CSV
Computer System Validation
What a definition is not
A definition is SPEQ’s plain-language decode of how a term is used in practice, cited to the documents that define it. It is a practitioner reference, not legal or regulatory advice, it does not replace the definition in the source, and where a regulator’s wording differs the regulator’s wording governs.
Establishing documented evidence that a GxP computerized system does what it is intended to do and will continue to — spanning requirements, risk assessment, verification, and lifecycle control (GAMP 5; 21 CFR Part 11; EU GMP Annex 11).
CSV is the discipline of proving a GxP computerised system does what you need it to do, and keeps doing it. The lifecycle runs from user requirements through risk assessment, supplier assessment, configuration and design, verification testing, release, and then the long operational tail — change control, periodic review, backup and restore, business continuity, and eventual decommissioning with the records intact.
The reason it matters is not paperwork but consequence: these systems hold the data that batch-release decisions rest on. If the audit trail can be disabled, if a user can delete a result without trace, or if a calculation is wrong in an unverified spreadsheet, then every quality decision downstream is unsupported. That is why CSV and data integrity are inseparable in practice.
The field is shifting. Traditional CSV drifted toward exhaustive documentation of everything equally, which consumed effort without reducing risk. The FDA’s Computer Software Assurance approach — and GAMP 5 2nd edition alongside it — pushes critical thinking instead: identify what could actually harm the patient or corrupt the record, test that rigorously with the most appropriate method (including unscripted and exploratory testing), and keep the evidence proportionate everywhere else.
- —Lifecycle, not a project: requirements → risk assessment → verification → release → operation → decommissioning.
- —Scope is risk-based; GAMP 5 software categories set the depth of specification and testing.
- —Inseparable from data integrity — audit trails, access control, and ALCOA+ are the point.
- —Spreadsheets used for GxP calculations are computerised systems and need validating too.
- —CSA reframes the effort: critical thinking and assurance activity over documentation volume.
- —The operational phase (change control, periodic review, backups) is where most findings arise.
21 CFR Part 11 (Electronic Records; Electronic Signatures) and the applicable predicate rules; EU GMP Annex 11 (Computerised Systems); ISPE GAMP 5 2nd ed. (2022); FDA final guidance, Computer Software Assurance for Production and Quality System Software (September 2025; draft 2022); PIC/S PI 041-1 for data integrity.
Frequently asked questions
What does CSV stand for?
CSV stands for Computer System Validation.
What is CSV?
Establishing documented evidence that a GxP computerized system does what it is intended to do and will continue to — spanning requirements, risk assessment, verification, and lifecycle control (GAMP 5; 21 CFR Part 11; EU GMP Annex 11).
Which regulations cover CSV?
21 CFR Part 11 (Electronic Records; Electronic Signatures) and the applicable predicate rules; EU GMP Annex 11 (Computerised Systems); ISPE GAMP 5 2nd ed. (2022); FDA final guidance, Computer Software Assurance for Production and Quality System Software (September 2025; draft 2022); PIC/S PI 041-1 for data integrity.