Ad Code

Available Principle in ALCOA+

Web of Pharma · Data Integrity · ALCOA+

Available Principle in ALCOA+

How authorized teams can locate, read, and review complete pharmaceutical data whenever a quality decision, investigation, or inspection requires it.

Data availability Retrieval controls Inspection readiness
Quick
answer

The Available Principle in ALCOA+ means that authorized personnel can locate, retrieve, read, and review complete data when it is needed. Availability includes raw data, metadata, audit trails, methods, calculations, attachments, signatures, and context—not just a final report or a file name.

PeopleTrained, authorized reviewers can reach the record without shared accounts or informal workarounds.
TimeRecords are retrievable within a defined, risk-based timeframe for quality decisions and inspections.
EvidenceRaw data, metadata, audit trails, calculations, and approvals stay together and understandable.
AccessSystems, archives, permissions, indexes, and readers support secure human-readable review.

Pharmaceutical data has value only when people can find it and understand it. A result hidden in an unindexed folder, an HPLC file that cannot be opened, or a batch record separated from its attachments may technically exist but is not practically available.

The Available Principle applies across the data lifecycle: creation, processing, review, approval, retention, archival, retrieval, and disposition. It covers paper records, laboratory systems, manufacturing platforms, spreadsheets, stability databases, validation files, quality events, and outsourced activities.

Availability works inside cGMP controls and complements the broader ALCOA data-integrity framework. This guide turns the principle into practical design, operating, archive, and audit controls for pharmaceutical organizations.

What Is the Available Principle in ALCOA+?

Data are available when the right person can obtain the right record, in a readable and meaningful form, at the time and place required for an authorized purpose. The record must include enough context to support reconstruction, review, verification, and a defensible quality decision.

Availability is therefore more than system uptime or a successful login. It depends on findability, permissions, readable formats, retained metadata, working software, reliable retrieval processes, and evidence that the controls have been tested.

Availability questionWhat good control looks likeEvidence an auditor can review
Can the record be found?Controlled indexes, identifiers, search fields, naming rules, and ownership make the record discoverable.Archive index, record register, search log, or retrieval request.
Can it be opened and read?Approved readers, supported software, durable paper, and human-readable outputs remain available.Retrieval test, viewer qualification, archive inspection, or readability check.
Is the context intact?Raw data, metadata, audit trails, methods, calculations, attachments, and approvals remain linked.Source-to-report review, audit-trail export, or true-copy verification.
Can an authorized person access it?Unique accounts, role-based permissions, documented requests, and controlled administrator access are in place.Access matrix, user review, permission log, or training record.
Will access work after failure?Backup, archive, restore, disaster recovery, and migration controls are validated or verified.Restore test, migration report, recovery exercise, and deviation record.
Short definition for readers: Available data are complete, readable, and retrievable by authorized people when needed for an approved pharmaceutical activity.

Available Is More Than Stored

Storage answers the question “Where is the data?” Availability answers a larger set of questions: “Can the right person find it, open it, understand it, verify it, and use it without changing the evidence?” Each layer below should be considered during system design and periodic review.

Exists

The record, raw data, or approved copy is retained in an identified location rather than held on an uncontrolled personal device.

Findable

Identifiers, indexes, metadata, and naming conventions allow a reviewer to locate the exact batch, sample, run, or quality event.

Readable

Paper and electronic records can be viewed clearly without relying on unavailable software, damaged media, or undocumented conversion.

Complete

Supporting raw data, audit trails, methods, calculations, signatures, and attachments are available with the reported result.

Contextual

Dates, times, users, instrument identifiers, units, configuration, status, and relationships remain understandable.

Authorized

Access is granted through named users and approved roles, with controls that prevent unauthorized change or disclosure.

Timely

Retrieval can support batch disposition, investigation, complaint response, and inspection requests within defined expectations.

Recoverable

Backups, archives, and restoration procedures have been tested so availability does not depend on an assumption.

Traceable

Access, retrieval, copying, migration, and changes can be explained through records, audit trails, and controlled procedures.

Why Data Availability Matters in Pharmaceutical Quality

Quality decisions are evidence-based. A release reviewer needs the executed batch record and associated checks; a laboratory investigator needs the complete analytical sequence; a stability scientist needs historical pulls and chamber conditions; and an inspector may request any of these records with little notice.

Batch disposition

Manufacturing and laboratory evidence must be accessible to confirm that approved instructions were followed and acceptance criteria were met.

Deviation and OOS work

Investigators need original observations, audit trails, calculations, training, equipment history, and prior events to test possible causes.

Complaints and recalls

Rapid retrieval of traceability, distribution, testing, and batch history supports effective health-risk assessment and action.

Stability decisions

Protocols, chamber records, pulls, results, excursions, trends, and approvals must remain available throughout the study and product lifecycle.

