Written and maintained by CASRAI Editorial Board
Last updated
A validation master plan (VMP) is the governing document that defines how an organisation runs qualification and validation as a programme — what is in scope, who decides, how much evidence each system needs, and when everything gets looked at again. It sits above individual validation exercises. A VMP does not qualify anything; it is the document that says which things get qualified, to what depth, against whose acceptance criteria, and on what review cycle.
Almost every VMP guide on the internet is written for a pharmaceutical manufacturing site: process validation, cleaning validation, utilities, batch equipment. This page is written for a regulated laboratory — a GMP QC lab, a GLP test facility, a GCP central or bioanalytical lab, or an accredited testing lab operating under GxP obligations. The regulatory clauses are the same; the inventory, the criticality calls and the review triggers are not. A lab’s validation burden is concentrated in computerised systems and analytical instruments, not in process trains, and that changes what a useful VMP looks like.
If you need the mechanics of a single validation exercise — the IQ/OQ/PQ sequence, GAMP software categories in detail, 21 CFR Part 11 applicability — read Computer System Validation (CSV): GAMP 5, IQ/OQ/PQ, and 21 CFR Part 11. This page deliberately does not repeat that; it covers the layer above it.
The document hierarchy: where the VMP actually sits
Confusion between a VMP, a validation plan and a validation protocol is the single most common structural error in lab quality systems, and it produces real inspection findings because the wrong document ends up carrying the wrong decision. The hierarchy, in the order the documents are approved:
| Level | Document | Scope | What it decides |
|---|---|---|---|
| 1 | Validation policy | The organisation | The commitment and principles; often a short section inside the VMP rather than a separate document. |
| 2 | Validation master plan (VMP) | The site, facility or lab | Scope, inventory, criticality method, strategy per system class, roles, acceptance-criteria rules, review cycle. |
| 3 | Validation plan / project validation plan | One system or project | The deliverable set and schedule for this LIMS, this chromatography data system, this instrument fleet. |
| 4 | Protocol (IQ/OQ/PQ, URS, traceability matrix) | One qualification stage | The specific tests, parameters and acceptance criteria to be executed. |
| 5 | Summary report / validation summary | One system or project | Results against criteria, deviations, and the release decision. |
EU GMP Annex 15 acknowledges level 3 explicitly: for large and complex projects, “separate validation plans may enhance clarity” (Annex 15, §1.6). That is the clause to cite when someone insists a single VMP should contain every project schedule. It should not.
Where the VMP requirement actually comes from
There is no single global rule that says “write a VMP.” The obligation is assembled from different instruments depending on which GxP the lab operates under. Getting this right matters because a lab that writes a manufacturing-style VMP under a framework that never asked for one has wasted effort, and a lab that skips it under EU GMP has a finding waiting.
EU GMP Annex 15 — the clause that names the document
Annex 15 (Qualification and Validation) of EudraLex Volume 4 is the source that names the VMP directly. The revised version carries a deadline for coming into operation of 1 October 2015. Its §1.4 states that the key elements of the site qualification and validation programme “should be clearly defined and documented in a validation master plan (VMP) or equivalent document.” Note the phrase or equivalent document — the requirement is that the content exists and is controlled, not that the file is titled “VMP.”
Annex 15 also sets two framing rules that a lab VMP has to reflect. First, decisions on the scope and extent of qualification and validation must be based on a justified and documented risk assessment (Annex 15, General). Second, retrospective validation is no longer considered an acceptable approach — a point that still catches out labs planning to “document what we already do” for a legacy instrument fleet.
EU GMP Annex 11 — the clause that drives the inventory
Annex 11 (Computerised Systems), revision 1, came into operation on 30 June 2011. For a laboratory it is the more operationally significant of the two, because it is where the system inventory obligation lives. Annex 11 §4.3 requires that “an up to date listing of all relevant systems and their GMP functionality (inventory) should be available,” and adds that for critical systems there must also be a current system description covering the physical and logical arrangements, data flows, interfaces with other systems or processes, hardware and software pre-requisites, and security measures.
Two further Annex 11 clauses shape the VMP’s strategy section: §4.4 requires User Requirements Specifications to describe the required functions and to be based on documented risk assessment and GMP impact, with user requirements traceable throughout the life cycle; §11 requires periodic evaluation of computerised systems.
