ALCOA+ is widely used in life sciences to describe the qualities that make regulated data trustworthy. It is often discussed when data is created or reviewed, but the same principles matter years later, after a study has closed, a product has moved through its lifecycle or the original system has been retired.
File retention alone does not preserve the context needed to assess a regulated record. An organisation must still be able to explain where the record came from, whether it is complete, what changed, who was responsible and whether the information remains readable and available.
What does ALCOA stand for?
ALCOA stands for:
- Attributable: it is possible to identify who performed an action or created, changed, reviewed or approved a record.
- Legible: the record remains readable and understandable.
- Contemporaneous: the activity is recorded at the time it occurs, with reliable timing and sequence.
- Original: the authoritative record, or a verified true copy, is identifiable.
- Accurate: the record correctly reflects the activity or result it represents.
The additional principles commonly expressed as ALCOA+ are:
- Complete: the relevant data, metadata, changes and contextual information are present.
- Consistent: dates, times, sequence and relationships remain coherent.
- Enduring: the record is maintained on durable, governed media throughout retention.
- Available: authorised users, auditors and inspectors can retrieve it when required.
Some organisations and guidance also make traceable explicit. Terminology varies, but the preservation objective is consistent: regulated records should remain reliable in context, not merely present.
ALCOA+ is a lifecycle requirement
Data integrity does not stop when an operational process finishes. A record may still be needed for an inspection, investigation, product review, legal matter or regulatory submission many years later.
During that period:
- applications are upgraded, replaced or decommissioned;
- staff and suppliers change;
- file formats and viewing software age;
- metadata can become separated from content;
- audit trails may remain trapped in an old application;
- signatures, certificates and validation evidence can become harder to verify;
- ownership of records may transfer between sponsors, CROs or other parties.
An archive therefore has to preserve both the record and the information needed to interpret and defend it.
What each ALCOA+ principle means for an archive
Attributable
Identity information should remain connected to the relevant action. User IDs alone may be insufficient if the archive cannot explain who the user was, which role they held and what an event represented.
Preservation planning should include relevant authorship, approval, signature and audit-trail context.
Legible
A file can remain intact while becoming unusable. Long-term legibility depends on retaining suitable viewers, documenting formats and planning controlled migrations where formats or dependencies become obsolete.
The archive should also preserve enough metadata to explain the content and its relationship to the study, batch, product, process or dossier.
Contemporaneous
Timestamps must retain their meaning. Time zones, clock sources, event sequence and the distinction between creation, modification, approval and ingest dates should not be flattened into a single date field.
When records move into an archive, the migration should not obscure the original chronology.
Original
The archive should distinguish the authoritative record from working copies, renditions and later preservation representations. If a true copy is used, the process that established it should be documented and reproducible.
Keeping the original bitstream alongside controlled representations is often an important part of this approach.
Accurate
Accuracy depends partly on controlled transfer. Record counts, identifiers, file sizes and hashes can be reconciled between the source, export and archive. Exceptions should be recorded and resolved rather than disappearing inside a migration log.
Complete
Completeness is one of the most common weaknesses in archive projects. The visible document may arrive while attachments, relationships, metadata, audit events, signatures or validation context are omitted.
The archive scope should define the complete evidence package for each record class before extraction begins.
Consistent
Records should preserve their sequence and relationships. Study structure, document versions, superseded records and parent-child links need to remain understandable after they leave the source application.
Enduring
Durability is more than storage redundancy. It includes fixity checking, preservation monitoring, controlled change, documented evidence and the ability to move content without losing provenance.
Available
Availability means more than keeping data online. The archive should support timely search, controlled retrieval and usable exports without depending on an obsolete operational system. Access must remain governed and traceable.
Why an export folder is rarely sufficient
A folder of PDFs or data exports may look complete, but it often removes precisely the information that makes the records defensible:
- original identifiers and relationships;
- version and approval history;
- audit-trail events;
- retention and legal-hold context;
- signature and validation material;
- proof that the export was complete and unchanged.
An export can be part of a migration, but it is not a preservation strategy by itself.
A practical ALCOA+ archive checklist
Before retiring a GxP system or transferring regulated records, establish:
- Which record classes and data are in scope.
- Which content, metadata, relationships and audit evidence form the complete record.
- How authoritative records and verified copies are identified.
- How the source-to-archive transfer will be reconciled and documented.
- How integrity will be checked at ingest and during retention.
- How formats, viewers and structured data dependencies will be managed.
- How retention, legal hold and controlled disposal will be applied.
- How authorised users and inspectors will search, view and export records.
- How archive actions and access will remain traceable.
- How records can be exported with sufficient evidence for independent review.
How digital preservation supports ALCOA+
Digital preservation can provide controls that help keep records understandable, intact and usable after their original systems and processes have changed. It combines governed ingest, metadata, provenance, integrity evidence, retention and controlled access.
It does not replace a pharmaceutical quality system, validation responsibilities or regulatory judgement. It provides a long-term evidence layer that helps those controls remain demonstrable.
Docbyte Vault is designed to preserve regulated records together with metadata and evidence context, support controlled retention and access, and reduce dependence on legacy systems kept alive only for historical retrieval.
For the broader requirements, read GxP Archiving Requirements: A Practical Checklist. For the life-sciences use case, see Digital Preservation for Pharmaceutical and Life Sciences.
Assess your GxP archive readiness
If records must remain attributable, legible, complete and available after their source system changes, the archive needs to preserve more than files.
Assess your GxP archive readiness