Web of Pharma · Data Integrity · ALCOA+
Available Principle in ALCOA+
How authorized teams can locate, read, and review complete pharmaceutical data whenever a quality decision, investigation, or inspection requires it.
answer
The Available Principle in ALCOA+ means that authorized personnel can locate, retrieve, read, and review complete data when it is needed. Availability includes raw data, metadata, audit trails, methods, calculations, attachments, signatures, and context—not just a final report or a file name.
Pharmaceutical data has value only when people can find it and understand it. A result hidden in an unindexed folder, an HPLC file that cannot be opened, or a batch record separated from its attachments may technically exist but is not practically available.
The Available Principle applies across the data lifecycle: creation, processing, review, approval, retention, archival, retrieval, and disposition. It covers paper records, laboratory systems, manufacturing platforms, spreadsheets, stability databases, validation files, quality events, and outsourced activities.
Availability works inside cGMP controls and complements the broader ALCOA data-integrity framework. This guide turns the principle into practical design, operating, archive, and audit controls for pharmaceutical organizations.
What Is the Available Principle in ALCOA+?
Data are available when the right person can obtain the right record, in a readable and meaningful form, at the time and place required for an authorized purpose. The record must include enough context to support reconstruction, review, verification, and a defensible quality decision.
Availability is therefore more than system uptime or a successful login. It depends on findability, permissions, readable formats, retained metadata, working software, reliable retrieval processes, and evidence that the controls have been tested.
| Availability question | What good control looks like | Evidence an auditor can review |
|---|---|---|
| Can the record be found? | Controlled indexes, identifiers, search fields, naming rules, and ownership make the record discoverable. | Archive index, record register, search log, or retrieval request. |
| Can it be opened and read? | Approved readers, supported software, durable paper, and human-readable outputs remain available. | Retrieval test, viewer qualification, archive inspection, or readability check. |
| Is the context intact? | Raw data, metadata, audit trails, methods, calculations, attachments, and approvals remain linked. | Source-to-report review, audit-trail export, or true-copy verification. |
| Can an authorized person access it? | Unique accounts, role-based permissions, documented requests, and controlled administrator access are in place. | Access matrix, user review, permission log, or training record. |
| Will access work after failure? | Backup, archive, restore, disaster recovery, and migration controls are validated or verified. | Restore test, migration report, recovery exercise, and deviation record. |
Available Is More Than Stored
Storage answers the question “Where is the data?” Availability answers a larger set of questions: “Can the right person find it, open it, understand it, verify it, and use it without changing the evidence?” Each layer below should be considered during system design and periodic review.
Exists
The record, raw data, or approved copy is retained in an identified location rather than held on an uncontrolled personal device.
Findable
Identifiers, indexes, metadata, and naming conventions allow a reviewer to locate the exact batch, sample, run, or quality event.
Readable
Paper and electronic records can be viewed clearly without relying on unavailable software, damaged media, or undocumented conversion.
Complete
Supporting raw data, audit trails, methods, calculations, signatures, and attachments are available with the reported result.
Contextual
Dates, times, users, instrument identifiers, units, configuration, status, and relationships remain understandable.
Authorized
Access is granted through named users and approved roles, with controls that prevent unauthorized change or disclosure.
Timely
Retrieval can support batch disposition, investigation, complaint response, and inspection requests within defined expectations.
Recoverable
Backups, archives, and restoration procedures have been tested so availability does not depend on an assumption.
Traceable
Access, retrieval, copying, migration, and changes can be explained through records, audit trails, and controlled procedures.
Why Data Availability Matters in Pharmaceutical Quality
Quality decisions are evidence-based. A release reviewer needs the executed batch record and associated checks; a laboratory investigator needs the complete analytical sequence; a stability scientist needs historical pulls and chamber conditions; and an inspector may request any of these records with little notice.
Batch disposition
Manufacturing and laboratory evidence must be accessible to confirm that approved instructions were followed and acceptance criteria were met.
Deviation and OOS work
Investigators need original observations, audit trails, calculations, training, equipment history, and prior events to test possible causes.
Complaints and recalls
Rapid retrieval of traceability, distribution, testing, and batch history supports effective health-risk assessment and action.
Stability decisions
Protocols, chamber records, pulls, results, excursions, trends, and approvals must remain available throughout the study and product lifecycle.
Validation evidence
Protocols, raw readings, calculations, deviations, and reports support continued confidence in equipment, methods, and computerized systems.
Inspection readiness
A controlled retrieval process demonstrates that data governance works in practice, not only in a written procedure.
FDA data-integrity guidance describes data integrity across creation, modification, processing, maintenance, archival, retrieval, transmission, and disposition. Availability must therefore be designed for the complete lifecycle rather than added only after a record is archived.
