|

Data Integrity and Good Documentation Practices in Process Validation

Process validation conclusions are only as reliable as the records and data used to support them. Development studies, PPQ execution, process measurements, laboratory results, calculations, statistical datasets, deviations, and final validation conclusions must therefore remain complete, accurate, attributable, traceable, and capable of reconstruction.

FDA’s Data Integrity and Compliance With Drug CGMP: Questions and Answers defines data integrity in terms of completeness, consistency, and accuracy and states that data should be attributable, legible, contemporaneously recorded, original or a true copy, and accurate—the commonly used ALCOA principles. FDA also emphasizes preservation of the data and associated metadata needed to reconstruct the CGMP activity.

This article applies those principles specifically to process validation execution. It does not attempt to duplicate detailed computerized-system requirements for security, audit-trail configuration, access administration, system validation, backup architecture, or Part 11 assessments. Those system-level controls are addressed in 21 CFR Part 11 Applicability, Assessment, and Compliance. Here the focus is the integrity of the validation evidence generated, processed, reviewed, and retained while a process-validation protocol is executed.


Data Integrity Is Part of the Validation Conclusion

A PPQ report may conclude that a process is capable and reproducible, but that conclusion is only defensible if the supporting evidence can be reconstructed. The reviewer should be able to determine what was required by the approved protocol, what was actually performed, who performed it, when it occurred, which equipment and materials were involved, what raw data were generated, how calculations were performed, whether exceptions occurred, and how those exceptions affected the conclusion.

This is consistent with 21 CFR 211.188, which requires complete batch production and control information and specifically includes dates, equipment identification, material identification, in-process and laboratory results, sampling performed, responsible personnel, and investigations.

Validation documentation should therefore function as an evidence chain, not merely as a completed protocol with signatures.

Process validation data-integrity flow from data generation and contemporaneous recording through calculations, statistical analysis, technical review, reconciliation, and the approved validation record.
Validation evidence should remain controlled from initial data generation through review and final approval. Raw data, calculations, metadata, deviations, statistical analyses, and reconciliation records collectively support reconstruction of the validation conclusion.

Attributable Records

Validation activities should identify who performed or verified the activity. For paper records, this normally means controlled signatures or initials linked to an identifiable individual. For electronic records, actions should similarly remain attributable through individual user identities and appropriate electronic-record controls.

FDA specifically asks whether activities are attributable to a specific individual and identifies attribution as one of the fundamental characteristics supporting data integrity.

This becomes particularly important during PPQ because execution often involves Manufacturing, Engineering, Validation, Quality, laboratories, contractors, and other functions. Entries such as “checked,” “verified,” or “acceptable” have limited evidentiary value if the responsible individual cannot be identified.

Shared credentials, generic electronic accounts used to create or modify validation records, or undocumented delegation weaken attribution and should not be relied upon for regulated execution.


Contemporaneous Documentation

Validation activities should be documented when they occur rather than reconstructed later from memory. 21 CFR 211.100 requires production and process-control activities to be documented at the time of performance and requires deviations from approved procedures to be recorded and justified.

For validation execution, contemporaneous documentation includes recording actual parameter values, sample times, observations, equipment identification, deviations, interventions, and protocol steps as the activities occur. The person performing the work should not maintain unofficial notes and transfer selected information into the protocol later.

Late entries may occasionally be necessary, but they should be clearly identified as late entries, dated when actually entered, attributed to the person making the entry, and supported by the source information used to reconstruct the event.

Backdating is not an acceptable substitute for contemporaneous documentation.


Legibility and Clarity

Paper validation records should remain readable throughout their retention period. Entries should be sufficiently clear that another technically qualified reviewer can understand what was performed without relying on the memory of the original executor.

Ambiguous abbreviations, unexplained symbols, overwritten results, illegible handwriting, and incomplete references to external data weaken the evidentiary value of the record. Where abbreviations or codes are routinely used, their meaning should be controlled or otherwise readily reconstructable.

Good documentation practice is not primarily about neatness. Its purpose is to preserve the meaning of the validation evidence.


