ALCOA Principles & ALCOA+: Data Integrity, 21 CFR Part 11 & Annex 11
ALCOA principles are one of the most practical ways to look at data integrity in pharmaceutical QC. But their real value becomes clear when you are reviewing actual laboratory data, not when you are simply memorizing what each letter stands for.
Let me start with a situation that can happen in almost any pharmaceutical QC laboratory.
You are reviewing an HPLC assay.
The system suitability has passed.
The chromatogram looks good.
The assay result is within specification.
The calculation is correct.
The analyst has signed the worksheet.
So you think, “Okay, this one is fine.”
Then you open the chromatography software.
There is another injection.
Then another one.
One result is not reported.
An integration has been changed.
There is an audit-trail entry.
Now you have a different question.
Not “Does the final result pass?”
The question is:
“What actually happened during this analysis?”
This is where data integrity starts becoming real.
ALCOA is often taught as five words that people memorize for training:
Attributable, Legible, Contemporaneous, Original and Accurate.
Then ALCOA+ adds:
Complete, Consistent, Enduring and Available.
That is correct, but memorizing nine words is not the difficult part.
The difficult part is applying them when the laboratory data does not tell a clean story.
That is where I want to focus in this article.
Because in pharmaceutical QC, data integrity is not just about having a good-looking report. It is about being able to follow the complete story of the test — from the moment the analyst starts the work until the final result is reviewed and approved.
What Does ALCOA Actually Mean?
I find ALCOA much easier to understand when we stop treating it like a definition and look at what we would expect from a normal QC record.
Suppose an analyst prepares a standard, prepares samples, runs an HPLC sequence and reports an assay result.
Later, another person reviews that work.
That reviewer should be able to answer some very basic questions:
Who did the work?
When was it done?
What exactly was done?
What data was generated?
Was anything changed?
Can we still see the original information?
Is the final result actually correct?
Those questions are basically ALCOA.
A — Attributable: Who Actually Did It?
This sounds simple.
But this is one of the first things I look at when reviewing electronic laboratory data.
When I see an HPLC sequence, I want to know who created it. An integration change should also show who made the change. The same applies to a result that was reviewed or approved; I want to know who performed that activity.
That is what Attributable means.
The record should be linked to the person who performed the activity.
Now imagine a laboratory where two or three analysts know the password for one chromatography account.
Technically, the software may still produce a perfect chromatogram.
But from a data-integrity point of view, there is a basic problem.
If the audit trail says:
User: QC Analyst
who was actually sitting at the computer?
We don’t know.
That is why individual user accounts are not just an IT preference. They are part of maintaining accountability for GMP data.
The same issue can appear with paper records.
If somebody fills in an entry for another person, signs it later, or makes an entry without properly identifying who performed the activity, the traceability becomes weak.
The question is always:
Can I confidently identify the person responsible for this activity?
L — Legible: Can We Actually Read the Record?
Legible does not simply mean that the handwriting looks nice.
The bigger question is whether the information can be read and understood throughout its required retention period.
With paper records, this is obvious.
A faint entry, overwritten number or badly damaged record can create problems.
With electronic data, the situation is slightly different.
A file may still exist on a server, but that does not necessarily mean the record is usable.
The real questions are: Can we open it? Do we interpret it? Can we see the relevant information? Can we retrieve the associated data when it is needed?
There is no real value in saying:
“The file is somewhere in the backup.”
If nobody can retrieve or interpret it when needed, the practical value of that record is very limited.
C — Contemporaneous: Record It When the Work Happens
This is one of those principles that looks very easy until you see what happens in a busy laboratory.
An analyst performs an activity at 10:00 AM.
The worksheet is completed at 4:00 PM.
The analyst remembers what happened and fills everything in.
The handwriting may be perfect.
The numbers may even be correct.
But there is still a question:
Was the record made at the time the activity actually happened?
That is the heart of contemporaneous recording.
A GMP record should be created at the appropriate time, not reconstructed later from memory.
This becomes even more important during investigations.
Suppose there is an unexpected result and the analyst says:
“I remember that I actually did this step differently.”
That explanation is much weaker than a contemporaneous record showing exactly what was done.
Good documentation should tell the story while the work is happening.
It should not depend on somebody remembering the story several hours or days later.
O — Original: Where Is the Real Data?
This is where pharmaceutical QC becomes particularly interesting.
Let’s take HPLC.
An analyst runs a sample.
The system generates electronic chromatographic data.
Later, somebody prints the chromatogram and attaches it to the worksheet.
The paper looks complete.
But is that printout necessarily the complete original data?
Not necessarily.
Depending on the chromatography system, the electronic record may contain information that is not visible on the printed chromatogram.
