When the FDA concludes that data underlying a drug application or CGMP records cannot be trusted, the consequences reach well beyond a single deficiency letter. For regulatory and clinical teams, understanding how the Agency treats data integrity failures — and what happens once the Application Integrity Policy is invoked — is essential to assessing submission risk, structuring quality oversight, and gauging the exposure a firm faces when misconduct surfaces in laboratory, manufacturing, or clinical records.
The analysis below explains what the Application Integrity Policy is and the compliance policy guide it rests on, the wrongful acts that trigger it, the actions it sets in motion against pending and approved applications, and the steps a firm must take to be reinstated. It then walks through enforcement precedents spanning both manufacturing/laboratory data and clinical trial data to show how these principles have been applied in practice.
Want Rhizome's help on your own question? Try it for free.
FDA responses to data falsification and fraud: the Application Integrity Policy and enforcement precedents
When FDA concludes that data in a drug application or in CGMP records cannot be trusted, its response is not a single action but a graduated set of tools. At one end sits routine remediation inside a firm's quality system; at the other sits the Application Integrity Policy (AIP), which effectively freezes a company's dealings with the Agency until it rebuilds credibility. This overview walks through what the AIP is, what conduct triggers it, what it sets in motion, how a firm gets out from under it, and the enforcement precedents that show how these principles play out in practice, spanning both manufacturing/laboratory records and clinical data.
What the Application Integrity Policy is
The AIP is set out in FDA's compliance policy guide "Fraud, Untrue Statements of Material Facts, Bribery, and Illegal Gratuities" (CPG Sec. 120.100). FDA uses it when an applicant's submissions have been called into question by wrongful acts, and its stated purpose is to ensure the validity of data submissions and to withdraw approval of, or refuse to approve, applications containing fraudulent data 39. The policy is applied broadly to applicants and applications, and it reaches submissions made by an applicant or by its employees or agents 3940.
What triggers AIP-related action
The policy is triggered by "wrongful acts" that raise a significant question about the reliability of data. FDA lists the triggering conduct as 4039:
- submitting fraudulent applications;
- making untrue statements of material fact;
- giving or promising bribes; and
- giving or promising illegal gratuities.
In the manufacturing context, FDA's internal inspection procedures treat a documented pattern of data-reliability problems as the gateway to the AIP. If a preapproval or CGMP inspection finds data-reliability issues, the inspection team lead is to document whether the findings call the reliability of submitted data into question, identify the specific application data where possible, and promptly notify the review program so FDA can immediately assess the impact on the application 21. If the inspection reveals a pattern, it may be expanded to marketed products, and if the expanded inspection shows broader problems, FDA is directed to consider invoking the AIP or planning a for-cause inspection to define the scope of the unreliability 212224.
What the AIP sets in motion
Once wrongful acts are suspected, the policy moves through a defined sequence 40:
- Investigation. FDA investigates to identify all instances of wrongful acts and to determine the extent to which they may have affected approved or pending applications 40.
- Validity assessment. If the wrongful acts raise a significant question about data reliability in some or all pending applications, FDA ordinarily conducts validity assessments of those applications 40. In a validity assessment, FDA examines whether the firm can manage paper, computerized, and hybrid data systems with proper access controls and audit trails; whether data are calculated and reported through reliable, verifiable mechanisms and interpreted with sound scientific rationale; whether any data that should have been reported were omitted; and whether submissions contain inaccurate, misleading, manipulated, or incomplete data. FDA reviews representative raw data across in-process, release, and stability testing to see whether a pattern affects product-quality specifications or retest and expiry dating 22.
- Deferral of substantive review. FDA generally defers substantive scientific review of a pending application while the validity assessment is ongoing, until the reliability questions are resolved 40414344. In practice, when a requester or applicant appears on the AIP list, FDA reviews that list and consults its internal offices to determine the appropriate action before proceeding 414344.
- Refusal or withdrawal of approval. If FDA determines the approval criteria cannot be met because reliability questions are unresolved, it will not approve the application 40. Where fraudulent data render the data unreliable, FDA ordinarily refuses to approve a pending application or withdraws approval of an approved one, even if the applicant tries to swap in replacement data through an amendment or supplement. FDA's position is that replacement data should instead be submitted as a new application 40.
The practical effect is that AIP status stalls not just the implicated submission but the applicant's broader pipeline, because the Agency will not expend substantive review resources until integrity is re-established.
