This is a ready-to-use release authorization form. It is the artifact that records the go-live decision for a validated system: what was released, on what basis, subject to which conditions, and the quality-unit signature that authorizes GxP use. It references an approved validation summary report rather than repeating it. Replace every <<FILL: ...>> placeholder with your own specifics, set your document numbers and dates, and route it through your normal document control. A worked filled specimen follows the template. Verify each cited regulation against the current source before you rely on it.
Document control header
| Field | Entry |
|---|---|
| Form title | System Release Authorization |
| Record number | <<FILL: REL-ID, e.g. REL-2026-018>> |
| System name and version | <<FILL: SYSTEM NAME / version>> |
| GxP classification / GAMP category | <<FILL: e.g. GxP, GAMP Category 4>> |
| Validation summary report referenced | <<FILL: VSR doc number and version>> |
| Validation plan referenced | <<FILL: VP doc number>> |
| Change control reference | <<FILL: CR number>> |
| System owner | <<FILL: role>> |
| Requested effective (go-live) date | <<FILL: date>> |
1. Release statement
This form authorizes <<FILL: SYSTEM NAME>> for GxP use, based on the approved validation summary report referenced above, subject to the conditions recorded in section 3. GxP use may begin no earlier than the effective date recorded in section 5, and not before the quality-unit approval date in section 6.
2. Release criteria confirmation
Confirm each criterion. Any “No” must be justified in section 3 as a condition or must stop the release.
| # | Release criterion | Met? | Evidence / reference |
|---|---|---|---|
| 2.1 | All planned deliverables produced, executed, reviewed, and approved | Yes / No | <<FILL>> |
| 2.2 | 100% of requirements traced and verified, or justified exception recorded | Yes / No | <<FILL: RTM reference>> |
| 2.3 | All critical and major deviations closed; minor deviations closed or carried as justified conditions | Yes / No | <<FILL: deviation log reference>> |
| 2.4 | Required SOPs approved and effective (operation, backup/restore, security admin, periodic review, business continuity) | Yes / No | <<FILL>> |
| 2.5 | Training completed for users and administrators | Yes / No | <<FILL>> |
| 2.6 | Supporting infrastructure qualified | Yes / No | <<FILL>> |
| 2.7 | Data migration verified, if applicable | Yes / No | <<FILL: or N/A>> |
| 2.8 | Residual risk assessed and formally accepted | Yes / No | <<FILL: residual-risk acceptance record number>> |
3. Conditions of release (open items carried into operation)
List each open item released as a condition. A critical deviation is never eligible to be a condition.
| # | Condition / open item | Class | Compensating control | Owner | Due date | Tracking reference |
|---|---|---|---|---|---|---|
| 1 | <<FILL>> | <<FILL: Major / Minor>> | <<FILL>> | <<FILL>> | <<FILL>> | <<FILL: CAPA / action number>> |
If there are no conditions, state “None; released without conditions.”
4. Residual risk
| Field | Entry |
|---|---|
| Overall residual risk | <<FILL: Low / Medium / High>> |
| Residual-risk acceptance record | <<FILL: record number>> |
| Accepted by (role) | <<FILL: e.g. Head of QA for high residual risk>> |
5. Effective date
| Field | Entry |
|---|---|
| Effective (go-live) date for GxP use | <<FILL: date, on or after QA approval in section 6>> |
| Any documented interim-use arrangement | <<FILL: reference and justification, or "None">> |
6. Authorization signatures
The quality-unit signature is the gating approval for GxP release and must be dated on or before the effective date.
| Role | Attests | Name | Signature | Date |
|---|---|---|---|---|
| Validation lead | The VSR conclusion is supported by the evidence | <<FILL>> | ||
| System / process owner | Operational readiness: SOPs, training, infrastructure in place | <<FILL>> | ||
| Quality Assurance (release authority) | Validation met procedural and regulatory requirements; deviation handling and residual-risk acceptance are sound; system is released for GxP use | <<FILL>> |
7. References
21 CFR 211.22 (quality unit responsibility to approve procedures and specifications affecting product quality). 21 CFR 211.68 (automatic, mechanical, and electronic equipment); 21 CFR Part 11 (electronic records and signatures). EU GMP Annex 11 (computerised systems: fitness for intended purpose; validation documentation and reports). GAMP 5 (Second Edition, ISPE 2022) for the validation report and release concept. Where a combination product brings a device constituent into scope, the applicable device quality-system process-validation and release requirements.
Confirm the current version and clause numbers before issue.
Filled specimen
The following shows the form completed for an example configured LIMS (GAMP Category 4), released with two conditions carried from its VSR.
| Field | Entry |
|---|---|
| Record number | REL-2026-018 |
| System name and version | QC LIMS, v7.2 (configured) |
| VSR referenced | VSR-LIMS-2026-004 v1.0 |
| Requested effective date | 22 June 2026 |
Release criteria: 2.1 Yes; 2.2 Yes (142/142 traced); 2.3 Yes (all critical/major closed; two majors carried as conditions per below); 2.4 Yes; 2.5 Yes; 2.6 Yes; 2.7 Yes (migration verified, 1 deviation); 2.8 Yes (RRA-2026-011).
Conditions of release:
| # | Condition | Class | Compensating control | Owner | Due date | Tracking |
|---|---|---|---|---|---|---|
| 1 | Post-go-live check that no further deprecated-unit records exist in the active dataset | Major | 11 affected records individually verified 1:1; mapping rule added | QC Supervisor | 22 July 2026 | CAPA-2026-057 |
| 2 | 3 archived records permanently lack original analyst ID | Major | Records read-only, flagged, excluded from current decisions; data-limitation note travels with them | Head of QA | Closed at acceptance | RRA-2026-011 |
Residual risk: Low overall; acceptance record RRA-2026-011; accepted by Head of QA. Effective date: 22 June 2026. Interim use: none.
Signatures: Validation lead (18 June 2026), QC system owner (18 June 2026), Head of QA as release authority (19 June 2026). The QA date, 19 June, precedes the 22 June go-live, which is exactly the ordering an inspector checks.
Common inspection findings this form prevents
- GxP data created in the gap between go-live and the signed release decision, because no artifact recorded when release was actually authorized.
- A QA approval dated after the effective go-live date.
- Open items live in production with no owner, due date, or tracking reference.
- A critical deviation quietly carried as a “condition” instead of blocking release.
- A release with no clear single quality-unit authorizing signature.
How to adapt this form
- Set your record number and point the header references to your real VSR, validation plan, and change control.
- Align the release criteria in section 2 with the criteria your validation plan actually committed to.
- Route the form so the QA signature is applied before the effective date is set, and capture both dates.
- Feed every condition in section 3 into your action-tracking system so it closes rather than becoming a permanent gap.
- Keep the residual-risk detail in a separate acceptance record and reference it here, so the acceptance is owned by name at the right level.