PIC/S — the same expectations, applied by inspectorates outside the EU
PIC/S publishes PI 011-3, “Good Practices for Computerised Systems in Regulated GXP Environments” (dated 25 September 2007), which is the reference many non-EU inspectorates apply to computerised-system validation, and PI 041-1, “Good Practices for Data Management and Integrity in Regulated GMP/GDP Environments” (dated 1 July 2021), which is the current PIC/S data-integrity reference. If your lab is inspected by a PIC/S participating authority rather than an EU one, cite these alongside the Annexes in the VMP’s regulatory-basis section rather than assuming Annex 15 alone covers you.
FDA — no VMP mandate by that name
This is where a lot of lab VMPs overclaim. FDA regulations do not require a document called a validation master plan. What FDA requires is that computer systems used to create, modify, maintain, archive, retrieve or transmit electronic records subject to a predicate rule be validated — see 21 CFR Part 11 — and that equipment and processes be suitable and controlled under the applicable predicate rule (Part 58 for nonclinical laboratory studies, Part 211 for drug GMP, Part 820 for devices). A VMP is the normal, sensible way to demonstrate that programme exists, and FDA investigators will read one if you have it — but the correct statement in your VMP is that it satisfies Annex 15 §1.5 and supports FDA predicate-rule compliance, not that FDA mandates it.
Which framework applies to which kind of lab
| Lab type | Primary framework | Is a VMP expected? | Practical note |
|---|---|---|---|
| GMP QC / release testing lab | EU GMP Part I Ch. 6, Annex 15, Annex 11; 21 CFR 211 | Yes — directly, via Annex 15 §1.4 | Usually a chapter of the site VMP rather than a standalone lab document. |
| GLP test facility | OECD GLP Principles; 21 CFR Part 58 | Not by name | GLP requires equipment suitability, SOPs and computerised-system control; a VMP is the practical vehicle but is not the named deliverable. |
| GCP central / bioanalytical lab | ICH E6; sponsor-imposed requirements | Usually by contract | The sponsor’s own computerised-systems expectations often flow down and must be reconciled with your VMP scope. |
| ISO/IEC 17025 or ISO 15189 lab | ISO/IEC 17025, ISO 15189 | No | These standards require control of equipment, method validation and control of data/information management — related obligations, different vocabulary. Do not conflate analytical method validation under ICH Q2(R2) with system validation. |
| CLIA-certified clinical lab (US) | 42 CFR 493 | No | See CLIA high-complexity requirements; the performance-specification obligation is test-level, not system-level. |
The seven things Annex 15 says a VMP must include or reference
Annex 15 §1.5 lists what the VMP or equivalent document should define, “include or reference.” The word reference is doing real work: a VMP is allowed to point at a controlled SOP rather than restate it, and a lean VMP that cross-references well is easier to keep current than a 90-page one that duplicates the quality manual. The seven items, with what each one means in a laboratory:
| # | Annex 15 §1.5 item | What it means in a lab VMP |
|---|---|---|
| i | Qualification and validation policy | The one-page commitment: risk-based, lifecycle, no retrospective validation, quality oversight over the whole lifecycle. |
| ii | Organisational structure including roles and responsibilities | Named roles (Process Owner, System Owner, QA, IT, validation lead) with a RACI, plus how third-party vendor activity is governed. |
| iii | Summary of the facilities, equipment, systems, processes on site and their qualification/validation status | The inventory. In a lab this is the heaviest section and the one inspectors open first. Status, not just a list. |
| iv | Change control and deviation management for qualification and validation | How a change is impact-assessed against validated status, and how a failed acceptance criterion becomes a deviation. |
| v | Guidance on developing acceptance criteria | The rules by which criteria are set and justified — not the criteria themselves, which live in protocols. |
| vi | References to existing documents | The SOP map: URS, risk assessment, protocol templates, periodic review, supplier assessment, data integrity. |
| vii | The qualification and validation strategy, including requalification where applicable | The strategy matrix — which system class gets which deliverable set, and on what re-evaluation cycle. |
If you write nothing else, write items iii and vii properly. They are the two an inspector can test against reality in ten minutes by picking a system off your shelf and asking to see its file.
