Independent and not affiliated with the FDA, MHRA, ISPE, PDA, or any agency. Get the appgoutham@madhadi.com
madhadi.comData Integrity & GxP Quality
Browse all topics → Articles Templates & Procedures Learning paths GlossaryScenariosToolsRegulatory ReferencesLearning PathsTopics About Start here
Matrix Plug-and-play starting point Data Integrity

Matrix: Data Integrity Program Maturity Scorecard

A plug-and-play scorecard that rates a data integrity program itself, not one system, against a four-stage maturity ladder across inventory, tiering, data-flow mapping, governance, periodic review, and metrics, with evidence prompts, a filled specimen, and the regulations it satisfies.

Document type: Matrix

Read and copy the template below into your own quality system. It is a generic starting point for your own internal use, provided as is, with no warranty; see the Terms and License. Adopting it does not by itself create compliance.

This is a ready-to-use scorecard for a question the per-system tools in this library do not answer: not “is this record trustworthy” but “is the program itself mature enough to keep every record trustworthy without being told to.” It is distinct from the ALCOA+ Multi-System Data Integrity Scorecard, which rolls up per-system data attribute scores, and from the Checklist: Data Integrity Culture Maturity Self-Assessment, which rates behavior and psychological safety. This scorecard rates the program’s mechanics: whether the inventory, tiering, mapping, governance, and review machinery actually run, and at what stage. Replace every <<FILL: ...>> placeholder with your own specifics, rate each dimension against the evidence you can point to, and route the completed scorecard through your normal document control. A worked filled specimen follows. This is an educational aid to adapt and verify against your own quality system, not a compliance guarantee.

Document control header

FieldEntry
Document titleData Integrity Program Maturity Scorecard
Document number<<FILL: MTX-ID, e.g. MTX-DI-011>>
Version<<FILL: version, e.g. 1.0>>
Assessment date<<FILL: date>>
Document owner<<FILL: role, e.g. Data Integrity Lead>>
Applies to<<FILL: site / enterprise scope, referencing the program scope decision>>
Refresh cycle<<FILL: e.g. annual, or after any material governance change>>

How to use this scorecard

  1. Rate each of the six program dimensions below against the four-stage ladder: Ad hoc, Defined, Managed, or Optimizing. Do not rate on impression; rate on the evidence you can point to for the period under review.
  2. Record the evidence for every rating in the evidence column. A rating with no evidence is the same unsupported claim the scorecard exists to catch elsewhere in the program.
  3. Do not average the six ratings into one headline number. Report the lowest-rated dimension alongside the average, because the weakest dimension, not the mean, is usually where the next finding comes from.
  4. Take the completed scorecard, with named actions for every dimension below Managed, into management review on the defined refresh cycle.
  5. Re-run the scorecard after any material change to governance, ownership, or the inventory scope, not only on the fixed cycle.

The maturity ladder (rating scale)

StageWhat it looks like across the program
Ad hocNo formal inventory or documented methodology; activity happens only after a finding, not on a schedule
DefinedThe inventory, tiering methodology, and governance model are documented; execution is inconsistent across systems or sites
ManagedThe inventory, tiering, data-flow mapping, and risk assessment are current, connected to change control, and reviewed on schedule with tracked metrics
OptimizingThe program anticipates risk, trends its own metrics, and applies a lesson found on one system or site to others without being told to

1. Dimension scoring

#DimensionQuestion that discriminates the stagesRatingEvidence
1System inventory coverageIs every GxP system, including the shadow estate, on a current, owned inventory, or are there systems the program would only find during an inspection?<<FILL: Ad hoc / Defined / Managed / Optimizing>><<FILL>>
2Criticality tiering consistencyIs every system tiered against a documented, evidence-based scoring method, or does tiering vary by who scored it?<<FILL>><<FILL>>
3Data-flow mappingAre the transfer points for critical reportable results mapped and assessed for data loss, or does the program only look at systems in isolation?<<FILL>><<FILL>>
4Governance and ownershipDoes every Tier 1 system have a named, active business owner and a working segregation of duties, or are roles assigned on paper with no one able to name who would catch a falsified record?<<FILL>><<FILL>>
5Periodic review executionDo audit trail review, access review, and the annual risk assessment refresh run on their defined schedule with completion evidence, or does the schedule slip without anyone tracking it?<<FILL>><<FILL>>
6Metrics and management visibilityDoes the program track and trend a small set of honest metrics at management review, or does no one outside the DI function know whether the program is improving or decaying?<<FILL>><<FILL>>

2. Scorecard summary

FieldEntry
Highest-rated dimension<<FILL>>
Lowest-rated dimension<<FILL>> (work this one first, not the average)
Dimensions at Managed or above<<FILL: count out of 6>>
Dimensions at Ad hoc<<FILL: count out of 6>>
Overall program stage (do not average; state the lowest dimension’s stage as the honest headline)<<FILL>>

3. Actions for every dimension below Managed

DimensionCurrent stageTarget stageActionOwnerTarget date
<<FILL>><<FILL>><<FILL>><<FILL>><<FILL>><<FILL>>

4. Acceptance criteria

  • Every dimension has a rating supported by named evidence, not a self-assessed impression with no reference.
  • The overall program stage reported to management is the lowest-rated dimension’s stage, not an average across dimensions.
  • Every dimension below Managed has at least one named action with an owner and a target date in section 3.
  • The scorecard was presented at management review within <<FILL: number>> days of the assessment date.
  • The scorecard is re-run on the defined refresh cycle and after any material change to governance, ownership, or inventory scope.

