Skip to content

The validation lifecycle

VP ─► SRA ─► URS ─► FS / DS / IS ─► Test Protocol ─► Executions (+ evidence) ─► Deviations ─► VSR

Documents

Document Purpose
VP Validation Plan Scope, approach and the risk-based assurance strategy. Starts from a template.
SRA System Risk Assessment GxP impact questions and the GAMP category give the system risk. See Risk.
URS User Requirements Specification What the users need.
FS / DS / IS Functional, Design and Installation Specifications How the system meets the URS. FS and DS requirements trace to URS requirements.
TP Test Protocol The test cases, pre-approved before execution.
VSR Validation Summary Report Results, deliverable statuses, deviations and the RTM.

Documents are written in Markdown with a live preview, and can be printed or exported as PDF.

Document states

State Meaning
Draft Editable by authors.
In review An author signed and submitted it; locked. The reviewer signs, then the approver (QA) signs.
Approved The approver has signed; locked.
Approved, but content changed after signing The signed hash no longer matches the record, so the approval no longer counts.

Submitting, reviewing and approving are each electronic signatures. Review must be signed before approval. A reviewer or approver can reject a document in review, which returns it to draft with a reason. Documents in review or approved, with their requirements and test cases, cannot be edited; this lock is enforced on the data itself, not only on the screens.

Revising an approved document

To change an approved document, revise it: it returns to draft with a new version and must be reviewed and approved again. A rejection or revision invalidates earlier signatures on that document. Tests changed after they were executed show up in the RTM as test-changed-since-execution.

Validation Summary Report

The VSR is generated from the results, deliverable statuses, deviations and the RTM. It cannot be signed while the RTM has any open gap. Its signature binds a hash of those results, so any later test activity shows as content changed after signing. See Traceability matrix.