A trial result is trustworthy only if the path from observation to analysis can be reconstructed. Modern data integrity is not achieved by locking a final spreadsheet. It requires controlled capture, relevant metadata, and visible corrections. It requires secure access, validated systems, and retained records. It requires review focused on the data that matter to participant safety and trial conclusions.
Key points#
- ALCOA summarizes five core properties: attributable, legible, contemporaneous, original, and accurate.
- Many regulators extend the idea to complete, consistent, enduring, and available records across the data life cycle.
- An audit trail records creation, change, and deletion events without obscuring the earlier value.
- ICH E6(R3), finalized internationally in 2025 and adopted by FDA as final guidance in September 2025, emphasizes data governance, quality by design, and proportionate controls.
- Audit trails deter hidden alteration, but they are useful only when systems are validated, access is controlled, and important changes are actually reviewed.
From one observation to one analysis cell#
Consider a blood-pressure value used in a trial endpoint. The apparent number may pass through a device, a local health record, an electronic case-report form, a query, a data-management review, a derived dataset, and a statistical program before it appears in a table.
At each transfer, questions arise. Was the correct participant measured? Was the time point within the protocol window? Did the unit change? Was a repeat selected? Was the value corrected after a query? Which source controlled when records disagreed? Did the derivation code use the prespecified rule?
Data integrity means that these questions can be answered from retained records and metadata. It does not mean that no error ever occurs. It means errors can be found, corrections remain visible, and the final value can be traced to a defensible source.
ALCOA as a reading framework#
The ALCOA terms are compact but practical.
Attributable#
The record identifies who or what created it. Shared accounts weaken attribution. Device-generated data should identify the instrument, participant, date, time, and transfer pathway.
Legible#
The information remains readable and understandable for the required retention period, and for electronic records, legibility includes the ability to render data and relevant metadata after software changes or system retirement.
Contemporaneous#
The observation is recorded when it occurs, with trustworthy timing. Late entry may sometimes be legitimate, but it should be identified and explained rather than presented as real-time capture.
Original#
The first capture, or a verified copy that preserves the same information and relevant metadata, is retained. Printing a dynamic electronic record can discard audit history and may not be an adequate replacement.
Accurate#
The record reflects the observation and permitted processing correctly. Accuracy depends on calibrated equipment, trained users, validated calculations, controlled terminology, and documented correction processes.
Completeness, consistency, endurance, and availability extend these properties across the life cycle. A perfectly accurate value that disappears before inspection is not sufficient. A table without the excluded observations is not complete.
What an audit trail should reveal#
An audit trail is secure metadata recording activities on a record. For a changed data field, it should make the original value and new value visible, identify the person or system responsible, preserve date and time, and record a reason where applicable.
Suppose a weight is changed from 72 kilograms to 172 kilograms. The history might show that the original direct entry was 72, a later query requested confirmation, and a coordinator changed it after checking a source note; you can then judge whether 172 is right. If the system simply overwrites 72, nobody can tell a genuine correction from an accidental keystroke or an inappropriate alteration.
Users who enter trial data should not be able to edit the audit trail. Access should follow roles, and records should show changes to privileges. System clocks, backups, and interfaces also need controls. So do exports and migration processes, because data can be altered outside the visible case-report form.
The E6(R3) shift to proportionate data governance#
ICH E6(R3) updates Good Clinical Practice for decentralized activities, digital systems, new data sources, and risk-based quality management; it asks sponsors and investigators to identify data and processes critical to participant protection and result reliability, then design proportionate controls around them.
This does not reduce the need for traceability. It avoids treating every field as equally consequential. A typo in an internal scheduling note is not equivalent to a changed primary endpoint or serious adverse event. Monitoring, validation, audit-trail review, and query effort should concentrate on critical risks while retaining the essential record.
The guideline also treats relevant metadata as part of data governance. A value without context may be impossible to interpret. Time zone, unit, and device version can determine whether two identical-looking numbers mean the same thing. So can transformation, assessor, and status.
Source data verification is not the whole system#
Traditional monitoring often compared case-report-form entries with source documents, and this can detect transcription errors, but checking every field against paper is inefficient and may miss failures in system design, missing participants, fabricated source records, or flawed derivations.
A risk-based approach asks where errors could change safety decisions or the trial conclusion. It can combine targeted source review, centralized statistical monitoring, and missing-data checks. It can combine outlier detection, protocol-deviation review, and audit-trail analysis.
The source itself must also be defined. In direct electronic capture, the instrument record may be original. In an electronic patient-reported outcome system, the participant's entry may be source data. Copying it into a local worksheet does not make the worksheet original.
Audit-trail review needs a question#
Collecting an enormous audit log without reviewing it creates the appearance of control. Review should be planned around meaningful risks, such as:
- changes to eligibility or randomization fields,
- deletion or late entry of adverse events,
- repeated edits near database lock,
- implausible timing or shared credentials,
- changes to primary endpoint components,
- modifications after unblinding,
- bulk corrections without clear rationale,
- edits made by users outside their expected role.
A flag still requires context. A surge of edits may reflect a documented data migration or central unit correction. The trail helps reconstruct the reason; it does not decide intent by itself.
Questions readers can ask from the published report#
A journal article cannot reproduce the full data-governance plan, but it can still give you useful signals:
- Was the trial conducted under a current Good Clinical Practice framework?
- Were electronic systems and critical data sources described?
- Was the protocol and statistical analysis plan available?
- Were changes to outcomes or analyses dated and explained?
- Did the report account for every randomized participant?
- Were missing, corrected, and excluded observations handled transparently?
- Was the dataset finalized before unblinded analysis?
- Are code, data dictionaries, or sharing procedures available where lawful?
- Did inspections, monitoring, or audits identify findings that affect reliability?
Compliance language alone does not prove integrity. A traceable, internally consistent report with an accessible protocol history tells you more than a generic claim that standards were followed.
Sources and further reading
Questions and answers
Does an audit trail prevent every data error?
No. It records actions and supports reconstruction. Prevention also requires usable systems, training, validation, access control, device checks, and processes that reduce opportunities for error.
Is a scanned paper form an original record?
It may be an acceptable certified copy if the verification process preserves all relevant information and metadata under applicable requirements. A scan that omits context or an original feature may be inadequate.
Why not verify every data point?
Universal checking consumes resources and can distract from critical risks. E6(R3) supports proportionate controls focused on participant protection and the reliability of important results, while still requiring complete and traceable essential records.