This is a ready-to-use failure mode and effects analysis (FMEA) for the interfaces between GxP systems, the transfer points where the cleanest individual systems still lose data integrity. Interfaces are where a mistyped result, a silently dropped transfer, or a disagreement over which copy is authoritative does its damage. Replace every <<FILL: ...>> placeholder, adapt the scoring scales to your quality risk management SOP, and route the completed assessment through your normal approval. A filled specimen follows. Confirm each cited regulation against the current source before you rely on it.
Control header
| Field | Entry |
|---|---|
| Document title | GxP System Interface Data Integrity Risk Assessment |
| Document number | <<FILL: RA-ID, e.g. RA-DI-009>> |
| Version | <<FILL>> |
| Scope | <<FILL: the interfaces / data flows assessed>> |
| Facilitator | <<FILL: name / role>> |
| Team | <<FILL: SMEs, QA, IT, validation>> |
| Date | <<FILL>> |
1. Methodology
This assessment uses FMEA. For each interface, the team identifies the ways the data transfer can fail (failure modes), the effect on data integrity and product quality, and the causes, then scores severity, occurrence, and detection to produce a risk priority number (RPN = Severity x Occurrence x Detection). Failure modes at or above the action threshold receive mitigations, and the residual risk after mitigation is recorded. The approach follows quality risk management principles (ICH Q9).
2. Scoring scales
Adapt these to your QRM SOP; keep them consistent across assessments so RPNs are comparable.
Severity (impact on data integrity / product / patient)
| Score | Meaning |
|---|---|
| 5 | Wrong data reaches a release or safety decision undetected; patient or trial impact. |
| 4 | Wrong or missing data reaches a GMP record; likely detected only in investigation. |
| 3 | Data integrity affected but caught before a decision. |
| 2 | Minor; local, self-correcting. |
| 1 | No GMP or data-integrity impact. |
Occurrence (how likely the failure is)
| Score | Meaning |
|---|---|
| 5 | Expected routinely (for example manual retyping every batch). |
| 4 | Likely. |
| 3 | Occasional. |
| 2 | Unlikely. |
| 1 | Remote. |
Detection (how likely the current controls catch it before harm)
| Score | Meaning |
|---|---|
| 5 | Almost never detected before use. |
| 4 | Poor detection. |
| 3 | Moderate detection. |
| 2 | Good detection (automated verification). |
| 1 | Detected almost certainly at transfer. |
Action threshold
<<FILL: e.g. RPN >= 36, or any Severity 5 with Detection >= 3>>. Document the rationale for the threshold. A high-severity, low-detection failure warrants action even below a numeric RPN cutoff.
3. Assessment table
| Interface / data flow | Failure mode | Effect on data integrity | Cause | S | O | D | RPN | Above threshold? |
|---|---|---|---|---|---|---|---|---|
<<FILL: e.g. CDS result to LIMS>> | Manual retype introduces a wrong value | Reported result differs from raw data; OOS logic sees the typed number | No validated interface; copy-paste step | <<FILL>> | <<FILL>> | <<FILL>> | <<FILL>> | <<FILL>> |
<<FILL: e.g. SCADA to historian>> | Compression drops a limit-crossing value | Archived trace no longer represents what happened | Deadband set for storage, not qualified | <<FILL>> | <<FILL>> | <<FILL>> | <<FILL>> | <<FILL>> |
<<FILL: e.g. scale to MES>> | Partial or failed transfer accepted silently | Missing or default value recorded as real | No failed-transfer detection | <<FILL>> | <<FILL>> | <<FILL>> | <<FILL>> | <<FILL>> |
<<FILL: e.g. LIMS to ERP>> | Two systems disagree on the released value | Ambiguity over the authoritative copy | Original/copy not defined | <<FILL>> | <<FILL>> | <<FILL>> | <<FILL>> | <<FILL>> |
<<FILL>> | <<FILL>> | <<FILL>> | <<FILL>> | <<FILL>> | <<FILL>> | <<FILL>> | <<FILL>> | <<FILL>> |
4. Mitigations
For each failure mode above the threshold, define the mitigation, the owner, and the target date.
