Services/CSV Assessments

Data Integrity & CSV

Computer System Validation Assessments

CSV assessments aligned to GAMP 5 methodology, FDA 21 CFR Part 11 and EU Annex 11, covering legacy system validation reviews, SaaS qualification and IT vendor quality assessments.

Executive Overview

Computer system validation is the documented evidence that a computerised system does what it is designed to do consistently and correctly in a regulated environment. FDA 21 CFR Part 11 and EU GMP Annex 11 establish the regulatory requirements for electronic records and electronic signatures used in GxP-regulated activities. Both regulations require that computerised systems are validated and that organisations maintain documented evidence of that validation throughout the system lifecycle.

GAMP 5 (Good Automated Manufacturing Practice, 5th Edition) provides the industry-recognised risk-based framework for planning and executing computer system validation activities. It categorises systems by complexity and novelty (Categories 1 through 5) and scales validation effort accordingly. The objective is to apply appropriate validation rigour to systems that carry genuine regulatory risk while avoiding disproportionate effort on low-risk infrastructure.

Sthira Assure CSV assessments evaluate your existing validation documentation, identify gaps against GAMP 5 methodology and regulatory requirements, assess the validation status of priority systems and provide remediation recommendations. We also assess SaaS and cloud-based systems, increasingly critical in regulated environments, against the specific requirements of Annex 11 and Part 11, including vendor audit programmes and supplier quality assessments.

Regulatory Frameworks

  • GAMP 5 (2nd Edition, 2022)
  • FDA 21 CFR Part 11
  • EU GMP Annex 11
  • PIC/S PI 011-3
  • MHRA Guidance
  • ICH Q10

CSV Assessment Needed?

Speak with our team about your system landscape and validation gaps.

Get in Touch

Common Compliance Risks

Retrospective Validation Backlogs

Many organisations have systems in productive regulated use without adequate validation documentation. Regulatory inspectors assess the validation status of computerised systems used in GxP-regulated activities and expect to see documented evidence that systems have been validated as fit for purpose. Retrospective validation programmes must be prioritised by risk and executed systematically.

SaaS and Cloud System Qualification Gaps

The pharmaceutical industry has accelerated adoption of cloud-hosted and SaaS solutions for laboratory management, document control and manufacturing execution. The regulatory requirements of FDA 21 CFR Part 11 and EU Annex 11 apply equally to these systems. Many organisations have deployed SaaS solutions without adequate vendor assessment, user requirements documentation or qualification testing.

Change Control for Validated Systems

Changes to validated systems, including software updates, configuration changes, infrastructure migrations and user access changes, must be assessed for impact on validated state and managed through controlled change control processes. Organisations frequently apply software updates without validation impact assessment, invalidating the validated status of systems that support critical GxP operations.

Incomplete Risk-Based Documentation

GAMP 5 provides a risk-based framework for CSV that scales documentation effort to system criticality and complexity. Many organisations either over-document low-risk systems or, more significantly, under-document critical systems, applying a one-size-fits-all approach that does not reflect the actual risk profile of different computerised systems in their GxP environment.

Scope of Services

GAMP 5 category-based system assessments
Validation documentation gap reviews (IQ, OQ, PQ)
SaaS and cloud-based system qualification
Electronic signature and audit trail compliance assessments
IT vendor quality management system assessments
Software Development Lifecycle (SDLC) reviews
Change control and patch management assessments
User requirements specification and risk assessment reviews

Typical Deliverables

Computerised System Inventory and Risk Classification Matrix
CSV Gap Assessment Report with Risk-Rated Findings
Remediation Priority Plan with Implementation Timeline
SaaS Vendor Qualification Package
IT Vendor Quality System Assessment Report
CSV Programme Design and SOP Framework
Electronic Records and Signatures Compliance Assessment
Validation Status Report for Regulatory Review

Frequently Asked Questions

What is GAMP 5 and how does it affect our validation approach?

GAMP 5 (Good Automated Manufacturing Practice, 5th Edition) is the industry standard for risk-based computer system validation in regulated environments. It categorises computerised systems by complexity and novelty — from Category 1 (infrastructure) through Category 5 (custom developed software) — and scales validation effort accordingly. A risk-based approach under GAMP 5 avoids disproportionate effort on low-risk systems while ensuring that critical GxP systems receive adequate validation rigour. Regulatory authorities accept GAMP 5 as the appropriate methodology for pharmaceutical computer system validation.

Do SaaS systems require the same validation documentation as on-premise systems?

SaaS systems require validation that is equivalent in compliance outcome but different in approach. Customers cannot access source code, control update schedules or qualify infrastructure directly. Validation relies heavily on vendor-provided evidence — SOC 2 reports, penetration test summaries, validation summary reports — supplemented by customer-controlled testing of GxP-critical functions and quality agreements that define vendor responsibilities. GAMP 5 Second Edition addresses SaaS qualification specifically and provides a risk-based framework appropriate to these system categories.

How should we approach retrospective validation of legacy systems?

Retrospective validation of systems in regulated use without adequate existing documentation should begin with a risk assessment of each system's GxP impact. High-risk systems — those directly generating or controlling regulated data — require prioritised remediation. A retrospective validation programme typically involves a gap assessment of existing documentation against GAMP 5 requirements, development of a remediation plan, and systematic completion of missing validation records including risk assessments, configuration verification evidence and retrospective testing where required.

What constitutes adequate audit trail functionality under 21 CFR Part 11?

Under 21 CFR Part 11, computer systems used to create, modify, maintain or transmit electronic records must provide secure, computer-generated time-stamped audit trails that record operator entries and actions that create, modify or delete electronic records. The audit trail must capture the date and time of events, the original and new values of any changed data and be retained for the same period as the records it protects. Audit trails must not be modifiable by users and must be available for regulatory review.

Discuss Your CSV Requirements

Contact our team to assess your computerised system landscape and identify priority validation gaps.