Independent and not affiliated with the FDA, MHRA, ISPE, PDA, or any agency. Get the appgoutham@madhadi.com
madhadi.comData Integrity & GxP Quality
Browse all topics → Articles Templates & Procedures Learning paths GlossaryScenariosToolsRegulatory ReferencesLearning PathsTopics About Start here
Log Plug-and-play starting point CSV / CSA

GxP Computerized System Inventory Register

A plug-and-play register with one row per computerized system: ownership, GxP determination and basis, GAMP category, criticality tier, regulated records held, Part 11 and Annex 11 applicability, validation status and last validation date, periodic review due date, supplier, hosting, data classification, and decommission status, with maintenance rules and a filled specimen.

Document type: Log

Read and copy the template below into your own quality system. It is a generic starting point for your own internal use, provided as is, with no warranty; see the Terms and License. Adopting it does not by itself create compliance.

This is a ready-to-use register of computerized systems. It is the master list every other control depends on: you cannot show an inspector a validation state, a periodic review schedule, or a Part 11 scope for systems you have not inventoried, and the most common opening finding in a computer system inspection is a system in use that was never on a list. Replace every <<FILL: ...>> placeholder, keep one row per system, set your own document numbers and dates, and route the register through your normal document control, review, and approval. A worked filled specimen follows so you can see how a completed register reads. Verify each cited regulation against the current source before you rely on it. Maintaining this register does not by itself create compliance; it makes the state of your estate visible so the rest of the system can act on it.

Document control header

FieldEntry
Document titleGxP Computerized System Inventory Register
Document number<<FILL: LOG-ID, e.g. LOG-QA-CSV-001>>
Version<<FILL: version, e.g. 1.0>>
Effective date<<FILL: effective date>>
Supersedes<<FILL: prior version or "New">>
Register owner<<FILL: role, e.g. CSV / Computerized Systems Lead, Quality>>
Approvers<<FILL: e.g. Head of Quality, Head of IT/Validation>>
Applies to<<FILL: sites / business units in scope>>
Review cadence<<FILL: e.g. quarterly reconciliation, full review annually>>

How to use this register

  1. Set the document number, owner, and approvers in the header.
  2. Enter one row per computerized system in scope. A system is in scope if it creates, modifies, stores, transmits, or uses data that supports a GxP decision, including spreadsheets, standalone instrument workstations, and cloud applications, not only the large validated platforms.
  3. Complete the GxP determination column with a Yes or No and a short basis. A No still gets a row, with the basis recorded, so the decision is defensible later.
  4. For GxP systems, complete the GAMP category, criticality tier, Part 11 and Annex 11 applicability, validation status, and periodic review due date.
  5. Link each row to its supporting records (validation report number, periodic review record, system risk assessment).
  6. Keep the register under change control. Reconcile it on the cadence in the header and update it whenever a trigger occurs.

Field definitions

Use these definitions so every entry is consistent. The same field meanings apply to the blank register and the filled specimen below.

ColumnWhat goes in itAllowed values / format
System IDUnique internal identifier for the systemShort code, e.g. SYS-001
System name and versionCommon name plus the version or release in productionText
Business ownerThe accountable user-side owner (function that relies on the system)Role / name
System ownerThe accountable owner for the system lifecycle and validated stateRole / name
GxP determinationWhether the system is GxP, with a one-line basisYes / No + basis
GAMP categorySoftware category that sets the validation approach1, 3, 4, or 5
Criticality tierRisk-based tier driving rigor and review frequencyHigh / Medium / Low
Regulated records heldThe GxP records the system creates or storesText
Part 11 / Annex 11 applicabilityWhether electronic records and signatures rules applyYes / No + scope note
Validation statusCurrent state of the validated conditionValidated / In validation / Not required / Retired
Last validation dateDate validation (or last revalidation) was completedDate
Periodic review dueDate the next periodic review is dueDate
SupplierVendor of the softwareText
HostingWhere the system runsOn-prem / SaaS / Hosted / Hybrid
Data classificationConfidentiality / sensitivity class per company policye.g. Restricted / Confidential / Internal
Decommission statusActive or retirement stateActive / Planned retirement / Retired-archived

GAMP category at a glance

These are the GAMP 5 (2nd ed.) software categories. Use them to set the validation effort, not to skip a risk assessment.

