Skip to main content
v2026.11,772 entries · CC-BY 4.0

Direct comparison

CSA vs CSV: Risk-Based vs Scripted Testing

CSA vs CSV: FDA's risk-based, critical-thinking approach versus traditional scripted CSV testing, and when each applies in GxP validation.

Written and maintained by CASRAI Editorial Board

Last updated

Ask CASRAI · included with Regulatory Radar

Ask about CSA vs CSV: Risk-Based vs Scripted Testing

Ask CASRAI answers research-administration questions and cites the passages behind every claim — and says so when the corpus does not cover something, instead of guessing. It comes with a Regulatory Radar subscription at $29 a month, alongside the daily digest of regulatory changes and the dashboard of what changed.

150 questions a day, on this site, over the API, or inside your own tools through the CASRAI MCP server.

Everything CASRAI publishes — this page, the dictionary, the guides and the news — stays free to read, with no account and no card.

How do Computer Software Assurance (CSA), Computer System Validation (CSV) compare side by side?

The table below compares Computer Software Assurance (CSA), Computer System Validation (CSV) across 8 procurement-relevant dimensions, from what it is through effect on part 11 / audit-trail obligations.

Side-by-side comparison

DimensionComputer Software Assurance (CSA)Computer System Validation (CSV)
What it isA risk-based method for deciding how much testing rigor a feature needsThe overarching GxP requirement to document that a system works as intended
Governing guidanceFDA draft guidance Sept 2022, finalized 24 Sept 2025 — "Computer Software Assurance for Production and Quality System Software"Decades of GxP practice; formalized industry-wide via ISPE GAMP (now GAMP 5, 2nd edition, July 2022)
Formal regulatory scopeProduction and quality system software under the Quality System Regulation (21 CFR Part 820) — medical device manufacturingBroad — applies across GxP systems in pharma, device, clinical, and lab settings
Testing approachRisk-based; favors critical thinking, exploratory/unscripted testing for low-risk functionsTraditionally exhaustive scripted testing of every function, regardless of risk level
Documentation burdenScaled to risk — assurance activity and outcome recorded, not necessarily a full scripted protocolComprehensive IQ/OQ/PQ protocols with step-by-step expected vs. actual results for every test case
Best fitConfigured COTS software (GAMP Cat. 3/4), low/indirect-risk features, iterative or agile releasesCustom-coded software (GAMP Cat. 5), high-risk functions, features with subtle failure modes
Relationship to the otherA method used within a CSV effort — not a separate regulatory requirement or a replacementThe umbrella obligation; can incorporate CSA-style testing for lower-risk features
Effect on Part 11 / audit-trail obligationsNone — record-keeping, audit-trail, and e-signature requirements are unchangedEstablishes the validated system those record-keeping obligations then apply to

Common questions

Common questions about Computer Software Assurance (CSA) vs Computer System Validation (CSV)

Is CSA a replacement for CSV?

+

No. CSA is a risk-based method for determining how much testing effort and documentation a given system feature needs — it operates within a CSV effort, not instead of one. A system still has to be validated; CSA changes the proportionality of how that validation evidence is gathered for lower-risk functions.

Does CSA apply outside medical device manufacturing?

+

FDA's CSA guidance is formally scoped to production and quality system software under the Quality System Regulation (21 CFR Part 820), which covers medical device makers. Its risk-based, critical-thinking philosophy has been widely adopted more broadly across pharma and lab GxP systems — partly because GAMP 5's second edition explicitly aligned with it — even though the binding guidance document itself doesn't formally reach those systems.

Does CSA reduce Part 11 audit trail or electronic signature requirements?

+

No. CSA changes how much testing effort goes into proving a feature works correctly; it does not change what electronic records, audit trails, or signatures a validated system must maintain under 21 CFR Part 11 or equivalent rules.

Can CSA and traditional scripted CSV testing be used in the same validation plan?

+

Yes, and in practice this is the common pattern. A single system's validation plan typically applies full scripted testing to its high-risk functions (calculations, interlocks, data-integrity controls) while applying CSA-style risk-based, unscripted testing to its low-risk configuration and usability features.

Referenced across the research world

University of Cambridge logoColumbia University logoCrossref logoUniversity of Edinburgh logoHarvard University logoUniversity of Oxford logoPrinceton University logoStanford School of Medicine logoUniversity College London logoORCID logoUniversity of Cambridge logoColumbia University logoCrossref logoUniversity of Edinburgh logoHarvard University logoUniversity of Oxford logoPrinceton University logoStanford School of Medicine logoUniversity College London logoORCID logo
  • University of Cambridge logo
  • Columbia University logo
  • Crossref logo
  • University of Edinburgh logo
  • Harvard University logo
  • University of Oxford logo
  • Princeton University logo
  • Stanford School of Medicine logo
  • University College London logo
  • ORCID logo

View CASRAI adoption →

Regulatory Radar

Stop finding out after the fact

$29/month, cancel anytime. Daily digest updates from our analysis, a dashboard holding the same items, and a cited assistant for everything they raise.

  • Federal Register, Federal Register+, Grants.gov, Regulations.gov, NSF News, UKRI, plus CASRAI’s own published content.
  • 72,264 indexed passages, and every answer cites the ones it drew on.