Data Integrity Risk
Data integrity risk is the chance that data becomes inaccurate, incomplete, or altered in an unauthorized way at some point during its lifecycle, whether when it is created, transmitted, or stored. In a third-party context, this risk arises when data shared with or handled by suppliers and service providers may not remain reliable and accurate. It concerns whether data can still be trusted, not whether it has been kept confidential or remains available.
Data integrity risk is the exposure arising from the potential loss of the integrity property of data, defined as data having been altered in an unauthorized manner since it was created, transmitted, or stored. The risk spans the full data lifecycle and, in third-party and supply chain settings, extends to data processed, transmitted, or retained by vendors and service providers, where limited visibility may reduce assurance over controls. Data integrity risk is distinct from confidentiality and availability risks: an integrity failure concerns the accuracy, completeness, and trustworthiness of data rather than its exposure or accessibility. Managing this risk typically involves risk-based programs that address people, processes, and controls across the lifecycle; note that self-attested controls or point-in-time reviews of a third party's environment may not provide independent, ongoing verification of integrity. Applicable control expectations vary by sector and jurisdiction (for example, regulated life sciences environments may reference requirements such as 21 CFR provisions that do not apply universally).
Why it matters
Data integrity risk matters because decisions, transactions, and controls all depend on data that can be trusted. When data shared with or handled by a third party becomes inaccurate, incomplete, or altered in an unauthorized way, the consequences flow back to the organization that relies on it: flawed reporting, incorrect operational decisions, or corrupted records that may not be detected until well after the fact. Unlike a confidentiality breach, which concerns whether data has been exposed, or an availability failure, which concerns whether data is accessible, an integrity failure concerns whether the data can still be believed at all. Data that looks complete and available may nonetheless be wrong.
Who it's relevant to
Inside Data Integrity Risk
Common questions
Answers to the questions practitioners most commonly ask about Data Integrity Risk.