Getting out from under the AIP: the reinstatement pathway
Removal from AIP status is demanding and is built around the applicant demonstrating, to FDA's satisfaction, that its data and operations can again be trusted. The policy requires the applicant to 97:
- Cooperate fully with FDA and any other Federal investigations to determine the cause and scope of the wrongful acts and their effect on product safety, effectiveness, or quality 97.
- Identify and remove implicated individuals, ensuring that anyone who was or may have been involved in the wrongful acts is removed from any substantive authority over matters under FDA jurisdiction 97.
- Conduct a credible internal review, ordinarily using an outside consultant or team qualified by training and experience, to identify all wrongful acts associated with FDA applications, including discrepancies between approved manufacturing conditions and actual production. All oral and written reports from the consultant must be provided to FDA simultaneously for independent verification 97.
- Commit in writing to a corrective action operating plan, ordinarily through a consent decree or agreement signed by the most responsible senior official, addressing the procedures and controls needed to prevent future wrongful acts and, where appropriate, a comprehensive ethics program 97.
- Restore FDA's confidence through reinspection, where FDA reinspects to confirm the internal review was satisfactorily completed and the corrective action plan satisfactorily implemented, looking for positive evidence such as effective management controls, SOPs, and corroborating documentation that the data are reliable 97.
- Retest or recall as requested, which may include a written commitment to retest products, including bioequivalence and bioavailability retesting for drugs, and to recall affected products lacking adequate assurance of safety, effectiveness, or quality 97.
The through-line is credibility: the firm must independently verify its own data, expose it to FDA, and then let FDA confirm the result on the ground before review resumes.
Data integrity in CGMP and manufacturing records
Outside the formal AIP, FDA's data-integrity expectations define what "falsification" looks like and what remediation it demands. FDA expects data to be complete, consistent, and accurate, with systems designed so errors, omissions, and aberrant results are easy to detect across the data life cycle 73. Required data must not be modifiable without a record of the modification; chromatographic data should be saved to durable media at each step, changes to data or injection sequences must be captured in an audit trail, and aborted or incomplete injections must be captured, investigated, and justified. Storing electronic records in a way that permits manipulation without a permanent record is not acceptable 75. Computerized systems must prevent unauthorized access or change, prevent data omissions, and record each change, the prior entry, who made it, and when 82. A tip about a possible quality problem such as data falsification is to be handled through the documented quality system rather than informally 74, and out-of-specification results attributable to laboratory error may be invalidated only where there is clear evidence of that error, with a full-scale OOS investigation required otherwise 81. For sponsor oversight, FDA expects qualified testing sites, a monitoring plan, and audits verifying compliance with that plan 7692.
Enforcement precedents: manufacturing and laboratory data falsification
FDA's warning letters are the clearest record of how these principles are enforced, and they show a consistent menu of misconduct met by a consistent menu of required remediation.
Backdating and clock manipulation. Chongqing Lummy Pharmaceutical changed gas-chromatograph clocks to make testing appear months earlier, performed repeated injections until a favorable result was obtained, and deleted earlier failing results while reporting only the passing run 6. Sri Krishna Pharmaceuticals analysts changed the clock before reanalyzing, deleted original files, and back-dated sample-preparation data, with one analyst admitting a plan to back-date worksheets after testing was complete 7. RPG Life Sciences found a backdated QC worksheet that the analyst admitted backdating, and FDA stated that backdating casts doubt on the validity of records 11.
Deleting or replacing original data. Micro Labs replaced original injection-sequence data with a single manual injection and failed to save the original sequence 9. Sri Krishna analysts deleted original injections and an entire "trails" folder and submitted only second runs 7.
Retesting into compliance. Missouri Analytical Laboratories had a failing assay, passed the lot after retesting freshly prepared samples, but never established a root cause and relied on resampling to invalidate the original OOS result 15. Sandoz Private Limited failed to investigate an OOS impurity result and simply repeated the analysis the next day with a new sample solution, reporting only the passing retest 14.
Weak or shared access controls. BBC Group Limited's laboratory staff all logged in as "System Administrator" with full rights, no password, and audit trails disabled 19. Sandoz had no access restrictions on the instrument used to test and release materials 14, and Posh Chemicals had no restrictions on access to HPLC, FTIR, and GC data or backups, with no audit trails 20.
