ALCOA+ isn’t just for lab notebooks. Every glossary term your team defines is a controlled record — and auditors evaluate it against the same data integrity principles. Here’s what each principle means for terminology management.
ALCOA+ is a nine-principle data integrity framework (Attributable, Legible, Contemporaneous, Original, Accurate, Complete, Consistent, Enduring, Available) that governs how regulated records must be created, maintained, and retrieved. It is mandated or referenced by the FDA, EMA, WHO, PIC/S, MHRA, and ISPE/GAMP across GxP environments. Because glossaries define the terminology used inside controlled records, they fall under the same data integrity scope as the documents that reference them.
ALCOA is a mnemonic for five data integrity principles: Attributable, Legible, Contemporaneous, Original, Accurate. It is widely attributed in industry literature to Stan W. Woollen of the FDA’s Office of Enforcement in the early 1990s as a training tool for GLP inspectors. Attribution is consistent across secondary GxP industry references; the FDA’s primary guidance documents codifying these principles are linked in the Regulatory References section below.
The “+” extends the mnemonic with Complete, Consistent, Enduring, Available. These additional principles appear across EMA, MHRA, WHO and PIC/S data integrity guidance published between 2010 and 2021 (see Regulatory References below for the primary documents).
Today, ALCOA+ is referenced across the FDA, EMA, WHO, PIC/S and MHRA data integrity guidance linked in the Regulatory References table.
Each principle below includes: the regulatory definition, what auditors look for, and how it maps to terminology management in Confluence.
Definition: Data must be traceable to the person (or system) who created, modified, or deleted it, with date and time stamps.
What auditors check: “Who changed this definition? When? Can you prove it?”
Definition: Data must be readable, permanent, and understandable — both when recorded and throughout its retention period.
What auditors check: “Can I read every version of this definition clearly? Will it still be readable in 5 years?”
Definition: Data must be recorded at the time the activity was performed, not reconstructed afterward.
What auditors check: “Was this term defined before it appeared in your documentation, or was the glossary backfilled after the audit was announced?”
Definition: The first-captured record (or a verified true copy) must be preserved. Not a rewrite or uncontrolled transcription.
What auditors check: “Is this the authoritative glossary, or a copy? How do I know this hasn’t been recreated?”
Definition: Data must be correct, truthful, complete in context, and free from undocumented edits.
What auditors check: “Does your definition of ‘adverse event’ match the regulatory source? Has anyone made undocumented changes?”
Definition: All data must be present, including metadata, repeat results, and audit trails. Nothing omitted or deleted.
What auditors check: “Why is this term missing a category? Where are the synonyms? Is the audit trail complete?”
Definition: Data elements must follow expected patterns. Timestamps reference common time sources. Documentation must be orderly across systems.
What auditors check: “Does ‘material adverse change’ mean the same thing in your legal space as in your finance space?”
Definition: Records must be stored on durable, authorized media and maintained intact for the full required retention period.
What auditors check: “Where is this data stored? Will it survive a system migration? Can I see records from 3 years ago?”
Definition: Data must be accessible and retrievable when needed for review, audit, or inspection over its entire lifetime.
What auditors check: “Can you produce your controlled vocabulary right now? With full history? In a format I can review?”
