Ready to fix validation chaos? Book Review
Change Management

Change Control and Revalidation: Deciding What Evidence a GxP System Change Needs

Not every change needs the same evidence, but every change needs a decision

ICH Q10 identifies change management, corrective and preventive action, process performance and product quality monitoring, and management review as elements of a pharmaceutical quality system. For computerised systems, change control is where the validated state meets reality. The right response is not to re-run everything by reflex or to waive testing because the vendor called the change minor.

Assess impact before selecting tests

Describe what is changing, why, where, when, and who is affected. Assess impact on intended use, critical data, calculations, interfaces, permissions, audit trails, electronic signatures, reports, records, integrations, infrastructure, and procedures. Consider supplier release notes, configuration differences, known defects, and recent incidents.

A proportionate change path

  1. Classify the change and document the rationale.
  2. Identify affected requirements, risks, controls, records, and training.
  3. Select regression, focused, exploratory, configuration, data, or interface checks as appropriate.
  4. Define preconditions, acceptance criteria, test data, and independent review.
  5. Manage deviations and unresolved defects before release or record an authorised decision.
  6. Update controlled documentation, training, configuration records, and the traceability matrix.
  7. Verify the change in operation and set any follow-up or periodic-review action.

The validated state includes people and procedures

A software update can leave the application technically functional while the process is uncontrolled. New fields may change training. A changed report may alter a review procedure. An interface retry rule may affect reconciliation. Include these operational effects in the impact assessment and release decision.

Use post-change evidence wisely

Keep the baseline, the change record, the test evidence, the approval, and the first-use or follow-up observation together. Trend incidents and repeated changes. If a class of vendor updates repeatedly causes the same issue, the risk model or supplier control needs improvement. Change control should produce learning, not just signatures.

VLMS Software helps teams connect change requests to impact, evidence, approval, and review. The principle is simple: know what changed, know what could be affected, and show why the evidence supports release.

Make change control a lifecycle control

Start with the system, process, and evidence questions that matter to your team.

Talk with VLMS about your validation programme →