CategoryMeaning (in plain terms)Typical validation emphasis
1Foundational layer the applications run on, such as operating systems, database engines, and network or middleware servicesQualified infrastructure; record version and patch control
3Off-the-shelf product run as delivered, with no setup beyond its out-of-the-box behaviorVerify intended use; risk-based testing of GxP functions
4Commercial product tailored to your process through built-in settings and parameters, without writing codeValidate the configuration and the GxP-relevant workflows
5Software written or coded for your needs, including bespoke applications and user-authored scripts or macrosFull lifecycle rigor; design review and code-level controls

Criticality tier and what it drives

TierBasisDrives
HighDirect impact on product quality, patient safety, or batch / lot dispositionMost rigorous validation, tightest review frequency, shortest periodic review interval
MediumIndirect or supporting GxP impactModerate validation, periodic review on a standard interval
LowMinor GxP relevance, reference or non-decision dataReuse supplier evidence where justified, longest periodic review interval

Register (blank)

Keep one row per system. Wide registers are usually maintained in a controlled spreadsheet or a validated inventory tool; the columns below are the controlled minimum. Split into two stacked tables if your page is narrow, but keep the System ID as the key in both.

System IDSystem name and versionBusiness ownerSystem ownerGxP (Y/N + basis)GAMP catTier
<<FILL>><<FILL>><<FILL>><<FILL>><<FILL>><<FILL>><<FILL>>
<<FILL>><<FILL>><<FILL>><<FILL>><<FILL>><<FILL>><<FILL>>
<<FILL>><<FILL>><<FILL>><<FILL>><<FILL>><<FILL>><<FILL>>
System IDRegulated records heldPart 11 / Annex 11Validation statusLast validationPeriodic review dueSupplierHostingData classDecommission
<<FILL>><<FILL>><<FILL>><<FILL>><<FILL>><<FILL>><<FILL>><<FILL>><<FILL>><<FILL>>
<<FILL>><<FILL>><<FILL>><<FILL>><<FILL>><<FILL>><<FILL>><<FILL>><<FILL>><<FILL>>
<<FILL>><<FILL>><<FILL>><<FILL>><<FILL>><<FILL>><<FILL>><<FILL>><<FILL>><<FILL>>

Rules for keeping the register current

The value of an inventory is its accuracy on the day an inspector asks for it. A register that was right at go-live and never updated is worse than no register, because it asserts a state that is no longer true. Maintain it against the triggers and cadence below.

Triggers that require an update before the change takes effect

TriggerActionOwner
New system introduced (including a new spreadsheet used for a GxP calculation, a new standalone instrument, or a new SaaS subscription)Add a row and complete the GxP determination before the system is used for GxP workSystem owner with register owner
Version upgrade, major configuration change, migration, or re-hostingUpdate version, validation status, last validation date, and re-evaluate GAMP category and tierSystem owner
Change in GxP use (a system starts or stops holding regulated records)Re-run the GxP determination and update the basis, Part 11 / Annex 11 scope, and tierBusiness owner with Quality
Ownership change (people or function)Update business owner and system ownerRegister owner
Supplier or hosting changeUpdate supplier, hosting, and supplier assessment referenceSystem owner
Periodic review completedUpdate the periodic review due date to the next intervalRegister owner
Retirement / decommissionSet decommission status, record the data archival or migration reference, and the retention end dateSystem owner with Quality and IT

Periodic reconciliation

  • On the cadence stated in the header, the register owner reconciles the register against an independent source (for example the IT asset list, the access management list, software purchase records, and validation document indexes) to find systems that are in use but missing from the register, and entries that should be retired.
  • Discrepancies are logged and corrected under change control, with a short note of how each gap arose so the process can be improved.
  • The reconciliation is itself recorded, dated, and signed, so the act of keeping the register current is evidenced.

Ownership

  • The register has one accountable owner (the register owner in the header). Distributed editing without a single owner is how inventories drift.
  • Each row has a named business owner and a named system owner; an unowned system is a finding waiting to happen and should be resolved, not parked.

Acceptance criteria

  • Every computerized system that creates, modifies, stores, transmits, or uses GxP data has a row, including spreadsheets, standalone instrument workstations, and cloud applications.
  • Each row records a GxP determination with a one-line basis, including the No determinations.
  • For each GxP system, the GAMP category, criticality tier, Part 11 and Annex 11 applicability, validation status, last validation date, and periodic review due date are populated and current.
  • Each GxP row links to its supporting records (validation report, periodic review record, system risk assessment, supplier assessment).
  • The register is under change control, reconciled on the stated cadence, and updated against the defined triggers before changes take effect.
  • No system is in production GxP use without a corresponding row.

Roles and responsibilities

RoleResponsibility
Register owner (CSV / Computerized Systems Lead)Maintains the register, runs reconciliation, ensures one owner per row, controls versions.
Business ownerConfirms GxP use and the records held; raises changes in use.
System ownerKeeps version, GAMP category, validation status, hosting, and supplier current; drives validation and periodic review for the system.
Quality AssuranceApproves the register, confirms GxP determinations are defensible, oversees the link to validation and periodic review.
ITProvides the independent asset and access lists for reconciliation; maintains hosting and infrastructure qualification state.

