Independent and not affiliated with the FDA, MHRA, ISPE, PDA, or any agency. Get the appgoutham@madhadi.com
madhadi.comData Integrity & GxP Quality
Browse all topics → Articles Templates & Procedures Learning paths GlossaryScenariosToolsRegulatory ReferencesLearning PathsTopics About Start here
Form Plug-and-play starting point CSV / CSA

Form: Periodic Review Evidence Collection Worksheet

A plug-and-play working worksheet for gathering periodic review evidence before the report is written: one row per evidence input with the owning function, date requested, date received, record reference, reviewer assessment of compliant, action, or non-conformance, and a comment, with completion instructions, retention, and a filled specimen.

Document type: Form

Read and copy the template below into your own quality system. It is a generic starting point for your own internal use, provided as is, with no warranty; see the Terms and License. Adopting it does not by itself create compliance.

This is a ready-to-use worksheet. Replace every <<FILL: ...>> placeholder with your own specifics, set your document numbers and dates, and route the completed worksheet with the review record through your normal document control and retention. A worked filled specimen follows the template so you can see how a completed version reads. Verify each cited regulation against the current source before you rely on it. This template is an educational reference for you to adapt to your own quality system, products, and regulatory context; it is not legal, regulatory, or professional advice. This worksheet is the working paper behind a periodic review, not the review itself. It exists because the failure mode of periodic review is almost never bad judgment. It is evidence that was requested late, or requested from the wrong function, or never received at all, with the gap invisible by the time the report is drafted because an empty section looks the same as a section with nothing to report. Recording the request date and the receipt date for every input makes a missing input show up as a missing input.

The governing procedure is SOP: Periodic Review of GxP Computerized Systems. The report this worksheet feeds is Periodic Review Report (Validated System).

Document control header

FieldEntry
Form titlePeriodic Review Evidence Collection Worksheet
Form number<<FILL: e.g. FRM-VAL-021-01>>
Version<<FILL: version, e.g. 1.0>>
Effective date<<FILL: effective date>>
Governing procedure<<FILL: SOP-ID for periodic review>>
Form owner<<FILL: role, e.g. Head of Validation>>

Review identification

FieldEntry
Review record ID<<FILL: e.g. PR-2026-031>>
System name and inventory ID<<FILL: SYSTEM NAME / ID>>
Application version in scope<<FILL: version>>
Risk tier and review interval<<FILL: High / Medium / Low, interval>>
Review depth set for this reviewFull / Standard / Reduced: <<FILL>>
Review period<<FILL: from date>> to <<FILL: to date>>
Previous review record and period end<<FILL: prior ID and end date, or "first review, validation released on <date>">>
TriggerScheduled / Event-driven: <<FILL: reason if event-driven>>
Grouped review?No / Yes: <<FILL: group name and approved grouping rationale reference>>
Reviewer (performs)<<FILL: name and function>>
Evidence collection opened<<FILL: date>>
Target completion<<FILL: date>>

Purpose of this form

To record, for one periodic review of one system or one approved group, every evidence input required by the governing procedure: what was requested, from whom, when it was requested, when it arrived, what record satisfies it, and how the reviewer assessed it. The completed worksheet is the audit trail of the review itself. It answers the question an inspector asks when a review section looks thin: did you look and find nothing, or did you not look.

Field definitions

FieldFormatRequiredWho providesWhen
Input #Fixed number from the standard input list belowYesPre-printed on the formNot editable
Evidence requestedSpecific description of the record wanted, naming the system of record and the period. Not “change records” but “all change requests for MES-PROD-01 closed between 01 Jun 2025 and 31 May 2026, from the change management system”YesReviewerAt the point of request
Owning functionThe function accountable for producing the record, named to a role or team, not to “IT” generallyYesReviewerAt the point of request
Date requestedDD MMM YYYYYesReviewerThe day the request is sent
Date receivedDD MMM YYYY, or “not received”YesReviewerThe day the evidence arrives
Record reference / attachment IDThe identifier of the record itself: report number, export file name with generation date, log reference, ticket number, attachment index on the review recordYes where receivedProvider, recorded by reviewerOn receipt
Reviewer assessmentOne of: Compliant, Action, Non-conformance, Not applicable, Not receivedYesReviewerAfter examining the evidence
CommentWhat the evidence showed, with counts. The basis for the assessment, in one or two sentencesYes for anything other than a plain Compliant with no activityReviewerAfter examining the evidence
Reviewer initials and dateTwo or three letters plus dateYesReviewerWhen the row is assessed

