GxP Evidence Types

Evidence is where the chain lands. Each record here is shown with the controls that produce it, so a claim that an obligation is met can be followed to the thing that proves it.

23 evidence types in library
EVD-REQUIREMENTS-AND-DESIGN-SPECIFICATION

Requirements and design specification set

The approved statement of what the system must do and how it is built to do it — the baseline every test, change and periodic review is judged against.

IS PRODUCED BY
1 control
EVD-ACCESS-REVIEW-RECORD

Periodic access review record

The dated, signed record of a review comparing granted access against current roles, including the removals and corrections it triggered.

IS PRODUCED BY
1 control
EVD-AUDIT-TRAIL-REVIEW-RECORD

Audit trail review record

The record showing that audit-trail entries were reviewed by a competent person, what was examined, and how anomalies were dispositioned.

IS PRODUCED BY
1 control
EVD-AUDIT-TRAIL-CONFIGURATION-RECORD

Audit trail configuration record

Documented proof of the audit-trail settings in force — that it is enabled, captures the required attributes, and cannot be disabled or edited by users.

IS PRODUCED BY
1 control
EVD-TRAINING-RECORD

Training and qualification record

The per-person record of the education, training and experience qualifying someone for their regulated tasks, current as of the date they performed them.

IS PRODUCED BY
1 control
EVD-CHANGE-CONTROL-RECORD

Change control record

The approved record of a proposed change: its assessment, the regression or revalidation performed, the approvals obtained, and the closure evidence.

IS PRODUCED BY
1 control
EVD-CONFIGURATION-BASELINE

Configuration baseline and system inventory entry

The recorded configuration and version of the system as released, plus its entry in the inventory of regulated systems — the reference an unplanned change is detected against.

IS PRODUCED BY
8 controls
EVD-PERIODIC-REVIEW-REPORT

Periodic system review report

The dated evaluation confirming a system remains in its validated state, drawing on change, incident, access and audit-trail history since the last review.

IS PRODUCED BY
1 control
EVD-BACKUP-RESTORE-TEST-RECORD

Backup and restore test record

Evidence that backed-up data was actually restored and found complete and accurate — the only proof a backup regime works, as distinct from proof that it ran.

IS PRODUCED BY
1 control
EVD-SUPPLIER-ASSESSMENT-REPORT

Supplier assessment or audit report

The documented evaluation of a supplier or service provider against the quality obligations placed on it, with the agreement or corrective actions that followed.

IS PRODUCED BY
1 control
EVD-RISK-ASSESSMENT-RECORD

System risk assessment record

The documented assessment of patient safety, data integrity and product quality risk for a system, and the justification for the resulting validation and control effort.

IS PRODUCED BY
1 control
EVD-INCIDENT-RECORD

Incident or deviation record

The record of a system failure or data anomaly: what happened, the impact assessed on product and data, the root cause, and the actions closed out against it.

IS PRODUCED BY
1 control
EVD-SIGNATURE-POLICY-ATTESTATION

Signature accountability policy and attestation

The written policy holding individuals accountable for actions taken under their electronic signature, together with each signatory’s acknowledgement of it.

IS PRODUCED BY
1 control
EVD-SIGNATURE-CERTIFICATION-LETTER

Electronic signature certification letter

The certification submitted to the agency stating that electronic signatures used in the organisation are the legally binding equivalent of handwritten signatures.

IS PRODUCED BY
1 control
EVD-INTERFACE-VERIFICATION-RECORD

Data interface verification record

Evidence that data crossing a system boundary was verified as complete and accurate — the built-in checks configured, and the result of exercising them.

IS PRODUCED BY
1 control
EVD-SECOND-PERSON-VERIFICATION-RECORD

Second-person verification record

The record of a critical manually entered value being independently checked, or of the validated system check that was justified in its place.

IS PRODUCED BY
1 control
EVD-CREDENTIAL-MANAGEMENT-RECORD

Credential management record

Evidence that identification codes and passwords are unique, periodically revised, and that loss, compromise or device deauthorisation is handled by a defined procedure.

IS PRODUCED BY
1 control
EVD-BUSINESS-CONTINUITY-TEST-RECORD

Business continuity arrangement and test record

The documented alternative arrangement for continuing a critical process during system unavailability, and evidence that it was exercised and found workable.

IS PRODUCED BY
1 control
EVD-BATCH-RELEASE-RECORD

Certified batch release record

The record showing that batch certification and release was performed by the authorised person, identifying who released the batch and on what basis.

IS PRODUCED BY
1 control
COMPLETE INDEX — ALL 23 EVIDENCE TYPE
WHAT IS FACT AND WHAT IS SPEQ’S READING

The requirement statements are faithful restatements of the regulations they cite, each carrying its clause and source. The controls, risks, evidence types and processes — and every line drawn from an obligation to a control — are SPEQ synthesis: a practitioner’s reading of how an obligation is customarily discharged. No regulator publishes this mapping. 21 CFR 11.10(d) requires that system access be limited to authorised individuals; it does not say “run a quarterly access review”. That inference is what SPEQ adds, and it is labelled rather than presented in a regulator’s voice.