"This Record Was Filled Out Yesterday" — One Sentence Exposes a System Gap: Five Steps to Implement Data Integrity (ALCOA+)
A car parts company was undergoing a second-party audit by a customer. During the process audit of the assembly line, the auditor stopped at the process inspection station. He pulled out three process inspection records from a folder, along with the equipment inspection sheet and the first article inspection (FAI) confirmation form, and placed them side by side for about twenty seconds before asking three questions.
First, why are the handwriting, ink color, and pen pressure of these three records from September 12 almost identical, as if they were written in one breath with the same pen within ten minutes? Second, the signature on this calibration record is Zhang Gong, but the shift schedule shows he was on leave that day—so who signed it? Third, the appearance judgment in the system for August 28 shows only "合格" (conforming) in the history column, but the batch was returned by the customer last week—was the judgment changed, and if so, why is it not reflected?
These three questions all point to one term: data integrity. They are not asking whether there are records, but whether these records can be trusted.
Many companies treat records as materials to be reviewed during audits: they are found when auditors come and filed away in folders otherwise. However, from the perspective of customers and certification bodies, records are the evidence chain of quality. If one link in the evidence chain is doubted, the credibility of the entire batch of products must be reassessed—resulting in a minor nonconformity at best, and at worst, triggering a re-inspection of the same batch by the customer, on-site confirmation, or even a suspension of new project quotations. More troubling is that these issues are often not due to "someone not being serious," but rather because the rules themselves are not clearly defined.
1. First, Distinguish: Data Integrity Does Not Equal "Record Authenticity"
"Record authenticity" refers to whether the content is correct—whether what is filled out actually happened at the time. "Data integrity" refers to whether the entire evidence chain is complete and traceable: who recorded it, when, what the original value was, whether it has been modified, who modified it, why, and whether it can still be retrieved in full.
ALCOA is the five basic elements of data integrity, which later expanded into ALCOA+ in highly regulated industries such as pharmaceuticals, food, and medical devices, totaling nine points. Although nine points may sound like a lot, they can all be translated into specific, visible forms in the field.
| Element | Meaning | What a Qualified Record Looks Like | Common Nonconformities |
|---|---|---|---|
| Attributable | Each record points to a specific person | Handwritten signature or unique electronic account, traceable to an individual | Proxy signatures, shared accounts, printed signatures |
| Legible | Permanent, easy to read, and not erasable | Pens that do not easily fade, with visible corrections | Pencil writing, correction fluid, illegible handwriting |
| Contemporaneous | Recorded at the time the data is generated | Recorded on-site, with times consistent with process times | Records filled out in bulk at the end of the shift, copied in batches |
| Original | Retains the original value of the first record | Actual measurement values, original curves, original images | Only "合格" (conforming) or "OK" written, only conclusions without data |
| Accurate | Data is true, calculations are correct, and there are no errors or omissions | Units, rounding, and judgments consistent with inspection standards | Incorrect units, inconsistent rounding, judgments not aligned with standards |
| Complete | No missing fields | Each field has a value, no blanks, no skipped lines | Entire sections left blank, items skipped and marked as conforming |
| Consistent | No contradictions between records | Batches, dates, and parameters align with upstream and downstream records | Record dates do not match material input dates, quantities do not match accounts |
| Enduring | Not lost or damaged during the retention period | Durable media, backed up offsite or in the system | Thermal paper fading, oil stains, single-point storage on USB drives |
| Available | Can be fully retrieved and read when needed | Indexed, searchable by batch or date | Sealed without a list, chaotic naming of scanned documents, data cannot be exported from old systems |
When you connect these nine points, you will see that they all point to the same thing: records cannot be "text compiled after the fact," but must be "natural traces left during the work process."
This is also why this issue has become increasingly acute in recent years. On one hand, the way customers conduct audits has changed: they used to check whether "documents exist and are signed," but now they follow an evidence chain, asking who, when, and with what equipment the data was measured. On the other hand, moving paper records into systems and onto tablets has not eliminated the problems—deleting a data entry or overwriting a field is more隐蔽 (covert) than tearing out a page of paper. ISO 9001 clause 7.5 requires documented information to be "protected and maintained," while IATF 16949 has more detailed requirements for the traceability of records. Different industries, such as medical devices, food, and automotive safety components, have their own regulatory constraints. The wording of the clauses may differ, but they all point to the same thing: records must be trustworthy evidence.
