GxP compliance checklists exist everywhere — and most of them are useless. They list vague principles without pass/fail criteria. They conflate FDA requirements with EU expectations. They skip the items inspectors actually cite in 483 observations. This checklist is different. It covers 60 specific items across eight compliance domains, mapped to the regulation that requires them, with the evidence an inspector expects to see and the failure mode that triggers a finding. Print it, run it quarterly, and close gaps before an inspector finds them.
Domain 1: Electronic records and signatures (21 CFR Part 11 / EU Annex 11)
| # | Check Item | Regulation | Evidence Required |
|---|---|---|---|
| 1 | Unique user IDs — no shared accounts | 11.10(d), Annex 11 §12.1 | User admin export showing 1:1 mapping |
| 2 | Electronic signatures include printed name, date, time, and meaning | 11.50(a) | Screenshot of e-sig record with all four fields |
| 3 | Password complexity and expiry policy enforced by the system | 11.300(b) | Security config export showing policy parameters |
| 4 | Audit trail captures who, what, when, why for every record change | 11.10(e), Annex 11 §9 | Audit trail extract showing a real change with all four fields |
| 5 | Audit trails cannot be disabled or modified by users | 11.10(e) | Config showing audit trail is system-enforced, not user-togglable |
| 6 | Backup and restore procedures tested and documented | Annex 11 §7.2 | Most recent backup test report with recovery time |
| 7 | System access provisioning and deprovisioning tied to HR process | 11.10(d) | Access review log showing deprovisioned leavers |
| 8 | Session timeout enforced after defined inactivity period | 11.10(d) | System config showing timeout value |
FDA 21 CFR Part 11 compliance and EU Annex 11 & Annex 22 compliance are the two regulatory anchors for electronic records. GxP Copilot enforces items 1–5 by design — the hash-chained audit trail cannot be disabled, and electronic signatures capture all four Part 11 fields without configuration.
Domain 2: Data integrity (ALCOA+)
| # | Check Item | ALCOA+ Element | Evidence Required |
|---|---|---|---|
| 9 | All GxP records attributable to a specific individual | Attributable | Record sample showing user identity on every entry |
| 10 | Records are readable and permanently accessible for retention period | Legible | Retention policy + test retrieval of oldest record |
| 11 | Records created at the time of the activity, not retrospectively | Contemporaneous | Timestamp evidence showing entry time matches activity time |
| 12 | Original records are preserved — no transcription without both versions retained | Original | Data flow map showing original record path |
| 13 | Records are accurate and verified by a second person where required | Accurate | Second-person verification evidence on critical records |
| 14 | Data integrity risk assessment performed for each GxP system | All | Completed DI risk assessment with scoring |
| 15 | Periodic data integrity audit programme in place | All | Audit schedule + most recent DI audit report |
data integrity (ALCOA+) services cover the full ALCOA+ programme — from initial risk assessment through periodic audit. The hash-chained audit trail in GxP Copilot provides tamper-evident evidence for items 9, 11, and 12 automatically.
Domain 3: Validation lifecycle
- 16. Validation master plan (VMP) current and approved. Reg: EU GMP Annex 15 §1. Evidence: signed VMP with review date within 12 months.
- 17. Every GxP system has a current validation status. Reg: GAMP 5. Evidence: system inventory with validation status and next review date.
- 18. Risk-based approach to validation documented. Reg: FDA CSA guidance, GAMP 5 SE. Evidence: risk assessment per system showing how testing depth was determined.
- 19. Traceability matrix links requirements → tests → results. Reg: GAMP 5. Evidence: RTM for each validated system showing complete coverage.
- 20. Periodic review programme in place. Reg: EU GMP Annex 11 §11. Evidence: review schedule + most recent periodic review report.
- 21. Change control procedure covers all validated systems. Reg: ICH Q10, GAMP 5. Evidence: change control SOP + log of recent changes with impact assessments.
