PLANREFERENCE OUTLINE

Computer System Validation (CSV) Plan

CSV plan scoping a GxP computerised system by GAMP category and risk, defining IQ/OQ/PQ deliverables, Part 11 applicability, and requirements traceability. Maps to GAMP 5, Part 11, and Annex 11.

What a template is not

A template is a document baseline to adapt inside your own quality system. SPEQ does not approve, validate, or take responsibility for what you issue from it, and using one is not evidence of compliance.

CHECKING ACCESS

Checking your Professional access…

REGULATIONS MAPPED
ISPE GAMP 521 CFR Part 11EU GMP Annex 11
DOCUMENT TYPE
Plan
LAST UPDATED
January 2025
PURPOSE

The plan that scopes a GxP computerised system, sizes the validation effort by risk and software category, and names the deliverables that will demonstrate fitness for intended use. The decision the plan exists to record is the scaling one — what will not be tested and why — because unscoped validation defaults to testing everything shallowly, which is both expensive and weaker than testing what matters deeply.

What's Inside

System description and intended use, stated in terms of the GxP decisions the system supports
GxP assessment and electronic-record applicability, including which records the system creates, modifies, or maintains
Software category and risk assessment, with the category justified rather than asserted
Supplier assessment and the extent to which supplier documentation is leveraged
Validation strategy and deliverables, stating what is tested, what is leveraged, and what is deliberately not tested
Roles, responsibilities, and approval authority for each deliverable
Requirements-to-test traceability approach, acceptance and release criteria, periodic review, and retirement

How to Use It

1Describe intended use in terms of the GxP decisions made on the system's output, which is what determines risk
2Confirm electronic-record and signature applicability record by record rather than system-wide
3Justify the software category; a configured product assumed to be a standard one is the most common scoping error
4Scale testing to risk and category, and state explicitly what you are not testing and on what basis
5Assess the supplier before deciding how much of their documentation to leverage, and record that assessment
6Maintain requirements-to-test traceability from the start, and define periodic review and retirement in the plan rather than later
DOCUMENT CONTENTS

The full section structure of this template — every section and sub-section, so you can use it as a baseline for your own site document.

Document Control
Document InformationApproval SignaturesRevision HistoryDistribution List
1System Description and Intended Use
2GxP and Part 11 / Annex 11 Assessment
3GAMP Category and Risk Assessment
4Validation Strategy and Deliverables
5Roles and Supplier Assessment
6Requirements Traceability Approach
7Acceptance and Release Criteria
8Periodic Review and Retirement
REGULATORY CONTEXT

ISPE GAMP 5 (2nd ed.) sets out the risk-based, category-scaled approach to computerised system validation, including leveraging supplier activity where justified. EU GMP Annex 11 requires computerised systems to be validated for intended use with risk management applied throughout the lifecycle, and 21 CFR Part 11 governs electronic records and signatures. FDA's Computer Software Assurance guidance is scoped to medical-device production and quality-system software and should not be mapped onto clinical or pharmacovigilance systems. The category and the scaling are your determination.

MAPPED STANDARDS
ISPE GAMP 521 CFR Part 11EU GMP Annex 11
Browse the standards catalog →