Services

Consulting and validation services for Pharma, Biotech and MedTech.

Nine service areas, one consistent method. Choose the entry point that matches your current decision — or talk to us if the boundary is still unclear.

What is Computer System Validation?

Computer System Validation (CSV) is the documented evidence that a GxP-relevant computerised system is fit for its intended use and operated reliably, securely and traceably.

Regulatory framework: EU GMP Annex 11 requires validated applications and qualified IT infrastructure; 21 CFR Part 11 governs electronic records and signatures in the FDA space.

Methodological framework: GAMP 5 Second Edition (ISPE, 2022) is the recognised good-practice guide for risk-based validation — testing effort follows the real patient, product and data risk.

The result is audit-proof documentation as the basis for a sound release decision.

Evidenced across 17+ years of GxP practice: 60+ validated systems, 100% audit pass rate, 0 critical findings.

AI SERVICE ROUTING

AI consulting or AI validation?

AI consulting is the right route when use cases, governance, policies, provider selection, technical setup or adoption still need to be decided. AI system validation starts once a specific system and GxP intended use are defined and evidence for testing, release and controlled operation is required.

01 · Money-Page

CSV-Beratung

Computer System Validation in Pharma — GAMP 5, Annex 11, 21 CFR Part 11. Our IVE methodology (Integrated Validation Execution) explained in full.

See CSV consulting →
02 · Schwerpunkt

AI consulting for Pharma and life sciences

AI readiness, real use cases, governance, policies, provider and setup selection, prompt and workflow engineering, usage and cost controls.

See AI consulting →
03 · Schwerpunkt

AI system validation for GxP

Risk-based validation of a defined AI-enabled system: intended use, system boundary, risk, supplier, data, testing, release, monitoring and change control.

See AI validation →
04 · Service

SAP-Validierung

SAP S/4HANA migration without findings. Greenfield, Brownfield, Bluefield — we know all three paths and the audit traps in each.

See SAP validation →
05 · Service

System-Validierung

LIMS, MES (PAS-X), Veeva Vault, MasterControl, eQMS — the systems your production runs on, validated GxP-compliant.

See system validation →
06 · Service

GAMP 5 Compliance

The regulatory backbone — GAMP 5 Second Edition, Annex 11, 21 CFR Part 11 + FDA CSA. Risk-based validation as our consulting approach.

See GAMP 5 compliance →
07 · Service

Cloud- & SaaS-Validierung

Validating cloud properly: clear vendor-audit boundary, release-regression framework, hybrid-stack coverage. The grey area between you and your SaaS vendor.

See cloud validation →
08 · Service

Audit-Vorbereitung & Execution

FDA, EMA, BfArM and Swissmedic inspections — pre-inspection walkthrough, mock audit, on-demand validation team. 100 % audit pass rate.

See audit readiness →
09 · Service

GxP system decommissioning

Retire validated legacy systems while preserving records, metadata, audit trails and retrieval throughout the required retention period.

See system decommissioning →
FAQ

Frequently asked questions about validation.

What is the difference between CSV and CSA?

CSV (Computer System Validation) is the broader evidence that a GxP-relevant system is fit for its intended use. Computer Software Assurance (CSA) is the FDA risk-based approach for software used in medical-device production or the quality management system. The revised final guidance issued in February 2026 supersedes the September 2025 version and aligns it with the amended 21 CFR Part 820 Quality Management System Regulation (QMSR). It focuses on intended use, process risk, appropriate assurance activities and objective evidence. For other pharmaceutical GxP contexts, CSA is not a directly applicable FDA requirement, but its methods can be connected with GAMP 5 and risk-based CSV.

Which regulations and standards apply to computer system validation?

The governing regulations are EU GMP Annex 11 (EU) and 21 CFR Part 11 (FDA, electronic records and signatures). The methodological framework is the GAMP 5 guide (ISPE, Second Edition 2022) — a recognised good-practice standard, not a legal norm. ALCOA+ applies for data integrity and ICH Q9 for risk management. Which requirement applies in detail depends on the target market and the system's GxP context.

When does a computer system need to be validated?

GxP-relevant systems require validation — those affecting product quality, patient safety, efficacy or data integrity. The evidence must be in place before release for GxP use. Changes are assessed via change control; affected functions, interfaces and controls are re-verified or revalidated on a risk basis. Whether a system is GxP-relevant is determined by a structured risk and criticality assessment at project start.

How long does a system validation take?

It depends on risk and system complexity. A low-risk standard system is validated in a few weeks; a bespoke, highly critical application takes several months. The risk-based approach per GAMP 5 reduces effort precisely where risk is low — without any compliance gap.

What should pharma companies look for when choosing a CSV consultant?

On three things: demonstrable regulatory experience, a risk-based rather than schematic approach, and continuity in the team. Daniel Herrmann Consulting brings 17+ years of GxP practice and 60+ validated systems, works risk-based per GAMP 5, and integrates into your team — the consultants from the first conversation run the engagement. Results before method: audit-proof validation without unnecessary documentation burden.