This is a ready-to-use controlled log for end-user computing (EUC) tools, overwhelmingly Excel spreadsheets, that do regulated work. The finding this log prevents is the most common one in this space: a release-calculation workbook that is on no inventory, so it is unmanaged by definition. Replace every <<FILL: ...>> placeholder with your own specifics and route the log through document control. A filled sample row follows. This content is general educational reference, not legal or regulatory advice.
Purpose
Maintain a single controlled list of every EUC tool with GxP relevance, its risk classification, and its validation and control status, so that each one is visible, owned, and kept in a controlled state. An unlisted calculating spreadsheet is an uncontrolled one; the inventory entry is the first thing an inspector checks and the first thing that is missing.
Scope
Any end-user-built tool whose output affects product quality, patient safety, or a regulatory submission: assay and stability calculations, dissolution math, environmental monitoring trending, yield reconciliation, out-of-specification calculations, and anything feeding a Certificate of Analysis or a batch disposition. Tools with no GxP data or decision are out of scope and marked as such, not omitted.
Log field definitions
| Field | Format | Required | Who enters | When |
|---|---|---|---|---|
| EUC ID | Controlled unique ID | Yes | Owner / QA | On registration |
| Name and file reference | Text + file path | Yes | Owner | On registration |
| Purpose / calculation | Text | Yes | Owner | On registration |
| GxP impact | Yes / No | Yes | Owner + QA | On registration |
| Risk class | Out of scope / Low / Medium / High | Yes | Owner + QA | On classification |
| Validation status | Not required / Planned / Validated / Retired | Yes | QA | On status change |
| Validation record ref | Doc number | If validated | QA | On validation |
| Protection applied | Yes / No / N/A | Yes | Owner | On release |
| Controlled storage location | Path / DMS ref | Yes | Owner | On release |
| Version identifier (in file) | Text | Yes for validated | Owner | On release |
| Owner | Name / role | Yes | QA | On registration |
| Last periodic review | Date | Yes | Owner | Each review |
| Next review due | Date | Yes | Owner | Each review |
The inventory
| EUC ID | Name / file | Purpose | GxP impact | Risk class | Validation status | Validation ref | Protection | Storage | Version | Owner | Last review | Next due |
|---|---|---|---|---|---|---|---|---|---|---|---|---|
<<FILL>> | <<FILL>> | <<FILL>> | <<FILL: Yes/No>> | <<FILL>> | <<FILL>> | <<FILL>> | <<FILL>> | <<FILL>> | <<FILL>> | <<FILL>> | <<FILL>> | <<FILL>> |
<<FILL>> | <<FILL>> | <<FILL>> | <<FILL>> | <<FILL>> | <<FILL>> | <<FILL>> | <<FILL>> | <<FILL>> | <<FILL>> | <<FILL>> | <<FILL>> | <<FILL>> |
Classification rule (applied on registration)
- If the output does not affect product quality, patient safety, or a submission, mark Out of scope and keep it out of GxP decisions.
- If it does, it is in scope (a computerized system under Annex 11). Then grade: Low (simple single-cell arithmetic, output independently checkable, no stored records), Medium (multi-step calculations, lookups, or conditional logic feeding a GxP record), or High (macros/VBA, complex logic, or it retains records).
- Low gets lightweight verification and a controlled template; Medium gets full lifecycle validation; High gets full validation, and a documented consideration of whether it should be a validated application instead.
Acceptance criteria for the log
- Every in-scope EUC tool is listed with an owner, a risk class, and a validation status.
- No in-scope Medium or High tool is in use with validation status “Planned” past its committed date without a documented interim control.
- Every validated tool has a validation reference, a controlled storage location, protection applied, and a version identifier inside the file.
- Periodic review dates are current; overdue reviews are visible and actioned.
References
EU GMP Annex 11, Computerised Systems. 21 CFR Part 11 and the predicate rules under 21 CFR 210/211. MHRA GxP Data Integrity Guidance and Definitions (2018). ISPE GAMP 5 (second edition) for the software category and risk approach.
Confirm the current version of each reference before issue.
Retention
Retain this log as a controlled quality record for not less than <<FILL: retention period>>, and retain superseded versions per the records retention schedule.
Revision history
| Version | Date | Author | Summary of change |
|---|---|---|---|
<<FILL: 1.0>> | <<FILL: date>> | <<FILL: author>> | Initial issue. |
Filled sample rows
The following illustrative rows show the level of detail expected. Company and file specifics are illustrative.
| EUC ID | Name / file | Purpose | GxP impact | Risk class | Validation status | Validation ref | Protection | Storage | Version | Owner | Last review | Next due |
|---|---|---|---|---|---|---|---|---|---|---|---|---|
| EUC-014 | ASSAY-LC-CALC.xlsx | % label claim from paired responses | Yes | Medium | Validated | VAL-SS-009 | Yes | QA controlled folder (read-only) | v2.0 (cell A1) | QC lab lead | 12 Mar 2026 | 12 Mar 2027 |
| EUC-021 | STAB-TREND.xlsx | Stability trending and shelf-life fit | Yes | High | Validated | VAL-SS-012 | Yes | Validated DMS | v1.3 | Stability lead | 02 Feb 2026 | 02 Feb 2027 |
| EUC-033 | MEETING-TRACKER.xlsx | Team meeting actions | No | Out of scope | Not required | n/a | N/A | Team drive | n/a | Dept admin | n/a | n/a |
Row EUC-021 is the one to watch: a High-risk, record-retaining stability workbook. The log shows it validated and in a validated DMS (so the retained files get access control and audit trail around them), and it carries a next-review date, which is where the team should reconsider whether it belongs in Excel at all.
Common inspection findings this log prevents
- A GxP-relevant calculating spreadsheet that appears on no inventory, so nobody owns or controls it.
- Risk classes assigned with no rule, so effort is disproportionate to impact.
- A “validated” tool with no version identifier inside the file, so a printout cannot be tied to the version that produced it.
- Periodic reviews that never happen because no due date is tracked.
- High-risk macro workbooks retaining records with no plan to migrate them to a proper validated system.
How to adapt this log
- Seed it by asking each GxP-facing team what spreadsheets they use to produce or decide anything; the unlisted ones are the risk.
- Apply the classification rule consistently and record the rationale for borderline calls.
- Tie the validation status to your spreadsheet validation protocol so “Validated” always has a reference. See infrastructure qualification and spreadsheet validation.
- Set and honor periodic review dates; a change to a validated workbook is a change to a validated system and triggers re-verification and a version increment.