Assessment values

ValueMeaningWhat it does downstream
CompliantThe control operated as intended across the whole period.Feeds the report section as satisfactory.
ActionThe control operated, with a gap that does not put the validated state or data at risk now and must be corrected within a defined time.Drives a “remains validated with actions” conclusion and a tracked action.
Non-conformanceThe control did not operate, or the evidence shows the validated state or data integrity may be affected.Drives a “validated state not confirmed” conclusion, escalation, and CAPA.
Not applicableThe input genuinely does not apply to this system. The reason is recorded.Carried to the report with the rationale, so the gap is explained rather than blank.
Not receivedThe input applies and was requested, but no evidence was produced.Cannot be treated as Compliant. Chase, then assess as Non-conformance if it remains unavailable.

“Not received” and “Not applicable” are different states and are never merged. That distinction is the whole point of the worksheet.

Completion instructions

  1. Open the worksheet before you request anything. Fill the review identification block first, including the review period start date taken from the previous review’s period end. If those two dates do not meet, you have found a coverage gap before you have collected a single record; note it now.
  2. Send every request in writing, on the same day where possible. Requests dribbled out over six weeks produce a review that stalls waiting on the last one. Record the request date as the date you sent it, not the date you meant to.
  3. Name the system of record in every request. “Send me the access list” gets you a spreadsheet somebody typed. “Export the active user list for MES-PROD-01 from the identity management system, with role and last-login date, generated on or after the period end date” gets you evidence.
  4. Record the record reference exactly as it appears on the evidence, including the generation date of any export. An export with no generation date cannot be tied to the review period later.
  5. Do not assess a row until you have examined the underlying record. A summary email from the owning function saying “no issues” is a communication, not evidence, and is recorded as “not received” until the record arrives.
  6. Chase anything outstanding at the interval set in the governing procedure, and record each chase in the comment field with its date. Two recorded chases and no evidence is a much stronger position than a blank row.
  7. Assess every row. No row is left empty. If the input does not apply, mark it Not applicable and say why.
  8. Record counts, not adjectives. “14 changes, all closed, all with validation impact assessments” is evidence of a review. “Change control looks fine” is not.
  9. Escalate a Non-conformance when you find it, not when the worksheet is finished. The governing procedure sets the notification time. Waiting until the report is drafted wastes the days that matter most.
  10. Do not erase or overwrite. If an assessment changes because further evidence arrived, add the revision in the comment with the date and your initials, and state what changed it. This worksheet follows the same documentation practice as any other GxP record.
  11. Attach or index every piece of evidence to the review record so the report can cite it by reference rather than paraphrase it.

Retention

FieldEntry
Retention period<<FILL: period, aligned to the periodic review report retention in your records schedule>>
Storage location<<FILL: controlled location or system where the review record and its attachments are held>>
Retained withThe periodic review record and report for the same system and period
Disposition at end of retention<<FILL: per records retention schedule reference>>

The worksheet

One row per evidence input. Rows 1 to 14 are the standard input set from the governing procedure; add system-specific rows at the end where the system warrants them.

