Skip to content
VTValiTracAI
GDP / GMP

Computerised system validation for monitoring and mapping software

Software that produces GxP records must be validated for its intended use: requirements, risk assessment, testing, audit trails, access control and change control.

ValiTrac AI editorialUpdated 2026-09-132 min read

EU GMP Annex 11 requires computerised systems to be validated and IT infrastructure qualified, with the extent of validation based on a documented risk assessment. For environmental monitoring and mapping software, the critical functions are data capture, calculation, alarm generation, review workflow and record retention.

What a validation package covers

  • User requirements and a functional risk assessment.
  • Supplier assessment for purchased software.
  • Installation and configuration records.
  • Testing of critical functions: correct statistics on known datasets, alarm behaviour, audit-trail capture, access control.
  • Data migration and retention approach.
  • Change control and periodic review.

Deterministic calculation engines are easier to validate than opaque ones: the same inputs must always give the same outputs, and those outputs can be checked against independent calculations. ValiTrac's engineering engine is designed to be tested exactly that way.

Frequently asked questions

Does using a cloud monitoring service remove the validation obligation?
No. The regulated company remains responsible; supplier assessment and documented controls become a larger part of the package.

References

  1. [1]EudraLex Volume 4, Annex 11: Computerised Systems
  2. [2]PIC/S PI 041-1: Good Practices for Data Management and Integrity in Regulated GMP/GDP Environments (2021)

General technical guidance written against the cited sources. It is not regulatory or legal advice and does not replace the applicable standard, guideline or a qualified reviewer's judgement.

Related articles