GxP Controls

Every control here answers a specific clause. Filter by the quality process that performs it or the GxP discipline it bears on, and follow any card through to the risk it reduces or the record it produces.

33 controls in library
CTL-COMPUTERIZED-SYSTEM-VALIDATION

Validate the system for its intended use

Specify what the system must do, verify it against that specification at a depth justified by risk, and release it under an approved validation summary before regulated use begins.

DISCHARGES
  • 21 CFR 11.10(a)Validation of systems
  • EU GMP Annex 11 §4Validation
REDUCES THE RISK OF
IS EVIDENCED BY
CTL-UNIQUE-USER-ACCOUNTS

Give every user a unique, non-shared account

Issue each individual their own account and forbid shared or generic logins, so every entry and change in the system resolves to one named person.

DISCHARGES
  • 21 CFR 11.10(d)Limiting system access
  • 21 CFR 11.300Controls for identification codes and passwords
  • EU GMP Annex 11 §12Security
REDUCES THE RISK OF
IS EVIDENCED BY
CTL-ROLE-BASED-ACCESS-PROVISIONING

Provision access by authorised role

Grant privileges from a defined role model on documented authorisation, and withdraw them when the role changes or the person leaves — not at the individual’s discretion.

DISCHARGES
  • 21 CFR 11.10(d)Limiting system access
  • 21 CFR 11.10(g)Authority checks
  • EU GMP Annex 11 §12Security
  • EU GMP Annex 11 §2Personnel
REDUCES THE RISK OF
IS EVIDENCED BY
CTL-PASSWORD-AND-CREDENTIAL-MANAGEMENT

Manage identification codes and passwords

Keep every identification code and password combination unique to one individual, revise credentials on a defined cycle, and operate a documented procedure for loss, compromise and deauthorisation of tokens or devices.

DISCHARGES
  • 21 CFR 11.300Controls for identification codes and passwords
REDUCES THE RISK OF
IS EVIDENCED BY
CTL-AUDIT-TRAIL-CONFIGURATION

Enable and lock the audit trail

Enable a secure, computer-generated, time-stamped audit trail that records who did what and when without obscuring the previous value, and configure it so users cannot disable or edit it.

DISCHARGES
  • 21 CFR 11.10(e)Secure, computer-generated audit trails
  • EU GMP Annex 11 §9Audit trails
REDUCES THE RISK OF
IS EVIDENCED BY
CTL-AUDIT-TRAIL-REVIEW

Review the audit trail on a defined cycle

Have a competent person review audit-trail entries at a risk-based frequency, record what was examined, and disposition anomalies — an enabled trail nobody reads detects nothing.

DISCHARGES
  • 21 CFR 11.10(e)Secure, computer-generated audit trails
  • EU GMP Annex 11 §9Audit trails
REDUCES THE RISK OF
IS EVIDENCED BY
CTL-RECORD-EXPORT-AND-COPY

Produce accurate and complete copies of records

Provide a means to generate copies of regulated records in both human-readable and electronic form, complete with the metadata and audit trail that make them meaningful, for inspection and for the agency’s own use.

DISCHARGES
  • 21 CFR 11.10(b)Accurate and complete copies
  • EU GMP Annex 11 §8Printouts
REDUCES THE RISK OF
IS EVIDENCED BY
CTL-BACKUP-AND-RESTORE

Back up regulated data and prove the restore works

Back up regulated data on a defined cycle and periodically restore it to confirm the restored data is complete and accurate — a backup that has never been restored is an assumption, not a control.

DISCHARGES
  • 21 CFR 11.10(c)Protection and retrieval of records
  • EU GMP Annex 11 §7Data storage
REDUCES THE RISK OF
IS EVIDENCED BY
CTL-RECORD-RETENTION-AND-ARCHIVE

Retain and archive records for the required period

Protect regulated records so they remain accurate and retrievable throughout the retention period, with archived data secured against loss or alteration for as long as it must be kept.

DISCHARGES
  • 21 CFR 11.10(c)Protection and retrieval of records
  • EU GMP Annex 11 §7Data storage
  • EU GMP Annex 11 §17Archiving
REDUCES THE RISK OF
IS EVIDENCED BY
CTL-ROLE-BASED-TRAINING-AND-QUALIFICATION

Qualify people for the tasks they perform

Establish that everyone who develops, maintains or uses a regulated system has the education, training and experience their specific tasks require, and keep the record current.

DISCHARGES
  • 21 CFR 11.10(i)Personnel education, training, and experience
  • EU GMP Annex 11 §2Personnel
REDUCES THE RISK OF
IS EVIDENCED BY
CTL-SIGNATURE-IDENTITY-VERIFICATION

Verify identity and certify signatures to the agency

Verify the identity of each individual before issuing an electronic signature, keep each signature unique to one person and never reassigned, and certify to the agency that electronic signatures are the legally binding equivalent of handwritten ones.

