Part of The GMP Training AcademyAll GMP courses
All guides
Previews Module 6 10 minUpdated 15 Sept 2026

Data governance, culture and remediation: what to do when the finding is about behaviour

Why data integrity is a management responsibility under PIC/S PI 041-1 and EU GMP Chapter 1, the signals inspectors read as culture, how to assess your own data risk, and what a remediation plan regulators accept looks like.

Most data integrity failures are not fraud. They are people under pressure doing what the system makes easy: completing the record at the end of the shift, using the login that is already open, aborting a run that is heading the wrong way. The controls in the previous guides make those things harder. Governance is about the pressure. The regulators are explicit that it belongs to senior management, and an inspection that finds a behavioural failure will look for what management did to cause it and what they will do to fix it.

What the guidance puts on management

PIC/S PI 041-1 section 6 sets out data governance as a system: a policy owned by senior management, a risk-based approach to data criticality and vulnerability, defined roles, training, and monitoring. It is explicit that management should create a working environment that encourages open reporting of errors and does not set targets that can only be achieved by compromising data. EU GMP Chapter 1 says the same in fewer words: 1.5 makes senior management responsible for the pharmaceutical quality system and 1.6 requires them to review it. PI 041-1 section 6 adds that the organisation's culture is considered during inspection, and section 12 on remediation, with the EMA data integrity Q&A, completes the picture.

None of this is abstract. When an inspector interviews an operator and asks 'what happens here if you make a mistake in the batch record', the answer tells them more about data integrity than any procedure. When they ask a QC analyst 'has anyone ever asked you to re-run a sample without a deviation', the pause before the answer is read too.

The signals inspectors read as culture

  • How errors are handled. A site where a corrected entry is normal and a hidden one is unthinkable has a culture. A site where people are disciplined for errors has one too, and it is the wrong one.
  • Whether targets can be met honestly. Release deadlines, right-first-time metrics and laboratory throughput targets that are only achievable by omitting or altering data are a governance failure, not an individual one.
  • Whether people can explain why. Staff who know that corrections must show the original because the reviewer needs both versions behave differently from staff who know it is a rule.
  • Whether reporting has consequences. If the last person who raised a data integrity concern was sidelined, nobody will raise the next one, and the inspector will hear that from someone.
  • Whether management has looked. A data integrity risk assessment that exists, is current and has led to changes is evidence that management understands the topic. Its absence is evidence of the opposite.

Assessing your own data risk

The guidance expects a risk-based approach, which means a documented assessment of where data are critical and where they are vulnerable. Criticality is about the decision the data support: a release assay is more critical than a canteen temperature log. Vulnerability is about how easy the data are to alter, lose or fabricate: a standalone instrument with a shared login and no audit trail is more vulnerable than a validated LIMS. The assessment crosses the two and puts controls where both are high.

  1. Inventory every process and system that generates or processes GMP data, including paper records and spreadsheets.
  2. For each, rate the criticality of the data and the vulnerability of the process. Use the checklist on this site as the prompt for vulnerability.
  3. Where both are high and the controls are weak, define the remediation: technical (unique logins, audit trail locked on), procedural (review defined), or behavioural (training, targets).
  4. Track the actions through CAPA, and repeat the assessment when systems, processes or people change.

When a failure is found

A data integrity failure, whether found by an internal audit, a whistleblower or an inspector, is investigated through the deviation system, not handled quietly. The investigation has a shape that regulators recognise, described in PIC/S PI 041-1 section 12 and in the EMA data integrity Q&A. First, scope: how far does the failure extend, across which records, which systems, which people, and over what period. Second, impact: does any released product rest on data that cannot now be trusted, and what is the patient risk. Third, cause: what pressure, system design or gap in training made the failure possible. Fourth, correction: of the data, the systems and the behaviour. Fifth, effectiveness: how you will know the fix worked.

For serious cases, PI 041-1 sections 11 and 12 describe what EU regulators expect: a comprehensive investigation, often with a third-party assessment of the extent of the failure and of the site's data integrity controls generally, a risk assessment of the potential effect on product quality, and a management strategy including a corrective action plan across the site. The site that does this itself, credibly, before it is asked, is treated very differently from the one that has it imposed.

Training that changes behaviour

Every site has GDocP training. Most of it is a list of rules read aloud. The training that works explains the reason behind each rule in terms of what the reviewer and the inspector need to see, uses the site's own records with the problems left in, and is repeated when someone changes role or when a failure occurs. Contractors and temporary staff are included; they make entries too. And it is recorded, because training is itself a GMP record and inspectors ask for it.

Module 6 of the course is built for managers and QA leads. It works through a data risk assessment for a real site, a remediation plan that was accepted by a regulator, and the interview questions inspectors use to read culture, with the answers that reassure and the ones that do not.