Fabricated records. Emcure reported environmental-monitoring data for samples that were never collected, labeling and incubating plates as if exposed, and FDA found that prior corrective efforts had been ineffective 10. Zhejiang Jiuzhou had a QA employee admit to falsifying a batch-record review signature 17, and Toyobo reported falsified environmental-monitoring records, including reporting Grade A particle data as Grade B 13.
What FDA required in response. The remediation pattern is telling and mirrors the AIP's logic in miniature. FDA routinely directed firms to commission an independent, third-party data-integrity audit: BBC Group was required to provide a comprehensive independent assessment and CAPA plan for computer-system security and a retrospective assessment of laboratory practices back to a fixed date 19; Zhejiang Jiuzhou was strongly recommended to hire a third-party auditor experienced in detecting data-integrity problems 17; and Emcure had previously committed to a third-party comprehensive audit of its laboratory data 10. FDA also required root-cause investigations 156, retrospective reviews of all invalidated OOS results for marketed, in-expiry product 159, and risk assessments of the effect of the data failures on drug quality and patient safety 1910.
Enforcement precedents: clinical data fraud and application-level integrity
The same intolerance for unreliable data extends to clinical submissions. In the Sanofi-Aventis matter, FDA found that a clinical investigator falsified case report forms and documentation supporting a fictitious subject and pled guilty to one count of mail fraud; FDA further faulted the sponsor for failing to adequately investigate the fraud allegations and for failing to secure compliance or notify FDA after finding serious protocol violations affecting data submitted to an NDA 2. In the EUA context, FDA told Innova Medical Group that clinical data submitted in its request were identical to data previously provided by other manufacturers, raising significant concerns about reliability and rendering the labeling's performance claims false or misleading 5. Related COVID-19 letters show FDA treating false representations of FDA authorization as misbranding: USA Medical was cited for labeling that created a false impression that FDA had authorized its products 4, and iSlim for labeling that failed to reveal the material fact of undeclared sibutramine 1.
When the problem is the clinical investigator's own conduct, FDA's toolkit is distinct from the AIP but parallel in structure. FDA may open disqualification proceedings where an investigator repeatedly or deliberately fails to comply or deliberately submits false information, beginning with a Notice of Initiation of Disqualification Proceedings and Opportunity to Explain (NIDPOE); if the explanation is not accepted, a Notice of Opportunity for Hearing (NOOH) can follow, and a disqualified investigator becomes ineligible to receive investigational products, with the action posted publicly 10010199. As an alternative to disqualification, FDA may accept a detailed corrective action plan or specific restrictions on the investigator's use of investigational products, reinitiating disqualification if the agreement is violated 101. On the data itself, where an inspection reveals serious violations the review division may request additional analyses or reject the affected data where FDA considers it unreliable, and FDA can impose a clinical hold to protect subjects pending action 100102.
How this connects to the preapproval inspection
The preapproval inspection (PAI) is where much of this surfaces before approval. FDA uses the PAI to verify that data submitted in an application are accurate and complete and to assess whether the facility can manufacture in conformance with CGMP and the application 65. A finding of data-integrity problems is treated as a significant issue 26: falsification of data generated at the manufacturing site and used to support product-quality decisions is evaluated for systemic CGMP impact on current operations 26, and in the clinical-records context inspectors who find falsification, fabrication, or alteration that may affect data reliability or subject welfare are to escalate immediately and consider expanding the inspection's scope 646970. Significant findings are evaluated jointly by the field and the review center in the context of the application 66, which is the decision point where a validity assessment, deferral of review, and ultimately the AIP can be set in motion.
Bottom line for regulatory teams
FDA's response to data falsification scales with the severity and breadth of the unreliability. Isolated laboratory error is handled inside the quality system; a documented pattern of manipulation draws warning letters demanding independent audits, root-cause work, and retrospective OOS review; and wrongful acts that call an entire body of submitted data into question invoke the Application Integrity Policy, which defers review, drives validity assessments, and can lead to refusal or withdrawal of approval until the firm rebuilds credibility through cooperation, an independently verified internal review, a corrective action operating plan, and passing reinspection. The recurring theme across every tier is that FDA does not accept replacement data as a shortcut; it requires the applicant to demonstrate that its data-generating systems, and the people running them, can be trusted again 4097.