Revalidation is the controlled repetition of selectedvalidation or assurance activities when a change, incident, or other triggermay affect a system’s validated state or fitness for intended use.
· Software upgrades andvendor releases
· Configuration changes
· New or modifiedintegrations
· Changes in intended use orbusiness processes
· Infrastructure or hostingchanges
· Data migration
· Security or authenticationchanges
· Significant deviations,incidents, or repeated failures
· Findings from periodicreview or audit
The scope should be based on a documented impact and riskassessment. A change with no effect on intended use, regulated functionality,data, interfaces, security, or existing controls may require only a documentedassessment. A higher-impact change may require updated requirements, riskevaluation, configuration documentation, targeted testing, traceability, andapproval.
Revalidating the entire system is not necessary when theimpact can be reliably identified and appropriately controlled. Automatedchange detection and traceability can support recurring release assessment byidentifying potentially affected requirements, risks, and evidence.
Frequently Asked Questions
Does every change require revalidation?
Not every change requires additional testing, but applicablechanges should be evaluated through the approved change-management process. Thedocumented assessment provides the basis for deciding whether further assuranceactivities are necessary.
What is the difference between revalidation and regression testing?
Regression testing is a verification technique used todetermine whether a change adversely affected existing functionality.Revalidation is the broader controlled process and may include impactassessment, requirements updates, testing, traceability, deviation management,and a documented conclusion.
Do vendor security patches trigger revalidation?
Security patches should be assessed for effects on theapplication, infrastructure, authentication, interfaces, compatibility,availability, performance, data integrity, and other relevant controls. Theresulting assurance activities should be documented.
How long does a revalidation cycle take?
The effort depends on the nature of the change, systemcomplexity, available supplier information, quality of existing traceability,and the assurance activities required. Quantified time-saving claims should besupported by documented data and a defined comparison baseline.