Audit Trails & Data Integrity: An ALCOA+ Case Study
See how Meridian BioAnalytics fixed chronic ALCOA+ audit trail failures—reducing findings from 14 to zero and passing two consecutive regulatory inspections.
Audit trails and data integrity are among the top citations in FDA 483 observations and ISO 17025 nonconformance reports—yet many small labs still manage them through spreadsheets, paper logs, and institutional memory. This case study follows Meridian BioAnalytics through an 18-month data integrity crisis and shows exactly what they changed to resolve it.
The Lab That Almost Lost Its Accreditation
Meridian BioAnalytics is a 22-person contract testing lab in Raleigh, NC, serving pharmaceutical manufacturers and medical device companies. They run roughly 4,000 sample batches per year across environmental monitoring, raw material ID, and finished-product release testing.
In early 2022, their ISO 17025 surveillance audit returned 14 nonconformances—nine of them tied directly to data integrity. The auditor's written findings included:
- Result entries with no timestamp or analyst attribution
- A deleted raw data file with no record of who deleted it or why
- Handwritten bench sheets that didn't match the corresponding electronic records
- Backdated sample receipt logs discovered through metadata comparison
Their accreditation body gave Meridian 90 days to submit a corrective action plan. The lab director, Dr. Priya Nair, described the situation plainly: "We weren't falsifying data. We were just sloppy. But to a regulator, sloppy looks the same as intentional."
What ALCOA+ Actually Requires (and Where Meridian Fell Short)
ALCOA+ is the framework FDA and many accreditation bodies use to evaluate data integrity. The acronym stands for:
- Attributable — Who collected the data, and when?
- Legible — Can the record be read throughout its retention period?
- Contemporaneous — Was it recorded at the time of the activity?
- Original — Is this the first capture, or a copy?
- Accurate — Does the record reflect what actually happened?
The "+" adds Complete, Consistent, Enduring, and Available.
Meridian's gaps mapped almost entirely to Attributable and Contemporaneous. Analysts were logging sample receipt times from memory at end-of-shift rather than at the moment of receipt. Electronic records in their homegrown Access database had no user-level audit trail—any analyst could open and overwrite a record with no system log of the change.
Critically, the deleted raw data file had been removed by a senior analyst who made a mistake during a file reorganization. His intent was innocent, but the system had no mechanism to capture the deletion event, who performed it, or what the file contained. That single gap nearly cost the lab its accreditation.
Building a Real Audit Trail: The 6-Month Rebuild
Dr. Nair's corrective action plan had three workstreams running in parallel.
1. Lock Down Electronic Record Modification
Meridian replaced their Access database with a LIMS that enforced role-based permissions and captured every create, read, update, and delete event with a UTC timestamp and user ID. Analysts could no longer overwrite a result—they could only append a correction with a mandatory reason code and supervisor co-signature.
Within 60 days of go-live, the system had logged over 11,000 individual record events. Seventeen of those events were correction entries. Each one was visible, attributable, and explainable.
2. Point-of-Activity Data Capture
The lab installed barcode scanners at the sample receiving bench. Analysts now scan samples on receipt, and the timestamp is captured by the system at that moment—not recalled from memory later. The LIMS also flags any sample whose login timestamp falls outside the lab's published chain-of-custody window.
This single change eliminated the backdating problem entirely. In their follow-up audit 12 months later, the auditor noted zero findings related to contemporaneous recording.
3. Deletion and Archiving Protocols
No raw data file can be permanently deleted by an analyst. The new protocol routes deletion requests to a QA-only archive queue. QA reviews the request, attaches a justification record, and moves the file to a write-protected archive partition rather than removing it. The original record remains retrievable, and the audit trail captures every step.
Meridian also implemented a quarterly audit trail review—a two-hour session where the QA manager pulls a system-generated report of all corrections, deletions, and after-hours logins, then signs off that nothing looks anomalous.
The Numbers Before and After
After 12 months under the new system, Meridian's surveillance audit returned zero data integrity findings. Their second consecutive clean audit came six months after that.
