· ACCESS CONTROL

Identity & Access Management in GxP Systems

Attributable is the first attribute of ALCOA, and it is not a documentation property — it is an access-control property. A record is attributable only if the system can establish which individual performed the action, which requires that identities are unique, that authority is checked before an action is permitted, and that the ability to alter the record or its audit trail is held separately from the ability to create it. Every data-integrity finding involving a shared login is, underneath, an identity-management failure.

What an explainer is not

A topic explainer is SPEQ’s synthesis of what a practice involves, cited to the standards that govern it. It does not reproduce their text, and it does not determine which of them apply to your product or process.

[ POSITION IN THE FRAMEWORK ]

7 DIMENSIONS · 27 LINKS

Attributability is the foundation every other GxP record control rests on. One shared account does not weaken it — it removes it, and takes the audit trail’s meaning with it.

06 · QUALITY MATURITY — IDENTITY & ACCESS MANAGEMENT IN GXP SYSTEMS, REACTIVE TO ADAPTIVE

L1
Reactive

Accounts are created on request and removed when someone remembers. Generic logins exist on instruments because it is easier.

L2
Defined

Accounts are individual on the main systems and roles are defined, but leavers linger and privileged access has no separate treatment.

L3
Controlled

Joiner, mover and leaver are one controlled process tied to the HR record, privileged access is separated and time-bound, and periodic review reconciles entitlements against role.

L4
Predictive

Reviews look at what access was used rather than only what was granted, so dormant and excessive entitlement is removed rather than re-approved.

L5
Adaptive

Access is granted by role from a single source of identity, expires by default, and an exception is a recorded decision rather than an accumulation.

SPEQ’s shared five-stage progression, labelled synthesis — not the FDA QMM rating scale. Where does your organization sit? Score your quality system →

07 · REGULATORY & EVIDENCE

GOVERNING STANDARDS · 6

Derived from the 6 standards SPEQ maps to this subject, across 6 regulatory bodies: FDA, EMA, MHRA, PIC/S, ISO, IEC.

RECORDS & OBJECTIVE EVIDENCE

  • The user list per GxP system, reconciled against current personnel
  • Joiner, mover and leaver records showing timeliness of removal
  • Privileged and administrative account inventory, with justification for each
  • Periodic access review records, with what was revoked as a result
  • The role-to-entitlement definition each grant is made against

COMMON INSPECTION FINDINGS

  • Shared or generic accounts on systems producing regulated records
  • Leavers retaining active access after departure
  • Administrators able to alter regulated data and the audit trail that records it
  • Access reviews that re-approve every entitlement with nothing ever removed
  • Entitlement accumulating as people change role, because moves are treated as additions
EVERY CHIP IS A DOOR · WALK THE FRAMEWORK FROM ANY SUBJECTHow SPEQ maps the framework →

Attributability depends on identity, not on signatures

Shared accounts are the most consistently cited data-integrity deficiency across GMP and GLP inspections, and the reason is structural rather than procedural. A logbook next to the terminal recording who used the shared "Analyst" account is a compensating control at best: it records an intention, while the system records the action, and the two can be reconciled only by trusting the logbook. When they disagree, there is no way to establish which is correct, so every record produced through that account is weakened at once.

The same logic reaches standalone instruments, which is where the problem is usually worst. A balance, a pH meter or a bench-top instrument with a single local account and no user management is not a small exception to the identity model; it is a system whose records cannot be attributed, and the assessment should say so. The proportionate answers are known — connect it to a managed system, replace it, or restrict and document its use to non-GxP work — but they all start from recognising it as an integrity gap rather than an inconvenience.

What the rules actually require

21 CFR Part 11 requires limiting system access to authorised individuals under §11.10(d), and authority checks under §11.10(g) ensuring that only authorised individuals can use the system, sign electronically, access an input or output device, alter a record, or perform the operation at hand. Where identification codes and passwords are used, §11.300 adds maintaining their uniqueness, periodic checking, recall or revision, procedures for loss management, and transaction safeguards that detect and report attempted unauthorised use to the security unit.

EU GMP Annex 11 states the same outcomes in fewer words: physical or logical controls restricting access to authorised persons; recording the creation, change and cancellation of access authorisations; and systems designed to record the identity of operators entering, changing, confirming or deleting data, with date and time. The MHRA data-integrity guidance and PIC/S PI 041 add the practitioner detail regulators actually look for — that access rights match documented roles, that administrator rights are restricted, and that the assignment is reviewed rather than set once.

