Ready to fix validation chaos? Book Review
Business Continuity

Backup and Restore for GxP Systems: The Test Is the Restore

A backup job is not proof of recoverability

Computerised-system controls must address data storage, security, incident management, and business continuity. These themes appear in EU GMP Annex 11 and in MHRA data-integrity guidance. The operational test is simple but often neglected: can the organisation restore the records and functionality it needs, within a timeframe the process can tolerate, and verify that the result is complete and trustworthy?

Define what must be recovered

List applications, databases, files, configuration, keys, integrations, audit trails, attachments, reports, and procedures. Classify what is essential for patient, product, trial, release, or regulatory decisions. Recovery scope should include the dependencies that make the system usable, not just the largest database.

A controlled recovery model

  1. Set retention, frequency, protection, and access requirements from process risk and record obligations.
  2. Separate backup administration from ordinary user access where appropriate.
  3. Protect copies from accidental deletion, unauthorised alteration, and the same failure that affects production.
  4. Document restoration prerequisites, owners, sequence, and acceptance criteria.
  5. Perform restoration tests using representative data or a controlled copy.
  6. Check completeness, integrity, timestamps, relationships, audit history, access, and critical reports.
  7. Record failures, corrective actions, retest results, and the decision about continued use.
  8. Update the plan after system, infrastructure, supplier, or process changes.

Do not forget the human path

Continuity depends on people and decisions as well as technology. Define who declares an incident, who approves a workaround, how manual records are controlled, how reconciliation occurs after recovery, and when normal processing resumes. A technically successful restore can still leave the process in an uncontrolled state if the handoff is unclear.

Connect backup and recovery evidence to the system’s validation lifecycle, periodic review, incident management, and supplier controls. If the restore has never been tested, describe it as an assumption, not as a control.

Prove that critical records can come back

Start with the system, process, and evidence questions that matter to your team.

Talk with VLMS about your validation programme →