Validation evidence

Protocols, raw readings, calculations, deviations, and reports support continued confidence in equipment, methods, and computerized systems.

Inspection readiness

A controlled retrieval process demonstrates that data governance works in practice, not only in a written procedure.

FDA data-integrity guidance describes data integrity across creation, modification, processing, maintenance, archival, retrieval, transmission, and disposition. Availability must therefore be designed for the complete lifecycle rather than added only after a record is archived.

Availability Across the Pharmaceutical Data Lifecycle

Lifecycle stageAvailability riskPractical control
Creation and captureData are recorded on loose paper, local drives, or temporary worksheets that are hard to reconcile.Provide controlled forms, approved systems, nearby recording points, unique identifiers, and clear ownership.
Processing and calculationMethods, formulas, intermediate files, or audit trails are separated from the reported result.Retain raw and processed data with metadata, version control, calculation review, and traceable links.
Review and approvalReviewers cannot access source data, or permissions delay an important quality decision.Use role-based access, documented review workflows, read-only evidence, and escalation paths.
Retention and archiveRecords are stored without an index, reader, migration plan, or documented retention owner.Define archive format, location, search fields, access rules, integrity checks, and retention responsibility.
Retrieval and inspectionRecords are found slowly, are unreadable, or lack metadata and attachments.Run representative retrieval tests and document response time, completeness, readability, and reviewer sign-off.
DispositionRecords are destroyed while investigations, holds, or retention obligations remain open.Use approved disposition authorization, hold checks, destruction logs, and retained evidence of the decision.

Controls for Available Paper Records

Paper remains a source record for many pharmaceutical activities. Availability depends on controlled issuance, good indexing, physical protection, and a retrieval process that preserves page order, attachments, signatures, and corrections.

  • Use controlled, numbered forms, bound notebooks, or paginated logbooks for critical records.
  • Record the batch, sample, equipment, study, or event identifier on every page and attachment.
  • Maintain a clear index, filing convention, archive location, and owner for each record class.
  • Protect records from moisture, heat, light, dust, insects, unauthorized removal, and accidental loss.
  • Use permanent, legible entries and approved correction practices that preserve the original entry.
  • Control check-out and return of records so the archive location is always known.
  • Verify that scanned or copied records are complete, readable, and linked to the source record.
  • Train staff to return records promptly and report missing, damaged, or misfiled pages.
Paper scenarioAvailability weaknessBetter practice
Executed batch recordLoose pages are filed without a batch index or attachment reconciliation.Use page counts, controlled filing, attachment lists, and a documented retrieval location.
Laboratory notebookEntries are difficult to locate because samples and dates are not cross-referenced.Use sequential entries, sample identifiers, page references, and a controlled notebook register.
Equipment logbookThe current log is kept in an area that reviewers cannot access without an informal request.Place controlled logs where the activity occurs and define authorized access and review routes.
Scanned archivePages are cropped, out of order, or missing signatures and attachments.Use a verified scanning process, image-quality checks, reconciliation, and documented approval.

Controls for Available Electronic Records

Electronic availability requires more than keeping a file on a server. The organization must preserve the data’s content, context, metadata, audit trail, relationships, and the software or viewer needed for meaningful review.

  • Assign each system a data owner, record owner, retention rule, and approved archive location.
  • Use unique user accounts, role-based permissions, and controlled administrator access.
  • Retain raw data, methods, sequences, calculations, audit trails, electronic signatures, and reports.
  • Keep dynamic records in a format that supports the review required for their intended use.
  • Document file naming, indexing, search fields, version control, and relationships between records.
  • Monitor storage capacity, system health, software support, certificates, interfaces, and vendor dependencies.
  • Validate or verify data transfer, migration, scanning, conversion, and true-copy processes.
  • Use secure backup and archive controls with defined recovery objectives and periodic restore tests.
  • Make records available in human-readable form without enabling uncontrolled alteration.
Important distinction: A PDF may be useful for review, but it is not automatically a complete replacement for dynamic raw data. Decide what must be retained through a documented, risk-based assessment that considers metadata, audit trails, calculations, and the ability to reconstruct the activity.

ALCOA+ Availability in HPLC and Laboratory Data

Chromatographic records illustrate why availability must include more than a final printed result. A reviewer may need to understand the sample sequence, instrument, method, processing parameters, integrations, reinjections, reprocessing, audit trail, calculations, and approval history.

What should be available?

  • Original raw data files and the complete sample or injection sequence.
  • Instrument identifier, analyst identity, date and time, method version, and system status.
  • Processing methods, integration parameters, calculations, report templates, and result files.
  • Audit-trail entries for changes, reprocessing, deleted or invalidated injections, and justifications.
  • Reference standards, sample preparation records, worksheets, calculations, and final approvals.
  • Validated viewers or supported software that can display the record and its relevant metadata.

