Are results and metadata saved to durable media at the required point? | System settings, transaction history, procedure, test record |
| Raw data | Are dynamic files, methods, sequences, processing, and attachments retained? | Data inventory, project folder, archive sample |
| Transfer | Are interfaces, exports, migrations, and manual transcriptions verified? | Mapping, validation, reconciliation, audit trail |
| Recovery | Can representative records be restored, opened, and understood? | Backup, restore test, archive and retrieval report |
Retention, Archive, and Retrieval of Laboratory Records
Laboratory data may be needed for batch investigations, complaints, recalls, stability decisions, regulatory submissions, and method lifecycle review. Retention controls should preserve the information and context needed to reconstruct the activity.
- Define the official laboratory record, retention period, owner, archive location, and disposition rules.
- Retain raw data, metadata, audit trails, methods, calculations, reports, and relevant configuration.
- Use durable paper, controlled scans, validated archive formats, and supported software or readers.
- Protect records from loss, alteration, unauthorized access, media degradation, and premature destruction.
- Test retrieval using old, dynamic, large, migrated, and exception-containing records.
- Document backup, restore, migration, true-copy, and archive verification activities.
- Maintain links between samples, raw files, reports, investigations, batches, and approvals.
- Check for open investigations, complaints, recalls, legal holds, or regulatory requests before disposal.
Common ALCOA+ Failures in Laboratory Records
Loose raw-data sheets
Analysts use unnumbered paper or desk notes and selectively transcribe values into the official worksheet.
Final report only
The approved result is retained while raw instrument files, calculations, methods, or audit trails are missing.
Shared accounts
Multiple analysts use one login, preventing reliable attribution of entries, changes, and approvals.
Reprocessing without reason
Integration or processing changes are made to improve a result without scientific justification and review.
Missing injections
Aborted, failed, or repeated injections are absent from the official sequence without explanation.
Uncontrolled spreadsheets
Formulas, units, limits, and reference values change without version control or independent verification.
Incomplete OOS files
First results, retest data, investigation evidence, or invalidation rationale are not retained together.
Unreadable archives
Scans fade, files cannot be opened, or metadata and audit trails are lost during migration.
Weak review
The second-person review checks signatures and final values but not raw data, exceptions, or audit trails.
How to Implement ALCOA+ in a QC Laboratory
Map laboratory data
Identify samples, notebooks, instruments, systems, spreadsheets, reports, archives, vendors, and the decisions they support.
Define raw data
Document the first capture, associated metadata, audit trails, methods, processing, calculations, and attachments for each technique.
Control the workflow
Provide approved procedures, controlled forms, unique accounts, suitable equipment, recording space, and realistic time.
Train and qualify
Teach analysts and reviewers how to record, correct, investigate, review, retain, and retrieve laboratory data.
Review the data
Use risk-based second-person and audit-trail review that covers exceptions, raw data, calculations, and reported conclusions.
Test retention
Run representative archive, backup, restoration, migration, and retrieval tests and document the results.
Trend failures
Monitor late entries, missing data, repeat testing, audit-trail exceptions, access issues, and retrieval failures.
Improve the system
Use deviations, root-cause analysis, change control, training, and CAPA to address systemic weaknesses.
Verify effectiveness
Repeat sampling and review to confirm that controls work across analysts, instruments, methods, and record types.
ALCOA+ Laboratory Records Audit Checklist
Use these questions during self-inspection, routine data review, laboratory audit, OOS investigation, or computerized-system periodic review:
| Audit theme | Question | Evidence to sample |
|---|---|---|
| Sample traceability | Can the complete chain be followed from sampling and receipt through testing and reporting? | Sample log, chain of custody, test request, report |
| Raw data | Are first-capture observations, dynamic files, methods, metadata, and audit trails retained? | Notebook, instrument system, raw-data inventory |
| Attribution | Can every critical action, change, review, and approval be linked to one authorized person? | User list, signatures, access report, audit trail |
| Chronology | Were preparation, testing, processing, review, and approval recorded at the time they occurred? | Time stamps, sequences, notebooks, interviews |
| Accuracy | Are calculations, units, transcriptions, instrument status, and specifications verified? | Worksheets, formulas, calibration, second-person check |
| Exceptions | Are failed, aborted, repeated, OOS, OOT, and atypical data retained and explained? | Sequence, investigations, deviations, audit trail |
| Review | Does second-person review include raw data, calculations, metadata, and audit trails? | Review checklist, comments, approval record |
| Retention | Can records be opened, read, and retrieved throughout the retention period? | Archive index, restore test, migration evidence |
| Improvement | Are recurring weaknesses escalated, corrected, and checked for effectiveness? | Deviation, CAPA, trend report, follow-up audit |
Laboratory Data-Integrity Metrics
Metrics should reveal risk and support improvement rather than encourage analysts to hide errors. Trend data by method, instrument, analyst, laboratory area, system, vendor, and ALCOA+ principle.
