Data Integrity Framework

ALCOA+ Principles for Terminology Management

ALCOA+ isn’t just for lab notebooks. Every glossary term your team defines is a controlled record — and auditors evaluate it against the same data integrity principles. Here’s what each principle means for terminology management.

What Is ALCOA+?

ALCOA+ is a nine-principle data integrity framework (Attributable, Legible, Contemporaneous, Original, Accurate, Complete, Consistent, Enduring, Available) that governs how regulated records must be created, maintained, and retrieved. It is mandated or referenced by the FDA, EMA, WHO, PIC/S, MHRA, and ISPE/GAMP across GxP environments. Because glossaries define the terminology used inside controlled records, they fall under the same data integrity scope as the documents that reference them.

ALCOA is a mnemonic for five data integrity principles: Attributable, Legible, Contemporaneous, Original, Accurate. It is widely attributed in industry literature to Stan W. Woollen of the FDA’s Office of Enforcement in the early 1990s as a training tool for GLP inspectors. Attribution is consistent across secondary GxP industry references; the FDA’s primary guidance documents codifying these principles are linked in the Regulatory References section below.

The “+” extends the mnemonic with Complete, Consistent, Enduring, Available. These additional principles appear across EMA, MHRA, WHO and PIC/S data integrity guidance published between 2010 and 2021 (see Regulatory References below for the primary documents).

Today, ALCOA+ is referenced across the FDA, EMA, WHO, PIC/S and MHRA data integrity guidance linked in the Regulatory References table.

Why this matters for glossaries: Regulatory bodies apply ALCOA+ to all GxP data and documentation — not just clinical data. Your controlled vocabulary defines the terms used in regulated records. If your glossary doesn’t meet ALCOA+ standards, the documents that reference it inherit the gap.

The Nine ALCOA+ Principles

Each principle below includes: the regulatory definition, what auditors look for, and how it maps to terminology management in Confluence.

A Attributable

Definition: Data must be traceable to the person (or system) who created, modified, or deleted it, with date and time stamps.

What auditors check: “Who changed this definition? When? Can you prove it?”

How Compliance Glossary meets this: Every action — create, edit, status change, approval — is recorded with the Atlassian user ID and timestamp. No anonymous changes. No shared accounts. The audit CSV export includes the full attribution chain.

L Legible

Definition: Data must be readable, permanent, and understandable — both when recorded and throughout its retention period.

What auditors check: “Can I read every version of this definition clearly? Will it still be readable in 5 years?”

How Compliance Glossary meets this: Structured term records with dedicated fields (definition, category, synonyms, notes) ensure clarity. No handwritten annotations, no ambiguous formatting. Version history preserves every past state in a readable format.

C Contemporaneous

Definition: Data must be recorded at the time the activity was performed, not reconstructed afterward.

What auditors check: “Was this term defined before it appeared in your documentation, or was the glossary backfilled after the audit was announced?”

How Compliance Glossary meets this: Creation and modification timestamps are system-generated and immutable. The version timeline shows the exact sequence of changes. Backdating is not possible — timestamps come from the Forge platform, not user input.

O Original

Definition: The first-captured record (or a verified true copy) must be preserved. Not a rewrite or uncontrolled transcription.

What auditors check: “Is this the authoritative glossary, or a copy? How do I know this hasn’t been recreated?”

How Compliance Glossary meets this: The glossary is the single source of truth, stored in Atlassian’s Forge infrastructure. Version history is append-only — there is no UI to edit or delete previous versions. The first version of every term is permanently preserved.

A Accurate

Definition: Data must be correct, truthful, complete in context, and free from undocumented edits.

What auditors check: “Does your definition of ‘adverse event’ match the regulatory source? Has anyone made undocumented changes?”

How Compliance Glossary meets this: The four-eyes approval workflow requires a second person to verify accuracy before a term becomes active. Mandatory change reasons document why every edit was made. The compliance scanner detects when page content drifts from approved definitions.

C Complete

Definition: All data must be present, including metadata, repeat results, and audit trails. Nothing omitted or deleted.

What auditors check: “Why is this term missing a category? Where are the synonyms? Is the audit trail complete?”

How Compliance Glossary meets this: Terms have structured metadata fields: category, synonyms, notes, space scope. The dashboard compliance score surfaces incomplete records. The audit export includes the full history — no data is omitted.

C Consistent

Definition: Data elements must follow expected patterns. Timestamps reference common time sources. Documentation must be orderly across systems.

What auditors check: “Does ‘material adverse change’ mean the same thing in your legal space as in your finance space?”

How Compliance Glossary meets this: One glossary serves all Confluence spaces — a single source of truth. The compliance scanner runs across spaces, detecting where page content uses terminology inconsistently. See our synonym drift detection for details.

E Enduring

Definition: Records must be stored on durable, authorized media and maintained intact for the full required retention period.

What auditors check: “Where is this data stored? Will it survive a system migration? Can I see records from 3 years ago?”

How Compliance Glossary meets this: Customer terminology data is stored on Atlassian’s Forge infrastructure. Atlassian Cloud holds SOC 2 Type II and ISO 27001 certifications, inherited by the app as platform controls; DailyMind LTD (Compliance Glossary publisher) is not independently SOC 2 Type II or ISO 27001 certified (see /security-whitepaper). The Forge app does not operate external servers and does not write to local storage outside Forge. Version history is append-only and persists for the life of the Confluence instance.

