This is a ready-to-use register that maps each GxP data set to a system and to a named owner, steward, and custodian. Abstract role definitions do not survive contact with an inspector; a concrete register that answers “who owns this data” on the spot does. Keep it under change control and review it at every governance board meeting, because people move and the mapping decays in months if untended. Replace every <<FILL: ...>> placeholder. A filled specimen follows.
Register
Field definitions
Acceptance criteria for the register
- Every GxP system in the validated system inventory appears at least once.
- Every row has all three roles filled with a real role title, never “TBD.”
- The owner is always a business or quality role, never “IT”; the custodian is the only column where an external vendor appears.
- No person sits as both custodian admin and approver of their own access or data changes on the same system (segregation confirmed).
- Owner acceptance is on file for every high-criticality data set, and the register is under change control and reviewed at governance board cadence.
Filled specimen
In this specimen every owner is a named business role, the only external parties sit in the custodian column, and each high-criticality data set has a dated owner acceptance and a confirmed segregation of duties. When the inspector asks who owns the chromatography data, the site opens this register and points to the head of QC, the steward, and the custodian, then produces the signed acceptance form.
Common inspection findings this register prevents
- Asked who owns a data set, three people give three answers, or none can name an owner.
- A high-criticality system has no assigned steward, so audit trail review falls to no one or to the person who created the data.
- A hosted system’s custodian is a vendor with no owner acceptance and no segregation check recorded.
- The register exists but is a year stale, listing leavers as owners and stewards.
How to adapt this register
- Seed it from your validated system inventory so every GxP system appears.
- Assign and ratify roles through the governance board, and record owner acceptance dates from the acceptance form.
- Confirm segregation of duties for each system before marking the column Y.
- Put the register under change control and review it at every governance board meeting.
- Cross-reference it with the data governance RACI so activity-level responsibilities line up with the named roles.