PLANREFERENCE OUTLINE

Computer Software Assurance (CSA) Test Strategy

A CSA test strategy that assigns assurance effort to each software feature by its impact on product quality or the quality system, then matches the testing activity — unscripted, ad-hoc, or scripted — to that risk, leveraging supplier evidence to keep documentation least-burdensome. Aligned to the FDA CSA guidance (2025) and GAMP 5 (2nd ed.).

What a template is not

A template is a document baseline to adapt inside your own quality system. SPEQ does not approve, validate, or take responsibility for what you issue from it, and using one is not evidence of compliance.

CHECKING ACCESS

Checking your Professional access…

REGULATIONS MAPPED
FDA CSA Guidance (2025)GAMP 5 (2nd ed.)EU GMP Annex 11
DOCUMENT TYPE
Plan
LAST UPDATED
August 2026
PURPOSE

The strategy that decides, feature by feature, how much assurance a piece of software actually needs — and then commits to the lightest activity that establishes confidence. It goes wrong in two opposite ways: a blanket scripted approach that documents everything and proves little, or an unscripted approach applied to a feature whose failure reaches the patient. The intended use and risk determination behind each choice belongs to your organisation.

What's Inside

Feature and function inventory with the intended use stated for each, in process terms not vendor terms
Risk determination per feature — direct or indirect impact on product quality or the quality system
Assurance-effort assignment that escalates with potential harm, with the escalation rule written down
Test-activity selection per feature: unscripted, ad-hoc error-guessing, or scripted, with the reason recorded
Supplier-leverage rationale naming which vendor evidence is relied on and what was done to assess it
Record expectations per activity — what is captured, by whom, and what counts as a result
Change triggers that reassess a feature’s risk when configuration, intended use or the process changes

How to Use It

1List features by intended use in your process, not by the vendor’s module names; a module list is not an intended-use inventory
2Determine direct or indirect impact for each feature, and record the reasoning; that classification is what the rest of the strategy rests on
3Escalate assurance effort with potential harm, and state the rule, so two reviewers reach the same answer for the same feature
4Select the least burdensome activity that fits the risk — unscripted testing is a method, not an excuse for absent records
5Assess supplier evidence before leveraging it; unexamined vendor documentation transfers their testing assumptions into your risk determination
6Reassess when configuration or intended use changes, because a feature’s risk moves with the process it now supports
DOCUMENT CONTENTS

The full section structure of this template — every section and sub-section, so you can use it as a baseline for your own site document.

Document Control
Document InformationApproval SignaturesRevision HistoryDistribution List
1System and Scope
2Feature Inventory, Risk, and Assurance Effort
3Test-Activity Selection
4Documentation and Records
REGULATORY CONTEXT

The FDA CSA guidance (2025) shifts effort from exhaustive documentation toward risk-based assurance driven by critical thinking, and GAMP 5 (2nd ed.) supplies the lifecycle and the supplier-leverage model behind it; EU GMP Annex 11 sets the validated-state expectation the strategy has to satisfy. None of them classifies your features, sets your escalation thresholds, or decides which vendor evidence is good enough to rely on. Those determinations are yours, and the matrix here is SPEQ synthesis for recording them consistently.

MAPPED STANDARDS
FDA CSA Guidance (2025)GAMP 5 (2nd ed.)EU GMP Annex 11
Browse the standards catalog →