A Available

Definition: Data must be accessible and retrievable when needed for review, audit, or inspection over its entire lifetime.

What auditors check: “Can you produce your controlled vocabulary right now? With full history? In a format I can review?”

How Compliance Glossary meets this: One-click CSV export produces the complete glossary with all metadata, version history, and approval chain. The dashboard provides instant visibility into glossary health. No IT involvement needed to produce audit evidence.

ALCOA+ Compliance Summary

PrincipleRequirementCompliance Glossary FeatureStatus
AttributableWho did it, whenUser ID + timestamp on every actionLive (v4.3.0)
LegibleReadable, permanentStructured fields, version historyLive (v4.3.0)
ContemporaneousRecorded in real timeSystem-generated timestamps, no backdatingLive (v4.3.0)
OriginalFirst record preservedAppend-only version historyLive (v4.3.0)
AccurateCorrect, verifiedFour-eyes approval + page scanner for undefined termsLive (v4.3.0)
CompleteNothing omittedStructured metadata + dashboard compliance scoreLive (v4.3.0)
ConsistentSame meaning everywhereCross-space page scanner + single source of truthLive (v4.3.0)
EnduringDurable storageAtlassian Forge infrastructure (SOC 2, ISO 27001)Live (v4.3.0)
AvailableAccessible on demandAudit CSV export (terms + approvals + version history) + dashboardLive (v4.3.0); PDF export on roadmap

Regulatory References

ALCOA+ is referenced across major pharmaceutical regulators and industry bodies. Primary sources:

AgencyDocumentYear
FDAData Integrity and Compliance with Drug CGMP: Questions and Answers (Guidance for Industry)2018
FDA21 CFR Part 11 — Electronic Records; Electronic Signatures1997
MHRA‘GXP’ Data Integrity Guidance and Definitions, Rev. 12018
WHOGuideline on Data Integrity (TRS 1033, Annex 4)2021
PIC/SGood Practices for Data Management and Integrity in Regulated GMP/GDP Environments (PI 041-1)2021
EMAGuideline on computerised systems and electronic data in clinical trials (EMA/INS/GCP/112288/2023)2023
ISPE/GAMPGAMP Records and Data Integrity Guide2017

Last verified: 2026-04-17

Beyond Lab Data: Why Glossaries Need ALCOA+

Most teams associate ALCOA+ with clinical data, batch records, and lab notebooks. But the principles apply to all controlled documentation in regulated environments — including the glossary that defines the terminology used in those records.

Consider: if your glossary defines “adverse event” for your entire organization, that definition is a controlled record. It needs the same governance as any other GxP data:

Spreadsheet glossaries fail on most of these. A shared Google Sheet has no append-only audit trail, no enforced approval workflow, and no way to prove who changed a definition or when. See how teams in FDA-regulated industries and SOC 2 environments use ALCOA+ principles in practice.

Frequently Asked Questions

What does ALCOA+ stand for?

ALCOA stands for Attributable, Legible, Contemporaneous, Original, and Accurate. The “+” extends the mnemonic with four additional principles: Complete, Consistent, Enduring, and Available. Together, these nine principles form the global data integrity standard for regulated industries.

Who coined ALCOA?

ALCOA is widely attributed to Stan W. Woollen of the FDA’s Office of Enforcement in the early 1990s as a training mnemonic for Good Laboratory Practice (GLP) inspectors. The attribution is consistent across industry sources but is not published on an FDA primary-source page. The “+” principles (Complete, Consistent, Enduring, Available) appear across EMA, MHRA, WHO and PIC/S data integrity guidance between 2010 and 2021.

Does ALCOA+ apply to glossaries?

Yes. Regulators apply ALCOA+ to all GxP data and controlled documentation, not just clinical or lab data. A glossary that defines terminology used in regulated records is itself a controlled record and must meet the same attribution, audit trail, and retention standards.

Which regulators reference ALCOA+?

ALCOA+ is referenced or mandated by the FDA, EMA, WHO, PIC/S, MHRA, and ISPE/GAMP. Key documents include FDA’s 2018 Data Integrity guidance, MHRA’s GxP Data Integrity Guidance Rev. 1 (2018), PIC/S PI 041-1 (2021), and WHO TRS 1033 (2021).

Terminology Management Aligned with ALCOA+

Every principle. Every term. Every audit. Built on Atlassian Forge — tenant data stays inside the Atlassian platform; the app publisher has no runtime access to glossary content.

Evaluate in Confluence Read Documentation

Related Resources

Compliance for Confluence — approved terms, page scanning, and audit evidence for regulated teams in Confluence

Pharma terminology management — controlled vocabulary for GxP documentation, data integrity, and regulatory submissions

GxP documentation — Good Practice documentation controls for pharma, medtech, and biotech teams

Annex 11 terminology — EU GMP Annex 11 controlled vocabulary for computerised systems in regulated environments

Four-Eyes Principle — approval workflows for compliance, QA, GRC, legal, security, and regulatory teams, mapped to SOX, MiFID II, and FDA GMP

FDA Terminology Management — 43-term template for pharma & medtech, mapped to 21 CFR Part 11

Compliance Guide — what auditors check and how we help, mapped to real regulatory standards