Independent and not affiliated with the FDA, MHRA, ISPE, PDA, or any agency. Get the appgoutham@madhadi.com
madhadi.comData Integrity & GxP Quality
Browse all topics → Articles Templates & Procedures Learning paths GlossaryScenariosToolsRegulatory ReferencesLearning PathsTopics About Start here
Log Plug-and-play starting point CSV / CSA

Log: Part 11 / Annex 11 Gap Remediation Tracker

A plug-and-play running log for tracking every open Part 11 / Annex 11 gap across your GxP computerized systems from identification through verified closure, with severity, owner, due date, and closure evidence columns, and a filled specimen.

Document type: Log

Read and copy the template below into your own quality system. It is a generic starting point for your own internal use, provided as is, with no warranty; see the Terms and License. Adopting it does not by itself create compliance.

This is a ready-to-use tracking log. Replace every <<FILL: ...>> placeholder, add one row per gap identified from any assessment or periodic review, and keep it current until every gap shows a verified closure. A filled specimen row follows.

Log

Gap IDSystemRequirementDescriptionSeverityIdentified (date, source)OwnerDue dateStatusClosure evidence
<<FILL: GAP-YYYY-NNN>><<FILL>><<FILL: e.g. §11.10(e) / cl.9>><<FILL>><<FILL: Critical/Major/Minor>><<FILL: date, assessment or review ID>><<FILL: name/role>><<FILL>><<FILL: Open/In progress/Closed>><<FILL: verification record reference>>

Instructions

  1. Open a row the same day a gap is identified, whether from an assessment, a periodic review, an inspection, or an internal audit. Do not batch gaps into the log after the fact.
  2. Set the due date from severity: Critical gaps close before the affected system is used for release decisions or are formally risk-accepted with an interim control; Major gaps close before go-live or carry a documented risk acceptance; Minor gaps carry a defined post-go-live date.
  3. “Closed” requires a verification record, not just a statement that the fix was made. A configuration change needs a re-test; a procedural fix needs evidence of training and use.
  4. Review the open items in this log at every periodic review and at every management review of the data integrity program; a gap open past its due date without an escalation is itself a finding.

Filled specimen

Gap IDSystemRequirementDescriptionSeverityIdentifiedOwnerDue dateStatusClosure evidence
GAP-2026-014EM LIMS module v4.2§11.10(e) / cl.9, Audit trail reviewWeekly audit trail review defined in SOP but not yet performed on the live systemMajor5 Aug 2026, assessment CSV-2026-071Micro QA lead19 Aug 2026ClosedReview record ATR-2026-0819, first review performed and approved
GAP-2026-015EM LIMS module v4.2cl.3, Supplier oversightQuality/service agreement with hosting vendor expired 2025, not yet renewedMajor5 Aug 2026, assessment CSV-2026-071Procurement12 Aug 2026ClosedRenewed agreement, executed 10 Aug 2026, filed with QA
GAP-2026-022MES recipe module v6.1§11.10(d), Access controlShared “engineering” login used for recipe deploymentMajor18 Aug 2026, baseline checklist go-live gateIT / CSV lead17 Oct 2026Open, interim control in placeInterim: shared login excluded from approval rights; final fix (individual accounts) in progress, target build date 30 Sep 2026

Reading the pattern: two Major gaps from the same assessment closed within two weeks with real verification evidence attached, and one gap carried forward with a documented, time-bound interim control rather than an open-ended promise. That is the difference between a log that demonstrates control and a list that quietly ages.

Common inspection findings this log prevents

  • Gaps identified during an assessment that never appear in any tracking system, so nobody can show whether they were closed.
  • A “closed” status with no verification record behind it.
  • An interim risk acceptance with no stated end date, effectively becoming a permanent, undocumented exception.

How to adapt this log

  1. If you track CAPAs or deviations in a dedicated quality system, this log can be a filtered view or export from that system rather than a standalone file, as long as the same fields are captured.
  2. Add a column for regulatory/inspection linkage if a gap was identified during an actual inspection, so the response commitment and this log stay consistent.
  3. Review aging open items against their due dates at a fixed cadence and escalate anything overdue to QA management.
Use madhadi.com as an app Full screen, works offline, one tap from your home screen.