
Introduction
Pharmaceutical manufacturing has undergone a fundamental digital transformation. Modern pharmaceutical organizations rely on computerized systems across manufacturing, quality control, quality assurance, engineering, supply chain, warehousing, regulatory operations, clinical development and pharmacovigilance.
Systems such as SAP/ERP, Manufacturing Execution Systems (MES), Laboratory Information Management Systems (LIMS), Electronic Quality Management Systems (eQMS), Electronic Document Management Systems (eDMS), Supervisory Control and Data Acquisition (SCADA), Building Management Systems (BMS), Environmental Monitoring Systems (EMS), Chromatography Data Systems (CDS), stability systems, serialization platforms and cloud/SaaS applications increasingly perform activities that were previously paper-based.
These systems can create, modify, calculate, transmit, approve, store or report information that influences:
- Product quality
- Patient safety
- Product efficacy
- Batch disposition
- Laboratory decisions
- Manufacturing controls
- Regulatory submissions
- Data integrity
- Pharmaceutical Quality Systems
Consequently, GxP CSV compliance is not simply an information-technology exercise. It is a cross-functional quality and compliance activity involving QA, IT, CSV/validation, system owners, process owners, production, QC, engineering, regulatory affairs, cybersecurity and other stakeholders.
The central question is not:
“Have we validated the software?”
The better question is:
“Have we established and maintained documented confidence that the computerized system is fit for its intended GxP use and that the data it generates, processes, stores and reports remain trustworthy throughout the system lifecycle?”
This distinction is important because contemporary approaches increasingly emphasize intended use, critical thinking, quality risk management, supplier involvement, efficient testing and data integrity, rather than simply producing large quantities of validation documentation.
FDA’s data-integrity guidance states that FDA expects data to be reliable and accurate and recognizes flexible, risk-based approaches for preventing and detecting data-integrity problems.
Similarly, EU GMP Annex 11 applies to computerized systems used as part of GMP-regulated activities and requires risk management throughout the lifecycle, with the extent of validation and data-integrity controls justified through documented risk assessment.
1. What Is GxP?
GxP is a collective term used to describe regulated “Good Practice” requirements applicable to different activities in the life-sciences industry.
The “x” represents the specific discipline.
| GxP Area | Example Computerized Systems | Potential Impact |
|---|---|---|
| GMP | MES, eQMS, SCADA | Product quality |
| GLP | LIMS, laboratory systems | Laboratory data |
| GCP | Clinical trial systems | Patient/clinical data |
| GDP | Warehouse and distribution systems | Product distribution |
| GVP | Pharmacovigilance systems | Patient safety |
GMP — Good Manufacturing Practice
GMP controls manufacturing, testing, documentation, quality systems and related activities so that medicinal products consistently meet appropriate quality standards.
FDA describes CGMP as the foundation for systems that assure appropriate design, monitoring and control of manufacturing processes and facilities.
GLP — Good Laboratory Practice
GLP governs certain nonclinical laboratory activities and emphasizes reliable, traceable and controlled scientific data.
GCP — Good Clinical Practice
GCP establishes principles for the conduct and documentation of clinical studies involving human participants.
GDP — Good Distribution Practice
GDP controls storage, transportation and distribution activities to maintain product quality throughout the supply chain.
GVP — Good Pharmacovigilance Practice
GVP addresses pharmacovigilance activities, including the collection, assessment and management of safety information.
Why GxP matters to computerized systems
When a computerized system supports a regulated process, the organization must determine what controls are necessary to ensure that the system remains suitable for its intended use and that associated records and data are trustworthy.
Therefore, GxP compliance and computerized-system governance are closely connected.
2. What Is Computer System Validation?
Simple Definition
Computer System Validation (CSV) is the documented process of establishing evidence that a computerized system consistently performs according to predetermined requirements and is suitable for its intended use.
In a pharmaceutical environment, validation should provide reasonable confidence that:
- Requirements are defined.
- Risks are understood.
- Critical functionality is appropriately tested.
- Data are protected.
- Access is controlled.
- Electronic records are trustworthy.
- Changes are controlled.
- The validated state is maintained.
Validation is more than testing
A common misconception is:
Validation = IQ + OQ + PQ
This is too simplistic.
Validation is a lifecycle activity involving:
Planning → Requirements → Risk Assessment → Design/Configuration → Verification/Testing → Release → Operation → Change Management → Periodic Review → Retirement
The exact activities and documentation should be proportionate to the system’s:
- Intended use
- GxP impact
- Complexity
- Patient/product/data risk
- Configuration/customization
- Supplier evidence
- Applicable regulations
- Organizational procedures
3. Why Is GxP CSV Compliance Important in the Pharmaceutical Industry?
Computerized systems can directly influence pharmaceutical quality decisions.
Consider a laboratory using a LIMS.
If the system:
- calculates results incorrectly,
- allows unauthorized modification,
- loses original data,
- fails to maintain an audit trail,
- permits inappropriate access,
- produces incorrect reports,
the problem is not merely an IT problem.
It can become a GxP compliance and potentially product-quality problem.
Major reasons for CSV
1. Patient safety
Incorrect computerized-system output could contribute to inappropriate manufacturing or laboratory decisions.
2. Product quality
Systems may control or record:
- Critical Process Parameters
- Critical Quality Attributes
- Batch records
- Laboratory results
- Environmental conditions
- Equipment status
3. Data integrity
Data must remain reliable, complete, consistent and attributable throughout its lifecycle.
FDA specifically emphasizes reliable and accurate data and risk-based controls for data-integrity risks.
4. Regulatory compliance
Computerized systems may support regulated records and processes subject to applicable GMP requirements and electronic-record controls.
5. Audit readiness
A well-controlled system allows an organization to demonstrate:
Requirement → Risk → Control → Test → Evidence → Approval
6. Business continuity
Critical systems require appropriate backup, recovery and continuity controls.
4. Which Systems Require GxP CSV?
The answer should not be based simply on the software category.
