What is a periodic review of a computerized system?
A periodic review is a documented, risk-based evaluation confirming a computerized system remains in a validated state and compliant with GMP, required under EU GMP Annex 11 Section 11. It checks validation status, deviations since the last review, change history, access control, audit trail review completion, and backup evidence — not just whether the system still runs.
Most periodic reviews are a signature confirming the system is "still validated" — with nobody having actually checked anything since the last one. The draft Annex 11 revision is about to make that a lot harder to get away with.
What Annex 11 Actually Requires — Today
EU GMP Annex 11, Section 11, states that computerized systems should be periodically evaluated to confirm they remain in a valid state and compliant with GMP, covering functionality, deviation and incident records, upgrade history, performance, reliability, security, and validation status. Notably, the currently effective 2011 text does not prescribe a fixed frequency — it's left to a risk-based justification set by the company's quality function, one you need to be able to defend to an inspector on request.
The 2026 Shift: Fixed Review Cadences Are Coming
In July 2025, the European Commission and PIC/S published a draft revision of Annex 11 (alongside a new Annex 22 on AI) that proposes something the current text doesn't: explicit review frequencies — monthly for high-risk systems, quarterly for routine systems — plus expanded audit trail scope and dedicated cybersecurity and access management sections. A final version is expected in 2026. As of this writing, the 2011 text remains legally in force, so these specific cadences aren't yet mandatory — but they're the clearest signal available of where enforcement is heading, and risk-based judgment today should account for it.
The Periodic Review Checklist
- ✓Validation status confirmed current — the system's validated state matches its actual configuration, not the configuration at initial qualification.
- ✓Deviations and incidents since the last review are logged, investigated, and closed, with no open items carried silently forward.
- ✓Change control history reviewed — every change since the last review was assessed for GxP impact and properly documented.
- ✓Access list reviewed — current users match current roles, with no stale accounts or unresolved access exceptions.
- ✓Audit trail review confirmed as actually performed, not just enabled — with evidence the reviews happened on schedule.
- ✓Backup and disaster recovery evidence current — a successful restore test, not just a backup log showing jobs ran.
- ✓Supplier and vendor oversight status checked beyond a certificate on file — confirm the quality agreement and change-notification process are still active.
- ✓SOPs and training records current against how the system is actually operated today, not how it was described at go-live.
Setting Review Frequency by Risk
| System Risk Tier | Typical Frequency Today | Draft Annex 11 Direction |
|---|---|---|
| High-risk / GxP-critical | Annual, or tighter based on risk assessment | Monthly |
| Routine / moderate risk | 12–18 months | Quarterly |
| Low risk / limited GxP impact | 18–24 months | Not explicitly addressed in the draft |
The failure mode to watch for: the most common periodic review problem isn't a missed deadline — it's a review that happened on schedule but checked nothing substantive, because it was treated as an IT housekeeping task rather than a quality-owned compliance activity. Regulators expect the quality function and senior management to be accountable for the outcome, even though IT typically supplies the technical evidence behind it.
How GoVal Supports Periodic Review
GoVal schedules periodic review systematically based on each system's GAMP 5 risk classification, rather than relying on a spreadsheet of due dates someone has to remember to check. Change control history, deviations, access records, and audit trail review status are pulled into one review record, so the review reflects an actual current-state check rather than a signature on a template. Every completed review is captured as a timestamped, audit-trailed record — the evidence an inspector, and the draft Annex 11 revision, will both expect to see.
Related Topics
Frequently Asked Questions
What is a periodic review of a computerized system? +
How often should computerized systems be reviewed under GxP? +
What does EU Annex 11 require for periodic review? +
Is a vendor's SOC 2 or ISO 27001 certificate enough for periodic review of a cloud system? +
What's changing in the 2025/2026 Annex 11 revision for periodic review? +
Who is responsible for periodic review of a computerized system — IT or Quality? +
How does GoVal support periodic review of computerized systems? +
Make every periodic review a real check, not a signature
Risk-tiered review scheduling, change history, and audit-trailed review records — in GoVal.
