Ask four questions
- What process does the system support?
- What does the system actually do?
- What records or decisions depend on it?
- What could happen if it does not work correctly?
Start with the use, not the product name
These are fictional examples. The same software can have different scope in different organizations.
| Use | GxP consideration |
|---|---|
| MES controls production steps and records execution | Assess the process controls and production records relied on for product quality |
| eQMS manages nonconformances and CAPA approval | Assess the quality decisions, approval workflows and retained records |
| Training system determines qualification for a regulated task | Assess qualification rules, training status and any work-access control |
| Jira used only for general project scheduling | May be outside GxP scope if no regulated activity, decision or required record relies on it |
| Spreadsheet calculates product acceptance criteria | Assess the formula, data, limits and consequence of an incorrect acceptance decision |
Record the conclusion
State the process, functions and records in scope, why they matter, and who confirmed the assessment. If the use is unclear, keep the question open. A Jira project that retains controlled validation records has a different scope from a general project schedule: assess record integrity, access, review and retention for that use. GxP relevance establishes scope; the risk of individual functions determines the assurance effort.
Practitioner guidance by Sandip Thorat · Simplified 17 September 2026. Apply the requirements and approved procedures relevant to your system. Report a correction.