#Evidence requestedOwning functionDate requestedDate receivedRecord reference / attachment IDAssessmentCommentInitials / date
1Change records for the period, with validation impact assessments and closure status<<FILL: change control / QA>><<FILL>><<FILL>><<FILL>><<FILL>><<FILL>><<FILL>>
2Deviation, incident, problem, and outage records affecting the system<<FILL: quality / IT service management>><<FILL>><<FILL>><<FILL>><<FILL>><<FILL>><<FILL>>
3Live configuration extract of GxP-relevant settings, generated on or after period end<<FILL: system administrator>><<FILL>><<FILL>><<FILL>><<FILL>><<FILL>><<FILL>>
4Approved validated baseline configuration specification<<FILL: validation>><<FILL>><<FILL>><<FILL>><<FILL>><<FILL>><<FILL>>
5Patch and upgrade history: application, operating system, database, middleware<<FILL: IT infrastructure>><<FILL>><<FILL>><<FILL>><<FILL>><<FILL>><<FILL>>
6Audit trail review records covering the full period<<FILL: reviewing function per audit trail SOP>><<FILL>><<FILL>><<FILL>><<FILL>><<FILL>><<FILL>>
7User access list with roles, plus the access reconciliation record and leaver data<<FILL: system administrator / HR>><<FILL>><<FILL>><<FILL>><<FILL>><<FILL>><<FILL>>
8Backup completion logs AND the verified restore test record for the period<<FILL: IT infrastructure>><<FILL>><<FILL>><<FILL>><<FILL>><<FILL>><<FILL>>
9Business continuity or disaster recovery test record with recovery targets and actual results<<FILL: business continuity / IT>><<FILL>><<FILL>><<FILL>><<FILL>><<FILL>><<FILL>>
10SOP currency check and training completion records for current users<<FILL: process owner / training>><<FILL>><<FILL>><<FILL>><<FILL>><<FILL>><<FILL>>
11Supplier status: support and end-of-life position, assessment or audit currency, service reports, change notifications<<FILL: supplier management>><<FILL>><<FILL>><<FILL>><<FILL>><<FILL>><<FILL>>
12Open and closed CAPA records against the system, including prior review actions<<FILL: quality>><<FILL>><<FILL>><<FILL>><<FILL>><<FILL>><<FILL>>
13Data integrity checks: time synchronization verification, electronic signature control operation, orphan or unexplained record checks<<FILL: system owner with IT>><<FILL>><<FILL>><<FILL>><<FILL>><<FILL>><<FILL>>
14Security event and vulnerability records for the period<<FILL: IT security>><<FILL>><<FILL>><<FILL>><<FILL>><<FILL>><<FILL>>
15<<FILL: system-specific input, e.g. interface reconciliation report with the ERP>><<FILL>><<FILL>><<FILL>><<FILL>><<FILL>><<FILL>><<FILL>>
16<<FILL: system-specific input>><<FILL>><<FILL>><<FILL>><<FILL>><<FILL>><<FILL>><<FILL>>

Collection status summary

Complete this block before drafting the report. The report cannot conclude that the validated state is confirmed while any applicable input is outstanding.

FieldEntry
Inputs applicable to this review<<FILL: count>>
Inputs received and assessed<<FILL: count>>
Inputs marked Not applicable (with rationale recorded)<<FILL: count>>
Inputs outstanding at cut-off<<FILL: count, list input numbers>>
Assessments: Compliant<<FILL: count>>
Assessments: Action<<FILL: count, list input numbers>>
Assessments: Non-conformance<<FILL: count, list input numbers>>
Non-conformance escalated on<<FILL: date, to whom, or "none">>
Evidence collection completeYes / No: <<FILL>>
Reviewer signature and date<<FILL>>

References

EU GMP Annex 11, Computerised Systems, section 11 (periodic evaluation), which contemplates evaluation of matters including current functionality, deviation records, incidents, problems, upgrade history, performance, reliability, security, and validation status reports. EU GMP Annex 15, Qualification and Validation. 21 CFR Part 11 (electronic records and electronic signatures); 21 CFR 211.68, 211.180, 211.194. ICH Q9(R1), Quality Risk Management, for the risk-based depth applied to evidence collection. ISPE GAMP 5, Second Edition (2022), A Risk-Based Approach to Compliant GxP Computerized Systems. MHRA, ‘GxP’ Data Integrity Guidance and Definitions (2018). PIC/S PI 041, Good Practices for Data Management and Integrity in Regulated GMP/GDP Environments.

Confirm the current version and clause numbers of each reference before issue.


Filled specimen

The following shows the worksheet completed for an example laboratory information management system, so you can see the level of detail an inspector expects. The company, system, and numbers are illustrative; replace them with your own.

