Independent and not affiliated with the FDA, MHRA, ISPE, PDA, or any agency. Get the appgoutham@madhadi.com
madhadi.comData Integrity & GxP Quality
Browse all topics → Articles Templates & Procedures Learning paths GlossaryScenariosToolsRegulatory ReferencesLearning PathsTopics About Start here
Checklist Plug-and-play starting point Manufacturing Automation

Checklist: Automation System Periodic Review (Validated-State Verification)

A plug-and-play periodic review checklist for a validated automation system (PLC, SCADA, DCS): version-baseline comparison, change and deviation history, access-list review, audit-trail review evidence, time synchronization, alarm rationalization, backup and restore, and interface health, with pass/fail items and a filled specimen.

Document type: Checklist

Read and copy the template below into your own quality system. It is a generic starting point for your own internal use, provided as is, with no warranty; see the Terms and License. Adopting it does not by itself create compliance.

This is the periodic review that confirms an automation system is still in its validated state and that accumulated minor changes have not eroded it. Run it at the defined interval and after any significant change. Mark each item Pass, Fail, or N/A with evidence, and route every Fail to CAPA. A filled specimen follows. This content is educational and general; adapt it to your own quality system.

FieldEntry
System name / ID<<FILL>>
ISA-95 level / GMP impact<<FILL>>
Review period<<FILL>> to <<FILL>>
Reviewer<<FILL>>
Last validation / requalification reference<<FILL>>

Part 1: configuration and version integrity

#ItemPass / Fail / NAEvidence
1Live program / configuration version and checksum equal the approved baseline
2Programming and engineering access remains restricted; no open USB or maintenance ports found
3All changes in the period went through change control (no undocumented setpoint or logic changes)

Part 2: change, deviation, and CAPA history

#ItemPass / Fail / NAEvidence
4Every change record for the period is closed or on track, with requalification done where required
5Deviations involving the system are closed or tracked; no trend indicating erosion of control
6Open CAPAs affecting the system are on schedule

Part 3: data integrity controls

#ItemPass / Fail / NAEvidence
7Audit trail enabled for the whole period; audit-trail reviews performed at the defined frequency
8Time synchronization to the defined source is active; drift within limit; sync-failure alerting works
9Unique accounts only; access list reviewed and recertified; leavers removed; roles still segregate operate/configure/administer
10Alarm configuration under change control; alarm priority scheme still rationalized (not a wall of “critical”)

Part 4: resilience and interfaces

#ItemPass / Fail / NAEvidence
11Backups run per schedule; a restore was tested, not just assumed
12Interfaces feeding the batch record reconciled; no unexplained gaps in the period
13Historian compression / deadband settings unchanged from the validated configuration

Part 5: outcome

FieldEntry
Overall verdict<<FILL: remains in validated state / conditions apply / requalification needed>>
Actions raised<<FILL: CAPA / change references>>
Next review due<<FILL>>
RoleNameSignatureDate
Reviewer<<FILL>>
System owner<<FILL>>
QA approval<<FILL>>

References

21 CFR 211.68; 21 CFR Part 11. EU GMP Annex 11 (Computerised systems), periodic evaluation. EU GMP Annex 15. ISPE GAMP 5 (Second Edition, 2022).


Filled specimen

#ItemResultEvidence
1Live version equals baselinePassChecksum 0x4F2A matches baseline record BL-SCADA-03
3All changes went through change controlFailSetpoint on TIC-118 found changed with no change record; CAPA-2026-041 raised
7Audit-trail reviews performedPass26 weekly reviews on file for the period
11Restore testedPassDR restore test DR-2026-02 passed 14 May 2026

The Fail on item 3 is the value of the review: an undocumented setpoint change is exactly the slow erosion of the validated state that a periodic review is designed to catch before an inspector does.

Common inspection findings this checklist prevents

  • The live program has drifted from the approved baseline and nobody noticed.
  • “Temporary” setpoint or logic changes made during callouts never entered change control.
  • Audit-trail review is required by procedure but no evidence it happened.
  • Access lists still contain leavers, or shared logins reappeared.
  • Backups run but a restore was never actually tested.

How to adapt this checklist

  1. Set your review interval from the system’s GMP impact.
  2. Add system-specific items (specific interfaces, specific alarm groups, specific historian tags).
  3. Point item 7 to your audit-trail review SOP and item 11 to your backup/restore procedure.
  4. Define what verdict triggers requalification versus a conditional pass.
  5. File the completed checklist with the system’s validation lifecycle records.
Use madhadi.com as an app Full screen, works offline, one tap from your home screen.