
How Regulated Pharma Builds Audit Trails for Energy Data
How ALCOA+ records and read-only PLC links support GMP energy audits
A pharmaceutical installation covered by the UK Emissions Trading Scheme must submit its verified annual emissions report by 31 March following the scheme year. If the report does not meet the scheme’s monitoring and verification requirements, the regulator can determine the installation’s emissions and recover its costs. That deadline turns energy data from a facilities metric into a controlled record.
Energy-data audit trails for regulated pharma provide the evidence needed to trace a utility reading from its source through calculation, review, correction and reporting. In a GMP environment, the trail must support data integrity without compromising the qualified state of production systems.
That task involves more than retaining monthly consumption totals. Quality Assurance teams need to know whether a reading is attributable, complete and retrievable. Validation engineers need assurance that the configured system meets its approved intended use. Sustainability and finance teams need figures that withstand SECR, ISO 50001 and, where applicable, UK ETS or EU ETS scrutiny.
The shared requirement is reproducibility. An auditor should be able to start with a reported energy or emissions figure and reconstruct the source data, calculation method, exceptions, approvals and relevant configuration history.
When energy data becomes GxP-relevant

A meter reading does not become GxP data solely because it was collected within a pharmaceutical facility. Its relevance depends on intended use and the decisions it informs.
Site-level electricity consumption used only for corporate reporting may carry a different risk profile from steam data used during an investigation into sterilisation performance. The latter can become evidence supporting a GMP decision. The same distinction applies to purified-water generation, cold storage, cleanroom HVAC and compressed-air systems where a utility record contributes to deviation assessment, maintenance decisions or verification of controlled conditions.
The MHRA GxP Data Integrity Definitions and Guidance for Industry expects organisations to identify data with the greatest GxP impact and apply controls proportionate to risk. A pharmaceutical site should therefore assess energy records by use case, rather than validate every utility dashboard to the same level.
Start with an intended-use statement
The user requirements specification should state exactly what each energy-data function supports. Common uses include:
- SECR and internal carbon reporting.
- ISO 50001 energy-performance evaluation.
- Energy allocation by batch, campaign or product family.
- Investigation of utility failures or deviations.
- Monitoring energy associated with a GMP-critical utility.
- Evidence supporting a quality review or operational decision.
This assessment establishes the system boundary. It also prevents two familiar errors: treating data that informs a GMP decision as a low-risk facilities record, or applying extensive GMP controls to a report with no GxP impact.
Retain evidence of the monitoring boundary
Where an energy-monitoring system collects data from a validated environment, the audit package should retain approved evidence of its read-only boundary and any approved change to that boundary. The record should identify the approved scope of acquired data, the system owner, approval date and impact assessment for amendments.
That evidence belongs in the configuration and change-control record. It gives inspectors confidence that reporting activity remains within its qualified and approved purpose.

Omni Vision delivers turnkey utility metering, CO2 tracking, and AI-powered production KPI intelligence — giving you real-time dashboards and actionable insights across your entire facility.
Applying ALCOA+ to energy monitoring data
The MHRA guidance defines ALCOA as Attributable, Legible, Contemporaneous, Original and Accurate. The associated “plus” attributes are Complete, Consistent, Enduring and Available. Together, they provide a practical test for energy-data audit trails in regulated pharma.
A monthly total in a spreadsheet rarely meets that test alone. The supporting record should preserve interval data, source identity, units, time information, quality status and the history of manual actions.
What ALCOA+ means for utility records
| ALCOA+ attribute | Application to energy data audit trails |
|---|---|
| Attributable | Each manual entry, correction, approval, configuration amendment and access-role change identifies the authenticated user or system account. |
| Legible | Records show a meaningful tag name, utility, unit, time zone, source description and value that a reviewer can interpret. |
| Contemporaneous | The system records acquisition time and event time when data or an action occurs, with controlled time synchronisation. |
| Original | Raw acquired readings and their metadata remain available alongside calculated or aggregated values. |
| Accurate | Meter selection, installation, scaling, conversion logic, calibration or verification status and calculation inputs are controlled. |
| Complete | The system retains gaps, rejected values, substitutions, corrections and explanations rather than presenting a falsely continuous record. |
| Consistent | Units, time conventions, tag naming, calculations and retention rules remain controlled across reporting periods. |
| Enduring | Retained records and audit entries remain protected for the applicable retention period. |
| Available | Authorised personnel can retrieve human-readable data and audit evidence promptly during review or inspection. |
The value of this framework appears most clearly when a record is challenged. If a gas total differs from a finance report, an investigation should identify whether the issue arose at the meter, during data collection, through unit conversion, during aggregation or from a later manual correction.
Preserve raw and derived values
Energy-monitoring systems produce derived records: daily totals, energy per batch, energy-intensity indicators, CO₂e calculations and cost allocations. These outputs inform decisions, but must not obscure their source.
A defensible audit trail separates five elements:
- Raw readings acquired from the meter, analyser or approved source tag.
- Data-quality events, such as communication loss, implausible values, late-arriving records or missing intervals.
- Configured transformations, including scaling, aggregation, time-zone treatment and allocation rules.
- Calculation inputs, including emission factors, tariffs and production references.
- Issued reports, review records, approvals and exports.
If an authorised user corrects a value after a meter fault, the system should preserve the original value, replacement value, reason, supporting evidence, date and user identity. An overwritten record leaves an auditor unable to assess the correction.
What an energy data audit trail should capture