A system is potentially GxP-relevant when its intended use supports a regulated activity or manages data that can affect product quality, patient safety, regulatory compliance or data integrity.
| System | Typical GxP Relevance | Typical Validation Focus |
| SAP/ERP | High in relevant processes | Master data, materials, batch processes, interfaces |
| MES | High | Electronic batch records, recipes, workflow, data integrity |
| LIMS | High | Sample management, calculations, results, audit trail |
| eQMS | High | Deviations, CAPA, change control, approvals |
| eDMS | High | Controlled documents, access, versioning, approvals |
| SCADA/HMI | Potentially high | Process control, alarms, data acquisition |
| BMS | Potentially high | Environmental and facility controls |
| EMS | High where environmental conditions are critical | Monitoring, alarms, records |
| CDS | High | Chromatography data, calculations, audit trails |
| Stability System | High | Sample management, schedules, results |
| Serialization | High | Product identity and traceability |
| WMS | Potentially high | Material/product status and traceability |
| Clinical Systems | High | Clinical data and records |
| Pharmacovigilance Systems | High | Safety information |
| Cloud/SaaS | Depends on intended use | Configuration, security, records, supplier controls |
| AI/ML | Risk-dependent | Intended use, model performance, data, monitoring |
Key principle
Validate based on GxP impact and intended use—not simply on whether the product is called SAP, LIMS, MES or SCADA.
5. Regulatory and Industry Framework for GxP CSV Compliance
A strong CSV program distinguishes between regulations, regulatory guidance, and industry best practice.
| Framework | Nature | Relevance |
| 21 CFR Part 11 | U.S. regulation | Electronic records/signatures |
| EU GMP Annex 11 | EU GMP guidance | Computerized systems |
| EU GMP Chapter 4 | GMP guidance | Documentation |
| GAMP 5 | Industry guidance | Risk-based computerized-system lifecycle |
| ICH Q9(R1) | ICH guideline | Quality Risk Management |
| ICH Q10 | ICH guideline | Pharmaceutical Quality System |
| FDA Data Integrity Guidance | FDA guidance | Data integrity |
| PIC/S PI 041-1 | Inspectorate guidance | Data management/integrity |
| WHO data-integrity guidance | WHO guidance | Data governance/integrity |
| ISO 27001 | International standard | Information security |
| Internal SOPs | Company-controlled requirements | Operational governance |
FDA notes that guidance documents generally represent the agency’s current thinking and are not themselves legally binding unless regulatory/statutory requirements are specifically cited.
6. 21 CFR Part 11
21 CFR Part 11 establishes requirements for electronic records and electronic signatures in circumstances where applicable FDA regulations require records to be maintained or submitted electronically.
It is important not to reduce Part 11 to one feature such as audit trails.
Relevant controls include areas such as:
- System validation
- Accurate and complete copies of records
- Record protection
- Access limitation
- Operational checks
- Authority checks
- Device checks where applicable
- Electronic signatures
- Signature controls
- Documentation controls
- Record retention
Important practical point
A system having an audit trail does not automatically mean the system is Part 11 compliant.
Compliance depends on the overall system, procedural and organizational control environment and the applicable requirements.
Part 11 compliance checklist
A regulated organization should evaluate:
- Is the applicable record within scope?
- Has the system been appropriately validated?
- Are authorized users uniquely identified?
- Are access privileges appropriate?
- Are electronic signatures appropriately controlled?
- Are records protected against unauthorized modification?
- Are audit trails appropriate for relevant activities?
- Can accurate and complete records be retrieved?
- Are procedures established and followed?
- Are controls implemented consistently?
7. EU GMP Annex 11
EU GMP Annex 11 applies to computerized systems used as part of GMP-regulated activities.
The current listed EudraLex Volume 4 Annex 11 is the January 2011 version.
Its principles include:
- Risk management
- Personnel
- Suppliers and service providers
- Validation
- Data
- Accuracy checks
- Data storage
- Printouts
- Audit trails
- Change management
- Periodic evaluation
- Security
- Business continuity
- Archiving
The Annex states that risk management should be applied throughout the lifecycle, considering patient safety, data integrity and product quality.
Important 2026 development
The European Commission conducted a stakeholder consultation during 2025 on a revised Annex 11 and related GMP documentation changes. The draft revision strengthens lifecycle management, supplier oversight, data integrity, audit trails, electronic signatures and security. It should therefore be treated as an emerging regulatory direction rather than confused with the currently operative Annex 11 text.
8. GAMP 5 and Risk-Based CSV
GAMP 5 is an industry good-practice guide published by ISPE. It is not a law and is not itself a regulation.
The second edition maintains the lifecycle and risk-based principles while placing greater emphasis on critical thinking, supplier involvement, modern development approaches and efficient testing.
GAMP 5 supports organizations in applying:
- Lifecycle thinking
- Quality risk management
- Intended-use assessment
- Supplier involvement
- Requirements management
- Verification
- Configuration management
- Change management
- Efficient testing
GAMP 5 principle
A useful way to understand modern GAMP 5 is:
Patient safety + product quality + data integrity
combined with:
Intended use + risk assessment + critical thinking + appropriate verification
Software categories
GAMP 5 discusses software categories and approaches for different types of software.
However, organizations should avoid treating historical category numbers as a universal regulatory checklist.
The more important questions are:
- What does the system do?
- What is the intended use?
- What is configurable?
- What is customized?
- What are the critical functions?
- What are the risks?
- What supplier evidence is available?
9. GxP CSV Lifecycle
A practical computerized-system validation lifecycle can be represented as follows:
Business Need
↓
GxP Impact Assessment
↓
System Classification
↓
Validation Strategy
↓
URS
↓
Risk Assessment
↓
Supplier Assessment
↓
Functional/Design Specifications
↓
Configuration/Development
↓
Testing
↓
Traceability
↓
Validation Summary
↓
Release
↓
Operational Control
↓
Change Control
↓
Periodic Review
↓
Retirement
Lifecycle stages
| Stage | Main Objective |
| Concept | Define business need |
| GxP Assessment | Determine regulatory relevance |
| Classification | Establish risk/complexity |
| Planning | Define validation strategy |
| URS | Define user requirements |
| Risk Assessment | Identify critical risks |
| Supplier Assessment | Evaluate supplier capability |
| Specification | Define functional/design expectations |
| Configuration | Configure system appropriately |
| Testing | Generate objective evidence |
| Traceability | Demonstrate requirement coverage |
| Release | Approve system for intended use |
| Operation | Maintain validated state |
| Change Control | Control modifications |
| Periodic Review | Reconfirm continued suitability |
| Retirement | Control final disposition and records |
10. GxP Impact Assessment
The GxP impact assessment is one of the most important early decisions.
