A data integrity concern
These escalate faster than almost any other event, because the concern is not about one record but about whether records generally can be relied upon.
Handle the investigation itself carefully — a mishandled data integrity enquiry can create a second, worse problem.
Roughly the first working day
- Preserve, do not tidySecure systems, audit trails and records in their current state. Any cleanup during an investigation is itself likely to be discovered and will be interpreted badly.
- Restrict change, not access to truthConsider limiting the ability to modify affected records while preserving the ability to review them.
- Separate the investigator from the subjectWhoever investigates should not be the person whose work is being examined, nor their direct manager.
- Establish scope before conclusionsOne system, one analyst, one period, or wider. Scope determines everything downstream and is hard to revise later.
- Consider the behavioural dimension earlyWhere pressure or fear contributed, a technical remedy alone will not hold. That assessment is uncomfortable and necessary.
What must not be lost while people react
- Audit trails in native format, with metadata intact.
- Source data files for dynamic records, not printouts.
- Access logs, account configuration and privilege assignments.
- Any paper records associated with a hybrid arrangement.
What shapes the investigation
- 01Is this a control weakness, a process failure, or a deliberate act? The three need different responses.
- 02What is the earliest date the concern could apply from?
- 03Which product decisions relied on the data in question?
- 04Are the same conditions present on other systems or in other departments?
- 05Did the system make the non-compliant route easier than the compliant one?
Things to consider, not conclusions to adopt
- Data integrity findings frequently expand in scope, because they call into question the evidence supporting other records.
- Where product decisions relied on affected data, consider whether product impact and notification processes are engaged.
- PIC/S PI 041 and the MHRA guidance set out the expectations in detail and are the appropriate reference for scoping a review.
- Where a deliberate act is suspected, consider taking legal advice before proceeding — employment and evidential considerations apply.
What sites commonly get wrong
- Investigating informally first, which risks contaminating the evidence.
- Narrowing scope to the single record identified because a wider review is unwelcome.
- Fixing the technical control without addressing why the behaviour occurred.
- Allowing the person whose work is under review to lead or influence the investigation.
Ten steps, in this order
- 01
Contain
Stop the situation getting worse. Quarantine affected material, halt the process step if continuing would compound the problem, and secure the area or system involved.
- 02
Assess
Establish what is known versus assumed. What happened, when, to what, and who observed it. Resist the pull to conclude a cause in the first hour.
- 03
Escalate
Notify according to your own procedure. Getting the right people informed early costs little; discovering later that QA or the QP was not told is itself a finding.
- 04
Investigate
Establish the cause with evidence rather than plausibility. Depth should be proportionate to risk, but the standard for a confirmed cause does not move.
- 05
Document
Record contemporaneously as you go. Reconstructing a record afterwards converts a quality problem into a data integrity problem, which is a different order of seriousness.
- 06
Determine impact
Assess product impact beyond the batch in front of you — other batches sharing equipment, materials, personnel or time window, and material already released.
- 07
Correct
Fix the immediate instance, and separately address the cause. Conflating correction with corrective action is the most common weakness in a response.
- 08
Prevent recurrence
Address why the process permitted the event. Where the design invites the error, training a person not to make it is a delay rather than a correction.
- 09
Verify effectiveness
Check against a criterion defined before implementation. This is the step most often skipped, and the one that decides whether the event returns as a repeat finding.
- 10
Close and monitor
Close with evidence attached, and keep the indicator under review long enough to know the fix held rather than merely completed.
This is quality guidance, not legal advice
This is practical quality guidance, not legal or regulatory advice. Whether a specific event triggers a particular regulatory obligation depends on the product, the market, the marketing authorisation and the facts. Assess against your own procedures, and take qualified advice where the situation may involve notification, recall or a deliberate act.
A date you did not choose
If there is a response deadline or an investigation that has to hold up under scrutiny, a short call is the fastest route to a view on what to do first.