Independent and not affiliated with the FDA, MHRA, ISPE, PDA, or any agency. Get the appgoutham@madhadi.com
madhadi.comData Integrity & GxP Quality
Browse all topics → Articles Templates & Procedures Learning paths GlossaryScenariosToolsRegulatory ReferencesLearning PathsTopics About Start here
Checklist Plug-and-play starting point Data Integrity

Checklist: Data Integrity Culture Maturity Self-Assessment

A scored self-assessment that places a site on the reactive-to-generative culture ladder across the behaviors that drive or prevent data integrity failures, with evidence prompts, a filled specimen, and the regulatory basis for treating culture as assessable.

Document type: Checklist

Read and copy the template below into your own quality system. It is a generic starting point for your own internal use, provided as is, with no warranty; see the Terms and License. Adopting it does not by itself create compliance.

This is a ready-to-use self-assessment. Replace every <<FILL: ...>> placeholder with your own specifics, run it as a facilitated exercise rather than a solo tick-box, and require a piece of evidence for every rating so the score is defensible rather than aspirational. A worked filled specimen follows the template. This is an educational aid to adapt and verify against your own quality system, not a compliance guarantee.

How to use this assessment

  1. Rate each dimension against the four-stage ladder (Reactive, Compliant, Proactive, Generative), not on a feeling but on the observable evidence you can point to.
  2. Record the evidence in the evidence column. A rating with no evidence is the same empty claim as a culture slide deck, and it is the first thing an auditor will test.
  3. Do not average the scores for a headline number. Work the lowest rows, because the lowest dimension, not the average, is usually where the next failure comes from.
  4. Take the completed assessment, with actions for the weak rows, into management review on a defined cadence.

The maturity ladder (rating scale)

StageWhat it looks like
ReactiveData integrity work happens only after a finding; “we fixed what the inspector cited”
CompliantControls and procedures exist; reviews are scheduled but can be rubber-stamped
ProactiveBehavior is monitored, reporting is rewarded, rising self-reported concerns are seen as good
GenerativeIntegrity is assumed; people stop bad practices without being told and are thanked for it

Assessment dimensions

Rate each dimension R / C / P / G and record the evidence.

#DimensionQuestion that discriminates the stagesRatingEvidence
1Reporting and psychological safetyWhen did someone last bring leadership bad news before it became a crisis, and what happened to them?<<FILL: R/C/P/G>><<FILL: evidence>>
2Investigation depthDoes “retrain the analyst” still appear as the corrective action for deliberate acts?<<FILL>><<FILL>>
3Metric plausibilityIs the OOS rate plausible for the volume, is the deviation severity mix realistic, do results cluster just inside limits?<<FILL>><<FILL>>
4Leadership behavior under pressureHow did leadership behave the last time a borderline result met a shipment deadline?<<FILL>><<FILL>>
5Bench practice versus SOPIs there a routine program that watches work at the point of performance, or only document review?<<FILL>><<FILL>>
6Just-culture consistencyAre honest reporters and deliberate falsifiers treated differently, by a documented method?<<FILL>><<FILL>>
7Confidential reporting pathwayDoes a no-retaliation channel exist, is it used, and do reporters hear the outcome?<<FILL>><<FILL>>
8Audit trail review ownershipIs a single named person accountable for each audit trail review, and does the review produce real discussion items?<<FILL>><<FILL>>
9Incentive and metric designDo any individual or team scorecards reward low deviation counts or fast release without a paired data-reliability measure?<<FILL>><<FILL>>
10Remediation follow-throughAfter the last finding, was the behavioral rebuild resourced, or only the technical hardening?<<FILL>><<FILL>>

Acceptance criteria

This assessment is complete and usable when all of the following are true:

  • Every dimension carries a rating and a specific piece of evidence, not an assertion.
  • No dimension rated Proactive or Generative rests on evidence that is only a policy statement or a training record.
  • Every dimension rated Reactive or Compliant has a named owner and a dated action.
  • The result is reviewed by quality leadership and recorded, and the weak dimensions carry into the next management review.

References

FDA guidance, Data Integrity and Compliance With Drug CGMP: Questions and Answers (December 2018), on management responsibility for a work environment that enables data integrity. MHRA GXP Data Integrity Guidance and Definitions (2018), on the behavioral dimension of data governance. PIC/S PI 041, Good Practices for Data Management and Integrity in Regulated GMP/GDP Environments, on data governance and management’s role. ICH Q10, Pharmaceutical Quality System, on management responsibility and continual improvement. WHO guidance on good data and record management practices, on a culture that supports integrity.

Confirm the current version of each reference before you rely on it.

Revision history

VersionDateAuthorSummary of change
<<FILL: 1.0>><<FILL: date>><<FILL: author>>Initial issue.

Approvals

RoleNameSignatureDate
Facilitator<<FILL>>
Quality Head<<FILL>>

Filled specimen

The following shows the assessment completed for an illustrative site. The ratings and evidence are examples; replace them with your own.

#DimensionRatingEvidence
1Reporting and psychological safetyProactiveSelf-reported DI concerns rose from 2 to 11 per quarter after the confidential channel launched; each was resolved with a recorded outcome
2Investigation depthCompliantInvestigations are thorough, but “retrain” appeared as the sole CAPA on 3 of 9 deliberate-act events last year
3Metric plausibilityProactiveOOS rate (about 1.8 percent) tracks volume; deviation mix included 4 majors last quarter; no clustering just inside the lower limit
4Leadership behavior under pressureCompliantLeaders verbally support investigations, but the last borderline release before a clinical shipment was closed in the minimum time
5Bench practice versus SOPReactiveNo routine bench-observation program; last SOP-to-practice comparison was during the prior inspection
6Just-culture consistencyCompliantA just-culture procedure exists but was applied inconsistently in two recent events
7Confidential reporting pathwayProactiveChannel exists, received 11 reports last quarter, reporters received written follow-up
8Audit trail review ownershipCompliantEach review has one accountable name, but reviews rarely surface discussion items, suggesting review by rote
9Incentive and metric designReactiveThe lab scorecard still rewards a low deviation count per analyst
10Remediation follow-throughReactiveAfter the last finding, systems were hardened in six weeks; no behavioral or cultural action was resourced

Reading this specimen the way a quality leader should: the average is somewhere around Compliant, but the story is in rows 5, 9, and 10. A scorecard that rewards low deviation counts (row 9) actively discourages the reporting that row 1 says is improving, and the absence of bench observation (row 5) means normalized deviance would be invisible. Those three rows, not the average, are the work.

Common inspection findings this assessment surfaces early

  • Culture “addressed” with an annual training slide and no behavioral metrics.
  • A confidential reporting channel that has never received a report, presented as proof of a clean site.
  • Audit trail review that is signed but produces nothing, indicating review by rote.
  • “Retrain the analyst” as the recurring corrective action for deliberate acts.
  • A suspiciously low OOS or deviation-severity profile that no one has tested for plausibility.
  • Remediation that closed technical gaps only, with the behavioral root cause left untouched, setting up a recurrence.

How to adapt this assessment

  1. Add or remove dimensions to match your operation; keep each dimension observable and evidence-backed.
  2. Set the cadence (annual is common, with an out-of-cycle run after a serious finding).
  3. Decide who facilitates. An assessment run only by the people being assessed tends to score high; a cross-functional or independent facilitator is more honest.
  4. Feed the weak rows into real actions with owners and dates, then re-assess those rows at the next cycle rather than re-scoring everything from scratch.
  5. Confirm each reference in the References section against its current published version before issue.
Use madhadi.com as an app Full screen, works offline, one tap from your home screen.