What is good documentation practice?. The complete guide to data integrity, ALCOA+ principles, source documentation, and GCP R3 compliance
What is good documentation practice? In the world of clinical trials, we have a golden rule: “If it is not documented, it did not happen”. But the regulators are raising the bar. It is no longer enough to just have a piece of paper with a signature.
With the release of the ICH E6 R3 guideline, the focus has shifted. We are now in the era of “Data Life Cycle” and “Quality by Design”. If you want to survive an audit today, you need to master Good Documentation Practice (GDocP) and understand the deep connection between your notes and Data Integrity.
In this guide, we will break down exactly what you need to know to protect your study, your patients, and your career, including the ALCOA+ principles explained in plain language, source documentation rules, the most common mistakes, and what the latest ICH GCP training standards require of you.
What is Good Documentation Practice?
Good Documentation Practice is a set of standards used in the pharmaceutical and medical device industries to ensure that all records are accurate, complete, and trustworthy. Think of it as the “grammar” of clinical research.
When you follow GDocP, you ensure that anyone, an auditor, a fellow researcher, or a regulator, can look at your files and reconstruct exactly what happened during a study without needing to ask for explanations.
Good Documentation Practice definition
The Good documentation practice definition refers to the processes for creating, maintaining, and archiving documents that support a clinical trial. According to the ICH E6 R3, documentation must allow for the “accurate reporting, interpretation, and verification” of trial results.
In simple terms: it is the way to prove that science is real and the patients are safe.
What are the fundamental principles of good documentation practice?
Good documentation practice is not one rule; it is a framework of principles that work together. Understanding these principles is the first step to applying them correctly in your daily clinical research work.
The core requirement is straightforward: every record must be created in a way that it can stand alone. An auditor, inspector, or colleague who was not present when the event occurred must be able to read the document and fully understand what happened, when it happened, who did it, and why.
Regulatory agencies, including the FDA, EMA, and MHRA, use these principles as the benchmark during inspections. Failing to meet them does not simply result in a finding; it calls into question the validity of your entire study.
The 5 W’s of documentation
A practical way to test whether your documentation is complete is to apply the 5 W’s framework. Every entry in a clinical trial record should answer:
- Who: Who performed the action or collected the data? Name, signature, and role must be clearly identifiable.
- What: What was done, measured, or observed? The data itself must be specific and unambiguous.
- When: When did the event occur? Date and time must be recorded at the moment of the event, not reconstructed later.
- Where: Where did it happen? The study site, patient location, or system used must be documented.
- Why: Why was the action taken, especially when it deviates from the expected? Corrections, late entries, and protocol deviations all require a stated reason.
If your documentation cannot answer all five questions, it is incomplete — and incomplete records are among the most frequently cited findings during FDA and EMA inspections.
The five C’s of good clinical documentation practice
Another widely used framework in clinical documentation is the five C’s. Good documentation practice requires that every record be:
- Clear: Written in plain, unambiguous language that leaves no room for interpretation.
- Concise: Including all necessary information without padding or repetition.
- Complete: Covering all data points required by the protocol, with no blank fields left unexplained.
- Correct: Accurately reflecting the observation, measurement, or event as it occurred.
- Consistent: Matching the information found in related documents, such as source records, case report forms (CRFs), and the trial master file.
These two frameworks, the 5 W’s and the five C’s, are taught in every credible, good documentation practice training program because they give you a fast, practical checklist to apply before you sign any document.
The heart of the matter: What is data integrity?
Documentation is the act, but Data Integrity is the goal. You can have thousands of pages of documents, but if they are not reliable, they have no integrity.
Data integrity definition
The modern Data integrity definition is the degree to which all data are complete, consistent, accurate, trustworthy, and reliable throughout their entire life cycle.
The ICH E6 R3 (Section 1.10) explicitly states that data integrity is a fundamental pillar of Good Clinical Practice. It requires that data be protected from unauthorized changes and that every action be traceable.
What is the ALCOA principle in GCP?
ALCOA is the foundational acronym used in GCP to define the minimum standards for data integrity in clinical research. It was first introduced by the FDA in the early 1990s and stands for:
- Attributable
- Legible
- Contemporaneous
- Original
- Accurate
In GCP, the ALCOA principle means that every data entry in a clinical trial, whether it is a patient’s vital sign, a dosing record, or an adverse event note, must be clearly attributed to the person who recorded it, readable, recorded in real time, preserved as the original entry, and factually accurate.
The FDA’s 2016 guidance document on data integrity references ALCOA as the baseline expectation for all regulated data in pharmaceutical and clinical research environments. If your records fail the ALCOA test, you are not just at risk of an audit finding, you are at risk of having your entire study data invalidated.