Original Records and True Copies

Validation files frequently contain copies of equipment records, laboratory reports, charts, instrument outputs, batch-record pages, and electronic exports. The validation package does not necessarily need to duplicate every original record, but it should clearly identify the authoritative source and preserve access to it.

FDA recognizes true copies of paper or electronic records when the copy preserves the content and meaning of the original record, including metadata necessary for reconstruction. Dynamic electronic records can require preservation in the original format or another format that retains their content and meaning; a static printout may not always capture everything contained in the underlying electronic record.

For validation purposes, this means a PDF report can sometimes be adequate evidence, while in other cases the underlying electronic record remains necessary. The decision depends on what information is required to reconstruct the activity and evaluate the result.


Raw PPQ Data

PPQ generates evidence across Manufacturing, laboratories, equipment systems, and validation activities. Raw evidence can include process measurements, sampling records, laboratory results, equipment outputs, historian data, environmental information, manual observations, alarms, batch records, and protocol worksheets.

The validation team should define where these records reside and how they connect to the protocol. It is usually unnecessary and inefficient to copy every source record into the PPQ protocol, but the PPQ package should make the evidence traceable.

A useful approach is: Protocol requirement → execution record → raw data source → evaluated result → acceptance criterion → conclusion

This relationship becomes particularly important when PPQ produces thousands of electronic process values or laboratory measurements that are summarized in tables for the final report.

PPQ Sampling Plan and Data Collection Strategy addresses what data should be collected. This article addresses how the resulting data remain controlled and reconstructable.


Complete Data

A final summarized value should not become the only retained evidence when additional original information is necessary to understand how that value was obtained.

21 CFR 211.194 requires laboratory records to include complete data generated during testing, including graphs, charts, spectra, calculations, results, identification of the person performing the test, and review for accuracy and completeness. FDA’s data-integrity guidance similarly emphasizes that data necessary to reconstruct the CGMP activity should be preserved with the associated metadata.

For validation execution, this principle extends beyond laboratory testing. If the final validation table reports only minimum, maximum, and average values, the underlying observations used to generate those statistics should remain traceable and available.


Calculations

Calculations used to support validation conclusions should be reproducible. This includes straightforward calculations such as averages and yields as well as more complex capability indices, confidence intervals, regression calculations, statistical transformations, or automated formulas.

The validation record should identify the source data, formula or method, units, applicable conversion factors, software or tool where relevant, and review of the resulting calculation. 21 CFR 211.194 explicitly requires laboratory records to contain calculations performed in connection with testing, including units and conversion factors.

If calculations are performed in a controlled spreadsheet, statistical application, database, or other computerized tool, the validation execution record should reference that controlled tool and preserve the dataset and output necessary to reproduce the analysis.

The detailed qualification or validation of the software itself belongs within the computerized-systems framework rather than this article.

Statistical Datasets

Statistical analyses often require transformation of raw manufacturing data into an analysis-ready dataset. That transformation creates an important integrity boundary.

The reviewer should be able to determine: Raw source → extraction → dataset → transformation → analysis → reported result

Examples include converting historian exports into batch-based datasets, joining material attributes with PPQ process results, removing duplicate timestamps, assigning samples to strata, deriving elapsed times, or calculating normalized process responses.

The statistical dataset should therefore have clear provenance. The source records, extraction date, selection criteria, transformations, formulas, exclusions, dataset version, and analysis version should be sufficiently documented to reproduce the reported result.

This complements the statistical governance principles in Sampling and Statistical Strategy for Process Validation and the PPQ-specific evaluation in PPQ Acceptance Criteria and Statistical Evaluation.


Dataset Version Control

When statistical datasets are repeatedly updated during PPQ execution, version control becomes important. An analyst may begin with partial data, add later batches, correct source errors, or revise a transformation before the final analysis is completed.

The final PPQ report should be tied to an identifiable approved dataset and analysis version. Earlier datasets do not necessarily need to be treated as separate final records when they are simply working stages, but the organization should preserve enough history to explain significant changes and demonstrate which dataset supported the approved conclusion.

Where an intermediate dataset was used to make a regulated decision, it may itself become relevant validation evidence and should be retained accordingly.


