Independent and not affiliated with the FDA, MHRA, ISPE, PDA, or any agency. Get the appgoutham@madhadi.com
madhadi.comData Integrity & GxP Quality
Browse all topics → Articles Templates & Procedures Learning paths GlossaryScenariosToolsRegulatory ReferencesLearning PathsTopics About Start here
Risk Assessment Plug-and-play starting point Manufacturing Automation

Risk Assessment: GxP System Interface Data Integrity (FMEA)

A failure mode and effects analysis for the interfaces between GxP systems (instrument to CDS, CDS to LIMS, SCADA to historian, LIMS to MES/ERP): scoring scales, the assessment table, mitigations, residual risk, and a filled specimen.

Document type: Risk Assessment

Read and copy the template below into your own quality system. It is a generic starting point for your own internal use, provided as is, with no warranty; see the Terms and License. Adopting it does not by itself create compliance.

This is a ready-to-use failure mode and effects analysis (FMEA) for the interfaces between GxP systems, the transfer points where the cleanest individual systems still lose data integrity. Interfaces are where a mistyped result, a silently dropped transfer, or a disagreement over which copy is authoritative does its damage. Replace every <<FILL: ...>> placeholder, adapt the scoring scales to your quality risk management SOP, and route the completed assessment through your normal approval. A filled specimen follows. Confirm each cited regulation against the current source before you rely on it.

Control header

FieldEntry
Document titleGxP System Interface Data Integrity Risk Assessment
Document number<<FILL: RA-ID, e.g. RA-DI-009>>
Version<<FILL>>
Scope<<FILL: the interfaces / data flows assessed>>
Facilitator<<FILL: name / role>>
Team<<FILL: SMEs, QA, IT, validation>>
Date<<FILL>>

1. Methodology

This assessment uses FMEA. For each interface, the team identifies the ways the data transfer can fail (failure modes), the effect on data integrity and product quality, and the causes, then scores severity, occurrence, and detection to produce a risk priority number (RPN = Severity x Occurrence x Detection). Failure modes at or above the action threshold receive mitigations, and the residual risk after mitigation is recorded. The approach follows quality risk management principles (ICH Q9).

2. Scoring scales

Adapt these to your QRM SOP; keep them consistent across assessments so RPNs are comparable.

Severity (impact on data integrity / product / patient)

ScoreMeaning
5Wrong data reaches a release or safety decision undetected; patient or trial impact.
4Wrong or missing data reaches a GMP record; likely detected only in investigation.
3Data integrity affected but caught before a decision.
2Minor; local, self-correcting.
1No GMP or data-integrity impact.

Occurrence (how likely the failure is)

ScoreMeaning
5Expected routinely (for example manual retyping every batch).
4Likely.
3Occasional.
2Unlikely.
1Remote.

Detection (how likely the current controls catch it before harm)

ScoreMeaning
5Almost never detected before use.
4Poor detection.
3Moderate detection.
2Good detection (automated verification).
1Detected almost certainly at transfer.

Action threshold

<<FILL: e.g. RPN >= 36, or any Severity 5 with Detection >= 3>>. Document the rationale for the threshold. A high-severity, low-detection failure warrants action even below a numeric RPN cutoff.

3. Assessment table

Interface / data flowFailure modeEffect on data integrityCauseSODRPNAbove threshold?
<<FILL: e.g. CDS result to LIMS>>Manual retype introduces a wrong valueReported result differs from raw data; OOS logic sees the typed numberNo validated interface; copy-paste step<<FILL>><<FILL>><<FILL>><<FILL>><<FILL>>
<<FILL: e.g. SCADA to historian>>Compression drops a limit-crossing valueArchived trace no longer represents what happenedDeadband set for storage, not qualified<<FILL>><<FILL>><<FILL>><<FILL>><<FILL>>
<<FILL: e.g. scale to MES>>Partial or failed transfer accepted silentlyMissing or default value recorded as realNo failed-transfer detection<<FILL>><<FILL>><<FILL>><<FILL>><<FILL>>
<<FILL: e.g. LIMS to ERP>>Two systems disagree on the released valueAmbiguity over the authoritative copyOriginal/copy not defined<<FILL>><<FILL>><<FILL>><<FILL>><<FILL>>
<<FILL>><<FILL>><<FILL>><<FILL>><<FILL>><<FILL>><<FILL>><<FILL>><<FILL>>

4. Mitigations

For each failure mode above the threshold, define the mitigation, the owner, and the target date.

