ALCOA — introduced by the FDA in the early 1990s — started as five data-integrity attributes: Attributable, Legible, Contemporaneous, Original, Accurate. Regulators later added four more, forming ALCOA+: Complete, Consistent, Enduring, Available. Together, these nine attributes are what "data integrity" concretely means when an inspector uses the phrase.
The nine attributes
| Attribute | What it actually requires |
|---|---|
| Attributable | Every entry is traceable to the specific individual who made it — no shared logins. |
| Legible | Records are permanently readable — no illegible handwriting, no data that decays or becomes unreadable. |
| Contemporaneous | Recorded at the time the activity happened — not reconstructed from memory afterward. |
| Original | The first recording, or a verified true copy — not a re-transcription. |
| Accurate | Free of errors, and edited (if ever) with the change and reason documented. |
| Complete | All data included, including repeat or reprocessed analyses — nothing selectively omitted. |
| Consistent | Chronologically dated and time-stamped in the expected sequence. |
| Enduring | Recorded on a durable medium, retained for the required retention period. |
| Available | Retrievable for review or inspection for the entire retention period, not archived beyond practical reach. |
Where these come from
ALCOA+ isn't informal industry jargon — it's referenced explicitly in WHO TRS 996 Annex 5, PIC/S PI 041-1 (2021), and the MHRA GxP Data Integrity Guidance (2018). The FDA treats these nine attributes as the minimum data-integrity expectation under 21 CFR 211.68 and 211.100.
The detail most articles skip
Recording only the final, corrected value without preserving the original entry and the reason for the change violates both "Original" and "Accurate" simultaneously — a correction without an audit trail of the correction is itself a data-integrity gap.
The most common violation
Shared login credentials remain the single most frequently cited ALCOA+ violation in FDA 483 observations. It's a deceptively simple failure — a lab where every analyst logs in as "QC1" has already broken "Attributable" before any test result is even entered, regardless of how accurate the results themselves turn out to be.
Why paper and Excel both struggle here
Paper logbooks can satisfy several ALCOA+ attributes reasonably well (legible, if handwriting is good; contemporaneous, if filled out promptly) — but consistently fail "Attributable" when multiple people share a logbook, and fail "Available" the moment a page goes missing. Spreadsheets fail differently: they're easy to edit without a trace, meaning "Original" and "Accurate" both depend entirely on manual discipline rather than system enforcement.
Ready to see this in your own lab? Book a free ValiCore demo.