This is a ready-to-use self-check for one validated system. The point is to prove a state of control continuously, not to prepare for an announced visit. Run it on a rotating schedule against a system picked at random. If assembling the evidence takes a day, the site is not ready; if it takes an hour, the inspection becomes a demonstration. Replace every <<FILL: ...>> placeholder with your specifics. A filled specimen follows.
How to use
Pick one validated GxP system (a laboratory system, a manufacturing or automation system, or a quality system). Confirm you can produce each artifact below on demand, from a controlled source, and that each meets its acceptance criterion. Mark Pass, Fail, or N/A, and open a <<FILL: CAPA / action reference>> for any Fail.
| Field | Entry |
|---|---|
| System name / ID | <<FILL: SYSTEM NAME / ID>> |
| System owner | <<FILL: role>> |
| Check date | <<FILL: date>> |
| Performed by | <<FILL: name / role>> |
| GxP criticality | <<FILL: High / Medium / Low>> |
Checklist
| # | Item | Acceptance criterion | Pass / Fail / NA | Evidence location | Action ref |
|---|---|---|---|---|---|
| 1 | Current validation summary | Approved, in effect, and matches the system’s actual installed version and configuration | <<FILL>> | ||
| 2 | Access list with role justification | Retrievable, current; no shared or generic accounts; no leavers active; privileges match role | <<FILL>> | ||
| 3 | Audit trail configuration record | Trail enabled, field-level (previous value, new value, user, time, reason), cannot be disabled by an ordinary user | <<FILL>> | ||
| 4 | Last audit trail review record | Within its defined frequency, signed, findings closed or tracked | <<FILL>> | ||
| 5 | Periodic review status | Last periodic review current against schedule; actions closed | <<FILL>> | ||
| 6 | Last 3 deviations / OOS linked to the system | Closed within timeline, or open with current status; linked to the batch or test record | <<FILL>> | ||
| 7 | System clock control | Synchronized to a trusted time source; drift within tolerance; change of clock restricted and logged | <<FILL>> | ||
| 8 | Backup and restore evidence | Backups running per procedure; a restore has been tested and recorded | <<FILL>> | ||
| 9 | Change control history | Recent changes were assessed, tested, and approved before implementation | <<FILL>> | ||
| 10 | Data retention and readable copy | Records retained per schedule; a human-readable copy of electronic records can be produced | <<FILL>> | ||
| 11 | User training current | Users trained on the current version of the operating procedure | <<FILL>> | ||
| 12 | Known gaps documented | Any open gap is in a risk assessment with a dated remediation plan and progress | <<FILL>> |
Acceptance criteria (overall)
The system is inspection-ready when every applicable item is Pass, every Fail has an open action with an owner and a due date, and all twelve artifacts can be produced from a controlled source within about an hour. A self-identified, actively remediated gap (item 12) is a sign of control, not a failure of the check; an undocumented surprise is the opposite.
Sign-off
| Role | Name | Signature | Date |
|---|---|---|---|
| Performed by | <<FILL>> | ||
| System owner | <<FILL>> | ||
| QA review | <<FILL>> |
Filled specimen
Illustrative self-check for a chromatography data system. Names, numbers, and dates are examples.
| Field | Entry |
|---|---|
| System name / ID | Chromatography Data System, instrument HPLC-07 |
| System owner | QC Laboratory Manager |
| Check date | 03 July 2026 |
| Performed by | A. Patel, QA |
| GxP criticality | High (release-testing data) |
| # | Item | Result | Note |
|---|---|---|---|
| 1 | Validation summary | Pass | v3.2 validated, matches installed version |
| 2 | Access list | Pass | No shared accounts; one leaver removed 20 June; privileges match role |
| 3 | Audit trail config | Pass | Field-level, cannot be disabled by analyst or reviewer role |
| 4 | Last audit trail review | Pass | Reviewed each run; last review 02 July, one exception closed |
| 5 | Periodic review | Pass | Last review March 2026, actions closed |
| 6 | Last 3 OOS | Fail | One OOS open past its 30-day target; action <<CAPA-2026-071>> opened |
| 7 | Clock control | Pass | Synced to network time, drift under 1 s |
| 8 | Backup / restore | Pass | Restore tested Q1 2026, recorded |
| 9 | Change control | Pass | Last change (patch) assessed and approved before install |
| 10 | Retention / readable copy | Pass | 7-year retention, PDF export demonstrated |
| 11 | Training | Pass | All users on v3.2 SOP |
| 12 | Known gaps | Pass | Open OOS is in the risk log with a remediation date |
The single Fail (item 6) is exactly what the check is for: it surfaced an OOS past its target internally, an action was opened, and it was added to the known-gaps log, so the site can show an investigator a self-identified, tracked issue rather than being surprised by it.
Common findings this checklist prevents
- Validation state is out of date or does not match the installed version.
- Shared or generic accounts, or a departed employee still active.
- Audit trail present but never reviewed, or reviewable but not field-level.
- An OOS or deviation quietly past its timeline with no visible action.
- A gap the site knew about but never documented, so it reads as a surprise at inspection.
How to adapt this checklist
- Set the criticality and adjust which items are N/A for the system type (a manufacturing system will treat items differently than a lab system).
- Point the action reference to your CAPA or action-tracking system.
- Run it on a rotating schedule so every high-criticality system is checked within its cycle; feed Fails into continuous readiness ownership.
- Keep completed checks as evidence that readiness is maintained, not assembled for a visit.