ALCOA vs ALCOA+ vs ALCOA++: understanding the differences
One of the most common sources of confusion in clinical research is the difference between ALCOA, ALCOA+, and ALCOA++. Here is a clear breakdown.
ALCOA: the original 5 principles
The original five-letter acronym from the FDA, Attributable, Legible, Contemporaneous, Original, Accurate, is the baseline standard that has been in place since the 1990s and remains the starting point for all data integrity discussions in regulated environments.
ALCOA+: the ICH E6 R3 standard (8 principles)
ALCOA+ adds three more attributes to address the growing complexity of clinical trials and the expanded use of electronic systems:
- Complete: All data must be present. No data point can be selectively excluded, even if it is a failed result or a protocol deviation.
- Consistent: Data must be internally coherent and follow logical timelines.
- Enduring: Records must be durable and legible for the entire required retention period, whether on paper or in a validated electronic system.
ALCOA+ is the standard referenced in the ICH E6 R3 guideline and in current regulatory guidance from the EMA and FDA. If you are enrolled in ICH GCP training today, ALCOA+ is what you will be assessed on.
ALCOA++: the industry best practice (9 principles)
ALCOA++ adds one final attribute to the ALCOA+ list:
- Available: Data must be readily accessible and retrievable for the duration of the required retention period, particularly during inspections and audits.
This is the standard increasingly referenced in industry practice, including the WHO Technical Report Series No. 996. For practical purposes, ALCOA++ is what most pharmaceutical companies and good documentation practice certification programs now train professionals to meet.
| Standard | Principles | Regulatory context |
| ALCOA | 5 | Original FDA baseline (1990s) |
| ALCOA+ | 8 | ICH E6 R3, EMA, FDA (current) |
| ALCOA++ | 9 | Industry best practice, WHO |
Mastering the ALCOA++ principles
The industry uses a famous acronym to define what data integrity means: ALCOA++. If your documentation doesn’t meet these nine standards, it is a red flag for auditors:
- Attributable: You must know who did the work. Every entry must have a signature and a date.
- Legible: If an auditor can’t read your handwriting, the data doesn’t exist. This includes electronic fonts and clear audit trails.
- Contemporaneous: You must record the data at the time the event happens. Never wait until the end of the day to “fill in the blanks.”
- Original: The first record is the most important. Avoid “shadow files” or scrap paper.
- Accurate: The record must match the observation. No rounding up or “guessing” numbers.
- Complete: All data, including failed tests or deleted entries, must be part of the record.
- Consistent: Data must follow a logical date and time sequence.
- Enduring: Records must last. Fading ink or thermal paper that turns black in the sun are major GCP violations.
- Available: You must be able to find the document immediately during an inspection.
What are source records in GCP?
Source records are one of the most important and most frequently misunderstood concepts in good documentation practice. The ICH E6 R3 guideline defines source records as “Original documents or data (which includes relevant metadata) or certified copies of the original documents or data, irrespective of the media used. “
In plain language, source records are the first place where data is recorded. They are the foundation upon which the entire clinical trial is built.
What counts as source records in GCP?
Source records in clinical trials can include, but is not limited to:
- trial participants’ medical/health records/notes/charts;
- data provided/entered by trial participants (e.g., electronic patient-reported outcomes (ePROs));
- healthcare professionals’ records from pharmacies, laboratories and other facilities involved in the clinical trial;
- and data from automated instruments, such as wearables and sensors.
- Investigator notes and physician assessments taken at the time of the visit
- Signed informed consent forms
A critical principle: the first place data is recorded is always the source. If a nurse writes a blood pressure reading on a notepad and then transfers it to the CRF, that notepad is the source document. Destroying it, or simply discarding it, is a GCP violation.
The ICH E6 R3 also reinforces that when electronic systems are used, the audit trail of those systems becomes part of the source documentation. This means that your EDC system logs, edit histories, and user access records all count as source data subject to inspection.
Understanding what constitutes source documentation and how to retain it correctly is a key competency covered in our Good Documentation Practice and Data Integrity training course.
What are the 5 characteristics of quality documentation?
Quality documentation in a clinical trial environment must be evaluated against five core characteristics. These are higher-level attributes that define the overall quality of a document system, distinct from the operational frameworks like the 5 W’s or ALCOA+:
- Trustworthiness: The document accurately represents the event as it occurred. No alterations, no backdating, no fabrication.
- Reliability: The document was created by a competent and authorized person following a defined, approved procedure.
- Integrity: The document is complete and unaltered. If changes were made, they were transparent and fully traceable.
- Authenticity: The document is genuine; it is what it claims to be, created by the person who claims to have created it, at the time stated.
- Usability: The document can be retrieved, read, and understood by any authorized person, including a regulatory inspector, at any point during the required retention period.
