Compliance
My Calibration Register Is Just a Spreadsheet. Does It Really Need Validation?
A calibration register that only tracks equipment IDs, dates, and certificate references is a different risk to a spreadsheet that calculates pass or fail. A practical, risk-based look at what validation it may actually need.
"It's just a spreadsheet" is one of the most common phrases heard when discussing calibration registers in GMP facilities. Usually it is true, in the sense that the file does not calculate anything or make a GMP decision. It simply records what has already happened.
That does not mean the register is automatically outside the scope of validation thinking. It means the validation approach can be proportionate to what the spreadsheet actually does.
This article is a practical interpretation of a common register scenario. It is not a validation protocol or a determination that any specific spreadsheet is compliant. Your organisation's own risk assessment, quality system, and the applicable regulatory expectations remain the controlling references.
The scenario
A typical calibration register spreadsheet contains:
- Equipment ID
- Last calibration date
- Next due date
- Certificate reference
- Equipment location
- Comments
There are no GMP calculations. There is no decision-making logic. The spreadsheet is a structured list, what we describe in our maturity model for GMP spreadsheets as a register spreadsheet, the first and lowest-risk level.
What inspectors tend to focus on
Regardless of whether a register is a spreadsheet or a formal system, the underlying data integrity expectations are the same. An inspector reviewing a calibration register is typically interested in:
- Data integrity. Can the organisation show the record has not been altered inappropriately?
- Accuracy. Do the dates and references in the register match the underlying certificates?
- Traceability. Can a specific piece of equipment be traced to its calibration history and supporting certificate?
- Evidence. Is there something to show, beyond "we've always done it this way," that the register is maintained and reviewed?
None of these questions require the register to have been through a full software validation lifecycle. They do require the organisation to be able to answer them with more than an assumption.
Common risks in a register like this
Even a simple register carries recognisable risks:
- Manual transcription errors, where a date or reference is typed incorrectly when copying from a certificate.
- Missing calibration certificates, where the register shows a date but the supporting document cannot be located.
- Formula corruption, if a due-date calculation (
= [Last calibration date] + 365, for example) is accidentally overwritten in a cell. - Poor version control, with several copies of the register circulating across email or shared drives, each slightly out of date.
What validation evidence may be needed
For a register at this level, a pragmatic, risk-based approach is usually more appropriate than a full software validation lifecycle. Evidence that is commonly useful includes:
- Intended use: a short statement of what the register is used for, and what it is not used for (for example, it does not calculate pass/fail status).
- Risk assessment: an assessment of what could go wrong (missing certificate, wrong date, overwritten formula) and how likely and significant that is.
- Formula verification: where any calculation exists (even a simple due-date formula), a check that it produces the expected result.
- Change control: a record of how the register's structure, formulas, or fields are changed and by whom.
- Validation report or summary: a short document that ties the above together and states the register is fit for its intended use.
When Excel may still be acceptable
Excel is not automatically the wrong tool for a register like this. Where the register:
- only records dates, references, and status information;
- has no formulas that determine equipment fitness for use or product disposition;
- has a small number of controlled editors; and
- is backed by a defined review and certificate-filing process,
a lightweight, proportionate validation approach can often be justified without moving to a new platform. The risk changes materially once the spreadsheet starts calculating anything the organisation relies on to make a GMP decision. That scenario is covered in When Your Spreadsheet Starts Making GMP Decisions.
A proportionate next step
Not sure whether your calibration register requires formal validation, or what level of evidence is enough? A structured Annex 11 spreadsheet assessment can classify the risk and recommend whether the register should be retained with light-touch controls, remediated with formal evidence, or migrated to a governed SharePoint register. See Annex 11 in Plain English for the underlying computerised-systems questions this assessment draws on.
Book a discovery call to talk through your calibration register and the evidence you may already have.