Skip to main content

Most Common Data Integrity Audit Findings in Pharma

Ready to modernize?

See GoVal in Action

Book a 30-minute walkthrough with our validation specialists. No slides — just your questions, answered live.

Contact Us
Summary

Pharmaceutical data integrity findings usually arise when a process lets users create, alter, select, or discard GxP evidence without timely detection. The recurring patterns are incomplete original records, unsupported repeat testing, weak access control, ineffective audit-trail review, and CAPA that fixes one application without assessing the wider data lifecycle. Inspectors expect preserved evidence, a scientifically justified product-impact assessment, an appropriately broad scope, corrected controls, and proof that remediation works. GoVal supports this by tying corrective actions to a documented risk assessment, with audit trail review, access control, and CAPA tracked as one live, audit-trailed record rather than a standalone SOP update.

What are the most common data integrity audit findings in pharma?

The most common findings are missing original data or metadata, unjustified repeat testing, shared or excessive system access, audit trails that are unavailable or not reviewed, and narrow CAPA. Each points to a process that cannot reliably preserve, attribute, or challenge the evidence used for a GxP decision.

A serious data integrity observation rarely begins with one careless entry. It begins with a process that lets unreliable evidence survive long enough to influence a batch, laboratory, or quality decision.

Five Findings That Deserve Immediate Attention

FindingWhat usually went wrongFirst corrective move
Incomplete original recordsPDFs or printouts were retained while raw files, metadata, failed runs, or sequence history were lost.Stop deletion or overwriting, preserve affected records, and define the complete record for each process.
Unsupported repeat testingA passing result replaced the first adverse signal without a scientifically demonstrated assignable cause.Retain every run, investigate the first failure, and trend repeats by analyst, instrument, method, and product.
Weak access controlShared accounts, stale users, or analyst administrator rights made actions difficult to attribute.Use unique identities, least privilege, independent administration, and periodic access recertification.
Ineffective audit-trail reviewThe audit trail was enabled but critical changes were not reviewed before the related GxP decision.Define high-risk events and review them with the record, using validated exception reporting where appropriate.
Superficial CAPAThe firm issued an SOP or training record but did not assess comparable systems, sites, or historical data.Broaden scope, assess product impact, correct the control design, and measure whether the fix works.

The audit-trail finding above deserves particular attention because it's rarely a broken control — see our audit trail review checklist for the review cadence and review-by-exception approach inspectors actually expect.

What Evidence Will an Inspector Expect?

The inspection question is not whether a policy exists. It is whether the organisation can reconstruct what happened and show that the control operates in routine work. A defensible evidence set normally includes:

  • a record inventory covering raw data, metadata, interfaces, temporary files, reports, and retention;
  • approved roles, administrator independence, recent access reviews, and resolved exceptions;
  • audit-trail review criteria with completed examples linked to the underlying record;
  • an investigation that explains product impact, retrospective scope, root cause, and decision logic; and
  • CAPA verification showing that recurrence is prevented or detected sooner.

Consultant's view: do not begin remediation by buying software. First identify where the process permits data selection, deletion, unattributed action, or review after the decision. Technology helps only when the control objective and ownership are already clear.

How to Remediate Without Over-Validating

  1. Contain and preserve. Restrict risky access, stop destructive practices, and secure all potentially relevant records.
  2. Assess impact before closure. Determine whether released batches, stability conclusions, submissions, or investigations relied on affected data.
  3. Expand scope logically. Review comparable systems, products, sites, and time periods; do not assume the first example is isolated.
  4. Match assurance to risk. Increase testing for calculations, interfaces, privileges, signatures, audit trails, data transfer, and restore. Use lighter evidence only for genuinely low-risk supporting functions.
  5. Verify effectiveness. Measure abnormal events, review completion, access exceptions, repeat testing, and retrieval success after implementation.

FDA's February 2026 CSA guidance supports risk-based assurance for medical-device production and quality management system software. It does not justify reducing controls over critical GxP data. For pharmaceutical operations, the safer principle is simple: reduce low-value paperwork, not evidence quality.

Regulatory anchors: FDA data integrity guidance, EMA GMP/GDP data integrity Q&A, and ISPE's 2026 audit-trail session. As of July 2026, the 2011 EU GMP Annex 11 remains effective; the 2025 revision is still a consultation text.

How GoVal Supports Data Integrity Remediation

GoVal ties every corrective action to a documented risk assessment instead of a standalone SOP update, so a finding, its root cause, and its fix stay linked as one record rather than three disconnected documents. It supports validated review-by-exception workflows for audit trails, role-based access control with independent administration, and a live requirements traceability matrix connecting each control back to the finding it was meant to close. Containment, impact assessment, corrected controls, and effectiveness checks are all captured as timestamped, audit-trailed evidence — the exact closure package an inspector expects, generated as a byproduct of the workflow rather than assembled after the fact.

Related Topics

Frequently Asked Questions

What are the most common data integrity audit findings in pharma? +
The most common findings are incomplete original records or metadata, repeat testing that is not scientifically justified, shared or excessive user access, audit trails that are unavailable or not reviewed, and CAPA that addresses one symptom without assessing similar systems or records. These findings are serious because they weaken the organisation's ability to prove that GxP decisions were made from complete, attributable, contemporaneous, and reviewable evidence.
What evidence is sufficient to close a pharmaceutical data integrity finding? +
An updated SOP and completed training are rarely sufficient. A credible closure package shows immediate containment, preservation of affected records, product and patient impact assessment, root cause, retrospective scope across comparable systems, corrected technical and procedural controls, appropriate validation or assurance testing, and an effectiveness check. Each action should be traceable to objective evidence, with a clear explanation of why the failure is now less likely to recur or remain undetected.
How often should GxP audit trails be reviewed? +
The review timing should match the decision supported by the data. For batch release, laboratory disposition, or another critical decision, relevant audit-trail events should normally be reviewed with the record before approval. Lower-risk processes may use justified periodic or exception-based review. The procedure should define which events matter, who reviews them, how unusual activity is escalated, and how completion is documented; a calendar frequency alone does not make the control effective.
What triggers an FDA data integrity investigation rather than a routine observation? +
FDA typically escalates to a formal investigation when inspectors find evidence of intentional data manipulation, deletion of failing results, disabled or bypassed audit trails, shared login credentials obscuring who performed an action, or a recurring pattern of unexplained repeat testing. A single isolated lapse is usually handled as a standard 483 observation; deeper scrutiny follows when the process itself appears to have allowed unreliable data to go undetected, or the same gap recurs across batches, analysts, or sites.
Does Computer Software Assurance reduce data integrity validation effort? +
Computer Software Assurance can reduce low-value documentation for lower-risk software functions, but it should not reduce assurance over data-integrity-critical controls. Testing and review should increase for calculations, interfaces, security roles, electronic signatures, audit trails, data transformation, and backup or restore. FDA's February 2026 CSA guidance directly addresses medical-device production and quality management system software; pharmaceutical manufacturers may apply compatible principles, but CSA is not a waiver from CGMP or Annex 11 expectations.
How does GoVal help remediate and prevent data integrity findings? +
GoVal ties corrective actions to a documented risk assessment rather than a standalone SOP update. It supports validated review-by-exception workflows for audit trails, role-based access control with independent administration, and a live requirements traceability matrix linking each control back to the finding it was meant to fix. Every remediation step — containment, impact assessment, corrected control, and effectiveness check — is captured as a timestamped, audit-trailed record.

Turn findings into a controlled remediation plan

Map each gap to risk, evidence, validation activity, ownership, and effectiveness checks — in GoVal.

Book a Free Demo →