Questions to ask
- Does the system support a GxP-regulated process?
- Does it create or maintain GxP records?
- Does it process GxP data?
- Can it influence product quality?
- Can it influence patient safety?
- Does it support batch release?
- Does it control a critical process?
- Does it perform regulated calculations?
- Does it manage electronic signatures?
- Could failure compromise data integrity?
Practical decision tree
Does the system support a GxP activity?
↓ Yes
Does it create/process/store GxP data or influence a regulated decision?
↓ Yes
Could failure affect product quality, patient safety or data integrity?
↓ Yes
Perform documented risk assessment and define appropriate validation/assurance controls.
This does not mean every system needs the same validation package.
The final decision should be documented according to the organization’s procedures and applicable regulations.
11. User Requirements Specification — URS
The User Requirements Specification (URS) establishes what users need the system to accomplish.
A good URS should be:
Clear + measurable + testable + traceable + risk-based
Typical URS content
- Functional requirements
- Business requirements
- Regulatory requirements
- Data integrity requirements
- Security
- User access
- Audit trail
- Electronic signatures
- Reporting
- Interfaces
- Backup/recovery
- Performance
- Data retention
- Availability
Example
URS-001: The system shall restrict access to authorized users according to predefined roles.
This requirement is stronger than:
“The system should have security.”
Why?
Because URS-001 can be objectively tested.
Another example
URS-002: The system shall maintain an audit trail for defined GxP-relevant creation, modification and deletion activities.
The requirement should then be linked to:
- Risk assessment
- Configuration/design
- Test case
- Test result
- Traceability matrix
12. Risk Assessment
Risk assessment determines where validation resources should be concentrated.
A traditional FMEA approach considers:
- Severity
- Occurrence/Probability
- Detectability
A simple Risk Priority Number may be calculated in some organizational methodologies, although organizations should use their approved QRM methodology rather than assuming one universal scoring system.
ICH Q9(R1) provides the pharmaceutical quality-risk-management framework and emphasizes protecting patients by managing quality risks throughout the product lifecycle.
Illustrative FMEA
| Function | Failure Mode | Severity | Probability | Detectability | Risk | Control |
| Result calculation | Incorrect calculation | High | Medium | Low | High | Functional testing |
| User access | Unauthorized access | High | Low | Medium | High | RBAC testing |
| Audit trail | Activity not captured | High | Low | Low | High | Audit trail testing |
| Report | Incorrect data | Medium | Medium | Medium | Medium | Report verification |
| Backup | Data cannot be restored | High | Low | Low | High | Restore testing |
Risk determines effort
Higher-risk functionality may justify:
- More detailed requirements
- Additional test coverage
- Independent review
- More robust supplier assessment
- More extensive negative testing
- Additional procedural controls
Lower-risk functionality may require proportionately less effort.
13. CSV Documentation
The documentation package should be risk-based.
| Document | Purpose |
| Validation Plan | Defines strategy |
| GxP Assessment | Determines regulatory impact |
| URS | Defines user needs |
| Risk Assessment | Identifies and ranks risks |
| Functional Specification | Defines functional behavior |
| Design/Configuration Specification | Defines implementation |
| IQ | Verifies installation |
| OQ | Verifies operation |
| PQ/UAT | Verifies intended use |
| Traceability Matrix | Demonstrates coverage |
| Validation Summary Report | Summarizes evidence |
| SOPs | Define operational controls |
| Training Records | Demonstrate competency |
| Periodic Review | Confirms continued state |
Not every system necessarily requires every document as a standalone deliverable.
For example, a simple configurable SaaS application may use an appropriately scaled documentation approach, while a highly customized MES controlling critical manufacturing operations may require much greater rigor.
14. IQ, OQ and PQ
Installation Qualification — IQ
IQ establishes documented evidence that the relevant system components have been installed according to approved specifications.
Potential checks include:
- Hardware
- Software
- Version
- Operating environment
- Configuration
- Infrastructure
- Required documentation
- Installation records
Operational Qualification — OQ
OQ evaluates whether the system operates correctly against defined functional requirements.
Typical tests include:
- Functional operation
- Security
- Access controls
- Audit trails
- Calculations
- Interfaces
- Alarms
- Error handling
- Boundary conditions
- Negative testing
Performance Qualification — PQ / UAT
PQ/UAT evaluates whether the system performs appropriately in its intended business environment.
Examples:
- End-to-end workflow
- Manufacturing process
- Laboratory workflow
- Batch review
- Approval workflow
- Reporting
- Business scenarios
Simple distinction
IQ: Is it installed correctly?
OQ: Does it function correctly?
PQ/UAT: Does it support its intended use effectively?
However, these labels should not be treated as universally mandatory stages for every software system. The appropriate verification strategy should follow intended use, risk and lifecycle methodology.
15. Traceability Matrix
A Traceability Matrix demonstrates that requirements have been appropriately addressed through the lifecycle.
Example:
| URS | Risk | Specification | Test | Result |
| URS-001 | RA-001 | FS-001 | OQ-001 | PASS |
| URS-002 | RA-002 | FS-002 | OQ-002 | PASS |
| URS-003 | RA-003 | DS-003 | PQ-003 | PASS |
The relationship is:
Requirement → Risk → Specification → Test → Evidence
Traceability helps demonstrate that critical requirements were not overlooked.
16. Data Integrity and ALCOA+
Data integrity is central to GxP CSV compliance.
ALCOA
- Attributable
- Legible
- Contemporaneous
- Original
- Accurate
ALCOA+
- Complete
- Consistent
- Enduring
- Available
The practical goal is not simply to display the acronym.
