This is a ready-to-use data-integrity readiness checklist for an advanced-therapy program, built around the failure modes that actually get cited: partial instrument audit trails, shared logins, unverified transfers, deleted failing results, and contract-lab data the sponsor still owns. Replace every <<FILL: ...>> placeholder, mark each item Pass / Fail / NA with evidence, and route the completed checklist through QA. A filled specimen row set follows. Verify each cited regulation against the current source before you rely on it. Pair this with the Form: Single-Result Data Integrity Trace and the Log: Instrument Audit Trail and Access Capability Register.
Checklist header
| Field | Entry |
|---|---|
| Checklist number | <<FILL: ID>> |
| Program / product | <<FILL: product, modality>> |
| Sites / labs / CDMOs in scope | <<FILL>> |
| Completed by / date | <<FILL>> |
| QA reviewed by / date | <<FILL>> |
How to score
Mark each item Pass (control in place and evidenced), Fail (gap), or NA (with a reason). Any Fail on a GxP-critical release path is a finding to route through the DI remediation program before inspection.
Section A: Instrument audit trails
| # | Item | P/F/NA | Evidence / note | Reference |
|---|---|---|---|---|
| A1 | Every GxP instrument (ddPCR, flow cytometry, NGS, plate readers, balances, pH meters) has an audit trail that is enabled | <<FILL>> | <<FILL>> | 21 CFR 211.68; Part 11.10(e) |
| A2 | Audit trails capture field-level changes with the prior value (old value, new value, who, when, why), not just “modified” | <<FILL>> | <<FILL>> | Part 11.10(e); Annex 11 |
| A3 | Audit trails cover metadata: methods, integration/threshold/gating parameters, and sequence tables, not only final results | <<FILL>> | <<FILL>> | Part 11.10(e) |
| A4 | Where an instrument genuinely cannot audit-trail, the gap is documented, risk-assessed, and has a compensating control | <<FILL>> | <<FILL>> | Annex 11; risk-based |
| A5 | Audit trails cannot be disabled by routine users | <<FILL>> | <<FILL>> | Part 11.10(d) |
Section B: Attribution and access
| # | Item | P/F/NA | Evidence / note | Reference |
|---|---|---|---|---|
| B1 | Individual named accounts on every GxP system; no shared or generic logins | <<FILL>> | <<FILL>> | Part 11.10(d), 11.10(g) |
| B2 | Privileged/administrative functions separated from routine analyst functions | <<FILL>> | <<FILL>> | Part 11; Annex 11 |
| B3 | Access provisioned by role, reviewed periodically, revoked promptly on role change or exit | <<FILL>> | <<FILL>> | Part 11.10(d) |
Section C: Data transfer
| # | Item | P/F/NA | Evidence / note | Reference |
|---|---|---|---|---|
| C1 | Critical data stays inside a validated system end to end, or each boundary has an automated integrity check (checksum, reconciliation, verified interface) | <<FILL>> | <<FILL>> | FDA 2018 DI Q&A |
| C2 | No manual retyping of release-critical values into spreadsheets that then drive disposition | <<FILL>> | <<FILL>> | ALCOA Original/Accurate |
| C3 | Any spreadsheet used for GxP calculation is validated, formula-protected, and access-controlled | <<FILL>> | <<FILL>> | Part 11; Annex 11 |
| C4 | Transfer events are logged on both source and destination | <<FILL>> | <<FILL>> | Part 11.10(e) |
Section D: Failing results and testing into compliance
| # | Item | P/F/NA | Evidence / note | Reference |
|---|---|---|---|---|
| D1 | All data, including failing and aberrant runs, is retained and evaluated; no deletion of the first acquisition | <<FILL>> | <<FILL>> | FDA OOS (Rev.1, 2022); 211.192 |
| D2 | Invalidation of a result requires a documented, approved scientific justification | <<FILL>> | <<FILL>> | FDA OOS guidance |
| D3 | Acquisitions reconcile against reported results (twelve injections cannot become eight results unexplained) | <<FILL>> | <<FILL>> | 211.194; Part 11.10(e) |
| D4 | Re-integration, re-injection, or parameter changes are documented with justification, not run until it passes | <<FILL>> | <<FILL>> | FDA OOS guidance |
Section E: Time, records, and review