For example:
- injection sequence
- instrument method
- processing method
- integration information
- individual injections
- changes to processing
- audit-trail information
- other associated metadata
So when someone says:
“We have the chromatogram.”
my next question is:
“Do we have the complete electronic raw data?”
Those are not always the same thing.
This is one of the most important practical points in laboratory data integrity.
For a deeper practical discussion, see our article on HPLC audit trail review.
A printout can be part of the record.
It should not automatically be assumed to be the entire record.
A — Accurate: Is the Result Really Correct?
Accuracy goes much deeper than checking whether somebody added two numbers correctly.
Suppose the final HPLC assay is:
99.4%
The calculation is mathematically correct.
Good.
But I would still want to know:
- Was the correct sample tested?
- Was the correct standard used?
- Was the correct method used?
- Were the correct dilution factors applied?
- Was the instrument suitable?
- Was system suitability acceptable?
- Was the integration scientifically appropriate?
- Were any processing changes made?
- Were there unexpected injections?
- Was the reported result generated from the correct data?
A calculator can give you an accurate calculation from the wrong input.
So in QC, accurate data is not simply mathematically correct data.
It has to accurately represent what actually happened in the laboratory.
Then What Does the “+” in ALCOA+ Mean?
This is where the framework becomes more useful.
The additional four principles are:
Complete, Consistent, Enduring and Available.
And honestly, the word Complete is one of the most important ones when looking at chromatography data.
Complete: Don’t Tell Only the Good Part of the Story
Consider an HPLC sequence where the first injection produces an unexpected result, the second shows poor peak shape, and the third gives a passing result. The final report shows the passing result from Injection 3, but the earlier injections are still part of the analytical record and may be important to the investigation.
Now somebody asks:
“Why was Injection 3 reported?”
If the laboratory cannot explain what happened to the first two injections, there is a problem.
The issue is not that every abnormal injection automatically becomes an OOS result.
There can be legitimate reasons for an injection to be invalid.
The issue is whether the event was properly documented, scientifically evaluated and handled according to procedure.
Data integrity does not mean:
“Keep only the result we want.”
It means:
“Keep the relevant data and explain what happened.”
This is particularly important during OOS investigations.
Our separate guide on OOS investigation explains how an OOS result should be investigated rather than simply repeated until a passing result is obtained.
If the laboratory discovers unexpected data and the first response is to hide, delete or ignore it, the problem becomes much bigger than the original analytical result.
FDA has specifically addressed the retention and review of laboratory data, including problems associated with testing practices designed to obtain passing results.
Consistent: Does the Whole Story Make Sense?
Let’s say the worksheet says:
Analysis date: 5 October
But the instrument sequence shows:
6 October
The analyst’s preparation record shows another time.
The sample receipt record shows something else.
Now somebody has to explain the difference.
That is what consistency helps us see.
Data from different sources should tell a coherent story.
The chromatogram, worksheet, calculation, instrument record and report should not look like five unrelated versions of the same test.
When they disagree, we investigate.
Sometimes there is a perfectly valid explanation.
Sometimes there isn’t.
But we should not simply ignore the discrepancy because the final assay passed.
Enduring: Will the Data Still Be There?
Pharmaceutical records may need to be retained for years.
So the question is not only:
“Did we record it?”
It is also:
“Will we still have it when we need it?”
This matters with electronic systems, backups, software changes, servers and data migration.
When a laboratory replaces an old chromatography system, the first question is: what happens to the old data?
The original records should remain retrievable after the system is replaced. They also need to remain interpretable, with the associated metadata available where required.
The audit trail is another important part of that review. Can it still be accessed and evaluated after migration?
That is why data integrity has a lifecycle.
It does not end when the analyst clicks “Save.”
Available: Can We Retrieve It When Needed?
Data may be perfectly recorded and properly stored.
But if an authorized person cannot retrieve it during an investigation, audit or regulatory inspection, there is still a practical problem.
Imagine an inspector asks:
“Show me the raw data for this batch.”
The laboratory should not have to spend three days trying to find out where the data went.
The data should be available to authorized personnel when required.
That is the practical meaning of Available.
ALCOA+ Is Not 21 CFR Part 11
This distinction is important, especially because these terms are often mixed together.
ALCOA+ is not a regulation.
It is a practical framework for thinking about data integrity.
21 CFR Part 11 is an FDA regulation dealing with electronic records and electronic signatures within its scope.
And then there are the underlying GMP requirements, including requirements under 21 CFR Part 211.
So we should not say:
“ALCOA+ is FDA Part 11.”
It isn’t.
A better way to understand the relationship is:
GMP requirements tell us what records and controls are needed.
Part 11 addresses applicable electronic records and electronic signatures.
ALCOA+ gives us a practical way to think about whether the data itself remains trustworthy.
These concepts overlap, but they are not the same thing.
21 CFR Part 11 and 21 CFR Part 211 Are Also Different
This is another common confusion.
