Validation evidence
an auditor can actually trace.
The real test of a validation package isn't whether you have documents — it's whether an auditor can trace an unbroken chain from the original requirement (URS) and risk assessment, through executed test evidence, to sign-off. ValiCore builds that chain in, not as an afterthought.
What is computer system validation, and what is GAMP 5?
Computer system validation (CSV) is documented evidence that a computerized system does what it's intended to do, reliably and reproducibly, and that it's fit for its GxP use. GAMP 5 (now in its Second Edition, published 2022 by ISPE) is the industry-standard framework for this: it categorizes software by risk — from Category 1 (infrastructure like operating systems, minimal validation) to Category 5 (bespoke, custom-developed software, requiring the most rigorous testing) — and the Second Edition added explicit guidance for cloud/SaaS validation and endorsed a risk-proportionate, Computer Software Assurance (CSA)-aligned approach over rigid, document-heavy validation for its own sake.
Built for
What goes wrong without it
IQ executed without verified calibration status
A recurring, specific inspection finding: Installation Qualification executed on equipment whose calibration status wasn't verified at the time — a gap that invalidates the qualification's premise.
OQ acceptance criteria looser than the actual process
Operational Qualification that tests a wider range than the process actually requires doesn't prove the equipment works for your real operating conditions — a documented, specific inspection observation.
Change control that doesn't ask the re-qualification question
Every equipment or process change needs an explicit assessment: does this change require re-qualification? Skipping this question is one of the most common change-control findings.
What ValiCore actually does here
IQ/OQ/PQ workflow with linked evidence
Installation, Operational, and Performance Qualification stages linked to the original URS and risk assessment — the full chain of evidence in one record.
USP <1058> · GAMP 5GAMP 5-aligned risk categorization
Validation depth scoped to software category — infrastructure vs. configured vs. bespoke — rather than one-size-fits-all documentation.
GAMP 5 (2nd Edition, 2022)Method validation with acceptance criteria
Analytical method validation tracked against ICH Q2-style parameters — accuracy, precision, specificity, linearity — with results captured against pre-defined acceptance criteria.
Cleaning validation with residue limits
Cleaning validation protocols tied to equipment and product, with residue acceptance limits and swab/rinse sample results recorded against them.
Change control tied to re-qualification
Every logged change explicitly assesses whether re-qualification is triggered — closing the exact gap inspectors check for.
E-signature approval at every stage
Protocol approval, execution sign-off, and final report approval each carry an individual, timestamped e-signature.
21 CFR Part 11Regulations this addresses
Frequently asked questions
Unmodified, standalone Excel is not validated for GxP use out of the box. Some organizations validate narrow, specific calculation templates within Excel for a defined purpose, but this requires its own documented validation effort and doesn't extend to using Excel generally as a system of record — it still lacks the audit trail and access-control features GAMP 5 and Part 11 expect from a validated system.
Installation Qualification (IQ) verifies equipment is installed correctly per specification. Operational Qualification (OQ) verifies it operates correctly across its intended operating range. Performance Qualification (PQ) verifies it performs consistently under real, routine production conditions. Each stage builds on the previous — OQ assumes IQ passed, PQ assumes OQ passed — which is why a broken chain of evidence between stages is a common audit finding.
The Second Edition added explicit guidance for validating cloud and SaaS-based systems (increasingly relevant as more GxP software moves off-premise), updated data-integrity expectations to align with ALCOA+, introduced cybersecurity considerations, and formally endorsed Computer Software Assurance (CSA) — a shift toward risk-proportionate, critical-thinking-driven testing rather than exhaustive, checklist-style documentation for every system regardless of risk.
See ValiCore
live in your lab.
Book a free 30-minute demo. We’ll walk through the modules your team will use, answer your compliance questions, and give you a clear picture of what implementation looks like for your lab.
Book your free demo
30 minutes. No credit card. We’ll respond within 4 business hours with a calendar invite tailored to your time zone.
Book my free demo35 working modules · Founder-led onboarding · 14-day go-live guarantee