Independent and not affiliated with the FDA, MHRA, ISPE, PDA, or any agency. Get the appgoutham@madhadi.com
madhadi.comData Integrity & GxP Quality
Browse all topics → Articles Templates & Procedures Learning paths GlossaryScenariosToolsRegulatory ReferencesLearning PathsTopics About Start here
Form Plug-and-play starting point Manufacturing Automation

Form: GxP Computerized System Inventory and Data Criticality Assessment

A plug-and-play inventory and data-criticality form for GxP computerized systems: fields, formats, the GxP determination, GAMP category, criticality tier, audit-trail-review frequency, and a filled specimen row, with retention and instructions.

Document type: Form

Read and copy the template below into your own quality system. It is a generic starting point for your own internal use, provided as is, with no warranty; see the Terms and License. Adopting it does not by itself create compliance.

This is a ready-to-use inventory and data-criticality form for GxP computerized systems. The inventory is the foundation the rest of the data-integrity program stands on: you cannot review audit trails, define system-of-record ownership, or scope validation for systems you have not listed and classified. Replace <<FILL: ...>> placeholders, adopt the field definitions, and maintain the inventory as a controlled living record. A filled specimen row follows. Confirm each cited regulation against the current source before you rely on it.

Control header

FieldEntry
Document titleGxP Computerized System Inventory and Data Criticality Assessment
Document number<<FILL: e.g. LOG-DI-001>>
Owner<<FILL: role, e.g. Data Integrity Lead / Validation>>
Review frequency<<FILL: e.g. annually and on change>>
Retention<<FILL: e.g. life of the systems plus the site records-retention period>>

Field definitions

FieldFormatRequiredWho entersWhen
System IDUnique codeYesInventory ownerAt registration
System nameTextYesInventory ownerAt registration
Business owner / system ownerRole and nameYesInventory ownerAt registration
Function / process supportedTextYesSystem ownerAt registration
GxP? (Yes / No / Partial)Controlled valueYesQA with system ownerAt registration and on change
GxP rationaleTextYesQAAt determination
Regulatory basisText (for example Part 211, Part 11, Annex 11, QMSR)YesQAAt determination
GAMP category1, 3, 4, or 5YesValidationAt registration
Data criticality tierHigh / Medium / LowYesQA with data ownerAt registration and on change
Original records heldText (which records this system is the original for)YesSystem ownerAt registration
Audit-trail-review frequencyControlled valueYesQAAt determination
Validation statusNot started / In progress / Validated / RetiredYesValidationOngoing
Interfaces (to / from)List of System IDsYesSystem ownerAt registration and on change
Periodic review dueDateYesSystem ownerOngoing
Last change referenceChange-control IDNoSystem ownerOn change

Instructions

  1. Register every computerized system that could create, modify, store, or transmit a GMP record, before deciding whether it is GxP. Systems you exclude must still appear, marked GxP = No with a rationale.
  2. Make the GxP determination point by point for platforms that are partly in scope (a BMS is the classic case: classified-area data is GxP, comfort HVAC is not). Record “Partial” and describe the in-scope data.
  3. Set data criticality from the GMP decision the data supports, not the price of the software. A validated spreadsheet that sets a release limit can outrank a six-figure platform. See data criticality and data risk.
  4. Record which records each system is the original (first-capture) copy for, so downstream copies and interfaces can be reconciled against it.
  5. Set audit-trail-review frequency from criticality (High: each batch/run; Medium: weekly or monthly; Low: at periodic review), consistent with your audit trail review SOP.
  6. Keep the inventory under change control; every system change updates its row, and new systems are added before go-live.

The inventory table

System IDSystem nameOwnerFunctionGxP?Regulatory basisGAMP cat.CriticalityOriginal recordsAudit-trail review freq.Validation statusInterfacesPeriodic review due
<<FILL>><<FILL>><<FILL>><<FILL>><<FILL>><<FILL>><<FILL>><<FILL>><<FILL>><<FILL>><<FILL>><<FILL>><<FILL>>
<<FILL>><<FILL>><<FILL>><<FILL>><<FILL>><<FILL>><<FILL>><<FILL>><<FILL>><<FILL>><<FILL>><<FILL>><<FILL>>

Acceptance criteria for a defensible inventory

  • Every system that could touch a GMP record appears, including those excluded as non-GxP with a rationale.
  • The GxP determination, regulatory basis, GAMP category, and criticality are recorded and approved by QA.
  • Each system’s original-record ownership is stated, so interfaces and copies can be reconciled.
  • Audit-trail-review frequency follows criticality and matches the review SOP.
  • The inventory is under change control and reviewed on schedule; no system reaches production absent from it.

References

EU GMP Annex 11 (computerised systems), including risk management and periodic evaluation. 21 CFR Part 11; FDA and MHRA data-integrity guidance (data criticality and audit-trail review). ISPE GAMP 5 (Second Edition) for the software-category concept. Related reading: GxP manufacturing and laboratory systems, data criticality and data risk.

Confirm the current version and clause numbers of each reference before issue.

Revision history

VersionDateAuthorSummary of change
<<FILL: 1.0>><<FILL>><<FILL>>Initial issue.

Filled specimen

The following shows one completed inventory row for an example chromatography data system, so you can see how the fields read. The values are illustrative.

FieldEntry
System IDLAB-CDS-01
System nameChromatography Data System (QC lab)
OwnerQC Systems Manager, R. Gomez
FunctionAcquires and processes HPLC/GC data for release and stability testing
GxP?Yes
Regulatory basis21 CFR 211.194, 21 CFR Part 11, EU GMP Annex 11
GAMP category4 (configured)
CriticalityHigh (output drives release decisions)
Original recordsChromatographic raw data files (this system is the original; LIMS holds copies)
Audit-trail review frequencyEach analytical run, before the result is used
Validation statusValidated
InterfacesInstruments to CDS (in); CDS to LAB-LIMS-01 (out)
Periodic review due2027-03-15

In this example the row records not just that the CDS is GxP and high-criticality, but that it holds the original raw data while the LIMS holds copies, and that its audit trail is reviewed every run. Those two facts, original-record ownership and criticality-driven review frequency, are what let a reviewer connect this system to its interfaces and its review obligations. A common weak inventory lists the system and its GAMP category but never states what it is the original for or how often its trail is reviewed.

Common inspection findings this form prevents

  • No current inventory of GxP computerized systems, so scope cannot be demonstrated.
  • Systems in production that never appear on any inventory.
  • Criticality assigned by software cost or vendor tier rather than the decision the data supports.
  • No record of which system holds the original for a shared value, so interface disagreements cannot be resolved.
  • Audit-trail-review frequency fixed for every system with no link to criticality.

How to adapt this form

  1. Set your document number, owner, and review cadence in the header.
  2. Load every system, including validated spreadsheets and small utilities that touch GMP records.
  3. Make the GxP and criticality determinations with QA and record the rationale, especially for partial-scope platforms.
  4. Keep the original-record and interface columns accurate; they are what make the inventory useful for data-integrity work.
  5. Confirm every regulation against the current published version before issue.
Use madhadi.com as an app Full screen, works offline, one tap from your home screen.