These five characteristics align with the international standard for records management (ISO 15489) and are increasingly referenced in pharmaceutical regulatory guidance alongside ALCOA+.
Data integrity vs Data quality: The big confusion
This is where many professionals get tripped up. Understanding data integrity vs data quality is essential for high-level management.
- Data Quality refers to how well the data fits the purpose of the study. For example, if you used a calibrated thermometer to take a temperature, the quality is high.
- Data Integrity refers to the security and truthfulness of that record. If you took the temperature correctly (high quality) but then someone changed the number on the paper to make it look “better” (low integrity), the trial is compromised.
Quality is about the science; integrity is about the truth.
Good documentation practice examples: 5 common mistakes to avoid
Let’s look at how to handle common situations using good documentation practice, and the five mistakes that most often lead to inspection findings.
- Mistake 1: Using correction fluid: Never use white-out, tape, or any method that obscures the original entry. Draw a single line through the error, write the correct information next to it, and add your initials, the date, and a brief reason (e.g., “transcription error”).
- Mistake 2: Leaving blank fields: Never leave a field empty in a Case Report Form (CRF). If data is not available, write “N/A” (Not Applicable) or “N/D” (Not Done). A blank field with no explanation is indistinguishable from a missed observation.
- Mistake 3: Backdating entries: If you forgot to record something the previous day, record it today, labeled clearly as a “Late Entry” with an explanation of why it was missed. Never backdate. Auditors are trained to detect it through ink analysis, system timestamps, and logical inconsistencies. It is considered fraud.
- Mistake 4: Using unauthorized abbreviations: All abbreviations must appear in an approved abbreviation list specific to the trial. Personal shorthand that is not in the study’s glossary creates ambiguity and is a direct violation of good documentation practice.
- Mistake 5: Failing to document corrections in electronic systems: In EDC systems and electronic health records, all corrections must go through the proper audit trail function. Deleting and re-entering data without documenting the reason is the electronic equivalent of data falsification.
What is changing with ICH E6 R3?
The latest updates to the GCP guidelines have added new layers to our documentation duties. Here is what is different:
- Computerized systems and audit trails
The ICH E6 R3 (Section 4.10) places a massive emphasis on electronic records. You are now required to maintain a “certified copy” of all data. More importantly, your electronic systems must have an audit trail.
An audit trail is a digital “diary” that records every single change made to a file. It shows who changed it, when they changed it, and why. If you turn off the audit trail, you have destroyed your data integrity. - Decentralized trials and remote data
The Annex 2 addresses the rise of “modern” trials. If you are collecting data via an app or a wearable device (Digital Health Technologies), the documentation requirements are even stricter.- You must document the provenance of the data (where it came from).
- You must prove that the patient was the one who actually entered the data.
- You must document the training provided to patients to ensure they know how to use the tech correctly.
Common Good documentation practice examples
Let’s look at how to handle common situations using GDocP.
- The Error Correction: Never use correction fluid (white-out) or tape. Draw a single line through the error, write the correct info next to it, and add your initials, the date, and a reason for the change (e.g., “entry error”).
- The Blank Space: Never leave a field empty in a Case Report Form (CRF). If data is not available, write “N/A” (Not Applicable) or “N/D” (Not Done) so it’s clear you didn’t just forget.
- The Late Entry: If you forgot to record something yesterday, record it today. Label it clearly as a “Late Entry” and explain why it was missed. Never, ever backdate a document.
Why failing GDocP is a career-killer
Bad documentation isn’t just a “small mistake.” In the eyes of the FDA and EMA, it is a sign of a “lack of control.”
- Regulatory Action: Inadequate documentation leads to Warning Letters and Form 483s. This can stop a drug’s approval.
- Scientific Rejection: If an auditor finds that 10% of your records have integrity issues, they might assume the other 90% are also fake. They will throw out your entire study.
- Patient Risk: If a nurse documents a dose incorrectly, the next shift might give a double dose. Poor GDocP kills people.
Investing in good documentation practice training and investing in an ICH GCP certification are the only ways to prove you have the skills to handle these risks.
Key takeaways
- Good documentation practice (GDocP) is the set of standards that ensures all clinical trial records are accurate, complete, and trustworthy throughout their entire life cycle.
- The ALCOA principle (5 principles) is the original FDA baseline; ALCOA+ (8 principles) is the current ICH E6 R3 standard; ALCOA++ (9 principles, adding “Available”) is the industry best practice most companies train to today.
- Source documentation includes any record where data is first captured — from hospital charts and lab reports to EDC system entries, patient diaries, and digital health app outputs.
- The 5 W’s (Who, What, When, Where, Why) and the five C’s (Clear, Concise, Complete, Correct, Consistent) are practical frameworks for verifying your documentation before you sign it.
