This is the containment checklist for the first hours of a suspected data integrity breach, the phase that decides whether the rest of the investigation is possible. Work it top to bottom before any wide conversation. Mark each item Pass, Fail, or N/A with a justification, and treat any Fail as a stop condition until resolved. A chain-of-custody log and a filled specimen follow. This content is educational and general; adapt it to your own quality system and legal advice.
Header
| Field | Entry |
|---|---|
| Investigation number | <<FILL: DI-INV-ID>> |
| Date and time started | <<FILL>> |
| Led by | <<FILL: name, role>> |
| Systems / records first identified | <<FILL>> |
Part 1: limit exposure (first hour)
| # | Item | Pass / Fail / NA | Note |
|---|---|---|---|
| 1 | Only need-to-know people briefed (quality leadership, system owner, IT, legal where serious) | ||
| 2 | Suspected individual NOT confronted or alerted | ||
| 3 | Investigation file opened with a timestamped first entry |
Part 2: preserve electronic evidence
| # | Item | Pass / Fail / NA | Note |
|---|---|---|---|
| 4 | Relevant systems frozen or forensically imaged, source left unaltered | ||
| 5 | Full audit trail exported to write-protected media | ||
| 6 | Raw data files captured, including aborted, trial, and “test” runs | ||
| 7 | Instrument logs and operating-system / application event logs captured | ||
| 8 | Underlying database tables (not just printed reports) captured | ||
| 9 | Metadata (creation, modification, deletion timestamps) preserved | ||
| 10 | Recycle bins, recovery folders, renamed / duplicated files, and local copies secured | ||
| 11 | Capture verified readable and complete before reliance |
Part 3: control access (where ongoing alteration is credible)
| # | Item | Pass / Fail / NA | Note |
|---|---|---|---|
| 12 | At-risk accounts and privileged access restricted, with time and basis recorded | ||
| 13 | Access change coordinated with IT so it did not destroy logs |
Part 4: preserve physical evidence
| # | Item | Pass / Fail / NA | Note |
|---|---|---|---|
| 14 | Logbooks, worksheets, printouts, notebooks sequestered | ||
| 15 | Location where each item was found recorded | ||
| 16 | Originals preserved; only copies worked on |
Part 5: protect product and the record
| # | Item | Pass / Fail / NA | Note |
|---|---|---|---|
| 17 | Any product whose disposition relied on the questioned data quarantined | ||
| 18 | Chain-of-custody log started for every evidence item | ||
| 19 | Containment gate met: no wide interview will begin until evidence is safe and questioned accounts can no longer alter it |
References
21 CFR 211.192 (thorough investigation of discrepancies). 21 CFR Part 11 (electronic records and signatures). FDA Guidance, Data Integrity and Compliance With Drug CGMP: Questions and Answers (final, December 2018). MHRA GXP Data Integrity Guidance and Definitions (March 2018); PIC/S PI 041.
Chain-of-custody log
| Item ID | Description | Collected by | Date / time | From location | Transferred to | Signature |
|---|---|---|---|---|---|---|
<<FILL>> | <<FILL>> | <<FILL>> | <<FILL>> | <<FILL>> | <<FILL>> | <<FILL>> |
<<FILL>> | <<FILL>> | <<FILL>> | <<FILL>> | <<FILL>> | <<FILL>> | <<FILL>> |
Signoff
| Role | Name | Signature | Date |
|---|---|---|---|
| Containment lead | <<FILL>> | ||
| QA approval | <<FILL>> |
Filled specimen
| # | Item | Result | Note |
|---|---|---|---|
| 4 | Systems imaged, source unaltered | Pass | HPLC-04 workstation imaged by IT forensics 22 Jun 2026 15:20; source untouched |
| 5 | Audit trail to write-protected media | Pass | CDS audit trail exported to WORM media, hash recorded |
| 6 | Raw files incl. aborted / test runs | Pass | Including the project “test” folder |
| 12 | At-risk accounts restricted | Pass | Analyst account set read-only 15:35, basis: credible alteration risk |
| 17 | Product quarantined | Pass | Batch B-2606-14 placed on quality hold |
| 19 | Containment gate met | Pass | Interview deferred to 24 Jun after reconciliation |
Sample chain-of-custody row: item CDS-IMG-01, forensic image of HPLC-04, collected by J. Okafor (IT forensics), 22 Jun 2026 15:20, from QC lab bench 4, transferred to secured evidence store, signed.
The specimen shows the one point inspectors test hardest in this phase: the interview was deferred until the evidence was safe, not run first.
Common inspection findings this checklist prevents
- The concern was discussed openly and evidence was altered or deleted before capture.
- Only printed reports were kept; the dynamic raw data and metadata were lost.
- The suspected individual retained live edit or delete access during the investigation.
- No chain of custody, so the evidence could later be argued to have been tampered with.
- Product shipped while the reliability of its data was still unknown.
How to adapt this checklist
- Name your forensic imaging tool and evidence-store location.
- Add system-specific capture steps (for example, the exact CDS audit-trail export path) as sub-items.
- Point the references to your investigation SOP and retention schedule.
- Define your own stop-condition escalation for any Fail.
- Keep the completed checklist and the custody log with the investigation file.