The digital transformation of the pharmaceutical industry has significantly increased the dependence on computerized systems for the generation, prosecution, storage and GxP data management. In this context, data integrity (Data Integrity) constitutes an essential requirement to ensure that decisions related to product quality are based on reliable, complete and traceable information.
GAMP 5 v2 states that data integrity must managed through a risk-based strategy, considering both the technical controls of the system and the organizational procedures that guarantee the reliability of the information throughout its life cycle.
What is Data Integrity and why is it a critical requirement in GMP?
Data integrity can be defined as the degree to which data is complete, consistent, accurate, and maintained throughout its lifecycle.
The most widely accepted regulatory principle is ALCOA+:
| ALCOA Principles | Additional principles (ALCOA+) |
| Attributable: Each piece of data must be able to be unequivocally linked to the person or system that generated it. | Full- All data, including original records, modifications, replays, invalid results, and associated metadata, must be preserved and available. |
| Legible: Data must be clear, permanent and understandable throughout its life cycle. | Consistent: The data must follow a logical and chronological sequence, faithfully reflecting the order in which the activities occurred. |
| Contemporary- Data must be recorded at the time the activity is carried out. | Lasting- Data must be recorded and maintained on durable media that preserves its integrity for the entire required retention period. |
| Original: The original record or a certified copy that maintains the content and meaning of the original must be retained. | Available– Data must be easily retrievable and queryable when needed for review, audit, investigation or inspection. |
| Exact: the data must faithfully reflect reality, without errors or unauthorized alterations. |
GAMP 5 v2 considers these principles as the basis for evaluating risks associated with data integrity.
GAMP 5 v2 Approach to Data Integrity Risk Management
One of the main new features of GAMP 5 v2 is the explicit incorporation of Data Integrity risk assessment within the life cycle management of the computerized system.
The approach is based on three key questions:
- What GxP data is critical?
- What threats can compromise said data?
- What controls are necessary to mitigate the identified risks?
The evaluation must be carried out from the initial stages of the project and maintained throughout the operational life of the system.
Identification and classification of critical data in computerized systems
The first step is to identify the Critical data (Critical Data). These are data whose loss, modification or deletion could affect product quality, patient safety, regulatory compliance or the traceability of GMP activities.
Examples
| System | Critical data |
| HPLC | Analytical results |
| LIMS | Specifications and results |
| SCADA | Process parameters |
| MES | Electronic manufacturing records |
| ERP | Batch release |
Data criticality is usually classified as high, medium or low and the classification must be justified by formal evaluation.
Data Integrity Risk Analysis according to GAMPS 5 v2
Once critical data is identified, potential threats must be evaluated.
| Technological risks |
|
| Organizational risks |
|
| Risks related to suppliers |
|
Data Integrity Risk Assessment Methodology
GAMP 5 v2 recommends using recognized methodologies such as FMEA (most used), Risk Ranking, Hazard Analysis, Bow-Tie Analysis and the ISO 14971 adapted where appropriate.
Simplified FMEA Example
| Risk | Impact | Probability | Detectability | RPN |
| Blurred analytical results | 5 | 3 | 4 | 60 |
| Method modification without authorization | 5 | 2 | 3 | 30 |
| Using shared accounts | 4 | 4 | 3 | 48 |
Higher priority risks require additional controls.
Controls to mitigate Data Integrity risks
GAMP 5 v2 distinguishes between technical and procedural controls.
| Technical controls | |
| User management |
|
| Audit Trail | The system must record:
He audit trail should be reviewed periodically. |
| Security |
|
| Backups |
|
| Electronic records |
|
| Procedural controls | |
|
|
Data Integrity Controls Maturity Assessment
GAMP 5 v2 promotes analyzing not only the existence of controls but also their effectiveness. Some aspects evaluated include:
| Area | Questions |
| Access | Is there adequate segregation of duties? |
| Audit Trail | Is it reviewed periodically? |
| Backups | Are restorations tested? |
| Changes | Is there formal approval? |
| Training | Is it documented and updated? |
Ineffective controls should be considered residual risk.
Residual risk management and acceptance criteria
After implementing the mitigation measures, the residual risk is recalculated.
Example:
| Risk | Initial RPN | Mitigation | RPN Residual |
| Data erasure | 60 | Audit trail + backup + permissions | 12 |
| Shared account | 48 | Unique users | 8 |
Risk acceptance must be documented and approved by the responsible Quality, Business and IT functions.
Relationship between Data Integrity and the validation of computerized systems
Data Integrity risk assessment directly influences:
- The validation strategy.
- The scope of IQ/OQ/PQ.
- The test cases.
- The periodic review.
- Audit planning.
Higher criticality risks require more robust validation evidence.
GAMP 5 v2 Trends
The second edition introduces concepts that strengthen Data Integrity management:
| Critical Thinking | Activities must be justified according to the real risk and not by a mechanical application of procedures. |
| Product based approach | The evaluation should focus on the impact on product quality and patient safety. |
| Scalability | Controls must be sized according to:
|
| Integration with CSA
|
The methodology is compatible with the principles of Computer Software Assurance (CSA) promoted by the FDA, prioritizing risk-oriented tests. |
Conclusion
Data Integrity risk assessment according to GAMP 5 v2 is an essential tool to ensure the reliability of GxP data managed by computerized systems. The modern risk-based approach allows you to focus efforts on the critical data and controls that truly help protect product quality and patient safety. The proper application of this methodology, combined with robust technical controls, effective procedures and a quality-oriented organizational culture, provides a solid framework for regulatory compliance and operational sustainability of computerized systems in GMP environments.
Do you need support in Data Integrity risk assessment?
Whether your organization is implementing new computerized systems, reviewing its validation strategy, or preparing for a GMP inspection, a well-structured Data Integrity risk assessment can help you. identify vulnerabilities, strengthen existing controls and demonstrate the meeting expectations current regulations.
Contact our team of specialists in Data Integrity, Computerized Systems Validation (CSV) and GAMP 5 to analyze your needs and define a compliance strategy adapted to your organization.