Step 1 — Build the system and equipment inventory
The inventory is the spine of a lab VMP. Annex 11 §4.3 requires it to be current and to record GMP functionality; the practical requirement is that someone can pick any instrument or application in the lab and find it, with its status, in one place.
Fields that make an inventory auditable rather than decorative:
- Unique system ID and the name people in the lab actually use for it (the informal name is what appears in deviations).
- Physical location, and for software, where it runs — standalone workstation, server, or a named cloud/SaaS tenancy.
- Business/process owner and system owner — two different named people, per Annex 11 §2.
- GxP applicability and criticality tier (see Step 2), with the date and reference of the assessment that set it.
- GAMP software category and, for instruments, whether the embedded firmware is separately controlled.
- Electronic-records / electronic-signature status — whether the system holds records subject to a predicate rule, and whether signatures are applied.
- Current validation status and evidence location — validated, in validation, legacy-assessed, retired; plus the document IDs.
- Date of last periodic review and next due date.
- Supplier and support arrangement, including whether a supplier assessment or audit was performed and when.
- Interfaces and data flows — which systems it sends data to or receives from. For critical systems this is a mandatory element of the system description under Annex 11 §4.3.
The four things lab inventories routinely miss
- Instrument-embedded software. A plate reader, a titrator or a balance runs software that creates GxP records. If the inventory lists only “networked applications,” the entire instrument estate is invisible to the VMP.
- Spreadsheets that perform GxP calculations. A validated LIMS feeding an unvalidated Excel template that computes the reportable result is a common and serious gap. If a spreadsheet transforms data into a decision, it is a computerised system.
- Standalone workstations with local-only data. These are where audit-trail and backup obligations quietly fail; see ALCOA+ data integrity.
- Cloud and vendor-hosted systems. Annex 11 §3.1 requires formal agreements with third parties including clear statements of their responsibilities, and states that IT departments should be considered analogous. A SaaS LIMS does not move the obligation off the regulated user.
Step 2 — Assess GxP criticality (the decision rule)
This is the judgment the VMP has to make repeatable. Without a written rule, criticality gets assigned by whoever is in the room, and the inventory becomes indefensible. A workable three-question rule, all three answerable from the system’s actual function:
- Does it create, modify, store, transmit or archive a record required by a predicate rule or a GxP obligation? (Result data, raw data, audit trails, training records, calibration records.)
- Does it make or directly support a GxP decision? (Calculates a reportable result, applies a specification, flags an out-of-specification, releases or rejects.)
- Does it control a GxP-relevant condition or process? (Chamber temperature, environmental monitoring alarms, sample chain of custody.)
Then assign to one of three tiers, with the tier determining the deliverable set in Step 3:
| Tier | Definition | Typical lab examples |
|---|---|---|
| GxP-critical | Yes to Q2 or Q3, or holds primary raw data under Q1 | LIMS, chromatography data system, ELN, stability chamber monitoring, environmental monitoring system |
| GxP-supporting | Yes to Q1 only; holds GxP records but makes no decision | Document management, training/LMS, calibration scheduling, deviation and CAPA tracking |
| Non-GxP | No to all three | Purchasing, HR, general office productivity, non-GxP research instruments |
Two rules that keep this honest. First, record the “no” decisions as formally as the “yes” ones — an inspector’s most productive question is “what did you decide is not GxP, and why?”, and an inventory with no non-GxP rows looks like nobody assessed anything. Second, criticality is a property of use, not of the product: the same freezer-monitoring platform is GxP-critical when it holds stability samples and non-GxP when it holds a student’s reagents. Assess the deployment.
Step 3 — Assign a validation strategy per GAMP 5 category
The ISPE GAMP 5 guide is the reference framework for scaling validation effort to software type and risk. Its software categories — infrastructure software, non-configured products, configured products, and custom or bespoke applications — are used to answer a single question: how much of the evidence can be leveraged from the supplier, and how much must the regulated user generate?
Sourcing note: GAMP 5 is a paid ISPE publication and is not reproduced here. The characterisation below reflects widely-reported industry summaries of the second edition rather than a direct reading of ISPE’s own text; verify category assignments against your own licensed copy before writing them into a VMP.
