← GXP GLOSSARY
Validation & Qualification

CSV

Computer System Validation

Establishing documented evidence that a GxP computerized system does what it is intended to do and will continue to — spanning requirements, risk assessment, verification, and lifecycle control (GAMP 5; 21 CFR Part 11; EU GMP Annex 11).

CSV is the discipline of proving a GxP computerised system does what you need it to do, and keeps doing it. The lifecycle runs from user requirements through risk assessment, supplier assessment, configuration and design, verification testing, release, and then the long operational tail — change control, periodic review, backup and restore, business continuity, and eventual decommissioning with the records intact.

The reason it matters is not paperwork but consequence: these systems hold the data that batch-release decisions rest on. If the audit trail can be disabled, if a user can delete a result without trace, or if a calculation is wrong in an unverified spreadsheet, then every quality decision downstream is unsupported. That is why CSV and data integrity are inseparable in practice.

The field is shifting. Traditional CSV drifted toward exhaustive documentation of everything equally, which consumed effort without reducing risk. The FDA’s Computer Software Assurance approach — and GAMP 5 2nd edition alongside it — pushes critical thinking instead: identify what could actually harm the patient or corrupt the record, test that rigorously with the most appropriate method (including unscripted and exploratory testing), and keep the evidence proportionate everywhere else.

KEY POINTS
  • Lifecycle, not a project: requirements → risk assessment → verification → release → operation → decommissioning.
  • Scope is risk-based; GAMP 5 software categories set the depth of specification and testing.
  • Inseparable from data integrity — audit trails, access control, and ALCOA+ are the point.
  • Spreadsheets used for GxP calculations are computerised systems and need validating too.
  • CSA reframes the effort: critical thinking and assurance activity over documentation volume.
  • The operational phase (change control, periodic review, backups) is where most findings arise.
REGULATORY BASIS

21 CFR Part 11 (Electronic Records; Electronic Signatures) and the applicable predicate rules; EU GMP Annex 11 (Computerised Systems); ISPE GAMP 5 2nd ed. (2022); FDA draft guidance, Computer Software Assurance for Production and Quality System Software (2022); PIC/S PI 041-1 for data integrity.

Frequently asked questions

What does CSV stand for?

CSV stands for Computer System Validation.

What is CSV?

Establishing documented evidence that a GxP computerized system does what it is intended to do and will continue to — spanning requirements, risk assessment, verification, and lifecycle control (GAMP 5; 21 CFR Part 11; EU GMP Annex 11).

Which regulations cover CSV?

21 CFR Part 11 (Electronic Records; Electronic Signatures) and the applicable predicate rules; EU GMP Annex 11 (Computerised Systems); ISPE GAMP 5 2nd ed. (2022); FDA draft guidance, Computer Software Assurance for Production and Quality System Software (2022); PIC/S PI 041-1 for data integrity.

SEE ALSO
CSAComputer Software AssuranceGAMP 5Good Automated Manufacturing Practice (ISPE)21 CFR Part 11
Browse the standards library →Explore GxP disciplines →

SPEQ decodes published regulatory concepts in plain language. Definitions are a practitioner reference, not legal or regulatory advice.

Weekly Briefing

Get the Weekly GxP Briefing

Curated regulatory intelligence — enforcement, recalls, guidance, and quality signals — in one practitioner-grade email each week. Free.

Read a past issue →