Independent and not affiliated with the FDA, MHRA, ISPE, PDA, or any agency. Get the appgoutham@madhadi.com
madhadi.comData Integrity & GxP Quality
Browse all topics → Articles Templates & Procedures Learning paths GlossaryScenariosToolsRegulatory ReferencesLearning PathsTopics About Start here
Checklist Plug-and-play starting point Data Integrity

Checklist: Evidence Preservation and Chain of Custody for a Data Integrity Investigation

A plug-and-play containment checklist for the first hours of a data integrity investigation: who to brief, how to preserve electronic and paper evidence without altering it, access lock-down, product quarantine, and an unbroken chain of custody, with pass/fail items and a filled specimen.

Document type: Checklist

Read and copy the template below into your own quality system. It is a generic starting point for your own internal use, provided as is, with no warranty; see the Terms and License. Adopting it does not by itself create compliance.

This is the containment checklist for the first hours of a suspected data integrity breach, the phase that decides whether the rest of the investigation is possible. Work it top to bottom before any wide conversation. Mark each item Pass, Fail, or N/A with a justification, and treat any Fail as a stop condition until resolved. A chain-of-custody log and a filled specimen follow. This content is educational and general; adapt it to your own quality system and legal advice.

FieldEntry
Investigation number<<FILL: DI-INV-ID>>
Date and time started<<FILL>>
Led by<<FILL: name, role>>
Systems / records first identified<<FILL>>

Part 1: limit exposure (first hour)

#ItemPass / Fail / NANote
1Only need-to-know people briefed (quality leadership, system owner, IT, legal where serious)
2Suspected individual NOT confronted or alerted
3Investigation file opened with a timestamped first entry

Part 2: preserve electronic evidence

#ItemPass / Fail / NANote
4Relevant systems frozen or forensically imaged, source left unaltered
5Full audit trail exported to write-protected media
6Raw data files captured, including aborted, trial, and “test” runs
7Instrument logs and operating-system / application event logs captured
8Underlying database tables (not just printed reports) captured
9Metadata (creation, modification, deletion timestamps) preserved
10Recycle bins, recovery folders, renamed / duplicated files, and local copies secured
11Capture verified readable and complete before reliance

Part 3: control access (where ongoing alteration is credible)

#ItemPass / Fail / NANote
12At-risk accounts and privileged access restricted, with time and basis recorded
13Access change coordinated with IT so it did not destroy logs

Part 4: preserve physical evidence

#ItemPass / Fail / NANote
14Logbooks, worksheets, printouts, notebooks sequestered
15Location where each item was found recorded
16Originals preserved; only copies worked on

Part 5: protect product and the record

#ItemPass / Fail / NANote
17Any product whose disposition relied on the questioned data quarantined
18Chain-of-custody log started for every evidence item
19Containment gate met: no wide interview will begin until evidence is safe and questioned accounts can no longer alter it

References

21 CFR 211.192 (thorough investigation of discrepancies). 21 CFR Part 11 (electronic records and signatures). FDA Guidance, Data Integrity and Compliance With Drug CGMP: Questions and Answers (final, December 2018). MHRA GXP Data Integrity Guidance and Definitions (March 2018); PIC/S PI 041.

Chain-of-custody log

Item IDDescriptionCollected byDate / timeFrom locationTransferred toSignature
<<FILL>><<FILL>><<FILL>><<FILL>><<FILL>><<FILL>><<FILL>>
<<FILL>><<FILL>><<FILL>><<FILL>><<FILL>><<FILL>><<FILL>>

Signoff

RoleNameSignatureDate
Containment lead<<FILL>>
QA approval<<FILL>>

Filled specimen

#ItemResultNote
4Systems imaged, source unalteredPassHPLC-04 workstation imaged by IT forensics 22 Jun 2026 15:20; source untouched
5Audit trail to write-protected mediaPassCDS audit trail exported to WORM media, hash recorded
6Raw files incl. aborted / test runsPassIncluding the project “test” folder
12At-risk accounts restrictedPassAnalyst account set read-only 15:35, basis: credible alteration risk
17Product quarantinedPassBatch B-2606-14 placed on quality hold
19Containment gate metPassInterview deferred to 24 Jun after reconciliation

Sample chain-of-custody row: item CDS-IMG-01, forensic image of HPLC-04, collected by J. Okafor (IT forensics), 22 Jun 2026 15:20, from QC lab bench 4, transferred to secured evidence store, signed.

The specimen shows the one point inspectors test hardest in this phase: the interview was deferred until the evidence was safe, not run first.

Common inspection findings this checklist prevents

  • The concern was discussed openly and evidence was altered or deleted before capture.
  • Only printed reports were kept; the dynamic raw data and metadata were lost.
  • The suspected individual retained live edit or delete access during the investigation.
  • No chain of custody, so the evidence could later be argued to have been tampered with.
  • Product shipped while the reliability of its data was still unknown.

How to adapt this checklist

  1. Name your forensic imaging tool and evidence-store location.
  2. Add system-specific capture steps (for example, the exact CDS audit-trail export path) as sub-items.
  3. Point the references to your investigation SOP and retention schedule.
  4. Define your own stop-condition escalation for any Fail.
  5. Keep the completed checklist and the custody log with the investigation file.
Use madhadi.com as an app Full screen, works offline, one tap from your home screen.