Life sciences
ALCOA principles don't cover your AI answers
Your batch records are attributable, legible, contemporaneous, original and accurate. The sentence your AI assistant wrote from them is probably none of those things. Here is how to close the gap.
Cognatum Team · Sep 15, 2026 · 5 min read
A regulated manufacturer can usually prove that a batch record is attributable, legible, contemporaneous, original and accurate. Ask the same company whether it can prove the same about the sentence its AI assistant just produced from that record, and the answer changes.
Cognatum governs the entry
source · version · approver · permissions
ALCOA governs the record. It says nothing about the answer derived from the record, and the answer is increasingly what people act on.
What ALCOA actually covers
MHRA's Guidance on GxP data integrity sets out the data integrity expectations for organizations across the pharmaceutical lifecycle, and it is where most teams first meet ALCOA alongside its extension ALCOA+, which adds complete, consistent, enduring and available. Read the guidance.
PIC/S PI 041-1 carries the same principles into routine data management for GMP and GDP inspectorates, running to sixty three pages of expectations for paper and electronic systems alike. Read the guidance.
ICH E6(R3), adopted in January 2025, pushes data governance, the record of who approved what, across the whole clinical trial lifecycle rather than leaving it as a records exercise at the end. Read the guideline.
What all three assume
Each of these instruments assumes the governed thing is a record. A result, an entry, a file, a signature. That assumption held for as long as the people reading the records were also the only ones writing about them.
Then an assistant reads it
An analyst asks whether a deviation from last spring was closed and what the disposition was. The assistant reads three documents and returns four fluent sentences. Those four sentences are now the operative record, because they are what the analyst acts on.
The underlying entries were ALCOA. The four sentences were not attributable to a named approver, were not stamped to the version of the source they relied on, and did not mention that two of the three documents disagreed.
Not a model failure
None of this is a failure of the model. The underlying documents were governed properly. What was never governed is the layer between the document and the person, which used to be a colleague reading carefully and is now a system producing hundreds of answers a day without being asked to show its working.
ALCOA, applied to the answer
- Attributable. Not only who created the source, but who approved the wording the assistant is permitted to give.
- Legible. Not a handwriting question. A reader should be able to see what the answer rests on, in the answer, without opening a ticket.
- Contemporaneous. The answer records the state of the knowledge at the moment it was given, not the state of the knowledge whenever somebody next looks.
- Original. Every answer is a derived copy. The link back to the original, and to the version of it in force at the time, has to survive the derivation.
- Accurate. And where two approved sources disagree, both are shown and the disagreement is named rather than quietly settled.
The last one is where most systems fail without anyone noticing. A retrieval system that picks the more confident looking passage has made an adjudication nobody asked it to make, and nobody recorded.
What the AI instruments add
The EU AI Act requires high risk systems to technically allow the automatic recording of events over the system's lifetime, in Article 12. Read Article 12.
NIST's Generative AI Profile treats information integrity as a risk category in its own right, separate from security and privacy. See the profile.
ISO/IEC 42001 extends management system discipline to artificial intelligence itself. See the standard.
None of them replaces ALCOA. They describe the same instinct applied one layer further out, to the system that reads the records rather than to the records.
What software can and cannot claim here
These instruments describe what an organization must be able to demonstrate. Software can align with them and produce the evidence that supports a demonstration. No product confers compliance or certification on the company running it, and a vendor who says otherwise is selling a sentence rather than a control.
A test you can run this week
Pick one controlled record an inspector has asked about before. Ask your assistant a question that depends on it. Then put four questions to the reply.
- Who approved this wording, by name?
- On what date, and has the source moved since?
- Which source, and which version of it, did this answer use?
- If anything disagreed, where is that recorded?
The third question is the useful one because it is answerable only if something recorded it at the time. A retrieval log is not enough. It tells you which documents were consulted, not which version of them was in force when the sentence was written.
Most teams can answer the first two and stall on the third. That gap is the one a reviewer reaches quickly, because it separates a system that produces answers from a system that can account for them.
Notification, not silent correction
When a source changes, the correct behavior is to tell a person. Every entry that depends on the changed source is flagged and routed to a named human, who decides what the change means and can rework the wording before approving it. A knowledge base that rewrites an approved answer on its own has removed the approver, which was the entire point of the approval. No knowledge base should be described as always current.
That handoff is the step the Cognatum Knowledge Loop is built around. Your company's knowledge isn't missing. It's unusable. Cognatum changes that.
Sources
- Guidance on GxP data integrity (gov.uk)
- PIC/S PI 041-1: Good Practices for Data Management and Integrity (picscheme.org)
- ICH E6(R3): Guideline for Good Clinical Practice (ich.org)
- EU AI Act Article 12: Record-Keeping (artificialintelligenceact.eu)
- Artificial Intelligence Risk Management Framework: Generative AI Profile (nist.gov)
- ISO/IEC 42001:2023 Artificial intelligence, Management system (iso.org)
- The Cognatum Knowledge Loop (cognatum.ai)
Common questions
Questions this raises.
What are the ALCOA principles?
ALCOA is shorthand for five attributes of a trustworthy record: attributable, legible, contemporaneous, original and accurate. It is used across regulated industries, most heavily in pharmaceutical manufacturing and clinical research, as a quick test of whether a record can be relied on during an inspection.
What is the difference between ALCOA and ALCOA+?
ALCOA+ keeps the original five attributes and adds four more: complete, consistent, enduring and available. The additions reflect electronic records, where a result can be technically accurate and still fail because metadata was dropped, timestamps drifted, the storage medium was not durable, or nobody could retrieve the record when asked.
Is ALCOA a legal requirement?
ALCOA is a mnemonic rather than a numbered clause. It appears as shorthand in regulator guidance such as MHRA's GxP data integrity guidance and PIC/S PI 041-1, not as a standalone rule you can be cited against. The underlying obligations are real and enforceable. The acronym is the memory aid for them.
Do the ALCOA principles apply to AI-generated answers?
Not by default. The principles were written for records, and an AI answer is a derived work rather than a record in the traditional sense. Nothing stops you applying the same five tests to the answer, and in practice that is what a reviewer is doing when they ask who approved a given response and what it was based on.
How do you make an AI answer attributable?
By approving the wording rather than only the source. An entry carries a named approver, the date of approval, and the specific source and version it draws on, and the answer surfaces those alongside the text. Retrieval logs alone do not achieve this, because they record which documents were consulted rather than who stands behind the result.