Insight Brief · CSV · EU Annex 11

Periodic review:
the most skipped step in CSV programmes.

Systems get validated, go live, and then just run. Nobody reviews whether the validated state remains current. EU Annex 11 is explicit about the requirement, and inspectors ask for the records.

Validated systems drift.
Silently, and without incident.

Systems get validated, go live, and then just run. No formal review of whether the validated state remains current. No check on whether user access still reflects actual roles. No examination of the change history. EU Annex 11 is explicit: periodic evaluation is required. Most programmes treat it as optional.

01
Why it is consistently skippedPeriodic review sits in an awkward administrative space: not part of a project, with no natural deadline, generating no obvious deliverable that creates urgency. Initial validation has a go-live milestone. Change control has a change request. Periodic review has a calendar date that is easy to defer.
02
What drift looks like in practiceChanges accumulate, some through formal change control, some informally. User access grows beyond its original scope. The system configuration gradually diverges from the validated configuration in the evidence package. By inspection, the filed documentation no longer describes the system in production.
03
The inspection question that exposes it"Show me the periodic review record for this system for the past 12 months." If that record does not exist, the explanation that the system has been operating without problems is not a substitute. Regulatory frameworks require evidence of active governance, not absence of incidents.

A proportionate annual review
covers five areas.

When performed consistently on a defined schedule, a periodic review need not be a lengthy exercise. A well-structured annual review synthesises inputs from routine governance activity; it does not generate new work from scratch.

01
User access reviewIs the current list of system users appropriate? Do access levels still reflect current roles? Are there accounts that should be deactivated: leavers, contractors, role changes? User access review is both a data integrity control and a security control.
02
Change history reviewWhat changes have been made since the last review? Were all processed through formal change control? Do any informal changes, in aggregate, represent a significant alteration to the validated configuration that requires a formal impact assessment?
03
Incident, deviation and supplier review, plus documented conclusionWhat incidents have been recorded? Is there a systemic pattern? For SaaS systems, has the supplier performed as expected and have supplier-initiated changes been assessed? The review must end with a formal, dated conclusion on the current validated state.

Frequently asked.

Annual is the usual cadence, but does every system need the same frequency?
Risk-based, not uniform
High-change systems, such as SaaS platforms with regular supplier updates or systems supporting batch release, benefit from more frequent review cycles. Stable, low-change systems can sustain an annual cadence proportionately. The review frequency should be documented and justified.
What if periodic review has not been conducted for a period?
Conduct one now and establish the forward schedule
There is no requirement to produce retrospective reviews for periods when none were conducted. Conduct a comprehensive current-state review, document it, identify any issues that have accumulated, and establish the ongoing schedule. The current review is the baseline for future governance.
How long does a periodic review take?
Proportionate to system complexity and change activity
For a stable, low-change system, a thorough periodic review may take two to three hours. For an active SaaS platform with significant change history and multiple user populations, a day is more realistic. The time investment is always significantly less than the remediation effort when an inspector finds the gap.

Facing a similar challenge?
Let's talk directly.

A focused 30-minute call, no sales process, no commitment. A direct conversation about your environment and where the risk actually sits.

Book a Call Now Prefer to write first? Send a question →