This is a ready-to-use log for the independent periodic review of privileged activity on GxP systems. It is the record that proves the highest-privilege actions on a system, the ones an application audit trail cannot see, were accounted for by someone who is not the administrator being reviewed. Replace every <<FILL: ...>> placeholder, keep the log under Quality control, and draw the events from the tamper-evident off-host store, never the host’s local copy. A filled specimen follows. This content is educational reference, not legal or regulatory advice; adapt it to your own quality system and verify each cited regulation against the current source before you rely on it.
Header
| Field | Entry |
|---|---|
| Log title | Privileged Access and Administrator Activity Review Record |
| Log / form number | <<FILL: FORM-ID, e.g. FRM-QA-088>> |
| System(s) covered | <<FILL: SYSTEM NAME(S) / ID>> |
| Review period | <<FILL: from date>> to <<FILL: to date>> |
| Event source | <<FILL: off-host store name / reference>> |
| Review frequency and basis | <<FILL: e.g. Monthly, High-risk release system>> |
| Governing SOP | <<FILL: SOP-ID for security event review>> |
Field definitions
| Field | Format | Required | Who enters | When |
|---|---|---|---|---|
| Line no. | Integer | Yes | Reviewer | At review |
| Event date / time | Timestamp from the log | Yes | Reviewer | At review |
| Actor (account) | Account identity from the log | Yes | Reviewer | At review |
| Named individual | Real person behind the account | Yes | Reviewer | At review |
| Event type | Privileged login / direct DB access / clock change / audit-trail change / logging stop / account or privilege change / other | Yes | Reviewer | At review |
| Host / target | System, database, or object acted on | Yes | Reviewer | At review |
| Authorizing record | Change no., incident ticket, maintenance record, or access request | Yes | Reviewer | At review |
| Reconciled? | Yes / No | Yes | Reviewer | At review |
| Exception / deviation ref | Deviation number if not reconciled | Conditional | Reviewer | At review |
| Reviewer initials | Initials | Yes | Reviewer | At review |
Instructions
- Pull every integrity-relevant privileged event for the period from the off-host store. Reviewing the host’s local copy reintroduces the tampering risk the store exists to remove.
- Enter one line per event. Do not summarize multiple privileged actions into a single line; each must reconcile on its own.
- For each event, find the authorizing record. A privileged action with no authorizing record is not reconciled and is raised as a deviation the same working day.
- Confirm the account maps to a named individual. A shared or generic account that cannot be tied to a person is itself a finding, note it and raise it.
- Sign and date the closeout. Route exceptions into the quality system and track them to closure; an exception with no follow-through is worse than no review.
- Retain the completed log for not less than
<<FILL: retention period, at least the retention of the records the system supports>>.
Reviewer independence attestation
I confirm I am not the administrator whose activity is recorded on this log, and that I reviewed the events from the tamper-evident off-host store. Reviewer:
<<FILL: name>>, signature:<<FILL>>, date:<<FILL>>.
Log grid (blank)
| Line | Event date/time | Actor (account) | Named individual | Event type | Host / target | Authorizing record | Reconciled? | Exception / dev ref | Init |
|---|---|---|---|---|---|---|---|---|---|
| 1 | <<FILL>> | <<FILL>> | <<FILL>> | <<FILL>> | <<FILL>> | <<FILL>> | <<FILL>> | <<FILL>> | <<FILL>> |
| 2 | |||||||||
| 3 |
Closeout
| Field | Entry |
|---|---|
| Total privileged events / reconciled | <<FILL>> / <<FILL>> |
| Exceptions raised (count) | <<FILL>> |
| Deviation reference(s) | <<FILL>> |
| Reviewer (name, signature, date) | <<FILL>> |
| QA approval (name, signature, date) | <<FILL>> |
Acceptance criteria
- Every integrity-relevant privileged event in the period appears on exactly one line.
- Each line either reconciles to an authorizing record or carries a deviation reference.
- Every account maps to a named individual, or the shared-account use is itself raised.
- The reviewer attestation is signed, the source is the off-host store, and QA has approved.
- Exceptions are tracked to closure in the quality system.
References
21 CFR Part 11, sections 11.10(d), (e), and (g). EU GMP Annex 11, section 12 (security). MHRA GxP Data Integrity Guidance and Definitions. PIC/S PI 041, Good Practices for Data Management and Integrity.
Confirm the current version and clause numbers of each reference before issue.
Filled specimen
The following shows a completed monthly review for an example database server supporting a release-testing chromatography data system. Illustrative only.
| Line | Event date/time | Actor (account) | Named individual | Event type | Host / target | Authorizing record | Reconciled? | Exception / dev ref | Init |
|---|---|---|---|---|---|---|---|---|---|
| 1 | 04 Jun 2026 09:12 | admin_jpatel | J. Patel | Privileged login | DB-CDS-02 | CHG-2026-0451 (index rebuild) | Yes | - | RG |
| 2 | 11 Jun 2026 14:38 | admin_jpatel | J. Patel | Privilege change | Directory (added L. Owens to DB-Operators) | REQ-ACC-2026-0771 | Yes | - | RG |
| 3 | 16 Jun 2026 23:14 | svc_dbadmin | Unknown (shared) | Direct DB access + UPDATE | DB-CDS-02 results table | None found | No | DEV-2026-0207 | RG |
| 4 | 16 Jun 2026 23:12 | svc_dbadmin | Unknown (shared) | Logging service stopped | DB-CDS-02 | None found | No | DEV-2026-0207 | RG |
Lines 3 and 4 did not reconcile: a shared service account performed a direct edit on the results table with logging briefly stopped, and no change record or deviation existed. The reviewer raised both under one deviation the same day. The investigation invalidated the affected result, held the batch, decommissioned the shared account in favor of named credentials without direct database rights, and added a real-time alert on logging-stopped. Lines 1 and 2 reconciled cleanly to an approved change and an approved access request.
Common inspection findings this log prevents
- Privileged activity is not reviewed at all, so no one can say whether administrator actions were authorized.
- The review is performed by the same function whose activity is under review, with no independent challenge.
- A “review” exists but cannot show its scope, source, or which events were examined.
- Direct database edits or logging stops occurred and were never reconciled to an authorizing record.
- Shared or service accounts perform privileged actions that cannot be attributed to a person.
How to adapt this log
- Set your form number, governing SOP, and retention in the header.
- Confirm your off-host store is named as the event source and that reviewers cannot be the administrators under review.
- Add columns your systems need (for example a ticketing-tool link) without removing any reconciliation field.
- Point the deviation reference to your real deviation procedure.
- Confirm every regulation in the references against the current published version before issue.