Independent and not affiliated with the FDA, MHRA, ISPE, PDA, or any agency. Get the appgoutham@madhadi.com
madhadi.comData Integrity & GxP Quality
Browse all topics → Articles Templates & Procedures Learning paths GlossaryScenariosToolsRegulatory ReferencesLearning PathsTopics About Start here
Checklist Plug-and-play starting point Data Integrity

Checklist: Data Integrity Self-Audit Five-Layer Field Checklist

A plug-and-play field checklist for running a data integrity self-audit across five layers, infrastructure, system configuration, procedural controls, work practice verification, and culture, with an evidence-reviewed column for every item and a filled specimen.

Document type: Checklist

Read and copy the template below into your own quality system. It is a generic starting point for your own internal use, provided as is, with no warranty; see the Terms and License. Adopting it does not by itself create compliance.

This is a ready-to-use field checklist. Replace every <<FILL: ...>> placeholder with your own specifics and route the completed copy through your normal audit reporting and CAPA process. A worked filled specimen follows the template. This checklist follows the five-layer method in Data Integrity Self-Audit: A Compliance Checklist; read that article first if the layered method is new to you.

Audit header

FieldEntry
System(s) / area audited<<FILL>>
Audit period covered<<FILL: from>> to <<FILL: to>>
Sample size and selection method<<FILL>>
Lead auditor (independent of area)<<FILL>>
Audit dates<<FILL>>

Every row below requires a named evidence artifact, not an impression. Use the Evidence column to record the specific record, log export, or observation examined, its identifier, and the date reviewed.

Layer 1: Infrastructure controls

ItemPass/Fail/NAEvidence reviewed
All GxP systems synchronized to one authoritative time source; users cannot change local time<<FILL>><<FILL>>
Concurrent events across two systems agree in timestamp within documented tolerance<<FILL>><<FILL>>
No shared or generic accounts in use on GxP systems<<FILL>><<FILL>>
Departed-staff accounts disabled within the SOP window, with evidence<<FILL>><<FILL>>
Backup schedule documented and followed; at least one dated restore test per critical system<<FILL>><<FILL>>
Oldest archived records confirmed still readable<<FILL>><<FILL>>
No unattended, logged-in GxP session reachable by an unauthorized person<<FILL>><<FILL>>

Layer 2: System configuration

ItemPass/Fail/NAEvidence reviewed
Audit trail enabled, captures create/modify/delete/approve with old and new values<<FILL>><<FILL>>
Audit trail unalterable, including by system administrators<<FILL>><<FILL>>
Documented audit trail review procedure exists, with defined frequency and scope<<FILL>><<FILL>>
Audit trail reviews actually performed and documented on schedule<<FILL>><<FILL>>
Electronic signatures carry two components, explicit meaning, and are bound to the record<<FILL>><<FILL>>
No single role both generates and independently approves the same record (segregation of duties)<<FILL>><<FILL>>
A documented baseline configuration exists and current state matches it, or every difference traces to an approved change<<FILL>><<FILL>>

Layer 3: Procedural controls

ItemPass/Fail/NAEvidence reviewed
SOPs require data recorded directly to the GxP record, not scratch paper or temporary notes<<FILL>><<FILL>>
OOS procedure requires investigation before retest and prohibits invalidation without documented justification<<FILL>><<FILL>>
Data review SOP requires reviewers to examine the audit trail, not just the final result<<FILL>><<FILL>>
DI training is role-specific and documented for everyone who generates GxP records<<FILL>><<FILL>>

Layer 4: Work practice verification

ItemPass/Fail/NAEvidence reviewed
Sampled analytical runs reconcile across LIMS and CDS with no undisposed injections<<FILL>><<FILL>>
Instrument timestamps consistent with staffed hours per access logs<<FILL>><<FILL>>
Sampled batch records show GMP activities recorded when they occurred<<FILL>><<FILL>>
No sign of blank forms filled out in advance<<FILL>><<FILL>>
Access-log review shows no unexplained after-hours, concurrent-location, or bulk-modification activity<<FILL>><<FILL>>

Layer 5: Culture indicators

ItemPass/Fail/NAEvidence reviewed
Staff interviews indicate analysts feel safe reporting an unexpected result<<FILL>><<FILL>>
No pattern of pressure to keep re-testing until an assignable lab error is found<<FILL>><<FILL>>
Deviations and OOS investigations described as learning, not blame, exercises<<FILL>><<FILL>>
DI issues tracked, trended, and reviewed at the quality system level<<FILL>><<FILL>>
Leading indicators (OOS invalidation rate, batch amendment rate, after-hours access, re-injection rate) reviewed and trended<<FILL>><<FILL>>

Summary

FieldEntry
Total items assessed<<FILL>>
Pass / Fail / NA counts<<FILL>>
Critical findings (list)<<FILL>>
Major findings (list)<<FILL>>
Minor findings (list)<<FILL>>
Overall conclusion<<FILL>>
Lead auditor signature / date<<FILL>>
QA sponsor signature / date<<FILL>>

References

FDA Data Integrity and Compliance With Drug CGMP guidance (December 2018). MHRA GxP Data Integrity Guidance and Definitions (March 2018). 21 CFR Part 11; EU GMP Annex 11.

Confirm the current version of each reference before issue.


Filled specimen (excerpt)

ItemPass/Fail/NAEvidence reviewed
Audit trail enabled, captures create/modify/delete/approve with old and new valuesPassCDS-HPLC-07 audit trail export, 01-07 June 2026, 14 entries reviewed, all show old/new values
Audit trail reviews actually performed and documented on scheduleFailBatch disposition packages BR-2026-0441 through 0452 (n=12), none contain a CDS audit trail review record
No single role both generates and independently approves the same recordPassRole matrix export for CDS-HPLC-07, 06 June 2026; Analyst role has no Approve right
Sampled analytical runs reconcile across LIMS and CDS with no undisposed injectionsFailSequence HPLC-07-2206-031, LIMS shows one result (99.2%), CDS shows 3 undisposed injections preceding it

Overall conclusion (excerpt): Two Major findings raised (audit trail review not performed for six months; one sequence showing undisposed injections preceding a reported result, escalated per the triage path as a potential testing-into-compliance pattern and referred for record forensics). CAPA opened for both; report closed pending CAPA completion.

Common inspection findings this checklist prevents

  • A self-audit that reads as a documentation review, with no named evidence artifact behind any answer.
  • Findings recorded as pass/fail with no supporting record identifier, which does not survive a challenge.
  • A clean result from an audit that never actually pulled a sample of real records.

How to adapt this checklist

  1. Add or remove items to match your actual system inventory; the five-layer structure should stay intact even if the specific checks change.
  2. Set the sample size and selection method before the audit starts, and record it in the header, not after the fact.
  3. Pair this checklist with the DI self-audit finding classification severity scheme so every fail gets a defensible severity.
Use madhadi.com as an app Full screen, works offline, one tap from your home screen.