This is a ready-to-use scorecard for a question the per-system tools in this library do not answer: not “is this record trustworthy” but “is the program itself mature enough to keep every record trustworthy without being told to.” It is distinct from the ALCOA+ Multi-System Data Integrity Scorecard, which rolls up per-system data attribute scores, and from the Checklist: Data Integrity Culture Maturity Self-Assessment, which rates behavior and psychological safety. This scorecard rates the program’s mechanics: whether the inventory, tiering, mapping, governance, and review machinery actually run, and at what stage. Replace every <<FILL: ...>> placeholder with your own specifics, rate each dimension against the evidence you can point to, and route the completed scorecard through your normal document control. A worked filled specimen follows. This is an educational aid to adapt and verify against your own quality system, not a compliance guarantee.
How to use this scorecard
- Rate each of the six program dimensions below against the four-stage ladder: Ad hoc, Defined, Managed, or Optimizing. Do not rate on impression; rate on the evidence you can point to for the period under review.
- Record the evidence for every rating in the evidence column. A rating with no evidence is the same unsupported claim the scorecard exists to catch elsewhere in the program.
- Do not average the six ratings into one headline number. Report the lowest-rated dimension alongside the average, because the weakest dimension, not the mean, is usually where the next finding comes from.
- Take the completed scorecard, with named actions for every dimension below Managed, into management review on the defined refresh cycle.
- Re-run the scorecard after any material change to governance, ownership, or the inventory scope, not only on the fixed cycle.
The maturity ladder (rating scale)
1. Dimension scoring
2. Scorecard summary
3. Actions for every dimension below Managed
4. Acceptance criteria
- Every dimension has a rating supported by named evidence, not a self-assessed impression with no reference.
- The overall program stage reported to management is the lowest-rated dimension’s stage, not an average across dimensions.
- Every dimension below Managed has at least one named action with an owner and a target date in section 3.
- The scorecard was presented at management review within
<<FILL: number>> days of the assessment date.
- The scorecard is re-run on the defined refresh cycle and after any material change to governance, ownership, or inventory scope.
References
FDA, Data Integrity and Compliance With Drug CGMP: Questions and Answers (final, December 2018).
MHRA, GXP Data Integrity Guidance and Definitions (Revision 1, March 2018).
PIC/S PI 041-1, Good Practices for Data Management and Integrity in Regulated GMP/GDP Environments (effective July 2021).
ICH Q9(R1), Quality Risk Management.
ICH Q10, Pharmaceutical Quality System (management review as a continuous quality system element).
Confirm the current version and clause numbers of each reference before issue.
Revision history
Approvals
Filled specimen
Illustrative scorecard for a single-site manufacturer running its second annual program maturity self-assessment. Replace with your own.
Dimension scoring:
Scorecard summary: highest-rated dimensions are System inventory coverage, Criticality tiering consistency, and Governance and ownership, all Managed. Lowest-rated dimension is Metrics and management visibility, at Ad hoc. Overall program stage reported to management: Ad hoc, driven by the metrics gap, not by the operational mechanics, which are largely working.
Actions for every dimension below Managed (extract):
The finding worth noting in this specimen: the inventory, tiering, and governance mechanics were all Managed, which would read as a healthy program on a narrower assessment. The scorecard’s insistence on reporting the lowest dimension, not the average, is what kept an invisible metrics gap from being masked by three strong dimensions next to it, and that gap is precisely the kind an inspector surfaces by asking “show me the trend” and getting a blank look instead of a chart.
Common inspection findings this scorecard prevents
- A program with strong individual mechanics (inventory, tiering) but no visibility at management review, so leadership cannot answer “is the DI program improving” with anything but an impression.
- A maturity claim (“we are a mature program”) with no dimension-level evidence behind it, collapsing under the first specific question.
- An averaged maturity score that hides one badly lagging dimension behind several strong ones.
- A program that was Managed a year ago and has quietly drifted toward Ad hoc with no one tracking the slide, because nothing measured it between assessments.
How to adapt this scorecard
- Set your document number, owner, and refresh cycle in the header.
- Score section 1 against your own program’s actual current state; do not rate a dimension without a specific piece of evidence behind it.
- If your organization already runs a different stage-naming convention (for example a five-stage internal model), map it to the four stages here or substitute your own, keeping the “report the lowest dimension” discipline regardless of the label set used.
- Connect every action in section 3 to your real CAPA, change control, or governance tracking mechanism, not only to this scorecard.
- Confirm every regulation in the references against the current published version before issue.