GDPR gap analysis: finding what is missing before someone else does
A gap analysis compares what the regulation requires against what you actually do. Its value depends entirely on evidence being tested, not asserted.
ALCOA+ is a checklist for whether data can be trusted. Most failures are not fraud — they are records made later, by someone else, in a file nobody versioned.
The ALCOA principles are the criteria regulators use to judge whether data can be relied on: attributable, legible, contemporaneous, original and accurate. The extended version, ALCOA+, adds complete, consistent, enduring and available. Together they are the shortest useful definition of data integrity.
They apply to any record that supports a regulated decision, not only to laboratory systems. A spreadsheet that feeds a release decision is in scope, and it is usually the weakest link in the chain because nothing about a shared file enforces any of the nine criteria.
Regulatory findings on data integrity are rarely about falsified results. They are about a shared account used by four analysts, a result recorded on paper and typed in later, an audit trail that was never switched on, a spreadsheet emailed between people with no way to tell which copy is current, and original instrument files that were deleted once the report was written.
The pattern is that each was convenient and none was dishonest — which is exactly why the principles are written as properties of the record rather than as rules about behaviour.
The spreadsheet is the classic weak point. It typically fails attributable (who changed this cell?), contemporaneous (when?), original (which copy?) and enduring (where does it live?) in one object. Either bring it under control — versioned, access-controlled, with change history — or move the data into a system that already is.
Where data genuinely belongs in a spreadsheet — reconciliations, calculations, trend tables — the fix is a spreadsheet with the properties the principles demand. Ettex Sheets keeps every change attributable and time-stamped with full version history, so a value can be traced to who entered it and when, and the current version is unambiguous. It does not turn a spreadsheet into a validated laboratory system; where the record is a regulated primary record, that distinction matters and the audit trail requirements are stricter.
Attributable, legible, contemporaneous, original and accurate. ALCOA+ adds complete, consistent, enduring and available.
No. It is a framework used by regulators and inspectors to express data integrity expectations that appear in GMP, GCP and GLP requirements. You are held to the underlying requirements, expressed through these criteria.
Yes. They originated in a paper context and apply to paper, electronic and hybrid records alike, which is why hybrid systems need particular care about which record is original.
A copy verified as complete and accurate against the original, with the verification recorded. It allows the original to be replaced in some circumstances — but the verification has to be evidenced.
A gap analysis compares what the regulation requires against what you actually do. Its value depends entirely on evidence being tested, not asserted.
The risk assessment is where an ISMS is won or lost. Vague risk statements produce controls nobody can test and a certificate that means little.
A risk control matrix maps what could go wrong to what stops it. Most matrices fail because the rows describe processes rather than risks.