The organization must ensure that the system and procedures protect the integrity of data throughout its lifecycle.
WHO guidance emphasizes risk-based controls and specifically discusses controls addressing deletion, modification and exclusion of data or results, together with review of data, metadata and audit trails.
Good practice
An analyst logs in with a unique account, performs an analysis, generates complete raw data, and the system records relevant changes through an appropriate audit trail.
Poor practice
An analyst uses a shared account and exports results to Excel, modifies the spreadsheet without adequate controls and retains only the final value.
Potential risk
The organization may be unable to reconstruct:
- Who performed the activity
- What happened
- When it happened
- What was changed
- Why it was changed
- Whether the original information remains available
17. Audit Trail Review
An audit trail is a computer-generated record that can capture relevant actions or changes associated with electronic records.
It may provide information such as:
- User
- Date/time
- Activity
- Previous value
- New value
- Reason, where applicable
Important point
An audit trail’s existence does not by itself guarantee data integrity.
The organization also needs:
- Appropriate configuration
- Access controls
- Procedures
- Risk-based review
- Investigation processes
- Trained personnel
Examples
LIMS: modification of test results or sample information.
MES: changes to electronic batch-record data.
eQMS: modification or approval of quality records.
CDS: processing or reprocessing analytical data.
SCADA: changes to critical parameters or configuration.
FDA’s laboratory CGMP Q&A emphasizes that data—including failing, passing, suspect and obvious-error data—must be appropriately retained and subject to review and oversight.
18. Electronic Signatures
Electronic signatures should provide appropriate confidence regarding:
- Who signed
- When the signature was applied
- What was signed
- The meaning of the signature
- The linkage between signature and record
Controls may include:
- Unique user identity
- Authentication
- Password controls
- Role-based authority
- Signature linkage
- Procedural controls
Common mistakes
- Shared user accounts
- Shared passwords
- Signing on behalf of another person
- Weak authentication
- Inadequate signature linkage
- Failure to define signature meaning
- Inadequate access termination
19. User Access Management
Access control is both a security and GxP data-integrity issue.
A robust system should address:
Role-Based Access Control
Users receive only the privileges necessary for their duties.
Least Privilege
Users should not receive unnecessary administrative access.
Segregation of Duties
Conflicting responsibilities should be appropriately separated.
Joiner/Mover/Leaver
Access should be:
- Created when needed
- Modified when responsibilities change
- Removed when no longer required
Periodic Access Review
Management should periodically verify that access remains appropriate.
Privileged Access
Administrator accounts should receive additional control and monitoring.
Shared accounts
Shared accounts create significant attribution and accountability problems and should generally be avoided where individual accountability is required.
20. Change Control
A validated system must remain under control throughout its operational lifecycle.
Typical changes include:
- Software upgrade
- Configuration modification
- New report
- New interface
- Database migration
- Security patch
- Infrastructure modification
- New user role
- Workflow change
Typical change-control process
Change Request
↓
Impact Assessment
↓
Risk Assessment
↓
Validation/Test Strategy
↓
Approval
↓
Implementation
↓
Verification
↓
Post-Implementation Review
The amount of testing should be proportionate to the impact and risk.
21. Deviation, Incident and CAPA
CSV-related issues may arise from:
- System failures
- Unexpected behavior
- Failed tests
- Unauthorized changes
- Data-integrity events
- Interface failures
- Backup failures
- Access-control issues
- Configuration errors
A robust investigation should determine:
- What happened?
- When did it happen?
- Which system/function was involved?
- Which data were affected?
- Which products/batches may be affected?
- Was data integrity compromised?
- What was the root cause?
- Were previous records affected?
- Is retrospective review required?
- What CAPA is necessary?
Depending on circumstances, an issue may require:
- Batch impact assessment
- Data-integrity assessment
- Retrospective review
- CAPA
- Regulatory assessment
The appropriate response depends on the facts, applicable regulations and company procedures.
22. Periodic Review
Validation does not end when the system is released.
Periodic review confirms whether the system remains fit for intended use.
Periodic review checklist
- Current system version
- System performance
- Incidents
- Deviations
- CAPA
- Change controls
- User access
- Audit trail controls
- Backup/restore
- Disaster recovery
- Supplier performance
- Security
- Regulatory changes
- Validation status
- Training
- Business/process changes
The objective is to answer:
Is the system still in a controlled and validated state?
23. Backup, Restore and Business Continuity
Backup is not equivalent to recoverability.
A backup strategy should consider:
- Frequency
- Retention
- Storage location
- Security
- Encryption where appropriate
- Recovery process
- Restoration testing
- Data integrity
- Disaster recovery
- Business continuity
WHO material emphasizes backup, separate storage and periodic restoration/verification of selected data.
Key lesson
A company cannot confidently state that data are recoverable merely because backup jobs are running.
Restore testing provides evidence of recoverability.
24. Cloud and SaaS CSV
Cloud and SaaS systems do not automatically eliminate validation responsibilities.
The organization should assess:
Supplier
- Supplier qualification
- Supplier quality system
- Development practices
- Security
- Service-level arrangements
- Change management
- Incident management
Application
- Configuration
- GxP functionality
- Audit trail
- Electronic signatures
- Access
- Data retention
Data
- Ownership
- Location
- Migration
- Backup
- Recovery
- Export
- Archiving
Change management
Cloud providers may release updates frequently.
The regulated organization therefore needs a strategy for:
- Vendor notifications
- Impact assessment
- Release assessment
- Regression testing where justified
- Configuration review
EU Annex 11 specifically addresses supplier/service-provider responsibilities and states that supplier reliability and competence are important considerations, with audit needs determined using risk assessment.
Do not blindly accept supplier testing
Supplier documentation can be leveraged as evidence, but the regulated organization remains responsible for demonstrating that the system is suitable for its own intended use.
25. Computer Software Assurance — CSA vs CSV
Computer Software Assurance represents a more risk-based approach to establishing confidence in software used for relevant production and quality-system activities.
| CSV | CSA |
| Traditional validation framework | Risk-based assurance mindset |
| Often document-intensive | Critical-thinking focused |
| Extensive scripted testing can occur | Testing effort concentrated on critical risks |
| Strong focus on validation deliverables | Strong focus on objective assurance |
| Can become inefficient if poorly implemented | Encourages efficient evidence generation |
Does CSA replace CSV?
