Launch webinar · AI in Pharma · 30 Aug, 12:00 PM IST
Home / Knowledge Hub / Article
Knowledge Hub

CSV vs CSA: what actually changed?

By Sachin Bhandari, Honorary Dean · 25+ years in pharma Quality IT · 12-minute read

Everyone says CSA replaces CSV. After twenty-five years of validating systems, facing inspections and sitting on both sides of the audit table, I can tell you that is not quite right. CSA changes how you validate. It does not change why, and it does not change what you will be asked to defend when an auditor sits across the table.

How we got here

You cannot understand CSA without the history, because CSA is a correction, not an invention. The industry over-rotated on documentation for two decades, and the regulators themselves told us to stop.

1997 21 CFR Part 11: e-records law 2003 FDA narrows Part 11 scope and enforcement 2008 GAMP 5: risk-based lifecycle validation 2015-18 Data integrity era: ALCOA+ front and centre 2022 CSA draft guidance + GAMP 5 2nd edition 2025 FDA CSA guidance: the new baseline
Three decades from "document everything" to "think, then document what matters".

Here is what that history did to us in practice. Part 11 landed in 1997 and the industry panicked. We validated everything, printed everything and signed everything, because nobody wanted to be the first warning letter. By the mid-2000s a mid-size company could produce a thousand pages of OQ scripts for a system where maybe forty functions actually touched product quality. The FDA noticed something worse than the waste: teams were so busy producing evidence that they had stopped thinking about risk. CSA, first drafted in 2022 and now the operating baseline, is the agency saying it plainly: spend your effort where the patient risk is, and stop performing documentation theatre.

The five shifts that matter

  • Testing follows risk, not templates. High-risk functions, the ones that touch product quality, patient safety or data integrity, still get rigorous scripted testing with full evidence. Low-risk functions get lighter checks. The skill is classifying honestly: I have seen teams call everything high-risk to avoid the argument, which just rebuilds the old problem with new vocabulary.
  • Critical thinking beats paperwork. The audit question moved from "show me the document" to "walk me through why you decided that". A one-page risk rationale a reviewer actually wrote beats a fifty-page protocol nobody read. This is the shift teams find hardest, because it moves accountability from the binder to the person.
  • Vendor work counts, when you have earned it. If you have assessed a supplier properly, their testing becomes part of your evidence. You do not repeat their 10,000 regression tests; you test your configuration, your data and your intended use on top. The catch: "we have their SOC 2 certificate" is not a supplier assessment. You need to know what they tested and where their testing stops.
  • Unscripted testing is legitimate. Exploratory and ad-hoc testing, recorded honestly with who, what, when and outcome, now has an accepted place for lower-risk functions. Experienced testers find more real defects exploring than following scripts. The record is leaner but it still exists.
  • The record got leaner, not optional. Evidence of thinking replaces volume of paper. You keep the risk assessment, the rationale, the results and the sign-off. You stop keeping screenshots of every click.

Side by side

Traditional CSV practiceCSA practice
Starting questionWhat must we document?Where is the risk to the patient?
Testing depthSame rigour everywhereScaled to risk, deep where it counts
Test methodScripted, step by step, evidence per stepScripted for high risk; unscripted and exploratory where justified
Vendor testingLargely repeated in-houseLeveraged after a real supplier assessment
EvidenceVolume: screenshots, printouts, signaturesJudgement: rationale, results, sign-off
Failure modeTeams stop thinking, binders growTeams under-classify risk to cut corners

What never changed

  • You still own patient safety and data integrity. No guidance moved that one inch. CSA changes the route, not the destination.
  • You still need evidence. Less of it, better chosen, but auditable end to end. "We did risk-based testing" with nothing written down is not CSA. It is negligence with a modern name.
  • You still defend your decisions. Risk-based means you can explain the risk. In an inspection, "the template said so" was always a weak answer. Now it is not even an answer.

What auditors actually ask now

From recent inspection experience, the questions have changed shape. Prepare for these five and you are most of the way there.

1

"Walk me through your risk classification for this system."

They want to hear your reasoning, not read your SOP. If the person who owns the system cannot explain why module X is high-risk and module Y is not, the leaner records stop being defensible.

2

"You leveraged the vendor's testing. Show me your assessment of the vendor."

This is where weak CSA adoption gets caught. A certificate on file is not an assessment; know what they tested and what they did not.

3

"This test was unscripted. Show me what was done and what was found."

Unscripted never means unrecorded. Tester, scope, date, observations, outcome. Five lines that save the day.

4

"Who reviewed this decision, and were they qualified to?"

When judgement replaces paper, the qualification of the person judging becomes part of the evidence.

5

"The system changed in March. Show me the impact assessment."

CSA extends into operations. Change control, periodic review and audit trail review carry more weight, not less, when initial validation is leaner.

The mistakes I keep seeing

  • Relabelling, not rethinking. Same thousand-page package, new cover sheet that says CSA. Auditors read past cover sheets.
  • Everything is suddenly low-risk. The opposite failure. If your risk assessment conveniently concludes that nothing needs deep testing, it will not survive its first inspection.
  • Nobody owns the rationale. Risk decisions made in a workshop, captured in a slide, owned by no one. When the auditor asks "why", someone has to answer in the first person.
  • Forgetting the operational tail. Leaner initial validation raises the bar on change control and periodic review. Teams that treat go-live as the finish line get caught a year later.
Where to go deeper: we teach the full shift hands-on, with a portfolio practical you can defend in an interview or an audit, in CSV & CSA Essentials. Already running validation? Operational CSV & CSA covers the operational tail, and Advanced CSV & CSA covers cloud and AI system validation.
One practical article at a time.

We publish when we have something worth your inbox, and not before.

Read next: Before you paste that into an AI tool…