Data Integrity

Data Integrity Risk Assessment in Computerized Systems According to GAMP 5 v2

The digital transformation of the pharmaceutical industry has significantly increased the dependence on computerized systems for the generation, prosecution, storage and GxP data management. In this context, data integrity (Data Integrity) constitutes an essential requirement to ensure that decisions related to product quality are based on reliable, complete and traceable information.

GAMP 5 v2 states that data integrity must managed through a risk-based strategy, considering both the technical controls of the system and the organizational procedures that guarantee the reliability of the information throughout its life cycle.

What is Data Integrity and why is it a critical requirement in GMP?

Data integrity can be defined as the degree to which data is complete, consistent, accurate, and maintained throughout its lifecycle.

The most widely accepted regulatory principle is ALCOA+:

ALCOA Principles Additional principles (ALCOA+)
Attributable: Each piece of data must be able to be unequivocally linked to the person or system that generated it. Full- All data, including original records, modifications, replays, invalid results, and associated metadata, must be preserved and available.
Legible: Data must be clear, permanent and understandable throughout its life cycle. Consistent: The data must follow a logical and chronological sequence, faithfully reflecting the order in which the activities occurred.
Contemporary- Data must be recorded at the time the activity is carried out. Lasting- Data must be recorded and maintained on durable media that preserves its integrity for the entire required retention period.
Original: The original record or a certified copy that maintains the content and meaning of the original must be retained. Available– Data must be easily retrievable and queryable when needed for review, audit, investigation or inspection.
Exact: the data must faithfully reflect reality, without errors or unauthorized alterations.

GAMP 5 v2 considers these principles as the basis for evaluating risks associated with data integrity.

GAMP 5 v2 Approach to Data Integrity Risk Management

One of the main new features of GAMP 5 v2 is the explicit incorporation of Data Integrity risk assessment within the life cycle management of the computerized system.

The approach is based on three key questions:

  1. What GxP data is critical?
  2. What threats can compromise said data?
  3. What controls are necessary to mitigate the identified risks?

The evaluation must be carried out from the initial stages of the project and maintained throughout the operational life of the system.

Identification and classification of critical data in computerized systems

The first step is to identify the Critical data (Critical Data). These are data whose loss, modification or deletion could affect product quality, patient safety, regulatory compliance or the traceability of GMP activities.

Examples

System Critical data
HPLC Analytical results
LIMS Specifications and results
SCADA Process parameters
MES Electronic manufacturing records
ERP Batch release

Data criticality is usually classified as high, medium or low and the classification must be justified by formal evaluation.

Data Integrity Risk Analysis according to GAMPS 5 v2

Once critical data is identified, potential threats must be evaluated.

Technological risks
  • Unauthorized modification of records.
  • Accidental deletion of data.
  • Storage failure.
  • Incorrect system configuration.
  • Defective interfaces.
  • Loss of traceability.
Organizational risks
  • Inadequate procedures.
  • Insufficient training.
  • User account sharing.
  • Poor audit review.
  • Inadequate supervision.
Risks related to suppliers
  • Insufficiently controlled development.
  • Lack of exchange controls.
  • Unmanaged remote access.
  • Poor support.

Data Integrity Risk Assessment Methodology

GAMP 5 v2 recommends using recognized methodologies such as FMEA (most used), Risk Ranking, Hazard Analysis, Bow-Tie Analysis and the ISO 14971 adapted where appropriate.

Simplified FMEA Example

Risk Impact Probability Detectability RPN
Blurred analytical results 5 3 4 60
Method modification without authorization 5 2 3 30
Using shared accounts 4 4 3 48

Higher priority risks require additional controls.

Controls to mitigate Data Integrity risks

GAMP 5 v2 distinguishes between technical and procedural controls.

Technical controls
User management
  • Unique ID.
  • Individual accounts.
  • Password policies.
  • Multi-factor authentication when appropriate.
Audit Trail The system must record:

  • Who performed an action.
  • What action was executed.
  • When did it happen.
  • Reason for change when applicable.

