Learn GLP computerized systems requirements for validation, access controls, audit trails, backups, archiving, ALCOA+ and 21 CFR Part 11.
Computerized systems support many Good Laboratory Practice (GLP) activities, including instrument data capture, sample tracking, calculations, study documentation, and archiving. Their records must allow a study to be reviewed and reconstructed. FDA’s GLP regulation recognizes data generated by automated systems and requires controls for recording, changing, retaining, and retrieving study records. OECD guidance recommends managing computerized systems through a risk-based lifecycle.
Key takeaways
- Validate a computerized system for its intended use and document its status before relying on it for regulated study work.
- Control user access, system changes, data processing, backups, and record retention.
- Preserve original data and make changes traceable, dated, and attributable to the responsible person.
- Apply 21 CFR Part 11 controls when electronic records or signatures fall within its scope.
- Treat ALCOA+ as a practical data-integrity framework, not as a phrase expressly listed as a checklist in 21 CFR Part 58. https://iampharmacist.com/complete-testing-guide/
What GLP requires from computerized systems
Under 21 CFR Part 58, GLP records can include computer printouts, magnetic media, and data from automated instruments. The regulation requires written procedures for data handling, storage, and retrieval; suitable equipment; and records that can be retained and accessed. For automated data, the person responsible for direct input must be identified. Changes must preserve the original entry, state the reason for the change, include the date, and identify the responsible person.
Facilities should translate these requirements into system-specific procedures. For example, a procedure for an analytical instrument may explain how analysts start a run, review integrations, handle failed injections, document reprocessing, and transfer complete records to the study archive. A broader SOP framework can help teams keep those procedures controlled and available.
Individual user accounts and role-based permissions are important controls for attributing work and limiting access. Configure permissions so routine users can perform their assigned tasks without changing system settings or removing records. Protect hardware and data storage from conditions that could affect operation or availability, following the system’s intended operating environment and facility procedures.
Risk-based validation over the system lifecycle
Validation should demonstrate that the system works as intended and produces records that can be reviewed and retrieved. OECD guidance recommends a lifecycle approach based on system complexity and data-integrity risk. The exact package should suit the intended use; IQ, OQ, and PQ are common validation stages, but GLP does not prescribe one universal test script or require those labels.
| Validation activity | What to document or test |
|---|---|
| Intended use and requirements | Define functions, users, data, interfaces, access needs, and retention needs in the URS. |
| Risk assessment | Identify failures that could affect study conduct, data integrity, or record retrieval; document controls and test depth. |
| Installation checks | Confirm approved software versions, hardware, configuration, and connections are installed as intended. |
| Operational testing | Challenge calculations, permissions, audit-trail functions, error handling, interfaces, and data export with suitable test cases. |
| Performance testing | Demonstrate that representative workflows perform reliably for the intended GLP use. |
| Release and maintenance | Summarize results, resolve deviations, approve release, and control changes, backups, restoration, and periodic review. |
A validation record should link requirements to test evidence and identify any unresolved issue and its impact. Validation continues after release: software updates, configuration changes, new interfaces, or changes to intended use may require documented assessment and testing.
Apply ALCOA+ across electronic records
ALCOA+ helps teams assess whether records remain trustworthy through creation, processing, retention, and retrieval. OECD describes ALCOA as attributable, legible, contemporaneous, original, and accurate, with “+” commonly referring to complete, consistent, enduring, and available records.
In practice, a GLP laboratory should be able to establish who performed an action and when; read the record throughout its retention period; connect it to the activity when it occurred; preserve the original data or a verified copy; and account for changes. Related ALCOA+ data integrity principles can guide local procedures and staff training.
Audit trails, backups, and quality assurance
Where Part 11 applies, its controls include system validation, access restrictions, accurate copies, and secure computer-generated, time-stamped audit trails. Changes must not obscure previously recorded information, and audit-trail documentation must be retained for at least as long as the related electronic record. FDA’s guidance explains that Part 11 applies to electronic records maintained under FDA record requirements; it also notes that electronic and paper records may coexist if the underlying requirements are met.