Electronic Records and Metadata

Electronic validation evidence frequently contains important information that is not visible in a printed result. Metadata may include user identity, date and time, equipment or instrument identifier, sample identity, method version, units, configuration, processing history, or audit-trail information.

FDA describes metadata as contextual information required to understand data and specifically states that data and metadata necessary to reconstruct the CGMP activity should remain securely linked throughout the record-retention period.

The validation team should therefore avoid assuming that a screenshot or PDF automatically represents the complete electronic record. Whether a static copy is sufficient depends on the nature of the original record and the information needed to reconstruct the validation activity.


Electronic Record Scope

The existence of a computer does not automatically make every supporting file a Part 11 record. FDA’s current Part 11, Electronic Records; Electronic Signatures — Scope and Application explains that Part 11 applicability depends in part on whether required records are maintained electronically and relied upon to perform regulated activities. FDA continues to emphasize compliance with the underlying predicate-rule recordkeeping requirements.

For process validation, the important first question is therefore what record is relied upon as the regulated evidence. Once that is understood, the appropriate electronic-record and computerized-system controls can be applied.

Detailed Part 11 assessments, user-access controls, system validation, audit-trail configuration, backup architecture, and electronic-signature controls belong in 21 CFR Part 11 Applicability, Assessment, and Compliance and related Computerized Systems articles.


Audit Trails During Validation Execution

Where electronic audit trails form part of the relevant record, they can provide important context for validation execution. FDA defines an audit trail as a secure, computer-generated, time-stamped electronic record that permits reconstruction of creation, modification, or deletion of electronic records.

A validation reviewer generally does not need to reproduce every system audit trail within the protocol. However, audit-trail information should be considered where it is necessary to confirm data integrity, explain reprocessing or modification, investigate an unexpected result, or verify a critical electronic action.

FDA states that personnel responsible for CGMP record review should review audit trails that capture changes to data associated with the record as part of the record review.

The system-level design and frequency of audit-trail review should remain governed by the applicable computerized-system and quality procedures.


Data Transfers and Transcription

Validation data may move between systems and documents several times before reaching the final report. Manual transcription introduces risk of omitted digits, incorrect units, misplaced decimal points, changed sample identifiers, or selection of the wrong source record.

Where practical, controlled electronic transfer can reduce transcription risk, but automated transfer also requires appropriate controls. The validation team should know whether data were manually transcribed, electronically exported, copied through an interface, or transformed by software.

Manual entries should be checked where the risk warrants it. Electronic transfers should preserve source identity and meaning. Any reconciliation between source records and final datasets should be documented sufficiently to demonstrate that the analysis represents the intended data population.


Corrections to Paper Validation Records

Corrections should preserve the original entry rather than obscure it. A typical GDP correction uses a single line through the incorrect entry so that it remains readable, enters the correct information nearby, and includes the identity of the person making the correction and the date. A reason should be provided when the reason is not obvious from context or where the correction is significant to the validation conclusion.

Correction fluid, erasure, overwriting, removal of pages, or replacing completed protocol pages without retaining the original record can destroy the history needed to reconstruct execution.

FDA similarly emphasizes the need for controls that allow detection of errors, omissions, and record changes and recommends retaining incomplete or erroneous controlled forms with justification when they are replaced.


Corrections to Electronic Records

Electronic corrections should retain equivalent transparency. The original value, revised value, person making the change, time of change, and reason where appropriate should remain reconstructable through the system record and associated audit trail.

Validation personnel should not bypass controlled electronic records by exporting results into editable files and modifying them outside the originating system without traceability.

Where electronic corrections are performed in systems used to support PPQ or other validation decisions, the validation package should reference the authoritative record rather than attempting to reproduce the complete electronic history manually.


Excluded and Invalid Data

Data exclusion is one of the most important integrity issues in validation because selective removal of unfavorable results can fundamentally alter the conclusion.

FDA states that invalidating a CGMP result requires a valid, documented, scientifically sound justification. Even when invalidation is justified, the original invalidated data and the investigation supporting the decision remain part of the CGMP record.

The same principle should apply to process-validation analyses. An excluded point is not equivalent to a deleted point.