Failure modeMitigationOwnerTarget date
Manual retype introduces a wrong valueReplace with a validated electronic interface with checksum/record-count verification; until then require documented independent second-person verification of each transferred value (Annex 11 accuracy check)<<FILL>><<FILL>>
Compression drops a limit-crossing valueQualify the deadband so no value crossing an alert or action limit is dropped; document the setting as a validated parameter<<FILL>><<FILL>>
Partial or failed transfer accepted silentlyConfigure and test detection: a failed or partial transfer raises an alarm or hold, never a default value<<FILL>><<FILL>>
Two systems disagree on the released valueDefine the original (first-capture) and the copy for every shared value in the system inventory; reconcile the copy against the original<<FILL>><<FILL>>

5. Residual risk

Failure modeRPN beforeRPN after mitigationResidual risk acceptable?Justification
<<FILL>><<FILL>><<FILL>><<FILL>><<FILL>>

Residual risk is acceptable when the mitigated RPN is below the threshold and any remaining Severity-5 failure has a strong detection control. Document any residual risk that is accepted rather than reduced.

6. Acceptance criteria for the assessment

  • Every GxP interface in scope has at least one failure mode assessed.
  • Severity, occurrence, and detection are scored against the defined scales, consistently.
  • Every failure mode above the threshold has an owned, dated mitigation.
  • Residual risk is recorded and either acceptable or explicitly accepted with justification.
  • The assessment is approved and linked to the affected validation and change-control records.

7. Approvals

RoleNameSignatureDate
Facilitator<<FILL>>
SME<<FILL>>
QA<<FILL>>

8. References

EU GMP Annex 11 (computerised systems), accuracy-check and data-transfer expectations. ICH Q9 (quality risk management) for the FMEA methodology. 21 CFR Part 11 and 211.68 for record accuracy and input/output checks. Related reading: GxP manufacturing and laboratory systems, data lifecycle and metadata.

Confirm the current version and clause numbers of each reference before issue.

9. Revision history

VersionDateAuthorSummary of change
<<FILL: 1.0>><<FILL>><<FILL>>Initial issue.

Filled specimen

The following shows one row assessed and mitigated for an example CDS-to-LIMS interface, so you can see how the scoring and mitigation read. The values are illustrative.

InterfaceFailure modeEffectCauseSODRPNAbove threshold?
CDS result manually typed into LIMSWrong assay value enteredLIMS holds a value that differs from the CDS raw data; the OOS check runs on the typed number, not the real resultNo validated interface; analyst copy-pastes54480Yes

Mitigation: build a validated electronic interface from the CDS to the LIMS with a record-count and value check; until it is live, require a second analyst to independently verify each transferred value against the CDS and initial the LIMS record. After mitigation the interface removes the manual step (Occurrence drops to 2, Detection to 1), giving a residual RPN of 10, below the threshold. The interim second-person check is documented as the control until the interface is validated. The point the specimen makes: an RPN of 80 driven by high severity and poor detection is exactly the kind of quiet interface risk that only surfaces in an investigation, which is why interfaces are assessed explicitly rather than assumed clean.

Common inspection findings this assessment prevents

  • Manual data transfers between GxP systems with no verification and no risk assessment acknowledging them.
  • Historian compression set for storage convenience, quietly smoothing out an excursion.
  • Failed or partial transfers accepted as valid data with no detection.
  • Two systems holding the same value with no defined authoritative copy.
  • Interfaces treated as “IT plumbing” outside the data-integrity program.

How to adapt this assessment

  1. Set your document number and list every GxP interface in scope.
  2. Align the scoring scales and action threshold to your QRM SOP so RPNs compare across assessments.
  3. Add your real interfaces and their specific failure modes; do not rely on the generic examples alone.
  4. Assign owned, dated mitigations for everything above the threshold and track them to closure.
  5. Confirm every regulation in section 8 against the current published version before issue.
Use madhadi.com as an app Full screen, works offline, one tap from your home screen.