What ALCOA+ is — and why it matters
In an audit, the inspector rarely asks “do you have a protocol?”. They ask: “show me who entered this value, and when — and what was there before.” And that is the moment data integrity is decided — the question of whether a record truly holds up to what it claims.
ALCOA+ is the acronym regulators use to bundle that expectation — the properties a record must carry so that a release, a test result or a batch decision stays trustworthy.
The core ALCOA — attributable, legible, contemporaneous, original, accurate — originates in the FDA context and was later extended by four properties to form the “+”: complete, consistent, enduring, available. Today FDA, MHRA, PIC/S, WHO and EMA carry the same core expectation — wording and structure differ in the detail, but the substance largely lines up across the rulebooks.
Important for context: ALCOA+ is not a law of its own. It is a mnemonic for what GMP, EU Annex 11 and 21 CFR Part 11 already require. And it applies across the entire data lifecycle — from creation through processing and analysis to archiving and controlled destruction.
The five classical ALCOA principles
- Attributable: it is unambiguously determinable who or which system performed a data activity — creation, change, deletion — at which point in time.
- Legible: the record is permanently readable and understandable — years later too, for third parties in an audit too. Illegible or overwritten is not evidence.
- Contemporaneous: the data is recorded at the time of the activity — not reconstructed later from memory.
- Original: what counts is the original record (or a certified true copy) — the first raw data, not a transcribed summary.
- Accurate: the data is error-free, truthful and reflects the actual result — without unauthorised change.
ALCOA does not ask “do you have a document?”, it asks “can you reconstruct what actually happened?”.
The plus: four extensions
The four extensions close the gaps ALCOA alone left open — above all in the digital, system-supported world:
- Complete: all data belongs — including repeats, failed attempts, metadata and the audit trail. Selective omission contradicts integrity.
- Consistent: the records are internally contradiction-free and chronological — timestamps and sequence line up.
- Enduring: the data stays durable and unchanged across the full retention period — not on the sticky note that fades.
- Available: the data is retrievable across its lifecycle — for review, inspection and reuse, not lost in an inaccessible archive.
Beyond the nine principles: what carries data integrity
The guidances stress that the nine principles do not stand in isolation. Four overarching expectations carry them:
- Audit trail: for closed systems, 21 CFR Part 11 § 11.10(e) requires secure, computer-generated, time-stamped audit trails that independently record the date and time of operator entries and actions that create, modify or delete electronic records. EU GMP Annex 11 § 9 additionally states that the reason should be documented when GMP-relevant data are changed or deleted.
- Data lifecycle: integrity is thought through across all phases — creation, processing, review, reporting, archiving, destruction — not only at the moment of capture.
- Risk-based: the effort is aligned with the risk to product quality and patient safety — critical data needs stronger controls than non-critical data.
- Quality culture: technical controls alone are not enough. Regulators expect a culture in which errors and deviations are reported transparently, promptly and without fear.
The pattern behind it
All nine properties aim at the same thing: a record must show what really happened — traceable, unchanged, over time. It is the same evidence discipline GxP validation demands of software — applied to data.
ALCOA+ in AI-assisted work
As soon as AI contributes to a GxP-relevant record — a draft, an analysis, a summary — its output, once it feeds into a GxP record, becomes data that must satisfy ALCOA+. A freely generating assistant without source binding creates an additional provenance/lineage risk: the source, version, section and relevant metadata behind a used claim no longer remain dependably traceable. Provenance/lineage is a separate control question; it can support ALCOA evidence but does not replace its definitions: attributable links the data activity to a person or, for automatically generated data, to the original data source; original concerns the original record or a verified true copy; accurate concerns correctness.
Such AI work becomes dependable only with a control architecture that supports these principles right in the work process. That is how the traqx approach to AI in GxP is set up: drafts arise from controlled sources whose version and origin remain visible (provenance/lineage). Every statement ends on a clickable citation and every source reference is checked deterministically. This supports expert review but does not by itself prove correctness. Every review decision remains attributable to a human, while the audit trail retains the decision history completely and durably. Not a data-integrity certificate — a way of working that supports ALCOA+ instead of undermining it.
How AI systems themselves are validated — under GAMP 5 and the draft Annex 22 on artificial intelligence — is covered in two dedicated articles: validating AI systems under GAMP 5 and Annex 22 vs Annex 11.
Seven data-integrity questions before using AI software
An AI product demo does not answer a data-integrity question. What matters is whether the specific work case remains reconstructable across its lifecycle. Before approval, teams should resolve seven points:
- Intended use: does the output only support a draft, or does it enter a GxP record, controlled document or quality decision?
- Controlled inputs: where did source data and documents come from, and which version and status applied?
- Provenance / lineage: does every used claim remain connected to its original source, section and relevant metadata?
- Output status: is the AI proposal visibly separate from a reviewed or effective work state?
- Attributable review: can you see who reviewed, changed, adopted or rejected each proposal?
- Complete evidence: are relevant inputs, sources, changes, decisions and audit-trail events retained under the applicable procedure?
- Change control: does a model, configuration, provider or data-processing change trigger an assessment for the specific use?
These questions do not belong only in tool validation. They must stay answerable in real work. The GxP AI policy guide shows how to turn them into binding use rules, roles and stop conditions.
The honest limits
Three limits that belong with it:
- ALCOA+ is an acronym, not a rulebook. It summarises what the binding requirements demand — it does not replace them.
- Terminology varies slightly. Some guidances list the “+” properties partly under ALCOA itself; the substance is the same across FDA, MHRA, PIC/S, WHO and EMA.
- No tool makes you compliant by itself. Technology can support integrity; it is owned by your process and your quality organisation.
Orientation, not compliance advice
ALCOA+ is a mnemonic, not a law. The binding requirements are GMP, EU Annex 11 and 21 CFR Part 11. No tool is inherently “data-integrity compliant” — integrity is always established by your validated process in your context.
Frequently asked questions
What does ALCOA mean in GxP?
In GxP, ALCOA stands for attributable, legible, contemporaneous, original, accurate. The “+” adds four properties: complete, consistent, enduring, available. Together they are the nine properties that make a GxP-relevant record trustworthy.
What is the difference between ALCOA and ALCOA+?
ALCOA is the five classical criteria from the FDA context. The “+” was added later and closes the gaps in the digital, system-supported environment: complete, consistent, enduring, available. Some guidances now list the “+” properties under ALCOA itself — the substance is largely the same across FDA, MHRA, PIC/S, WHO and EMA.
Is ALCOA+ a law?
No. ALCOA+ is a mnemonic, not a regulation in its own right. The binding requirements are the applicable GMP requirements — in the EU, Annex 11; in the US, 21 CFR Part 11. ALCOA+ summarises what those already require and does not replace them.
Does ALCOA+ apply to AI-generated data too?
Yes. As soon as an AI output flows into a GxP record it becomes a datum itself that must satisfy ALCOA+. Missing source binding creates a distinct provenance/lineage risk; it does not redefine attributable or original. Defensible AI work also needs source binding, human review and a complete audit trail.
What should teams check for data integrity when using AI software?
Check the entire work context: intended use, approved and versioned inputs, the link to original sources, visible AI-proposal status, attributable human review, complete records, and assessment of relevant model, provider or configuration changes. Keeping only the final text is often not enough for defensible evidence.