· CSV / CSA

Computer System Validation & CSA

Computerised system validation (CSV) is documented evidence that a GxP computerised system does what it is intended to do, and only that, throughout its operational life. Done well it is a risk-based lifecycle discipline focused on patient safety, product quality, and data integrity. Done badly it degenerates into documentation for its own sake — which is exactly what the FDA’s Computer Software Assurance (CSA) direction is meant to correct.

Explore the standards library →Assess your quality system →

GAMP 5 and the risk-based lifecycle

ISPE GAMP 5 (Second Edition) is the practitioner framework for validating GxP computerised systems. Its core idea is that effort should be scaled to risk: a system’s validation rigour is driven by its impact on patient safety, product quality, and data integrity, and by its novelty and complexity. A configurable off-the-shelf LIMS is not validated the same way as bespoke code.

GAMP 5 organises work across a lifecycle — concept, project (specify, configure/build, verify), operation, and retirement — and around software categories that set the baseline approach. It also leans on supplier assessment and leverage: where a supplier has robust development and testing, the regulated company can rely on that evidence rather than re-testing everything itself.

Part 11 and Annex 11 — electronic records and signatures

Where a system creates, modifies, maintains, or transmits GxP electronic records, the electronic-records/electronic-signatures controls apply: unique user access, audit trails, operational and authority checks, and — where used — compliant electronic signatures. In the US this is 21 CFR Part 11; in the EU it is EU GMP Annex 11. The two are closely aligned in intent.

These controls are the mechanism by which validation delivers data integrity. Validation proves the record is trustworthy; Part 11 / Annex 11 keep it that way — by ensuring changes are attributable, traceable, and non-repudiable.

Computer Software Assurance (CSA) — the shift in emphasis

The FDA’s CSA direction (draft guidance for production and quality-system software) is a deliberate correction to validation that had become documentation-heavy and testing-light. CSA asks teams to spend their effort on critical thinking and on the features that actually bear on safety and quality — using unscripted and exploratory testing where appropriate, and reserving heavy scripted testing for high-risk functions.

CSA does not lower the bar for high-risk systems; it re-allocates effort. Less time producing screenshots that no one reads, more time analysing what could go wrong and testing that. It is the same risk-based philosophy GAMP 5 already teaches, stated by the regulator as an expectation.

What good looks like in operation

Validation is not finished at go-live. The operational phase — change control, periodic review, backup and restore, security and access management, and eventual data migration or retirement — is where most systems spend their life and where most findings arise. A validated system that is not kept in a validated state is no longer validated.

ANCHOR STANDARDS · 4
Open the library →
21 CFR Part 11FDAHIGH INSPECTION RISK
Electronic Records; Electronic Signatures
21 CFR Part 210FDA
Current Good Manufacturing Practice in Manufacturing, Processing, Packing, or Holding of Drugs — General
EU GMP Annex 11EMAHIGH INSPECTION RISK
Computerised Systems
ISPE GAMP 5 (2022)ISPE
Good Practice Guide: Compliant GxP Computerised Systems
SITS ACROSS THESE DISCIPLINES
KEY REGULATORY BODIES
FDAEMAISPE

Derived from the 4 standards that anchor this topic.

FREQUENTLY ASKED

What is the difference between CSV and CSA?

CSV (computer system validation) is the overall discipline of proving a GxP system is fit for use. CSA (computer software assurance) is the FDA’s risk-based emphasis within it — spend effort on critical thinking and testing that matters for safety and quality, rather than on exhaustive documentation. CSA is an approach to CSV, not a replacement for it.

Is GAMP 5 mandatory?

No. GAMP 5 is an ISPE good-practice guide, not a regulation. But it is the de facto industry framework, and regulators expect a risk-based validation approach consistent with its principles. The binding requirements are the predicate rules plus 21 CFR Part 11 / EU GMP Annex 11.

Do all computerised systems need validating?

Only GxP systems — those whose failure could affect patient safety, product quality, or data integrity — need validation, and the rigour scales with that risk. GAMP 5’s software categories and risk assessment are how you decide how much validation each system needs.

RELATED TOPICS
DATA INTEGRITYData Integrity & ALCOA+QUALITY RISK MANAGEMENTQuality Risk Management (ICH Q9)
Weekly Briefing

Get the Weekly GxP Briefing

Curated regulatory intelligence — enforcement, recalls, guidance, and quality signals — in one practitioner-grade email each week. Free.

Read a past issue →