What are the most common data integrity audit findings in pharma?
The most common findings are missing original data or metadata, unjustified repeat testing, shared or excessive system access, audit trails that are unavailable or not reviewed, and narrow CAPA. Each points to a process that cannot reliably preserve, attribute, or challenge the evidence used for a GxP decision.
A serious data integrity observation rarely begins with one careless entry. It begins with a process that lets unreliable evidence survive long enough to influence a batch, laboratory, or quality decision.
Five Findings That Deserve Immediate Attention
| Finding | What usually went wrong | First corrective move |
|---|---|---|
| Incomplete original records | PDFs or printouts were retained while raw files, metadata, failed runs, or sequence history were lost. | Stop deletion or overwriting, preserve affected records, and define the complete record for each process. |
| Unsupported repeat testing | A passing result replaced the first adverse signal without a scientifically demonstrated assignable cause. | Retain every run, investigate the first failure, and trend repeats by analyst, instrument, method, and product. |
| Weak access control | Shared accounts, stale users, or analyst administrator rights made actions difficult to attribute. | Use unique identities, least privilege, independent administration, and periodic access recertification. |
| Ineffective audit-trail review | The audit trail was enabled but critical changes were not reviewed before the related GxP decision. | Define high-risk events and review them with the record, using validated exception reporting where appropriate. |
| Superficial CAPA | The firm issued an SOP or training record but did not assess comparable systems, sites, or historical data. | Broaden scope, assess product impact, correct the control design, and measure whether the fix works. |
The audit-trail finding above deserves particular attention because it's rarely a broken control — see our audit trail review checklist for the review cadence and review-by-exception approach inspectors actually expect.
What Evidence Will an Inspector Expect?
The inspection question is not whether a policy exists. It is whether the organisation can reconstruct what happened and show that the control operates in routine work. A defensible evidence set normally includes:
- a record inventory covering raw data, metadata, interfaces, temporary files, reports, and retention;
- approved roles, administrator independence, recent access reviews, and resolved exceptions;
- audit-trail review criteria with completed examples linked to the underlying record;
- an investigation that explains product impact, retrospective scope, root cause, and decision logic; and
- CAPA verification showing that recurrence is prevented or detected sooner.
Consultant's view: do not begin remediation by buying software. First identify where the process permits data selection, deletion, unattributed action, or review after the decision. Technology helps only when the control objective and ownership are already clear.
How to Remediate Without Over-Validating
- Contain and preserve. Restrict risky access, stop destructive practices, and secure all potentially relevant records.
- Assess impact before closure. Determine whether released batches, stability conclusions, submissions, or investigations relied on affected data.
- Expand scope logically. Review comparable systems, products, sites, and time periods; do not assume the first example is isolated.
- Match assurance to risk. Increase testing for calculations, interfaces, privileges, signatures, audit trails, data transfer, and restore. Use lighter evidence only for genuinely low-risk supporting functions.
- Verify effectiveness. Measure abnormal events, review completion, access exceptions, repeat testing, and retrieval success after implementation.
FDA's February 2026 CSA guidance supports risk-based assurance for medical-device production and quality management system software. It does not justify reducing controls over critical GxP data. For pharmaceutical operations, the safer principle is simple: reduce low-value paperwork, not evidence quality.
Regulatory anchors: FDA data integrity guidance, EMA GMP/GDP data integrity Q&A, and ISPE's 2026 audit-trail session. As of July 2026, the 2011 EU GMP Annex 11 remains effective; the 2025 revision is still a consultation text.
How GoVal Supports Data Integrity Remediation
GoVal ties every corrective action to a documented risk assessment instead of a standalone SOP update, so a finding, its root cause, and its fix stay linked as one record rather than three disconnected documents. It supports validated review-by-exception workflows for audit trails, role-based access control with independent administration, and a live requirements traceability matrix connecting each control back to the finding it was meant to close. Containment, impact assessment, corrected controls, and effectiveness checks are all captured as timestamped, audit-trailed evidence — the exact closure package an inspector expects, generated as a byproduct of the workflow rather than assembled after the fact.
Related Topics
Frequently Asked Questions
What are the most common data integrity audit findings in pharma? +
What evidence is sufficient to close a pharmaceutical data integrity finding? +
How often should GxP audit trails be reviewed? +
What triggers an FDA data integrity investigation rather than a routine observation? +
Does Computer Software Assurance reduce data integrity validation effort? +
How does GoVal help remediate and prevent data integrity findings? +
Turn findings into a controlled remediation plan
Map each gap to risk, evidence, validation activity, ownership, and effectiveness checks — in GoVal.
