· CROSS-CUTTING
CSV

Computerised System Validation

Validation of GxP computerised systems and electronic records.

What this page does not claim

Educational orientation — not a determination of regulatory applicability, compliance, validation scope, or organizational approval.

WHAT IT GOVERNS

Computerised System Validation establishes documented evidence that a GxP computerised system does what it is intended to do and will continue to do so throughout its lifecycle (GAMP 5, FDA 21 CFR Part 11, EU GMP Annex 11). It spans requirements, risk assessment, verification, and ongoing control of the electronic records and signatures the system holds.

WHY IT MATTERS

Nearly every GxP process now runs on software — LIMS, MES, ERP, chromatography data systems, building management. An unvalidated or poorly controlled system puts both product quality and data integrity at risk, and Part 11 / Annex 11 make those systems directly inspectable. CSV is how confidence in the software layer is established and maintained.

KEY FOCUS AREAS

01

The GAMP 5 lifecycle & software categories

A risk- and category-based lifecycle that scales effort to system complexity and novelty, from configurable products to bespoke development.

02

Risk-based verification (CSA)

Computer Software Assurance thinking — focusing testing on the functions whose failure would affect patient safety, product quality, or data integrity, and using critical thinking over rote documentation.

03

Electronic records & signatures

Part 11 / Annex 11 controls — audit trails, access control, and trustworthy electronic signatures — that make electronic records as reliable as paper.

04

Periodic review & change control

Keeping systems in a validated state over time through change control, configuration management, and periodic review across the operational life of the system.

STANDARDS SPEQ DECODES · 16

Open the full library →
21 CFR Part 11FDAHIGH INSPECTION RISK
Electronic Records; Electronic Signatures
EU GMP Annex 11EMAHIGH INSPECTION RISK
Computerised Systems
EU GMP Annex 22EC
Artificial Intelligence
ISPE GAMP 5 (2022)ISPE
Good Practice Guide: Compliant GxP Computerised Systems
IEC 62304:2006+A1:2015IEC
Medical Device Software — Software Life Cycle Processes
IMDRF/SaMD WG/N10IMDRF
Software as a Medical Device (SaMD): Key Definitions
IMDRF/SaMD WG/N12IMDRF
SaMD: Possible Framework for Risk Categorization and Corresponding Considerations
FDA CSA Guidance (2026)FDAHIGH INSPECTION RISK
Computer Software Assurance for Production and Quality Management System Software
IEC 81001-5-1:2021IEC
Health Software and Health IT Systems Safety, Effectiveness and Security — Part 5-1: Security — Activities in the Product Life Cycle
FDA GPSV (2002)FDAHIGH INSPECTION RISK
General Principles of Software Validation
FDA Premarket Cybersecurity (2026)FDAHIGH INSPECTION RISK
Cybersecurity in Medical Devices: Quality Management System Considerations and Content of Premarket Submissions
FDA PCCP for AI-Enabled DSF (2024)FDA
Marketing Submission Recommendations for a Predetermined Change Control Plan for Artificial Intelligence-Enabled Device Software Functions
IEC 82304-1:2016IEC
Health Software — Part 1: General Requirements for Product Safety
IEC 62443-2-1:2024IEC
Security for Industrial Automation and Control Systems — Part 2-1: Security Program Requirements for IACS Asset Owners
IEC 62443-3-3:2013IEC
Industrial Communication Networks — Network and System Security — Part 3-3: System Security Requirements and Security Levels
ICH M8 (eCTD v4.0)ICH
Electronic Common Technical Document (eCTD)

WHAT INSPECTORS LOOK AT

  • System inventory and the validation status of each GxP system
  • Audit trails, access control, and segregation of duties
  • Change and configuration management keeping the system in a validated state
  • Data backup, restore, and business-continuity for GxP data

KEY REGULATORY BODIES

Derived from the 16 standards SPEQ decodes for this discipline.