21 CFR Part 11 deals with electronic records and electronic signatures.
21 CFR Part 211 contains CGMP requirements for finished pharmaceuticals.
For a QC laboratory, both can become relevant.
For example, the laboratory may perform testing required under GMP requirements in Part 211, while the analytical system generates electronic records that fall within the scope of Part 11.
So saying:
“Our HPLC software is Part 11 compliant.”
does not finish the discussion.
I would still ask:
- Are users individually identified?
- Are access rights controlled?
- Is the system properly validated?
- Are audit trails functioning?
- Are audit trails reviewed?
- Is the raw data retained?
- Are changes controlled?
- Are procedures followed?
- Are analysts trained?
- Can the complete data be retrieved?
A software feature alone does not create a good data-integrity system.
Where Does EU GMP Annex 11 Fit?
EU GMP Annex 11 deals with Computerised Systems used in GMP activities.
This is particularly relevant today because computerized systems are everywhere in pharmaceutical QC.
Think about a modern laboratory.
An HPLC may connect to chromatography software.
The software may connect to a server.
The laboratory may use a LIMS.
User access may be controlled through a network.
Reports may be generated electronically.
Data may be backed up automatically.
So when we talk about data integrity, we are not talking only about the analyst sitting in front of the HPLC.
We are talking about the whole computerized environment.
Annex 11 addresses areas such as:
- risk management
- validation
- data storage
- audit trails
- security
- electronic signatures
- incident management
- periodic evaluation
- business continuity
- archiving
The important point is that computerized systems have to be controlled according to their intended GMP use and associated risks.
Audit Trail: Having It Is Not the Same as Reviewing It
This is one area where I would always look beyond the checkbox.
A laboratory may proudly say:
“Our software has an audit trail.”
Fine.
But my next question would be:
“Who reviews it, when, and what exactly are they looking for?”
An audit trail can tell us about changes and other actions performed in the system.
For example, it may show:
- who changed something
- when it was changed
- what was changed
- whether a record was deleted or modified
- sometimes the reason for the change
But simply having an audit trail switched on does not automatically mean the data-integrity risk is controlled.
If nobody reviews relevant audit-trail activity, an important control is effectively being left unused.
This is why audit-trail review should be based on the system, the data and the associated GMP risk.
Let’s Go Back to the HPLC Example
Suppose an assay result is OOS.
The analyst checks the chromatogram.
There is an unusual peak.
The analyst thinks it may be an injection problem.
A repeat injection is performed.
The repeat passes.
Now stop here.
This is the point where a weak laboratory can make a mistake.
Someone may simply say:
“First injection was abnormal. Second injection passed. Report second result.”
But a proper investigation asks more questions.
What caused the first result?
Could an instrument problem have contributed?
Was the sample prepared correctly?
Did the injection run as expected?
Was the chromatographic system suitable?
Most importantly, was the repeat scientifically justified?
The raw data may provide part of the answer. The audit trail may provide more.
Any integration change also needs to be understood.
The original data must be retained, and the event should be properly documented.
A passing repeat result does not automatically erase the first result.
The first result is part of the story.
That is the mindset ALCOA+ should create in a QC laboratory.
Some Data-Integrity Problems Are Very Small at the Beginning
Not every data-integrity problem starts with someone deliberately trying to manipulate a result.
Sometimes it starts with a shortcut.
“I’ll enter it later.”
“Everyone uses this password.”
“I’ll just reprocess this peak.”
“Let’s repeat it before we investigate.”
“We don’t need to keep that injection.”
“The printout is enough.”
“We’ll check the audit trail if there is a problem.”
Each sentence may sound harmless by itself.
But when these habits become normal laboratory practice, the data starts losing its traceability.
That is why data integrity is also a laboratory culture issue.
A good QC system should make the right behavior normal.
My Practical ALCOA+ Check for QC Data
When reviewing an analytical record, I would keep the questions simple.
Who did it?
→ Attributable
Can I read and understand it?
→ Legible
Was it recorded at the right time?
→ Contemporaneous
Can I access the original data?
→ Original
Is the result scientifically and mathematically correct?
→ Accurate
Do I have the complete story, including relevant unexpected data?
→ Complete
Do all records agree with each other?
→ Consistent
Will the record remain protected over its required lifetime?
→ Enduring
Can I retrieve it when I need it?
→ Available
That is ALCOA+ without making it complicated.
What Does an Inspector Really Want to See?
An inspector does not only want to see a nicely printed Certificate of Analysis.
The deeper question is whether the company can demonstrate that the reported result came from a controlled and trustworthy process.
That can lead into:
- raw data
- audit trails
- instrument methods
- processing methods
- user accounts
- sample preparation
- calculations
- repeat injections
- OOS investigations
- deviations
- CAPA
- backup and retention
- system validation
- procedures
- training
And this is exactly why data integrity should not sit only with the IT department.