Regulations this supports

21 CFR Part 11 (electronic records and electronic signatures); EU GMP Annex 11 (2011, computerised systems) and EU GMP Chapter 4 (documentation); GAMP 5 (2nd ed.), ISPE (software categories and risk-based validation); FDA guidance “Computer Software Assurance for Production and Quality Management System Software” (current version issued 3 February 2026); MHRA GxP Data Integrity Guidance (2018); PIC/S PI 041; ICH Q9(R1) (2022) for risk-based prioritization.

Cite these by number and title only and confirm the current version before you rely on any of them.

Retention

Retain the register and its superseded versions as controlled records for not less than <<FILL: retention period per records policy>>. Retired-system rows stay in the register (or a controlled retired-systems annex) with their archival reference for the full record retention period of the data those systems held.


Filled specimen

The following shows representative rows for a small estate, including the spreadsheet and standalone monitoring system that inventories most often miss. Company and system names are fictional and used only to illustrate format.

Register header (specimen)

FieldEntry
Document titleGxP Computerized System Inventory Register
Document numberLOG-QA-CSV-001
Version4.0
Effective date12 May 2026
Register ownerCSV Lead, Quality (A. Rao)
Applies toAcme Bio, Site B (drug substance and QC)
Review cadenceQuarterly reconciliation, full review annually

Identity and classification (specimen)

System IDSystem name and versionBusiness ownerSystem ownerGxP (Y/N + basis)GAMP catTier
SYS-001LIMS-01 (LabTrack v8.2)QC ManagerCSV LeadYes, holds QC release results4High
SYS-002CDS-01 (ChromaWorks v5.1)QC Lab LeadCSV LeadYes, generates release chromatography4High
SYS-003ERP-QM (NovaERP Quality module v2024.1)QA ManagerIT Apps LeadYes, batch disposition and deviations4High
SYS-014Stability pull scheduler (controlled spreadsheet)Stability LeadQC Lab LeadYes, schedules and tracks GxP stability pulls5Medium
SYS-022EM-01 (EnviroMon v3.0 monitoring system)Microbiology LeadFacilities LeadYes, environmental monitoring data4Medium

Lifecycle and hosting (specimen)

System IDRegulated records heldPart 11 / Annex 11Validation statusLast validationPeriodic review dueSupplierHostingData classDecommission
SYS-001Sample results, specifications, CoA dataYes, e-records + e-signaturesValidated18 Feb 202618 Feb 2027LabTrack IncOn-premRestrictedActive
SYS-002Chromatograms, integration, sequencesYes, e-records + e-signaturesValidated03 Nov 202503 Nov 2026ChromaWorks LtdOn-premRestrictedActive
SYS-003Disposition decisions, deviations, CAPAsYes, e-records + e-signaturesValidated27 Jan 202627 Jan 2027NovaERPSaaSConfidentialActive
SYS-014Stability pull dates and confirmationsYes, e-records (no e-sig; hybrid approval)Validated09 Apr 202609 Apr 2027In-house (workbook)On-premInternalActive
SYS-022Viable/non-viable counts, alarms, trendsYes, e-records + e-signaturesIn validationn/a (target 30 Jun 2026)First review 30 Jun 2027EnviroMon GmbHHostedConfidentialActive

The register earns its keep in rows SYS-014 and SYS-022. The stability spreadsheet is a custom (category 5) GxP tool that an estate often treats as “just a spreadsheet” and leaves off every list; here it is owned, classified, validated, and on a review clock. The EM system is shown mid-validation, so the inventory truthfully reflects a not-yet-validated state with a target date rather than an empty cell that hides a gap. SYS-003 is a SaaS module, which keeps the hosting and supplier columns honest and points to the supplier assessment that the on-prem systems do not need in the same way.

Common inspection findings this register prevents

  • A system in GxP use that appears on no inventory, surfaced by the inspector before the company finds it.
  • A spreadsheet or standalone instrument workstation performing a GxP function with no owner, no classification, and no validation.
  • A periodic review that is overdue because nothing tracked the due date.
  • A GxP determination that cannot be explained because the basis was never recorded.
  • A retired system still listed as active, or a still-active system marked retired, because retirement was never driven through the register.
  • Part 11 or Annex 11 scope that was never stated for systems holding electronic records and signatures.

How to adapt this register

  1. Set the document number, owner, and approvers; decide whether the controlled master lives in a spreadsheet or a validated inventory tool.
  2. Seed the register by reconciling against IT asset lists, access lists, and validation indexes, so the first version is complete rather than convenient.
  3. Sweep deliberately for spreadsheets, standalone instruments, and SaaS subscriptions; these are the rows that prevent findings.
  4. Wire the triggers into your change control so a new or changed system updates the register before it goes live.
  5. Set periodic review intervals by tier and let the register drive the schedule.
Use madhadi.com as an app Full screen, works offline, one tap from your home screen.