Validation Summary Report
The approved report concluding that a computerised system was verified against its intended use, listing what was tested, what deviated, and the basis for release.
Evidence is where the chain lands. Each record here is shown with the controls that produce it, so a claim that an obligation is met can be followed to the thing that proves it.
The approved report concluding that a computerised system was verified against its intended use, listing what was tested, what deviated, and the basis for release.
The approved statement of what the system must do and how it is built to do it — the baseline every test, change and periodic review is judged against.
A system-generated list of active accounts and their granted privileges, used to show that access matches authorised roles at a point in time.
The dated, signed record of a review comparing granted access against current roles, including the removals and corrections it triggered.
The record showing that audit-trail entries were reviewed by a competent person, what was examined, and how anomalies were dispositioned.
Documented proof of the audit-trail settings in force — that it is enabled, captures the required attributes, and cannot be disabled or edited by users.
The per-person record of the education, training and experience qualifying someone for their regulated tasks, current as of the date they performed them.
The approved record of a proposed change: its assessment, the regression or revalidation performed, the approvals obtained, and the closure evidence.
The recorded configuration and version of the system as released, plus its entry in the inventory of regulated systems — the reference an unplanned change is detected against.
The dated evaluation confirming a system remains in its validated state, drawing on change, incident, access and audit-trail history since the last review.
Evidence that backed-up data was actually restored and found complete and accurate — the only proof a backup regime works, as distinct from proof that it ran.
Evidence that an archived record was retrieved and rendered readable within the retention period, including any migration performed to keep it so.
The documented evaluation of a supplier or service provider against the quality obligations placed on it, with the agreement or corrective actions that followed.
The documented assessment of patient safety, data integrity and product quality risk for a system, and the justification for the resulting validation and control effort.
The record of a system failure or data anomaly: what happened, the impact assessed on product and data, the root cause, and the actions closed out against it.
The written policy holding individuals accountable for actions taken under their electronic signature, together with each signatory’s acknowledgement of it.
The certification submitted to the agency stating that electronic signatures used in the organisation are the legally binding equivalent of handwritten signatures.
The versioned, access-controlled set of operating and maintenance documentation for a system, with a change history showing who revised what and when.
Evidence that data crossing a system boundary was verified as complete and accurate — the built-in checks configured, and the result of exercising them.
The record of a critical manually entered value being independently checked, or of the validated system check that was justified in its place.
Evidence that identification codes and passwords are unique, periodically revised, and that loss, compromise or device deauthorisation is handled by a defined procedure.
The documented alternative arrangement for continuing a critical process during system unavailability, and evidence that it was exercised and found workable.
The record showing that batch certification and release was performed by the authorised person, identifying who released the batch and on what basis.
The requirement statements are faithful restatements of the regulations they cite, each carrying its clause and source. The controls, risks, evidence types and processes — and every line drawn from an obligation to a control — are SPEQ synthesis: a practitioner’s reading of how an obligation is customarily discharged. No regulator publishes this mapping. 21 CFR 11.10(d) requires that system access be limited to authorised individuals; it does not say “run a quarterly access review”. That inference is what SPEQ adds, and it is labelled rather than presented in a regulator’s voice.