Segregation of duties and the administrator problem

The controlling principle is that the person who generates data should not be able to alter the record of how it was generated. In practice this means system-administration rights — the ability to change audit-trail configuration, adjust the system clock, delete data, or create and modify user accounts — must sit outside the function producing the data. An analyst who is also the local administrator of the chromatography data system can, in principle, produce a result and remove the evidence of how it was produced, and an inspector reading the access matrix will see that immediately.

The common objection is resourcing: a small laboratory has one person who understands the software. That is a real constraint and it has real answers — administration performed by IT or quality with the laboratory raising requests, an approval step for privileged actions, independent review of the administrator’s own audit trail — but "there is only one of us" is not one of them, because the control being described is not a preference. It is what makes the record trustworthy.

Privileged access, break-glass, and third parties

Standing administrator rights are the highest-value target in any environment and the hardest to justify, because the need for them is intermittent while the exposure is continuous. The direction of travel is to grant privilege for a session against a recorded reason and withdraw it automatically, and to log privileged sessions in a way the privileged user cannot alter. Emergency or break-glass access follows the same logic: an account that exists, is documented, is monitored, and generates a review every time it is used.

Vendor and third-party access is the version of this that regulated sites most often get wrong, because it is arranged during commissioning and then forgotten. IEC 62443-2-1 expects remote and third-party access to control systems to be granted per session rather than held as a standing connection, and the same expectation is reasonable for any GxP system. The failure mode is specific and common: a permanent remote-support tunnel, opened years ago for a validation issue, still terminating inside the manufacturing network with credentials nobody at the site controls.

Periodic review is the evidence, not the policy

Access management degrades along one axis: people move. Joiners are handled well because someone is waiting for the account. Movers are handled badly, because a transfer usually adds rights without removing the old ones, and after several moves an individual holds a combination nobody ever approved. Leavers are handled inconsistently, and a dormant account with live credentials is a standing exposure with no owner.

Periodic access review is the control that catches all three, and it is the artefact an inspector asks for, because it demonstrates the policy operated rather than existed. A review that is worth performing compares actual entitlements against documented role definitions and current training records, is signed by someone who knows what the role should be able to do rather than by IT, and produces removals. A review that returns no changes across a whole site over a year is not evidence of good hygiene; it is evidence the review was not performed properly.

SPEQ’s view is that access review should be scoped by GxP impact rather than by system ownership. Reviews organised around who administers a system leave the highest-risk assets — standalone instruments, control-system engineering stations, laboratory workstations with local accounts — outside every cycle, because no central team owns them. Scoping by impact puts them first.

FREQUENTLY ASKED

Are shared logins ever acceptable in a GxP system?

Not for any action that has to be attributable — data entry, review, approval, or configuration change. A shared read-only account on a display terminal that cannot alter anything is a different case and can be justified by risk assessment. Where a legacy system genuinely cannot support unique users, the position to document is that it is an integrity gap with defined compensating controls and a remediation plan, not that it is compliant.

Is multi-factor authentication required for GxP systems?

No regulation requires it by name. What the rules require is that access is limited to authorised individuals and that credentials are protected against unauthorised use, and MFA is now the ordinary way to achieve that for anything reachable from outside the local network. The defensible approach is risk-based: MFA for remote access, administrative access and internet-facing systems, with the rationale recorded rather than the control assumed.

How often should user access be reviewed?

There is no prescribed frequency. Common practice is at least annually for GxP systems and more often — quarterly or semi-annually — for systems with high data-integrity impact or large privileged populations, with an event-driven review on any organisational change. Frequency matters less than whether the review compares entitlements against current role definitions and actually produces removals.

Does an electronic signature need to be a biometric?

No. Part 11 permits electronic signatures based on biometrics or on identification code and password combinations. Non-biometric signatures carry additional obligations: they must use at least two distinct identification components, and for a series of signings in a single continuous session the full set is required for the first signing with at least one component for subsequent ones.

Who should hold system administrator rights on a laboratory system?

Someone outside the function that generates the data — typically IT or a quality-systems group — so that the ability to alter audit-trail configuration or delete records is separated from the ability to produce results. Where that separation is not practical, the compensating controls are an approval step for privileged actions and independent review of the administrator’s own audit trail.

PROFESSIONAL · INSPECTION PLAYBOOK · SPEQ SYNTHESIS

The inspection-readiness playbook for this topic

CHECKING ACCESS

Checking your Professional access…