Common laboratory availability failure

A laboratory may provide a signed chromatogram but be unable to produce the original sequence, processing method, audit trail, or invalidated injections. The report exists, yet the evidence needed to evaluate the result is unavailable. Prevent this by defining the complete record in the laboratory data-retention procedure and testing retrieval from the archive.

Availability in Manufacturing and Stability Records

Record areaRecords that should remain availableAvailability check
ManufacturingExecuted batch records, electronic batch data, equipment logs, line-clearance evidence, labels, reconciliation, and approvals.Can a reviewer reconstruct the batch, verify each critical step, and trace the materials and equipment used?
PackagingPackaging instructions, coding and inspection results, reconciliation, artwork versions, line checks, and exception records.Can the site confirm the correct component, code, quantity, and release decision for the batch?
StabilityProtocol, sample map, chamber conditions, pull schedule, results, excursions, calculations, trends, and approvals.Can the study be reconstructed from sample placement through the latest approved conclusion?
Environmental monitoringLocation maps, sampling records, incubation conditions, counts, identifications, excursions, and trend reviews.Can the organization connect each result to the location, time, method, analyst, and investigation?
ValidationApproved protocols, raw readings, calculations, deviations, change assessments, reports, and signatures.Can an independent reviewer confirm that acceptance criteria were tested and conclusions are supported?

For every record class, define the official source, required attachments, authorized users, retention period, archive location, retrieval owner, and acceptable response time. This turns a broad principle into a measurable quality-system expectation.

Access, Roles, and Security for Available Data

Availability must be balanced with confidentiality and data-integrity protection. A record should be accessible to authorized users without becoming editable by everyone who can view it.

Role-based access

Assign permissions according to job responsibility and record purpose. Review access when roles change.

Unique identities

Use individual accounts and electronic signatures so access and actions are attributable to a person.

Least privilege

Give users the minimum rights needed to perform approved tasks; separate administration from data review where practical.

Read-only review

Provide a protected viewing path for archived records so review does not create uncontrolled changes.

Emergency access

Define temporary access, approval, logging, and post-event review for urgent quality or recovery situations.

Vendor controls

Include ownership, accessibility, retention, support, and data-return expectations in technical agreements.

Do not solve an availability problem with shared passwords, emailed raw files, uncontrolled removable media, or unapproved copies. These shortcuts may make a record easier to reach while weakening attribution, confidentiality, and the audit trail.

Archive, Backup, and Retrieval Testing

Availability depends on a deliberate distinction between active records, backups, and archives. The exact terminology may differ by organization, but the responsibilities should be unambiguous.

ControlPrimary purposeWhat to verify
Active systemSupports current creation, processing, review, and approval.Users can perform authorized work and source records remain linked to their metadata.
BackupSupports recovery after corruption, hardware failure, or another disruption.Copies are complete, secure, restorable, and protected from alteration or loss.
ArchivePreserves the official record for the approved retention period.Records are indexed, protected, readable, retrievable, and linked to required context.
True copyProvides a verified copy that preserves the content, context, structure, metadata, and history of the source.The copying process is controlled, verified, documented, and suitable for the intended use.
Retrieval testDemonstrates that an authorized person can produce and understand the record.Test results cover search, access, completeness, readability, timing, and reviewer approval.

Test representative records, not only the easiest examples. Include old file formats, legacy systems, paper scans, large data sets, records with audit trails, and records held by service providers. Document failures as quality events and assess whether a broader impact review is required.

Common Failures of the Available Principle

Unindexed storage

Files are retained on a shared drive or in boxes without a controlled identifier, owner, or retrieval location.

Final report only

A signed report is saved but raw data, audit trails, methods, calculations, or attachments are unavailable.

Inactive accounts

Records depend on a former employee’s account or a shared password that no longer works.

Obsolete software

Electronic files exist but cannot be opened, rendered, searched, or interpreted with supported tools.

Unverified migration

Data are moved without checking metadata, audit trails, formulas, relationships, or the meaning of the result.

Backup confusion

A temporary recovery copy is treated as the official archive without an index, retention owner, or restore evidence.

Broken attachments

Reports, worksheets, images, logs, or approvals are separated so the full record cannot be reconstructed.

Uncontrolled sharing

People email or copy records to make them accessible, creating duplicate versions and weakening security.

No retrieval rehearsal

The organization assumes the archive works and discovers missing data, permissions, or readers during an inspection.

How to Implement the Available Principle

01

Map critical records

List paper and electronic records by process, product, study, system, owner, criticality, and retention requirement.

02

Define availability needs

Set search fields, authorized users, readable formats, required context, retrieval timing, and escalation routes.

03

Design the controls

Configure access, indexing, archive, backup, audit trails, readers, interfaces, and physical storage around the risk.

04

Qualify and train

Validate or verify systems and processes, then train users to create, file, retrieve, review, and protect records correctly.