No—not as a blanket statement.
CSA should be understood as an evolution toward more risk-based assurance practices rather than a declaration that CSV is obsolete.
FDA’s current CSA guidance is specifically focused on software used in medical-device production and quality management systems, so pharmaceutical organizations should not automatically treat that guidance as a direct replacement for pharmaceutical GMP requirements.
For pharmaceutical companies, CSA concepts can nevertheless inform a broader modernization of validation practices when consistent with applicable regulations and company procedures.
26. CSV for Pharmaceutical Manufacturing
MES
GxP impact
Potentially high because MES may control or record:
- Electronic batch records
- Manufacturing instructions
- Process steps
- Material verification
- Equipment status
- Batch genealogy
Validation focus
- Recipe management
- Electronic records
- Workflow
- Access control
- Audit trails
- Interfaces
- Calculations
- Exception handling
LIMS
GxP impact
High where laboratory data support release or other regulated decisions.
Validation focus
- Sample management
- Specifications
- Calculations
- Result entry
- Data review
- Audit trails
- Electronic signatures
- Interfaces
- Reporting
SAP/ERP
SAP may support GxP processes such as:
- Material management
- Batch management
- Inventory status
- Quality processes
- Production planning
- Master data
The entire SAP platform should not automatically be classified as “GxP.”
Instead, assess the specific processes, configurations, interfaces and intended uses that are within the regulated scope.
SCADA/HMI
Potentially critical when SCADA/HMI:
- Controls manufacturing equipment
- Records critical process data
- Generates alarms
- Controls process parameters
- Interfaces with batch systems
Validation should focus on functions whose failure could affect product quality, process control or data integrity.
BMS/EMS
Potentially GxP-relevant when systems monitor or control critical environmental conditions such as:
- Temperature
- Humidity
- Differential pressure
- Cleanroom conditions
- Critical facility parameters
eQMS
Typical scope includes:
- Deviations
- CAPA
- Change control
- Complaints
- Training
- Audits
- Quality events
Validation should focus on workflow, data integrity, permissions, approvals, audit trails and reporting.
27. Practical Case Study: LIMS Validation
Consider a pharmaceutical QC laboratory implementing a new LIMS.
Step 1 — Business need
The laboratory wants to replace manual sample tracking with an electronic system.
Step 2 — GxP assessment
The system will manage laboratory results used in product-quality decisions.
Therefore, it has significant GxP impact.
Step 3 — URS
Requirements include:
- Unique user access
- Sample traceability
- Specification management
- Result entry
- Calculations
- Audit trail
- Electronic approval
- Reporting
- Data retention
Step 4 — Risk assessment
Critical risks are identified around:
- Incorrect calculations
- Unauthorized result modification
- Missing audit trails
- Incorrect specifications
- Data loss
Step 5 — Supplier assessment
The supplier’s:
- Quality system
- Development approach
- Security
- Documentation
- Support model
- Change-management process
are assessed.
Step 6 — Configuration
The organization configures:
- User roles
- Specifications
- Workflows
- Reports
- Approval processes
Step 7 — Testing
Testing focuses strongly on critical functionality.
Examples:
- Login
- Role permissions
- Sample registration
- Result entry
- Calculation
- Specification comparison
- Audit trail
- Approval
- Report generation
- Exception handling
Step 8 — Data migration
If historical data are migrated, the organization assesses:
- Data mapping
- Transformation
- Completeness
- Accuracy
- Reconciliation
- Migration verification
Step 9 — Release
After review of test evidence, deviations and outstanding actions, QA and responsible stakeholders approve release.
Step 10 — Operation
The system enters controlled operation.
Step 11 — Periodic review
The organization reviews:
- Incidents
- Changes
- CAPA
- Access
- Audit trail controls
- Supplier status
- Backup
- System performance
This is a practical example of risk-based GxP CSV compliance: effort is concentrated on functions that can affect laboratory data and quality decisions.
28. Common CSV Compliance Failures
| Problem | Compliance Risk | Recommended Control |
| Inadequate URS | Wrong system validated | Establish clear, testable requirements |
| Poor risk assessment | Critical functions overlooked | Perform documented QRM |
| Missing traceability | Incomplete requirement coverage | Maintain requirement-to-test mapping |
| Inadequate testing | Undetected defects | Risk-based verification |
| Testing without requirements | Weak validation basis | Approve requirements first |
| Shared accounts | Poor attribution | Unique user IDs |
| Weak access control | Unauthorized activity | RBAC and periodic review |
| Poor audit-trail review | Undetected data manipulation | Risk-based review |
| Missing periodic review | Loss of validated state | Scheduled review |
| Poor change control | Uncontrolled system state | Formal change process |
| Uncontrolled spreadsheets | Data-integrity risk | Spreadsheet assessment/control |
| Backup without restore testing | False recovery confidence | Perform restoration tests |
| Blind acceptance of supplier evidence | Inadequate intended-use assurance | Supplier evidence assessment |
| Poor migration validation | Data loss/inaccuracy | Reconciliation and testing |
| Weak deviation investigation | Recurrence | Root-cause analysis/CAPA |
| Poor retirement | Loss of required records | Controlled archival/retirement |
29. CSV Audit Preparation Checklist
Before an FDA, EU GMP or other regulatory inspection, verify that the organization can readily demonstrate:
Governance
- Computerized-system governance procedure
- System ownership
- Process ownership
- QA responsibilities
- IT responsibilities
GxP Assessment
- GxP impact assessment
- Intended-use statement
- System classification
- Risk assessment
Requirements
- Approved URS
- Functional requirements
- Data-integrity requirements
- Security requirements
Validation
- Validation plan
- Approved protocols
- Test evidence
- Deviations documented
- Traceability matrix
- Validation summary
Data Integrity
- ALCOA+ assessment
- Audit trail controls
- Audit trail review procedure
- Access control
- Electronic signatures
- Data retention
Lifecycle
- Change controls
- Incident management
- CAPA
- Periodic review
- Backup/restore
- Disaster recovery
- Retirement plan
Supplier
- Supplier qualification
- Supplier agreements
- Supplier documentation
- Supplier change notifications
- Supplier performance review
Training
- User training
- Administrator training
- SOP training
- Training records
30. Questions a Regulatory Auditor May Ask
An auditor may ask:
“How did you determine this system is GxP?”
