Prepare the review population
Identify the system, approved GxP roles, privileged roles, current users, current job responsibilities, assigned access, inactive or terminated users, service accounts, shared or emergency accounts, exceptions, owners, and approvers. Reconcile application access with authoritative identity and role information without assuming employment status proves appropriateness.
Review questions
For each account, ask whether access is required, least privilege is maintained, approval and execution duties remain appropriately separated, privileged access is justified and monitored, service-account ownership and credentials are controlled, and prior exceptions have expired or remain approved.
Completed fictional example
A former Quality reviewer moves to information-technology support and remains employed. The application report shows that the user retains CAPA approval, record-administration, and production-support roles. Current employment confirms identity status but not business need or segregation of duties.
The process owner removes CAPA approval, retains time-limited support access, requires ticket-based elevation for administration, and reviews activity during the overlap period. The exception and removal evidence are attached to the access-review record before Quality approval.
Regulatory and procedural context
Primary sources. 21 CFR Part 11 ↗ includes limiting system access to authorized individuals and authority checks for records and signatures within scope. EU GMP Annex 11 ↗ addresses security and access for applicable GMP systems.
Company procedure. The organization’s approved validation, change-control, supplier-management, information-security, data-integrity, records-retention, and Quality approval procedures determine the required records, roles, and approval route.
CSVtoCSA practitioner interpretation. Access review should test authorization against current responsibility and controlled process design, not merely confirm that the account belongs to an active employee. This is a recommended validation approach, not a statement that every listed activity is a direct regulatory requirement.