Validation of computerized systems in clinical trials - QFINITY
QFINITY · Company · Publications

Validation is applied quality management - not an IT project.

In the ECV guide "Klinische Prüfungen von Arzneimitteln und Medizinprodukten" (5th, fully revised edition 2024, Part C), M. Schwabedissen, F. Henrichmann, Dr. J. Gebhardt and O. Herrmann (QFINITY) explain in the chapter "Validierung von Computersystemen" why validating computerized systems draws on sound process knowledge - not on the IT department.

What it is about

Validation, grounded in process knowledge.

Clinical trials use a wide range of computerized systems - EDC, eTMF, CTMS, IRT, statistics programs. The chapter clears up a widespread misconception: that validation is a matter for IT.

Neither regulation nor practice supports this, because a computerized system is more than software and hardware - it includes how both interact with the supported process and with trained personnel. Demonstrating that a system supports this process as expected therefore takes an understanding of the study and the process - technical expertise complements that understanding, it does not replace it.

The obligation to validate follows not from the software but from its use in the process. The benchmark is its significance for patient safety, data integrity and product quality - not the tool.
The key points

What the chapter argues.

  • Applied quality management

    Validation follows quality management's familiar Deming cycle (Plan-Do-Check-Act): define expectations, plan requirements, verify against the system, refine - until the result matches expectations.

  • From the process, not from IT

    Validation draws on sound process knowledge. Sponsor representatives bring study and process understanding, IT and the software vendor bring technical expertise - it takes both for the effort to scale with the risk.

  • Intended Use as the benchmark

    The intended use describes how the system is meant to be used in the process. The obligation to validate derives from that use - a function that exists but goes unused ties up no validation resources.

  • Risk-based scaling

    Critical process steps and the system functions behind them get closer scrutiny; less critical ones get by with less effort. Criticality is measured by patient safety, data integrity and product quality in the context of the process.

  • Responsibility with the sponsor

    All regulations make the sponsor of the clinical trial responsible for validating the systems used. This responsibility cannot be fully delegated to a software vendor or a CRO.

  • Staying validated

    A validated system stays validated only through controlled change management: every change - in whatever layer - documented and risk-assessed, through to emergency, maintenance and decommissioning.

The common thread

Why the purpose comes from the process.

The focus shifts away from the product toward use: validation demonstrates that a system supports the specific process as expected, in the way its users plan to work with it - the tool does not decide whether validation is required, its intended use does.

Typical office software therefore generally needs no validation; but once Excel macros or bundled operating software are adapted for a specific study, the risks of that adaptation must be assessed. Following that logic, the guide scales every activity by risk across a layer model - from qualified infrastructure through the cross-study reference architecture to the study-specific configuration - with reference to the documented risk analysis in the approved validation plan.

Regulatory framework

From principle to expectation.

The chapter anchors validation in its regulatory context: ICH E6(R2) requires, as part of quality management, that computerized systems be validated - SOPs included - through to decommissioning; the PIC/S guidance describes international expectations; and, depending on the jurisdiction, EU GMP Annex 11 or 21 CFR Part 11 apply to electronic records and signatures.

In addition, it references GAMP 5 (Second Edition) and the ISPE GAMP Good Practice Guide on computerized GCP systems, whose 2nd Edition ("Computerized GCP Systems and Data", July 2024) was developed with QFINITY as co-lead. The sponsor remains responsible for the compliance of the entire supply chain and must qualify and monitor vendors and CROs on a risk basis, a non-delegable responsibility that the EMA Notice to sponsors (2020) also emphasizes.

Today's benchmark: since September 2023, the EMA guideline on computerised systems and electronic data (EudraLex Vol. 10, Annex III) has spelled out what inspectors expect in Europe, and since January 2025, ICH E6(R3) has anchored data governance globally. In the US, the FDA's Q&A guidance on electronic systems, records and signatures in clinical investigations has been answering the practical questions since October 2024, superseding its 2007 predecessor. To see how we put both into practice, visit our page on data integrity of GCP-relevant computerized systems.

ICH E6(R2) EU GMP Annex 11 21 CFR Part 11 PIC/S PI 011 GAMP 5 (Second Edition) EMA Notice to sponsors
The authors

Written by QFINITY.

The chapter "Validierung von Computersystemen" is by M. Schwabedissen, F. Henrichmann, Dr. J. Gebhardt and O. Herrmann - all QFINITY. It is therefore not a third-party piece about QFINITY but QFINITY's own expert position, contributed to Part C ("Dokumente und Prozesse") of the ECV guide "Klinische Prüfungen von Arzneimitteln und Medizinprodukten", 5th, fully revised edition 2024 (Editio Cantor Verlag).

ECV Guide, Clinical Trials Part C 5th edition 2024 Editio Cantor Verlag
Klinische Prüfungen von Arzneimitteln und Medizinprodukten - Editio Cantor Verlag
Related topics

From thesis to everyday practice.

Validation that comes from the process.

We help sponsors, CROs and trial sites validate computerized systems in clinical trials - risk-based and inspection-ready. Free initial consultation, about 30 minutes.

Arrange an initial consultation