RELATED DISCIPLINES

SECTORS THAT OPERATE UNDER CSV

TOPIC EXPLAINERS ACROSS THIS DISCIPLINE
39 total
Data Integrity & ALCOA+
ALCOA+, the data lifecycle, and why integrity is the foundation every GxP claim rests on.
Computer System Validation & CSA
GAMP 5, the risk-based lifecycle, Part 11, and the shift from documentation to critical thinking (CSA).
Medical Device Quality System (ISO 13485 / QMSR)
ISO 13485, the FDA QMSR harmonisation with 21 CFR 820, device risk management (ISO 14971), and software (IEC 62304).
Software as a Medical Device (SaMD)
Software that is itself a medical device — the IMDRF definition, IEC 62304 lifecycle, ISO 14971 risk, EU MDR Rule 11, and how AI/ML changes the picture.
EU GMP Annex 11 (2025 Revision)
The draft revision of the EU GMP computerised-systems annex — lifecycle validation, data integrity, cloud, AI, and cybersecurity as a core GMP requirement.
AI/ML Validation in GxP
Validating machine-learning and AI systems in regulated environments — data provenance, model lifecycle, and the static-vs-adaptive distinction.
Correcting GxP Records
How to change a GxP record defensibly — single-line strike-through, reason, initials, date — on paper and in electronic systems.
GAMP 5 Software Categories
The risk-based classification scheme, from GAMP 5, that determines how much validation effort a given piece of GxP software actually needs.
Computer Software Assurance (CSA)
FDA’s 2022 guidance shifting device production and quality-system software assurance from documentation-heavy CSV toward critical-thinking, risk-based testing.
21 CFR Part 11 — Electronic Records and Signatures
The FDA rule setting the criteria under which electronic records and electronic signatures are considered equivalent to paper records and handwritten signatures.
Medical Device Cybersecurity
The engineering and regulatory discipline for securing connected medical devices against cyber threats across their design, submission, and post-market lifecycle.
OT & ICS Security in Regulated Manufacturing
Securing the PLCs, DCS, SCADA and historians that run regulated production — where availability outranks confidentiality and a patch is a change.
Software Supply-Chain Security & SBOM
Third-party components, software bills of materials, vulnerability intake, and supplier assurance for the software a regulated organisation did not write.
Identity & Access Management in GxP Systems
Unique identity, authority checks, segregation of duties, privileged access and periodic review — the controls that make a GxP record attributable.
Cyber Incident Response for Regulated Records
What happens to GxP records, batch disposition and reporting clocks when a security incident lands — and why containment is only half the response.
Regulatory Submission Strategy & Planning
The CTD, the eCTD, and how a dossier plan built on dependencies rather than document counts survives contact with a filing date.
Cybersecurity Governance in Regulated Organisations
Who owns cyber risk, what residual risk the business has actually accepted, and how an ISMS meets a pharmaceutical quality system.
Asset Inventory & Attack Surface
Every other control depends on knowing what exists — and in regulated manufacturing the forgotten assets are the ones connected to production.
Data Privacy & Protection in GxP Environments
Where GDPR meets GxP record-keeping — the retention-versus-erasure conflict, health data as a special category, and encryption that survives an audit trail.
Network, Cloud & Endpoint Security for GxP Systems
Segmentation as the control that stops an ordinary compromise becoming a production outage — plus cloud responsibility and endpoints that cannot be touched.
Third-Party Cyber Risk in Regulated Supply
Suppliers hold credentials into the estate and copies of regulated data — and concentration is the risk that appears on nobody’s register.
Vulnerability & Patch Management Under Change Control
Most compromises exploit something known and unpatched — and in validated environments the window between disclosure and remediation is structurally wider.
Business Continuity & Recovery
Ransomware made recovery the primary control — and in regulated manufacturing a system that is running again is not yet back in a validated state.
Security Awareness & Human Factors in GxP
People are the most-attacked control and the fastest detector — and which one dominates depends entirely on whether reporting a mistake is safe.
Automation Strategy & Architecture
Architecture decides what can be changed independently later — which is why obsolete control systems stay in service past the point of support.
Alarm Management & Safety Instrumented Systems
An alarm asks a person to act; a safety instrumented function acts itself. Collapsing the two removes the independence the risk assessment assumed.
Automation Lifecycle & Support
Control systems outlive the projects that install them and the people who configured them — support arrangements made at handover decide year eight.
Requirements Traceability & Critical Aspects
Traceability converts a stack of test results into an argument — that the testing covered what mattered, which is the question actually asked.
Control System Assurance
Where a small configuration change has a direct physical consequence — and can be made by someone whose role is not framed as regulated.
Maintaining the Validated State
Validation is a claim about the present, maintained by work nobody sees — and most loss of validated state is cumulative and undramatic.
Safety Systems & Partner Data Exchange
Every exchange with a partner is a place a case can be delayed or lost — and reconciliation only works if it is periodic and two-way.
Digital Strategy & Application Portfolio
Regulated organisations accumulate systems faster than they retire them, and each carries a validation obligation for life.
Integration & Interoperability for GxP Data
Errors here are silent by construction — a successful transfer looks identical to a correct one.
Platforms, Cloud & Infrastructure for GxP
Moving to a managed platform moves the work, not the accountability.
Analytics & Decision Support in GxP
Self-service lets a good question be answered quickly and lets a wrong metric spread before anyone checks it.
Records, Content & Retrieval
A record that cannot be found within the time an inspection allows is functionally missing.
Digital Service Management in Regulated Operations
The validated state is maintained or lost in routine service management, not in projects.
Physical Security & Site Protection
Someone in the room can defeat most logical controls — and controlled substances carry federally prescribed security, not risk-based security.
Protect vs Disclose — The Trade-Secret Seam
One obligation requires the method and the data behind a regulated product to be written down and filed; another says their commercial value is that they are not. Where the two meet, and which disclosure bites hardest.

CSV: frequently asked questions

Reference answers on Computerised System Validation — what it governs, what regulations define it, and what it requires.

What is Computerised System Validation (CSV)?

CSV establishes documented evidence that a GxP computerised system does what it is intended to do and will continue to do so throughout its lifecycle. It spans requirements, risk assessment, verification, and ongoing control of the electronic records and signatures the system holds — for systems such as LIMS, MES, ERP, and chromatography data systems.

What standards and regulations govern CSV?

The primary industry framework is GAMP 5, which defines a risk- and category-based lifecycle. Regulatory requirements for electronic records and signatures come from FDA 21 CFR Part 11 and EU GMP Annex 11, which make GxP computerised systems directly inspectable.

What is the difference between CSV and CSA?

Computer Software Assurance (CSA) is a risk-based evolution of traditional CSV. Rather than documenting every function exhaustively, CSA focuses testing on the functions whose failure would affect patient safety, product quality, or data integrity, emphasising critical thinking over rote documentation — a more efficient path to the same assurance objective.