- 22. Decommissioning procedure exists for retiring validated systems. Reg: Annex 11 §11. Evidence: decommissioning SOP + evidence of data migration or archival.
GxP Copilot generates the validation package — URS, risk assessment, IQ/OQ/PQ protocols, Live RTM, and Validation Summary Report — for items 16–19. Change controls handles item 21 with full audit trail and impact assessment workflows.
Domain 4: Change control and configuration management
- 23. Change control SOP defines categories (minor, major, emergency). Evidence: SOP with category definitions and approval matrices.
- 24. All changes risk-assessed before implementation. Evidence: change records with completed impact assessments.
- 25. Regression testing performed for major changes. Evidence: test records linked to change control records.
- 26. Emergency changes documented retrospectively within defined timeframe. Evidence: emergency change records with retrospective documentation within SOP-defined window.
- 27. Configuration items baselined and version-controlled. Evidence: configuration baseline document + change history.
- 28. Vendor patches assessed for GxP impact before deployment. Evidence: patch assessment records showing GxP impact analysis.
Domain 5: Training and competency
- 29. Training matrix covers all GxP roles and required SOPs. Evidence: current training matrix with role-to-SOP mapping.
- 30. Training completed before performing GxP activities. Evidence: training records with completion dates before first activity date.
- 31. Training effectiveness assessed (not just attendance). Evidence: competency assessments (quiz, observation, practical) with pass/fail criteria.
- 32. Retraining triggered by SOP revisions. Evidence: SOP revision log cross-referenced with retraining records.
- 33. Training records maintained for retention period. Evidence: oldest training record retrievable within the defined retention window.
- 34. Annual training gap analysis performed. Evidence: most recent gap analysis report with remediation actions.
Domain 6: Supplier and vendor qualification
- 35. Approved supplier list maintained and current. Evidence: ASL with qualification status and review dates.
- 36. GxP software vendors audited or assessed before use. Evidence: vendor audit reports or questionnaire assessments.
- 37. Quality agreements in place for GxP-critical suppliers. Evidence: signed quality agreements with defined responsibilities.
- 38. SaaS/cloud vendor shared responsibility model documented. Evidence: shared responsibility matrix per cloud vendor.
- 39. Supplier performance monitored periodically. Evidence: supplier scorecard or performance review records.
- 40. Supplier change notifications received and assessed. Evidence: notification log with impact assessments for recent changes.
supplier qualification and cloud & SaaS validation services cover items 35–40, including the shared responsibility model documentation that cloud and SaaS deployments require.
Domains 7 and 8: Deviation/CAPA management and documentation control
- 41–45: Deviations. All deviations documented within defined timeframe. Root cause investigation performed for major deviations. CAPA assigned, tracked, and verified for effectiveness. Repeat deviations trigger trend analysis. CAPA closure verified by QA.
- 46–50: Documentation. All GxP documents version-controlled. Obsolete documents removed from point of use. Document review cycle defined and followed. Distribution controlled and acknowledged. Retention periods defined and enforced.
- 51–55: Facilities and equipment. Equipment qualification current (IQ/OQ/PQ). Calibration programme in place with defined schedules. Preventive maintenance programme documented. Environmental monitoring where required. Cleaning validation current.
- 56–60: Management review. Annual product quality review performed. Management review of quality system conducted. KPIs defined and tracked. Internal audit programme in place with trained auditors. Regulatory intelligence programme monitors guidance changes.
This checklist is not exhaustive — individual regulatory submissions, clinical operations, and manufacturing processes carry additional requirements. But these 60 items represent the core compliance posture that every GxP organisation must maintain. Run the checklist quarterly. Close gaps within 30 days. Track closure rates as a leading indicator of inspection readiness. audit readiness provides the mock-audit protocol that tests these items under realistic inspection conditions.
Where to go next
Explore GxP Copilot for AI-native validation, TraceDraft for source-traceable clinical documentation, or book a demo to see either on your own data.