| Principle | Requirement | Compliance Glossary Feature | Status |
|---|---|---|---|
| Attributable | Who did it, when | User ID + timestamp on every action | Live (v4.3.0) |
| Legible | Readable, permanent | Structured fields, version history | Live (v4.3.0) |
| Contemporaneous | Recorded in real time | System-generated timestamps, no backdating | Live (v4.3.0) |
| Original | First record preserved | Append-only version history | Live (v4.3.0) |
| Accurate | Correct, verified | Four-eyes approval + page scanner for undefined terms | Live (v4.3.0) |
| Complete | Nothing omitted | Structured metadata + dashboard compliance score | Live (v4.3.0) |
| Consistent | Same meaning everywhere | Cross-space page scanner + single source of truth | Live (v4.3.0) |
| Enduring | Durable storage | Atlassian Forge infrastructure (SOC 2, ISO 27001) | Live (v4.3.0) |
| Available | Accessible on demand | Audit CSV export (terms + approvals + version history) + dashboard | Live (v4.3.0); PDF export on roadmap |
ALCOA+ is referenced across major pharmaceutical regulators and industry bodies. Primary sources:
| Agency | Document | Year |
|---|---|---|
| FDA | Data Integrity and Compliance with Drug CGMP: Questions and Answers (Guidance for Industry) | 2018 |
| FDA | 21 CFR Part 11 — Electronic Records; Electronic Signatures | 1997 |
| MHRA | ‘GXP’ Data Integrity Guidance and Definitions, Rev. 1 | 2018 |
| WHO | Guideline on Data Integrity (TRS 1033, Annex 4) | 2021 |
| PIC/S | Good Practices for Data Management and Integrity in Regulated GMP/GDP Environments (PI 041-1) | 2021 |
| EMA | Guideline on computerised systems and electronic data in clinical trials (EMA/INS/GCP/112288/2023) | 2023 |
| ISPE/GAMP | GAMP Records and Data Integrity Guide | 2017 |
Last verified: 2026-04-17
Most teams associate ALCOA+ with clinical data, batch records, and lab notebooks. But the principles apply to all controlled documentation in regulated environments — including the glossary that defines the terminology used in those records.
Consider: if your glossary defines “adverse event” for your entire organization, that definition is a controlled record. It needs the same governance as any other GxP data:
Spreadsheet glossaries fail on most of these. A shared Google Sheet has no append-only audit trail, no enforced approval workflow, and no way to prove who changed a definition or when. See how teams in FDA-regulated industries and SOC 2 environments use ALCOA+ principles in practice.
ALCOA stands for Attributable, Legible, Contemporaneous, Original, and Accurate. The “+” extends the mnemonic with four additional principles: Complete, Consistent, Enduring, and Available. Together, these nine principles form the global data integrity standard for regulated industries.
ALCOA is widely attributed to Stan W. Woollen of the FDA’s Office of Enforcement in the early 1990s as a training mnemonic for Good Laboratory Practice (GLP) inspectors. The attribution is consistent across industry sources but is not published on an FDA primary-source page. The “+” principles (Complete, Consistent, Enduring, Available) appear across EMA, MHRA, WHO and PIC/S data integrity guidance between 2010 and 2021.
Yes. Regulators apply ALCOA+ to all GxP data and controlled documentation, not just clinical or lab data. A glossary that defines terminology used in regulated records is itself a controlled record and must meet the same attribution, audit trail, and retention standards.
ALCOA+ is referenced or mandated by the FDA, EMA, WHO, PIC/S, MHRA, and ISPE/GAMP. Key documents include FDA’s 2018 Data Integrity guidance, MHRA’s GxP Data Integrity Guidance Rev. 1 (2018), PIC/S PI 041-1 (2021), and WHO TRS 1033 (2021).
Every principle. Every term. Every audit. Built on Atlassian Forge — tenant data stays inside the Atlassian platform; the app publisher has no runtime access to glossary content.
Evaluate in Confluence Read DocumentationCompliance for Confluence — approved terms, page scanning, and audit evidence for regulated teams in Confluence
Pharma terminology management — controlled vocabulary for GxP documentation, data integrity, and regulatory submissions
GxP documentation — Good Practice documentation controls for pharma, medtech, and biotech teams
Annex 11 terminology — EU GMP Annex 11 controlled vocabulary for computerised systems in regulated environments
Four-Eyes Principle — approval workflows for compliance, QA, GRC, legal, security, and regulatory teams, mapped to SOX, MiFID II, and FDA GMP
FDA Terminology Management — 43-term template for pharma & medtech, mapped to 21 CFR Part 11
Compliance Guide — what auditors check and how we help, mapped to real regulatory standards