The data couldn't be altered. Except it could.
What the Post Office Horizon scandal should make every pharma professional ask about their own suppliers.
A system that promised certainty
In 1999, the UK's Post Office started pulling the paper ledgers out of its branches and replacing them with a computer. The system was called Horizon, built originally by ICL and inherited by Fujitsu, and over the next few years it was rolled out to around 14,000 branches, all connected to one central accounting system. Most of those branches were run by subpostmasters: self-employed people who held a contract to operate a local Post Office, usually alongside their own shop. They keyed each transaction into a touchscreen, and Horizon did the arithmetic in the background. It promised something simple and appealing: one accurate, reliable record of every sale, payment and transfer across the whole network.
At the end of each accounting period, the subpostmaster had to balance the branch. You counted the actual cash and stock on hand and checked it against what Horizon said you should have. If the two didn't match, the difference was a shortfall, and under the contract the subpostmaster had to cover it themselves unless they could prove it wasn't their fault. So whatever Horizon said was missing came straight out of the pocket of the person at the counter.
When the numbers were wrong
The trouble was that Horizon produced shortfalls that were not real. Software faults invented money that had never gone missing. In the Dalmellington bug, a frozen screen tricked the system into logging the same cash transfer over and over, leaving one subpostmaster staring at a £24,000 hole that existed only in the software. The Callendar Square bug quietly duplicated entries in the ledger. Subpostmasters called the helpline to report the discrepancies and were told, in effect, that the system was sound and the mistake was theirs.
There was a further cruelty in how the system worked. Horizon gave no way to record a figure as disputed. To close the accounting period at all, the subpostmaster had to accept the balance on the screen, which meant signing a declaration that it was correct, even when they knew it was not. People with no means of proving the software wrong were required to put their name to its numbers as though they were their own honest account, and that signature was often the very thing the Post Office later used to charge them with false accounting. The few who refused outright, and would not sign off on an account they did not believe, were treated as troublemakers and pushed out, but they never handed over the signed false statement the prosecutions leaned on.
The people who could reach in
One assurance in particular came up again and again: that nobody outside the branch could reach in and alter those accounts. At Fujitsu's Software Support Centre in Bracknell, a team of roughly twenty-five to thirty people could do precisely that. They had remote access to branch accounts and could adjust and overwrite transaction data on the live system. Richard Roll, a former Fujitsu engineer who eventually blew the whistle, described the access as effectively unaudited, and his old colleagues as people who could "crack anything" and get in through the back door without the subpostmaster ever knowing. The public inquiry later heard the same thing in flatter language: the access was "unrestricted and unauditable."
The official position, repeated to Parliament as late as 2015, was that there was "no functionality in Horizon for either a branch, Post Office or Fujitsu to edit, manipulate or remove transaction data once it has been recorded in a branch's accounts." The Post Office only conceded otherwise in 2019, in the High Court, once it had run out of room to deny it.
Held accountable for data they couldn't see
More than 900 subpostmasters were prosecuted on the strength of the system's word, and many more quietly paid back shortfalls that were never real. What I keep coming back to is the gap between those two facts. On one side, a person behind a counter being told the system is sound and the missing money is their responsibility. On the other, a support team that could reach into that same system and change what it recorded. The people held accountable for the data were the only ones in the chain who couldn't see what was being done to it.
That is a data integrity story. It just happens to be wearing a Post Office uniform.
Why this should feel familiar
Almost everything that failed at Horizon maps onto principles this industry has already written down and made mandatory. We talk about ALCOA+: data should be attributable, legible, contemporaneous, original and accurate, and on top of that complete, consistent, enduring and available. Horizon's records were none of those things in any way a subpostmaster could rely on. The changes weren't attributable, because privileged users could edit without leaving a trace. They weren't complete, because the audit data handed to courts had been filtered. And they weren't available to the one person who most needed them. There is also a part no acronym quite captures: nobody should ever be put in a position where they have to attest to a figure they know is wrong, which is what Horizon demanded of a subpostmaster every time a branch closed its books.
Annex 11 and 21 CFR Part 11 exist to stop exactly this. Audit trails that cannot be switched off. Access controls that separate ordinary users from administrators. A durable record of who changed what, when, and why. The reason regulators are so preoccupied with privileged access, the admin accounts and the database-level "IT can fix it from here" edits, is that this is precisely where Horizon came apart. Give someone elevated rights and no oversight and they can quietly rewrite reality, while the person living with the result never finds out.
If you work in pharma, none of this theory is new to you. The uncomfortable part is that Fujitsu presumably knew it too. Knowing the rules and having the rules followed are not the same thing.
The part that should change how you work
You already know audit trails matter, so I won't dwell on it. The harder question is what you do when a supplier hands you a guarantee.
The Post Office's guarantee was that the data couldn't be touched. Nobody with the power to check ever really checked, until litigation dragged it into the open. By then, hundreds of lives had been wrecked on the basis of a statement that a few days of honest, independent investigation would have exposed.
In pharma we lean on supplier statements all the time. The vendor says the system is validated. The CMO says the audit trail is switched on and reviewed. The lab software provider says users can't alter results, that timestamps are locked, that deleted data can be recovered. Most of the time those statements are made in good faith and they're accurate. But "most of the time" is carrying a lot of weight in that sentence, and you can outsource the activity without ever outsourcing the accountability. When it goes wrong, the finding lands on the marketing authorisation holder, not the supplier.
So verify. Good faith on the supplier's side doesn't change the arithmetic: the cost of being wrong is enormous, and the cost of checking is a few days and some slightly awkward questions. Ask to see the audit trail configuration rather than a description of it. Watch someone try to change a locked record and confirm the attempt is actually logged. Find out who holds administrator rights on the system your quality decisions depend on, and what stops them using those rights quietly. Run a real supplier audit instead of trading a questionnaire by email.
And do it while you still can. This is the part that gets missed. The window for verification doesn't stay open. Audit trails get archived or overwritten. Retention periods lapse. System migrations quietly leave the old data behind. Contracts end, people move on, and the person who could have shown you the truth takes their knowledge with them. Evidence that exists today may be gone next year, and the moment you finally need it tends to be the moment it is hardest to reconstruct.
The subpostmasters never had this option. They couldn't audit Fujitsu. They couldn't see the back door. They were handed a number, told it was true, and left with no standing to test it and no way to know that a team elsewhere could change it. That powerlessness is what makes their story so hard to sit with.
You are almost never in that position. When a supplier gives you a guarantee about the integrity of your data, you usually hold the contractual right, the technical means and the professional standing to test whether it holds up. Horizon is a reminder of what it costs when people who could have checked simply didn't, while the checking was still possible.
You don't have to treat every vendor as a suspect to take this seriously. You do have to notice the moments when you're signing off on a statement you could check yourself, and treat checking it as part of the job rather than a formality.