2. Five-Step Implementation Method: Connecting the Nine Points to the Field
Step One: Identify "Records That Cannot Be Wrong" and Avoid Averaging Efforts.
A comprehensive approach often leads to a comprehensive应付 (patch-up). First, classify records into three categories and focus on managing the first two.
| Category | Typical Records | Management Requirements |
|---|---|---|
| Release and Judgment | First article inspection, process patrol inspection, final inspection, test reports, re-inspection after rework or repair | Fully implement data integrity requirements, prohibit post-event compilation |
| Traceability and Compliance | Batch production records, calibration certificates and metrology confirmation, safety characteristic data, special process parameters | Fully implement, and must be traceable to the finished product batch number |
| General Operations | Daily equipment inspections, cleaning records, energy consumption registration | Fields can be simplified, but must still be recorded synchronously, with names and no alterations |
Output a "Critical Record List," with each record on a separate line. Fields include: record name, category, medium (paper/system), retention period, recorder, verifier, and disposition method upon expiration. The list itself is the best tool for internal audits.
There are two additional actions that are often overlooked. First, the retention period must be clearly stated based on: customer contract terms, regulatory requirements, product life cycle, and certification rules—taking the longest of these, rather than a blanket "一般存三年" (three-year retention). Second, the list should indicate "谁是第一责任人" (who is the primary responsible person). If a record has issues, the first person to be questioned should be the person in that position, not the quality department—otherwise, all rules will eventually degrade into "QC copies everything for everyone."
Step Two: Use Form Design to Block Errors at the Filling Site.
Most data integrity issues are actually forced by poor form design. The following four changes are the most effective.
- Fields that require actual measurement values should not allow "合格/不合格" (conforming/nonconforming) as a shortcut; the judgment field should be separate, forcing the filler to write the data before making a judgment.
- Field order should be consistent with the work sequence, so that operators fill out the form from top to bottom, which is equivalent to following the process step by step.
- Correction rules should be written in the form footer: single-line strike-through, write the correct value next to it, sign, add the date, and write the reason if necessary. Correction fluid, tearing out pages, and re-copying the entire form are strictly prohibited.
- Each field should have a "what to write in case of abnormality" design, otherwise, operators will fill in "正常" (normal) when encountering abnormalities.
Step Three: Fix "Who Records, Who Signs, Who Approves," and Provide Alternatives.
- Recorder: must be the person who actually performed the task or conducted the inspection; Verifier: team leader or independent inspector; Approver: only set in scenarios such as conditional acceptance or deviation handling.
- Proxy signatures are prohibited, but a legal alternative path must be designed. When employees are on leave or changing shifts, a person with the same level of qualification should sign and mark "代" (proxy) and the authorization basis next to the signature. The purpose of prohibiting proxy signatures is not to halt production, but to make responsibility visible.
- Handwritten signatures or verified electronic signatures are required; printed signatures, stamps, and shared system accounts are not accepted.
- Supporting rules: who is qualified to record which type of data should be written into the job qualification and authorization table. When qualifications expire (e.g., vision recheck overdue), recording permissions should be suspended.
Step Four: After Digitization, Three Things Must Be Added.
Replacing paper with a system does not automatically ensure data integrity. At least three things must be confirmed when the system goes live.
- Permission Grading: separation of input, modification, and deletion permissions. Frontline workers can only input, team leaders can correct, and deletion permissions are generally not given to the field, with all deletions leaving a trace.
- Audit Trail: automatic recording of who, when, which field was modified, and the before and after values, which cannot be turned off. This is the easiest thing for suppliers to skip and the easiest for customers to catch during audits.
- Retention of Original Data: local data, curves, and images from instruments should not be reduced to just conclusions. Automatic overwriting of hardness tester memory, non-retention of visual inspection images, and exporting only judgment results from testing equipment are all typical cases of original data loss.
Two other minor issues are often overlooked: system servers across the factory should be uniformly calibrated, and no one should be allowed to modify the system time; reports exported from the system should include a unique number and export time to avoid using "screenshots as evidence."
Step Five: Invert One Chain Each Quarter and Make It a Routine.
