Periodic Review

Periodic review is a planned and documented evaluation ofwhether a computerized system remains fit for its intended use and continues tooperate in a controlled, compliant, and validated state.

Unlike change assessment, which evaluates a specific event,periodic review considers system performance and control effectiveness across adefined review period.

·        Changes and associatedimpact assessments

·        Deviations, incidents,problems, and CAPAs

·        System performance andavailability

·        User and privileged-accessreviews

·        Audit-trail configurationand required reviews

·        Security events andvulnerabilities

·        Backup, restore, andbusiness-continuity controls

·        Supplier performance

·        Current versions andsupport status

·        SOP and training status

·        Interfaces and datatransfers

·        Open actions from reviews,audits, or inspections

·        Continued accuracy ofrequirements, risks, and documentation

The review should conclude whether the system remains fitfor intended use, whether corrective actions are required, and whether anyissue triggers change control or revalidation. Frequency should be defined andjustified based on GxP impact, complexity, change frequency, incident history,data criticality, supplier performance, and ongoing monitoring.

Frequently Asked Questions

How often should periodic review be performed?

The organization should define a risk-based review frequencyin an approved procedure or plan. Higher-risk or frequently changing systemsmay require more frequent review; stable lower-risk systems may be reviewedless frequently where justified.

What is the difference between periodic review and revalidation?

Periodic review is a scheduled evaluation of the system’svalidated state and control environment. Revalidation is the repetition ofselected assurance activities in response to a change, incident, finding, orother trigger.

Who should perform the periodic review?

The system owner or another designated role commonlycoordinates the review. QA provides quality oversight, while IT, informationsecurity, business users, data owners, suppliers, and other specialists providerelevant input.

What evidence should a periodic review produce?

The approved record should identify the review period andscope, information evaluated, issues and trends, assessment of the validatedstate, required actions, owners and target dates, and the final conclusion.

‍