14.3 Electronic Records, Data Integrity & Cybersecurity

Key Takeaways

  • CQA BoK IV.A.10 is Apply-level: when auditing electronic records and computerized systems, apply data integrity, fraud-awareness, and cybersecurity concepts in sampling, interviews, and evidence evaluation.
  • Data integrity expectations (e.g., ALCOA+ thinking: attributable, legible, contemporaneous, original, accurate—plus complete, consistent, enduring, available) guide how e-records are created, changed, and retained.
  • Auditors examine access control, audit trails, privilege management, shared accounts, backdating, and deleted data—not only whether a screen “looks complete.”
  • Cybersecurity and fraud risks (ransomware, unauthorized access, insider threat, manipulated records) are emphasized in the 2026 BoK context; quality auditors escalate and sample within competence/scope rather than acting as penetration testers.
  • Retention, retrieval, and electronic document management must support inspection readiness: findable authentic records over the full retention period, including after system changes or migrations.
Last updated: August 2026

14.3 Electronic Records, Data Integrity & Cybersecurity (CQA BoK IV.A.10 — Apply)

Quick Answer: When auditing electronic records and computerized systems, apply controls for data integrity, fraud detection, and cybersecurity—including access, audit trails, retention/retrieval, and electronic document management—so evidence of product quality and compliance remains trustworthy.

Paper-era audit habits fail when batch records, training files, CAPA, calibration, and deviations live in validated (or should-be-validated) systems, shared drives, eDMS platforms, and cloud apps. BoK IV.A.10 (Apply) expects CQAs to use integrity and cyber concepts during real audits, not only recite definitions. The 2026 BoK emphasis on cybersecurity reflects that ransomware, credential theft, and silent data alteration are now ordinary quality risks—not exotic IT problems.


Scope of electronic records and computerized systems

System / record typeWhy auditors care
e-batch / eBMR / MES / LIMSDirect product disposition evidence
ERP release / shipping gatesUnauthorized release risk
eQMS (CAPA, change, deviations, audits)System effectiveness evidence
eDMS / document controlCriteria authenticity and version control
Training LMSCompetence claims
Calibration / CMMSMeasurement integrity
Cloud SaaS and hybrid hostingAccess, residency, vendor controls
Backup / archive / migration storesEnduring availability and authenticity

Apply means selecting samples and methods that can expose integrity failures (e.g., pull audit trails, test retrieval of archived lots, observe real login practices).


Data integrity foundations (ALCOA+)

Quality and regulated environments commonly use ALCOA and ALCOA+ as a practical integrity lens. Auditors apply these attributes to electronic as well as paper records.

AttributeMeaning for e-recordsAudit application example
AttributableWho did what, whenUnique user IDs; no shared logins for GxP actions
LegibleReadable over retention lifeReadable formats; not corrupted files
ContemporaneousRecorded at time of activityTimestamps vs process clocks; delayed entry rules
OriginalFirst capture or certified true copyControls on export/print as “original”
AccurateCorrect reflection of what happenedCross-check instruments, weights, yields
CompleteFull set including failed / rejected dataMissing rejected runs or deleted trials
ConsistentSequence and time logic holdsOut-of-order steps without justification
EnduringSurvives full retentionMigration tested; media not obsolete
AvailableRetrievable when neededInspection drill: produce lot record in X minutes

Scenario — incomplete electronic data.
LIMS shows only passing assay results for a stability time point. The audit trail shows three failing injections deleted by a supervisor account shared by the lab. Apply: this is a classic data-integrity nonconformity (completeness, attributable, accurate)—not a “documentation preference.” Treat as high significance when product disposition depends on the data.


Fraud and intentional manipulation

Not all integrity failures are accidental. Auditors should remain alert to fraud indicators without assuming malice for every error.

IndicatorPossible concernApply-level response
Shared passwords / generic accountsUnattributable actions; collusion coverSample access lists; observe login; write NC to access policy
End-of-period data clustersBackfilling for metricsCompare timestamps to process times
Disabled audit trailsConcealment of changesCritical finding; escalate
Privilege far beyond roleUnauthorized changesSegregation of duties review
Unexplained deletes / retests without protocolResult shoppingTrail + procedure vs practice
Resistance to providing admin logsConcealment or chaosDocument limitation; escalate to client/management
Perfect records with zero deviations in high-risk processToo-good-to-be-trueExpand sample; observe live work

Auditors apply professional skepticism: seek corroboration, protect chain of custody for screenshots/exports, and follow program rules for suspected intentional wrongdoing (often escalate beyond normal CAPA).


Cybersecurity for the quality auditor (2026 emphasis)

CQAs are not expected to replace cybersecurity engineers. They are expected to recognize when cyber control gaps threaten record trustworthiness, availability, and product decisions, and to audit within scope/competence.

