Validation Life Cycle

The validation life cycle includes the activities used toestablish and maintain confidence that a regulated computerized system remainsfit for its intended use from initial planning through retirement.

Validation does not end when a system goes live. Thesystem’s validated state must be maintained as its use, configuration,integrations, infrastructure, risks, and supporting processes change.

·        Planning and governance

·        Definition of intended useand requirements

·        Supplier and productassessment

·        Risk assessment

·        Design and configuration

·        Verification and assuranceactivities

·        Resolution of deviationsand identified issues

·        Approval and release

·        Operation and support

·        Change management

·        Periodic review

·        Revalidation or additionalassurance, when required

·        Retirement, data migration,and record retention

The exact deliverables and sequence should be appropriate tothe organization’s methodology and the nature of the system. Assurance evidencemay be structured as IQ, OQ, and PQ or through another documented, risk-basedlife-cycle model.

The operational phase is particularly important for cloudand SaaS systems. Vendor releases, configuration updates, integrations,security changes, and business-process changes should be assessed for theirpotential effect on intended use and the validated state.

Frequently Asked Questions

When does the validation life cycle end?

It ends when the system has been formally retired andapplicable data, records, and responsibilities have been appropriatelyaddressed.

Who owns the validation life cycle?

Accountability is typically assigned to the system owner,business process owner, or another designated role. QA provides qualityoversight, while IT and other subject-matter experts contribute according todefined responsibilities.

How do vendor releases fit into the life cycle?

Vendor releases should be managed through an approvedchange-management process. Each applicable release should be assessed foreffects on intended use, regulated functions, configuration, interfaces,security, data integrity, and existing assurance evidence.

‍