Data Integrity (ALCOA+): Protecting Result Integrity in Effluent and Industrial Laboratories
Key Facts — Data Integrity in Laboratories
- ALCOA: Attributable, Legible, Contemporaneous, Original, Accurate. Framework developed by the FDA in the 1990s.
- ALCOA+: Adds Complete, Consistent, Enduring, and Available. Adopted by PIC/S, WHO, and the EMA, and reflected in accreditation frameworks worldwide, including ISO/IEC 17025 assessments under bodies such as UKAS, A2LA, DAkkS, and Spain’s ENAC.
- ISO/IEC 17025:2025: First edition to incorporate specific provisions on information technology, LIMS, and automated data pipelines.
- Spreadsheet vulnerabilities: Overwriting without traceability, editable formulas, absent access control, no audit trail, uncontrolled copies.
- FDA QMSR: The FDA’s new Quality Management System Regulation (in effect since February 2026) aligns with ISO 13485 and reinforces data integrity requirements for regulated laboratories.
Table of contents
1. The pharmaceutical origins of ALCOA+ and its expansion across laboratories
ALCOA emerged in the 1990s as the FDA’s response to a series of data manipulation scandals in pharmaceutical laboratories: companies falsifying drug stability results, discarding unfavorable chromatograms, or re-testing samples until an “acceptable” result appeared, without documenting the earlier attempts. The FDA codified in ALCOA the minimum attributes laboratory data must meet to be considered trustworthy.
What began as a pharmaceutical regulatory requirement has since spread to every laboratory sector. PIC/S, the WHO, the EMA, and regulatory agencies around the world have adopted ALCOA+ as their reference framework. Accreditation bodies such as UKAS (UK), A2LA (US), DAkkS (Germany), and ENAC (Spain) apply these same principles when evaluating clause 7.11 of ISO 17025 (control of data and information management), even where ALCOA+ is not cited by name in their published criteria.
A note on Spain’s SINAC framework
In Spain, laboratories operating under the SINAC system for reporting drinking-water quality data face an additional layer of scrutiny: SINAC requires that reported results be traceable to their source records, which in practice means the underlying laboratory data must already satisfy ALCOA+-equivalent integrity criteria before it is ever submitted.
For effluent and industrial laboratories, where analytical data determines whether a company is within or in breach of its authorized discharge limits, data integrity is not an academic question — it is the foundation on which regulatory decisions, financial penalties, and legal liability rest.
2. Seven vulnerabilities of manual systems
Before discussing solutions, it’s worth understanding exactly where data integrity breaks down in laboratories that manage their processes without a LIMS.
Vulnerability 1: Overwriting without traceability
In a spreadsheet, when someone changes a value, the previous value simply disappears. There’s no record of who changed it, when, or why. This violates ALCOA’s Attributable and Original principles.
Vulnerability 2: Editable formulas
Calculation formulas in a spreadsheet can be modified by any user with access to the file. An unnoticed error in a single formula can propagate across hundreds of results without leaving a trace.
Vulnerability 3: No access control
If the results file sits in a shared folder, anyone with access to that folder can open, modify, and save it. Password protection on spreadsheet tabs is trivial to remove with freely available tools.
Vulnerability 4: Uncontrolled copies
Files get copied, emailed, and saved to local desktops. Within weeks, multiple versions of the same file exist and no one can determine which is the official one.
Vulnerability 5: Manual data transcription
Transferring data from the instrument to the recording system introduces transcription errors. Industry studies suggest manual transcription of numeric data carries an error rate of roughly 0.1% to 1% per field. In a laboratory processing hundreds of samples a day, that translates into dozens of potential errors.
Vulnerability 6: No reliable timestamps
A value logged in a lab notebook or spreadsheet can carry whatever date the user chooses to enter. There’s no guarantee the data was recorded at the moment it was generated (Contemporaneousness).
Vulnerability 7: Orphaned data
Chromatograms, spectra, and raw instrument records are often left unlinked to the final reported result. If an auditor requests the original chromatogram behind a PFAS analysis, the laboratory may simply be unable to locate it.
3. How Zendo LIMS implements each ALCOA+ principle
3.1 Attributable
Every action in Zendo LIMS is tied to a unique user with non-transferable credentials. The Activity Auditor automatically records who performed each action. Nothing can happen in the system without an authenticated user behind it.
