Independent and not affiliated with the FDA, MHRA, ISPE, PDA, or any agency. Get the appgoutham@madhadi.com
madhadi.comData Integrity & GxP Quality
Browse all topics → Articles Templates & Procedures Learning paths GlossaryScenariosToolsRegulatory ReferencesLearning PathsTopics About Start here
Work Instruction Plug-and-play starting point Data Integrity

Work Instruction: Just-Culture Classification of a Data Integrity Event

A step-by-step decision aid for classifying an integrity event as honest error, at-risk behavior, falsification, or fraud, using the substitution and knowledge tests, so the response fits the behavior and does not punish the honest reporter.

Document type: Work Instruction

Read and copy the template below into your own quality system. It is a generic starting point for your own internal use, provided as is, with no warranty; see the Terms and License. Adopting it does not by itself create compliance.

This is a ready-to-use work instruction. Replace every <<FILL: ...>> placeholder with your own specifics and reference it from your parent deviation and investigation SOP. A worked filled specimen follows the template. It is an educational aid to adapt and verify, not legal, HR, or disciplinary advice; run any accountability decision through your own HR and legal processes.

Control header

FieldEntry
Work instruction number<<FILL: WI-ID, e.g. WI-QA-031>>
Parent SOP<<FILL: deviation / investigation SOP-ID>>
Version<<FILL: version>>
Effective date<<FILL: date>>
Owner<<FILL: role, e.g. Head of Quality>>

Purpose

Classify a data integrity event so the response fits what actually happened. The aim is to separate the honest reporter, whose event is a signal to fix the system, from the deliberate falsifier, whose event calls for accountability, and to name the large middle category of at-risk behavior that most normalized deviance falls into. Applying one response to all three is the fastest way to kill a reporting culture.

When to use

Use this work instruction whenever an event involves the reliability of a GxP record: a deleted or re-run result, a changed value without a reason, a record made not-contemporaneously, a shared login, a bench practice that differs from the procedure, or any similar finding. Use it before deciding on corrective action, and before any conversation that could feel disciplinary.

Definitions

  • Honest error: an unintended departure from a correct procedure. Driven by inattention, ambiguity, or poor system design.
  • At-risk behavior: a shortcut that the person did not recognize as risky, usually because the system had made it feel normal. Neither a deliberate falsification nor something every careful peer would have done.
  • Falsification: knowingly recording something untrue, usually under pressure.
  • Fraud: deliberate, organized deception for gain.
  • Substitution test: would another competent, similarly trained person, in the same situation with the same information and the same system, plausibly have done the same thing?
  • Knowledge test: did the person knowingly record something false, or knowingly take an unjustifiable risk?

Procedure

Step 1: Secure the facts before anyone is interviewed

  1. Preserve the records and their context (the audit trail, the instrument files, the surrounding batch or run). Do not let the person alter anything further.
  2. Assemble what was done, when, by whom, and against which procedure version. Confirm the person was trained on that version.
  3. Do not form a conclusion yet. The classification comes from the two tests, not from how serious the outcome looks.

Step 2: Apply the substitution test

  1. Ask whether a competent, similarly trained peer, in the same system with the same information and pressure, would plausibly have done the same thing.
  2. If yes, the system shares the blame. The primary fix is a design fix (a clearer procedure, a system control, a removed pressure), whatever else follows. Continue to Step 3, because a design-driven event can still involve a knowing act.

Step 3: Apply the knowledge test

  1. Ask whether the person knowingly recorded something untrue, or knowingly took a risk they could not justify.
  2. If they knowingly recorded something false: this is falsification (or, if organized for gain, fraud). Accountability applies regardless of the pressure they were under.
  3. If they took a shortcut they did not recognize as risky: this is at-risk behavior. The response is coaching plus removing the incentive or condition that made the shortcut feel normal, not punishment.
  4. If neither is true and a careful peer would plausibly have done the same: this is honest error. The response is a system or design fix.

Step 4: Assess data reliability beyond the single event

  1. One deleted injection implies a question about the whole data set and possibly other batches or runs. Widen the assessment accordingly.
  2. Decide product impact, batch impact, and any field-action or disclosure question through the parent SOP. A falsification carries reliability and disclosure obligations that an honest error does not.