Expected evidence:
- Intended use
- GxP assessment
- Risk assessment
- Process mapping
- Applicable regulations
“Show me the critical requirements.”
Provide:
- URS
- Risk assessment
- Requirement classification
“How do you know all critical requirements were tested?”
Provide:
- Traceability Matrix
- Test evidence
“Who can modify data?”
Provide:
- User roles
- Access matrix
- Access review evidence
“Can the audit trail be disabled?”
Demonstrate:
- Configuration
- Access restrictions
- Testing
- Procedures
“How do you know your backup works?”
Provide:
- Backup records
- Restore test evidence
- Disaster-recovery evidence
“What happens when the vendor upgrades the system?”
Explain:
- Supplier notification
- Change control
- Impact assessment
- Risk assessment
- Regression testing where appropriate
31. Future of GxP CSV Compliance
Digital transformation is moving pharmaceutical organizations toward increasingly complex systems.
Emerging technologies include:
- Artificial Intelligence
- Generative AI
- Agentic AI
- Machine Learning
- Cloud computing
- SaaS
- IoT
- Digital twins
- Pharma 4.0
- MES
- Digital Quality Systems
- Automated testing
AI/ML validation challenges
AI introduces additional considerations:
Intended use
What exact decision or process does the model support?
Training data
Is the training data appropriate, representative and controlled?
Data quality
Poor data can result in poor model performance.
Model performance
What metrics define acceptable performance?
Explainability
Can the organization understand or appropriately document model behavior for its intended use?
Change control
What happens when the model, training data or algorithm changes?
Continuous monitoring
How will performance degradation be detected?
Human oversight
Where appropriate, how are human review and intervention incorporated?
The European Commission’s 2025 consultation on a proposed new Annex 22 illustrates the direction of travel: the draft specifically addresses AI/ML model selection, training, validation, intended use, performance metrics, training-data quality, ongoing monitoring, change control and human review. These are proposed/emerging expectations, not a statement that all such requirements are already operative EU GMP requirements.
32. CSV Career Guide
The expansion of digital pharmaceutical systems is creating opportunities in:
- CSV Engineer
- Validation Engineer
- Senior CSV Engineer
- CSV Consultant
- CSV Lead
- QA CSV Manager
- Computer Software Assurance Specialist
- IT Quality Manager
- Digital Quality Manager
- Computerized Systems Quality Lead
Important skills
Regulatory knowledge
- 21 CFR Part 11
- EU Annex 11
- GMP
- Data Integrity
- ALCOA+
- Applicable regional regulations
Technical knowledge
- Software lifecycle
- Databases
- Interfaces
- Cloud
- SaaS
- MES
- LIMS
- ERP/SAP
- SCADA
- eQMS
Validation skills
- URS
- Risk assessment
- Functional specifications
- Configuration/design
- Testing
- Traceability
- Change control
- Periodic review
Professional skills
- Technical writing
- Audit response
- Root-cause analysis
- Project management
- Stakeholder management
- Supplier management
For interview preparation, candidates should be able to explain why a validation activity is performed rather than merely memorizing document names.
33. Master GxP CSV Compliance Checklist
Governance
- Computerized-system governance procedure established
- System owner identified
- Process owner identified
- QA responsibilities defined
- IT responsibilities defined
GxP Assessment
- Intended use documented
- GxP impact assessed
- Applicable regulations identified
- System boundaries documented
- Critical processes identified
Risk Management
- Risk assessment completed
- Critical functions identified
- Critical data identified
- Patient/product/data risks assessed
- Controls linked to identified risks
URS
- Requirements approved
- Requirements are testable
- Data-integrity requirements included
- Security requirements included
- Audit-trail requirements included
- Electronic-signature requirements included
Design and Configuration
- Functional design documented
- Configuration controlled
- Interfaces documented
- Critical configuration reviewed
- Version information controlled
Testing
- Test strategy approved
- Critical functions tested
- Negative scenarios considered
- Boundary conditions considered
- Security tested
- Audit trail tested
- Interfaces tested
- Calculations verified
- Test evidence retained
Data Integrity
- ALCOA+ principles addressed
- Unique user IDs implemented
- Audit trails enabled where appropriate
- Audit trail review defined
- Data retention defined
- Data export controlled
Security
- Role-based access implemented
- Least privilege applied
- Privileged access controlled
- Access review performed
- Leaver access removed
- Password/authentication controls established
Electronic Signatures
- Signatures uniquely attributable
- Authentication controls implemented
- Signature meaning defined
- Signature-record linkage verified
Change Control
- Change request initiated
- Impact assessment completed
- Risk assessment completed
- Testing performed where required
- Approval completed
- Post-implementation review performed
Incidents and CAPA
- Incidents documented
- Deviations investigated
- Data-integrity impact assessed
- Product/batch impact assessed where applicable
- Root cause established
- CAPA implemented where necessary
Periodic Review
- Review performed according to procedure
- Changes reviewed
- Incidents reviewed
- CAPA reviewed
- Access reviewed
- Backup/recovery reviewed
- Supplier status reviewed
- Regulatory changes considered
Backup and Recovery
- Backup strategy approved
- Retention defined
- Backup monitoring performed
- Restore testing performed
- Disaster recovery tested
- Business continuity considered
Supplier Management
- Supplier assessed
- Supplier quality information evaluated
- Agreements established
- Supplier changes monitored
- Supplier performance reviewed
Retirement
- Retirement plan approved
- Required records identified
- Data archived appropriately
- Data retrieval verified
- Interfaces retired/redirected
- User access removed
- Final retirement documented
34. Key Comparison Tables
CSV vs CSA
| CSV | CSA |
| Lifecycle validation framework | Risk-based assurance approach |
| Can become documentation-heavy | Focuses on critical thinking |
| May use extensive scripted testing | Uses proportionate testing |
| Validation evidence is central | Objective evidence remains central |
| Can be inefficient if poorly implemented | Designed to focus effort where risk is highest |
21 CFR Part 11 vs EU Annex 11
| 21 CFR Part 11 | EU Annex 11 |
| U.S. FDA regulation | EU GMP guidance |
| Focuses on electronic records/signatures within scope | Broad computerized-system lifecycle controls |
| Validation | Risk-based validation |
| Access/security controls | Security and access |
| Audit trails | Audit trails |
| Electronic signatures | Electronic signatures |
| Record retention | Data storage/archiving |
| Applicable U.S. requirements determine scope | Applies to GMP-regulated computerized systems |
They should not be treated as interchangeable documents.
