A working semiconductor data integrity program has the same four elements (instrument validation, trend plot, excursion record, retention) as a pharmaceutical program, with the retention period shortened to the customer-specific requirement (typically 3 to 5 years) and the audit trail aligned to the customer’s audit expectation. The standard is the same. The cadence is the same. The audit defense is the same.
Closing: The Trend Plot Is the Defense
The mental shift that makes the data integrity program work is to stop treating it as a compliance program and start treating it as a documentation program. The data is already being generated. The documentation is what makes the data auditable, and the auditability is the input to the customer’s confidence. A working trend plot, a working excursion record, and a working retention program are the three artifacts that turn data into evidence, and the evidence is the input to the next order.
If you are building a data integrity program from scratch, or reviewing an existing one, we can share a draft ALCOA+ gap assessment, a trend plot template, and an excursion record template, typically within two business days. Reach out with your current LIMS, your current instrument list, and the date of your most recent data integrity audit.
The retention is the third audit defense, and the one most often overlooked. The retention period is defined by regulation (typically 10 years for pharmaceutical, 5 years for semiconductor), and the data has to be retrievable for the entire period. The most common retention failure is the data being stored in a proprietary format that the vendor no longer supports, typically because the vendor has been acquired or has discontinued the product. The corrective action is a defined export schedule, with the data exported to a non-proprietary format at the end of each retention period, and the export being validated.
A working retention program has the following elements:
- The retention period. The retention period is defined by regulation, and the data is retained for at least the period.
- The storage format. The storage format is non-proprietary (CSV, PDF) and the format is validated for readability at the end of each retention period.
- The export schedule. The export schedule is defined in advance, with the export run at the end of each retention period, and the export verified by a second person.
- The access control. The access control is defined in advance, with the access reviewed at a defined cadence, and the access revoked when the person leaves the organization.
The Semiconductor Equivalent: Less Prescriptive, Same Standard
Semiconductor R&D and pilot lines do not have a regulatory mandate to follow ALCOA+, but the standard is the same. The data integrity program is the evidence that the data the program produces is reliable, and the reliability is the input to the engineering decisions that follow. A data integrity finding in a semiconductor fab is a data integrity finding in the customer’s audit, and the customer’s audit is the input to the next order.
A working semiconductor data integrity program has the same four elements (instrument validation, trend plot, excursion record, retention) as a pharmaceutical program, with the retention period shortened to the customer-specific requirement (typically 3 to 5 years) and the audit trail aligned to the customer’s audit expectation. The standard is the same. The cadence is the same. The audit defense is the same.
Closing: The Trend Plot Is the Defense
The mental shift that makes the data integrity program work is to stop treating it as a compliance program and start treating it as a documentation program. The data is already being generated. The documentation is what makes the data auditable, and the auditability is the input to the customer’s confidence. A working trend plot, a working excursion record, and a working retention program are the three artifacts that turn data into evidence, and the evidence is the input to the next order.
If you are building a data integrity program from scratch, or reviewing an existing one, we can share a draft ALCOA+ gap assessment, a trend plot template, and an excursion record template, typically within two business days. Reach out with your current LIMS, your current instrument list, and the date of your most recent data integrity audit.
The excursion record is the second most useful artifact. The record has the data point that triggered the excursion, the response procedure, the investigation, the root cause, the corrective action, and the close-out. The record is created at the moment of the excursion, with the operator’s identity, the time, the location, and the data point captured automatically. The investigation is documented within a defined time window (typically 24 hours for pharmaceutical, 72 hours for semiconductor). The corrective action is documented with a CAPA, and the CAPA is closed before the excursion is closed.
A working excursion record has the following elements:
- The data point. The data point is the raw value that triggered the excursion, with the time, the location, and the instrument identifier captured automatically.
- The response. The response is the documented sequence of actions, with the operator’s identity, the time, and the action captured at each step.
- The investigation. The investigation is the documented root cause analysis, with the data reviewed, the procedure reviewed, and the personnel interviewed. The investigation is closed within the defined time window.
