Independent and not affiliated with the FDA, MHRA, ISPE, PDA, or any agency. Get the appgoutham@madhadi.com
madhadi.comData Integrity & GxP Quality
Browse all topics → Articles Templates & Procedures Learning paths GlossaryScenariosToolsRegulatory ReferencesLearning PathsTopics About Start here
Risk Assessment Plug-and-play starting point CSV / CSA

Risk Assessment: Part 11 / Annex 11 Predicate Rule Applicability and System Control Gap Assessment

A plug-and-play assessment that determines whether a computerized system still has a live predicate rule, classifies it open or closed, then scores its actual controls clause by clause against 21 CFR Part 11 and EU Annex 11 to produce a prioritized, evidence-based remediation plan, with a filled specimen.

Document type: Risk Assessment

Read and copy the template below into your own quality system. It is a generic starting point for your own internal use, provided as is, with no warranty; see the Terms and License. Adopting it does not by itself create compliance.

This is a ready-to-use assessment for an existing computerized system already in GxP use, answering two questions in sequence: does Part 11 still apply to this system’s records at all, and if it does, exactly which controls in 11.10, Subpart C, and EU GMP Annex 11 are actually missing. It is deliberately different from a URS-stage requirements checklist, which seeds requirements for a system that has not yet been built, and from a legacy-system testing-depth risk assessment, which scores functions for how much OQ evidence to collect. This document is a clause-by-clause compliance audit of a system already in production, producing a gap register with a severity read straight from the 2003 FDA scope-and-application guidance: a gap that could let bad data through is treated as materially more serious than a gap that is only a documentation shortfall. Replace every <<FILL: ...>> placeholder with your own specifics, set your document numbers and dates, and route it through document control. A worked filled specimen follows. This is general educational structure to adapt, not legal or regulatory advice; confirm each cited regulation against the current source before you rely on it.

Document control header

FieldEntry
Document titlePart 11 / Annex 11 Predicate Rule Applicability and System Control Gap Assessment
Document number<<FILL: ID, e.g. RA-CSV-044-01>>
Version<<FILL: version>>
Assessment date<<FILL: date>>
System assessed<<FILL: SYSTEM NAME / ID>>
Assessment owner<<FILL: role, e.g. CSV Lead>>
Assessment team<<FILL: names and roles, system owner, QA, IT, data integrity SME>>

1. Purpose and methodology

This assessment determines, with evidence, whether <<FILL: SYSTEM NAME / ID>> still produces records subject to a live predicate rule, classifies the system as open or closed, and then scores the gap between the controls the system actually has and the controls 21 CFR Part 11 and EU GMP Annex 11 require. The output is a prioritized remediation register, not a pass/fail label; a system can be substantially compliant with a small number of high-severity gaps, or largely compliant on paper with one control that quietly never worked.

Run this assessment: at initial validation of an existing (never-formally-assessed) system, whenever a periodic review or an internal audit raises doubt about Part 11 status, before a system is proposed for continued use past a planned retirement date, and as a standing element of a data integrity gap-assessment program.

2. System description and use

FieldEntry
System / application and version<<FILL>>
GxP process supported<<FILL>>
Record types produced<<FILL: e.g. batch data, stability data, complaint records>>
GxP decisions the data feeds<<FILL: release, in-process, stability, disposition, submission>>
Hosting<<FILL: on-premise / vendor-hosted / SaaS>>
Date entered GxP use<<FILL>>
Prior validation or assessment (if any)<<FILL: none / date and scope>>

Part A: Predicate rule and scope determination

3. Predicate rule per record type

A system frequently produces more than one record type, and each can carry a different predicate rule. List each type separately; do not collapse them into one blanket answer.

Record typePredicate rule(s)Still driving a live GxP decision?Basis
<<FILL: e.g. batch release result>><<FILL: e.g. 21 CFR 211>>Yes / No<<FILL>>
<<FILL: e.g. discontinued-product stability data>><<FILL>>Yes / No<<FILL>>
<<FILL: e.g. combination-product device record>><<FILL: e.g. 21 CFR 820 / QMSR>>Yes / No<<FILL>>

If every record type is “No” (retention only): the system needs its records preserved, readable, and retrievable through the retention period. Full 11.10/Annex 11 remediation to a current standard is not required unless the system returns to active GxP use. Skip to section 9 and record this determination.

If any record type is “Yes”: the system carries a live predicate rule. Continue to section 4.

4. Open or closed classification

Classify by who actually controls access to the content, not by hosting model.

QuestionAnswer
Who controls access to the records: your organization’s identity management, or a party you do not govern?<<FILL>>
Do provider personnel have any contractual or technical path to the production data?<<FILL>>
ClassificationOpen / Closed
If open, are 11.30 controls (encryption in transit/at rest, signature integrity) present?<<FILL>>

5. Electronic signature applicability and certification status

QuestionAnswer
Are electronic signatures applied to any record produced by this system?Yes / No
If yes, is the organization’s one-time 21 CFR 11.100(c) certification letter on file and current?<<FILL>>
Are signatures biometric, non-biometric, or both?<<FILL>>

Part B: Control gap scoring

6. Gap severity scale

Severity is read from the 2003 FDA scope-and-application guidance: the question is not “is this clause satisfied to the letter,” but “would this gap actually let a bad, unattributable, or unreliable record through.”