If a PPQ observation, laboratory result, statistical point, or process measurement is excluded from an analysis, the record should show:

  • the original result;
  • why the result was questioned;
  • the investigation performed;
  • the scientific basis for exclusion;
  • who approved the exclusion;
  • whether the exclusion affected other data or batches; and
  • the effect of inclusion versus exclusion where relevant to interpretation.

Detailed handling of PPQ deviations and their effect on the validation conclusion is addressed in PPQ Deviations, Investigation, and Validation Conclusion.


Outliers Are Not Automatically Invalid Data

A statistical outlier indicates unusual behavior relative to a dataset; it does not prove that the observation is erroneous.

The process and measurement system should be investigated before excluding the value. A valid extreme observation may reveal genuine process variability, equipment behavior, a material effect, or another important condition that the validation exercise was intended to detect.

Statistical techniques can help identify unusual observations, but the scientific investigation determines whether exclusion is justified.

Removing an outlier solely because it improves a capability index, narrows a confidence interval, or allows acceptance criteria to be met would undermine the validation conclusion.


Protocol Execution

An approved validation protocol defines what is intended to be performed. The executed protocol should show what was actually performed.

Execution records should clearly indicate completion of required steps, actual results, references to supporting data, deviations, samples collected, responsible personnel, and reviews. Blank spaces should not leave ambiguity about whether an activity was omitted, not applicable, or simply undocumented.

Where a test or activity is not performed, the reason should be documented. Where an alternative method is used, the change should be controlled before or during execution as required by the governing procedure.

Validation protocols should not be retrospectively edited to make actual execution appear identical to the original plan.


Protocol Amendments

Sometimes new information during execution requires a legitimate change to the approved protocol. A protocol amendment should normally be prospective and explain what is changing, why the change is necessary, and whether previously generated data remain valid.

An amendment should not be used retrospectively to conceal a deviation or change acceptance criteria after results are known.

The distinction is important:

  • Planned controlled change → amendment
  • Unplanned departure from approved execution → deviation

The final report should reconcile both.


Deviations and Exceptions

Deviation records are part of the validation evidence rather than administrative attachments. The final validation conclusion should consider whether deviations were isolated execution issues, evidence of a control weakness, indicators of process variability, or challenges to the representativeness of the qualification exercise.

21 CFR 211.192 requires investigation of unexplained discrepancies and specification failures, including documented conclusions and follow-up.

Validation deviations should remain traceable from the executed protocol through the investigation and into the final report. Closing the deviation separately without discussing its effect on the validation conclusion can leave an incomplete evidence trail.


Reconciliation Before Final Approval

Before the final validation report is approved, the validation package should be reconciled. The review should confirm that required protocol activities are complete, source data are available, calculations are verified, samples and test results are accounted for, deviations are resolved or appropriately carried forward, and excluded data are scientifically justified.

The reconciliation should also verify that statistical analyses use the intended final dataset and that conclusions correspond to the approved acceptance criteria.

This is where validation execution, data integrity, and Process Validation Documentation and Traceability converge.

Process validation record traceability from approved protocol and raw data through calculations, statistical analysis, deviations, excluded data, and the final validation report.
The final validation conclusion should remain traceable to the approved protocol, authoritative raw data, calculations, analyses, and documented exceptions. Reconstruction should not depend on undocumented working files or individual memory.

Validation Report Integrity

The final validation report should summarize the evidence without replacing it. Tables, charts, and statistical summaries may condense large amounts of information, but the underlying evidence should remain available.

The report should identify the executed protocol, batches or runs evaluated, acceptance criteria, relevant datasets, deviations, significant exclusions, statistical analyses, unresolved limitations, and final validation conclusion.

A reviewer should be able to move from the report back to the supporting evidence without encountering unexplained gaps.


Reconstruction

Reconstruction is one of the most useful practical tests of validation data integrity.

A knowledgeable person who did not participate in the original execution should be able to determine:

  • what was planned;
  • what was actually performed;
  • who performed it and when;
  • which materials, equipment, samples, and systems were involved;
  • what original data were generated;
  • how data were transformed or calculated;
  • what changes or corrections occurred;
  • what deviations or exclusions occurred;
  • how results were evaluated; and
  • why the final conclusion was reached.