05

Test retrieval

Run documented searches, restores, archive reviews, and migration checks using representative records and realistic timelines.

06

Monitor and improve

Trend retrieval failures, access delays, missing attachments, and archive defects; use CAPA when the weakness is systemic.

Availability should be measurable. Useful indicators include retrieval success rate, average retrieval time, incomplete-record rate, restore-test success, unresolved access requests, migration exceptions, and archive-related deviations.

Available Principle Audit Checklist

Use the following questions during self-inspection, periodic review, computerized-system assessment, or a data-integrity audit:

  • Are record owners, retention periods, archive locations, and retrieval responsibilities documented?
  • Can an authorized reviewer locate representative records using controlled identifiers and indexes?
  • Are raw data, metadata, audit trails, methods, calculations, attachments, and approvals available together?
  • Can records be opened and read with supported paper, software, hardware, or viewer technology?
  • Are dynamic records retained in a form that supports the required review and reconstruction?
  • Are role-based access, unique accounts, administrator rights, and periodic access reviews effective?
  • Are backup, archive, restore, migration, scanning, and true-copy controls validated or verified?
  • Are archive and retrieval tests documented with timing, completeness, readability, and reviewer approval?
  • Are vendors and cloud providers contractually responsible for data ownership, accessibility, retention, and return?
  • Are availability failures investigated, risk-assessed, trended, and escalated through the quality system?

Keep objective evidence for each answer: indexes, retrieval requests, access reports, restore results, migration validation, archive inspections, training records, and approved procedures.

How Available Fits Into ALCOA+

Available is one of the four additional ALCOA+ principles. It works with attributable, legible, contemporaneous, original, accurate, complete, consistent, and enduring records. A record can be accurate but unavailable if no authorized person can retrieve it; it can be available but not complete if only a final report is produced without the supporting raw data.

Consider an HPLC result stored as a signed PDF. The file may be easy to open, but the record is not fully available if the original sequence, processing method, audit trail, or metadata cannot be retrieved. Likewise, a paper batch record is not available if its archive location is unknown or critical pages cannot be read.

Key Takeaways

  • Available data can be found, opened, read, understood, and reviewed by authorized people when needed.
  • Availability includes raw data, metadata, audit trails, methods, calculations, attachments, signatures, and context.
  • Storage alone does not prove availability; indexing, permissions, readers, archive controls, and retrieval tests are also required.
  • Paper, laboratory, manufacturing, stability, validation, and quality-system records need availability controls across their full lifecycle.
  • Backup, archive, and true-copy functions have different purposes and should not be treated as interchangeable.
  • Retrieval failures should be investigated, risk-assessed, trended, and managed through CAPA when systemic.

Conclusion

The Available Principle in ALCOA+ makes pharmaceutical data usable when it matters. It ensures that authorized people can locate and review the complete evidence behind a batch decision, laboratory result, stability conclusion, validation report, investigation, or regulatory response.

Reliable availability is built through controlled records, clear indexes, role-based access, readable formats, retained metadata, secure archives, tested backups, validated migration, and realistic retrieval exercises. When organizations prove that their data can be found and understood—not merely stored—they strengthen data integrity and the credibility of the pharmaceutical quality system.

Frequently Asked Questions

1. What is the Available Principle in ALCOA+?

It means authorized personnel can locate, retrieve, read, and review complete data when needed for an approved pharmaceutical activity.

2. Is available the same as accessible?

They are closely related, but available also includes findability, readability, completeness, context, and timely retrieval—not just permission to log in.

3. What data must be available?

The required record includes raw data, metadata, audit trails, methods, calculations, attachments, signatures, approvals, and context needed to reconstruct the activity.

4. Does a final PDF prove data availability?

No. A PDF may support review, but it may not preserve dynamic raw data, metadata, audit trails, processing history, or the ability to reconstruct the result.

5. How can paper records remain available?

Use controlled forms, clear identifiers, indexing, protected storage, check-out controls, readable entries, attachment reconciliation, and a documented retrieval process.

6. How is availability tested for electronic records?

Run representative searches and restores, then check access, completeness, readability, metadata, audit trails, timing, and reviewer approval.

7. Is a backup the same as an archive?

No. A backup supports recovery after a failure, while an archive preserves the official record for the approved retention period with indexing and retrieval controls.

8. Who should own data availability?

Ownership should be assigned through the quality system. Data, system, records, IT, archive, and quality-unit responsibilities should be clear and periodically reviewed.

9. What is a common availability violation?

Common examples include storing only a final report, losing audit trails during migration, relying on obsolete software, using uncontrolled shared drives, and failing to test restores.

10. When should an availability failure become CAPA?

Escalate when the failure affects a critical record, recurs, prevents reconstruction or inspection response, or indicates a systemic weakness in the data-governance process.