What the assessment covers
The workbook has three tabs. An Instructions tab explains the scoring, the four-line test for working file versus system of record, and the clauses each break maps to. The Scoring tab is the matrix: seven rows, one per break, each with what to look for and where it sits in the regulations, and four columns for the workbooks under assessment — score each break 0 (the control exists and is evidenced), 1 (informal or partly in place) or 2 (absent). The total fills itself; the row beneath it asks what the file is for; the verdict row reads both and tells you whether the file is acceptable as it stands. The Inventory tab is the register: one row per workbook that holds GxP data, with what it holds, the decision made from it, its role, its total, the action, an owner and a date.
- The unofficial copy is where the truth was — is this file the first capture, with an "official" form transcribed from it?
- The formula is the method — specified, tested across its range, protected, and the check recorded?
- Anyone who can open it can change the logic — who can edit, and can a paste-over silently replace a formula?
- Version history is a filename; approval lives in the inbox; training, change and the tracker don't share a story
- There is no trail to review — file-level "last modified" and Track Changes are not a computer-generated, cell-level audit trail
How to use it
List the workbooks first. The Inventory tab wants a row for every file that still holds GxP data — the stability tracker, the training matrix, the deviation log, the assay calculation — with its owner, what it holds and what decision is made from it. Then take them four at a time onto the Scoring tab and score each break from the dropdown. Scores are evidence-based: 0 only where the control can be shown, not where someone believes it exists.
The decision row is the post's own distinction. A working file is a calculation you can reconstruct from the raw data, a personal analysis discarded after the decision, a one-off extract from a governed system — one author, short life, nobody else depends on it. A system of record is where current status lives, what people approve against, what an inspector is handed — shared and enduring. Excel is excellent at the first column. A system of record scoring above zero is not acceptable as it stands: migrate it to a governed system, or apply compensating controls with QA approval and a date to revisit. Carry the total, the role and the action back to the Inventory tab. Pair it with the data integrity (ALCOA+) checklist for the system you migrate to, and the audit trail review checklist once there is a trail to review.
How an inspector reads this
An inspector does not ask whether you use Excel. They pick a result that supported a quality decision and ask where the number came from, who could have changed the formula, which version was in force on the date, who approved it, and where the trail is. §211.68(b) already describes the unlocked formula cell — changes only by authorised personnel, input and output checked for accuracy — without waiting for Part 11; §211.194(a)(5) wants a record of the calculations and (a)(8) a second person's review; §11.10(e) wants a secure, computer-generated, time-stamped audit trail when the workbook is the electronic record; Annex 11 clause 9 wants GMP-relevant changes and deletions recorded with reasons and reviewed; the MHRA guide says electronic worksheets are version controlled and data transferred into them is not altered and carries a trail of the transfer. FDA warning letters have cited unvalidated spreadsheets used to calculate assay results and cell formulas that produced impossible values.
A file that opens and calculates can fail every row of this sheet. The cost of "free" arrives as QA labour — reconstructing which version was in force, chasing the approval email, joining three lists by hand — and it arrives during the inspection. The scoring is there to find it before then.