- The corrective action. The corrective action is the documented CAPA, with the owner, the target close date, and the close-out evidence.
- The close-out. The close-out is the documented verification that the corrective action worked, typically with a re-monitoring at the same location, with the data confirming the recovery.
The Retention: The Third Audit Defense
The retention is the third audit defense, and the one most often overlooked. The retention period is defined by regulation (typically 10 years for pharmaceutical, 5 years for semiconductor), and the data has to be retrievable for the entire period. The most common retention failure is the data being stored in a proprietary format that the vendor no longer supports, typically because the vendor has been acquired or has discontinued the product. The corrective action is a defined export schedule, with the data exported to a non-proprietary format at the end of each retention period, and the export being validated.
A working retention program has the following elements:
- The retention period. The retention period is defined by regulation, and the data is retained for at least the period.
- The storage format. The storage format is non-proprietary (CSV, PDF) and the format is validated for readability at the end of each retention period.
- The export schedule. The export schedule is defined in advance, with the export run at the end of each retention period, and the export verified by a second person.
- The access control. The access control is defined in advance, with the access reviewed at a defined cadence, and the access revoked when the person leaves the organization.
The Semiconductor Equivalent: Less Prescriptive, Same Standard
Semiconductor R&D and pilot lines do not have a regulatory mandate to follow ALCOA+, but the standard is the same. The data integrity program is the evidence that the data the program produces is reliable, and the reliability is the input to the engineering decisions that follow. A data integrity finding in a semiconductor fab is a data integrity finding in the customer’s audit, and the customer’s audit is the input to the next order.
A working semiconductor data integrity program has the same four elements (instrument validation, trend plot, excursion record, retention) as a pharmaceutical program, with the retention period shortened to the customer-specific requirement (typically 3 to 5 years) and the audit trail aligned to the customer’s audit expectation. The standard is the same. The cadence is the same. The audit defense is the same.
Closing: The Trend Plot Is the Defense
The mental shift that makes the data integrity program work is to stop treating it as a compliance program and start treating it as a documentation program. The data is already being generated. The documentation is what makes the data auditable, and the auditability is the input to the customer’s confidence. A working trend plot, a working excursion record, and a working retention program are the three artifacts that turn data into evidence, and the evidence is the input to the next order.
If you are building a data integrity program from scratch, or reviewing an existing one, we can share a draft ALCOA+ gap assessment, a trend plot template, and an excursion record template, typically within two business days. Reach out with your current LIMS, your current instrument list, and the date of your most recent data integrity audit.
Environmental monitoring data typically fails ALCOA+ at one of four points: the sample collection, the data entry, the data aggregation, or the data retention. Each point has a different failure mode and a different corrective action. A program that has a data integrity finding at any of the four points has a data integrity problem at all four points, because the four points share the same underlying data flow.
- Sample collection. The sample is collected by an operator, and the operator’s identity, the sample location, the sample time, and the sample volume are all captured at the moment of collection. The most common failure is the operator recording the time at the end of the shift, which breaks contemporaneous. The corrective action is an instrument or a barcode scanner that captures the time and the location automatically, with the operator identity captured by login.
- Data entry. The data is entered into the LIMS or the monitoring database. The most common failure is the transcription from a paper record to the database, which breaks original. The corrective action is direct entry at the instrument, with the paper record used only as a backup.
- Data aggregation. The data is aggregated into a trend plot, an action limit report, and a monthly summary. The most common failure is the aggregation being done in a spreadsheet, with the underlying data exported from the LIMS, which breaks complete. The corrective action is the trend plot being generated from the LIMS, with the spreadsheet used only for ad hoc analysis.
- Data retention. The data is retained for the retention period (typically 10 years for pharmaceutical, 5 years for semiconductor). The most common failure is the data being retained in a proprietary format that the vendor no longer supports, which breaks enduring and available. The corrective action is the data being exported to a non-proprietary format (CSV, PDF) at the end of each retention period, with the export being validated.
