· CROSS-CUTTING
CSV

Computerised System Validation

Validation of GxP computerised systems and electronic records.

Browse all 6 CSV standardsAssess your quality system →
WHAT IT GOVERNS

Computerised System Validation establishes documented evidence that a GxP computerised system does what it is intended to do and will continue to do so throughout its lifecycle (GAMP 5, FDA 21 CFR Part 11, EU GMP Annex 11). It spans requirements, risk assessment, verification, and ongoing control of the electronic records and signatures the system holds.

WHY IT MATTERS

Nearly every GxP process now runs on software — LIMS, MES, ERP, chromatography data systems, building management. An unvalidated or poorly controlled system puts both product quality and data integrity at risk, and Part 11 / Annex 11 make those systems directly inspectable. CSV is how confidence in the software layer is established and maintained.

KEY FOCUS AREAS
01

The GAMP 5 lifecycle & software categories

A risk- and category-based lifecycle that scales effort to system complexity and novelty, from configurable products to bespoke development.

02

Risk-based verification (CSA)

Computer Software Assurance thinking — focusing testing on the functions whose failure would affect patient safety, product quality, or data integrity, and using critical thinking over rote documentation.

03

Electronic records & signatures

Part 11 / Annex 11 controls — audit trails, access control, and trustworthy electronic signatures — that make electronic records as reliable as paper.

04

Periodic review & change control

Keeping systems in a validated state over time through change control, configuration management, and periodic review across the operational life of the system.

STANDARDS SPEQ DECODES · 6
Open in the library →
21 CFR Part 11FDAHIGH INSPECTION RISK
Electronic Records; Electronic Signatures
EU GMP Annex 11EMAHIGH INSPECTION RISK
Computerised Systems
ISPE GAMP 5 (2022)ISPE
Good Practice Guide: Compliant GxP Computerised Systems
IEC 62304:2006+A1:2015IEC
Medical Device Software — Software Life Cycle Processes
IMDRF/SaMD WG/N10IMDRF
Software as a Medical Device (SaMD): Key Definitions
IMDRF/SaMD WG/N12IMDRF
SaMD: Possible Framework for Risk Categorization and Corresponding Considerations
WHAT INSPECTORS LOOK AT
  • System inventory and the validation status of each GxP system
  • Audit trails, access control, and segregation of duties
  • Change and configuration management keeping the system in a validated state
  • Data backup, restore, and business-continuity for GxP data
KEY REGULATORY BODIES
FDAEMAISPEIECIMDRF

Derived from the 6 standards SPEQ decodes for this discipline.

RELATED DISCIPLINES
GDocPGood Documentation PracticeGEPGood Engineering PracticeQMSQuality Management Systems
SECTORS THAT OPERATE UNDER CSV
CDMOCDMOs & Contract ManufacturersCROCROs & Contract ResearchSponsors / MAHSponsors & Marketing Authorization HoldersPackagingPackaging, Labeling & SerializationCertificationNotified Bodies & CertificationVendorsSoftware & Equipment Vendors
THE FRAMEWORK
How SPEQ maps this discipline across the three layers →
FDA QMM
The maturity of the quality system behind this discipline →
Weekly Briefing

Get the Weekly GxP Briefing

Curated regulatory intelligence — enforcement, recalls, guidance, and quality signals — in one practitioner-grade email each week. Free.

Read a past issue →