Decision Integrity: The Layer ALCOA+ Was Never Built to Cover

Sachin Bhandari, Founder, TrustBridge Compliance

For decades, pharma quality has protected data integrity, ALCOA+, audit trails, and the record reflecting reality. AI changes the question. When a model triages a deviation, flags a batch, or drafts an investigation, the record can be perfectly intact while the decision behind it stays opaque. This piece makes the case that decision integrity now sits on top of data integrity as the layer that quality and regulatory leaders have to govern: how a decision was reached, on what data, with what human oversight, and whether it can be defended to a board and to an inspector. It sets out what decision integrity means in practice, where it tends to break, and the governance that keeps AI-assisted decisions traceable and accountable across the lifecycle.

Introduction:

When a model helps make a GxP call, the data underneath it can be spotless and the decision still indefensible. Here is where the gap opens, and the controls that close it. For 25 years, the discipline that has kept regulated records trustworthy is data integrity. We learned ALCOA, then ALCOA+, and built whole quality systems around the idea that a record has to be attributable, legible, contemporaneous, original, and accurate, then complete, consistent, enduring, and available. Audit trails, e-signatures, review by exception, all of it exists to protect the integrity of the data.

That work is largely done in mature organisations. The problem I keep running into now is different. When an AI model helps make a decision in a GxP process, the data can be perfect and the decision can still be one you cannot defend. The record shows clean numbers and a signature, and it says almost nothing about how the call was actually made. That gap has a name worth using: decision integrity.

Let me make it concrete. Picture an immediate-release tablet line. The example is invented to keep it clean, and I am walking through it deliberately rather than describing a specific client system, but every move in it is one I have watched play out on real programmes.

One decision, three eras

The critical quality attribute here is dissolution. A batch has to release enough active ingredient in the specified window, and if it does not, that batch is in trouble. During compression, the line generates a stream of in-process data: compression force, tablet weight, hardness, granule moisture. Somewhere in that stream sits an early signal that dissolution is drifting toward the limit. The decision that matters is what a person does with that signal: keep running, adjust the process, divert suspect tablets, or hold the batch for extra testing.

Watch how that one decision changes across three eras of how we have run quality. The shift is the whole point.

Figure 1. One quality decision across three eras. The data trail stays intact as AI enters, but the decision’s traceability drops away in Era 3. Illustrative example.

Era 1: the paper line

In the pre-digital version, the operator records weight and hardness on a paper batch record every 30 minutes. Dissolution itself is only known days later, when QC runs the finished batch. If it fails, a deviation opens after the fact, and the investigation works backward.

There is no decision to keep running, not really, because there is nothing to decide against. Nobody is weighing a prediction. The record captures the data the operator wrote down and the result QC produced, and the integrity risks are the familiar ones: was the entry contemporaneous, is it legible, did anyone transcribe a number wrong. This is the world data integrity was built for, and it is a reactive world. The quality signal arrives after the batch is already made.

Era 2: data integrity, solved

Now give the same line a validated manufacturing execution system with statistical process control. Sensors feed compression force, weight, and hardness continuously. Trends raise alarms. Every reading is attributable and time-stamped, the audit trail is intact, and dispositions carry an electronic signature under 21 CFR Part 11 and EU Annex 11. Review by exception means a human looks closely only where the data says to look.

When a parameter trends toward a limit, the system flags it, a named person reviews the data, and they sign a disposition. This is a good place to be. The data has integrity in the full ALCOA+ sense, and the decision is still human. Better still, the decision is reconstructable: months later you can open the record and see this person, looking at this data, making this signed call. The reasoning lives in a human head, but a competent reviewer or inspector can follow the trail from the data to the disposition and understand why.

The important thing about Era 2 is that data integrity and decision integrity have not yet come apart. The person who owns the decision is the same person who read the data, and the record ties them together.

Era 3: the model makes the call

Add a predictive quality model. Trained on years of historical batches, it now reads the live in-process stream and, 20 minutes into compression, returns a judgment: 72% probability this batch trends below the dissolution limit, recommend diverting the last portion of tablets and adding a sampling point. A human accepts the recommendation and signs.

Here is what the record holds afterward. The sensor data, clean and complete, fully ALCOA+ compliant. And a signed disposition that reads, in effect, “tablets diverted per model recommendation.” Every data-integrity control has done its job.

Now an inspector arrives, as one eventually does, and asks the obvious questions. Why did you divert those tablets. What did the model actually tell you, and how confident was it. Which inputs drove that recommendation, and were they inside the range the model was validated for. Did the reviewer genuinely evaluate the recommendation or wave it through. And was the model even in a validated, monitored state on the day it made this call.

The record answers none of that. The data has integrity. The decision does not. That space between a spotless data trail and an indefensible decision is exactly where AI drops a firm, and no amount of ALCOA+ maturity closes it, because ALCOA+ was never pointed at the decision in the first place.