It belongs to the quality system.
The analyst generates the data.
The reviewer reviews it.
The QC manager needs to understand the controls.
QA needs confidence that the system is controlled.
For a broader view of how laboratory testing, documentation, investigations and other QC activities fit together, see our guide to pharmaceutical quality control.
IT supports the technical environment.
Everyone has a role.
One Last Point: ALCOA+ Is Not Just for Computers
This is worth remembering.
Data integrity existed long before computerized HPLC systems.
A handwritten laboratory notebook can have data-integrity problems.
A paper worksheet can have data-integrity problems.
A computerized system can have data-integrity problems.
A hybrid system can have even more complicated problems if the relationship between electronic and paper records is not clear.
The technology changes.
The principle does not.
The record should honestly represent what happened.
That is really what we are trying to protect.
FAQs
What does ALCOA stand for in pharma? + ALCOA stands for Attributable, Legible, Contemporaneous, Original and Accurate. These principles are used to evaluate the reliability and integrity of GMP data.
What are the ALCOA+ principles? + ALCOA+ adds Complete, Consistent, Enduring and Available to the original five ALCOA principles.
Is ALCOA+ a regulation? + No. ALCOA+ is a data-integrity framework, not a regulation.
Is ALCOA+ the same as 21 CFR Part 11? + No. Part 11 is an FDA regulation covering applicable electronic records and electronic signatures. ALCOA+ is a broader practical framework for evaluating data integrity.
What is the difference between 21 CFR Part 11 and Annex 11? + Part 11 is an FDA regulation concerning applicable electronic records and electronic signatures. EU GMP Annex 11 addresses computerized systems used in GMP-regulated activities.
Is a printed HPLC chromatogram enough? + Not necessarily. A printed chromatogram may not contain all of the electronic raw data and associated metadata generated by the chromatography system.
Why is audit-trail review important? + Because an audit trail can reveal changes, deletions and other relevant actions in an electronic system. Simply having an audit trail is not enough; appropriate review is also important.
Should failed or unexpected HPLC injections be deleted? + Relevant data should not simply be deleted because it is inconvenient or does not support the desired result. Unexpected or invalid data should be handled according to approved procedures and properly documented.
The Bottom Line
ALCOA stands for Attributable, Legible, Contemporaneous, Original and Accurate. These principles are used to evaluate the reliability and integrity of GMP data.
ALCOA+ adds Complete, Consistent, Enduring and Available to the original five ALCOA principles.
No. ALCOA+ is a data-integrity framework, not a regulation.
No. Part 11 is an FDA regulation covering applicable electronic records and electronic signatures. ALCOA+ is a broader practical framework for evaluating data integrity.
Part 11 is an FDA regulation concerning applicable electronic records and electronic signatures. EU GMP Annex 11 addresses computerized systems used in GMP-regulated activities.
Not necessarily. A printed chromatogram may not contain all of the electronic raw data and associated metadata generated by the chromatography system.
Because an audit trail can reveal changes, deletions and other relevant actions in an electronic system. Simply having an audit trail is not enough; appropriate review is also important.
Relevant data should not simply be deleted because it is inconvenient or does not support the desired result. Unexpected or invalid data should be handled according to approved procedures and properly documented.
After years of working with pharmaceutical QC data, I have learned that the final number is often the easiest part to look at.
The harder part is understanding how that number was produced.
If I see an assay result of 99.5%, I don’t want to know only that it passed.
I want to know:
Who generated it?
When?
Which sample generated the result?
Which method was used?
How many injections were performed?
Were any injections repeated?
Was the data reprocessed?
Were any changes made during processing?
Is the original data still available?
Finally, does the audit trail support the documented story?
Can another qualified person review the complete record and reach the same conclusion?
That is where ALCOA+ becomes more than nine words on a training slide.
It becomes a way of thinking.
Good data integrity means that the record tells the truth about what happened in the laboratory.
And when that principle is supported by the appropriate GMP requirements, computerized-system controls, Part 11 requirements where applicable, Annex 11 expectations, validation, access controls, audit trails, procedures and proper review, the final result becomes much easier to defend.
Because in a good QC laboratory, we should not only be able to say:
“The result passed.”
We should be able to say:
“We know exactly how this result was generated, and we can prove it.”
References
- U.S. FDA — Data Integrity and Compliance With Drug CGMP: Questions and Answers.
- U.S. FDA — Part 11, Electronic Records; Electronic Signatures — Scope and Application.
- U.S. FDA — Questions and Answers on Current Good Manufacturing Practice Requirements — Laboratory Controls.
- European Commission — EudraLex Volume 4, Annex 11: Computerised Systems.
- MHRA — GxP Data Integrity Guidance and Definitions.



