Independent and not affiliated with the FDA, MHRA, ISPE, PDA, or any agency. Get the appgoutham@madhadi.com
madhadi.comData Integrity & GxP Quality
Browse all topics → Articles Templates & Procedures Learning paths GlossaryScenariosToolsRegulatory ReferencesLearning PathsTopics About Start here
Matrix Plug-and-play starting point Data Integrity

Matrix: ALCOA+ Multi-System Data Integrity Scorecard and Remediation Register

A plug-and-play portfolio-level scorecard that rolls up per-system ALCOA+ assessments into one prioritized view: a nine-principle scoring matrix across every GxP system, a risk-ranked remediation register, and a management-review-ready summary, with a filled specimen and the regulations it satisfies.

Document type: Matrix

Read and copy the template below into your own quality system. It is a generic starting point for your own internal use, provided as is, with no warranty; see the Terms and License. Adopting it does not by itself create compliance.

This is a ready-to-use portfolio scorecard. It does not replace the per-system ALCOA+ self-assessment checklist, which scores one system against all nine principles in detail. This matrix takes the output of every completed self-assessment and rolls it up into one view across the whole GxP system inventory, so gaps can be risk-ranked and prioritized against each other rather than managed one binder at a time. Replace every <<FILL: ...>> placeholder with your own specifics. A worked filled specimen follows the template. Verify each cited regulation against the current source before you rely on it.

Document control header

FieldEntry
Document titleALCOA+ Multi-System Data Integrity Scorecard and Remediation Register
Document number<<FILL: MTX-ID, e.g. MTX-DI-004>>
Version<<FILL: version, e.g. 1.0>>
Effective date<<FILL: effective date>>
Document owner<<FILL: role, e.g. Data Integrity Lead>>
Applies to<<FILL: sites / system inventory in scope>>
Refresh cycle<<FILL: e.g. quarterly rollup, immediately after any new per-system assessment>>

Purpose

A single system’s ALCOA+ self-assessment tells you whether that system is trustworthy. It does not tell you whether the data integrity program as a whole is improving, which systems carry the highest residual risk, or whether the same principle keeps failing across many systems, which would point to a program-level root cause rather than a series of unrelated local ones. This scorecard closes that gap: it is the artifact a data integrity lead brings to management review to answer “where do we actually stand.”

How to use this scorecard

  1. Populate one row per GxP system from its most recent completed ALCOA+ self-assessment checklist. Do not score a system here that has not been individually assessed; this matrix aggregates, it does not substitute.
  2. Mark each of the nine principle columns OK (no open gap), Gap (open gap, any risk level), or N/A, matching the underlying assessment.
  3. Compute the system risk rank from the highest-risk open gap on that system, not an average across principles; one high-risk gap makes the system high risk regardless of how many other principles pass.
  4. Carry every open gap into the remediation register (section 2) with an owner and due date.
  5. Refresh on the defined cycle and immediately whenever a new or updated per-system assessment closes.
  6. Present the summary (section 3) at management review.

1. Portfolio scoring matrix

OK = no open gap. Gap = open gap (any risk level, detailed in section 2). N/A = principle does not apply to this system’s record type.

SystemAttLegConOriAccCmpCnsEndAvaSystem risk rankLast assessed
<<FILL: system name / ID>><<FILL>><<FILL>><<FILL>><<FILL>><<FILL>><<FILL>><<FILL>><<FILL>><<FILL>><<FILL: H/M/L>><<FILL: date>>

2. Remediation register

One row per open gap, sourced from the individual system assessments. This is the register that turns the matrix into action rather than a status report.

RefSystemPrinciple(s)FindingRiskOwnerRemediation actionDue dateStatus
<<FILL: G1>><<FILL>><<FILL>><<FILL>><<FILL: H/M/L>><<FILL>><<FILL>><<FILL>><<FILL: Open / In progress / Closed>>

3. Management review summary

MetricThis periodPrior periodTrend
Systems assessed / total in inventory<<FILL>><<FILL>><<FILL>>
Systems with an open high-risk gap<<FILL>><<FILL>><<FILL>>
Total open gaps<<FILL>><<FILL>><<FILL>>
Gaps closed this period<<FILL>><<FILL>><<FILL>>
Most frequently failing principle across the portfolio<<FILL>><<FILL>><<FILL>>
Overdue remediation actions<<FILL>><<FILL>><<FILL>>

Program-level pattern check. If the same principle recurs as a gap across multiple, otherwise unrelated systems, treat it as a program-level finding, not a coincidence of several local ones. A recurring Attributable gap across three lab systems usually means the site’s account-provisioning process is the actual root cause, and the fix belongs at that level, not as three separate local CAPAs that each leave the process gap in place. Record any such pattern here and route it to a program-level CAPA.