References

FDA, Data Integrity and Compliance With Drug CGMP: Questions and Answers (final, December 2018). MHRA, GXP Data Integrity Guidance and Definitions (Revision 1, March 2018). PIC/S PI 041-1, Good Practices for Data Management and Integrity in Regulated GMP/GDP Environments (effective July 2021). ICH Q9(R1), Quality Risk Management. ICH Q10, Pharmaceutical Quality System (management review as a continuous quality system element).

Confirm the current version and clause numbers of each reference before issue.

Revision history

VersionDateAuthorSummary of change
<<FILL: 1.0>><<FILL: date>><<FILL: author>>Initial issue.

Approvals

RoleNameSignatureDate
Author (Data Integrity Lead)<<FILL>>
Reviewer (QA)<<FILL>>
Approver (Quality Head)<<FILL>>

Filled specimen

Illustrative scorecard for a single-site manufacturer running its second annual program maturity self-assessment. Replace with your own.

Dimension scoring:

#DimensionRatingEvidence
1System inventory coverageManaged34 of 34 systems on the current inventory; the last shadow-system discovery (a stability logging spreadsheet) was found and added 5 months ago through the routine floor-walk step, not an inspection
2Criticality tiering consistencyManagedAll 34 systems scored against the documented control-element worksheet; two independent assessors re-scored 6 systems as a check and matched on all 6
3Data-flow mappingDefinedMaps exist for the 8 highest-volume reportable result types; the remaining Tier 1 result types are mapped informally, not documented
4Governance and ownershipManagedEvery Tier 1 system has a named business owner; segregation of duties confirmed for 11 of 12 Tier 1 systems, one gap open with a remediation date
5Periodic review executionDefinedAudit trail review runs for 9 of 12 Tier 1 systems on schedule; 3 systems are 2 to 4 months overdue with no escalation until this scorecard surfaced it
6Metrics and management visibilityAd hocNo standing DI metrics slide exists at management review; the DI Officer reports status verbally when asked, with no trend data

Scorecard summary: highest-rated dimensions are System inventory coverage, Criticality tiering consistency, and Governance and ownership, all Managed. Lowest-rated dimension is Metrics and management visibility, at Ad hoc. Overall program stage reported to management: Ad hoc, driven by the metrics gap, not by the operational mechanics, which are largely working.

Actions for every dimension below Managed (extract):

DimensionCurrent stageTarget stageActionOwnerTarget date
Metrics and management visibilityAd hocManagedStand up the five-metric DI dashboard (coverage, overdue Tier 1 remediation, audit trail review completion, systems found outside inventory, average age of open Tier 1 gaps) as a standing management review agenda itemDI Officer30 September 2026
Periodic review executionDefinedManagedEscalate the 3 overdue Tier 1 audit trail reviews immediately; add an automated overdue-review flag so the next slip is caught before it reaches 2 monthsQA + IT31 July 2026
Data-flow mappingDefinedManagedComplete formal data-flow maps for the remaining Tier 1 result types not yet documentedData Integrity Lead15 November 2026

The finding worth noting in this specimen: the inventory, tiering, and governance mechanics were all Managed, which would read as a healthy program on a narrower assessment. The scorecard’s insistence on reporting the lowest dimension, not the average, is what kept an invisible metrics gap from being masked by three strong dimensions next to it, and that gap is precisely the kind an inspector surfaces by asking “show me the trend” and getting a blank look instead of a chart.

Common inspection findings this scorecard prevents

  • A program with strong individual mechanics (inventory, tiering) but no visibility at management review, so leadership cannot answer “is the DI program improving” with anything but an impression.
  • A maturity claim (“we are a mature program”) with no dimension-level evidence behind it, collapsing under the first specific question.
  • An averaged maturity score that hides one badly lagging dimension behind several strong ones.
  • A program that was Managed a year ago and has quietly drifted toward Ad hoc with no one tracking the slide, because nothing measured it between assessments.

How to adapt this scorecard

  1. Set your document number, owner, and refresh cycle in the header.
  2. Score section 1 against your own program’s actual current state; do not rate a dimension without a specific piece of evidence behind it.
  3. If your organization already runs a different stage-naming convention (for example a five-stage internal model), map it to the four stages here or substitute your own, keeping the “report the lowest dimension” discipline regardless of the label set used.
  4. Connect every action in section 3 to your real CAPA, change control, or governance tracking mechanism, not only to this scorecard.
  5. Confirm every regulation in the references against the current published version before issue.
Use madhadi.com as an app Full screen, works offline, one tap from your home screen.