Independent and not affiliated with the FDA, MHRA, ISPE, PDA, or any agency. Get the appgoutham@madhadi.com
madhadi.comData Integrity & GxP Quality
Browse all topics → Articles Templates & Procedures Learning paths GlossaryScenariosToolsRegulatory ReferencesLearning PathsTopics About Start here
Checklist Plug-and-play starting point Data Integrity

Checklist: Data Integrity Gap Assessment Evidence Collection and Interview Guide

A plug-and-play field guide for running the evidence-gathering phase of a data integrity gap assessment: a pre-read document pull list, a structured interview question bank by role, floor-observation prompts mapped to the five layers, and an evidence log with pass/fail/NA, plus a filled specimen.

Document type: Checklist

Read and copy the template below into your own quality system. It is a generic starting point for your own internal use, provided as is, with no warranty; see the Terms and License. Adopting it does not by itself create compliance.

This is a ready-to-use field guide for running the evidence-gathering steps of a data integrity gap assessment, the pre-read, the live configuration walkthrough, the interviews, and the floor observation, before anything gets scored. It is not the scoring tool: for the per-system control scoring see the Data Integrity Risk and Gap Assessment (Per System), and for finding classification see the Data Integrity Gap Assessment Finding Scoring and Classification Worksheet. This document exists so that the evidence going into those tools is collected consistently, by whoever is running the floor day, rather than reconstructed from memory afterward. Replace every <<FILL: ...>> placeholder with your own specifics. A worked filled specimen follows. This is educational structure to adapt, not legal or regulatory advice.

Document control header

FieldEntry
Document titleData Integrity Gap Assessment Evidence Collection and Interview Guide, for <<FILL: SYSTEM NAME / ID>>
Document number<<FILL: reference, e.g. DI-EVD-2026-01>>
Assessment date(s)<<FILL>>
Assessor(s)<<FILL>>
Parent charter reference<<FILL: charter / scope document number>>

1. Purpose

This guide structures the evidence-gathering phase of a data integrity gap assessment so that pre-read, configuration review, interviews, and floor observation are done consistently across systems and assessors, and so the evidence captured is specific enough to feed directly into scoring, not a general impression written up later from memory.

2. Pre-read document pull list

Pull and read every item below before floor time starts, so the day is spent verifying, not orienting.

#DocumentObtained (Y/N)Reviewed (Y/N)Notes
1DI policy<<FILL>><<FILL>><<FILL>>
2Audit trail review procedure and recent review records<<FILL>><<FILL>><<FILL>>
3Access management procedure and current user list<<FILL>><<FILL>><<FILL>>
4Validation summary report for the system<<FILL>><<FILL>><<FILL>>
5Backup and recovery procedure and recent restore-test record<<FILL>><<FILL>><<FILL>>
6Prior gap assessment, 483, or warning letter findings touching this system<<FILL>><<FILL>><<FILL>>
7Training records for the staff to be interviewed<<FILL>><<FILL>><<FILL>>

3. Live configuration walkthrough, evidence to capture

Capture the evidence itself (a screenshot, an exported list, a printed setting), not a description of it. This maps to Layer 1 and Layer 2 of the parent methodology.

#ItemEvidence captured (Y/N/Partial)Where filed
1Audit trail configuration screen, showing which event types are captured<<FILL>><<FILL>>
2Full user and role list export<<FILL>><<FILL>>
3Password policy and session timeout settings<<FILL>><<FILL>>
4System clock setting and time-source configuration<<FILL>><<FILL>>
5A sample of records showing the record structure the audit trail actually captures (not just that it is “on”)<<FILL>><<FILL>>

4. Structured interview question bank, by role

Ask open questions first and let the answer lead; use the prompts only to redirect if the conversation stalls. Record answers in the interviewee’s own words where a discrepancy with the documented procedure appears.

4.1 System owner

QuestionLayer it informsNotes
Walk me through how you’d know today if someone changed a result without a valid reason.Configuration, procedural<<FILL>>
Who currently holds administrative rights on this system, and why each of them?Configuration<<FILL>>
When was the audit trail last reviewed, and what did the reviewer actually look at?Procedural, work practice<<FILL>>
Describe the last time someone left the team. How long did their account stay active?Configuration, procedural<<FILL>>

4.2 Analyst / operator

QuestionLayer it informsNotes
Walk me through what you do from the moment a result comes off the instrument to the moment it’s in the record.Work practice<<FILL>>
Has anyone ever asked you to rerun something and just keep the passing result? What did you do?Work practice, culture<<FILL>>
What happens if you make a mistake entering a result? Show me, don’t just tell me.Work practice<<FILL>>
If you saw something that felt wrong on this system, who would you tell, and what do you think would happen?Culture<<FILL>>

4.3 IT / system administrator

QuestionLayer it informsNotes
How is this system’s clock synchronized, and how do you know it’s still in sync today?Physical, configuration<<FILL>>
When was the last restore test, and what was the result?Physical<<FILL>>
Can any administrator, including you, disable or edit the audit trail? Show me the control that would stop that.Configuration<<FILL>>

4.4 Quality Assurance / leadership

QuestionLayer it informsNotes
How many data integrity findings has this area had in the last two years, and what changed after each one?Culture<<FILL>>
If a DI concern were raised confidentially tomorrow, what is the actual process, step by step?Culture<<FILL>>
Where does data integrity performance get reported at management review, and what does the trend look like?Culture, procedural<<FILL>>

5. Floor observation prompts

Observe real operations, ideally across more than one shift. Record what actually happens, not what the SOP says should happen.