FieldEntry
Review record IDPR-2026-018
SystemLaboratory Information Management System, LIMS-PROD-01, version 8.3.2
Risk tierHigh. Owns QC release-testing results and stability data. Interval 12 months, depth full.
Review period01 May 2025 to 30 April 2026 (previous period PR-2025-016 ended 30 April 2025, continuous)
ReviewerA. Reyes, System Owner, Laboratory Systems
Collection opened06 April 2026
#Evidence requestedOwning functionRequestedReceivedRecord referenceAssessmentCommentInit / date
1All change requests closed 01 May 2025 to 30 Apr 2026, from the change management systemChange Control06 Apr 202609 Apr 2026CHG-EXPORT-LIMS-20260409Compliant11 changes. All closed, all with validation impact assessments. CR-2025-241 (stability interface) drove targeted re-test, closed 14 Nov 2025.AR 15 Apr
2Deviations, incidents, outages naming LIMS-PROD-01Quality / IT Service Desk06 Apr 202610 Apr 2026DEV-EXPORT-20260410, INC-EXPORT-20260410Action4 deviations, 2 outages. All closed. Delayed result entry recurred 3 times against the same interface. Pattern not previously trended. Action to trend at interface level.AR 16 Apr
3Live configuration extract, GxP settings, generated after 30 Apr 2026LIMS Administrator06 Apr 202604 May 2026CFG-EXTRACT-LIMS-20260504CompliantExtract generated 04 May 2026. Reconciled setting by setting against baseline.AR 08 May
4Approved baseline configuration specificationValidation06 Apr 202607 Apr 2026CFG-LIMS-011 rev 3CompliantCurrent, approved 22 Nov 2025 following CR-2025-241. Matches extract on all 84 GxP settings.AR 08 May
5Patch history: application, OS, databaseIT Infrastructure06 Apr 202613 Apr 2026PATCH-LOG-LIMS-FY26Compliant9 patches. All impact-assessed. Vendor patch 8.3.2 regression-tested per CR-2025-198.AR 16 Apr
6Audit trail review records for the full periodQC Data Review06 Apr 202611 Apr 2026ATR-LIMS-2025-19 through ATR-LIMS-2026-17CompliantReviews performed per release run per SOP-QA-014. 51 records, no gaps. 2 exceptions raised, both closed (DEV-2025-0311, DEV-2026-0088).AR 17 Apr
7Active user list with roles and last login, plus reconciliation record and leaver listLIMS Administrator / HR06 Apr 202608 Apr 2026IAM-LIMS-20260408, ACC-REC-2026-04Non-conformance147 active accounts. Reconciliation of 08 Apr 2026 identified 2 accounts belonging to staff who left 61 and 94 days earlier, both with result-entry privileges. Not caught by the leaver process. Escalated same day.AR 09 Apr
8Backup logs plus the verified restore test recordIT Infrastructure06 Apr 202614 Apr 2026BKP-LIMS-FY26, RST-2026-004CompliantDaily backups, 3 failures, all re-run successfully. Restore test 09 Feb 2026: full database restored to validation environment, record counts and 20 sampled results verified against source.AR 17 Apr
9Business continuity test record with recovery targets and resultsIT Business Continuity06 Apr 202621 Apr 2026BC-TEST-2026-02CompliantTest 05 Mar 2026. Recovery time objective 8 hours, achieved 5 hours 20 minutes. Recovery point objective 4 hours, achieved 35 minutes.AR 24 Apr
10SOP currency check and training completion for current LIMS usersQC / Training06 Apr 202620 Apr 2026TRN-EXPORT-20260420ActionSOP-QC-033 last reviewed 2023 and still describes the pre-8.3 result approval screen. Training 100 percent complete but against the outdated SOP. Action to revise SOP-QC-033.AR 24 Apr
11Vendor support status, assessment currency, service reports, change notificationsSupplier Management06 Apr 202616 Apr 2026SUP-LIMS-STATUS-2026, SA-2024-007ActionSupport current to 30 Jun 2028. Supplier assessment SA-2024-007 expires 31 Aug 2026. Action to schedule reassessment.AR 24 Apr
12Open and closed CAPAs against LIMS-PROD-01 including PR-2025-016 actionsQuality06 Apr 202610 Apr 2026CAPA-EXPORT-20260410Compliant2 prior-review actions closed and effectiveness-checked. 1 CAPA open (CAPA-2026-018), on track, due 30 Jun 2026.AR 17 Apr
13Time sync verification, e-signature control check, orphan record checkSystem Owner with IT06 Apr 202622 Apr 2026DI-CHECK-LIMS-2026-01CompliantClock synchronized to the site time source, user-change blocked and verified. E-signature manifestation checked on 10 sampled records. No orphan or unassigned results found.AR 27 Apr
14Security events and vulnerability scan results for the periodIT Security06 Apr 2026Not receivedNot receivedNot receivedRequested 06 Apr. Chased 20 Apr and 04 May. Owning team reorganized; no owner identified. Escalated to IT Security lead 04 May.AR 04 May
Collection statusEntry
Inputs applicable14
Received and assessed13
Not applicable0
Outstanding at cut-off1 (input 14)
Compliant9
Action3 (inputs 2, 10, 11)
Non-conformance1 (input 7)
Non-conformance escalated on09 April 2026, to QA (L. Brennan) and the Validation Lead, same day as discovery
Evidence collection completeNo. Input 14 outstanding; the review cannot conclude the validated state is confirmed while it is open.