FDA specifically links preservation of data and metadata with the ability to reconstruct the underlying CGMP activity. If reconstruction requires contacting the original executor because the documentation itself is insufficient, the record is weaker than it should be.


Review Responsibilities

Validation data review should be more than checking whether every signature box is complete. Technical reviewers should evaluate whether execution followed the protocol, whether the data support the acceptance decision, whether calculations are correct, and whether exceptions have been adequately assessed.

Quality review should provide independent oversight appropriate to the validation activity and verify that deviations, excluded data, and changes have been properly controlled.

21 CFR 211.194 requires second-person review of original laboratory records for accuracy, completeness, and compliance with established standards. FDA also states that production and control records, including relevant audit trails, are subject to Quality Unit review.


Retention and Availability

Validation evidence should remain available for the applicable retention period in a form that preserves its content and meaning. References within the validation report should therefore point to controlled records that will remain retrievable, not temporary directories or analyst workspaces.

21 CFR 211.180 establishes retention and availability expectations for production, control, and laboratory records. FDA’s data-integrity guidance also emphasizes secure retention of data and metadata throughout the record lifecycle.

Where validation evidence is distributed across several repositories, retention responsibilities should be clear enough that the complete package can still be reconstructed later.


Relationship With Computerized Systems

Electronic records are increasingly central to process validation, but this article intentionally stops at the boundary between validation evidence and computerized-system control.

For validation execution, the questions are:

  • What is the authoritative record?
  • What metadata are necessary to understand it?
  • Can changes be reconstructed?
  • Can the result be traced into the validation conclusion?

The detailed questions of system classification, validation, access control, audit-trail configuration, electronic signatures, backup/recovery, infrastructure, and Part 11 applicability belong in the Computerized Systems domain, particularly 21 CFR Part 11 Applicability, Assessment, and Compliance.

That separation avoids turning a process-validation GDP article into another computerized-system validation article.


Good Documentation Practices During Execution

Good Documentation Practices should make the true history of validation execution visible rather than create the appearance of perfect execution.

Appropriate practices include recording information at the time of activity, identifying the person performing the activity, preserving original records or controlled true copies, documenting calculations, maintaining links between data and metadata, correcting records transparently, investigating unusual results, documenting exclusions, maintaining version control, and preserving approved evidence for the required retention period.

Practices that undermine validation integrity include backdating, obscuring original entries, undocumented data deletion, uncontrolled recalculation, selective exclusion of results, unidentified execution records, retrospective alteration of approved reports, or storing regulated evidence only in uncontrolled personal locations.

Good Documentation Practices for process validation showing proper contemporaneous recording, transparent corrections, scientific handling of excluded data, review, and prohibited documentation practices.
Good Documentation Practices preserve the actual history of validation execution. Corrections should remain transparent, excluded data should remain visible with scientific justification, and original validation evidence should never be obscured to create a cleaner record.

Key Principles

  • Process-validation conclusions should remain traceable to complete and reliable execution evidence.
  • Validation activities should be attributable and documented contemporaneously.
  • Original records or appropriate true copies should be preserved when they are necessary to reconstruct the activity.
  • Raw PPQ data should remain traceable to protocol requirements, calculations, analyses, and final conclusions.
  • Statistical datasets should have documented provenance, transformation logic, version control, and linkage to authoritative source data.
  • Electronic data should retain the metadata required to understand and reconstruct the validation activity.
  • Corrections should preserve the original information and make the reason, date, and responsible individual clear.
  • Excluded or invalidated data should remain part of the record with documented scientific justification; exclusion does not mean deletion.
  • Validation deviations should remain linked from protocol execution through investigation and the final validation conclusion.
  • Final validation approval should follow reconciliation of execution records, data, calculations, deviations, exclusions, and supporting evidence.
  • The validation package should be reconstructable without dependence on personal memory or uncontrolled working files.
  • Detailed computerized-system and Part 11 controls should be addressed through the Computerized Systems framework rather than duplicated within process-validation execution procedures.