#Observation pointWhat to look forRecorded observation
1Login practiceIndividual accounts used every time, or shared credentials left open<<FILL>>
2Data entryContemporaneous direct entry, or informal notes transcribed later<<FILL>>
3CorrectionsDocumented correction method with prior value preserved, or delete-and-retype<<FILL>>
4Handling of an unexpected or out-of-trend resultInvestigation path followed, or a quiet rerun<<FILL>>
5Printed or paper material at the workstationControlled copies only, no obsolete or uncontrolled printouts in use<<FILL>>

6. Evidence completeness log

Complete before scoring begins. A system with evidence gaps below is not ready to be scored; go back and close the gap or record why it cannot be closed within the assessment window.

SectionComplete (Y/N)Outstanding items
Pre-read<<FILL>><<FILL>>
Configuration walkthrough<<FILL>><<FILL>>
Interviews<<FILL>><<FILL>>
Floor observation<<FILL>><<FILL>>

7. Acceptance criteria

  • Every pre-read document is marked obtained and reviewed, or its absence is explicitly noted as a gap in its own right.
  • Every configuration item in section 3 has captured evidence, not a description of the setting relayed secondhand.
  • At least one interview from each applicable role in section 4 was conducted for the system, with answers recorded in enough detail to support a later finding if one is written.
  • Floor observation covers more than one shift where the system operates across shifts.
  • The evidence completeness log in section 6 shows no unresolved gap before the system moves to scoring.

8. References

FDA, Data Integrity and Compliance With Drug CGMP: Questions and Answers (final, December 2018). MHRA, GXP Data Integrity Guidance and Definitions (Revision 1, March 2018). PIC/S PI 041-1, Good Practices for Data Management and Integrity in Regulated GMP/GDP Environments (effective July 2021). 21 CFR Part 11; EU GMP Annex 11.

Confirm the current version of each reference before issue.

9. Revision history

VersionDateAuthorSummary of change
<<FILL: 1.0>><<FILL: date>><<FILL: author>>Initial issue.

Filled specimen

The following shows an excerpt of this guide completed for a chromatography data system used for release testing, so you can see the level of specificity expected. The company, system, and answers are illustrative; replace them with your own.

Pre-read (extract): DI policy obtained and reviewed; audit trail review procedure obtained, reviewed, records for the last 6 months pulled; prior assessment: none, first cycle for this system.

Configuration walkthrough (extract): audit trail configuration screenshot captured, shows manual integrations logged but method-change events not separately flagged, filed as CDS-EVD-014; user and role list export shows 22 active accounts, 3 with administrative rights, filed as CDS-EVD-015.

Interview extract, system owner: “Honestly, I’d notice a change in a result because the analyst would flag it to me, we don’t have anything automatic that would catch a re-integration that wasn’t supposed to happen unless someone reviews the trail.” Recorded verbatim; flagged as a candidate procedural/configuration gap, carried forward to scoring.

Interview extract, analyst: asked about reruns, answered “if it fails I document why and rerun under the OOS procedure, I’ve never been asked to just keep a passing number.” Recorded as a positive work-practice observation with the analyst’s name and date.

Floor observation (extract): two of four workstations observed had analysts logged in under their own accounts; one workstation had a session left open and unattended for approximately 12 minutes during a break, recorded as an observation for the work-practice layer, not yet an audit trail integrity issue but a candidate finding on session-timeout enforcement.

Evidence completeness log: pre-read complete, configuration walkthrough complete, interviews complete for system owner, two analysts, and IT; floor observation covered day shift only, night shift observation outstanding and carried forward to the next visit before this system is scored as complete.

Common inspection findings this guide prevents

  • A configuration claim taken from a document instead of the live system, because no evidence was actually captured during the walkthrough.
  • Interview answers paraphrased loosely after the fact, losing the specific wording that would have flagged a gap.
  • Floor observation limited to a single, convenient shift, missing a work-practice gap that only shows up on the shift the assessor never visited.
  • A system scored before its evidence was actually complete, because there was no log forcing that check before scoring began.

How to adapt this guide

  1. Set the system name, assessor, and parent charter reference in the header.
  2. Add or remove interview roles in section 4 to match the actual roles operating the system, a clinical system needs a data manager and a site monitor, not only an analyst.
  3. Extend the floor observation prompts in section 5 for system-specific risks, for example reprocessing behavior for a CDS or override logging for an MES.
  4. Do not move a system to scoring until section 6 shows no unresolved evidence gap.
  5. Confirm every regulation in section 8 against the current published version before issue.
Use madhadi.com as an app Full screen, works offline, one tap from your home screen.