Establishing documented evidence that a GxP computerized system does what it is intended to do and will continue to — spanning requirements, risk assessment, verification, and lifecycle control (GAMP 5; 21 CFR Part 11; EU GMP Annex 11).
CSV is the discipline of proving a GxP computerised system does what you need it to do, and keeps doing it. The lifecycle runs from user requirements through risk assessment, supplier assessment, configuration and design, verification testing, release, and then the long operational tail — change control, periodic review, backup and restore, business continuity, and eventual decommissioning with the records intact.
The reason it matters is not paperwork but consequence: these systems hold the data that batch-release decisions rest on. If the audit trail can be disabled, if a user can delete a result without trace, or if a calculation is wrong in an unverified spreadsheet, then every quality decision downstream is unsupported. That is why CSV and data integrity are inseparable in practice.
The field is shifting. Traditional CSV drifted toward exhaustive documentation of everything equally, which consumed effort without reducing risk. The FDA’s Computer Software Assurance approach — and GAMP 5 2nd edition alongside it — pushes critical thinking instead: identify what could actually harm the patient or corrupt the record, test that rigorously with the most appropriate method (including unscripted and exploratory testing), and keep the evidence proportionate everywhere else.
- —Lifecycle, not a project: requirements → risk assessment → verification → release → operation → decommissioning.
- —Scope is risk-based; GAMP 5 software categories set the depth of specification and testing.
- —Inseparable from data integrity — audit trails, access control, and ALCOA+ are the point.
- —Spreadsheets used for GxP calculations are computerised systems and need validating too.
- —CSA reframes the effort: critical thinking and assurance activity over documentation volume.
- —The operational phase (change control, periodic review, backups) is where most findings arise.
21 CFR Part 11 (Electronic Records; Electronic Signatures) and the applicable predicate rules; EU GMP Annex 11 (Computerised Systems); ISPE GAMP 5 2nd ed. (2022); FDA draft guidance, Computer Software Assurance for Production and Quality System Software (2022); PIC/S PI 041-1 for data integrity.
Frequently asked questions
What does CSV stand for?
CSV stands for Computer System Validation.
What is CSV?
Establishing documented evidence that a GxP computerized system does what it is intended to do and will continue to — spanning requirements, risk assessment, verification, and lifecycle control (GAMP 5; 21 CFR Part 11; EU GMP Annex 11).
Which regulations cover CSV?
21 CFR Part 11 (Electronic Records; Electronic Signatures) and the applicable predicate rules; EU GMP Annex 11 (Computerised Systems); ISPE GAMP 5 2nd ed. (2022); FDA draft guidance, Computer Software Assurance for Production and Quality System Software (2022); PIC/S PI 041-1 for data integrity.
SPEQ decodes published regulatory concepts in plain language. Definitions are a practitioner reference, not legal or regulatory advice.
Get the Weekly GxP Briefing
Curated regulatory intelligence — enforcement, recalls, guidance, and quality signals — in one practitioner-grade email each week. Free.