This is a ready-to-use tracking log. Replace every <<FILL: ...>> placeholder, add one row per gap identified from any assessment or periodic review, and keep it current until every gap shows a verified closure. A filled specimen row follows.
Log
| Gap ID | System | Requirement | Description | Severity | Identified (date, source) | Owner | Due date | Status | Closure evidence |
|---|---|---|---|---|---|---|---|---|---|
<<FILL: GAP-YYYY-NNN>> | <<FILL>> | <<FILL: e.g. §11.10(e) / cl.9>> | <<FILL>> | <<FILL: Critical/Major/Minor>> | <<FILL: date, assessment or review ID>> | <<FILL: name/role>> | <<FILL>> | <<FILL: Open/In progress/Closed>> | <<FILL: verification record reference>> |
Instructions
- Open a row the same day a gap is identified, whether from an assessment, a periodic review, an inspection, or an internal audit. Do not batch gaps into the log after the fact.
- Set the due date from severity: Critical gaps close before the affected system is used for release decisions or are formally risk-accepted with an interim control; Major gaps close before go-live or carry a documented risk acceptance; Minor gaps carry a defined post-go-live date.
- “Closed” requires a verification record, not just a statement that the fix was made. A configuration change needs a re-test; a procedural fix needs evidence of training and use.
- Review the open items in this log at every periodic review and at every management review of the data integrity program; a gap open past its due date without an escalation is itself a finding.
Filled specimen
| Gap ID | System | Requirement | Description | Severity | Identified | Owner | Due date | Status | Closure evidence |
|---|---|---|---|---|---|---|---|---|---|
| GAP-2026-014 | EM LIMS module v4.2 | §11.10(e) / cl.9, Audit trail review | Weekly audit trail review defined in SOP but not yet performed on the live system | Major | 5 Aug 2026, assessment CSV-2026-071 | Micro QA lead | 19 Aug 2026 | Closed | Review record ATR-2026-0819, first review performed and approved |
| GAP-2026-015 | EM LIMS module v4.2 | cl.3, Supplier oversight | Quality/service agreement with hosting vendor expired 2025, not yet renewed | Major | 5 Aug 2026, assessment CSV-2026-071 | Procurement | 12 Aug 2026 | Closed | Renewed agreement, executed 10 Aug 2026, filed with QA |
| GAP-2026-022 | MES recipe module v6.1 | §11.10(d), Access control | Shared “engineering” login used for recipe deployment | Major | 18 Aug 2026, baseline checklist go-live gate | IT / CSV lead | 17 Oct 2026 | Open, interim control in place | Interim: shared login excluded from approval rights; final fix (individual accounts) in progress, target build date 30 Sep 2026 |
Reading the pattern: two Major gaps from the same assessment closed within two weeks with real verification evidence attached, and one gap carried forward with a documented, time-bound interim control rather than an open-ended promise. That is the difference between a log that demonstrates control and a list that quietly ages.
Common inspection findings this log prevents
- Gaps identified during an assessment that never appear in any tracking system, so nobody can show whether they were closed.
- A “closed” status with no verification record behind it.
- An interim risk acceptance with no stated end date, effectively becoming a permanent, undocumented exception.
How to adapt this log
- If you track CAPAs or deviations in a dedicated quality system, this log can be a filtered view or export from that system rather than a standalone file, as long as the same fields are captured.
- Add a column for regulatory/inspection linkage if a gap was identified during an actual inspection, so the response commitment and this log stay consistent.
- Review aging open items against their due dates at a fixed cadence and escalate anything overdue to QA management.