What changed — and why a lot of VMP advice online is out of date
Three dated shifts matter, and content written before them describes an approach regulators are actively moving away from:
- GAMP 5 Second Edition, published July 2022. It retains the risk-based category framework but modernises it for agile development, cloud and SaaS delivery, and supplier-provided evidence, and formalises “critical thinking” — deciding what to test based on risk rather than executing a fixed documentation set. The practical consequence for a VMP is that rigid category-to-deliverable mapping is no longer the point; the category informs the judgment, it does not replace it.
- FDA’s Computer Software Assurance for Production and Quality System Software guidance, finalised 24 September 2025. Its formal scope is production and quality system software under the device Quality System Regulation, not a replacement for Part 11 — but its central move, shifting effort from exhaustive scripted documentation toward risk-proportionate assurance and unscripted testing for lower-risk features, is being applied across GxP CSV practice generally. A VMP written to a “every system gets a full scripted IQ/OQ/PQ package” rule is arguing against the direction of travel.
- The EU/PIC/S Annex 11 revision. A draft revision was published for public consultation on 7 July 2025, with the consultation closing 7 October 2025; industry reporting describes a substantially expanded document covering cybersecurity, identity and access management, supplier oversight and AI, aligned with PIC/S. As of August 2026 the final revised Annex 11 had not been published, and the 2011 revision 1 above remains the operative text. Do not cite draft clause numbers in a VMP. Check the EudraLex Volume 4 page and PIC/S publications for current status before your next VMP revision.
The strategy matrix
What the VMP should contain is a matrix that a project team can apply without escalating, crossing criticality tier with software category. An illustrative shape — set your own cells against your own risk appetite and document the justification:
| Criticality | Non-configured product (e.g. a standard instrument control package) | Configured product (e.g. LIMS, CDS) | Custom / bespoke |
|---|---|---|---|
| GxP-critical | URS, risk assessment, supplier assessment, leveraged supplier testing plus user-side verification of GxP-relevant functions, data integrity and audit-trail review | Full lifecycle: URS, functional/configuration specification, traceability matrix, risk-based testing of configured GxP functions, data migration verification, audit-trail and access review | Full lifecycle plus supplier quality-system assessment, design review, code/unit-test evidence, and formal reporting of quality and performance measures across all lifecycle stages (Annex 11 §4.6) |
| GxP-supporting | URS, risk assessment, supplier documentation review, verification of intended use | URS, risk-based testing limited to GxP-record-handling functions, access control verification | Reduced lifecycle with documented justification |
| Non-GxP | Documented assessment recording the non-GxP determination; no validation deliverables | ||
Two clauses to write into the strategy section because vendors will test them. Annex 15 §2.6: where validation protocols or documentation are supplied by a third party providing validation services, appropriate site personnel must confirm suitability and compliance with internal procedures before approval, and vendor protocols may need supplementing with additional documentation or test protocols. In plain terms — a vendor’s off-the-shelf IQ/OQ package for an HPLC is not automatically your qualification evidence. And Annex 11 §3.3: documentation supplied with commercial off-the-shelf products should be reviewed by the regulated user to check that user requirements are fulfilled. See IQ/OQ/PQ for how those stages are structured, and thermal cycler validation or sterilization validation for worked instrument examples.
Step 4 — Roles and responsibilities
Annex 11 §2 names the collaboration explicitly: Process Owner, System Owner, Qualified Persons and IT, all with appropriate qualifications, level of access and defined responsibilities. Annex 15 adds two constraints that are widely misread:
- §1.2 — qualification and validation activities should only be performed by suitably trained personnel following approved procedures. That means the training record for validation execution is itself an inspectable artefact.
- §1.3 — qualification/validation personnel should report as defined in the pharmaceutical quality system, “although this may not necessarily be to a quality management or a quality assurance function. However, there should be appropriate quality oversight over the whole validation life cycle.” This is the clause that legitimises a validation function sitting inside lab operations or IT rather than under QA — provided the oversight is defined. Many lab VMPs unnecessarily assert QA ownership of execution because they have not read it.