Why ALCOA+ stops at the data

The reason is structural, not a failure of anyone’s quality system. ALCOA+ governs the integrity of a record: the reading, the entry, the signature. In Era 2 that was enough, because the decision was a human act sitting directly on top of data the human had read. Protect the data, name the signer, and the decision came along for the ride.

A model breaks that coupling. The recommendation is now a second output, generated by a system with its own inputs, its own version, its own confidence, and its own validated envelope, and it shapes the call before the human ever signs. Protecting the sensor data tells you nothing about whether that recommendation was sound, whether the human tested it, or whether the model was operating where it was allowed to. The decision has floated free of the data trail, and the old controls do not reach it.

This is what I mean when I say decision integrity is the new layer on top of data integrity. It does not replace ALCOA+. It sits above it and answers a different question. Data integrity asks whether the record is true. Decision integrity asks whether the decision the record led to can be traced, explained, bounded, and owned.

Decision integrity, defined

A decision has integrity, in a GxP sense, when four things hold. It is attributable to a named human who genuinely owns it, not a system that quietly made it. It is explainable, so the reasoning, including the model’s contribution, can be reconstructed. It is bounded, meaning the model was operating inside its intended use when it spoke. And it is defensible, so that months later someone can open the record and stand behind the call in front of an inspector without the people who made it in the room.

Notice that the tablet example fails three of those four in Era 3, despite perfect data. The decision is nominally attributable to whoever signed, but it is not explainable, not visibly bounded, and not defensible. The signature is real and the reasoning behind it has vanished.

The controls AI adds on top

Closing the gap does not mean more data-integrity controls. It means a distinct set of controls aimed at the decision itself, layered on the ALCOA+ foundation. On the programmes where this works, six of them tend to carry the weight.

1.   An intended-use boundary check at the moment of decision. Before the model’s output is trusted, the system confirms the inputs sit within the range the model was validated for. Out-of-range inputs route to a human-only path because a model asked to judge a batch unlike anything it trained on is guessing, and the record should show you caught that.

2.   A decision snapshot. Capture the model version, the input values, the output, and the confidence score at the instant the recommendation is made, held immutable and time-stamped. This is the model equivalent of a contemporaneous record, and without it, the recommendation is hearsay.

3.   An explainability artefact tied to that specific decision. Not a generic statement that the model is interpretable, but the reason codes or feature attributions for this recommendation in this batch are captured alongside it.

4.   A human-in-the-loop with a real override. The reviewer records why they accepted or overrode the recommendation, and high-impact or low-confidence outputs force genuine adjudication rather than a default click. The control you are guarding against is the quiet rubber stamp, where “per model recommendation” becomes a signature with no thought behind it.

5.   A link to the model’s validated state. The decision record points to the model’s validation status and drift monitoring as they stood that day, so you can later prove the model was inside its envelope and not silently degrading when it made the call.

6.  A reconstructable decision trail. One retrievable record that binds the data, the model output, the explanation, the human’s reasoning, and the signature together, so that the inspector’s “walk me through this decision” has a single, honest answer.

None of this is exotic, and most of it reuses machinery a mature quality organisation already owns. The shift is where you point it. For 25 years, we aimed our integrity controls at the data. When a model helps decide, some of that attention has to move up a layer, onto the decision the model shaped.

Figure 2. Decision integrity is a layer on top of data integrity, with six added controls once a model helps make the call.

Where this leaves you

The regulators are already moving this way. The FDA’s Computer Software Assurance guidance, finalised in 2025, pushes validation effort toward the decisions that carry the most risk. The EU’s draft Annex 22 sets expectations specifically for AI in GMP, and it reads, at heart, as a demand that AI-influenced decisions be traceable and controlled. The direction is consistent even where the detail is still settling.

So the honest question to ask of your own AI-assisted processes is not whether the data is clean. In a mature shop, it almost certainly is. The question is whether, a year from now, you could reopen a single decision the model helped make and defend it: show what the model said, why the human agreed, that the model was allowed to weigh in, and who owns the outcome. If the answer is no, the gap is not in your data integrity. It is one layer up, and it is worth closing before an inspector finds it for you.

The tablet line in this article is an illustrative composite created to make the concept concrete, not an account of a specific system or client.

Sachin Bhandari

Sachin Bhandari is the founder of TrustBridge Compliance, an advisory practice in digital quality and validation. He has spent 25 years in pharma across CSV and CSA, data integrity, and enterprise quality systems, including an eQMS deployment for around 15,000 users and paperless validation across 40-plus sites. He has taken AI-supported quality systems through health-authority inspection in live operation. He is the author of Validating AI in GxP: A Practitioner's Guide.