The Instrument: A Validated Continuous Monitoring System
The instrument is the first line of data integrity. A continuous monitoring system that captures the particle count, the air velocity, the temperature, the humidity, and the pressure differential at a defined interval (typically 1 minute for ISO 5, 5 minutes for ISO 7) and stores the data with a time stamp, a location, and an instrument identifier is the foundation of an ALCOA+ compliant monitoring program. The validation of the instrument is the proof that the data is accurate, the calibration is the proof that the accuracy is maintained, and the audit trail is the proof that the data is attributable.
A working instrument validation has the following elements, all written down before the instrument is deployed:
- Design qualification (DQ). The instrument meets the user requirement, which is typically expressed as the particle size range, the concentration range, the sample volume, the data storage, and the data export.
- Installation qualification (IQ). The instrument is installed per the manufacturer’s specification, with the installation documented and the calibration verified.
- Operational qualification (OQ). The instrument operates within the specification under defined conditions, with the operation documented and the data verified.
- Performance qualification (PQ). The instrument operates within the specification under operational conditions, with the operation documented and the data verified.
The four qualifications are run once at initial qualification, and re-run at the requalification cadence. The validation is the input to the calibration program, and the calibration is the input to the monitoring program. A program that does not have the four qualifications is the most common audit finding in instrument validation.
The Trend Plot: The Best Audit Defense
The trend plot is the single most useful artifact in an ALCOA+ compliant monitoring program. The plot has the data on the y-axis (typically the particle count or the concentration) and the time on the x-axis, with the action limit and the class limit drawn as horizontal lines. The plot is generated from the LIMS, not from a spreadsheet, and the plot is reviewed at a defined cadence (typically monthly for the operational review, quarterly for the QA review). The review is documented, with the reviewer identified, the date recorded, and the observations recorded.
A working trend plot has the following elements:
- The data. The data is the raw particle counts or the concentrations, with no aggregation or smoothing. The aggregation is done in a separate view, not in the trend plot.
- The action limit. The action limit is drawn as a horizontal line, with the value labeled. The action limit is the trigger for the response procedure.
- The class limit. The class limit is drawn as a horizontal line, with the value labeled. The class limit is the design intent, and the data should be within the class limit for the majority of the time.
- The annotations. The annotations are the documented events that affected the data, such as a planned shutdown, an unplanned shutdown, a maintenance event, or an excursion. The annotations are linked to the corresponding record, so the auditor can trace the annotation to the underlying event.
- The review signature. The review signature is the documented review by the qualified reviewer, with the date, the observations, and any follow-up actions.
A trend plot that has all five elements is the single best defense in an audit. The auditor can read the plot, see the data, see the limits, see the annotations, and see the review signature, all in one artifact. A trend plot that is missing any of the five elements is the most common audit finding in monitoring programs.
The Excursion Record: The Second Best Audit Defense
The excursion record is the second most useful artifact. The record has the data point that triggered the excursion, the response procedure, the investigation, the root cause, the corrective action, and the close-out. The record is created at the moment of the excursion, with the operator’s identity, the time, the location, and the data point captured automatically. The investigation is documented within a defined time window (typically 24 hours for pharmaceutical, 72 hours for semiconductor). The corrective action is documented with a CAPA, and the CAPA is closed before the excursion is closed.
A working excursion record has the following elements:
- The data point. The data point is the raw value that triggered the excursion, with the time, the location, and the instrument identifier captured automatically.
- The response. The response is the documented sequence of actions, with the operator’s identity, the time, and the action captured at each step.
- The investigation. The investigation is the documented root cause analysis, with the data reviewed, the procedure reviewed, and the personnel interviewed. The investigation is closed within the defined time window.
- The corrective action. The corrective action is the documented CAPA, with the owner, the target close date, and the close-out evidence.
- The close-out. The close-out is the documented verification that the corrective action worked, typically with a re-monitoring at the same location, with the data confirming the recovery.
