Independent and not affiliated with the FDA, MHRA, ISPE, PDA, or any agency. Get the appgoutham@madhadi.com
madhadi.comData Integrity & GxP Quality
Browse all topics → Articles Templates & Procedures Learning paths GlossaryScenariosToolsRegulatory ReferencesLearning PathsTopics About Start here
Log Plug-and-play starting point Manufacturing Automation

Register: Manufacturing Automation System Inventory and Criticality (ISA-95 Stack)

A ready-to-use register of every automation system on the floor organized by the ISA-95 level it sits at, with the GxP record it owns, its owner, validation status, audit-trail capability, and criticality, so an inspection's first three questions have a one-page answer.

Document type: Log

Read and copy the template below into your own quality system. It is a generic starting point for your own internal use, provided as is, with no warranty; see the Terms and License. Adopting it does not by itself create compliance.

The first three questions of almost any inspection of manufacturing automation are: what systems do you have, who owns them, and how do you know they work. This register answers all three on one page, organized by the ISA-95 level each system sits at (device, control, supervisory, execution, enterprise, and the historian archive), so the layered integrity risk is visible rather than buried in an alphabetical list. It is the article’s “practical first deliverable” made ready to fill. Replace every <<FILL: ...>> placeholder, keep the register under document control, and review it on a defined cadence. Field definitions, a filled specimen, and use notes follow. Verify each cited regulation against the current source before you rely on it.

Why this register exists (regulatory basis)

You cannot remediate, validate, or defend what you have not inventoried. 21 CFR 211.68 requires that automated equipment used in manufacturing be validated and controlled; EU GMP Annex 11 expects an up-to-date inventory of GMP computerized systems with their validation status and GxP relevance. Organizing the inventory by ISA-95 level makes the integrity profile of each layer explicit: the execution layer owns the batch record, the device layer often has no audit trail at all, and the risk sits differently at each. This register is the map that tells you where to spend remediation effort first.

Field definitions

FieldFormatRequiredNote
ISA-95 levelL0-L4 or ArchiveYesDevice (L0/L1), Control (L1), Supervisory (L2), Execution (L3), Enterprise (L4), Archive
System name / IDTextYesThe real name used on the floor
FunctionTextYesWhat it does in one line
Primary GxP record ownedTextYesThe record this system is the source of truth for
System ownerRole / nameYesAccountable person by function
GxP criticalityHigh / Medium / Low / non-GxPYesFrom the data criticality assessment
Validation statusValidated / In progress / Legacy-not-revalidated / N/AYesCurrent qualified state
Audit trail capabilityFull / Partial / None + compensatingYesDrives the DI remediation priority
Individual accountsYes / Shared / MixedYesAttribution status
Time sourceNTP / Local / N/AYesClock synchronization
Interfaces toSystem listYesWhere its data flows; feed the data-flow map
Remediation decisionRemediate / Replace / Compensate / NoneYesFor any open gap

Register

ISA-95 levelSystem name / IDFunctionPrimary GxP recordOwnerCriticalityValidation statusAudit trailIndividual accountsTime sourceInterfaces toRemediation decision
Enterprise (L4)<<FILL>>Material genealogy, lot disposition<<FILL>><<FILL>><<FILL>><<FILL>><<FILL>><<FILL>><<FILL>><<FILL>><<FILL>>
Execution (L3)<<FILL>>MES / EBRThe official batch record<<FILL>>High<<FILL>><<FILL>><<FILL>><<FILL>><<FILL>><<FILL>>
Supervisory (L2)<<FILL>>SCADA / HMIOperator actions, alarms, trends<<FILL>><<FILL>><<FILL>><<FILL>><<FILL>><<FILL>><<FILL>><<FILL>>
Control (L1)<<FILL>>DCSSetpoints, recipe parameters<<FILL>><<FILL>><<FILL>><<FILL>><<FILL>><<FILL>><<FILL>><<FILL>>
Device (L0/L1)<<FILL>>PLC / equipment controllerEquipment control logic, setpoints<<FILL>><<FILL>><<FILL>><<FILL>><<FILL>><<FILL>><<FILL>><<FILL>>
Archive<<FILL>>HistorianLong-term time-series process data<<FILL>><<FILL>><<FILL>><<FILL>><<FILL>><<FILL>><<FILL>><<FILL>>

Add a row per real system; a plant typically has several at each level.

Instructions for use

  1. Populate one row per real system, not per system type. A site with four fill lines has four MES instances or four line configurations to name.
  2. Set criticality from the data criticality assessment, driven by how the record feeds a quality decision or a regulatory submission, not by the size of the system.
  3. Where audit trail capability is “None + compensating” or accounts are “Shared”, the remediation decision field must not be blank; every open gap carries a documented Remediate/Replace/Compensate decision with an owner.
  4. Use the interfaces column to build the data-flow map for each critical value, so reconciliation across systems is traceable.
  5. Review the register on a defined cadence and after any system is added, retired, upgraded, or re-classified.

Acceptance criteria

  • Every GxP-relevant automation system on the floor appears, placed at its correct ISA-95 level.
  • Each row has an owner by function and a current validation status.
  • Every open integrity gap (partial/no audit trail, shared accounts, unsynced clock) has a documented remediation decision.
  • Criticality is justified against data criticality, and an inspector can pick any high-criticality system and find its owner, validation record, and controls.
  • The register is version-controlled and its review date is current.

Filled specimen

An illustrative extract for a sterile fill line. Names and states are examples.

ISA-95 levelSystemFunctionGxP recordOwnerCriticalityValidationAudit trailAccountsTimeRemediation
Execution (L3)MES-FILL01EBR execution, fill line 1Batch recordMfg Systems LeadHighValidatedFullIndividualNTPNone (compliant)
Supervisory (L2)SCADA-FILL01HMI, alarms, trendsOperator actions, alarmsAutomation EngHighValidatedPartial (no access-event log)Mixed (shift login on night HMI)NTPRemediate: enable access log Q3, retire shared login
Device (L0/L1)PLC-AUTOCLAVE-3Sterilizer cycle controlCycle setpointsAutomation EngHighLegacy-not-revalidatedNoneN/ALocalCompensate: key-switch access, external config baseline, supervisory recording; replace at 2027 upgrade
ArchiveHIST-SITEHistorianProcess time seriesPlant ITMediumValidatedInsert-only, bulk-edit lockedIndividualNTPNone (compliant)

Reading this extract, an inspector immediately sees where the risk concentrates: a partial SCADA audit trail with a night-shift shared login (remediation dated), and a legacy autoclave PLC with no audit trail held under named compensating controls with a replacement date. That is exactly the risk-based picture the register is meant to surface, rather than a flat list that hides which system is the problem.

Common inspection findings this register prevents

  • No current inventory of floor automation systems, so scope of validation and remediation is unknown.
  • A GxP system missing from the inventory or mis-flagged as non-GxP, so its changes route around the change-control gate.
  • Integrity gaps with no owner and no decision, discovered by the inspector rather than the site.
  • Criticality assigned by system size rather than by the record’s impact on a quality decision.
  • A historian left off the inventory entirely because it “looks like infrastructure.”

How to adapt this register

  1. Replace the example rows with your real systems, one row each, at their true ISA-95 level.
  2. Align the criticality column to your data criticality and gap-assessment methodology.
  3. Make the remediation-decision column mandatory for any row with an open gap, and tie each decision to a change control or plan.
  4. Link the interfaces column into your data-flow maps for critical values.
  5. Confirm the referenced regulations against their current published versions before issue.
Use madhadi.com as an app Full screen, works offline, one tap from your home screen.