There is no need to wait for customer audits. Select a batch that has already been shipped and trace it backward from the finished product batch number: shipping record → finished product inspection → process inspection → first article inspection → equipment parameters → material batch → supplier report → inspection record of the material batch → calibration status of related measuring tools. Any break in the chain or the need to "find someone to fill in" indicates a data integrity gap.
It is recommended to include this rule in the internal audit plan: check one batch each quarter, and conduct one check before the customer audit. The results of the trace should not only record problems but also be fed back into the form or system rules—otherwise, the same issue will reappear in the next quarter.
Making Rules Effective: Three Things More Important Than Training. After the rules are set, what truly determines success or failure is often not the employees' awareness, but three specific actions: first, write the rules in a place visible at the filling site—form footers, workstation boards, and system input interface prompts, rather than locking them in management documents; second, provide appropriate tools at the site, such as pens that do not easily fade, record paper with timestamps, and equipment that can automatically store original data—without the right tools, the rules are just empty words; third, provide a channel for issues—when operators find unreasonable fields, redundant fields, or duplicate forms, they should be able to report them and have them actually fixed. By doing these three things, employees will not see data integrity as "another check added by the quality department," but as something that makes their work easier.
Case: One Trace Reveals Three Gaps. In the first quarterly trace check after implementing the mechanism, a certain electronics manufacturing company found three typical issues: 17 records were missing or had proxy signatures for the verifier; the calibration status of 2 testing devices was missing in the trace chain, with 9 days of "超期使用" (overdue use) unnoticed; the judgment process for one batch of products only left the "合格" (conforming) conclusion, and the original measurement data could not be reproduced. The cost of the three corrective actions was not high—clarifying the responsibility for completing verifier signatures, adding calibration expiration reminders to the equipment ledger, and requiring testing equipment to retain original data files. In the customer audit six months later, the number of record-related nonconformities dropped from 4 to 0. The real benefit is not the audit score, but the ability to present a complete chain of evidence when the batch is questioned.
3. Six Common Pitfalls
Pitfall One: Treating "Filling in Records Later" as Forgery, Leading to Concealment. Filling in records later is not necessarily a violation, but doing so without leaving a trace is. The proper approach is: allow post-event recording, but it must clearly state the reason for the post-event recording, the actual occurrence time, the actual recording time, and be signed by the verifier. Clarifying the rules prevents operators from covering up with corrections and re-copying.
Pitfall Two: Focusing Only on Paper Records and Ignoring System Modifications. Tearing out a page from a paper record leaves a visible trace, but covering a field in a system is almost silent. If the system lacks an audit trail or if the audit trail can be turned off during an audit, this itself is a nonconformity.
Pitfall Three: Using "√" Instead of Data. Long-term use of judgment symbols instead of actual measurement values in fields that require them is equivalent to voluntarily giving up original data. When the customer returns the product and needs to reproduce the judgment process, all you have is the word "合格" (conforming), which cannot be used to self-justify.
Pitfall Four: Correction Fluid, Tearing Out Pages, and Re-copying the Entire Form. These three practices are often directly classified as "forging records" during customer audits, which is a more serious issue than "incomplete records." A single-line strike-through with a signature has almost zero cost.
Pitfall Five: Original Data in Equipment Automatically Overwritten. Automatic overwriting of hardness tester memory, retention of only judgment results in visual systems, and exporting only Excel data from testing machines without saving original files are all hidden gaps. The requirement for "原始数据可导出、可留存" (exportable and retainable original data) should be written into technical specifications during procurement and acceptance.
Pitfall Six: Records Stored but Not Accessible. Sealed boxes without lists, scanned documents without naming rules, data that cannot be exported from old systems, and single copies stored offsite—all these will be exposed during a customer surprise audit. The solution is straightforward: a list of contents, a naming convention, an offsite backup, and an annual "actual retrieval drill."
4. One Sentence Summary
The key to data integrity is not how neatly the records are written, but whether each record naturally carries the four pieces of information: who, when, the original value, and whether it has been modified—defining clear rules, designing forms correctly, and inverting one chain each quarter are more effective than any full-staff training.
The credibility of records depends on the rules, not the attitude.
Knowledge code: 2.3.1
Version: v20261007
Author: QTank QTank is dedicated to providing systematic professional knowledge, methodologies, and practical tools for quality management practitioners, helping companies continuously improve their quality capabilities.