
On 13 September 2022 FDA issued the draft guidance "Computer Software Assurance for Production and Quality System Software". It describes a risk-based approach to establishing confidence that software used in manufacturing and quality systems is fit for its intended use, and it supersedes the software validation section of the 2002 General Principles of Software Validation for those uses.
The approach in brief
- Identify the intended use of the software feature or function.
- Determine the risk-based approach: does failure pose a high process risk that could affect product quality or patient safety?
- Select assurance activities proportionate to that risk, from scripted testing down to unscripted testing and vendor evidence.
- Record the assurance activities and the rationale.
What our validation consultants are telling clients
Do not rewrite every validation package. Start with new systems and major changes, apply the risk-based model there, and let the older packages age out on their periodic review cycle. Train the QA reviewers first; a CSA package that QA does not understand will be rejected internally before any inspector sees it.
Vakula's validation and CSV practice has been building CSA-style packages for clients since the draft appeared.