The MHRA describes an audit trail as metadata that records the lifecycle of a GxP record, including the who, what, when and why of creation, modification or deletion. For energy monitoring, the trail should concentrate on events that can change a record’s meaning, completeness or reportability.
Capture changes that affect reported figures
An energy audit trail should record:
- Creation, amendment and retirement of monitored meter points and tags.
- Changes to engineering units, multipliers, conversion factors and aggregation rules.
- Changes to data-quality rules, exception handling and approved substitution methods.
- Manual entry, correction, exclusion, restoration and approval of data.
- Changes to report templates, KPIs, production-allocation logic and emissions-factor sets.
- User-account creation, role changes, account disablement and approval-authority changes.
- Communication interruptions, recovery actions and resulting data gaps.
- Creation, review, approval and export of externally reported or GMP-relevant records.
- Archive, restoration and retrieval activity where it affects retained evidence.
The audit entry should show the before-and-after state for a configuration amendment. “Configuration changed” does not establish whether a multiplier changed from 1 to 10, a meter was reassigned to another utility stream, or a report calculation changed during the reporting year.
Treat metadata as part of the record
MHRA guidance identifies metadata as data that provide the context and meaning of other data. For energy reporting, essential metadata includes meter location, asset served, utility type, source identifier, engineering unit, sampling interval, time zone, calibration or verification status, owner, reporting boundary and intended use.
A steam meter on a site main and one serving a clean-steam generator may both report in kilograms per hour. They do not carry the same operational meaning. A controlled tag and asset register avoids accidental aggregation across boundaries and speeds later investigation.
The register should also state how a meter relates to an emissions source, production area or reporting entity. This supports environmental reporting while giving Quality Assurance a clear route to identify energy records linked to GMP-relevant utilities.
GAMP 5 and risk-based validation of energy reporting
ISPE GAMP 5: A Risk-Based Approach to Compliant GxP Computerised Systems, Second Edition, published in 2022, supports lifecycle controls proportionate to patient safety, product quality and data-integrity risk. It does not require an identical validation package for every energy-monitoring function.
The appropriate level of assurance follows intended use. A system used only for site energy reporting may require controlled configuration, access management and calculation verification. A system that supports a quality investigation or a GMP-relevant utility decision needs a more detailed assessment of data integrity, record review and failure conditions.
Assess configured products accurately
A configured energy-intelligence deployment may fall within GAMP Category 4, Configured Product, where standard software functions are configured to meet site-specific requirements for calculations, reports, roles, alerts or workflows. The category should follow the actual configuration and risk assessment, not the presence of a meter or PLC connection.
Category 4 does not make a facilities platform automatically GMP-critical. It identifies the need to demonstrate that the approved configuration performs as intended.
For a GxP-relevant implementation, the validation set commonly includes:
- A user requirements specification defining intended use, data sources, review requirements, audit events, retention and reporting outputs.
- A data-integrity risk assessment linking credible failures to controls and test evidence.
- Configuration specifications for tags, calculations, user roles, reports and exception handling.
- Traceability from requirements through testing to approved acceptance.
- Test evidence for audit-trail generation, role-based action, source-data retrieval and report reproduction.
- Change-control records for later configuration amendments.
Supplier documentation can support this work. The site still needs evidence that its configured deployment operates correctly in its approved environment.
Test exceptions, not only normal operation
Normal data collection is the least demanding condition. Qualification should also test events that challenge a record’s integrity.
Relevant tests include loss and restoration of data collection, missing intervals, duplicate timestamp handling, rejected values, manual correction, failed login, role change, calculation change, report amendment and audit-trail retrieval after archiving. Each protocol should state the expected behaviour, audit evidence and acceptance criterion.
Periodic review should assess whether the reporting boundary, user roles, data sources, calculations, retention arrangements or risks have changed. Meter replacement, rescaling and utility-network modification can each alter the meaning of a trend. Change control should assess that effect before the site relies on the new record for regulated reporting.

