# SaaS Release Assessment Template

Version 1.0 | CSVtoCSA practitioner template | Updated 12 September 2026

## Purpose

Determine whether a supplier release affects approved GxP functions and what evidence or monitoring is required.

## When to use

For scheduled and emergency releases to supplier-controlled multi-tenant services.

## Instructions

- Review the authoritative release information.
- Map changed components to enabled GxP functions and shared dependencies.
- Assess risk, detectability, evidence, and open defects.
- Choose no impact, targeted confirmation, regression, restriction, or escalation.

## Blank template

1. Release and date

   Response: 

2. Authoritative change information

   Response: 

3. Affected GxP functions

   Response: 

4. Configuration and interface exposure

   Response: 

5. Potential failure and impact

   Response: 

6. Supplier evidence

   Response: 

7. Customer evidence needed

   Response: 

8. Decision and rationale

   Response: 

9. Post-release monitoring

   Response: 

10. Reassessment criteria and approval

   Response: 

## Completed fictional example

The example below is teaching material, not an executed or approved validation record.

1. Release and date

   Fictional eQMS 8.4; 15 September 2026

2. Authoritative change information

   Dashboard color, routing engine, and export signature block

3. Affected GxP functions

   CAPA route and exported signed record

4. Configuration and interface exposure

   Local site/severity conditions and open legacy records

5. Potential failure and impact

   Approval bypass or incorrect signature association

6. Supplier evidence

   Release note, defect list, standard workflow regression summary

7. Customer evidence needed

   Targeted routing, open-state transition, signature export, and role challenge

8. Decision and rationale

   Approve only after mapping correction and retest; broad platform regression is not justified

9. Post-release monitoring

   Routing exceptions, audit-trail discrepancies, and export complaints for seven days

10. Reassessment criteria and approval

   Critical incident, workflow or identity change, or threshold breach; Quality approval required

## Use and limitations

Adapt this template to the applicable regulation, approved validation procedure, document-control process, risk method, and approval roles. CSVtoCSA does not present this template as a universally required validation record.
