Skip to content
We now build for Pharma & Life Sciences
ByteFlow Technologies
Insight

Computer System Validation Documentation: What the Pack Must Contain

Dheeraj Sharma · 2026-08-14 · 7 min

Computer System Validation is judged on paper. The system may be a LIMS, an ERP module, a chromatography data system, or a spreadsheet performing a GxP calculation — what an auditor reads is the pack. This is a working guide to what that pack contains, where teams lose time, and what changes when the documents are generated by a system instead of typed in Word.

The document set, by lifecycle phase

A complete pack is not one document. It is a chain where each link references the one before it.

| Phase | Documents | What it establishes | |---|---|---| | Planning | Validation Plan, Validation Strategy, Validation Summary Report | Scope, roles, acceptance criteria, and the closing statement | | Requirements | URS, Functional Spec, Design Spec, Configuration Spec | What the system must do, in testable statements | | Risk | GxP assessment, Risk Assessment, FRA, CSA, FMEA, RTM | Whether the system is GxP relevant, and how deep testing must go | | Testing | IQ, OQ, PQ, UAT, Test Summary Report, Defect Log | Evidence that the installed system meets the requirements | | Vendor | Vendor Assessment Questionnaire, Supplier Audit Checklist | Whether the supplier's own quality system can be leaned on | | SOPs | Change Control, Backup & Restore, Access Management, Incident, Disaster Recovery | How the validated state is maintained | | Operational | Data Integrity Assessment, Security, Business Continuity, Retention, Periodic Review | That the system stays in control after go-live |

The Requirements Traceability Matrix is the link that gets audited hardest: every requirement in the URS must trace to a test case, and every test case back to a requirement.

GxP relevance and GAMP 5 category decide the workload

Two determinations set the depth of everything downstream.

GxP relevance is a yes/no outcome of a structured questionnaire — does the system create, modify, store or retire GxP records; does it control a process affecting product quality; does it hold data supporting a regulatory submission. One Yes makes the system GxP relevant. It is not a judgement call to be settled in a meeting.

GAMP 5 category then sets the rigour: Category 1 (infrastructure), 3 (non-configured products), 4 (configured products) and 5 (custom applications). A Category 5 custom build needs design specification and code-level review that a Category 3 off-the-shelf product does not. Categorising conservatively "to be safe" is expensive; categorising loosely is worse.

Both determinations should be computed from the answered checklist and printed with the answers visible. If the checklist is incomplete, the honest output is "not yet established" — a missing answer can only raise a risk score, never lower it.

What a 21 CFR Part 11 signature has to bind to

A scanned signature on a PDF is not an electronic signature. Part 11 asks for three things that are easy to state and easy to get wrong:

  1. The signer, at the moment of signing. Authentication belongs to the signing event — a password entered at signature time, not a session that was opened an hour ago.
  2. The meaning, printed. Authored, reviewed, or approved — with the signer's name and the manifestation timestamp on the document itself, not only in a database.
  3. A binding to the content. The signature must be linked to the exact content signed. A content hash does this: change a section afterwards and the earlier signature is superseded rather than carried forward silently.

Add an append-only audit trail and you can answer the two questions an inspector will ask — who approved this, and has anything changed since.

Where teams actually lose time

  • Format drift. Three authors, three cover pages, three ways of numbering sections. The remediation work at audit time is larger than the original authoring.
  • Version-by-filename. URS_v3_final_QA_rev2.docx is not a version-controlled record, and nobody can say which version the test evidence traces to.
  • Evidence scattered across email. Screenshots for OQ steps sitting in an inbox rather than attached to the step they prove.
  • Serial review. A document mailed around for comments takes weeks; section-anchored comments with resolve/reopen take days.
  • Periodic review forgotten. The pack was correct at go-live and has not been looked at since. Periodic review is a document type for a reason.

Word versus a validation platform

Word is not disqualified by regulation — plenty of compliant packs were written in it. It just puts every control on the humans. A platform moves the controls into the system: sections arrive pre-filled from the format, determinations compute from the checklists, evidence attaches to the test step, signatures bind to the content, and the issued .docx carries your letterhead, SOP number, format number and page-numbered TOC every time.

That is what we built ValiDoc to do — 49 document types across the seven phases, built against real client annexure formats with a practising CSV consultant reviewing the output. It is multi-tenant, so a consultancy can carry several client organisations, each on its own letterhead and SOP numbering.

A short checklist before your next audit

  • Every URS requirement traces to a test case, and back again, in the RTM
  • The GxP and GAMP 5 determinations are printed with the answers that produced them
  • Every signature names the signer, the meaning, and the UTC timestamp
  • Test evidence is attached to the step it proves, with a checksum for uploaded files
  • Change control has been run for every post-go-live change to a validated system
  • The periodic review is dated within its own stated interval

If most of those are true and only the assembly is painful, the problem is tooling, not process. If several are not true, fix the chain before automating it.


Working on a validation pack now? See our CSV validation documentation service or our pharma and life sciences practice, or talk to the team about a walkthrough on one of your own document formats.

Ready When You Are

Start Your Transformation

One 45-minute discovery call. We walk you through scope, timeline, and pricing — no boilerplate.