Computerised System Validation
Validation of GxP computerised systems and electronic records.
What this page does not claim
Educational orientation — not a determination of regulatory applicability, compliance, validation scope, or organizational approval.
WHAT IT GOVERNS
Computerised System Validation establishes documented evidence that a GxP computerised system does what it is intended to do and will continue to do so throughout its lifecycle (GAMP 5, FDA 21 CFR Part 11, EU GMP Annex 11). It spans requirements, risk assessment, verification, and ongoing control of the electronic records and signatures the system holds.
WHY IT MATTERS
Nearly every GxP process now runs on software — LIMS, MES, ERP, chromatography data systems, building management. An unvalidated or poorly controlled system puts both product quality and data integrity at risk, and Part 11 / Annex 11 make those systems directly inspectable. CSV is how confidence in the software layer is established and maintained.
KEY FOCUS AREAS
The GAMP 5 lifecycle & software categories
A risk- and category-based lifecycle that scales effort to system complexity and novelty, from configurable products to bespoke development.
Risk-based verification (CSA)
Computer Software Assurance thinking — focusing testing on the functions whose failure would affect patient safety, product quality, or data integrity, and using critical thinking over rote documentation.
Electronic records & signatures
Part 11 / Annex 11 controls — audit trails, access control, and trustworthy electronic signatures — that make electronic records as reliable as paper.
Periodic review & change control
Keeping systems in a validated state over time through change control, configuration management, and periodic review across the operational life of the system.
STANDARDS SPEQ DECODES · 16
Open the full library →WHAT INSPECTORS LOOK AT
- System inventory and the validation status of each GxP system
- Audit trails, access control, and segregation of duties
- Change and configuration management keeping the system in a validated state
- Data backup, restore, and business-continuity for GxP data
RELATED DISCIPLINES
SECTORS THAT OPERATE UNDER CSV
CSV: frequently asked questions
Reference answers on Computerised System Validation — what it governs, what regulations define it, and what it requires.
What is Computerised System Validation (CSV)?
CSV establishes documented evidence that a GxP computerised system does what it is intended to do and will continue to do so throughout its lifecycle. It spans requirements, risk assessment, verification, and ongoing control of the electronic records and signatures the system holds — for systems such as LIMS, MES, ERP, and chromatography data systems.
What standards and regulations govern CSV?
The primary industry framework is GAMP 5, which defines a risk- and category-based lifecycle. Regulatory requirements for electronic records and signatures come from FDA 21 CFR Part 11 and EU GMP Annex 11, which make GxP computerised systems directly inspectable.
What is the difference between CSV and CSA?
Computer Software Assurance (CSA) is a risk-based evolution of traditional CSV. Rather than documenting every function exhaustively, CSA focuses testing on the functions whose failure would affect patient safety, product quality, or data integrity, emphasising critical thinking over rote documentation — a more efficient path to the same assurance objective.