IQ vs OQ vs PQ/UAT
| IQ | OQ | PQ/UAT |
| Installation | Operation | Intended use |
| Components/version | Functional behavior | Business process |
| Infrastructure | Security | End-to-end workflow |
| Configuration | Calculations | User scenarios |
| Documentation | Interfaces | Performance/use |
Validation vs Qualification
Validation is the broader lifecycle concept demonstrating that a system/process is suitable for intended use.
Qualification is commonly used for documented evidence that equipment, facilities, utilities or relevant system elements meet predetermined requirements.
The terminology should follow the applicable regulatory framework and company procedures.
ALCOA vs ALCOA+
| ALCOA | ALCOA+ |
| Attributable | ALCOA + Complete |
| Legible | Consistent |
| Contemporaneous | Enduring |
| Original | Available |
| Accurate |
URS vs FS vs DS
| URS | FS | DS/Configuration |
| What users need | How functions should behave | How the system is designed/configured |
| User-focused | Functional | Technical/configuration-focused |
| Testable | Testable | Testable/reviewable |
Verification vs Validation
Verification: Did we build/configure the system correctly against defined requirements?
Validation: Does the complete solution provide appropriate documented assurance that it is fit for its intended use?
35. Recommended External Authoritative References
Use authoritative sources rather than generic SEO websites.
FDA
FDA resources covering data integrity, CGMP and computerized-system assurance should be primary references for U.S.-specific claims.
FDA Data Integrity and Compliance With Drug CGMP
European Commission
Use EudraLex Volume 4 and Annex 11 for EU GMP requirements.
European Commission — EudraLex Volume 4
ICH
ICH Q9(R1) is relevant to quality risk management, while ICH Q10 provides the Pharmaceutical Quality System framework.
PIC/S
PIC/S PI 041-1 is a useful inspectorate-oriented reference for data management and integrity. PIC/S also published a revised Qualification and Validation recommendation, PI 006-4, in July 2026, with entry into force scheduled for October 1, 2026.
WHO
WHO publications provide useful international perspectives on data integrity, computerized systems and data management.
WHO — Medicines Quality Assurance
ISPE/GAMP 5
GAMP 5 should be presented as industry guidance/best practice, not a regulation. The second edition emphasizes risk-based decisions, supplier input, efficient testing and critical thinking.
36. Top 20 CSV Audit and Interview Questions
1. What is GxP CSV?
GxP CSV is the lifecycle-based process of establishing documented confidence that a computerized system supporting a regulated process is fit for its intended use and appropriately controlled.
2. What is the purpose of CSV?
To provide objective evidence that the computerized system operates as intended and supports product quality, patient safety, data integrity and applicable regulatory requirements.
3. What is GAMP 5?
GAMP 5 is ISPE industry guidance providing a risk-based lifecycle approach for compliant GxP computerized systems.
4. Is GAMP 5 mandatory?
GAMP 5 itself is not a regulation. It is industry guidance that organizations may use to structure their computerized-system lifecycle and validation practices.
5. What is 21 CFR Part 11?
It establishes FDA requirements for electronic records and electronic signatures within its applicable scope.
6. What is EU Annex 11?
EU GMP Annex 11 provides requirements and expectations for computerized systems used in GMP-regulated activities.
7. What is ALCOA+?
A framework for maintaining trustworthy data: Attributable, Legible, Contemporaneous, Original, Accurate, plus Complete, Consistent, Enduring and Available.
8. What is a GxP impact assessment?
An assessment used to determine whether and how a computerized system supports GxP activities and what level of control/validation is appropriate.
9. What is risk-based validation?
A validation strategy in which effort, documentation and testing are proportionate to intended use and risk.
10. What is the difference between IQ, OQ and PQ?
IQ addresses installation; OQ addresses operation/functionality; PQ/UAT addresses intended use in the business environment.
11. What is a Traceability Matrix?
A controlled mapping demonstrating that requirements are addressed by appropriate specifications and verification/testing evidence.
12. What is an audit trail?
A system-generated record that captures defined actions or changes associated with electronic records.
13. What is periodic review?
A documented assessment confirming that the computerized system remains suitable, controlled and fit for intended use.
14. What is change control?
A formal process for assessing, approving, implementing and verifying changes to a controlled system.
15. What is CSV vs CSA?
CSV traditionally describes computerized-system validation; CSA emphasizes risk-based assurance and critical thinking to focus evidence and testing where risk warrants it.
16. How do you validate SaaS?
Assess intended use, supplier, configuration, GxP functions, data integrity, security, interfaces, records, change management and supplier evidence, then perform proportionate verification.
17. How do you validate data migration?
Define mapping, transformation rules, acceptance criteria and reconciliation, then verify completeness, accuracy and integrity using risk-based testing.
18. How do you handle a CSV deviation?
Contain the issue, document it, assess impact, investigate root cause, evaluate product/data impact, determine CAPA and document resolution according to the QMS.
19. How do you determine testing scope?
Use intended use, risk assessment, criticality, complexity, configuration/customization, supplier evidence and applicable requirements.
20. What evidence would you show an auditor?
Typically:
- GxP assessment
- URS
- Risk assessment
- Validation plan
- Specifications
- Test evidence
- Traceability
- Deviations
- Validation summary
- Change controls
- Periodic review
- Access records
- Audit-trail controls
- Backup/restore evidence
- Training records
37. Frequently Asked Questions — GxP CSV Compliance
What is GxP CSV?