4. Acceptance criteria

  • Every system in the current GxP inventory has a row, or its absence is explained (for example, newly commissioned, assessment scheduled).
  • Every Gap marked in section 1 has a corresponding entry in the remediation register with an owner, a risk rating, and a due date.
  • The system risk rank reflects the highest-risk open gap on that system, not an averaged score.
  • Any principle recurring as a gap across multiple systems is flagged as a program-level pattern, not left as isolated line items.
  • The summary in section 3 was presented at management review within <<FILL: number>> days of the refresh.

References

21 CFR Part 211 (drug CGMP: 211.68, 211.180, 211.188, 211.194). 21 CFR Part 11 (electronic records and signatures). EU GMP Annex 11 (computerized systems). ICH Q9, Quality Risk Management (risk ranking). ICH Q10, Pharmaceutical Quality System (management review as a continuous quality system element). MHRA “GXP Data Integrity Guidance and Definitions” (March 2018). PIC/S PI 041 (good practices for data management and integrity).

Confirm the current version and clause numbers of each reference before issue.

Revision history

VersionDateAuthorSummary of change
<<FILL: 1.0>><<FILL: date>><<FILL: author>>Initial issue.

Approvals

RoleNameSignatureDate
Author (Data Integrity Lead)<<FILL>>
Reviewer (QA)<<FILL>>
Approver (Quality Head)<<FILL>>

Filled specimen

Illustrative rollup across three systems. Replace with your own.

Portfolio scoring matrix:

SystemAttLegConOriAccCmpCnsEndAvaSystem risk rankLast assessed
LIMS (release testing)OKOKGapOKOKOKOKOKOKMedium12 Jun 2026
CDS, HPLC-04 to HPLC-09GapOKOKGapOKOKOKGapOKHigh12 Jun 2026
Environmental monitoring spreadsheetGapOKGapGapGapGapOKGapOKHigh05 Jul 2026

Remediation register (extract):

RefSystemPrinciple(s)FindingRiskOwnerRemediation actionDue dateStatus
G1CDSAttributableShared Windows login on CDS workstation clusterHighIT + Lab LeadProvision named accounts, disable shared login, retrain30 Jul 2026In progress
G2CDSOriginal, EnduringOnly PDF printouts retained; vendor binary format has no migration planHighSystem Owner + ITConfigure raw-data archive; define format migration path in decommissioning plan15 Sep 2026Open
G3EM spreadsheetAttributable, Original, Contemporaneous, Accurate, Complete, EnduringUncontrolled spreadsheet: no named-user login, unlocked formulas, no audit trail, no archiveHighQA + AutomationReplace with validated EM data capture, or lock and version-control the interim spreadsheet under infrastructure and spreadsheet validation30 Nov 2026Open
G4LIMSContemporaneousTimestamp clustering observed on second-shift entries during periodic reviewMediumQAInvestigate shift practice; reinforce real-time entry expectation in training31 Aug 2026Open

Management review summary:

MetricThis periodPrior periodTrend
Systems assessed / total in inventory3 / 33 / 3Stable
Systems with an open high-risk gap21Worsening
Total open gaps46Improving
Gaps closed this period32Improving
Most frequently failing principle across the portfolioAttributable (2 of 3 systems)Enduring (2 of 3 systems)Shifted
Overdue remediation actions01Improving

Program-level pattern check: Attributable failed on both the CDS and the EM spreadsheet this period, both traced independently to the same root cause, no named-account provisioning step existed in the onboarding process for lab-floor instrument accounts. Rather than close G1 and part of G3 as two unrelated local fixes, a program-level CAPA was opened against the account-provisioning procedure itself, referenced from both G1 and G3.

This is the difference a rollup makes: read individually, G1 and G3’s attribution gaps look like two separate instrument problems. Read together, they point at one broken process behind both of them, and only the portfolio view surfaces that.

Common inspection findings this scorecard prevents

  • A site with several completed per-system ALCOA+ assessments but no view of the portfolio, so a recurring gap across systems is never connected to its shared root cause.
  • Remediation tracked informally per system, with no single register an inspector or a management review can pull to see total open risk.
  • A data integrity program that can produce individual checklists but cannot answer “how many high-risk gaps are currently open across the site” without a manual count.
  • Gaps closed locally that reappear on the next system because the underlying process cause was never fixed at the program level.

How to adapt this scorecard

  1. Set your document number, owner, and refresh cycle in the header.
  2. Populate section 1 from your actual GxP system inventory; do not hand-score a system here without a completed underlying assessment.
  3. Set your own system risk-ranking rule in section 1 if you use a different scheme than “highest single gap sets the rank.”
  4. Feed every remediation action into your real deviation or CAPA system in addition to the register here, so remediation is tracked to effectiveness, not just logged.
  5. Confirm every regulation in the references against the current published version before issue.
Use madhadi.com as an app Full screen, works offline, one tap from your home screen.