This is a ready-to-use register of what each GxP instrument’s software can actually do for data integrity, as opposed to what a slide claims. Instrument software for ddPCR, flow cytometry, sequencing, and plate reading was often built as a scientific tool first and a compliant records system second, so the audit-trail and access capability varies widely and is where partial-audit-trail and shared-login findings originate. Replace every <<FILL: ...>> placeholder, keep one row per instrument, and maintain it under document control. A filled specimen follows. Verify each cited regulation against the current source. Pair with the Checklist: Advanced Therapy Data Integrity Readiness.
Register header
| Field | Entry |
|---|---|
| Register number | <<FILL: ID>> |
| Program / site | <<FILL>> |
| Owner | <<FILL: role>> |
| Last review / by | <<FILL>> |
Field definitions
| Field | Format | Required | Notes |
|---|---|---|---|
| Instrument / ID | Name, asset ID | Yes | The physical unit |
| Software / version | Package and version | Yes | Capability is version-specific |
| GxP use | What decision it supports | Yes | Ties to criticality |
| Audit trail enabled | Yes / No | Yes | Off is an immediate gap |
| Field-level with prior value | Yes / Partial / No | Yes | The key capability; “modified” without prior value is Partial |
| Metadata in trail | Yes / No | Yes | Methods, thresholds, gating, sequences |
| Trail user-disableable | Yes / No | Yes | Yes is a gap |
| Named accounts | Yes / No | Yes | No means shared-login exposure |
| Privilege separation | Yes / No | Yes | Admin vs routine |
| Gap / compensating control | Text | If any gap | What mitigates the shortfall |
| Remediation / CAPA | Reference, date | If any gap | Upgrade or replacement plan |
The register
| Instrument / ID | Software / version | GxP use | AT enabled | Field-level + prior value | Metadata | Disableable | Named accts | Priv. sep. | Gap / compensating control | CAPA |
|---|---|---|---|---|---|---|---|---|---|---|
<<FILL>> | <<FILL>> | <<FILL>> | <<FILL>> | <<FILL>> | <<FILL>> | <<FILL>> | <<FILL>> | <<FILL>> | <<FILL>> | <<FILL>> |
<<FILL>> | <<FILL>> | <<FILL>> | <<FILL>> | <<FILL>> | <<FILL>> | <<FILL>> | <<FILL>> | <<FILL>> | <<FILL>> | <<FILL>> |
Add one row per GxP instrument. The register is the evidence behind Section A of the readiness checklist and the input to the risk-based prioritization of which instruments to remediate or replace first.
How to assess a “Partial” audit trail
An audit trail is Partial (not Pass) when it records that a change occurred but not enough to reconstruct the prior state: a “value modified” entry with a timestamp but no old value, or a trail that captures result changes but not the method, threshold, gating, or sequence changes where manipulation actually hides. Partial is a real gap: it must be documented, risk-assessed, given a compensating control (for example a contemporaneous second-person check of the parameter setting), and scheduled for upgrade or replacement.
Acceptance criteria
- Every GxP instrument is listed with its actual, version-specific capability, not an assumption.
- Any instrument with audit trail off, user-disableable, or without named accounts on a GxP-critical path has an open CAPA.
- Every Partial or No entry has a documented, risk-assessed compensating control.
- The register is reviewed on a defined cycle and after any software upgrade (capability can change with version).
References
21 CFR Part 11.10(d) (limited access, unique accounts), 11.10(e) (audit trail), 11.10(g) (authority checks). 21 CFR 211.68 (equipment controls). FDA Data Integrity and Compliance With Drug CGMP Q&A (final, Dec 2018). EU Annex 11 (audit trail, security). Pending draft Annex 11 revision and new draft Annex 22 (consultation closed 7 October 2025, draft as of mid-2026); confirm final text before citing.
Confirm each reference against the current source before issue.
Filled specimen
Illustrative extract across a small advanced-therapy analytical suite. The variation in capability is the realistic picture and the reason the register exists.
| Instrument / ID | Software / version | GxP use | AT enabled | Field-level + prior value | Metadata | Disableable | Named accts | Priv. sep. | Gap / compensating control | CAPA |
|---|---|---|---|---|---|---|---|---|---|---|
| ddPCR-01 | Vendor v<<FILL>> | VG titer release | Yes | Partial (no prior value on threshold edits) | Partial | No | Yes | Yes | Contemporaneous second-person check of threshold; gap logged | CAPA-2026-0132 (upgrade) |
| Flow-07 | Vendor v<<FILL>> | Transduction, identity | Yes | Yes | Yes | No | Yes (moved off shared login 06/2026) | Yes | None | Closed |
| NGS-02 | Pipeline v<<FILL>> | Off-target, editing outcome | Yes | Yes (pipeline params versioned) | Yes | No | Yes | Yes | None | N/A |
| Plate-04 | Vendor v<<FILL>> | Cell-based potency | Yes | Partial (curve-fit params not in trail) | Partial | No | Yes | No | Second-person review of curve fit; privilege separation gap | CAPA-2026-0140 |
| Balance-11 | Firmware v<<FILL>> | Formulation weights | No | No | No | N/A | No (single admin) | No | Standalone; move to networked balance with named accounts | CAPA-2026-0151 (replace) |
The balance is the worst case and the most common one: a cheap standalone unit with no audit trail and a single admin account, feeding GxP-critical weights. It is not ignored, it is documented, risk-assessed, given an interim compensating control, and scheduled for replacement. The ddPCR and plate reader show the realistic Partial case that a compensating control holds while an upgrade is pending.
How to adapt this register
- Walk the bench, not the asset list; the instruments that get missed are the small standalone units.
- Re-assess capability after every software or firmware upgrade, because it can change silently with version.
- Use the register to rank remediation: audit-trail-off and shared-login on release-critical paths first.
- Confirm each reference against the current source, including the pending Annex 11 revision, before use.