Independent and not affiliated with the FDA, MHRA, ISPE, PDA, or any agency. Get the appgoutham@madhadi.com
madhadi.comData Integrity & GxP Quality
Browse all topics → Articles Templates & Procedures Learning paths GlossaryScenariosToolsRegulatory ReferencesLearning PathsTopics About Start here
Form Plug-and-play starting point Data Integrity

Worksheet: Data Integrity Gap Assessment Finding Scoring and Classification

A plug-and-play worksheet that scores each gap-assessment finding on severity, likelihood, and detectability, computes a risk priority number, and bands it into Critical, Major, Minor, or Observation, so classification is reproducible instead of a label taken on trust, with a filled specimen.

Document type: Form

Read and copy the template below into your own quality system. It is a generic starting point for your own internal use, provided as is, with no warranty; see the Terms and License. Adopting it does not by itself create compliance.

This is a ready-to-use worksheet for scoring and classifying the individual findings a data integrity gap assessment produces. It operationalizes the numeric severity times likelihood times detectability method described in the parent article as a fillable tool, so two assessors working from the same evidence land on the same classification without arguing about the label itself. It is not the per-system control assessment, see the Data Integrity Risk and Gap Assessment (Per System) for that layer, and it is not the roll-up report, see the Report: Data Integrity Program Gap Assessment for that document. This worksheet sits between the two: it takes findings already identified during evidence gathering and turns each into a defensible, ranked classification before either of those documents is written. Replace every <<FILL: ...>> placeholder with your own specifics. A worked filled specimen follows. This is educational structure to adapt, not legal or regulatory advice.

Document control header

FieldEntry
Document titleData Integrity Gap Assessment Finding Scoring and Classification Worksheet
Document number<<FILL: reference, e.g. DI-SCORE-2026-01>>
Assessment date<<FILL>>
Scored by<<FILL: lead assessor name>>
Parent charter / report reference<<FILL>>

1. Purpose

This worksheet scores each finding from a data integrity gap assessment on three factors, severity, likelihood, and detectability, multiplies them into a risk priority number, and bands the result into the same four-level classification used in the assessment report, so the classification is reproducible from the evidence rather than a judgment call taken on trust.

2. Scoring scales

Factor135
Severity: consequence if the gap were exploited or the condition ran uncorrectedNegligible effect on record trustworthinessAffects a non-critical decisionDirectly compromises a release, safety, or reportable-result decision
Likelihood: how plausible the failure is under normal conditionsRequires an unusual, deliberate action to occurPlausible under normal operating pressureAlready occurring, or the normal way the system or process gets used
Detectability: how likely an existing control would catch it before harmWould be caught immediately by an independent controlMight be caught at periodic reviewLeaves no trace; nothing in the current control set would ever surface it

Score each factor 1, 2, 3, 4, or 5; intermediate values (2 and 4) are for a factor that sits between two anchor descriptions.

3. Risk priority number bands

RPN (severity x likelihood x detectability)ClassificationTypical target timeframe
75 to 125CriticalImmediate, in parallel with formal CAPA
30 to 74Major30 to 90 days
10 to 29Minor90 to 180 days
1 to 9ObservationTracked as continuous improvement

4. Finding scoring table

One row per finding. Score independently of the system owner; the lead assessor owns this table.

RefFindingSeverityLikelihoodDetectabilityRPNClassificationBasis for scores
<<FILL: F01>><<FILL>><<FILL: 1-5>><<FILL: 1-5>><<FILL: 1-5>><<FILL>><<FILL>><<FILL: one line justifying each score against the evidence>>

5. Reconciliation, where two assessors disagree

If two assessors score the same finding differently, do not average the classifications; reconcile the three underlying factors instead.

