# Functional Risk Assessment Template

Version 1.0 | CSVtoCSA practitioner template | Updated 12 September 2026

## Purpose

Link each important GxP function to a failure scenario, process effect, potential consequence, controls, and required evidence.

## When to use

After intended use and requirements are sufficiently understood and before finalizing test depth.

## Instructions

- Assess functions separately rather than assigning one risk to the whole system.
- Describe observable failure and process effect.
- Credit only controls that address the failure and can be shown to work.
- Use the remaining risk and uncertainty to select evidence.

## Blank template

1. GxP function or requirement

   Response: 

2. Failure scenario

   Response: 

3. Process effect

   Response: 

4. Potential impact

   Response: 

5. Existing controls

   Response: 

6. Detectability

   Response: 

7. Risk rationale

   Response: 

8. Mitigation or evidence needed

   Response: 

9. Residual risk

   Response: 

10. Owner

   Response: 

## Completed fictional example

The example below is teaching material, not an executed or approved validation record.

1. GxP function or requirement

   CAPA closure gate; URS-014

2. Failure scenario

   Record closes before required effectiveness approval

3. Process effect

   Open corrective action is represented as complete

4. Potential impact

   Ineffective action may remain undetected

5. Existing controls

   Server-side transition rule and role authorization

6. Detectability

   Daily exception report detects closure after the event

7. Risk rationale

   High consequence; preventive gate is required

8. Mitigation or evidence needed

   Scripted authorized and unauthorized transitions plus exploratory interruption and API paths

9. Residual risk

   Unexpected alternate integration path

10. Owner

   Quality Systems Owner

## Use and limitations

Adapt this template to the applicable regulation, approved validation procedure, document-control process, risk method, and approval roles. CSVtoCSA does not present this template as a universally required validation record.
