# User Access Review

Version 1.0 | CSVtoCSA practitioner template | Updated 12 September 2026

## Purpose

Evaluate current user and service-account access against approved GxP roles, responsibilities, least privilege, and segregation of duties.

## When to use

At the approved frequency and after role, employment, system, process, or access-model change.

## Instructions

- Define the specific system, service, change, population, and intended use.
- Complete each field from available records and accountable interviews; record unknowns rather than guessing.
- Link conclusions to affected GxP functions, failure scenarios, controls, evidence, and approval.
- Adapt the structure to the organization’s approved procedures and document-control process.

## Blank template

1. System and review period

   Response: 

2. Approved GxP and privileged roles

   Response: 

3. User or service account

   Response: 

4. Current job responsibility and owner

   Response: 

5. Assigned access

   Response: 

6. Access appropriate

   Response: 

7. Segregation of duties

   Response: 

8. Inactive or terminated status

   Response: 

9. Exception and expiry

   Response: 

10. Action and completion evidence

   Response: 

11. Reviewer and approver

   Response: 

12. Conclusion and next review

   Response: 

## Completed fictional example

The example below is teaching material, not an executed or approved validation record.

1. System and review period

   Fictional eQMS; annual review

2. Approved GxP and privileged roles

   Investigator, Quality approver, administrator, read only

3. User or service account

   Former Quality reviewer now IT support

4. Current job responsibility and owner

   Application support; IT manager

5. Assigned access

   Quality approver and administrator

6. Access appropriate

   No; approval is not required for support

7. Segregation of duties

   Approval plus administration creates conflict

8. Inactive or terminated status

   Active employee; employment alone does not justify role

9. Exception and expiry

   Temporary support exception expires in five days

10. Action and completion evidence

   Approval removed; ticket-based elevation retained; activity reviewed

11. Reviewer and approver

   Process owner and Quality approval

12. Conclusion and next review

   Appropriate after removal; next scheduled or role-change review

## Use and limitations

Adapt this template to the applicable regulation, approved validation procedure, document-control process, risk method, and approval roles. CSVtoCSA does not present this template as a universally required validation record.
