ALCOA+
A data integrity framework requiring records to be attributable, legible, contemporaneous, original, accurate, complete, consistent, enduring, and available.
Audit Trail
A secure, computer-generated record showing who performed an action, what changed, and when the action occurred.
Audit Readiness
The ability to quickly produce current, complete, and defensible evidence during an inspection or client audit.
CAPA
Corrective and Preventive Action. A formal process used to investigate quality problems, correct root causes, and prevent recurrence.
CSA
Computer Software Assurance. A risk-based approach to software assurance that emphasizes critical thinking, intended use, and patient safety/product quality/data integrity risk.
CSV
Computer System Validation. Documented evidence that a computerized system consistently performs as intended in a regulated process.
Change Control
A governed process for assessing, approving, implementing, testing, and documenting changes to validated systems.
Data Integrity
The completeness, consistency, accuracy, and trustworthiness of data throughout its lifecycle.
Deviation
A departure from an approved procedure, specification, protocol, or expected result that requires documentation and assessment.
Electronic Record
A record created, modified, maintained, archived, retrieved, or transmitted by a computerized system.
EU Annex 11
European guidance for computerized systems used in GMP-regulated activities.
GAMP 5
Good Automated Manufacturing Practice guidance widely used for risk-based validation of computerized systems.
GxP
A collective term for regulated good practices such as GMP, GCP, GLP, GDP, and related quality requirements.
Intended Use
The regulated purpose for which a system, function, report, workflow, or record is used. Intended use drives validation scope and risk.
IQ
Installation Qualification. Evidence that a system or component is installed according to approved specifications.
OQ
Operational Qualification. Evidence that system functions operate as intended under defined conditions.
Part 11
21 CFR Part 11. FDA regulation covering electronic records and electronic signatures.
PQ
Performance Qualification. Evidence that the system performs as intended in real or simulated business use.
Periodic Review
A scheduled review confirming that a validated system remains controlled, fit for intended use, and aligned with current procedures.
Risk Assessment
A documented evaluation of system functions, process impact, patient safety, product quality, data integrity, and control needs.
RTM
Requirements Traceability Matrix. A mapping from requirements to risk, tests, deviations, and release evidence.
SOP
Standard Operating Procedure. A controlled document defining how a regulated process must be performed.
Supplier Qualification
Evaluation of a vendor or service provider to confirm they can support regulated use and required controls.
URS
User Requirements Specification. A documented description of what the regulated user needs the system to do.
UAT
User Acceptance Testing. Testing performed by business users to confirm the system supports intended business use.
Validation Plan
A document defining scope, responsibilities, deliverables, strategy, acceptance criteria, and lifecycle controls for validation work.
Validation Summary Report
A final report summarizing validation execution, deviations, traceability, acceptance, and release recommendation.