In this example the worksheet did three things the report alone could not. It made the two leaver accounts visible on 09 April, five weeks before the report was due, so the accounts were disabled that day rather than after the paperwork finished. It recorded that the security evidence was requested, chased twice, and never produced, which turns an empty report section into a documented organizational gap with a name attached. And it separated “not applicable” from “not received”, so nobody reading the review later can mistake an unexamined input for a clean one.

Common inspection findings this form prevents

  • A periodic review section is blank or reads “no issues”, with no way to tell whether the reviewer looked and found nothing or never looked at all.
  • Evidence was requested so late that the review concluded on partial information, and the gap is invisible in the final report.
  • The review cites “backups running” because the restore record was never actually requested from infrastructure.
  • Access reconciliation is claimed but no access list export exists, so the claim rests on an administrator’s recollection.
  • A configuration extract is cited with no generation date, so it cannot be tied to the review period.
  • The report states data integrity is intact while the audit trail review records for part of the period were never produced.
  • A finding was discovered early in evidence collection but not escalated until the report was issued weeks later.
  • Prior-review actions were never requested from the CAPA system, so they were not carried forward.
  • A supplier’s support status is asserted rather than evidenced, and the system turns out to be running an unsupported version.
  • The reviewer’s assessment of each input is missing, so the conclusion cannot be traced to the evidence that produced it.

How to adapt this form

  1. Set your form number, version, and governing procedure reference in the header, and align the input list to whatever your own periodic review SOP requires. The 14 rows here match the standard set; add or remove rows so the worksheet and the SOP never disagree.
  2. Name the actual systems of record in the “evidence requested” column for your organization: your change management system, your identity management platform, your service desk, your CAPA system. A reviewer should not have to work out where evidence lives.
  3. Name the owning function to a team, not to a department. “IT Infrastructure, storage and backup team” gets an answer. “IT” gets forwarded three times.
  4. Set your own chase intervals in completion instruction 6 to match the lead time your SOP allows, and make the escalation path explicit.
  5. Add system-specific rows where the system needs them: interface reconciliation reports, instrument connectivity checks, hosted service level reports for a SaaS system, chain of identity checks for a cell and gene therapy system, batch record reconciliation for a manufacturing execution system.
  6. For a grouped review, run one worksheet per group for the common controls and one abbreviated worksheet per sampled member for the system-specific inputs, and reference the approved grouping rationale in the header.
  7. Keep the worksheet with the review record for the same retention period. It is the working paper that proves the review had coverage, and it is the first thing worth producing when an inspector asks how a conclusion was reached.
Use madhadi.com as an app Full screen, works offline, one tap from your home screen.