Skip to main content

Periodic Review Checklist for GxP Computerised Systems

Ready to modernize?

See GoVal in Action

Book a 30-minute walkthrough with our validation specialists. No slides — just your questions, answered live.

Contact Us
Summary

A periodic review of a computerized system is a documented, risk-based evaluation confirming the system remains in a validated state and compliant with GMP, required under EU GMP Annex 11 Section 11. The current 2011 version of Annex 11 leaves review frequency to the company's own risk-based justification, but the draft revision published in July 2025 proposes fixed cadences — monthly for high-risk systems, quarterly for routine systems — with a final version expected in 2026; as of this writing, the 2011 text remains in force. A defensible review checks validation status, deviations and incidents since the last review, change control history, access control, audit trail review completion, backup and disaster recovery evidence, and supplier oversight beyond a vendor's certificate. The most common failure is treating periodic review as a signature exercise rather than a substantive check, and treating it as an IT task rather than a quality-owned one. GoVal schedules periodic review systematically by GAMP 5 risk tier and captures every review as a timestamped, audit-trailed record.

What is a periodic review of a computerized system?

A periodic review is a documented, risk-based evaluation confirming a computerized system remains in a validated state and compliant with GMP, required under EU GMP Annex 11 Section 11. It checks validation status, deviations since the last review, change history, access control, audit trail review completion, and backup evidence — not just whether the system still runs.

Most periodic reviews are a signature confirming the system is "still validated" — with nobody having actually checked anything since the last one. The draft Annex 11 revision is about to make that a lot harder to get away with.

What Annex 11 Actually Requires — Today

EU GMP Annex 11, Section 11, states that computerized systems should be periodically evaluated to confirm they remain in a valid state and compliant with GMP, covering functionality, deviation and incident records, upgrade history, performance, reliability, security, and validation status. Notably, the currently effective 2011 text does not prescribe a fixed frequency — it's left to a risk-based justification set by the company's quality function, one you need to be able to defend to an inspector on request.

The 2026 Shift: Fixed Review Cadences Are Coming

In July 2025, the European Commission and PIC/S published a draft revision of Annex 11 (alongside a new Annex 22 on AI) that proposes something the current text doesn't: explicit review frequencies — monthly for high-risk systems, quarterly for routine systems — plus expanded audit trail scope and dedicated cybersecurity and access management sections. A final version is expected in 2026. As of this writing, the 2011 text remains legally in force, so these specific cadences aren't yet mandatory — but they're the clearest signal available of where enforcement is heading, and risk-based judgment today should account for it.

The Periodic Review Checklist

  • Validation status confirmed current — the system's validated state matches its actual configuration, not the configuration at initial qualification.
  • Deviations and incidents since the last review are logged, investigated, and closed, with no open items carried silently forward.
  • Change control history reviewed — every change since the last review was assessed for GxP impact and properly documented.
  • Access list reviewed — current users match current roles, with no stale accounts or unresolved access exceptions.
  • Audit trail review confirmed as actually performed, not just enabled — with evidence the reviews happened on schedule.
  • Backup and disaster recovery evidence current — a successful restore test, not just a backup log showing jobs ran.
  • Supplier and vendor oversight status checked beyond a certificate on file — confirm the quality agreement and change-notification process are still active.
  • SOPs and training records current against how the system is actually operated today, not how it was described at go-live.

Setting Review Frequency by Risk

System Risk TierTypical Frequency TodayDraft Annex 11 Direction
High-risk / GxP-criticalAnnual, or tighter based on risk assessmentMonthly
Routine / moderate risk12–18 monthsQuarterly
Low risk / limited GxP impact18–24 monthsNot explicitly addressed in the draft

The failure mode to watch for: the most common periodic review problem isn't a missed deadline — it's a review that happened on schedule but checked nothing substantive, because it was treated as an IT housekeeping task rather than a quality-owned compliance activity. Regulators expect the quality function and senior management to be accountable for the outcome, even though IT typically supplies the technical evidence behind it.

How GoVal Supports Periodic Review

GoVal schedules periodic review systematically based on each system's GAMP 5 risk classification, rather than relying on a spreadsheet of due dates someone has to remember to check. Change control history, deviations, access records, and audit trail review status are pulled into one review record, so the review reflects an actual current-state check rather than a signature on a template. Every completed review is captured as a timestamped, audit-trailed record — the evidence an inspector, and the draft Annex 11 revision, will both expect to see.

Related Topics

Frequently Asked Questions

What is a periodic review of a computerized system? +
A periodic review is a documented, risk-based evaluation confirming a computerized system remains in a validated state and compliant with GMP, required under EU GMP Annex 11 Section 11. It typically examines validation status, deviations and incidents since the last review, change history, access control, audit trail review completion, backup and business continuity evidence, and current documentation. Unlike an audit trail review, which checks specific data entries, a periodic review evaluates the system's overall compliance posture.
How often should computerized systems be reviewed under GxP? +
The currently effective 2011 EU Annex 11 leaves frequency to a documented, risk-based justification set by the company's quality function, rather than a fixed calendar rule. High-risk, GxP-critical systems generally warrant annual review or tighter; lower-risk systems can extend to 18–24 months. The draft Annex 11 revision proposes explicit cadences — monthly for high-risk systems and quarterly for routine ones — which organizations should start preparing for even before it's finalized.
What does EU Annex 11 require for periodic review? +
Annex 11 Section 11 requires that computerized systems be periodically evaluated to confirm they remain in a valid state and compliant with GMP, covering functionality, deviation and incident records, upgrade history, performance, reliability, security, and validation status. It doesn't prescribe a specific format or fixed frequency in its currently effective 2011 form — the company must define and justify both, and be prepared to defend that justification to an inspector.
Is a vendor's SOC 2 or ISO 27001 certificate enough for periodic review of a cloud system? +
No. A vendor certificate evidences the vendor's security controls, not your system's current validated state, configuration history, or compliance with your intended use. Periodic review still needs to confirm your specific configuration, access list, change history, and audit trail review status — the certificate supports vendor oversight, but doesn't substitute for reviewing the system itself.
What's changing in the 2025/2026 Annex 11 revision for periodic review? +
The draft revision, published by the European Commission and PIC/S in July 2025, proposes fixed periodic review cadences — monthly for high-risk systems and quarterly for routine systems — replacing the current purely risk-based approach, alongside expanded audit trail scope and new cybersecurity and access management sections. A final version is expected in 2026; as of this writing, the 2011 Annex 11 text remains legally in force, but the direction of travel is clear.
Who is responsible for periodic review of a computerized system — IT or Quality? +
Quality, not IT alone. Periodic review is a GMP compliance activity that assesses validated state, deviations, and risk — decisions that sit with the quality function, even though IT typically supplies technical evidence like patch history, backup logs, and access records. Treating periodic review as a purely technical task owned by IT is one of the most common ways organizations miss the procedural and oversight expectations regulators actually check for.
How does GoVal support periodic review of computerized systems? +
GoVal schedules periodic review systematically based on each system's GAMP 5 risk classification, rather than relying on a manually tracked spreadsheet of due dates. It pulls together change control history, deviations, access records, and audit trail review status into one review record, so the review reflects an actual current-state check rather than a signature on a template. Every completed review is captured as a timestamped, audit-trailed record.

Make every periodic review a real check, not a signature

Risk-tiered review scheduling, change history, and audit-trailed review records — in GoVal.

Book a Free Demo →