
Computer Systems Validation × FDA × AI
Computer Systems Validation, GAMP 5, and 21 CFR Part 11: The Stack Life Science Still Runs
- Computer Systems Validation
- GAMP 5
- 21 CFR Part 11
- ALCOA+
- IQ OQ PQ

Computer Systems Validation is how an FDA-regulated firm proves a GxP system is fit for intended use. GAMP 5 Second Edition, 21 CFR Part 11, EU Annex 11, ALCOA+, data integrity, URS, FS, DS, IQ, OQ, PQ, traceability matrix, change control, periodic review — these are not a glossary. They are the job. A general SAP consultant “doing validation” is how a 483 writes itself.
Intended use must be written so a tester can fail the system. Category 3, 4, and 5 thinking from GAMP decides how much you build versus configure versus code. Part 11 wants audit trail, operational checks, and e-sign that is more than a checkbox. ALCOA+ wants attributable, legible, contemporaneous, original, accurate — plus complete, consistent, enduring, available. If the SOP describes a system that was sold and the floor is running a system that was built, you are not validated. You are documented.
The challenges that are unique, not generic
A password-field script executed fourteen times is not quality. An audit trail that nobody reviews is not Part 11. A change control that starts after the transport is not change control. Periodic review that is a calendar invite is not review. SR Soft staffs CSV leads who have sat through an inspection question on data integrity, paired with the module expert who built the thing.
- URS drift — the live process no longer matches the signed intended use
- GAMP category inflation — everything treated as custom code, or nothing
- Part 11 audit trails that are on but unread
- Access and SoD that Basis configured and QA never challenged
- SOPs that describe the demo, not the transport

- 01
Intended use in one page
A tester can fail it. A nurse manager can recognize it.
- 02
Risk and category
GAMP 5, not a feeling. High-risk gets challenge. Low-risk gets assurance.
- 03
Traceability matrix
URS to test. Gaps are findings, not footnotes.
- 04
IQ / OQ / PQ with owners
Not a shared spreadsheet. Named execution, named review.
- 05
Part 11 walkthrough
Audit trail review as a SOP, not a screenshot.
- 06
Periodic review calendar
Triggered by change and by time. Both.
Inspection findings we staff against
Fortune 500 pharma and CDMOs fail CSV when they hire a generalist and a binder. We pair the module expert with a validation lead. We file visas for both. S/4 quality, batch, WM/EWM in scope — the system is in the intended use, not “SAP” as a word.
What a protocol actually contains
A URS that a tester can fail. A risk assessment that cites process harm, not “GxP = high.” A traceability matrix that does not have orphan requirements. IQ that proves the installed thing is the specified thing. OQ that challenges the intended use. PQ that uses real roles and real data shapes. A Part 11 walkthrough that reviews the audit trail as a SOP, not a screenshot. Periodic review triggered by time and by change. If any of those objects is a template with the client name find-replaced, you are not validated.
Access and SoD are validation. A Basis transport that grants SAP_ALL to a contractor is a finding waiting for an investigator. We challenge access in OQ. SOPs must match the transport, not the demo. Fortune 500 pharma that treat CSV as a binder project will fail the floor. We pair the module expert with a CSV lead who has been in the room.
