Life sciences software: validated state, not just tested state
Industry & Context · Life Sciences
GxP software must prove it stays in a validated state over its operating life: CSV, or its risk-based successor CSA, backs that with a validation summary report, ALCOA+ applies to 100% of GxP records, and 21 CFR Part 11 adds an audit trail for the records kept electronically.
What makes GxP software engineering different?
GxP software must prove it stays in a validated state over its operating life, not just that it passed a one-time test. CSV or its risk-based successor CSA backs that with a validation summary report, and 21 CFR Part 11 adds an audit trail for electronic records.
GxP-regulated software carries an obligation ordinary business software doesn't: proving the system stays in a validated state over its operating life, not just that it passed a one-time test. Computer System Validation (CSV) — or its risk-based descendant, Computer Software Assurance (CSA) — and ALCOA+ data-integrity discipline (attributable, legible, contemporaneous, original, accurate, plus complete, consistent, enduring, and available) are the two obligations that make life-sciences software engineering distinct from regulated software in general.
Validated state is a claim about the system over time, not at a moment
A conventional software test suite answers "did this pass, right now." Computer System Validation answers a different question: "is there documented evidence this system does what it's intended to do, reliably, for as long as it's in GxP use" — covering installation qualification (IQ), operational qualification (OQ), and performance qualification (PQ), plus a defined revalidation trigger whenever the system changes.
CSV vs. CSA: rigor scaled to actual risk
FDA's Computer Software Assurance guidance reframes traditional CSV's uniform, document-heavy rigor as risk-based: a system with direct patient- or product-quality impact still gets full validation rigor, while a lower-risk system (e.g. an internal scheduling tool with no direct GxP impact) can be assured with a lighter, more targeted testing approach — assurance effort scaled to actual risk, not a fixed checklist applied uniformly regardless of what the system actually does.
ALCOA+ — the data-integrity test every GxP record has to pass
| ALCOA+ attribute | What it actually requires |
|---|---|
| Attributable | Who (or what system) recorded the data is identifiable. |
| Legible | The record is readable for its full retention period, not dependent on obsolete software to open. |
| Contemporaneous | Recorded at the time the activity happened, not reconstructed later. |
| Original | The first, or a certified true copy of the first, record — not a re-entered summary. |
| Accurate | Free of error, and any correction is itself traceable. |
| Complete / Consistent / Enduring / Available | The "+" — nothing selectively omitted, internally consistent, durable for the retention period, and retrievable on request (including by an inspector). |
For life sciences teams, 21 CFR Part 11 layers electronic-records/electronic-signatures requirements on top of this — an audit trail, access controls, and signature-record linking — for any of these records kept or submitted electronically, which in practice means nearly all of them.
Engineering reference only. Not formal regulatory counsel. Consult your own quality system and legal counsel for a specific regulatory determination.
Provenance & review state
- Last reviewed
- Sources
-
- 21 CFR Part 11 — U.S. Food and Drug Administration
- FDA Computer Software Assurance for Production and Quality System Software — U.S. Food and Drug Administration
- Ingested from
-