This is a ready-to-use worksheet for the hardest and most valuable part of building a computerized system inventory: finding the systems nobody put on a list. You discover them by triangulating across independent sources, because no single source is complete, and the discrepancies between sources are the output that matters. Replace every <<FILL: ...>> placeholder and route it through your normal document control. A worked example follows. The full method is in the GxP computerized system inventory and classification; confirm each cited reference against the current source before you rely on it.
Why five sources, not one
A system that is not on the list is in no validation, change-control, or periodic-review process by definition, so the classic data-integrity failures (a spreadsheet doing GMP math with no version control, a SaaS tool bought on a credit card) are almost always systems that never made an inventory. Each discovery source has a blind spot; laid side by side, the gaps between them expose shadow systems and retirement candidates that any single source would miss.
Reconciliation header
| Field | Entry |
|---|---|
| Worksheet reference | <<FILL: ENUM-YYYY-nnn>> |
| Scope of this pass | <<FILL: site / business process / whole company>> |
| Sources used and dates pulled | <<FILL: process walk, CMDB, procurement, interviews, instruments>> |
| Performed by / date | <<FILL>> |
| Owner attestation (current as of) | <<FILL: name, date>> |
The five sources
| Source | What it surfaces | Blind spot |
|---|---|---|
| 1. Process walk (follow the data) | Systems in the actual GxP workflow, by department-independent data flow | Tools used rarely or off-process |
| 2. Procurement / license / SaaS billing | Paid-for tools IT never provisioned | Free tools, homegrown scripts |
| 3. IT asset / CMDB / identity / network scan | The technical population | Non-networked instruments, personal spreadsheets |
| 4. Bench interviews | Macros, local databases, de facto trackers | Whatever staff forget to mention |
| 5. Instrument review | Anything that produces, stores, or controls data, including firmware | Purely manual instruments |
The reconciliation grid
List every candidate system as a row; mark whether each source saw it (Yes/No); assign a disposition. Every discrepancy needs a recorded outcome.
| Candidate system | 1 Process | 2 Procurement | 3 IT/CMDB | 4 Interview | 5 Instrument | Disposition (added / de-scoped / retired / duplicate / confirmed) |
|---|---|---|---|---|---|---|
<<FILL>> | Y/N | Y/N | Y/N | Y/N | Y/N | <<FILL>> |
<<FILL>> | Y/N | Y/N | Y/N | Y/N | Y/N | <<FILL>> |
<<FILL>> | Y/N | Y/N | Y/N | Y/N | Y/N | <<FILL>> |
How to read the pattern
- In process/procurement/interview but not in IT: likely a shadow system; add it, scope it, assign an owner.
- In IT but not in any process/interview: likely a retirement candidate; verify data retention, then decommission.
- In all sources: confirmed; ensure it is already on the inventory.
- Appears twice under different names: duplicate; merge and record the alias.
Acceptance criteria
- Every GxP business process in scope was walked and its data touchpoints captured.
- At least three independent source lists (process, procurement, IT) were reconciled; five is better.
- Every reconciliation discrepancy has a recorded disposition, not a blank.
- A named owner attests the population is current as of a stated date.
- Each “added” system is handed to scoping and classification; each “retired” candidate is handed to decommissioning with a data-retention check.
Worked example (filled specimen)
A single-site QC and manufacturing pass. The systems are illustrative; replace with your own.
| Candidate system | 1 Process | 2 Procurement | 3 IT/CMDB | 4 Interview | 5 Instrument | Disposition |
|---|---|---|---|---|---|---|
| LIMS | Y | Y | Y | Y | N | Confirmed; already inventoried |
| Assay calc spreadsheet | Y | N | N | Y | N | Added; shadow system feeding release, scope + owner |
| Cloud stability tracker | Y | Y | N | Y | N | Added; shadow SaaS, scope + supplier assess |
| Legacy MES (unused) | N | N | Y | N | N | Retirement candidate; verify data retained then retire |
| Cafeteria menu app | N | Y | Y | N | N | De-scoped; record out-of-scope rationale |
| Particle counter | Y | N | Y | Y | Y | Confirmed in scope; classify (Category 3) + owner |
Two rows carry the whole exercise. The assay spreadsheet is visible to the process walk and the bench interview, and the cloud tracker to the process walk, procurement, and the interview, yet both are invisible to IT, which is exactly where shadow systems and findings live; both are added and routed to scoping. The legacy MES is visible only to IT and used by nobody, which is a retirement obligation, not a live system. A single stale spreadsheet would have shown none of this.
Common findings this worksheet prevents
- Shadow systems (spreadsheets, SaaS, instruments) never inventoried, later cited as findings.
- An enumeration based on one source, so half the population is missing.
- Discrepancies noted but never dispositioned, so the “found” systems are never actually added.
- Retired systems still carried as live, or live systems missing entirely.
- No dated owner attestation, so completeness cannot be defended.
References
21 CFR 211.68 (automatic equipment); 21 CFR Part 11. EU GMP Annex 11 (an up-to-date list of systems and their GMP functionality). A draft revision went to consultation 7 July 2025 (closed 7 October 2025), draft as of mid-2026; confirm final text before citing. PIC/S PI 011 and PI 041; ISPE GAMP 5 (second edition), described by title only.
Confirm the current version and clause numbers of each reference before issue.
How to adapt this worksheet
- Set your reference scheme and the scope of the pass (a site, a process, or the whole company).
- Pull each source on a stated date so the reconciliation is a snapshot you can attest to.
- Feed every “added” row into your scoping and classification procedure, and every “retired” candidate into decommissioning with a data-retention check.
- Repeat a lightweight version on a defined cycle (commonly annual) as the completeness reconciliation the inventory SOP requires.