SeverityMeaning
CriticalThe gap could let an inaccurate, unattributable, or unauthorized record through undetected (e.g., audit trail off, shared logins, no signature-record binding)
ModerateThe control exists but is incomplete, untested, or inconsistently applied (e.g., backup taken but restore never verified, periodic review overdue)
MinorDocumentation, formatting, or procedural tidiness gap with no plausible path to bad data reaching a decision

7. Part 11 clause-by-clause gap register

ClauseRequirementCurrent stateEvidenceGap severityRemediation actionOwnerTarget date
11.10(a) ValidationValidated, discerns altered records<<FILL: Compliant / Partial / Gap>><<FILL>><<FILL>><<FILL>><<FILL>><<FILL>>
11.10(b) CopiesComplete human-readable and electronic copies<<FILL>><<FILL>><<FILL>><<FILL>><<FILL>><<FILL>>
11.10(c) ProtectionRetrievable through retention<<FILL>><<FILL>><<FILL>><<FILL>><<FILL>><<FILL>>
11.10(d) AccessIndividual accounts, no sharing<<FILL>><<FILL>><<FILL>><<FILL>><<FILL>><<FILL>>
11.10(e) Audit trailOn, complete, cannot be disabled by users<<FILL>><<FILL>><<FILL>><<FILL>><<FILL>><<FILL>>
11.10(f) SequencingEnforces valid step order<<FILL>><<FILL>><<FILL>><<FILL>><<FILL>><<FILL>>
11.10(g) AuthorityRole-based access checks<<FILL>><<FILL>><<FILL>><<FILL>><<FILL>><<FILL>>
11.10(h) DeviceInput source validity checks (if relevant)<<FILL>><<FILL>><<FILL>><<FILL>><<FILL>><<FILL>>
11.10(i) TrainingRole-based training before access<<FILL>><<FILL>><<FILL>><<FILL>><<FILL>><<FILL>>
11.10(j) PolicySigned accountability policy<<FILL>><<FILL>><<FILL>><<FILL>><<FILL>><<FILL>>
11.10(k) DocumentationControlled admin/config documentation<<FILL>><<FILL>><<FILL>><<FILL>><<FILL>><<FILL>>
11.50 ManifestationName, date/time, meaning shown<<FILL>><<FILL>><<FILL>><<FILL>><<FILL>><<FILL>>
11.70 LinkingSignature bound to record version<<FILL>><<FILL>><<FILL>><<FILL>><<FILL>><<FILL>>
11.100 Identity/uniquenessVerified, unique, never reassigned<<FILL>><<FILL>><<FILL>><<FILL>><<FILL>><<FILL>>
11.200 ComponentsTwo-component or qualifying biometric<<FILL>><<FILL>><<FILL>><<FILL>><<FILL>><<FILL>>

8. Annex 11 clause-by-clause gap register (if EU-marketed or EU-inspected)

ClauseRequirementCurrent stateEvidenceGap severityRemediation actionOwnerTarget date
Cl. 1 Risk managementRisk-based effort through the lifecycle<<FILL>><<FILL>><<FILL>><<FILL>><<FILL>><<FILL>>
Cl. 3 SuppliersFormal agreement defining responsibilities<<FILL>><<FILL>><<FILL>><<FILL>><<FILL>><<FILL>>
Cl. 4 ValidationTraceable requirements and testing<<FILL>><<FILL>><<FILL>><<FILL>><<FILL>><<FILL>>
Cl. 6 Manual entry checksCritical manual entries verified<<FILL>><<FILL>><<FILL>><<FILL>><<FILL>><<FILL>>
Cl. 7 / 7.2 Storage, backup, restoreData protected; restore actually tested<<FILL>><<FILL>><<FILL>><<FILL>><<FILL>><<FILL>>
Cl. 9 Audit trailRisk-based, reviewed<<FILL>><<FILL>><<FILL>><<FILL>><<FILL>><<FILL>>
Cl. 11 Periodic evaluationDone on defined frequency<<FILL>><<FILL>><<FILL>><<FILL>><<FILL>><<FILL>>
Cl. 12 SecurityAccess control operating<<FILL>><<FILL>><<FILL>><<FILL>><<FILL>><<FILL>>
Cl. 13 Incident managementDefined and exercised<<FILL>><<FILL>><<FILL>><<FILL>><<FILL>><<FILL>>
Cl. 16 Business continuityTested, criticality-matched<<FILL>><<FILL>><<FILL>><<FILL>><<FILL>><<FILL>>

