For Quality, Compliance, IT and validation professionals
Practical CSV & CSA Guidance
Practical guides, examples and tools for software validation and assurance. Understand the relevant requirements, plan risk-based testing, and assess the use of AI in regulated work.
What are you working on?
Browse all practical guides →Choose the activity you need help with.
Assess a system
Define intended use, assess GxP impact and identify risk.
Plan testing
Select testing and evidence based on the risk of failure.
Review a change
Assess what changes, what could be affected and what to verify.
Maintain the validated state
Review access, incidents, periodic reviews and ongoing changes.
Featured tools
View all tools →System Assessment
Assess intended use, GxP impact and the proposed validation approach.
Open tool →PlanRequirements & Test Planner
Identify requirements, risk-based testing and the evidence to retain.
Open tool →ReviewDocument & Results Review
Review validation documents, test results and open issues.
Open tool →Practical articles and examples
View all articles →AI Assurance ·
Is your AI application ready for GxP use?
Consider intended use, testing, human review and the evidence needed before release.
Supplier & SaaS · Publication date not recorded
Maintaining the validated state when SaaS software changes
Assess supplier updates, affected functions and the testing needed for continued use.
Supplier & SaaS · Publication date not recorded
What supplier testing covers, and what you still need to verify
Assess which supplier evidence supports your intended use and where additional verification is needed.
Regulations, standards and guidance
Browse all references →Understand what applies to your work and how it relates to practical controls and evidence.
- FDA computer software assurance (CSA) →Medical-device manufacturers assuring software used in production or their quality management system.
- 21 CFR Part 11 →Electronic records and signatures within FDA Part 11 scope, tied to the underlying required records.
- FDA QMSR / 21 CFR Part 820 →Finished medical-device manufacturers and the operations within Part 820 scope.
- EU GMP Annex 11 →Computerised systems supporting activities in the applicable EU pharmaceutical GMP context.
- ISO 13485:2016 →Organizations performing medical-device lifecycle activities or related services.
Share your experience
How have you handled this in your organisation? Ask a question, suggest a topic, or share a practical example that could help another Quality or Compliance professional.