Service · CSV & Data Integrity

Computer System Validation to GAMP 5

Risk-based CSV to GAMP 5 (2nd edition), EU GMP Annex 11 and 21 CFR Part 11, with ALCOA+ data integrity built in from the start. From Visp in the Valais, on site in running GMP operations across Switzerland.

GAMP 5 (2. Ausgabe)EU-GMP Annex 1121 CFR Part 11ALCOA+ICH Q9

The systems we validate

Any computerised system that creates, processes, stores or transmits GxP-relevant data needs validation. Typical systems from our work:

Our CSV services, each with a clear outcome

Every service ends with an audit-proof document, not a recommendation. What you actually receive:

System inventory and GAMP 5 categorisation

We map your system landscape, assess GxP criticality and assign each system to its GAMP category. The validation scope follows, risk-based instead of blanket.

Outcome: a validation master plan with a justified test depth per system.

URS and specifications

We write requirements that are testable, unambiguous and traceable, and tie them to risk and test case through a traceability matrix.

Outcome: an audit-proof URS with end-to-end traceability.

Risk analyses to ICH Q9

We facilitate and document the risk analyses that justify the test depth: patient risk, product quality and data integrity as the yardstick.

Outcome: documented risk decisions that hold up in an audit.

IQ, OQ and PQ

We write and execute the qualification protocols, with acceptance criteria defined before testing and a clean handling of deviations.

Outcome: executed protocols and a validation report that carries the release.

Data integrity and audit trail review

We check audit trail, access concept and electronic signatures against Annex 11 and 21 CFR Part 11, technically configured rather than merely described in an SOP.

Outcome: a data integrity assessment with gap list and measures.

Lifecycle: change control and periodic review

We anchor impact assessments for updates and build the periodic review so the validated state holds across the system's lifetime.

Outcome: living procedures that maintain the validated state.

How a CSV project with us runs

01

Assessment and classification

System inventory, GxP criticality and GAMP 5 category per system. The validation scope follows.

02

Validation plan

Roles, acceptance criteria, risk assessment and test scope, aligned with your QA.

03

Specification and testing

URS, functional specification and traceability matrix, then IQ, OQ and PQ with documented results.

04

Validation report

Assessment of deviations and release of the system for GMP use.

05

Lifecycle in operations

Change control, periodic review and backup with restore, tested rather than asserted.

What sets us apart from paper-only CSV

Engineering closeness

Our engineers know the plant behind the system: process control, utilities, monitoring. CSV that fits the real facility, not just the system description.

At home in the Valais, on the road across Switzerland

Vispact is based in Visp, at the heart of the Swiss life-science industry. Short distances in the Valais, on-site work across Switzerland and Germany.

Critical thinking instead of templates

GAMP 5 (2nd edition) calls for engineers who think. We test what carries risk and justify what we leave out, documented and defensible in an audit.

Documentation that holds up in an audit

Every requirement is traceable through to its test evidence. That is the standard we hold ourselves to.

Frequently asked questions about CSV

What is Computer System Validation?

CSV is the documented evidence that a computerised system reproducibly does what it is intended to do, and that its GxP-relevant data remains intact across the entire lifecycle. The foundations are GAMP 5, EU GMP Annex 11 and 21 CFR Part 11.

Which systems need validation?

All systems that create, process, store or transmit GxP-relevant data: from the process control system through LIMS and MES to Excel applications with GMP relevance. The GAMP 5 categorisation determines how deeply testing goes.

How do CSV and CSA differ?

Computer Software Assurance is the FDA's direction of aligning test effort more closely with risk and cutting non-critical testing. GAMP 5 (2nd edition) follows the same idea. In practice CSA does not replace CSV: it is its consistently risk-based form.

How do Annex 11 and 21 CFR Part 11 relate?

Annex 11 is the European framework for computerised systems, Part 11 the US requirement for electronic records and signatures. They overlap heavily on audit trail, access control and signatures; anyone serving both markets tests each topic against the stricter requirement.

How does a CSV project with Vispact start?

With a 30-minute initial conversation, no strings attached. An assessment of your system landscape with GAMP 5 categorisation follows, from which the validation scope and a sound plan emerge. Reply within one working day, straight from engineering.

Deeper reading from our practice

Let's talk about your systems.

In the initial conversation we place your starting point: 30 minutes, no strings attached. Reply within one working day, straight from engineering.

Book an initial conversationSee all services