Independent and not affiliated with the FDA, MHRA, ISPE, PDA, or any agency. Get the appgoutham@madhadi.com
madhadi.comData Integrity & GxP Quality
Browse all topics → Articles Templates & Procedures Learning paths GlossaryScenariosToolsRegulatory ReferencesLearning PathsTopics About Start here
Checklist Plug-and-play starting point Audits & Inspection

Checklist: System-Level Inspection Readiness Self-Check

A plug-and-play checklist to confirm, on demand and without scrambling, that a single validated GxP system can withstand an inspection: validation state, access, audit trail, reviews, investigations, and clock control, with acceptance criteria and a filled specimen.

Document type: Checklist

Read and copy the template below into your own quality system. It is a generic starting point for your own internal use, provided as is, with no warranty; see the Terms and License. Adopting it does not by itself create compliance.

This is a ready-to-use self-check for one validated system. The point is to prove a state of control continuously, not to prepare for an announced visit. Run it on a rotating schedule against a system picked at random. If assembling the evidence takes a day, the site is not ready; if it takes an hour, the inspection becomes a demonstration. Replace every <<FILL: ...>> placeholder with your specifics. A filled specimen follows.

How to use

Pick one validated GxP system (a laboratory system, a manufacturing or automation system, or a quality system). Confirm you can produce each artifact below on demand, from a controlled source, and that each meets its acceptance criterion. Mark Pass, Fail, or N/A, and open a <<FILL: CAPA / action reference>> for any Fail.

FieldEntry
System name / ID<<FILL: SYSTEM NAME / ID>>
System owner<<FILL: role>>
Check date<<FILL: date>>
Performed by<<FILL: name / role>>
GxP criticality<<FILL: High / Medium / Low>>

Checklist

#ItemAcceptance criterionPass / Fail / NAEvidence locationAction ref
1Current validation summaryApproved, in effect, and matches the system’s actual installed version and configuration<<FILL>>
2Access list with role justificationRetrievable, current; no shared or generic accounts; no leavers active; privileges match role<<FILL>>
3Audit trail configuration recordTrail enabled, field-level (previous value, new value, user, time, reason), cannot be disabled by an ordinary user<<FILL>>
4Last audit trail review recordWithin its defined frequency, signed, findings closed or tracked<<FILL>>
5Periodic review statusLast periodic review current against schedule; actions closed<<FILL>>
6Last 3 deviations / OOS linked to the systemClosed within timeline, or open with current status; linked to the batch or test record<<FILL>>
7System clock controlSynchronized to a trusted time source; drift within tolerance; change of clock restricted and logged<<FILL>>
8Backup and restore evidenceBackups running per procedure; a restore has been tested and recorded<<FILL>>
9Change control historyRecent changes were assessed, tested, and approved before implementation<<FILL>>
10Data retention and readable copyRecords retained per schedule; a human-readable copy of electronic records can be produced<<FILL>>
11User training currentUsers trained on the current version of the operating procedure<<FILL>>
12Known gaps documentedAny open gap is in a risk assessment with a dated remediation plan and progress<<FILL>>

Acceptance criteria (overall)

The system is inspection-ready when every applicable item is Pass, every Fail has an open action with an owner and a due date, and all twelve artifacts can be produced from a controlled source within about an hour. A self-identified, actively remediated gap (item 12) is a sign of control, not a failure of the check; an undocumented surprise is the opposite.

Sign-off

RoleNameSignatureDate
Performed by<<FILL>>
System owner<<FILL>>
QA review<<FILL>>

Filled specimen

Illustrative self-check for a chromatography data system. Names, numbers, and dates are examples.

FieldEntry
System name / IDChromatography Data System, instrument HPLC-07
System ownerQC Laboratory Manager
Check date03 July 2026
Performed byA. Patel, QA
GxP criticalityHigh (release-testing data)
#ItemResultNote
1Validation summaryPassv3.2 validated, matches installed version
2Access listPassNo shared accounts; one leaver removed 20 June; privileges match role
3Audit trail configPassField-level, cannot be disabled by analyst or reviewer role
4Last audit trail reviewPassReviewed each run; last review 02 July, one exception closed
5Periodic reviewPassLast review March 2026, actions closed
6Last 3 OOSFailOne OOS open past its 30-day target; action <<CAPA-2026-071>> opened
7Clock controlPassSynced to network time, drift under 1 s
8Backup / restorePassRestore tested Q1 2026, recorded
9Change controlPassLast change (patch) assessed and approved before install
10Retention / readable copyPass7-year retention, PDF export demonstrated
11TrainingPassAll users on v3.2 SOP
12Known gapsPassOpen OOS is in the risk log with a remediation date

The single Fail (item 6) is exactly what the check is for: it surfaced an OOS past its target internally, an action was opened, and it was added to the known-gaps log, so the site can show an investigator a self-identified, tracked issue rather than being surprised by it.

Common findings this checklist prevents

  • Validation state is out of date or does not match the installed version.
  • Shared or generic accounts, or a departed employee still active.
  • Audit trail present but never reviewed, or reviewable but not field-level.
  • An OOS or deviation quietly past its timeline with no visible action.
  • A gap the site knew about but never documented, so it reads as a surprise at inspection.

How to adapt this checklist

  1. Set the criticality and adjust which items are N/A for the system type (a manufacturing system will treat items differently than a lab system).
  2. Point the action reference to your CAPA or action-tracking system.
  3. Run it on a rotating schedule so every high-criticality system is checked within its cycle; feed Fails into continuous readiness ownership.
  4. Keep completed checks as evidence that readiness is maintained, not assembled for a visit.
Use madhadi.com as an app Full screen, works offline, one tap from your home screen.