A minimal RACI that survives contact with a real lab:
| Activity | Process owner | System owner | QA | IT / vendor |
|---|---|---|---|---|
| Define user requirements | Accountable | Consulted | Consulted | Consulted |
| GxP criticality assessment | Responsible | Responsible | Approves | Consulted |
| Risk assessment | Responsible | Responsible | Approves | Consulted |
| Protocol authoring / execution | Consulted | Responsible | Approves | Responsible (technical) |
| Deviation handling during validation | Consulted | Responsible | Approves | Consulted |
| Release for use | Accountable | Consulted | Approves | Informed |
| Periodic review | Accountable | Responsible | Approves | Consulted |
On suppliers: Annex 11 §3.2 states that the need for a supplier audit should be based on a risk assessment — audit is not automatic, but the decision must be documented. §3.4 requires that quality-system and audit information relating to software suppliers be made available to inspectors on request, which means you need to hold it, not merely to have looked at it once.
Step 5 — Acceptance criteria: what “guidance on developing” means
Annex 15 §1.5(v) asks the VMP for guidance on developing acceptance criteria — the rules, not the numbers. The rules that belong there, each traceable to a clause:
- Acceptance criteria are defined in the protocol, before execution, alongside the critical systems, attributes and parameters they apply to (§2.4).
- A significant change to an approved protocol during execution — including a change to acceptance criteria or operating parameters — must be documented as a deviation and scientifically justified (§2.7). This is the clause that stops criteria being loosened to make a failing run pass.
- A result that fails a pre-defined acceptance criterion is recorded as a deviation and fully investigated, with implications for the validation discussed in the report (§2.8).
- The validation report summarises results against the acceptance criteria and makes a final recommendation on the outcome; subsequent changes to criteria must be scientifically justified (§2.9).
- Release to the next qualification stage is authorised by responsible personnel. Conditional approval to proceed is permitted where certain criteria or deviations are not fully addressed, provided there is a documented assessment that there is no significant impact on the next activity (§2.10) — a genuinely useful provision that many labs do not realise they have.
For a lab specifically, add a rule on where criteria come from: instrument acceptance criteria should be traceable to the method’s requirements and the instrument’s specification, not copied from a vendor template. If the assay needs 2% precision and the vendor OQ tests to 5%, the OQ has not qualified the instrument for your use.
Step 6 — Periodic review and requalification triggers
This is the section that decides whether the VMP is a live programme or a shelf document, and it is where the lab framing diverges most from the manufacturing one — a lab reviews dozens of systems and hundreds of instruments on staggered cycles rather than a handful of process trains.
What the regulations require
Annex 11 §11 requires computerised systems to be periodically evaluated to confirm they remain in a valid state and are compliant with GMP, and specifies what such evaluations should include where appropriate: the current range of functionality, deviation records, incidents, problems, upgrade history, performance, reliability, security and validation status reports. That list is effectively a ready-made periodic-review agenda — build the review template directly from it.
Annex 15 §4.1 requires that equipment, facilities, utilities and systems be evaluated at an appropriate frequency to confirm they remain in a state of control. §4.2 adds that where requalification is performed at a specific time period, the period must be justified and the criteria for evaluation defined, and the possibility of small changes over time assessed. “Annual because we always have” is not a justification; drift, usage intensity, criticality and deviation history are.
Time-based and event-based triggers
| Trigger type | Trigger | Typical response |
|---|---|---|
| Time | Scheduled periodic review reaching its due date (interval justified by criticality) | Full periodic review per the Annex 11 §11 agenda; outcome recorded and next date set |
| Event | Software upgrade, patch, or configuration change affecting GxP functionality | Impact assessment under change control; regression testing scoped to affected functions |
| Event | Migration to new hardware, server, or cloud tenancy | Verification that data are not altered in value or meaning during migration (Annex 11 §4.8) |
| Event | Change of intended use, new assay, or new record type on an existing system | Re-run the criticality assessment; extend the URS and re-verify affected functions |
| Event | Repeated deviations, incidents or data-integrity findings on the system | Triggered review ahead of schedule; CAPA linkage |
| Event | Supplier discontinues support or the product goes end-of-life | Risk assessment and remediation or retirement plan |
| Event | Instrument relocation, major repair, or replacement of a critical component | Partial requalification scoped to affected qualification stages |
| Event | Regulatory change (e.g. publication of the revised Annex 11) | Gap assessment against the VMP itself, then a VMP revision |
Write the review outcome options into the VMP as well, because “review completed” is not a conclusion: remains valid; remains valid with actions; requires requalification; requires remediation before continued GxP use; retire. Each outcome needs a named approver and a route into CAPA where applicable.