Finding refAssessor 1 scores (S/L/D)Assessor 2 scores (S/L/D)Factor with the disagreementResolution and final score
<<FILL>><<FILL>><<FILL>><<FILL>><<FILL>>

6. Acceptance criteria

  • Every finding carried forward from evidence gathering has a row in section 4 with all three factors scored and a stated basis for each score.
  • The RPN is calculated correctly (severity multiplied by likelihood multiplied by detectability) and banded per section 3 without manual override of the band.
  • Any classification that a reader would expect to be higher or lower than the RPN band suggests is either rescored with corrected factors or the override is explicitly justified in writing, an unexplained override defeats the purpose of a reproducible method.
  • Any scoring disagreement between assessors is resolved through section 5, not through an unrecorded compromise.
  • The completed worksheet is retained as a working paper supporting the assessment report.

7. References

ICH Q9(R1), Quality Risk Management, for the severity, likelihood, and detectability scoring logic this worksheet adapts. FDA, Data Integrity and Compliance With Drug CGMP: Questions and Answers (final, December 2018). MHRA, GXP Data Integrity Guidance and Definitions (Revision 1, March 2018).

Confirm the current version of each reference before issue.

8. Revision history

VersionDateAuthorSummary of change
<<FILL: 1.0>><<FILL: date>><<FILL: author>>Initial issue.

9. Approvals

RoleNameSignatureDate
Author (Lead Assessor)<<FILL>>
Reviewer (QA)<<FILL>>

Filled specimen

The following shows the worksheet completed for five findings from the same site assessment, so you can see how the numeric method drives a ranked list rather than four buckets of unequal size. The company and findings are illustrative; replace them with your own.

Finding scoring table:

RefFindingSeverityLikelihoodDetectabilityRPNClassificationBasis for scores
F01Audit trail off for method changes on a release-testing CDS545100CriticalSeverity 5: feeds batch release directly. Likelihood 4: method edits are a routine analyst action. Detectability 5: no other control captures this event type.
F02Three users hold unneeded admin rights on the LIMS43448MajorSeverity 4: LIMS results feed disposition but with a second-person check downstream. Likelihood 3: misuse would require a deliberate act. Detectability 4: no periodic access review exists to catch it.
F03No audit trail review procedure exists for a Tier 2 environmental monitoring system34336MajorSeverity 3: supports trending, not direct release. Likelihood 4: absence of a procedure means the gap is already the normal state. Detectability 3: an annual system audit would eventually surface it.
F04Password expiration disabled on a label-printing workstation23212MinorSeverity 2: label printing is a low-consequence function. Likelihood 3: plausible under normal IT workload pressure. Detectability 2: caught at the next periodic IT review.
F05Audit trail review procedure exists but was not updated after a recent configuration change2228ObservationSeverity 2: procedural currency gap, not an active control failure. Likelihood 2: requires the specific timing of a missed procedure update. Detectability 2: would be caught at the procedure’s own next periodic review.

Reconciliation extract: F02 was initially scored Severity 3 by one assessor and Severity 4 by a second; the disagreement traced to whether the downstream second-person check should discount severity. Resolved at Severity 4, because the worksheet scores the gap’s inherent consequence, not the residual risk after a compensating control, which is scored separately in the per-system risk assessment.

The finding worth noting in this specimen: F01 and F02 both read as serious findings in narrative, but the RPN gap, 100 against 48, made the sequencing decision for the remediation roadmap immediate rather than a matter of the report writer’s judgment call.

Common inspection findings this worksheet prevents

  • Two findings of similar apparent severity classified differently with no visible method, so the classification looks arbitrary when challenged.
  • A Critical downgraded to Major with no recorded basis for the change.
  • A large finding set with no way to produce a single ranked list, so remediation sequencing defaults to whoever wrote the report first.
  • Disagreement between assessors resolved by an unrecorded compromise rather than a traceable reconciliation of the underlying factors.

How to adapt this worksheet

  1. Set your document number and scorer in the header, and link it to the assessment charter or report it supports.
  2. If your organization already uses a different severity, likelihood, or detectability scale for FMEA or another risk tool, align the anchor descriptions in section 2 to that scale so classification language stays consistent across your quality system.
  3. Do not let a classification override the RPN band silently; if you disagree with what the math produced, rescore the factors and show your work.
  4. File the completed worksheet as a working paper behind the assessment report, not as a replacement for it.
  5. Confirm every regulation in section 7 against the current published version before issue.
Use madhadi.com as an app Full screen, works offline, one tap from your home screen.