14.3 Electronic Records, Data Integrity & Cybersecurity
Key Takeaways
- CQA BoK IV.A.10 is Apply-level: when auditing electronic records and computerized systems, apply data integrity, fraud-awareness, and cybersecurity concepts in sampling, interviews, and evidence evaluation.
- Data integrity expectations (e.g., ALCOA+ thinking: attributable, legible, contemporaneous, original, accurate—plus complete, consistent, enduring, available) guide how e-records are created, changed, and retained.
- Auditors examine access control, audit trails, privilege management, shared accounts, backdating, and deleted data—not only whether a screen “looks complete.”
- Cybersecurity and fraud risks (ransomware, unauthorized access, insider threat, manipulated records) are emphasized in the 2026 BoK context; quality auditors escalate and sample within competence/scope rather than acting as penetration testers.
- Retention, retrieval, and electronic document management must support inspection readiness: findable authentic records over the full retention period, including after system changes or migrations.
14.3 Electronic Records, Data Integrity & Cybersecurity (CQA BoK IV.A.10 — Apply)
Quick Answer: When auditing electronic records and computerized systems, apply controls for data integrity, fraud detection, and cybersecurity—including access, audit trails, retention/retrieval, and electronic document management—so evidence of product quality and compliance remains trustworthy.
Paper-era audit habits fail when batch records, training files, CAPA, calibration, and deviations live in validated (or should-be-validated) systems, shared drives, eDMS platforms, and cloud apps. BoK IV.A.10 (Apply) expects CQAs to use integrity and cyber concepts during real audits, not only recite definitions. The 2026 BoK emphasis on cybersecurity reflects that ransomware, credential theft, and silent data alteration are now ordinary quality risks—not exotic IT problems.
Scope of electronic records and computerized systems
| System / record type | Why auditors care |
|---|---|
| e-batch / eBMR / MES / LIMS | Direct product disposition evidence |
| ERP release / shipping gates | Unauthorized release risk |
| eQMS (CAPA, change, deviations, audits) | System effectiveness evidence |
| eDMS / document control | Criteria authenticity and version control |
| Training LMS | Competence claims |
| Calibration / CMMS | Measurement integrity |
| Cloud SaaS and hybrid hosting | Access, residency, vendor controls |
| Backup / archive / migration stores | Enduring availability and authenticity |
Apply means selecting samples and methods that can expose integrity failures (e.g., pull audit trails, test retrieval of archived lots, observe real login practices).
Data integrity foundations (ALCOA+)
Quality and regulated environments commonly use ALCOA and ALCOA+ as a practical integrity lens. Auditors apply these attributes to electronic as well as paper records.
| Attribute | Meaning for e-records | Audit application example |
|---|---|---|
| Attributable | Who did what, when | Unique user IDs; no shared logins for GxP actions |
| Legible | Readable over retention life | Readable formats; not corrupted files |
| Contemporaneous | Recorded at time of activity | Timestamps vs process clocks; delayed entry rules |
| Original | First capture or certified true copy | Controls on export/print as “original” |
| Accurate | Correct reflection of what happened | Cross-check instruments, weights, yields |
| Complete | Full set including failed / rejected data | Missing rejected runs or deleted trials |
| Consistent | Sequence and time logic holds | Out-of-order steps without justification |
| Enduring | Survives full retention | Migration tested; media not obsolete |
| Available | Retrievable when needed | Inspection drill: produce lot record in X minutes |
Scenario — incomplete electronic data.
LIMS shows only passing assay results for a stability time point. The audit trail shows three failing injections deleted by a supervisor account shared by the lab. Apply: this is a classic data-integrity nonconformity (completeness, attributable, accurate)—not a “documentation preference.” Treat as high significance when product disposition depends on the data.
Fraud and intentional manipulation
Not all integrity failures are accidental. Auditors should remain alert to fraud indicators without assuming malice for every error.
| Indicator | Possible concern | Apply-level response |
|---|---|---|
| Shared passwords / generic accounts | Unattributable actions; collusion cover | Sample access lists; observe login; write NC to access policy |
| End-of-period data clusters | Backfilling for metrics | Compare timestamps to process times |
| Disabled audit trails | Concealment of changes | Critical finding; escalate |
| Privilege far beyond role | Unauthorized changes | Segregation of duties review |
| Unexplained deletes / retests without protocol | Result shopping | Trail + procedure vs practice |
| Resistance to providing admin logs | Concealment or chaos | Document limitation; escalate to client/management |
| Perfect records with zero deviations in high-risk process | Too-good-to-be-true | Expand sample; observe live work |
Auditors apply professional skepticism: seek corroboration, protect chain of custody for screenshots/exports, and follow program rules for suspected intentional wrongdoing (often escalate beyond normal CAPA).