Complete-record rate
Percentage of sampled data packages containing raw data, metadata, methods, calculations, audit trails, and approvals.
Late-entry rate
Frequency of delayed or retrospective entries compared with the relevant notebook or test population.
Audit-trail exceptions
Unexplained reprocessing, deletions, changes, invalidations, or access events identified during review.
Retest and repeat trends
Patterns that may indicate method, instrument, training, sampling, or reporting weaknesses.
Retrieval success
Percentage of representative records retrieved completely, readably, and within the defined time.
Repeat findings
Laboratory data-integrity findings recurring after corrective action, retraining, or system change.
Regulatory Perspective on Laboratory Data Integrity
ALCOA+ is a practical data-integrity framework rather than a standalone regulation. It helps laboratories demonstrate that GMP records are reliable, authentic, complete, and suitable for the decisions they support.
The FDA pharmaceutical quality-control laboratory inspection guide emphasizes review of raw laboratory data, laboratory records, logs, worksheets, chromatograms, spectra, failed and retested analyses, equipment status, and the authenticity of reported results.
The FDA data-integrity guidance explains the ALCOA characteristics, metadata, audit trails, access restrictions, complete records, true copies, and dynamic electronic data. The MHRA GxP data-integrity guidance adds expectations for data governance, processing traceability, exclusion of data, retention, audit-trail review, and risk-based controls.
Apply these expectations with the current requirements of the markets where your products are manufactured, tested, released, or supplied, together with your approved procedures and quality-unit decisions.
Key Takeaways
- Laboratory ALCOA+ compliance covers sample receipt, preparation, raw data, processing, review, reporting, retention, and retrieval.
- A final result or signed report is not automatically a complete record.
- Retain original or verified true-copy data, metadata, methods, audit trails, calculations, exceptions, and approvals.
- HPLC, GC, UV-Vis, FTIR, dissolution, microbiology, balances, pH meters, LIMS, spreadsheets, and paper notebooks need risk-based controls.
- Failed, aborted, repeated, invalidated, OOS, OOT, and atypical results must be retained and scientifically evaluated.
- Use routine review, audit-trail monitoring, retrieval tests, metrics, investigations, and CAPA to prevent recurrence.
Conclusion
ALCOA+ compliance in laboratory records protects the evidence behind every pharmaceutical testing decision. It ensures that an analyst’s observation, an instrument’s raw signal, a calculation, a reviewer’s assessment, and a final report remain connected and trustworthy.
The strongest QC laboratories make compliant recording practical, define raw data clearly, retain complete data packages, review exceptions honestly, control electronic systems, and test archive retrieval. When laboratory records can be reconstructed without guesswork, the quality unit can make stronger decisions and demonstrate reliable GMP control.
Frequently Asked Questions
1. What is ALCOA+ compliance in laboratory records?
It means laboratory data meet the attributable, legible, contemporaneous, original, accurate, complete, consistent, enduring, and available characteristics throughout the data lifecycle.
2. What is considered raw data in a laboratory?
Raw data are the first capture of observations or electronic signals and the associated metadata, methods, processing, calculations, and records needed to reconstruct the activity.
3. Is a signed laboratory report enough?
Not always. The complete record may also require sample preparation, raw instrument files, methods, sequences, audit trails, calculations, exceptions, attachments, and review evidence.
4. Why are shared laboratory logins a problem?
Shared accounts prevent reliable attribution of data entry, changes, processing, review, and approval to one individual.
5. Should failed or invalidated tests be retained?
Yes. They are part of the analytical history and may be needed to assess laboratory error, product impact, selection bias, and the validity of the final conclusion.
6. Can a chromatogram PDF replace the original HPLC file?
Only when a documented, risk-based assessment shows that the copy preserves the content, context, metadata, audit trail, and meaning required for the intended review.
7. How should laboratory notebooks be controlled?
Use bound or paginated notebooks, controlled issuance, permanent entries, transparent corrections, page reconciliation, attachment references, and documented review.
8. How often should laboratory audit trails be reviewed?
Frequency should be risk-based and defined by the quality system, considering data criticality, system controls, process risk, and applicable GMP requirements.
9. When should a laboratory data-integrity issue become CAPA?
CAPA is appropriate when the issue is systemic, recurring, high risk, or requires lasting changes to procedures, systems, training, equipment, vendors, or oversight.
10. How can a laboratory demonstrate ALCOA+ compliance?
Maintain objective evidence such as controlled procedures, training, raw-data packages, access reports, audit-trail reviews, calculations, investigations, archive tests, metrics, and effectiveness checks.
Related ALCOA+ Resources
Connect this laboratory-records guide with the broader pharmaceutical quality and data-integrity framework:
