ALCOA principles help laboratories maintain reliable, traceable, and trustworthy records. They ensure data is attributable, clear, timely, original, accurate, complete, consistent, enduring, and available. Applying these principles in daily workflows and LIMS helps preserve data integrity and support compliance.
Reliable laboratory records must show more than a final result. They should allow an authorised reviewer to understand who performed an activity, what was recorded, when it occurred, where the information originated and how it changed. The ALCOA principles for diagnostic laboratory records provide a practical way to evaluate whether that evidence can be trusted.
ALCOA stands for Attributable, Legible, Contemporaneous, Original and Accurate. ALCOA+ adds Complete, Consistent, Enduring and Available. These concepts are widely used in regulated data-integrity guidance, but ALCOA is not a separate laboratory certification. A diagnostic laboratory should apply them alongside ISO 15189, applicable NABL or jurisdictional requirements and its approved procedures.
1. Origin and scope of ALCOA
ALCOA developed as a concise way to describe the characteristics of reliable records in regulated life-science work. Guidance from regulators such as the UK Medicines and Healthcare products Regulatory Agency uses ALCOA and ALCOA+ to explain data integrity throughout the data lifecycle. However, such GxP guidance was not written specifically to define every obligation of a medical laboratory. Its applicability must therefore be assessed rather than assumed.
For a diagnostic laboratory, the framework is a practical lens across paper, electronic and hybrid workflows. It applies to registration, analyser output, quality control, maintenance, calculations, review, report authorisation, corrections and communication records.
The aim is to design processes in which important records retain their identity, meaning and history through creation, use, storage, retrieval and authorised disposal. Controls should be proportionate to risk.
2. Attributable records
An attributable record identifies the person or system responsible for an action. A handwritten entry may require a signature or controlled identifier. An electronic record normally needs a unique user identity, a reliable timestamp and, where relevant, the instrument, interface or application that created or transmitted the data.
Attribution should distinguish between the person who entered information, the reviewer and the result authoriser. Shared accounts weaken that distinction. Access should reflect authorised roles, and delegated or exceptional activities should remain identifiable.
Automated data also need attribution. A result transferred from an analyser should retain enough provenance to connect it with the instrument, run, specimen and interface event. If staff transcribe a result during downtime, the record should identify both the original source and the person who entered it.
3. Legible and understandable records
Legibility means more than readable handwriting or a clear screen. A record must remain understandable in context. A value without its patient or specimen identifier, units, method, date, status or reference information may be visually clear but still be ambiguous.
Laboratories should use controlled terminology, approved abbreviations and consistent formats. Paper records need protection from damage. Electronic records and exports should remain human-readable after software changes or migration. The meaning of interpretive codes and flags should remain available throughout retention.
This principle also matters when information is condensed into a report. The presentation should not conceal whether a result was preliminary, authorised, corrected or accompanied by a comment. The record must provide enough context for an authorised reviewer to reconstruct the decision.
4. Contemporaneous capture
A contemporaneous record is created when the activity occurs, or as soon as the approved workflow reasonably permits. Recording information later from memory increases the risk of omission, incorrect sequencing and inaccurate attribution.
Examples include documenting specimen receipt, maintenance and result review when each occurs. Electronic interfaces can reduce delay, but timestamps, clocks and time zones still require control. Connected systems should use a consistent time source so events form a credible sequence.
When a late entry is necessary, it should be identified as a late entry rather than backdated. The laboratory's procedure should define the reason, authorisation and explanatory information required. Downtime records should likewise show the actual event time, the later system-entry time and the person responsible for reconciliation.
5. Original records and true copies
The original record is generally the first capture of information in the form that preserves its content and meaning. It may be a paper worksheet, an analyser data file or an electronic database record. Relevant metadata—such as the operator, timestamp, instrument, calculation or change history—can be part of that original record.
A printout or PDF is not automatically a true copy of a dynamic electronic record. If filtering, reprocessing, audit history or metadata are needed to reconstruct the activity, a static export may be incomplete. The laboratory should define the authoritative record for each workflow, especially where information moves between paper, analysers, middleware and a LIMS.
When a true copy is used, the copying process should preserve the original content, context and meaning. Transfers and migrations need checks so that identifiers, units, timestamps and audit information are not lost or altered.
6. Accurate records
Accuracy means that recorded information correctly represents the observation or activity. In laboratory practice, this includes the value, units, patient and specimen identity, test or method, status, timestamps and relevant metadata—not only the final numerical result.
Accuracy is supported by validated or verified systems, controlled entry, interface checks, quality control, calculation verification and authorised review. Transcription, default values, copy-and-paste actions and manual calculations require particular attention.
Corrections must improve accuracy without erasing history. Whether a worksheet entry, QC record or patient report is changed, the previous information should remain traceable as required. The record should show what changed, who changed it, when it changed and why; significant changes may also require review, authorisation, communication and an assessment of affected results.
7. Complete, consistent, enduring and available records
The additional ALCOA+ principles address the record across its lifecycle:
-
Complete: The record includes relevant results, repeats, rejected or excluded data, comments, approvals and changes—not only the selected final value. Completeness does not mean retaining irrelevant information indefinitely; the laboratory should define the required record set and retention period.
-
Consistent: Events appear in a logical sequence, with controlled identifiers, formats, units and version rules. Synchronized timestamps help demonstrate what occurred before and after a decision.
-
Enduring: Records remain protected and usable for the required period. This includes controlled storage, backup, archive, recovery and migration, with safeguards against unauthorised change, loss or deterioration.
-
Available: Authorised users can retrieve records in a readable form when needed for patient care, investigation, audit, assessment or management review. Access restrictions should protect confidentiality without making legitimate retrieval impractical. Downtime and disaster-recovery arrangements also matter.
These qualities are interdependent. A record can be attributable when created yet fail if its metadata disappear during export or it cannot later be retrieved.
8. Applying the principles in a LIMS
A LIMS can support ALCOA by using unique user accounts, role-based permissions, controlled timestamps, instrument provenance, audit trails, version history, electronic review and authorised release. It can also connect specimen, result, QC, correction and communication records so that reviewers can follow the evidence without assembling it from unrelated files.
Technology does not make records compliant by itself. Configuration, validation or verification, procedures, training, access reviews, audit-trail review, backup tests and change control determine whether system features work as intended. An audit trail that is never reviewed—or that lacks the context needed to interpret an event—provides limited assurance.
After the product owner verifies current behaviour, AyusLab may be described in terms of the specific functions it provides, such as recording identities and timestamps, connecting related workflow events, preserving version history, flagging required review or supporting retrieval. Claims should remain precise: software can improve visibility and traceability, but it cannot guarantee data integrity, ISO 15189 conformity or sound professional judgement.
The practical question for every important record is simple: Can an authorised reviewer reconstruct what happened, who was responsible, when it occurred, which source was used and what changed? If not, the workflow needs stronger controls.

Frequently asked questions
What is the simplest definition of ALCOA principles for diagnostic laboratory records?
ALCOA describes records that are Attributable, Legible, Contemporaneous, Original and Accurate. ALCOA+ adds Complete, Consistent, Enduring and Available, extending the principles across the full record lifecycle.
Which part of the laboratory workflow is responsible?
Responsibility is shared across the workflow. Staff who create and review records, authorised report signatories, quality personnel, system administrators and laboratory management each have defined responsibilities. The laboratory should assign them through approved procedures and access controls.
What records should remain available for review?
The required set depends on the record type and applicable retention rules. It may include source data and metadata, worksheets, analyser and interface records, QC, reviews, approvals, reports, corrections, audit history, communication records and evidence of system or equipment activity. The laboratory should define retention and retrieval requirements rather than use one universal period.
Where can a LIMS help and where is professional judgement still required?
A LIMS can structure capture, restrict access, connect records, preserve history and support retrieval. Laboratory professionals must still establish procedures, assess risk, validate or verify workflows, review exceptions and audit trails, evaluate corrections and decide whether evidence is adequate.
Reviewing your own lab's processes?
A Lab Growth Session walks through your turnaround time, rejection rates and workflow with our team.
Book a Lab Growth Session