Computerised System Validation: A Risk-Based Lifecycle That Survives Inspection

Almost every GxP decision a company makes today rests on data produced, stored or transformed by a computerised system. Regulators have responded by treating those systems as part of the quality system itself — not as IT infrastructure sitting quietly behind it. Computerised system validation (CSV) is how you demonstrate that a system does what you say it does, consistently, for as long as you use it.

Validation is a lifecycle, not a project

The most common structural mistake is treating validation as a one-off event that ends when the qualification report is signed. The ISPE GAMP 5 Guide, whose second edition was published in 2022, frames validation as a lifecycle that begins with a clear statement of intended use and ends only when the system is retired and its data are migrated or archived.

In practice that lifecycle has recognisable stages:

  • A user requirements specification that describes what the system must do, written by the people who will use it
  • A supplier assessment proportionate to the risk and to what the supplier has already done
  • Specification and configuration, with testing focused on the functions that matter
  • Release into operational use under change control, with defined roles and access
  • Periodic review, incident and deviation handling, and backup and restore verification
  • Decommissioning, with a documented plan for record retention and readability

Risk assessment is what makes the effort defensible

GAMP 5 keeps its familiar distinction between infrastructure software, non-configured products, configured products and bespoke applications — but its second edition is explicit that categorisation is not a checklist. Categories inform the approach; they do not replace judgement. The second edition places far more weight on critical thinking by subject matter experts, and expands its treatment of cloud services, agile development, automated testing tools and machine learning.

The practical consequence is that a spreadsheet performing a GxP calculation may need more scrutiny than a large commercial platform used for a low-risk purpose. Effort should follow risk to patient safety, product quality and data integrity — and the rationale for that effort should be written down, because it is the first thing an inspector will ask about.

What inspectors actually look for

Findings in this area are rarely about missing test scripts. They cluster around the gap between the validated state and the operational reality:

  • Systems in production with configuration changes that never went through change control
  • Shared or generic accounts that make records unattributable
  • Administrator rights held by the same people who generate the data
  • Audit trails switched on but never reviewed
  • Backups taken but restoration never tested
  • Interfaces between systems validated individually but never end to end

The Annex 11 revision raises the bar

On 7 July 2025 the European Medicines Agency and PIC/S published for consultation a comprehensive revision of EU GMP Annex 11 on computerised systems, alongside a revised Chapter 4 on documentation and an entirely new Annex 22 on artificial intelligence. The consultation closed on 7 October 2025 and final texts are expected from mid-2026.

The draft expands Annex 11 several times over and strengthens expectations on validation, audit trail review, supplier oversight, and identity and access management. Most significantly, it addresses cybersecurity as a core GMP concern for the first time. Companies whose validation packages were built against the current five-page annex should assume the evidentiary bar will rise, and should be reviewing their system inventory and risk assessments now rather than after the final text lands.

How PQRA helps

PQRA supports pharmaceutical companies, device manufacturers and healthcare innovators in building computerised system validation that is proportionate and defensible: system inventories and risk classification, validation master plans, URS and specification review, supplier assessments, periodic review programmes, and remediation of legacy systems ahead of inspection. We work with your existing quality system rather than imposing a parallel one.

If you are preparing for an inspection, onboarding a new platform, or reassessing your validation approach ahead of the revised Annex 11, get in touch with our team.

CATEGORIES:

Uncategorized

Tags:

No responses yet

Αφήστε μια απάντηση

Η ηλ. διεύθυνση σας δεν δημοσιεύεται. Τα υποχρεωτικά πεδία σημειώνονται με *