The Retention: The Third Audit Defense
The retention is the third audit defense, and the one most often overlooked. The retention period is defined by regulation (typically 10 years for pharmaceutical, 5 years for semiconductor), and the data has to be retrievable for the entire period. The most common retention failure is the data being stored in a proprietary format that the vendor no longer supports, typically because the vendor has been acquired or has discontinued the product. The corrective action is a defined export schedule, with the data exported to a non-proprietary format at the end of each retention period, and the export being validated.
A working retention program has the following elements:
- The retention period. The retention period is defined by regulation, and the data is retained for at least the period.
- The storage format. The storage format is non-proprietary (CSV, PDF) and the format is validated for readability at the end of each retention period.
- The export schedule. The export schedule is defined in advance, with the export run at the end of each retention period, and the export verified by a second person.
- The access control. The access control is defined in advance, with the access reviewed at a defined cadence, and the access revoked when the person leaves the organization.
The Semiconductor Equivalent: Less Prescriptive, Same Standard
Semiconductor R&D and pilot lines do not have a regulatory mandate to follow ALCOA+, but the standard is the same. The data integrity program is the evidence that the data the program produces is reliable, and the reliability is the input to the engineering decisions that follow. A data integrity finding in a semiconductor fab is a data integrity finding in the customer’s audit, and the customer’s audit is the input to the next order.
A working semiconductor data integrity program has the same four elements (instrument validation, trend plot, excursion record, retention) as a pharmaceutical program, with the retention period shortened to the customer-specific requirement (typically 3 to 5 years) and the audit trail aligned to the customer’s audit expectation. The standard is the same. The cadence is the same. The audit defense is the same.
Closing: The Trend Plot Is the Defense
The mental shift that makes the data integrity program work is to stop treating it as a compliance program and start treating it as a documentation program. The data is already being generated. The documentation is what makes the data auditable, and the auditability is the input to the customer’s confidence. A working trend plot, a working excursion record, and a working retention program are the three artifacts that turn data into evidence, and the evidence is the input to the next order.
If you are building a data integrity program from scratch, or reviewing an existing one, we can share a draft ALCOA+ gap assessment, a trend plot template, and an excursion record template, typically within two business days. Reach out with your current LIMS, your current instrument list, and the date of your most recent data integrity audit.
Environmental monitoring generates data. The data has to survive an audit, a regulatory inspection, and a 10-year retention. ALCOA+ — Attributable, Legible, Contemporaneous, Original, Accurate, plus Complete, Consistent, Enduring, and Available — is the framework that defines what survival means. A monitoring program that produces data which does not meet ALCOA+ is a monitoring program that has to be re-collected, and the re-collection is the most expensive part of the response to an audit finding.
This article is a working guide to building environmental monitoring data integrity from the sample location to the trend plot. It assumes the cleanroom is already running with a defined qualification and monitoring program, a working personnel qualification program, and a documented excursion response procedure. The data integrity program is the evidence that the data those programs produce is auditable.
ALCOA+ in 30 Seconds
ALCOA+ defines nine properties that regulated data has to have, in plain language, at every step from collection to retention. The properties are the difference between a record that an auditor accepts and a record that an auditor flags. A record that an auditor flags is a record that has to be re-collected, and the re-collection is the most expensive part of the response.
- Attributable. Every data point is traceable to the person who generated it, the instrument that generated it, and the time and location of the generation. The attribution is captured at the moment of the data point, not reconstructed later.
- Legible. The data is readable, in plain language, for the entire retention period. A handwritten record that is faded after five years is not legible. A digital record in a proprietary format that cannot be read after the vendor discontinues the product is not legible.
- Contemporaneous. The data is recorded at the time of the activity, not later. A record entered into a spreadsheet at the end of the shift is contemporaneous. A record reconstructed at the end of the week is not.
- Original. The data is the first recording, not a transcription. A scanned printout is original. A typed-in copy of a printout is not.
- Accurate. The data is free from error, with the error defined by the validated method. An out-of-spec reading is accurate. An in-spec reading with an undocumented calibration is not.
- Complete. All data is present, including the data that was unexpected, the data that was re-run, and the data that was invalidated with a reason.