- The 5 characteristics of quality documentation, trustworthiness, reliability, integrity, authenticity, and usability, define what an inspection-ready record system looks like at a systemic level.
- The five most common good documentation practice mistakes — correction fluid, blank fields, backdating, unauthorized abbreviations, and improper electronic corrections are all preventable with proper training.
- ICH E6 R3 has raised the bar for electronic records, audit trails, and decentralized trial data, making GDocP training more important than ever for clinical research professionals.
Conclusion
Good documentation practice is not bureaucracy — it is the backbone of clinical science. Every entry you make in a clinical trial record is a link in a chain of trust between you, the regulator, the scientific community, and most importantly, the patients who volunteered for that study.
The evolution from ALCOA to ALCOA+ to ALCOA++ reflects a simple truth: as clinical trials become more complex, the documentation standards must rise to match them. Understanding source documentation, mastering the ALCOA+ principles, knowing the five common mistakes that destroy data integrity, and applying frameworks like the 5 W’s and the five C’s are not optional skills, they are the foundation of a professional career in clinical research.
If you are preparing for an audit, renewing your GCP certificate, or simply trying to do your job to the highest standard, the investment in proper good documentation practice training will pay for itself the first time an inspector walks through your door.
Are you ready to master good documentation practice?
Enroll in our Good Documentation Practice and Data Integrity course and receive an immediate certificate upon successful completion. This good clinical practice certification training is fully aligned with ICH E6 R3, built for busy professionals, and developed by industry practitioners with direct regulatory inspection experience. Start your Good Documentation Practice training today.
FAQs: What is good documentation practice and data integrity
What is the most common documentation error?
Backdating. It is tempting to “fix” a date so it appears that work was completed on time. However, auditors are trained to detect backdated entries through ink analysis, system timestamps, and logical inconsistencies between documents. Backdating is considered fraud and can result in the loss of your ICH GCP certification and formal regulatory sanctions.
What is the ALCOA principle in GCP?
ALCOA stands for Attributable, Legible, Contemporaneous, Original, and Accurate. It is the foundational five-principle framework introduced by the FDA to define the minimum data integrity standards in regulated research. It has since evolved into ALCOA+ (which adds Complete, Consistent, and Enduring) and ALCOA++ (which adds Available). ALCOA+ is the version formally referenced in the current ICH E6 R3 guideline.
What is the difference between ALCOA and ALCOA+?
ALCOA has 5 principles and represents the original FDA baseline from the 1990s. ALCOA+ has 8 principles, adding Complete, Consistent, and Enduring to reflect the increased complexity of modern clinical trial documentation, particularly electronic systems. ALCOA++ adds a ninth principle, Available, which is now the standard most pharmaceutical companies train to internally.
What is source record in GCP?
Original documents or data (which includes relevant metadata) or certified copies of the original documents or data, irrespective of the media used. This may include trial participants’ medical/health records/notes/charts; data provided/entered by trial participants (e.g., electronic patient-reported outcomes (ePROs)); healthcare professionals’ records from pharmacies, laboratories and other facilities involved in the clinical trial; and data from automated instruments, such as wearables and sensors.
Source records refers to the original records where clinical trial data is first captured, including hospital charts, laboratory reports, EDC system entries, patient diaries, and digital health device outputs. Under ICH E6 R3, the audit trail of any electronic system used to capture source data is also considered part of the source records. Destroying or failing to retain source records is a critical GCP violation.
What are the fundamental principles of good documentation practice?
The fundamental principles are captured in two practical frameworks: the 5 W’s (Who, What, When, Where, Why) and the five C’s (Clear, Concise, Complete, Correct, Consistent). Together with the ALCOA+ attributes, they define what a compliant, inspection-ready clinical record looks like. All of these principles are covered in depth in our Good Documentation Practice training course.
Does GDocP apply to electronic health records (EHR)?
Yes. While EHRs are used for clinical care, when that data is used for a trial, it must meet GCP standards. ICH E6 R3 Annex 2 specifically discusses how to ensure “Fitness for Purpose” when pulling data from hospital systems into a clinical trial context. The audit trail of the EHR system is considered part of the source documentation.
What is a "Certified Copy"?
A certified copy is a duplicate of an original record that has been verified — typically by a dated signature — to contain the same information as the original. This concept is critical when transitioning from paper-based to digital record systems, or when transmitting records between investigator sites and sponsors.
Is data integrity only the Sponsor's responsibility?
No. While the sponsor is responsible for providing validated systems and data governance frameworks, the investigator is responsible for the integrity of the data at the site level. Every member of the site team, from the principal investigator to the data entry coordinator, must be trained on good documentation practice and data integrity.
