# Software Change Impact Assessment

Version 1.0 | CSVtoCSA practitioner template | Updated 12 September 2026

## Purpose

Determine affected GxP functions, risk, regression scope, readiness, and release conditions for a software or configuration change.

## When to use

For planned, supplier-managed, major, minor, and emergency software changes.

## Instructions

- Define the specific system, service, change, population, and intended use.
- Complete each field from available records and accountable interviews; record unknowns rather than guessing.
- Link conclusions to affected GxP functions, failure scenarios, controls, evidence, and approval.
- Adapt the structure to the organization’s approved procedures and document-control process.

## Blank template

1. Change and reason

   Response: 

2. Approved intended use

   Response: 

3. Affected GxP functions

   Response: 

4. Configuration impact

   Response: 

5. Interface and data impact

   Response: 

6. Electronic record and signature impact

   Response: 

7. Security and access impact

   Response: 

8. Failure scenarios and controls

   Response: 

9. Existing evidence

   Response: 

10. Testing and regression scope

   Response: 

11. Documentation and training

   Response: 

12. Release, monitoring, and approval

   Response: 

## Completed fictional example

The example below is teaching material, not an executed or approved validation record.

1. Change and reason

   Fictional eQMS routing-engine update required by supplier release 8.5

2. Approved intended use

   Create, route, approve, sign, retain, and export CAPA records

3. Affected GxP functions

   Configured routing and signed export

4. Configuration impact

   Site and severity branch rules

5. Interface and data impact

   No schema change; open legacy records require transition check

6. Electronic record and signature impact

   Verify signer, meaning, time, record revision, and export

7. Security and access impact

   No role model change; challenge unauthorized transition

8. Failure scenarios and controls

   Approval bypass controlled by server-side transition and Quality review

9. Existing evidence

   Supplier standard regression and release note accepted for unchanged engine functions

10. Testing and regression scope

   Targeted branch, legacy state, unauthorized transition, signature, and interruption tests

11. Documentation and training

   Configuration specification and support runbook updated; no end-user procedure change

12. Release, monitoring, and approval

   Conditional on deviation closure; seven-day exception monitoring; Quality approval

## Use and limitations

Adapt this template to the applicable regulation, approved validation procedure, document-control process, risk method, and approval roles. CSVtoCSA does not present this template as a universally required validation record.