- Consistent. The data is consistent across the systems that hold it. A sample location named “RM-A1” in the monitoring SOP and “Room A, Position 1” in the LIMS is inconsistent.
- Enduring. The data is preserved for the entire retention period, in a format that survives system changes, vendor changes, and organizational changes.
- Available. The data is retrievable for review, for audit, and for inspection, in plain language, without specialized tools that the auditor does not have.
Where Environmental Monitoring Data Typically Fails
Environmental monitoring data typically fails ALCOA+ at one of four points: the sample collection, the data entry, the data aggregation, or the data retention. Each point has a different failure mode and a different corrective action. A program that has a data integrity finding at any of the four points has a data integrity problem at all four points, because the four points share the same underlying data flow.
- Sample collection. The sample is collected by an operator, and the operator’s identity, the sample location, the sample time, and the sample volume are all captured at the moment of collection. The most common failure is the operator recording the time at the end of the shift, which breaks contemporaneous. The corrective action is an instrument or a barcode scanner that captures the time and the location automatically, with the operator identity captured by login.
- Data entry. The data is entered into the LIMS or the monitoring database. The most common failure is the transcription from a paper record to the database, which breaks original. The corrective action is direct entry at the instrument, with the paper record used only as a backup.
- Data aggregation. The data is aggregated into a trend plot, an action limit report, and a monthly summary. The most common failure is the aggregation being done in a spreadsheet, with the underlying data exported from the LIMS, which breaks complete. The corrective action is the trend plot being generated from the LIMS, with the spreadsheet used only for ad hoc analysis.
- Data retention. The data is retained for the retention period (typically 10 years for pharmaceutical, 5 years for semiconductor). The most common failure is the data being retained in a proprietary format that the vendor no longer supports, which breaks enduring and available. The corrective action is the data being exported to a non-proprietary format (CSV, PDF) at the end of each retention period, with the export being validated.
The Instrument: A Validated Continuous Monitoring System
The instrument is the first line of data integrity. A continuous monitoring system that captures the particle count, the air velocity, the temperature, the humidity, and the pressure differential at a defined interval (typically 1 minute for ISO 5, 5 minutes for ISO 7) and stores the data with a time stamp, a location, and an instrument identifier is the foundation of an ALCOA+ compliant monitoring program. The validation of the instrument is the proof that the data is accurate, the calibration is the proof that the accuracy is maintained, and the audit trail is the proof that the data is attributable.
A working instrument validation has the following elements, all written down before the instrument is deployed:
- Design qualification (DQ). The instrument meets the user requirement, which is typically expressed as the particle size range, the concentration range, the sample volume, the data storage, and the data export.
- Installation qualification (IQ). The instrument is installed per the manufacturer’s specification, with the installation documented and the calibration verified.
- Operational qualification (OQ). The instrument operates within the specification under defined conditions, with the operation documented and the data verified.
- Performance qualification (PQ). The instrument operates within the specification under operational conditions, with the operation documented and the data verified.
The four qualifications are run once at initial qualification, and re-run at the requalification cadence. The validation is the input to the calibration program, and the calibration is the input to the monitoring program. A program that does not have the four qualifications is the most common audit finding in instrument validation.
The Trend Plot: The Best Audit Defense
The trend plot is the single most useful artifact in an ALCOA+ compliant monitoring program. The plot has the data on the y-axis (typically the particle count or the concentration) and the time on the x-axis, with the action limit and the class limit drawn as horizontal lines. The plot is generated from the LIMS, not from a spreadsheet, and the plot is reviewed at a defined cadence (typically monthly for the operational review, quarterly for the QA review). The review is documented, with the reviewer identified, the date recorded, and the observations recorded.
A working trend plot has the following elements:
- The data. The data is the raw particle counts or the concentrations, with no aggregation or smoothing. The aggregation is done in a separate view, not in the trend plot.
- The action limit. The action limit is drawn as a horizontal line, with the value labeled. The action limit is the trigger for the response procedure.
- The class limit. The class limit is drawn as a horizontal line, with the value labeled. The class limit is the design intent, and the data should be within the class limit for the majority of the time.