DISCHARGES
  • 21 CFR 11.100General requirements for electronic signatures
REDUCES THE RISK OF
IS EVIDENCED BY
CTL-SIGNATURE-TWO-COMPONENT-CONTROLS

Enforce the two-component signature controls

Configure non-biometric signatures to use two distinct identification components, require both for a signing executed outside a single continuous session, and ensure a signature can only be used by its genuine owner.

DISCHARGES
  • 21 CFR 11.200Electronic-signature components and controls
REDUCES THE RISK OF
IS EVIDENCED BY
CTL-SIGNATURE-MANIFESTATION

Manifest the signature in readable form

Ensure the signed record displays the signatory’s printed name, the date and time of signing, and the meaning of the signature — review, approval, responsibility or authorship — in the same human-readable form as the record itself.

DISCHARGES
  • 21 CFR 11.50Signature manifestations
  • EU GMP Annex 11 §14Electronic signature
REDUCES THE RISK OF
IS EVIDENCED BY
CTL-SIGNATURE-RECORD-LINKING

Bind the signature to its record

Link each electronic signature to its record so it cannot be excised, copied or transferred to another record to falsify one — the binding, not the credential, is what makes the signature meaningful.

DISCHARGES
  • 21 CFR 11.70Signature/record linking
  • EU GMP Annex 11 §14Electronic signature
REDUCES THE RISK OF
IS EVIDENCED BY
CTL-OPEN-SYSTEM-ENCRYPTION-AND-INTEGRITY

Add open-system controls where access is not controlled

Where the people responsible for the record content do not control system access, add measures such as document encryption and appropriate digital signature standards on top of the closed-system controls, to keep records authentic, intact and confidential from creation to receipt.

DISCHARGES
  • 21 CFR 11.30Controls for open systems
REDUCES THE RISK OF
IS EVIDENCED BY
CTL-CONFIGURATION-AND-INVENTORY-MANAGEMENT

Maintain a configuration baseline and system inventory

Record the released configuration and version of each regulated system and keep an up-to-date inventory of them, so an unplanned change is detectable against a known baseline rather than against memory.

DISCHARGES
  • EU GMP Annex 11 §10Change and configuration management
  • EU GMP Annex 11 §4Validation
REDUCES THE RISK OF
IS EVIDENCED BY
CTL-SUPPLIER-ASSESSMENT-AND-AUDIT

Assess and re-assess suppliers and service providers

Assess the competence and reliability of suppliers and service providers before relying on them, define the quality obligations in a formal agreement, and re-evaluate on a risk-based cycle.

DISCHARGES
  • EU GMP Annex 11 §3Suppliers and service providers
REDUCES THE RISK OF
IS EVIDENCED BY
CTL-INCIDENT-AND-DEVIATION-MANAGEMENT

Report, assess and close out system incidents

Report system failures and data anomalies, assess their impact on product quality and record integrity, investigate root cause, and close the actions out — treating a repeat incident as an ineffective action, not bad luck.

DISCHARGES
  • EU GMP Annex 11 §13Incident management
REDUCES THE RISK OF
IS EVIDENCED BY
CTL-BUSINESS-CONTINUITY-AND-CONTINGENCY

Arrange and exercise continuity for critical systems

Define an alternative arrangement for continuing each critical process during system unavailability, scale it to the consequence of the outage, and exercise it so the arrangement is known to work before it is needed.

DISCHARGES
  • EU GMP Annex 11 §16Business continuity
REDUCES THE RISK OF
IS EVIDENCED BY
CTL-CERTIFIED-BATCH-RELEASE-CONTROL

Restrict batch certification to the authorised person

Where a system is used to certify and release batches, restrict that action to the authorised person and record clearly who released each batch, so release authority is enforced by the system rather than by convention.

DISCHARGES
  • EU GMP Annex 11 §15Batch release
REDUCES THE RISK OF
IS EVIDENCED BY
COMPLETE INDEX — ALL 33 CONTROL
WHAT IS FACT AND WHAT IS SPEQ’S READING

The requirement statements are faithful restatements of the regulations they cite, each carrying its clause and source. The controls, risks, evidence types and processes — and every line drawn from an obligation to a control — are SPEQ synthesis: a practitioner’s reading of how an obligation is customarily discharged. No regulator publishes this mapping. 21 CFR 11.10(d) requires that system access be limited to authorised individuals; it does not say “run a quarterly access review”. That inference is what SPEQ adds, and it is labelled rather than presented in a regulator’s voice.