Modern bioanalytical labs run on software. LC-MS/MS systems, HPLC, plate readers, qPCR instruments and flow cytometers all generate electronic data that supports drug development decisions and regulatory submissions. If that data cannot be trusted, neither can the study.
Data integrity failures remain among the most frequent findings in regulatory inspections and warning letters. At the centre of data integrity sits the audit trail: the built-in record that shows exactly who did what, when and why. This guide explains the principles, the regulations, how to review audit trails and how to make bioanalytical instruments inspection-ready.
What Is Data Integrity?
Data integrity means data is complete, consistent and accurate throughout its lifecycle, from generation to archiving. Regulators summarise this with the ALCOA+ principles:
- Attributable: Every record is linked to the person or system that created or changed it.
- Legible: Data can be read and understood throughout its retention period.
- Contemporaneous: Recorded at the time the work is done.
- Original: The first recording, or a verified true copy.
- Accurate: Error-free, with any changes documented.
- Plus: Complete, consistent, enduring and available.
Key Regulations and Guidance
- US FDA 21 CFR Part 11: Requirements for electronic records and electronic signatures.
- EU GMP Annex 11: Requirements for computerised systems in regulated environments.
- Regulatory data integrity guidance: Documents from the FDA, MHRA, WHO and PIC/S set out expectations for data governance and audit trail review.
- OECD GLP principles: Apply to non-clinical safety studies, including guidance on data integrity.
- ICH M10: The harmonised guideline on bioanalytical method validation and study sample analysis, which requires reliable, traceable data.
What Is an Audit Trail?
An audit trail is a secure, computer-generated, time-stamped record that captures the creation, modification and deletion of electronic data. A compliant audit trail records:
- Who made the change, through a unique user ID.
- What was changed, showing both the old and new values.
- When the change was made, with an accurate date and time stamp.
- Why the change was made, through a recorded reason.
Users must not be able to disable, edit or delete the audit trail. It should be retained for as long as the data itself.
Data Integrity Challenges in Bioanalytical Instruments
- Standalone instruments: Many plate readers, qPCR systems and flow cytometers run on local PCs, with data saved to the hard drive or exported by USB.
- Limited audit trail functions: Older or basic software may not record changes, or may require a separate compliance module to be enabled.
- Shared logins: Generic accounts make actions impossible to attribute to an individual.
- Excessive privileges: Analysts with administrator rights can delete data or change system settings.
- Hybrid systems: A mix of paper and electronic records can create gaps between what is printed and what is stored.
- Manual integration: In chromatography and LC-MS/MS, uncontrolled reintegration of peaks can change results.
Audit Trail Review: What to Look For
Having an audit trail is not enough; it must be reviewed. Regulators expect a risk-based review of relevant audit trail entries before results are reported or approved. Reviewers should focus on:
- Data deletions, modifications and overwritten files.
- Repeated reprocessing or manual integration of the same sample.
- Aborted, incomplete or unreported runs.
- Trial or test injections run outside the official sequence.
- Changes to methods, processing parameters or acceptance criteria during a run.
- Changes to the system date and time.
- Logins outside working hours or by unexpected users.
Any unexplained finding should be investigated and documented as a deviation.
Best Practices to Make Instruments Data-Integrity Compliant
Technical Controls
- Enable compliance or audit trail modules on all instrument software.
- Give every user a unique login and role-based access, keeping administrator rights with IT or QA, not analysts.
- Synchronise instrument clocks to a network time source and lock date and time settings.
- Save data directly to a secure, central network server rather than local drives.
- Disable USB ports or uncontrolled data export where possible.
- Automate regular backups and test data restoration.
- Validate computerised systems before use and after significant changes.
Procedural Controls
- Define what counts as raw data for each instrument, including metadata.
- Write SOPs for audit trail review, manual integration and data reprocessing.
- Retain all data, including failed and aborted runs, and justify any exclusions.
- Control hybrid systems so paper printouts can be linked to the original electronic records.
- Archive data securely for the full retention period, in a readable format.
People and Culture
- Train staff regularly on data integrity principles and expectations.
- Encourage open reporting of errors without fear of blame.
- Include data integrity checks in internal audits and management reviews.
Common Data Integrity Red Flags
- Audit trail switched off or never reviewed.
- Orphan data: files on the instrument that are not reported or explained.
- Identical results or chromatograms across different samples.
- Frequent manual integration without documented justification.
- Results recorded on paper before the electronic data exists.
Frequently Asked Questions
What is an audit trail in laboratory instruments?
An audit trail is a secure, time-stamped electronic record of who created, changed or deleted data, what was changed, when it happened and why.
What does ALCOA+ stand for?
Attributable, Legible, Contemporaneous, Original and Accurate, plus Complete, Consistent, Enduring and Available.
How often should audit trails be reviewed?
Using a risk-based approach, audit trails relevant to a result should be reviewed before the result is reported or approved, with periodic reviews of system-level audit trails.
Is 21 CFR Part 11 required for all lab instruments?
It applies when electronic records or electronic signatures are used to meet FDA regulatory requirements, which includes most instruments generating data for regulated studies.
Conclusion
Data integrity is no longer just a compliance checkbox; it is the foundation of credible bioanalytical science. Instruments with enabled and reviewed audit trails, unique user access, secure central storage and validated software, supported by clear SOPs and a strong quality culture, produce data that sponsors and regulators can trust. Investing in data integrity protects both study outcomes and the reputation of the laboratory.