- The annotations. The annotations are the documented events that affected the data, such as a planned shutdown, an unplanned shutdown, a maintenance event, or an excursion. The annotations are linked to the corresponding record, so the auditor can trace the annotation to the underlying event.
- The review signature. The review signature is the documented review by the qualified reviewer, with the date, the observations, and any follow-up actions.
A trend plot that has all five elements is the single best defense in an audit. The auditor can read the plot, see the data, see the limits, see the annotations, and see the review signature, all in one artifact. A trend plot that is missing any of the five elements is the most common audit finding in monitoring programs.
The Excursion Record: The Second Best Audit Defense
The excursion record is the second most useful artifact. The record has the data point that triggered the excursion, the response procedure, the investigation, the root cause, the corrective action, and the close-out. The record is created at the moment of the excursion, with the operator’s identity, the time, the location, and the data point captured automatically. The investigation is documented within a defined time window (typically 24 hours for pharmaceutical, 72 hours for semiconductor). The corrective action is documented with a CAPA, and the CAPA is closed before the excursion is closed.
A working excursion record has the following elements:
- The data point. The data point is the raw value that triggered the excursion, with the time, the location, and the instrument identifier captured automatically.
- The response. The response is the documented sequence of actions, with the operator’s identity, the time, and the action captured at each step.
- The investigation. The investigation is the documented root cause analysis, with the data reviewed, the procedure reviewed, and the personnel interviewed. The investigation is closed within the defined time window.
- The corrective action. The corrective action is the documented CAPA, with the owner, the target close date, and the close-out evidence.
- The close-out. The close-out is the documented verification that the corrective action worked, typically with a re-monitoring at the same location, with the data confirming the recovery.
The Retention: The Third Audit Defense
The retention is the third audit defense, and the one most often overlooked. The retention period is defined by regulation (typically 10 years for pharmaceutical, 5 years for semiconductor), and the data has to be retrievable for the entire period. The most common retention failure is the data being stored in a proprietary format that the vendor no longer supports, typically because the vendor has been acquired or has discontinued the product. The corrective action is a defined export schedule, with the data exported to a non-proprietary format at the end of each retention period, and the export being validated.
A working retention program has the following elements:
- The retention period. The retention period is defined by regulation, and the data is retained for at least the period.
- The storage format. The storage format is non-proprietary (CSV, PDF) and the format is validated for readability at the end of each retention period.
- The export schedule. The export schedule is defined in advance, with the export run at the end of each retention period, and the export verified by a second person.
- The access control. The access control is defined in advance, with the access reviewed at a defined cadence, and the access revoked when the person leaves the organization.
The Semiconductor Equivalent: Less Prescriptive, Same Standard
Semiconductor R&D and pilot lines do not have a regulatory mandate to follow ALCOA+, but the standard is the same. The data integrity program is the evidence that the data the program produces is reliable, and the reliability is the input to the engineering decisions that follow. A data integrity finding in a semiconductor fab is a data integrity finding in the customer’s audit, and the customer’s audit is the input to the next order.
A working semiconductor data integrity program has the same four elements (instrument validation, trend plot, excursion record, retention) as a pharmaceutical program, with the retention period shortened to the customer-specific requirement (typically 3 to 5 years) and the audit trail aligned to the customer’s audit expectation. The standard is the same. The cadence is the same. The audit defense is the same.
Closing: The Trend Plot Is the Defense
The mental shift that makes the data integrity program work is to stop treating it as a compliance program and start treating it as a documentation program. The data is already being generated. The documentation is what makes the data auditable, and the auditability is the input to the customer’s confidence. A working trend plot, a working excursion record, and a working retention program are the three artifacts that turn data into evidence, and the evidence is the input to the next order.
If you are building a data integrity program from scratch, or reviewing an existing one, we can share a draft ALCOA+ gap assessment, a trend plot template, and an excursion record template, typically within two business days. Reach out with your current LIMS, your current instrument list, and the date of your most recent data integrity audit.
