This is a ready-to-use inventory and data-criticality form for GxP computerized systems. The inventory is the foundation the rest of the data-integrity program stands on: you cannot review audit trails, define system-of-record ownership, or scope validation for systems you have not listed and classified. Replace <<FILL: ...>> placeholders, adopt the field definitions, and maintain the inventory as a controlled living record. A filled specimen row follows. Confirm each cited regulation against the current source before you rely on it.
Control header
| Field | Entry |
|---|---|
| Document title | GxP Computerized System Inventory and Data Criticality Assessment |
| Document number | <<FILL: e.g. LOG-DI-001>> |
| Owner | <<FILL: role, e.g. Data Integrity Lead / Validation>> |
| Review frequency | <<FILL: e.g. annually and on change>> |
| Retention | <<FILL: e.g. life of the systems plus the site records-retention period>> |
Field definitions
| Field | Format | Required | Who enters | When |
|---|---|---|---|---|
| System ID | Unique code | Yes | Inventory owner | At registration |
| System name | Text | Yes | Inventory owner | At registration |
| Business owner / system owner | Role and name | Yes | Inventory owner | At registration |
| Function / process supported | Text | Yes | System owner | At registration |
| GxP? (Yes / No / Partial) | Controlled value | Yes | QA with system owner | At registration and on change |
| GxP rationale | Text | Yes | QA | At determination |
| Regulatory basis | Text (for example Part 211, Part 11, Annex 11, QMSR) | Yes | QA | At determination |
| GAMP category | 1, 3, 4, or 5 | Yes | Validation | At registration |
| Data criticality tier | High / Medium / Low | Yes | QA with data owner | At registration and on change |
| Original records held | Text (which records this system is the original for) | Yes | System owner | At registration |
| Audit-trail-review frequency | Controlled value | Yes | QA | At determination |
| Validation status | Not started / In progress / Validated / Retired | Yes | Validation | Ongoing |
| Interfaces (to / from) | List of System IDs | Yes | System owner | At registration and on change |
| Periodic review due | Date | Yes | System owner | Ongoing |
| Last change reference | Change-control ID | No | System owner | On change |
Instructions
- Register every computerized system that could create, modify, store, or transmit a GMP record, before deciding whether it is GxP. Systems you exclude must still appear, marked GxP = No with a rationale.
- Make the GxP determination point by point for platforms that are partly in scope (a BMS is the classic case: classified-area data is GxP, comfort HVAC is not). Record “Partial” and describe the in-scope data.
- Set data criticality from the GMP decision the data supports, not the price of the software. A validated spreadsheet that sets a release limit can outrank a six-figure platform. See data criticality and data risk.
- Record which records each system is the original (first-capture) copy for, so downstream copies and interfaces can be reconciled against it.
- Set audit-trail-review frequency from criticality (High: each batch/run; Medium: weekly or monthly; Low: at periodic review), consistent with your audit trail review SOP.
- Keep the inventory under change control; every system change updates its row, and new systems are added before go-live.
The inventory table
| System ID | System name | Owner | Function | GxP? | Regulatory basis | GAMP cat. | Criticality | Original records | Audit-trail review freq. | Validation status | Interfaces | Periodic review due |
|---|---|---|---|---|---|---|---|---|---|---|---|---|
<<FILL>> | <<FILL>> | <<FILL>> | <<FILL>> | <<FILL>> | <<FILL>> | <<FILL>> | <<FILL>> | <<FILL>> | <<FILL>> | <<FILL>> | <<FILL>> | <<FILL>> |
<<FILL>> | <<FILL>> | <<FILL>> | <<FILL>> | <<FILL>> | <<FILL>> | <<FILL>> | <<FILL>> | <<FILL>> | <<FILL>> | <<FILL>> | <<FILL>> | <<FILL>> |
Acceptance criteria for a defensible inventory
- Every system that could touch a GMP record appears, including those excluded as non-GxP with a rationale.
- The GxP determination, regulatory basis, GAMP category, and criticality are recorded and approved by QA.
- Each system’s original-record ownership is stated, so interfaces and copies can be reconciled.
- Audit-trail-review frequency follows criticality and matches the review SOP.
- The inventory is under change control and reviewed on schedule; no system reaches production absent from it.
References
EU GMP Annex 11 (computerised systems), including risk management and periodic evaluation. 21 CFR Part 11; FDA and MHRA data-integrity guidance (data criticality and audit-trail review). ISPE GAMP 5 (Second Edition) for the software-category concept. Related reading: GxP manufacturing and laboratory systems, data criticality and data risk.
Confirm the current version and clause numbers of each reference before issue.
Revision history
| Version | Date | Author | Summary of change |
|---|---|---|---|
<<FILL: 1.0>> | <<FILL>> | <<FILL>> | Initial issue. |
Filled specimen
The following shows one completed inventory row for an example chromatography data system, so you can see how the fields read. The values are illustrative.
| Field | Entry |
|---|---|
| System ID | LAB-CDS-01 |
| System name | Chromatography Data System (QC lab) |
| Owner | QC Systems Manager, R. Gomez |
| Function | Acquires and processes HPLC/GC data for release and stability testing |
| GxP? | Yes |
| Regulatory basis | 21 CFR 211.194, 21 CFR Part 11, EU GMP Annex 11 |
| GAMP category | 4 (configured) |
| Criticality | High (output drives release decisions) |
| Original records | Chromatographic raw data files (this system is the original; LIMS holds copies) |
| Audit-trail review frequency | Each analytical run, before the result is used |
| Validation status | Validated |
| Interfaces | Instruments to CDS (in); CDS to LAB-LIMS-01 (out) |
| Periodic review due | 2027-03-15 |
In this example the row records not just that the CDS is GxP and high-criticality, but that it holds the original raw data while the LIMS holds copies, and that its audit trail is reviewed every run. Those two facts, original-record ownership and criticality-driven review frequency, are what let a reviewer connect this system to its interfaces and its review obligations. A common weak inventory lists the system and its GAMP category but never states what it is the original for or how often its trail is reviewed.
Common inspection findings this form prevents
- No current inventory of GxP computerized systems, so scope cannot be demonstrated.
- Systems in production that never appear on any inventory.
- Criticality assigned by software cost or vendor tier rather than the decision the data supports.
- No record of which system holds the original for a shared value, so interface disagreements cannot be resolved.
- Audit-trail-review frequency fixed for every system with no link to criticality.
How to adapt this form
- Set your document number, owner, and review cadence in the header.
- Load every system, including validated spreadsheets and small utilities that touch GMP records.
- Make the GxP and criticality determinations with QA and record the rationale, especially for partial-scope platforms.
- Keep the original-record and interface columns accurate; they are what make the inventory useful for data-integrity work.
- Confirm every regulation against the current published version before issue.