Validation (computerised system validation, CSV)
Validation, in the regulated life sciences context, is the documented process of establishing that a computerised system, process or method consistently performs as intended and fit for its purpose. Computerised system validation (CSV) applies to systems used in GxP activities: EDC and eCRF platforms, eCOA and IRT systems, safety databases, eTMF, laboratory and manufacturing systems, and increasingly AI-based tools. The regulatory bases are FDA 21 CFR Part 11 on electronic records and signatures, EU GMP Annex 11, the EMA guideline on computerised systems and electronic data in clinical trials (2023), ICH E6(R3) on GCP and, for devices, IEC 62304 and ISO 13485. ISPE's GAMP 5 (second edition, 2022) is the industry methodology, and the FDA's computer software assurance (CSA) guidance (2025) promotes a risk-based, critical-thinking approach over exhaustive documentation.
A validation package typically includes a validation plan, user requirements, functional and design specifications, risk assessment, supplier assessment, installation, operational and performance qualification (or agile equivalents), traceability matrix, test evidence, deviations, a validation report and procedures for change control and periodic review to keep the system in a validated state. For cloud software-as-a-service used in trials, sponsors rely on the vendor's validation and perform their own configuration and user acceptance testing, with the division of responsibilities recorded in the quality agreement.
Validation and data protection overlap substantially. Audit trails, access control, electronic signatures, data integrity (ALCOA+), backup and disaster recovery are simultaneously Part 11 requirements and Art. 32 GDPR security measures; user requirement specifications are the natural place to state data protection by design requirements such as pseudonymisation architecture, field-level access restrictions, minimisation of identifiers and retention configuration; and the DPIA and the validation risk assessment should reference each other. For AI systems, AI Act requirements on accuracy, robustness, logging and human oversight extend the validation scope. Vendor validation evidence is a standard item in iliomad's vendor assessments and quality assurance work.
