Skip to content

Data integrity through an acquisition: what GxP asks of an M&A data move

Quality and compliance · · 6 min read

When a life-sciences company buys another, it also takes on the target’s regulated records: batch records, clinical data, stability studies, validation documentation and more. Those records have to keep their standing with regulators after they move. That makes the data workstream of an integration a GxP activity, not only an IT project.

The principles regulators use

Regulators’ data integrity guidance, from the FDA, the UK MHRA, PIC/S and the WHO, describes good records with the ALCOA principles, which the MHRA, PIC/S and WHO extend as ALCOA+. A record should be:

  • Attributable: it shows who created or changed it, and when.
  • Legible: it can be read for as long as it is kept.
  • Contemporaneous: it was recorded at the time of the activity.
  • Original: it is the first record, or a true copy of it.
  • Accurate: it is correct and free of unrecorded changes.
  • Complete, Consistent, Enduring and Available: nothing is missing, the sequence holds, it lasts for its retention period, and it can be retrieved when needed.

None of these principles is suspended because a company changed hands. A migration is one more event in each record’s life, and it has to leave the record as trustworthy as it found it.

Where a migration puts integrity at risk

  • Metadata is lost or rewritten in transit, so authorship and dates no longer match the original.
  • Files are truncated or corrupted, and the tool reports success anyway.
  • The audit trail of the source system is left behind, so the history of the record ends at the move.
  • Approvals for the move live in e-mail, apart from the transfer itself, and cannot be tied to what actually moved.
  • Nobody can say afterwards exactly which files moved, when, under whose authority, and whether each arrived intact.

What evidence to keep

A useful test is to imagine an inspector picking one record at random and asking how it got here. A well-run move can answer with evidence, not recollection:

  1. An inventory of the source estate, taken before anything moved, with a fingerprint (a cryptographic hash) of each file.
  2. A classification of what each file is and how sensitive it is, so the plan reflects the content.
  3. A record of who approved each batch of files to move, with a signature that carries its meaning.
  4. Proof that each file arrived intact: the destination copy read back and its fingerprint compared with the source.
  5. A tamper-evident log of every step, kept for as long as the records themselves.

Validation is yours to execute

Computerised systems used in GMP work must be validated for their intended use. The regulated company is responsible for that validation and approves it; supplier documentation and testing can be used as part of it. What a supplier can do is make it straightforward: document each control and the mechanism behind it, and supply the test evidence your QA team needs as a starting point.

Start with one deal.

A pilot starts with the two systems you need to connect, and ends with evidence you can hand to an assessor.

  1. 1

    Name the pair

    Tell us the two systems you need to connect. We produce that pair’s evidence before the pilot starts.

  2. 2

    Scan one estate

    Run a Data Estate Scan in your own cluster. You get the PDF report and a classification your QA team can inspect.

  3. 3

    Plan validation together

    Evidence maps, the control inventory and test artefacts, executed with your QA team on your infrastructure.

  4. 4

    Run the first wave

    Two signatures, a verified transfer and a compliance report you can hand to an assessor.

Or write to contact@mergiva-ai.com.