Independent and not affiliated with the FDA, MHRA, ISPE, PDA, or any agency. Get the appgoutham@madhadi.com
madhadi.comData Integrity & GxP Quality
Browse all topics → Articles Templates & Procedures Learning paths GlossaryScenariosToolsRegulatory ReferencesLearning PathsTopics About Start here
Template Plug-and-play starting point CSV / CSA

Worksheet: GxP System Inventory Multi-Source Reconciliation

A plug-and-play worksheet for discovering every GxP computerized system by triangulating five independent sources, then dispositioning every discrepancy so shadow systems and retirement candidates surface, with a worked example and the findings it prevents.

Document type: Template

Read and copy the template below into your own quality system. It is a generic starting point for your own internal use, provided as is, with no warranty; see the Terms and License. Adopting it does not by itself create compliance.

This is a ready-to-use worksheet for the hardest and most valuable part of building a computerized system inventory: finding the systems nobody put on a list. You discover them by triangulating across independent sources, because no single source is complete, and the discrepancies between sources are the output that matters. Replace every <<FILL: ...>> placeholder and route it through your normal document control. A worked example follows. The full method is in the GxP computerized system inventory and classification; confirm each cited reference against the current source before you rely on it.

Why five sources, not one

A system that is not on the list is in no validation, change-control, or periodic-review process by definition, so the classic data-integrity failures (a spreadsheet doing GMP math with no version control, a SaaS tool bought on a credit card) are almost always systems that never made an inventory. Each discovery source has a blind spot; laid side by side, the gaps between them expose shadow systems and retirement candidates that any single source would miss.

Reconciliation header

FieldEntry
Worksheet reference<<FILL: ENUM-YYYY-nnn>>
Scope of this pass<<FILL: site / business process / whole company>>
Sources used and dates pulled<<FILL: process walk, CMDB, procurement, interviews, instruments>>
Performed by / date<<FILL>>
Owner attestation (current as of)<<FILL: name, date>>

The five sources

SourceWhat it surfacesBlind spot
1. Process walk (follow the data)Systems in the actual GxP workflow, by department-independent data flowTools used rarely or off-process
2. Procurement / license / SaaS billingPaid-for tools IT never provisionedFree tools, homegrown scripts
3. IT asset / CMDB / identity / network scanThe technical populationNon-networked instruments, personal spreadsheets
4. Bench interviewsMacros, local databases, de facto trackersWhatever staff forget to mention
5. Instrument reviewAnything that produces, stores, or controls data, including firmwarePurely manual instruments

The reconciliation grid

List every candidate system as a row; mark whether each source saw it (Yes/No); assign a disposition. Every discrepancy needs a recorded outcome.

Candidate system1 Process2 Procurement3 IT/CMDB4 Interview5 InstrumentDisposition (added / de-scoped / retired / duplicate / confirmed)
<<FILL>>Y/NY/NY/NY/NY/N<<FILL>>
<<FILL>>Y/NY/NY/NY/NY/N<<FILL>>
<<FILL>>Y/NY/NY/NY/NY/N<<FILL>>

How to read the pattern

  • In process/procurement/interview but not in IT: likely a shadow system; add it, scope it, assign an owner.
  • In IT but not in any process/interview: likely a retirement candidate; verify data retention, then decommission.
  • In all sources: confirmed; ensure it is already on the inventory.
  • Appears twice under different names: duplicate; merge and record the alias.

Acceptance criteria

  • Every GxP business process in scope was walked and its data touchpoints captured.
  • At least three independent source lists (process, procurement, IT) were reconciled; five is better.
  • Every reconciliation discrepancy has a recorded disposition, not a blank.
  • A named owner attests the population is current as of a stated date.
  • Each “added” system is handed to scoping and classification; each “retired” candidate is handed to decommissioning with a data-retention check.

Worked example (filled specimen)

A single-site QC and manufacturing pass. The systems are illustrative; replace with your own.

Candidate system1 Process2 Procurement3 IT/CMDB4 Interview5 InstrumentDisposition
LIMSYYYYNConfirmed; already inventoried
Assay calc spreadsheetYNNYNAdded; shadow system feeding release, scope + owner
Cloud stability trackerYYNYNAdded; shadow SaaS, scope + supplier assess
Legacy MES (unused)NNYNNRetirement candidate; verify data retained then retire
Cafeteria menu appNYYNNDe-scoped; record out-of-scope rationale
Particle counterYNYYYConfirmed in scope; classify (Category 3) + owner

Two rows carry the whole exercise. The assay spreadsheet is visible to the process walk and the bench interview, and the cloud tracker to the process walk, procurement, and the interview, yet both are invisible to IT, which is exactly where shadow systems and findings live; both are added and routed to scoping. The legacy MES is visible only to IT and used by nobody, which is a retirement obligation, not a live system. A single stale spreadsheet would have shown none of this.

Common findings this worksheet prevents

  • Shadow systems (spreadsheets, SaaS, instruments) never inventoried, later cited as findings.
  • An enumeration based on one source, so half the population is missing.
  • Discrepancies noted but never dispositioned, so the “found” systems are never actually added.
  • Retired systems still carried as live, or live systems missing entirely.
  • No dated owner attestation, so completeness cannot be defended.

References

21 CFR 211.68 (automatic equipment); 21 CFR Part 11. EU GMP Annex 11 (an up-to-date list of systems and their GMP functionality). A draft revision went to consultation 7 July 2025 (closed 7 October 2025), draft as of mid-2026; confirm final text before citing. PIC/S PI 011 and PI 041; ISPE GAMP 5 (second edition), described by title only.

Confirm the current version and clause numbers of each reference before issue.

How to adapt this worksheet

  1. Set your reference scheme and the scope of the pass (a site, a process, or the whole company).
  2. Pull each source on a stated date so the reconciliation is a snapshot you can attest to.
  3. Feed every “added” row into your scoping and classification procedure, and every “retired” candidate into decommissioning with a data-retention check.
  4. Repeat a lightweight version on a defined cycle (commonly annual) as the completeness reconciliation the inventory SOP requires.
Use madhadi.com as an app Full screen, works offline, one tap from your home screen.