GxP CSV is the lifecycle process of establishing documented confidence that computerized systems used in regulated activities are fit for intended use and appropriately controlled.
Why is CSV important in pharma?
CSV helps ensure that computerized systems supporting manufacturing, laboratory, quality and other regulated processes operate reliably and protect product quality, patient safety and data integrity.
What is GAMP 5?
GAMP 5 is ISPE industry guidance for applying a risk-based lifecycle approach to GxP computerized systems.
Is GAMP 5 mandatory?
No. GAMP 5 is industry guidance, not a pharmaceutical regulation. Organizations may use it as a best-practice framework.
What is 21 CFR Part 11?
21 CFR Part 11 establishes FDA requirements for electronic records and electronic signatures within its applicable scope.
What is EU Annex 11?
EU GMP Annex 11 provides requirements for computerized systems used as part of GMP-regulated activities.
What is ALCOA+?
ALCOA+ describes principles for maintaining trustworthy data: attributable, legible, contemporaneous, original, accurate, complete, consistent, enduring and available.
What is the difference between CSV and CSA?
CSV is the traditional term for computerized-system validation, while CSA emphasizes a more risk-based assurance approach. CSA does not mean that organizations can eliminate appropriate validation or evidence.
Which systems require CSV?
Systems supporting GxP processes or affecting GxP data may require validation or appropriate assurance. The scope and rigor should be based on intended use and risk.
Is SAP a GxP system?
SAP is not automatically GxP simply because it is SAP. Specific processes, configurations, data and intended uses determine GxP relevance.
Does SaaS require CSV?
A SaaS application can require appropriate validation or assurance when used for GxP purposes. Supplier evidence may be leveraged, but the organization must assess its own intended use and risks.
What documents are required for CSV?
Common documents include a GxP assessment, validation plan, URS, risk assessment, specifications, testing evidence, traceability and validation summary. The exact package should be risk-based.
What is a Traceability Matrix?
It maps requirements to risks, specifications and verification/testing evidence to demonstrate coverage.
What is periodic review?
Periodic review confirms that the system continues to operate in a controlled, compliant and validated state.
What is audit-trail review?
Audit-trail review is the risk-based examination of relevant system-generated records to identify inappropriate or unexplained activities and changes.
38. Conclusion
Effective GxP CSV compliance is not about producing the largest possible validation package.
It is about establishing and maintaining appropriate confidence that a computerized system is:
- Fit for intended use
- Appropriately tested
- Properly controlled
- Secure
- Traceable
- Reliable
- Data-integrity compliant
- Maintained throughout its lifecycle
The modern philosophy can be summarized as:
Risk-based thinking + appropriate testing + reliable documentation + data integrity + controlled lifecycle + effective governance
Organizations should concentrate their resources on computerized-system functions that can affect:
- Patient safety
- Product quality
- Data integrity
- Regulatory compliance
At the same time, organizations should avoid the opposite extreme of treating every software function as equally critical.
A mature CSV program therefore begins with intended use and GxP impact, applies quality risk management, leverages appropriate supplier evidence, defines meaningful requirements, performs proportionate verification, maintains traceability and continues to control the system after release.
This is particularly important as pharmaceutical companies move toward:
- Cloud platforms
- SaaS
- MES
- LIMS
- Digital Quality Systems
- Integrated ERP environments
- IoT
- AI/ML
- Pharma 4.0
- Automated testing
The future of computerized-system compliance is not simply “more validation.”
It is better assurance, better risk management and better control of critical digital processes and data.
Regulatory Accuracy Notes
This article deliberately makes several distinctions that are important for an audit-quality publication:
- GAMP 5 is not a regulation. It is industry guidance from ISPE.
- 21 CFR Part 11 should not be reduced to audit trails. Electronic records/signatures compliance involves a broader control framework.
- EU Annex 11 applies to computerized systems used in GMP-regulated activities and uses a lifecycle/risk-management approach.
- Not every computerized system requires the same validation effort. Risk, intended use, complexity and GxP impact determine the appropriate approach.
- IQ/OQ/PQ should not be treated as universally mandatory software stages. Verification should be appropriately designed for the system and risk.
- CSA does not make CSV obsolete. Modern risk-based assurance should be applied in a way consistent with applicable pharmaceutical regulations and organizational procedures.
- FDA’s 2026 CSA guidance is specifically directed toward software used in medical-device production and quality management systems, so it should not be presented as a direct pharmaceutical-GMP replacement for CSV.
- The European Commission’s revised Annex 11 material discussed in 2025 is a draft/revision initiative, not something that should be presented as the current operative Annex 11 requirement.
- PIC/S published revised qualification/validation recommendations PI 006-4 in July 2026, with entry into force scheduled for October 1, 2026. This is worth monitoring when maintaining a current validation program.
- ICH Q9(R1) provides the quality-risk-management framework, while ICH Q10 provides a Pharmaceutical Quality System model.
Primary authoritative references
- FDA — Data Integrity and Compliance With Drug CGMP: Questions and Answers.
- FDA — Computer Software Assurance for Production and Quality Management System Software.
- European Commission — EudraLex Volume 4 / Annex 11.
- European Commission — 2025 Annex 11 revision consultation.
- ICH Q9(R1) — Quality Risk Management.
- ICH Q10 — Pharmaceutical Quality System.
- WHO — Data Integrity and computerized data-management principles.
- PIC/S — PI 041-1 Data Management and Integrity.
- ISPE GAMP 5, Second Edition.
About Author
Ramesh Palav is a pharmaceutical professional with 21+ years of experience in pharmaceutical manufacturing, qualification, validation, GMP, CSV and quality compliance. He combines hands-on OSD manufacturing expertise with knowledge of GxP, Data Integrity, 21 CFR Part 11, GAMP 5 and digital pharmaceutical systems. Through Pharma Manufacturing Hub, he shares practical insights to help pharmaceutical professionals strengthen compliance, operational excellence and career development.
Published on: 23/08/2026