3.2 Legible
Data is stored in a standard digital format, accessible throughout the entire retention period required by regulation — with no risk of physical degradation, illegible handwriting, or corrupted files on obsolete local drives.
3.3 Contemporaneous
Automatic data capture from instruments (autoanalyzers, chromatographs, spectrophotometers) timestamps each result with the server clock at the moment it’s generated. There’s no window for backdating a record.
3.4 Original
Zendo LIMS always preserves the primary data. When a result is corrected — with mandatory justification — the system retains the original value and logs the change as a new entry in the audit trail. The original data point is never overwritten.
3.5 Accurate
Calculations run through validated, locked formulas. Configurable validation rules flag out-of-range values before a result is reported, and direct instrument connections eliminate transcription errors altogether.
3.6 Complete
The system won’t let a batch close with incomplete results. Every measurement, including discarded ones, is logged with its justification — there’s no room for cherry-picking favorable results.
3.7 Consistent
Procedures apply uniformly across all samples because they’re encoded in the system rather than left to individual analyst interpretation. Methods, acceptance limits, and validation rules stay the same for every sample of a given type.
3.8 Enduring
Data is stored in the cloud with automatic backups, geographic redundancy, and loss protection. Retention periods are configured to match applicable regulatory requirements.
3.9 Available
Data is accessible at all times to authorized personnel, including during inspections. Role-based access ensures each user sees only the information relevant to them.
4. Data integrity in industrial effluent laboratories
Laboratories that analyze industrial effluent operate in a regulatory context where analytical data carries direct legal consequences. A result showing that a discharge exceeds authorized limits can trigger financial penalties, remediation obligations, and even criminal liability for the discharge permit holder.
In this context, data integrity isn’t merely a technical requirement — it’s a legal safeguard. A result that can’t demonstrate its chain of custody and documentary integrity can be challenged by the affected company, potentially invalidating the entire regulatory action.
The case of effluent-monitoring laboratories
Laboratories that carry out effluent monitoring on behalf of public authorities and water agencies need to demonstrate that their data is immune to manipulation. A LIMS with an immutable audit trail and automatic data capture provides that proof structurally, rather than relying on individual good faith.
5. The new ISO/IEC 17025:2025 and the reinforcement of data integrity
The publication of ISO/IEC 17025:2025 in September 2025 marks a turning point for data integrity in laboratories. For the first time, the standard includes specific provisions on information technology, LIMS, and automated data pipelines. That means the software a laboratory uses is no longer a peripheral consideration — it’s now an evaluable component during an accreditation audit.
Laboratories still managing their data through spreadsheets, paper notebooks, or unvalidated software face growing risk of nonconformity in their next accreditation assessments, whether under UKAS, A2LA, DAkkS, ENAC, or any ILAC MRA signatory body. The standard no longer allows “our spreadsheet works fine” as an answer if the system can’t demonstrate it meets data integrity principles.
Ensure ALCOA+ data integrity with Zendo LIMS
6. Practical guide: 7 questions every lab director should ask
- Can my system show who modified a result, when, and why?
- Is the original data always preserved, even when a result is corrected?
- Does the system apply the timestamp on results, or does the user?
- Do uncontrolled copies of results files exist anywhere?
- Are calculations validated and locked, or can any user edit the formulas?
- Can I link every reported result back to the raw instrument data?
- Would my system hold up under an accreditation assessment against the new ISO/IEC 17025:2025 requirements?
If the answer to any of these is “no” or “not sure,” the laboratory has a data integrity gap that needs addressing before its next accreditation assessment.
7. Conclusion: data integrity as the foundation of trust
Data integrity isn’t an abstract concept, and it isn’t exclusive to the pharmaceutical industry. It’s the foundation on which trust in a laboratory’s results is built. Without data integrity, ISO 17025 accreditation is an empty shell — the seal is there, but the guarantee it’s supposed to represent has evaporated.
Zendo LIMS implements ALCOA+ principles natively and structurally, not as a bolt-on layer. Every data point is attributable, legible, contemporaneous, original, accurate, complete, consistent, enduring, and available. From generation to archiving, every bit of information is protected.
For effluent and industrial laboratories, where data determines legal liability and financial penalties, a LIMS built on ALCOA+ data integrity isn’t a luxury — it’s the cost of doing business seriously.