| Failure mode | Mitigation | Owner | Target date |
|---|---|---|---|
| Manual retype introduces a wrong value | Replace with a validated electronic interface with checksum/record-count verification; until then require documented independent second-person verification of each transferred value (Annex 11 accuracy check) | <<FILL>> | <<FILL>> |
| Compression drops a limit-crossing value | Qualify the deadband so no value crossing an alert or action limit is dropped; document the setting as a validated parameter | <<FILL>> | <<FILL>> |
| Partial or failed transfer accepted silently | Configure and test detection: a failed or partial transfer raises an alarm or hold, never a default value | <<FILL>> | <<FILL>> |
| Two systems disagree on the released value | Define the original (first-capture) and the copy for every shared value in the system inventory; reconcile the copy against the original | <<FILL>> | <<FILL>> |
5. Residual risk
| Failure mode | RPN before | RPN after mitigation | Residual risk acceptable? | Justification |
|---|---|---|---|---|
<<FILL>> | <<FILL>> | <<FILL>> | <<FILL>> | <<FILL>> |
Residual risk is acceptable when the mitigated RPN is below the threshold and any remaining Severity-5 failure has a strong detection control. Document any residual risk that is accepted rather than reduced.
6. Acceptance criteria for the assessment
- Every GxP interface in scope has at least one failure mode assessed.
- Severity, occurrence, and detection are scored against the defined scales, consistently.
- Every failure mode above the threshold has an owned, dated mitigation.
- Residual risk is recorded and either acceptable or explicitly accepted with justification.
- The assessment is approved and linked to the affected validation and change-control records.
7. Approvals
| Role | Name | Signature | Date |
|---|---|---|---|
| Facilitator | <<FILL>> | ||
| SME | <<FILL>> | ||
| QA | <<FILL>> |
8. References
EU GMP Annex 11 (computerised systems), accuracy-check and data-transfer expectations. ICH Q9 (quality risk management) for the FMEA methodology. 21 CFR Part 11 and 211.68 for record accuracy and input/output checks. Related reading: GxP manufacturing and laboratory systems, data lifecycle and metadata.
Confirm the current version and clause numbers of each reference before issue.
9. Revision history
| Version | Date | Author | Summary of change |
|---|---|---|---|
<<FILL: 1.0>> | <<FILL>> | <<FILL>> | Initial issue. |
Filled specimen
The following shows one row assessed and mitigated for an example CDS-to-LIMS interface, so you can see how the scoring and mitigation read. The values are illustrative.
| Interface | Failure mode | Effect | Cause | S | O | D | RPN | Above threshold? |
|---|---|---|---|---|---|---|---|---|
| CDS result manually typed into LIMS | Wrong assay value entered | LIMS holds a value that differs from the CDS raw data; the OOS check runs on the typed number, not the real result | No validated interface; analyst copy-pastes | 5 | 4 | 4 | 80 | Yes |
Mitigation: build a validated electronic interface from the CDS to the LIMS with a record-count and value check; until it is live, require a second analyst to independently verify each transferred value against the CDS and initial the LIMS record. After mitigation the interface removes the manual step (Occurrence drops to 2, Detection to 1), giving a residual RPN of 10, below the threshold. The interim second-person check is documented as the control until the interface is validated. The point the specimen makes: an RPN of 80 driven by high severity and poor detection is exactly the kind of quiet interface risk that only surfaces in an investigation, which is why interfaces are assessed explicitly rather than assumed clean.
Common inspection findings this assessment prevents
- Manual data transfers between GxP systems with no verification and no risk assessment acknowledging them.
- Historian compression set for storage convenience, quietly smoothing out an excursion.
- Failed or partial transfers accepted as valid data with no detection.
- Two systems holding the same value with no defined authoritative copy.
- Interfaces treated as “IT plumbing” outside the data-integrity program.
How to adapt this assessment
- Set your document number and list every GxP interface in scope.
- Align the scoring scales and action threshold to your QRM SOP so RPNs compare across assessments.
- Add your real interfaces and their specific failure modes; do not rely on the generic examples alone.
- Assign owned, dated mitigations for everything above the threshold and track them to closure.
- Confirm every regulation in section 8 against the current published version before issue.