Services

System Review: keep the validated state

A periodic review establishes whether a validated system still matches its documented state after months in operation. We run the review for computerised systems and equipment, check user rights, backup, audit trail, changes and CAPAs, and track findings through to closure.

Our services for system review

Review is operations, not closure

A system does not lose its validated state through a single event, but through drift: leavers with active accounts, untested backups, modifications made without a change, documents left at an earlier revision. The periodic review makes that drift visible before an inspection does.

We work for QA, system owners and IT management in GxP operations who have a review obligation in their SOP and no internal capacity to meet it. The usual trigger is an annual review coming due, or a set of systems with no documented review since go-live.

What we review

  • User and role reviews in the system or via Active Directory groups
  • Backup concepts (backup plan / disaster recovery plan)
  • Logbooks and administrative audit trail (system settings, user and role management)
  • Change controls, deviations, CAPAs and events
  • Validation documents for required updates

We assess, track and close the findings. Where the review shows that the validated state no longer holds, we trigger change control or revalidation. We document in the quality system you already use, for example TrackWise, Veeva Vault or SAP-based solutions.

Follow-on

An annual review in production is described in the periodic review process-control case story. Related are computer system validation, Change Control and the network map.

Clarify scope?

Book an intro call

Leistungs-Wegweiser

Welche Ausgangslage beschreibt Ihr Vorhaben?

Wählen Sie die Ausgangslage. Sie erhalten einen fokussierten Startpunkt mit Vertiefungen und Kontaktweg.

A system does not lose its validated state through a single event, but through drift: leavers with active accounts, untested backups, modifications made without a change, documents left at an earlier revision. The periodic review makes that drift visible before an inspection does.

Referenz: Case story: periodic review. Case Story lesen

What You Receive

A review report per system stating scope, findings and assessment
A findings list with risk rating, owners and dates
Evidence of the user and access rights review, including rights held in Active Directory
A statement on the validated state: confirmed, confirmed with actions, or revalidation required
A review plan for the following periods, derived from system risk and your SOP

Which deliverables do you need first?

Book an intro call
Regulatory framework: EU GMP, ICH and FDA references

The duty to carry out periodic evaluations is stated explicitly in the regulations; you set the interval on a risk basis.

Our approach in GxP projects: from planning through release – each step delivers evidence you can present in QA review and audit. View GxP consulting in five steps

FAQ: System Review

How often is a review due?
Often annually. Annex 11 names no interval; it requires a periodic evaluation. What governs is your SOP and the system risk: a GMP-critical process control system is reviewed more frequently than pure evaluation software.
Who runs the review?
Validation Manager and System Lead. We provide one or both roles and include IAM (for example Active Directory) where users live outside the application.
When does a review become a revalidation?
When the review shows that the validated state no longer holds: changed use, open gaps, missing evidence. The Revalidation station on the network map does not yet have its own page.

Plan a periodic review

Name the system, the interval and the next due date. We take on preparation, execution and follow-up of the findings.

Get in Touch