Track energy consumption, emissions, and process parameters with seamless PLC/SCADA integration via Modbus, OPC-UA, and MQTT protocols.
Audit-ready energy reporting for ISO 50001, SECR and ETS
ISO 50001:2018 provides a framework for establishing, implementing, maintaining and improving an energy-management system. Its energy-performance process depends on documented information that explains energy baselines, energy-performance indicators, monitoring methods and performance evaluation.
An audit trail gives those records continuity. It connects an Energy Performance Indicator to its source meters, calculation version, relevant production context and review decision. This is valuable when staff change, reporting templates are revised or a claimed improvement requires independent examination.
SECR needs a traceable calculation basis
The UK Streamlined Energy and Carbon Reporting framework requires qualifying companies and limited liability partnerships to disclose annual energy use, greenhouse-gas emissions and related information. It does not prescribe a single monitoring technology or audit-trail format.
A controlled energy record can reduce dependence on manual spreadsheet consolidation. The issued reporting file should retain the reporting period, organisational and operational boundaries, energy sources, exclusions, emission-factor set, calculation method, evidence of review and final approved output.
The factor version matters. Recalculating a historical report with a later government conversion-factor set can produce a different answer and obscure the basis of the original disclosure. A sound audit trail preserves the version used when the report was approved.
UK ETS and EU ETS require reproducible evidence
A pharmaceutical facility falls within the UK ETS or EU ETS only where its activities meet the relevant scheme scope. For affected sites, fuel and energy records may form part of the evidence reviewed by an accredited verifier.
Under the UK ETS, operators monitor emissions from 1 January to 31 December in accordance with their approved monitoring plan and the Monitoring and Reporting Regulation. They submit the verified annual emissions report and verification report through the Manage your UK ETS reporting service by 31 March.
For EU installations, European Commission Implementing Regulation (EU) 2018/2066 requires operators to obtain, record, compile, analyse and document monitoring data, assumptions, references, activity data and calculation factors transparently so that the verifier and competent authority can reproduce the emissions determination.
That requirement closely mirrors good data-integrity practice. The reporting process needs controlled source data, documented calculations, retained changes and evidence that missing data or corrective action received appropriate treatment.
Build an audit pack that inspectors can use

Audit readiness depends on retrieval discipline. A vast volume of electronic logs does not help if a reviewer cannot identify records relevant to a reported figure.
For a material utility or emissions report, the site should be able to assemble a coherent evidence pack containing:
- The approved report purpose, scope and reporting period.
- The controlled source-meter and tag register.
- Raw-data extracts and associated data-quality exceptions.
- The approved calculation, allocation and emissions-factor versions.
- Audit entries for configuration changes affecting the period.
- Correction records and supporting evidence.
- Reviewer identity, review date and approval outcome.
- The archived copy of the issued report.
- Retrieval-test evidence where records have moved to archive.
This structure lets an auditor follow the record without broad access to production controls. It also gives Quality Assurance, validation and sustainability teams a common basis for investigating a disputed result.
Where Omni Vision fits in pharmaceutical compliance
For pharmaceutical sites, EnerTherm Engineering’s Omni Vision platform can be specified as a bounded, read-only energy-monitoring layer for electricity, gas, water, steam, compressed air and oil. The user requirements specification and risk assessment should define which records support environmental reporting, which have GxP relevance, and what audit evidence the configured deployment must retain.
The configured deployment should preserve source context, calculation history, approved corrections and review evidence throughout the record lifecycle. This gives regulated pharma a credible energy report and a retrievable trail behind it.
This article reflects the independent analysis and editorial opinion of EnerTherm Engineering. Product names, trademarks, and brands mentioned belong to their respective owners. EnerTherm Engineering is not affiliated with, endorsed by, or a licensee of any third-party software or product mentioned unless explicitly stated.