He audit trail should be reviewed periodically.

Security
  • Role-based access management.
  • Network segmentation.
  • Encryption.
  • Antivirus protection.
Backups
  • Automatic copies.
  • Verified restoration.
  • Protected storage.
Electronic records
  • Protection against unauthorized modifications.
  • Versioned.
  • Conservation throughout the regulatory period.
Procedural controls
  • Computerized systems management SOP.
  • User management SOP.
  • Audit trail review SOP.
  • Deviation management.
  • Change management.
  • Periodic training.

Data Integrity Controls Maturity Assessment

GAMP 5 v2 promotes analyzing not only the existence of controls but also their effectiveness. Some aspects evaluated include:

Area Questions
Access Is there adequate segregation of duties?
Audit Trail Is it reviewed periodically?
Backups Are restorations tested?
Changes Is there formal approval?
Training Is it documented and updated?

Ineffective controls should be considered residual risk.

Residual risk management and acceptance criteria

After implementing the mitigation measures, the residual risk is recalculated.

Example:

Risk Initial RPN Mitigation RPN Residual
Data erasure 60 Audit trail + backup + permissions 12
Shared account 48 Unique users 8

Risk acceptance must be documented and approved by the responsible Quality, Business and IT functions.

Relationship between Data Integrity and the validation of computerized systems

Data Integrity risk assessment directly influences:

  • The validation strategy.
  • The scope of IQ/OQ/PQ.
  • The test cases.
  • The periodic review.
  • Audit planning.

Higher criticality risks require more robust validation evidence.

GAMP 5 v2 Trends

The second edition introduces concepts that strengthen Data Integrity management:

Critical Thinking Activities must be justified according to the real risk and not by a mechanical application of procedures.
Product based approach The evaluation should focus on the impact on product quality and patient safety.
Scalability Controls must be sized according to:

  • System complexity.
  • Data criticality.
  • Risk for the patient.
Integration with CSA

The methodology is compatible with the principles of Computer Software Assurance (CSA) promoted by the FDA, prioritizing risk-oriented tests.

Conclusion

Data Integrity risk assessment according to GAMP 5 v2 is an essential tool to ensure the reliability of GxP data managed by computerized systems. The modern risk-based approach allows you to focus efforts on the critical data and controls that truly help protect product quality and patient safety. The proper application of this methodology, combined with robust technical controls, effective procedures and a quality-oriented organizational culture, provides a solid framework for regulatory compliance and operational sustainability of computerized systems in GMP environments.

Do you need support in Data Integrity risk assessment?

Whether your organization is implementing new computerized systems, reviewing its validation strategy, or preparing for a GMP inspection, a well-structured Data Integrity risk assessment can help you. identify vulnerabilities, strengthen existing controls and demonstrate the meeting expectations current regulations.

Contact our team of specialists in Data Integrity, Computerized Systems Validation (CSV) and GAMP 5 to analyze your needs and define a compliance strategy adapted to your organization.

Scroll to Top
Privacy Summary

We use cookies to help you navigate efficiently and perform certain functions. You will find detailed information about each of the cookies under each consent category below.

Cookies categorized as “necessary” are stored in their browser, since they are essential to allow the basic functionalities of the website.

We also use third -party cookies that help us analyze how you use this website, save your preferences and provide the content and advertising that is relevant to you. These cookies are only saved in their browser prior consent on their part.

You can choose to activate or deactivate some or all these cookies, although the deactivation of some could affect your navigation experience.

Strictly necessary cookies

The necessary cookies help make the most accessible websites and allow basic functions such as navigation or access to safe areas of the website. The website cannot work without these cookies.

Analytics

This website uses Google Analytics to collect anonymous information such as the number of visitors to the site, and the most popular pages.

Keeping this cookie enabled helps us to improve our website.