Availability Across the Pharmaceutical Data Lifecycle
| Lifecycle stage | Availability risk | Practical control |
|---|---|---|
| Creation and capture | Data are recorded on loose paper, local drives, or temporary worksheets that are hard to reconcile. | Provide controlled forms, approved systems, nearby recording points, unique identifiers, and clear ownership. |
| Processing and calculation | Methods, formulas, intermediate files, or audit trails are separated from the reported result. | Retain raw and processed data with metadata, version control, calculation review, and traceable links. |
| Review and approval | Reviewers cannot access source data, or permissions delay an important quality decision. | Use role-based access, documented review workflows, read-only evidence, and escalation paths. |
| Retention and archive | Records are stored without an index, reader, migration plan, or documented retention owner. | Define archive format, location, search fields, access rules, integrity checks, and retention responsibility. |
| Retrieval and inspection | Records are found slowly, are unreadable, or lack metadata and attachments. | Run representative retrieval tests and document response time, completeness, readability, and reviewer sign-off. |
| Disposition | Records are destroyed while investigations, holds, or retention obligations remain open. | Use approved disposition authorization, hold checks, destruction logs, and retained evidence of the decision. |
Controls for Available Paper Records
Paper remains a source record for many pharmaceutical activities. Availability depends on controlled issuance, good indexing, physical protection, and a retrieval process that preserves page order, attachments, signatures, and corrections.
- Use controlled, numbered forms, bound notebooks, or paginated logbooks for critical records.
- Record the batch, sample, equipment, study, or event identifier on every page and attachment.
- Maintain a clear index, filing convention, archive location, and owner for each record class.
- Protect records from moisture, heat, light, dust, insects, unauthorized removal, and accidental loss.
- Use permanent, legible entries and approved correction practices that preserve the original entry.
- Control check-out and return of records so the archive location is always known.
- Verify that scanned or copied records are complete, readable, and linked to the source record.
- Train staff to return records promptly and report missing, damaged, or misfiled pages.
| Paper scenario | Availability weakness | Better practice |
|---|---|---|
| Executed batch record | Loose pages are filed without a batch index or attachment reconciliation. | Use page counts, controlled filing, attachment lists, and a documented retrieval location. |
| Laboratory notebook | Entries are difficult to locate because samples and dates are not cross-referenced. | Use sequential entries, sample identifiers, page references, and a controlled notebook register. |
| Equipment logbook | The current log is kept in an area that reviewers cannot access without an informal request. | Place controlled logs where the activity occurs and define authorized access and review routes. |
| Scanned archive | Pages are cropped, out of order, or missing signatures and attachments. | Use a verified scanning process, image-quality checks, reconciliation, and documented approval. |
Controls for Available Electronic Records
Electronic availability requires more than keeping a file on a server. The organization must preserve the data’s content, context, metadata, audit trail, relationships, and the software or viewer needed for meaningful review.
- Assign each system a data owner, record owner, retention rule, and approved archive location.
- Use unique user accounts, role-based permissions, and controlled administrator access.
- Retain raw data, methods, sequences, calculations, audit trails, electronic signatures, and reports.
- Keep dynamic records in a format that supports the review required for their intended use.
- Document file naming, indexing, search fields, version control, and relationships between records.
- Monitor storage capacity, system health, software support, certificates, interfaces, and vendor dependencies.
- Validate or verify data transfer, migration, scanning, conversion, and true-copy processes.
- Use secure backup and archive controls with defined recovery objectives and periodic restore tests.
- Make records available in human-readable form without enabling uncontrolled alteration.
ALCOA+ Availability in HPLC and Laboratory Data
Chromatographic records illustrate why availability must include more than a final printed result. A reviewer may need to understand the sample sequence, instrument, method, processing parameters, integrations, reinjections, reprocessing, audit trail, calculations, and approval history.
What should be available?
- Original raw data files and the complete sample or injection sequence.
- Instrument identifier, analyst identity, date and time, method version, and system status.
- Processing methods, integration parameters, calculations, report templates, and result files.
- Audit-trail entries for changes, reprocessing, deleted or invalidated injections, and justifications.
- Reference standards, sample preparation records, worksheets, calculations, and final approvals.
- Validated viewers or supported software that can display the record and its relevant metadata.
Common laboratory availability failure
A laboratory may provide a signed chromatogram but be unable to produce the original sequence, processing method, audit trail, or invalidated injections. The report exists, yet the evidence needed to evaluate the result is unavailable. Prevent this by defining the complete record in the laboratory data-retention procedure and testing retrieval from the archive.