Change control — the loop back into the VMP
Annex 15 §11 places change control inside the pharmaceutical quality system and requires written procedures for planned changes to equipment, premises, method of production or testing, or “any other change during the lifecycle that may affect product quality or reproducibility” (§11.2). Quality risk management is used to evaluate the planned change against its potential impact on quality, the quality system, documentation, validation, regulatory status, calibration and maintenance — explicitly “to plan for any necessary process validation, verification or requalification efforts” (§11.4). After implementation, an evaluation of the change’s effectiveness should confirm it was successful (§11.7).
Annex 11 §4.2 closes the loop from the other side: validation documentation should include change control records and reports on any deviations observed during the validation process. See ICH Q9 (Quality Risk Management) for the risk framework these clauses assume.
Keeping the VMP itself current
The VMP is a controlled document and needs its own lifecycle, which surprisingly few lab VMPs define. What to state explicitly:
- Review cadence — a defined periodic review of the VMP itself, with the interval justified, independent of the systems it governs.
- Revision triggers — new system class entering the lab, a change of scope or site, an organisational restructure that moves named roles, a regulatory publication (the revised Annex 11 will be one), or an inspection or audit finding against the validation programme.
- Approval — who signs, and confirmation that the quality-oversight requirement of Annex 15 §1.3 is met by that approval route.
- Inventory currency — the mechanism that keeps the inventory current between VMP revisions. Annex 11 §4.3 requires the listing to be up to date, which a document revised every three years cannot deliver on its own. In practice the inventory is a controlled register maintained continuously and referenced by the VMP, not a static appendix inside it. This is the single most common structural failure in lab VMPs.
A VMP outline you can adapt
- Purpose, scope and exclusions (state which sites, labs, systems and GxP frameworks are in and out)
- Regulatory basis (Annex 15, Annex 11, PI 011-3, applicable predicate rules, accreditation standards)
- Qualification and validation policy — Annex 15 §1.5(i)
- Organisation, roles and responsibilities, including third parties — §1.5(ii)
- System and equipment inventory: reference to the controlled register, and the fields it holds — §1.5(iii)
- GxP criticality assessment method and decision rule
- Risk-management approach and its link to ICH Q9
- Validation strategy matrix by criticality and software category, including requalification — §1.5(vii)
- Deliverables and documentation standards (URS, traceability, protocol, report templates)
- Acceptance-criteria rules — §1.5(v)
- Deviation handling during qualification and validation — §1.5(iv)
- Change control and impact assessment — §1.5(iv)
- Periodic review and requalification: triggers, agenda, outcomes
- Data integrity and electronic records/signatures scope
- Supplier assessment and audit decision rule
- Legacy system handling and retirement/decommissioning, including record retention
- Training requirements for validation personnel — Annex 15 §1.2
- Referenced documents — §1.5(vi)
- Glossary and revision history
Items 15 and 16 are not in the Annex 15 list but are where lab VMPs most often have a gap: instrument fleets outlive their software support, and decommissioning a system that still holds retained raw data is a data-integrity question before it is an IT one.
Frequently asked questions
What is a validation master plan?
A controlled document that defines an organisation’s qualification and validation programme — its scope, the inventory of systems and equipment in scope with their status, the strategy for how much validation each class of system receives, roles and responsibilities, the rules for setting acceptance criteria, and the change-control and periodic-review arrangements. EU GMP Annex 15 §1.4 names it directly and §1.5 lists the seven areas it must include or reference.
What is the difference between a validation master plan and a validation plan?
Scope and altitude. The VMP governs the whole site or lab and is essentially permanent, revised on a defined cycle. A validation plan covers one system or one project — a LIMS implementation, an instrument fleet upgrade — and closes when that project’s summary report is approved. Annex 15 §1.6 explicitly contemplates separate validation plans for large and complex projects.
Is a validation master plan required by the FDA?
