Data Integrity self-check

Data Integrity self-check: twelve questions on one system

Pick one GxP system. Answer honestly. The page scores locally in your browser; nothing is sent anywhere. Each question names the clause it comes from.

1. Is the audit trail enabled for all GMP-relevant data on this system, and is the reason for a change or deletion captured?

(21 CFR 11.10(e); Annex 11 §9)

2. Is there an approved SOP for audit trail review that names the risk basis, frequency and reviewer?

(Annex 11 §9; MHRA 2018 §6.15)

3. Is the last audit trail review on record with a signed, dated positive statement of the outcome?

(MHRA 2018 §6.15)

4. Does every user have an individual account, with roles that prevent a person from editing data they also review?

(Annex 11 §12; 21 CFR 11.10(d))

5. Are administrator rights held only by people who do not enter or review GMP data?

(Annex 11 §12.1)

6. Are electronic signatures linked to the record, time-stamped, and applied after re-authentication?

(Annex 11 §14; 21 CFR 11.50, 11.70)

7. Are backups performed, and has a restore been tested and recorded in the last year?

(Annex 11 §7.2)

8. Is every spreadsheet used for a GMP decision listed in the system inventory with a validation record?

(Annex 11 §1, §4)

9. Has a periodic evaluation of this system been done on schedule, covering changes, incidents and access?

(Annex 11 §11)

10. Is there a formal agreement with the supplier or cloud provider that covers data ownership, exit and support?

(Annex 11 §3.1)

11. Is the data retention period defined, and can archived data still be retrieved and read?

(Annex 11 §7.1, §17)

12. Have data reviewers been trained on what an audit trail anomaly looks like, with a training record?

(Annex 11 §2)

Answer all 12 questions to see your result. 0 of 12 answered.