Availability in Manufacturing and Stability Records
| Record area | Records that should remain available | Availability check |
|---|---|---|
| Manufacturing | Executed batch records, electronic batch data, equipment logs, line-clearance evidence, labels, reconciliation, and approvals. | Can a reviewer reconstruct the batch, verify each critical step, and trace the materials and equipment used? |
| Packaging | Packaging instructions, coding and inspection results, reconciliation, artwork versions, line checks, and exception records. | Can the site confirm the correct component, code, quantity, and release decision for the batch? |
| Stability | Protocol, sample map, chamber conditions, pull schedule, results, excursions, calculations, trends, and approvals. | Can the study be reconstructed from sample placement through the latest approved conclusion? |
| Environmental monitoring | Location maps, sampling records, incubation conditions, counts, identifications, excursions, and trend reviews. | Can the organization connect each result to the location, time, method, analyst, and investigation? |
| Validation | Approved protocols, raw readings, calculations, deviations, change assessments, reports, and signatures. | Can an independent reviewer confirm that acceptance criteria were tested and conclusions are supported? |
For every record class, define the official source, required attachments, authorized users, retention period, archive location, retrieval owner, and acceptable response time. This turns a broad principle into a measurable quality-system expectation.
Access, Roles, and Security for Available Data
Availability must be balanced with confidentiality and data-integrity protection. A record should be accessible to authorized users without becoming editable by everyone who can view it.
Role-based access
Assign permissions according to job responsibility and record purpose. Review access when roles change.
Unique identities
Use individual accounts and electronic signatures so access and actions are attributable to a person.
Least privilege
Give users the minimum rights needed to perform approved tasks; separate administration from data review where practical.
Read-only review
Provide a protected viewing path for archived records so review does not create uncontrolled changes.
Emergency access
Define temporary access, approval, logging, and post-event review for urgent quality or recovery situations.
Vendor controls
Include ownership, accessibility, retention, support, and data-return expectations in technical agreements.
Do not solve an availability problem with shared passwords, emailed raw files, uncontrolled removable media, or unapproved copies. These shortcuts may make a record easier to reach while weakening attribution, confidentiality, and the audit trail.
Archive, Backup, and Retrieval Testing
Availability depends on a deliberate distinction between active records, backups, and archives. The exact terminology may differ by organization, but the responsibilities should be unambiguous.
| Control | Primary purpose | What to verify |
|---|---|---|
| Active system | Supports current creation, processing, review, and approval. | Users can perform authorized work and source records remain linked to their metadata. |
| Backup | Supports recovery after corruption, hardware failure, or another disruption. | Copies are complete, secure, restorable, and protected from alteration or loss. |
| Archive | Preserves the official record for the approved retention period. | Records are indexed, protected, readable, retrievable, and linked to required context. |
| True copy | Provides a verified copy that preserves the content, context, structure, metadata, and history of the source. | The copying process is controlled, verified, documented, and suitable for the intended use. |
| Retrieval test | Demonstrates that an authorized person can produce and understand the record. | Test results cover search, access, completeness, readability, timing, and reviewer approval. |
Test representative records, not only the easiest examples. Include old file formats, legacy systems, paper scans, large data sets, records with audit trails, and records held by service providers. Document failures as quality events and assess whether a broader impact review is required.
Common Failures of the Available Principle
Unindexed storage
Files are retained on a shared drive or in boxes without a controlled identifier, owner, or retrieval location.
Final report only
A signed report is saved but raw data, audit trails, methods, calculations, or attachments are unavailable.
Inactive accounts
Records depend on a former employee’s account or a shared password that no longer works.
Obsolete software
Electronic files exist but cannot be opened, rendered, searched, or interpreted with supported tools.
Unverified migration
Data are moved without checking metadata, audit trails, formulas, relationships, or the meaning of the result.
Backup confusion
A temporary recovery copy is treated as the official archive without an index, retention owner, or restore evidence.
Broken attachments
Reports, worksheets, images, logs, or approvals are separated so the full record cannot be reconstructed.
Uncontrolled sharing
People email or copy records to make them accessible, creating duplicate versions and weakening security.
No retrieval rehearsal
The organization assumes the archive works and discovers missing data, permissions, or readers during an inspection.
How to Implement the Available Principle
Map critical records
List paper and electronic records by process, product, study, system, owner, criticality, and retention requirement.
Define availability needs
Set search fields, authorized users, readable formats, required context, retrieval timing, and escalation routes.
Design the controls
Configure access, indexing, archive, backup, audit trails, readers, interfaces, and physical storage around the risk.
Qualify and train
Validate or verify systems and processes, then train users to create, file, retrieve, review, and protect records correctly.
Test retrieval
Run documented searches, restores, archive reviews, and migration checks using representative records and realistic timelines.