Not by that name. FDA regulations require validation of computer systems handling records subject to a predicate rule (21 CFR Part 11) and control of equipment and processes under the applicable predicate rule, but no FDA regulation mandates a document titled “validation master plan.” The named requirement is in EU GMP Annex 15 §1.4. A VMP is nonetheless the standard way to demonstrate a controlled programme to any inspectorate.
Who writes and approves the VMP?
Typically a validation lead or quality function drafts it with input from process and system owners and IT. Annex 15 §1.3 makes clear that validation personnel do not have to report into QA, but that appropriate quality oversight over the whole validation lifecycle must exist — so quality approval of the VMP is the normal way to satisfy that, even where execution sits elsewhere.
How often should a VMP be reviewed?
The regulations do not set a fixed interval for the VMP itself. Annex 15 §4.2 requires that where a periodic requalification interval is used, the period be justified and the evaluation criteria defined — the same reasoning applies to the plan. Set an interval you can justify from the rate of change in your system estate, and define event triggers (new system class, reorganisation, regulatory change, inspection finding) that force an off-cycle revision.
Does a research laboratory need a VMP?
Only if it operates under a framework that requires one, or under a contract that imposes one. A purely discovery-stage academic lab has no VMP obligation. A lab performing GLP-compliant nonclinical safety studies, GMP QC release testing, or sponsor-contracted GCP sample analysis does have obligations that a VMP is the practical vehicle for — and in the GMP case, Annex 15 §1.4 names it. See GxP compliance for which framework applies to which activity.
Does every lab instrument need to be in the VMP inventory?
Every instrument in the lab’s scope should be assessed and the assessment recorded, including instruments determined to be non-GxP. That is different from every instrument requiring validation deliverables. An inventory that lists only the GxP systems cannot demonstrate that the non-GxP determinations were made deliberately.
Does a spreadsheet need to be validated?
If it creates, modifies or stores a GxP record, or performs a calculation that produces or supports a GxP decision, it is a computerised system and falls inside the VMP’s scope. The validation effort should be scaled to its complexity and risk — a locked template performing one arithmetic transformation needs far less than a macro-driven workbook, but it needs a documented assessment either way.
What is the relationship between a VMP and a data integrity policy?
They overlap and should cross-reference rather than duplicate. The VMP determines which systems are in scope and how much validation each receives; the data-integrity policy governs how records within those systems meet ALCOA+ expectations — audit trails, review-by-exception, access control, retention. PIC/S PI 041-1 is the current reference for the latter. The entry-level conventions those records have to satisfy in the first place — how a correction is struck, signed and dated, when a reason for change is actually required, and the point at which a slip stops being an error and becomes a data-integrity finding — are set out in CASRAI’s guide to good documentation practices and the ALCOA+ attributes.
Related CASRAI resources
- Computer System Validation (CSV): GAMP 5, IQ/OQ/PQ, and 21 CFR Part 11 — the individual-exercise layer beneath the VMP
- GxP Compliance: What GLP, GCP, GMP, and GDP Actually Require
- Facility Qualification: IQ/OQ/PQ Protocol, Checklist, and SOP
- GMP LIMS: What a LIMS Must Do to Comply with GMP and LIMS Implementation
- Cold Chain Qualification vs. Validation — the qualification/validation distinction the VMP has to be precise about
- Laboratory Environmental Monitoring and FDA Process Validation
- Lab Compliance — the full cluster hub
Primary sources
- EudraLex Volume 4, Annex 15: Qualification and Validation — European Commission; deadline for coming into operation 1 October 2015.
- EudraLex Volume 4, Annex 11: Computerised Systems — European Commission, revision 1; came into operation 30 June 2011.
- PIC/S PI 011-3, Good Practices for Computerised Systems in Regulated GXP Environments (25 September 2007) and PI 041-1, Good Practices for Data Management and Integrity in Regulated GMP/GDP Environments (1 July 2021).
- 21 CFR Part 11 — Electronic Records; Electronic Signatures, eCFR.
- FDA, Computer Software Assurance for Production and Quality System Software — final guidance, 24 September 2025.
- ISPE GAMP 5: A Risk-Based Approach to Compliant GxP Computerized Systems, Second Edition (July 2022) — a paid publication; not reproduced here, and the second-edition characterisation above reflects industry reporting rather than a direct reading of ISPE’s text.








