They are a widely used way to structure validation evidence for equipment and computerized systems in GxP environments, rather than a legal requirement in themselves. Regulators expect evidence that a system does what it is supposed to do, with effort proportionate to risk. For software, vendors often provide parts of the documentation, such as a test plan, risk assessment and executed test cases, and the organization confirms that it covers its own intended use.

Why it matters for labeling

Any computerized system used to make or support a labeling decision, including artwork comparison and proofreading software, is within the scope of validation expectations. How much effort is needed depends on the risk, and expectations are moving toward risk-based approaches, such as FDA's Computer Software Assurance guidance and the lifecycle emphasis in the draft revision of EU Annex 11.

Common mistakes

  • Treating validation as a one-time exercise at go-live
  • Relying on a vendor's claim of being validated without seeing the documentation
  • Validating each module of a tool separately when one validation could cover them all
  • Not reviewing validation after significant upgrades

Sources