| # | Item | P/F/NA | Evidence / note | Reference |
|---|---|---|---|---|
| E1 | System clocks synchronized and protected; users cannot move the clock to backdate | <<FILL>> | <<FILL>> | Part 11; ALCOA Contemporaneous |
| E2 | Dynamic records (chromatograms, ddPCR files, FCS files) retained in dynamic form, not flattened to PDF | <<FILL>> | <<FILL>> | FDA 2018 DI Q&A |
| E3 | Audit trail review is built into disposition for release-critical data, with documented evidence it happened | <<FILL>> | <<FILL>> | FDA 2018 DI Q&A |
| E4 | Review depth and frequency traced to a data-criticality risk assessment | <<FILL>> | <<FILL>> | GAMP 5; risk-based |
Section F: Contract labs and CDMOs
| # | Item | P/F/NA | Evidence / note | Reference |
|---|---|---|---|---|
| F1 | Quality agreement defines data-integrity expectations and the sponsor’s access to raw data and audit trails | <<FILL>> | <<FILL>> | Quality agreement |
| F2 | Qualification audit included a specific data-integrity focus; periodic audits scheduled | <<FILL>> | <<FILL>> | Supplier qualification |
| F3 | The program treats contract-lab data as in-scope; the sponsor owns the integrity of every number in the submission | <<FILL>> | <<FILL>> | FDA 2018 DI Q&A |
Section G: End-to-end traceability
| # | Item | P/F/NA | Evidence / note | Reference |
|---|---|---|---|---|
| G1 | A release-critical result can be traced end to end (raw to analysis to audit trail to transfer to disposition) without the story breaking | <<FILL>> | <<FILL>> | 211.194; Part 11 |
| G2 | A self-trace has been run this period on at least one release-critical result (use the paired trace form) | <<FILL>> | <<FILL>> | Self-audit |
| G3 | Any AI/ML tool used to screen audit trails is validated for intended use, and its flags are screens, not findings | <<FILL>> | <<FILL>> | GAMP 5; Part 11 |
Acceptance criteria
- No open Fail on a GxP-critical release path.
- Every Fail is captured with an owner and a remediation route; NAs carry a reason.
- The end-to-end self-trace (Section G) was completed and any gaps routed to CAPA before inspection.
References
21 CFR 211.68, 211.192, 211.194; 21 CFR Part 11. FDA Data Integrity and Compliance With Drug CGMP Q&A (final, Dec 2018). FDA OOS guidance (Rev. 1, May 2022). EU Annex 11; MHRA GxP Data Integrity Guidance (2018); PIC/S PI 041 (2021). A draft Annex 11 revision and new draft Annex 22 (AI) went to consultation in July 2025 (closed 7 October 2025) and remain drafts as of mid-2026; confirm final text before citing.
Confirm each reference against the current source before issue.
Filled specimen (illustrative rows)
| # | Item | P/F/NA | Evidence / note |
|---|---|---|---|
| A2 | Field-level audit trail with prior value | Fail | ddPCR software v<<FILL>> records “threshold modified” with timestamp but not the prior value; gap logged, compensating control (second-person contemporaneous check) in place, CAPA-2026-0132 to upgrade |
| B1 | Individual named accounts | Pass | Flow cytometer moved from shared “lab” login to named accounts via IAM, 12 June 2026; evidence AT-FC-07 |
| D3 | Acquisitions reconcile to results | Pass | Monthly reconciliation on ddPCR shows all acquisitions accounted for; last check DDP recon 30 June 2026 |
| F1 | CDMO quality agreement with DI and access rights | Pass | QA-CDMO-114 clause 7 grants raw-data and audit-trail access; last audit 03/2026 |
The A2 Fail is the realistic case: the instrument cannot capture the prior value, so the gap is not hidden but documented, risk-assessed, given a compensating control, and scheduled for an upgrade. That is a defensible position; a silent gap is not.
How to adapt this checklist
- Expand Section A to one row per GxP instrument in your program using the paired instrument capability register.
- Set your review frequency and criticality basis in Section E from your risk assessment.
- Run Section G’s self-trace with the paired trace form at least once per period and before any inspection.
- Confirm each reference against the current source, including the pending Annex 11 revision, before use.