OECD GLP data integrity follows the lifecycle—not just the final result
OECD Advisory Document No. 22 asks GLP facilities to understand data flows, risk, criticality, and lifecycle. A reviewed final value cannot prove that the underlying dynamic data, metadata, processing, transfer, and archive remain reconstructable.
Editorial figure by Lab Systems Index. Source context: OECD GLP Advisory Document No. 22 on data integrity.
Map the data flow before selecting the system of record
A GLP study can create data in instruments, acquisition software, local files, integrations, spreadsheets, ELNs, LIMS, scientific repositories, reports, and archives. The authoritative record may therefore be a controlled chain rather than one database. Teams need to identify each data object, owner, source, transformation, transfer, review, retention rule, and relationship to the study.
A product demonstration should follow one observation from original capture through processing, calculation, interpretation, review, report, and archive. It should expose manual steps, intermediate and dynamic data, metadata, failed transfers, and reconstructed context. Calling a LIMS or SDMS the source of truth does not establish that every material step entered or remained controlled there.
Risk and criticality determine proportionate controls
The OECD overview joins lifecycle to data risk and criticality. Not every field, temporary object, or technical log carries the same potential effect on study reconstruction or GLP compliance. A defensible assessment names the decision or record affected, likelihood of error or loss, detectability, downstream use, existing controls, and rationale for the selected review and retention.
Systems should retain that assessment beside configuration and validation evidence. Buyers should test a critical raw-data change, a low-risk convenience copy, a recalculation, and a field whose significance changes later. A generic critical-data label or audit-trail toggle cannot replace the reasoned connection between the data, study, process, and control.
Metadata and dynamic data remain part of reconstruction
A final PDF can show an approved result while omitting acquisition parameters, sequence, integration, audit history, reprocessing, excluded runs, calculation version, user context, or links to the original object. Where those elements are needed to understand or reconstruct activity, flattening the record can remove material evidence even if the displayed number remains unchanged.
The operating test should include changed processing, re-integration, amended metadata, time synchronization, account changes, and export to an archive that cannot run the original application. Reviewers should be able to distinguish contemporaneous data from later annotation and demonstrate how retained records remain readable, attributable, contextual, and protected through the required period.
Service and cloud arrangements do not transfer accountability
Laboratories may depend on vendors, hosted platforms, managed instruments, integration services, and long-term archives. Contracts and technical controls should define data ownership, access, privileged activity, change notice, backup, restoration, export, incident handling, retention, audit evidence, and exit. Provider certification or uptime does not establish the integrity of a specific study record.
Lab Systems Index treats Advisory Document No. 22 as a lifecycle evaluation framework. The publication does not validate software, establish GLP status, determine scientific validity, or prove integrity for particular data. Those conclusions require the actual study, facility, national program, configured systems, procedures, people, and retained evidence.
Enterprise buyer test
Translate this change into the exact population, record type, workflow stage, decision owner, effective date, and evidence that could be affected. Ask current or prospective providers to demonstrate the named workflow with representative data and an exception—not a polished feature tour. Record what official documentation establishes, what a provider states, what the team observes, and what remains unresolved.
A defensible review also identifies the dependency outside the product. Authority interpretation, policy configuration, data quality, integrations, human judgment, approval rights, release governance, training, and retained evidence may remain customer or service responsibilities. The evaluation should preserve those boundaries instead of treating a technology claim as the complete operating model.
What we will watch next
Lab Systems Index will watch the named source and affected market records for later evidence that changes status, scope, availability, implementation timing, workflow consequence, or the limits of the initial report. A later announcement does not silently overwrite this dated account; the change ledger preserves the sequence.