This is the working record for a data integrity investigation run under your investigation SOP. It is designed so a reviewer or an inspector can follow the extent, the impact, and the reliability verdict without reading a narrative first. Replace every <<FILL: ...>> placeholder, keep the field definitions with the form, and retain it per your records schedule. A filled specimen follows. This content is educational and general; adapt it to your own quality system.
Section A: investigation identity
| Field | Entry | Definition |
|---|---|---|
| Investigation number | <<FILL: DI-INV-ID>> | Unique controlled identifier |
| Date and time opened | <<FILL: date, time>> | When the file was opened; starts the chain of custody |
| Trigger | <<FILL: how it was found>> | Audit trail review, tip, orphan run, alarm, external notice |
| Declared by | <<FILL: name, role>> | Who declared the integrity path |
| Systems and records in scope (initial) | <<FILL>> | The starting set, expanded in Section C |
| Product(s) potentially affected | <<FILL>> | Lots or studies on hold pending the verdict |
| Independent party engaged | Yes / No | Required where the quality unit is implicated or the matter is severe |
Section B: containment confirmation
| Control | Done (Y/N) | Time | By whom |
|---|---|---|---|
| Access limited to need-to-know | <<FILL>> | <<FILL>> | |
| Electronic evidence imaged / exported to protected media | <<FILL>> | <<FILL>> | |
| At-risk accounts restricted | <<FILL>> | <<FILL>> | |
| Physical evidence sequestered | <<FILL>> | <<FILL>> | |
| Affected product quarantined | <<FILL>> | <<FILL>> |
Containment gate: no wide interview until every row above is Yes and the questioned accounts can no longer alter evidence.
Section C: scope and extent (justify each axis)
| Axis | Population pulled | Justification (why this boundary) | Examined / sampled |
|---|---|---|---|
| Person | <<FILL>> | <<FILL>> | <<FILL>> |
| System / instrument | <<FILL>> | <<FILL>> | <<FILL>> |
| Method / product | <<FILL>> | <<FILL>> | <<FILL>> |
| Time | <<FILL>> | <<FILL>> | <<FILL>> |
| Pattern (signature searched) | <<FILL>> | <<FILL>> | <<FILL>> |
Extent statement: <<FILL: "We looked and the problem stops at ..." with the evidence, not "we have no evidence it goes further">>
Section D: retrospective review and reconciliation
| Source | Count |
|---|---|
| Runs / injections on the instrument or sequence log | <<FILL>> |
| Reported results | <<FILL>> |
| Documented suitability / blanks / standards | <<FILL>> |
| Documented aborted runs with reason | <<FILL>> |
| Accounted for | <<FILL>> |
| Unexplained gap (each run down separately) | <<FILL>> |
Findings: <<FILL: specific records, specific anomalies, evidence behind each call>>
Section E: product and patient impact
| Decision the data supported | Re-evaluated on reliable data? | Outcome |
|---|---|---|
<<FILL: e.g. batch release B-...>> | Yes / No | <<FILL>> |
<<FILL>> | Yes / No | <<FILL>> |
Distribution / exposure traced: <<FILL>> Health-hazard evaluation reference: <<FILL: number or N/A>>
Section F: data-reliability verdict (per data set)
| Data set | Verdict | Evidence |
|---|---|---|
<<FILL>> | Reliable / Reliable after correction / Not reliable | <<FILL>> |
<<FILL>> | Reliable / Reliable after correction / Not reliable | <<FILL>> |
Section G: root cause and CAPA
| Field | Entry |
|---|---|
| Systemic enabler (the gap) | <<FILL>> |
| System gap / intentional act / both | <<FILL>> |
| Basis for the intent determination | <<FILL: the documentary pattern>> |
| CAPA to close the mechanism | <<FILL>> |
| Wider trust review (if intentional) | <<FILL: scope and result>> |
Section H: reportability
| Obligation | Applicable? | Basis | Action / reference |
|---|---|---|---|
| Field action | Y/N | <<FILL>> | <<FILL>> |
| Submission correction | Y/N | <<FILL>> | <<FILL>> |
| Safety reporting | Y/N | <<FILL>> | <<FILL>> |
| Contractual notification | Y/N | <<FILL>> | <<FILL>> |
| Assessed jointly with legal | Y/N | date | <<FILL>> |
Section I: approvals
| Role | Name | Signature | Date |
|---|---|---|---|
| Investigator | <<FILL>> | ||
| QA / data integrity lead (accountable) | <<FILL>> | ||
| Senior quality leadership | <<FILL>> |
Filled specimen
| Field | Entry |
|---|---|
| Investigation number | DI-INV-2026-014 |
| Trigger | Blank-reason re-integration found in audit trail review of HPLC-04, 22 June 2026 |
| Scope, person axis | All CDS activity by the analyst, four instruments, 24 months; justified because the mechanism travels with the person |
| Reconciliation | 312 injections vs 300 accounted; 12 orphans; 3 unreported failing results |
| Impact | Lot A re-derived in spec from valid original; Lot B not re-derivable |
| Verdict, Lot A | Reliable after correction |
| Verdict, Lot B | Not reliable, no valid original survives |
| Root cause | Deletable local folder plus no second review (gap) and selective reporting (intentional): both |
| Reportability | Field action on Lot B; submission group notified; assessed with legal 30 June 2026 |
The specimen shows the two things a reviewer checks first: that the scope was justified per axis, and that each data set carries an explicit verdict with evidence.
Common inspection findings this form prevents
- A scope with no per-axis justification, so extent looks assumed rather than demonstrated.
- Reconciliation left open, with orphan runs never run down.
- Impact asserted as “none” with no decision-by-decision re-evaluation.
- No stated reliability verdict, leaving downstream decisions unsupported.
- Reportability not documented against the actual extent.
How to adapt this form
- Match the section numbering to your investigation SOP so each phase maps to a section.
- Expand Section D with the reconciliation sources your systems actually produce.
- Add a chain-of-custody attachment reference in Section B and keep the custody log with the file.
- Set your retention period and approval roles to your quality system.
- Confirm the reportability obligations in Section H against current regulation with legal.