9. Overall determination and remediation summary

FieldEntry
Predicate rule statusLive / Retention only / No predicate rule identified
Open or closed<<FILL>>
Overall determinationCompliant / Remediation required / Replacement required
Number of Critical / Moderate / Minor gaps<<FILL>>
Interim controls in place now<<FILL>>
Historical data review requiredYes / No, <<FILL: population and basis>>
Disclosure assessment requiredYes / No, <<FILL: submission exposure>>
Next review date<<FILL>>

10. Acceptance criteria

This assessment is acceptable when all of the following are true:

  • The predicate rule status is determined per record type, with a basis, not assumed from the system’s age or name.
  • The open/closed classification is based on documented access control reality, not hosting model.
  • Every applicable Part 11 clause and, where relevant, Annex 11 clause carries a current-state entry with evidence, not a bare Pass/Fail.
  • Every gap carries a severity read from its actual data-reliability consequence, an owner, and a target date.
  • Any Critical gap has an interim control already in place, not only a planned future fix.
  • The overall determination and remediation summary is signed by the system owner and Quality Assurance.

11. References

21 CFR Part 11 (electronic records and electronic signatures), Subparts B and C. FDA guidance, Part 11, Electronic Records; Electronic Signatures, Scope and Application (August 2003). EU GMP Annex 11 (Computerised Systems), in-force 2011 version; track the draft revision published for consultation 7 July 2025, not yet final as of this writing. ICH Q9(R1), Quality Risk Management. FDA guidance, Computer Software Assurance for Production and Quality Management System Software (current version). FDA guidance, Data Integrity and Compliance With Drug CGMP, Questions and Answers (December 2018).

Confirm the current version and clause numbers of each reference before issue.

12. Approval

RoleNameSignatureDate
Assessment owner (CSV)<<FILL>>
System owner<<FILL>>
Quality Assurance<<FILL>>

Filled specimen

Illustrative, for a legacy quality control LIMS supporting release testing of a marketed injectable product, never formally assessed against Part 11 since its 2011 go-live.

Record types: release test results (live, predicate rule 21 CFR 211), a discontinued line’s retained stability data (retention only, product exited the market in 2019).

Part A: Release-testing record type carries a live predicate rule under 21 CFR 211; continue full assessment for that record type. Discontinued-line stability data is retention only; scoped to preservation and readability, no re-validation.

Open/closed: closed. Access controlled entirely by the site’s own Active Directory groups; no external party can reach production data. No 11.30 controls needed.

Electronic signatures: yes, non-biometric, ID plus password. Certification letter: found on file, dated 2012, current.

Part B (excerpt):

ClauseRequirementCurrent stateEvidenceGap severityRemediation actionOwnerTarget date
11.10(e) Audit trailOn, complete, cannot be disabled by usersPartialAudit trail enabled for results, but the “sample login” account used by two former analysts remains active with an unclear historyCriticalDisable shared account immediately; investigate two years of entries under that login for attribution; migrate to individual accountsIT / QAInterim control same day; investigation closed in 60 days
11.10(k) DocumentationControlled admin/config documentationGapNo change-control record for a 2019 server migrationModerateReconstruct configuration baseline from available logs and vendor records; bring under change control going forwardCSV Lead90 days
11.50 ManifestationName, date/time, meaning shownCompliantSignature manifestation screenshots and printouts confirm all three elements

Overall determination: Remediation required. Two Critical gaps (shared login, unclear historical attribution) with interim controls (shared account disabled same day, enhanced second-person review of results signed under that account pending investigation) already in place. Historical data review required for the shared-account period, population all release results signed under that login, disclosure assessment triggered because release results reached the marketing application.

This is the pattern a genuine assessment should produce for a system that has quietly run for over a decade with no formal Part 11 review: it finds the shared login, treats it as Critical because it breaks attribution, and does not wait for a project plan before disabling it.

Common inspection findings this assessment prevents

  • A system assumed to be “grandfathered” out of Part 11 because it predates a formal validation program, with no documented determination.
  • A predicate-rule status never re-checked after a product is discontinued, so a system is over-remediated or, worse, under-remediated relative to what it actually still supports.
  • A clause-by-clause gap never actually documented, so remediation priorities are set from memory or convenience rather than evidence.
  • A Critical gap (shared logins, disabled audit trail) sitting on a remediation project timeline with no interim control while it waits its turn.
  • An open/closed classification asserted from the hosting model rather than from who actually controls access.

How to adapt this assessment

  1. Set your document number and list your actual assessment team by name.
  2. In section 3, list every genuinely distinct record type the system produces; do not merge a live-decision record with a retention-only record.
  3. Use your own evidence sources (configuration exports, access logs, backup/restore logs) in the “Evidence” columns; do not accept an assertion with no artifact behind it.
  4. Keep the severity definitions tied to data-reliability consequence, matching the 2003 guidance philosophy, rather than a generic High/Medium/Low with no stated meaning.
  5. Feed every open action into your organization’s standard quality-commitment tracking system, not a standalone spreadsheet that nobody revisits.
  6. Confirm every regulation in section 11 against the current published version before issue.
Use madhadi.com as an app Full screen, works offline, one tap from your home screen.