Lifecycle · Practitioner guidance

Periodic Review of a Validated System

Use accumulated operational evidence to determine whether the approved intended use, configuration, controls, and validation evidence remain current.

Author
Sandip Thorat
Published
12 September 2026
Last reviewed
12 September 2026
Version
1.0
Content type
Practitioner guidance
Primary references
2 linked sources in this guide

Review scope

Confirm the approved intended use, system and service version, configuration, owner, validation baseline, review period, and prior commitments. Review changes, supplier releases, incidents and problems, validation deviations, corrective and preventive actions, open actions, user access, supplier status, backup and restore, disaster recovery, performance and availability, new or changed interfaces, new uses, and applicable regulatory or procedure changes.

Evidence-based conclusion

The conclusion should explain why the evidence supports continued use, conditional use, remediation, revalidation, restriction, or retirement. Avoid a checkbox or unsupported statement such as “validated state maintained.” Identify unresolved risks, accountable actions, target dates, monitoring, and the next scheduled or event-driven review.

Completed fictional review

An annual review of a LIMS-to-ERP interface identifies two approved mapping additions, one delayed-message incident, a supplier middleware update, an access review with one overdue service-account owner confirmation, a successful queue recovery, and no incorrect material disposition. Reconciliation monitoring shows no unexplained variance.

Continued use is supported because the intended use and failure controls remain unchanged and the mapping changes have approved targeted regression. The overdue service-account confirmation is recorded as an action with restricted credentials and a due date. The next review is scheduled in twelve months or earlier after schema, mapping, identity, reconciliation, or serious-incident change.

Regulatory and procedural context

Primary sources. EU GMP Annex 11 includes periodic evaluation for applicable GMP computerized systems. FDA CSA guidance supports risk-based assurance across software use and change.

Company procedure. The organization’s approved validation, change-control, supplier-management, information-security, data-integrity, records-retention, and Quality approval procedures determine the required records, roles, and approval route.

CSVtoCSA practitioner interpretation. Periodic review should test whether the assumptions supporting the validation conclusion remain true using current operating evidence. This is a recommended validation approach, not a statement that every listed activity is a direct regulatory requirement.