Step 5: Record the classification and route the response

  1. Record the event, the two test outcomes, the classification, and the basis for it.
  2. Route the corrective action to match the category (design fix, coaching, or accountability), and open the product-impact and CAPA work through the parent SOP.
  3. Do not close a deliberate act with “retrain the analyst.” Training is not a corrective action for a rule someone broke on purpose.

Classification at a glance

Substitution testKnowledge testCategoryPrimary response
A peer would plausibly do the sameNo knowing false record or unjustified riskHonest errorSystem / design fix, error-proofing
A peer would not clearly do the sameTook a shortcut, did not see the riskAt-risk behaviorCoaching, remove the enabling incentive
EitherKnowingly recorded something falseFalsificationAccountability, plus reliability and disclosure assessment
EitherOrganized deception for gainFraudInvestigation, HR and legal, accountability

Acceptance criteria

  • The two tests were applied and their outcomes recorded before any accountability decision.
  • Data reliability was assessed beyond the single event.
  • The corrective action matches the category, and no deliberate act was closed with training alone.
  • An honest reporter was not treated the same as a deliberate falsifier.

References

FDA guidance, Data Integrity and Compliance With Drug CGMP: Questions and Answers (December 2018). 21 CFR 211.192 (investigation of discrepancies and failures). The just-culture framework as applied in high-reliability safety fields, distinguishing honest error and at-risk behavior from reckless disregard and willful violation.

Confirm the current version of each reference before you rely on it.

Record generated: event classification record

FieldEntry
Event / deviation reference<<FILL: number>>
Record(s) affected<<FILL: system, run, batch>>
Procedure version in force and training confirmed<<FILL: version, trained Y/N>>
Substitution test outcome<<FILL: peer would / would not plausibly do the same, why>>
Knowledge test outcome<<FILL: knowing false / unjustified risk / neither>>
ClassificationHonest error / At-risk / Falsification / Fraud
Data reliability scope assessed<<FILL: single event / wider data set / other batches>>
Response routed<<FILL: design fix / coaching / accountability>>
Classified by (name, date)<<FILL>>
QA concurrence (name, date)<<FILL>>

Revision history

VersionDateAuthorSummary of change
<<FILL: 1.0>><<FILL: date>><<FILL: author>>Initial issue.

Filled specimen

An analyst is found to have re-run a sample after an out-of-specification injection and reported the passing re-run, with the first injection deleted from the sequence. The classification record, completed:

FieldEntry
Event / deviation referenceDEV-2026-0208
Record(s) affectedChromatography data system, run HPLC-04-2607-014, plus a review of the analyst’s last 20 runs
Procedure version in force and training confirmedOOS SOP Rev E; analyst trained 12 Jan 2026 (Y)
Substitution test outcomeA competent peer would open an OOS investigation, not delete the first injection; a peer would not plausibly do the same
Knowledge test outcomeThe analyst knowingly deleted a failing result and reported the passing re-run: knowing false record
ClassificationFalsification
Data reliability scope assessedWidened to the analyst’s last 20 runs; two more deletions found, expanding the investigation
Response routedAccountability through HR and QA; product-impact and disclosure assessment opened; not closed with retraining
Classified byA. Okafor, 06 Aug 2026
QA concurrenceR. Mehta, 06 Aug 2026

The point of the record is that the classification is driven by the two tests and documented, so the response (accountability plus a wider reliability review, not a training record) is defensible.

Common inspection findings this work instruction prevents

  • Deliberate acts closed with “retrain the analyst,” signaling the root cause was never found.
  • Honest errors treated punitively, which teaches people to stop reporting.
  • A single falsification investigated in isolation, without assessing whether other records are affected.
  • No consistent, documented method for deciding accountability, so decisions look arbitrary.

How to adapt this work instruction

  1. Point the parent-SOP references at your real deviation and investigation procedures.
  2. Align the accountability routing with your HR and legal processes; this document classifies behavior, it does not administer discipline.
  3. Keep the two tests exactly as written; their value is that they are applied before, and independent of, the seriousness of the outcome.
  4. Confirm each reference against its current published version before issue.
Use madhadi.com as an app Full screen, works offline, one tap from your home screen.