Cybersecurity for the quality auditor (2026 emphasis)
CQAs are not expected to replace cybersecurity engineers. They are expected to recognize when cyber control gaps threaten record trustworthiness, availability, and product decisions, and to audit within scope/competence.
| Cyber theme | Quality / audit relevance | Example evidence |
|---|---|---|
| Access control & authentication | Who can alter GxP data | MFA for remote admin; unique IDs; joiner/mover/leaver tickets |
| Authorization / least privilege | Segregation of write vs approve | Role matrix vs actual permissions |
| Audit trails & logging | Detect and investigate changes | Trail on; time sync; review procedures |
| Malware / ransomware resilience | Availability of quality systems | Backup isolation; recovery tests (ties to 14.1 continuity) |
| Network / remote access | Vendor and home-office access to MES/LIMS | VPN controls; vendor accounts time-bound |
| Patching & vulnerability mgmt | Unpatched GxP hosts | Change control for patches; risk acceptance docs |
| Vendor / SaaS assurance | Shared responsibility | Contracts, SOC reports, quality agreements |
| Incident response | Quality decisions during outage | Deviation/release rules when system down |
| Data exfiltration / privacy | Loss of confidential quality data | DLP where claimed; access reviews |
Scenario — ransomware and release.
A plant loses MES access for 72 hours. Paper backup batch records are used, but after restore, electronic and paper disagree on a critical yield step, and nobody can show a controlled reconciliation procedure. Apply: cyber events create data integrity and release control findings; recovery without reconciliation procedures is a system gap, not only an IT outage story.
Boundaries of competence
| Auditor does | Auditor typically does not |
|---|---|
| Sample user access vs procedure | Run unauthorized penetration tests |
| Review configuration against validated state | Exploit systems to “prove” weakness |
| Interview IT/quality on incident drills | Certify the entire enterprise security program alone |
| Escalate suspected breach indicators | Ignore cyber because “out of quality scope” when records are affected |
Auditing electronic records: practical methods
| Method | What to apply |
|---|---|
| Walk the transaction | Create → review → approve → archive path for a real lot/CAPA |
| Audit trail sampling | Changes to critical fields; who, when, why |
| Privilege testing (with permission) | Attempted actions under least-privilege accounts (or review logs of denied attempts) |
| Clock and sequence checks | Time sync (NTP); illogical timestamps |
| Hybrid paper/electronic | Where both exist, reconciliation rules |
| Observation of workarounds | Spreadsheet shadows of the “official” system |
| Interview operators | Shared passwords, sticky notes, “use John’s login” |
| Migration / upgrade history | Validation, data mapping, residual risk |
| Weak audit behavior | Strong apply behavior |
|---|---|
| Screenshot of login page only | Trail + role matrix + sample changed records |
| Accept “system is validated” plaque | Check validation status vs current configuration |
| Ignore Excel trackers beside eQMS | Treat shadow systems as uncontrolled records risk |
| Assume cloud vendor “handles everything” | Verify shared-responsibility controls and quality agreements |
Retention, retrieval, and electronic document management
Integrity without enduring availability fails inspections and investigations.
| Control area | Apply-level expectations |
|---|---|
| Retention schedule | Defined periods by record type; meets regulatory/customer minimums |
| Retrieval | Ability to find authentic records by lot, date, product, CAPA ID within required time |
| Archive format | Readable for full life; migration plans when software sunsets |
| True copies | Controlled export/PDF processes when used as official copies |
| eDMS version control | Approved current documents; obsolete removed from points of use |
| Electronic signatures | Meaning of signature, authentication, non-repudiation controls as applicable |
| Legal hold / investigation hold | Suspension of destruction when litigation or investigation requires |
| Destruction | Controlled, authorized, logged—not ad hoc admin deletes |
Scenario — retrieval failure.
During an audit, the team requests the e-batch record for a complaint lot from 4 years ago. IT restores a backup, but audit trails are missing and electronic signatures do not display. Apply: retention is incomplete if metadata and authenticity features needed to trust the record are not preserved—availability of a PDF alone may be insufficient for regulated decisions.
Putting IV.A.10 together for the exam
| Theme | Apply action on audit day |
|---|---|
| Data integrity | Sample ALCOA+ attributes on critical e-records |
| Fraud awareness | Watch for shared IDs, disabled trails, unexplained deletes |
| Cybersecurity (2026 emphasis) | Access, recovery, vendor access, incident impact on quality |
| Retention/retrieval | Drill real historical retrieval with authenticity checks |
| e-document management | Version control, points of use, signature controls |
Exam traps for IV.A.10
- “IT owns cyber; quality auditors ignore it” — false when quality records and release depend on systems.
- Validation certificate = perpetual integrity — configuration and access drift after go-live.
- Pretty UI = complete data — check rejected/deleted data and trails.
- Auditor as hacker — stay within authorization and competence; escalate technical exploits.
- Backup exists = continuity of integrity — test restore of usable, attributable records.
Key exam takeaway
IV.A.10 Apply means using data integrity, fraud awareness, and cybersecurity concepts while auditing electronic records and computerized systems—with practical attention to access, audit trails, retention/retrieval, and electronic document management. Under the 2026 BoK cyber emphasis, prefer answers that protect trustworthy, available quality evidence over cosmetic checks of screen layouts alone.
While auditing a LIMS, the auditor finds three failing assay injections deleted from the official report view; the audit trail shows a shared supervisor account performed the deletes with no documented investigation. Which IV.A.10 application is most appropriate?
Which approach best reflects a quality auditor applying 2026-relevant cybersecurity concepts within competence?
An inspection drill requests a 5-year-old e-batch record. A PDF is restored, but electronic signatures and audit-trail metadata are missing. What is the best integrity/retention judgment?
Operators routinely use a shared MES login posted on a monitor “to save time.” Pass/fail process data are entered under that ID. What is the primary data-integrity failure mode?