Monitor and improve
Trend retrieval failures, access delays, missing attachments, and archive defects; use CAPA when the weakness is systemic.
Availability should be measurable. Useful indicators include retrieval success rate, average retrieval time, incomplete-record rate, restore-test success, unresolved access requests, migration exceptions, and archive-related deviations.
Available Principle Audit Checklist
Use the following questions during self-inspection, periodic review, computerized-system assessment, or a data-integrity audit:
- Are record owners, retention periods, archive locations, and retrieval responsibilities documented?
- Can an authorized reviewer locate representative records using controlled identifiers and indexes?
- Are raw data, metadata, audit trails, methods, calculations, attachments, and approvals available together?
- Can records be opened and read with supported paper, software, hardware, or viewer technology?
- Are dynamic records retained in a form that supports the required review and reconstruction?
- Are role-based access, unique accounts, administrator rights, and periodic access reviews effective?
- Are backup, archive, restore, migration, scanning, and true-copy controls validated or verified?
- Are archive and retrieval tests documented with timing, completeness, readability, and reviewer approval?
- Are vendors and cloud providers contractually responsible for data ownership, accessibility, retention, and return?
- Are availability failures investigated, risk-assessed, trended, and escalated through the quality system?
Keep objective evidence for each answer: indexes, retrieval requests, access reports, restore results, migration validation, archive inspections, training records, and approved procedures.
How Available Fits Into ALCOA+
Available is one of the four additional ALCOA+ principles. It works with attributable, legible, contemporaneous, original, accurate, complete, consistent, and enduring records. A record can be accurate but unavailable if no authorized person can retrieve it; it can be available but not complete if only a final report is produced without the supporting raw data.
Consider an HPLC result stored as a signed PDF. The file may be easy to open, but the record is not fully available if the original sequence, processing method, audit trail, or metadata cannot be retrieved. Likewise, a paper batch record is not available if its archive location is unknown or critical pages cannot be read.
Key Takeaways
- Available data can be found, opened, read, understood, and reviewed by authorized people when needed.
- Availability includes raw data, metadata, audit trails, methods, calculations, attachments, signatures, and context.
- Storage alone does not prove availability; indexing, permissions, readers, archive controls, and retrieval tests are also required.
- Paper, laboratory, manufacturing, stability, validation, and quality-system records need availability controls across their full lifecycle.
- Backup, archive, and true-copy functions have different purposes and should not be treated as interchangeable.
- Retrieval failures should be investigated, risk-assessed, trended, and managed through CAPA when systemic.
Conclusion
The Available Principle in ALCOA+ makes pharmaceutical data usable when it matters. It ensures that authorized people can locate and review the complete evidence behind a batch decision, laboratory result, stability conclusion, validation report, investigation, or regulatory response.
Reliable availability is built through controlled records, clear indexes, role-based access, readable formats, retained metadata, secure archives, tested backups, validated migration, and realistic retrieval exercises. When organizations prove that their data can be found and understood—not merely stored—they strengthen data integrity and the credibility of the pharmaceutical quality system.
Frequently Asked Questions
1. What is the Available Principle in ALCOA+?
It means authorized personnel can locate, retrieve, read, and review complete data when needed for an approved pharmaceutical activity.
2. Is available the same as accessible?
They are closely related, but available also includes findability, readability, completeness, context, and timely retrieval—not just permission to log in.
3. What data must be available?
The required record includes raw data, metadata, audit trails, methods, calculations, attachments, signatures, approvals, and context needed to reconstruct the activity.
4. Does a final PDF prove data availability?
No. A PDF may support review, but it may not preserve dynamic raw data, metadata, audit trails, processing history, or the ability to reconstruct the result.
5. How can paper records remain available?
Use controlled forms, clear identifiers, indexing, protected storage, check-out controls, readable entries, attachment reconciliation, and a documented retrieval process.
6. How is availability tested for electronic records?
Run representative searches and restores, then check access, completeness, readability, metadata, audit trails, timing, and reviewer approval.
7. Is a backup the same as an archive?
No. A backup supports recovery after a failure, while an archive preserves the official record for the approved retention period with indexing and retrieval controls.
8. Who should own data availability?
Ownership should be assigned through the quality system. Data, system, records, IT, archive, and quality-unit responsibilities should be clear and periodically reviewed.
9. What is a common availability violation?
Common examples include storing only a final report, losing audit trails during migration, relying on obsolete software, using uncontrolled shared drives, and failing to test restores.
10. When should an availability failure become CAPA?
Escalate when the failure affects a critical record, recurs, prevents reconstruction or inspection response, or indicates a systemic weakness in the data-governance process.
