Skip to main content
v2026.11,772 entries · CC-BY 4.0
Laboratory Compliance & Quality

Computer System Validation & Data Integrity

Regulated research increasingly runs on electronic systems, and those systems have to meet specific regulatory requirements for data integrity. This sub-cluster covers 21 CFR Part 11 (the FDA regulation governing electronic records and electronic signatures), computer system validation (CSV — the documented process of proving a system performs as intended before it is relied on for regulated work), audit trails, and the ALCOA+ data-integrity principles (Attributable, Legible, Contemporaneous, Original, Accurate, plus Complete, Consistent, Enduring, Available). Pages here are aimed at researchers and lab managers who need to understand what these requirements mean in practice, not just cite them.

Guides

GxP Spreadsheet Validation: Controls, Limits, and When to Replace It

Validating an Excel spreadsheet used for GxP calculations: cell protection, formula verification, version control, why Excel’s native audit trail falls short, and when the right answer is to replace the spreadsheet rather than keep validating it.

Installation Qualification (IQ) Protocol: Structure, Evidence, and Deviation Handling

What an IQ protocol has to prove, section by section: prerequisites, as-built verification, utility checks, software/firmware version capture, and the risk-based logic for whether a deviation needs re-execution or a documented note.

GAMP 5 Second Edition: What Changed From the First Edition

GAMP 5 Second Edition (2022) replaced the 2008 first edition with the same risk-based CSV framework, but a genuinely different validation philosophy: critical, risk-based evaluation of evidential records instead of paper deliverables, new appendices for agile, AI/ML, blockchain and infrastructure, and explicit alignment with FDA’s Computer Software Assurance guidance.

Validation Summary Report: What It Must Contain to Close a Validation

What a validation summary report (VSR) needs to contain to actually close a validation: deviation disposition, how unresolved items are carried forward defensibly under Annex 15’s conditional-approval path, traceability closure back to the URS, and the release statement itself.

Audit Trail Review Procedure: A Risk-Based SOP for GxP Systems

A practical, risk-based audit trail review SOP: which systems need routine review, how often, reviewer independence, what counts as a documented review, and how to handle systems whose trails cannot be reviewed line by line.

What Is Data Integrity?

A plain-language guide to what data integrity means for regulated research and lab data, the ALCOA+ principles, and how it relates to data quality, security, and 21 CFR Part 11.

Data Integrity in Pharmaceutical Manufacturing

Where manufacturing-execution data integrity actually breaks: EBR/MES batch records, PLC/SCADA and historian data, and electronic batch review that has to reconcile both.

Chromatography Data System Audit Trails: What Must Be Captured, and Review by Exception

What a chromatography data system (CDS) audit trail specifically has to capture — injections, reprocessing, integration parameter changes — and how a risk-based review-by-exception programme is built and documented.

21 CFR Part 11 Compliance Checklist: A Clause-by-Clause Self-Assessment

An itemized 21 CFR Part 11 self-assessment checklist for a system you already run: what each clause (audit trails, e-signature binding, access controls, validation documentation) requires and the objective evidence to have on hand.

FDA’s Data Integrity Guidance for cGMP: The 2018 Q&A, Applied

FDA’s December 2018 Data Integrity Q&A guidance, mapped to the CFR sections it actually draws from: the five ALCOA attributes in FDA’s own words (not ALCOA+), the ALCOA-to-CFR crosswalk, audit trail review frequency and ownership, blank-form control, and what counts as an adequately remediated finding.

User Requirements Specification (URS) for GxP Systems

What a GxP user requirements specification must contain — functional, non-functional, and regulatory requirements — and how each requirement traces forward to OQ/PQ test scripts.

Computerised System Validation Under EU GMP: The Annex 15 and Annex 11 Lifecycle

How EU GMP Annex 15 and Annex 11 define the computerised system validation lifecycle end to end, from system inventory and URS through periodic evaluation and retirement, and where it structurally diverges from the FDA-centric CSV/GAMP 5/CSA framing most guidance defaults to.

Validation Master Plan (VMP) for a Regulated Laboratory: Scope, System Inventory, and Periodic Review

A validation master plan is the governing document above individual qualification exercises. This guide applies EU GMP Annex 15 and Annex 11 to a regulated laboratory rather than a manufacturing site: building the system inventory, assessing GxP criticality, assigning validation strategy by GAMP 5 category, defining acceptance-criteria rules, and setting periodic-review and requalification triggers.

Computer System Validation (CSV): GAMP 5, IQ/OQ/PQ, and 21 CFR Part 11

What computer system validation actually requires for regulated laboratory systems: the GAMP 5 risk-based approach, GAMP software categories and the classification judgment calls that actually arise, the IQ/OQ/PQ qualification sequence and the evidence each stage produces, how CSV relates to (but differs from) 21 CFR Part 11, FDA’s Computer Software Assurance direction, and a validation-deliverables checklist.

Referenced across the research world

University of Cambridge logoColumbia University logoCrossref logoUniversity of Edinburgh logoHarvard University logoUniversity of Oxford logoPrinceton University logoStanford School of Medicine logoUniversity College London logoORCID logoUniversity of Cambridge logoColumbia University logoCrossref logoUniversity of Edinburgh logoHarvard University logoUniversity of Oxford logoPrinceton University logoStanford School of Medicine logoUniversity College London logoORCID logo
  • University of Cambridge logo
  • Columbia University logo
  • Crossref logo
  • University of Edinburgh logo
  • Harvard University logo
  • University of Oxford logo
  • Princeton University logo
  • Stanford School of Medicine logo
  • University College London logo
  • ORCID logo

View CASRAI adoption →

Regulatory Radar

Stop finding out after the fact

$29/month, cancel anytime. Daily digest updates from our analysis, a dashboard holding the same items, and a cited assistant for everything they raise.

  • Federal Register, Federal Register+, Grants.gov, Regulations.gov, NSF News, UKRI, plus CASRAI’s own published content.
  • 72,264 indexed passages, and every answer cites the ones it drew on.