Cyber themeQuality / audit relevanceExample evidence
Access control & authenticationWho can alter GxP dataMFA for remote admin; unique IDs; joiner/mover/leaver tickets
Authorization / least privilegeSegregation of write vs approveRole matrix vs actual permissions
Audit trails & loggingDetect and investigate changesTrail on; time sync; review procedures
Malware / ransomware resilienceAvailability of quality systemsBackup isolation; recovery tests (ties to 14.1 continuity)
Network / remote accessVendor and home-office access to MES/LIMSVPN controls; vendor accounts time-bound
Patching & vulnerability mgmtUnpatched GxP hostsChange control for patches; risk acceptance docs
Vendor / SaaS assuranceShared responsibilityContracts, SOC reports, quality agreements
Incident responseQuality decisions during outageDeviation/release rules when system down
Data exfiltration / privacyLoss of confidential quality dataDLP where claimed; access reviews

Scenario — ransomware and release.
A plant loses MES access for 72 hours. Paper backup batch records are used, but after restore, electronic and paper disagree on a critical yield step, and nobody can show a controlled reconciliation procedure. Apply: cyber events create data integrity and release control findings; recovery without reconciliation procedures is a system gap, not only an IT outage story.

Boundaries of competence

Auditor doesAuditor typically does not
Sample user access vs procedureRun unauthorized penetration tests
Review configuration against validated stateExploit systems to “prove” weakness
Interview IT/quality on incident drillsCertify the entire enterprise security program alone
Escalate suspected breach indicatorsIgnore cyber because “out of quality scope” when records are affected

Auditing electronic records: practical methods

MethodWhat to apply
Walk the transactionCreate → review → approve → archive path for a real lot/CAPA
Audit trail samplingChanges to critical fields; who, when, why
Privilege testing (with permission)Attempted actions under least-privilege accounts (or review logs of denied attempts)
Clock and sequence checksTime sync (NTP); illogical timestamps
Hybrid paper/electronicWhere both exist, reconciliation rules
Observation of workaroundsSpreadsheet shadows of the “official” system
Interview operatorsShared passwords, sticky notes, “use John’s login”
Migration / upgrade historyValidation, data mapping, residual risk
Weak audit behaviorStrong apply behavior
Screenshot of login page onlyTrail + role matrix + sample changed records
Accept “system is validated” plaqueCheck validation status vs current configuration
Ignore Excel trackers beside eQMSTreat shadow systems as uncontrolled records risk
Assume cloud vendor “handles everything”Verify shared-responsibility controls and quality agreements

Retention, retrieval, and electronic document management

Integrity without enduring availability fails inspections and investigations.

Control areaApply-level expectations
Retention scheduleDefined periods by record type; meets regulatory/customer minimums
RetrievalAbility to find authentic records by lot, date, product, CAPA ID within required time
Archive formatReadable for full life; migration plans when software sunsets
True copiesControlled export/PDF processes when used as official copies
eDMS version controlApproved current documents; obsolete removed from points of use
Electronic signaturesMeaning of signature, authentication, non-repudiation controls as applicable
Legal hold / investigation holdSuspension of destruction when litigation or investigation requires
DestructionControlled, authorized, logged—not ad hoc admin deletes

Scenario — retrieval failure.
During an audit, the team requests the e-batch record for a complaint lot from 4 years ago. IT restores a backup, but audit trails are missing and electronic signatures do not display. Apply: retention is incomplete if metadata and authenticity features needed to trust the record are not preserved—availability of a PDF alone may be insufficient for regulated decisions.


Putting IV.A.10 together for the exam

ThemeApply action on audit day
Data integritySample ALCOA+ attributes on critical e-records
Fraud awarenessWatch for shared IDs, disabled trails, unexplained deletes
Cybersecurity (2026 emphasis)Access, recovery, vendor access, incident impact on quality
Retention/retrievalDrill real historical retrieval with authenticity checks
e-document managementVersion control, points of use, signature controls

Exam traps for IV.A.10

  1. “IT owns cyber; quality auditors ignore it” — false when quality records and release depend on systems.
  2. Validation certificate = perpetual integrity — configuration and access drift after go-live.
  3. Pretty UI = complete data — check rejected/deleted data and trails.
  4. Auditor as hacker — stay within authorization and competence; escalate technical exploits.
  5. Backup exists = continuity of integrity — test restore of usable, attributable records.

Key exam takeaway

IV.A.10 Apply means using data integrity, fraud awareness, and cybersecurity concepts while auditing electronic records and computerized systems—with practical attention to access, audit trails, retention/retrieval, and electronic document management. Under the 2026 BoK cyber emphasis, prefer answers that protect trustworthy, available quality evidence over cosmetic checks of screen layouts alone.

Test Your Knowledge

While auditing a LIMS, the auditor finds three failing assay injections deleted from the official report view; the audit trail shows a shared supervisor account performed the deletes with no documented investigation. Which IV.A.10 application is most appropriate?

A
B
C
D
Test Your Knowledge

Which approach best reflects a quality auditor applying 2026-relevant cybersecurity concepts within competence?

A
B
C
D
Test Your Knowledge

An inspection drill requests a 5-year-old e-batch record. A PDF is restored, but electronic signatures and audit-trail metadata are missing. What is the best integrity/retention judgment?

A
B
C
D
Test Your Knowledge

Operators routinely use a shared MES login posted on a monitor “to save time.” Pass/fail process data are entered under that ID. What is the primary data-integrity failure mode?

A
B
C
D