Part 58 separately requires a Quality Assurance Unit (QAU) that is independent of the study personnel and monitors whether records, equipment, methods, and controls conform to GLP. Provide the QAU with appropriate access to review study records and relevant system history while protecting records from unauthorized changes. Backups and restoration checks are practical controls for protecting access to data; set their frequency and scope through documented risk assessment and procedures. Part 58 requires orderly storage and expedient retrieval of records, but it does not set one universal backup schedule.
GLP Part 58 and 21 CFR Part 11: what is the difference?
| Topic | 21 CFR Part 58 | 21 CFR Part 11 |
|---|---|---|
| Main purpose | Governs the conduct, documentation, oversight, and archiving of covered nonclinical laboratory studies. | Sets controls for electronic records and electronic signatures when they fall within its scope. |
| Records covered | Paper and electronic study records, including automated data. | Electronic records and signatures. |
| Key responsibilities | Study director, testing-facility management, and independent QAU. | Controls for system access, validation, audit trails, signatures, and record copies. |
| Relationship | Provides the GLP study and record requirements. | Applies alongside relevant FDA “predicate” requirements; it does not replace Part 58. |
Part 11 does not require cryptographic signatures for every electronic record. Its requirements depend on the record and how it is used. See the FDA Part 11 Scope and Application guidance.
Practical GLP computerized systems audit checklist
- Are user accounts assigned to individuals, with permissions limited to job duties?
- Are system changes, data edits, and reprocessing documented without obscuring the original record?
- Can staff retrieve complete records, including relevant metadata and processing history, for inspection?
- Are system-specific procedures current for operation, maintenance, data handling, backup, and recovery?
- Are users trained for their assigned tasks, with training and experience records maintained?
- Are archive access, indexing, retention, and retrieval responsibilities defined?
- Does the QAU have documented access and procedures to conduct independent study oversight?
Frequently asked questions
1. What are GLP computerized systems?
They are hardware and software used to support GLP study activities, such as automated data collection, laboratory information management, calculations, electronic records, and archiving.
2. Does 21 CFR Part 58 allow electronic raw data?
Yes. The GLP regulation’s raw-data definition includes computer printouts, magnetic media, and recorded data from automated instruments.
3. Does GLP require computer system validation?
Systems should be suitable for their intended use and managed so that study data remain reliable and reconstructable. OECD guidance recommends a documented, risk-based lifecycle validation approach.
4. Are IQ, OQ, and PQ specifically required by Part 58?
Part 58 does not prescribe those exact stages. They are commonly used to organize installation, operational, and performance evidence in a validation lifecycle.
5. Does every GLP system need an audit trail?
Part 58 requires automated data changes to preserve the original entry, state the reason, include the date, and identify the responsible person. Where Part 11 applies, its audit-trail provisions also apply to covered electronic records.
6. Must an audit trail record the reason for every change?
For changes to automated data covered by 21 CFR 58.130(e), the reason must be indicated. Part 11 separately requires secure, time-stamped audit trails for covered record actions.
7. What does ALCOA+ mean?
It summarizes data-integrity attributes: attributable, legible, contemporaneous, original, accurate, complete, consistent, enduring, and available.
8. Does Part 11 replace GLP requirements?
No. Part 11 addresses electronic records and signatures within its scope. Part 58 governs the GLP study and its records, whether they are paper, electronic, or a permitted combination.
9. How often should a laboratory test data backups?
Part 58 does not set one universal backup frequency. Facilities should define and document backup and restoration checks according to system and data risk.
10. What should be retained for a GLP computerized system?
Retain required study records and raw data, along with information needed to interpret, retrieve, and reconstruct them. Apply the relevant Part 58 retention requirements and any other applicable record rules.