Beyond audit performance, the operational picture also shifted:
- Sample login discrepancies (timestamp mismatches, missing receipt data): from an average of 23 per month to 2 per month
- Correction entries requiring supervisor review: visible for the first time at 17 events over 60 days, giving management actual data to act on rather than guessing
- Time to produce audit trail documentation during an inspection: from an estimated 3–4 hours of manual record-pulling to a system-generated report in under 8 minutes
Dr. Nair's summary: "We used to spend an inspection day hunting for records. Now we hand the auditor a printed report before they finish their opening conference."
What Small Labs Can Implement Without a Full LIMS Overhaul
Not every lab has the runway to replace core systems in 60 days. If you're working with legacy infrastructure, here are the highest-leverage changes you can make immediately:
- Enable and review system logs in your existing software. Most lab software has audit trail functionality that is simply turned off by default. Check your admin settings before assuming you have no audit trail.
- Create a correction SOP that requires reason codes and second-person review. Even in paper-based systems, a signed correction log beats an erased entry.
- Separate deletion authority from analyst-level permissions. No one who generates data should also be able to permanently remove it.
- Schedule a monthly 30-minute audit trail spot-check. Pick a random date range, pull the logs, and ask: does every correction make sense? Is anyone logging in at 2 a.m.?
- Date and initial everything at the bench, not at your desk. Contemporaneous recording starts with physical habit, not software.
Aliquora's audit trail module enforces several of these controls by default—including mandatory reason codes on all result corrections and a read-only QA review dashboard—which made it a practical fit for labs at Meridian's scale when they were evaluating options.
Frequently Asked Questions
What is an ALCOA+ audit trail in a laboratory context?
An ALCOA+ audit trail is a complete, tamper-evident record of who created, modified, or deleted a data entry, when they did it, and why. It must satisfy the ALCOA+ principles—Attributable, Legible, Contemporaneous, Original, Accurate, Complete, Consistent, Enduring, and Available—so that any data event can be reconstructed during an inspection or dispute.
How long must a lab retain audit trail records?
Retention requirements vary by regulatory framework. FDA 21 CFR Part 211 generally requires records to be retained for at least two years after product distribution, while ISO 17025 ties retention to the duration of results' validity. Most QA managers default to a minimum of five years and align with the longest applicable requirement for their customer base.
What is the most common ALCOA+ failure in small labs?
The most cited failures are lack of contemporaneous recording (logging results after the fact) and missing attribution (no user ID or timestamp on electronic entries). Both are almost always systemic issues—analysts weren't trained or the software wasn't configured—rather than intentional falsification.
Can a paper-based lab maintain a compliant audit trail?
Yes, but it requires strict procedural controls: ink-only entries, single-line strikethroughs with initials and date for corrections, and secure physical storage. The practical challenge is that paper audit trails are slow to search and easy to lose, which is why regulators increasingly expect electronic records for labs above a certain sample volume.
What triggers an audit trail review during an FDA inspection?
Inspectors routinely request audit trail review when they see erasures, white-out, or overwritten entries on paper records, or when electronic records lack metadata. A mismatch between an instrument's internal clock log and the corresponding LIMS entry is a common trigger. Having your audit trail report ready at the start of the inspection—rather than producing it under pressure—signals a mature quality system.
Related reading
Audit Trails and Data Integrity: ALCOA+ in Practice
Learn how audit trails and ALCOA+ data integrity principles work in real QC labs — and what reviewers actually look for during an inspection.
Read Audit TrailsAudit Trails and Data Integrity: ALCOA+ Checklist for Labs
Master audit trails and data integrity with this ALCOA+ checklist — practical steps QC labs can act on today to satisfy FDA, ISO, and internal auditors.
Read ISO 17025GLP vs GMP vs ISO 17025: What Small Labs Actually Need
Confused by GLP, GMP, and ISO 17025? This guide breaks down which compliance framework small and mid-size labs actually need — and what auditors look for.
Read