💻 Top 50 Computer System Validation (CSV) Interview Questions & Answers
A Practical Guide for Pharma Students & Freshers
Computer System Validation (CSV) is an important area within the pharmaceutical industry, particularly for professionals working in Quality Assurance, IT Quality, Validation, Regulatory Compliance, and computerized systems.
Whether you’re preparing for an interview, learning CSV for the first time, or looking to understand how computerized systems are controlled in the pharma industry, these 50 medium-level questions and answers will help build a strong foundation.
- What is Computer System Validation (CSV)?
Answer:
Computer System Validation is a documented process of providing evidence that a computerized system consistently performs its intended functions and meets predefined requirements, regulatory expectations, and data integrity requirements.
- Why is CSV important in the pharmaceutical industry?
Answer:
CSV helps ensure that computerized systems used in GMP activities produce reliable and accurate results. It helps protect patient safety, product quality, and data integrity while maintaining regulatory compliance.
- When is CSV required?
Answer:
CSV is generally required when a computerized system is used in a regulated process and can affect product quality, patient safety, or the integrity of regulated data. The extent of validation depends on the system’s risk and intended use.
- What is the difference between CSV and software testing?
Answer:
Software testing mainly focuses on finding software defects and confirming that the software functions correctly. CSV goes further by demonstrating that the system is fit for its intended regulated use and that appropriate documentation, risk management, traceability, security, and data integrity controls are in place.
- What is GxP?
Answer:
GxP refers to regulations and guidelines covering regulated activities in the life sciences industry. Examples include GMP, GLP, GCP, and GDP.
- What is GAMP 5?
Answer:
GAMP 5 is a guidance framework developed by International Society for Pharmaceutical Engineering for applying a risk-based approach to computerized system validation. It provides principles for system lifecycle management, documentation, testing, and supplier involvement.
- What are the main objectives of GAMP 5?
Answer:
The major objectives are to:
- Focus validation on risks
- Ensure systems are fit for intended use
- Maintain product quality and patient safety
- Ensure data integrity
- Avoid unnecessary validation activities
- Apply appropriate controls throughout the system lifecycle
- What are the GAMP software categories?
Answer:
The commonly used GAMP 5 software categories are:
- Category 1: Infrastructure software
- Category 3: Non-configured products
- Category 4: Configured products
- Category 5: Custom applications
The validation effort generally increases as the complexity and customization of the software increase.
- What is a User Requirements Specification (URS)?
Answer:
URS is a document that describes what the user needs the system to do. It defines business, functional, regulatory, security, and data requirements from the user’s perspective.
- What makes a good URS?
Answer:
A good URS should be:
- Clear
- Specific
- Testable
- Unambiguous
- Traceable
- Relevant to the intended use
- Approved by appropriate stakeholders
- What is Functional Specification (FS)?
Answer:
Functional Specification describes how the system will function to meet the requirements defined in the URS. It translates user requirements into detailed functional requirements.
- What is a Design Specification (DS)?
Answer:
A Design Specification describes the technical design of the system, including how hardware, software, configurations, interfaces, and other components will be implemented to satisfy functional requirements.
- What is a Validation Plan?
Answer:
A Validation Plan defines the overall strategy for validating a computerized system. It typically includes the scope, responsibilities, validation approach, documentation, testing strategy, and acceptance criteria.
- What is a Traceability Matrix?
Answer:
A Traceability Matrix links requirements to corresponding specifications, test cases, and test results. It helps demonstrate that all critical requirements have been adequately tested.
- What is risk-based validation?
Answer:
Risk-based validation means allocating validation effort according to the potential impact of a system or function on patient safety, product quality, and data integrity.
- What is a risk assessment in CSV?
Answer:
A risk assessment identifies potential risks associated with a computerized system and evaluates their impact and likelihood. Appropriate controls and testing are then established to reduce significant risks.
- What is FMEA and how can it be used in CSV?
Answer:
Failure Mode and Effects Analysis (FMEA) is a risk assessment technique used to identify possible failure modes, their effects, causes, and risks. It can help determine which system functions require greater validation attention.
- What is IQ?
Answer:
Installation Qualification (IQ) provides documented evidence that the system and its components have been installed correctly according to approved specifications and requirements.
- What is OQ?
Answer:
Operational Qualification (OQ) provides documented evidence that the system operates correctly across specified operating ranges and performs according to its approved functional requirements.
- What is PQ?
Answer:
Performance Qualification (PQ) demonstrates that the system performs consistently and effectively under actual or simulated routine operating conditions using the intended users, processes, and environment.
- What is the difference between IQ, OQ, and PQ?
| Qualification | Main Focus |
| IQ | Was the system installed correctly? |
| OQ | Does the system operate correctly? |
| PQ | Does the system perform effectively in its intended environment? |
- What is User Acceptance Testing (UAT)?
Answer:
UAT is testing performed to confirm that the system meets the business and user needs before it is accepted for operational use. It is generally performed with participation from intended users.
- What is FAT?
Answer:
Factory Acceptance Testing (FAT) is testing performed at the supplier or manufacturer location before the system is delivered or installed at the user’s site.
- What is SAT?
Answer:
Site Acceptance Testing (SAT) is performed at the user’s site to confirm that the delivered system meets agreed requirements and operates appropriately in the actual site environment.
- What is 21 CFR Part 11?
Answer:
21 CFR Part 11 is a regulation from the U.S. Food and Drug Administration that establishes requirements for electronic records and electronic signatures so they can be considered trustworthy and reliable when used in FDA-regulated activities.
- What are the major requirements of 21 CFR Part 11?
Answer:
Important areas include:
- System validation
- Access controls
- Audit trails
- Electronic signatures
- User authentication
- Record protection
- Record retention
- Operational and authority checks
- What is an audit trail?
Answer:
An audit trail is a secure, computer-generated chronological record that tracks important activities or changes made to electronic records, including information such as who performed the action and when it occurred.
- Why is audit trail review important?
Answer:
Audit trail review helps identify unauthorized, unexpected, or inappropriate changes to critical data. It supports data integrity, investigation, and regulatory compliance.
- What is ALCOA+?
Answer:
ALCOA+ represents principles used to maintain data integrity:
A – Attributable
L – Legible
C – Contemporaneous
O – Original
A – Accurate
The “+” extends these principles to include data being Complete, Consistent, Enduring, and Available.
- What is data integrity?
Answer:
Data integrity means maintaining data so that it remains accurate, complete, consistent, reliable, and trustworthy throughout its entire lifecycle.
- What is an electronic signature?
Answer:
An electronic signature is an electronic method used by an individual to sign or approve an electronic record. In regulated environments, it should be securely linked to the individual and the corresponding record.
- What is access control in a computerized system?
Answer:
Access control ensures that users can access only the systems, functions, and data appropriate to their authorized roles. It helps prevent unauthorized access and inappropriate data modification.
- What is role-based access control?
Answer:
Role-based access control assigns system permissions based on a user’s job role rather than providing every user with the same level of access.
Example: A QC analyst may have permission to enter test results but may not have administrator privileges.
- What is segregation of duties?
Answer:
Segregation of duties means dividing critical responsibilities among different individuals to reduce the possibility of unauthorized actions, errors, or fraud.
Example: The person who creates a user account should not necessarily be the same person who approves that access.
- What is a computerized system?
Answer:
A computerized system is a combination of hardware, software, people, procedures, data, and supporting infrastructure that performs a specific function.
- Give examples of computerized systems used in pharma.
Answer:
Examples include:
- LIMS
- ERP
- MES
- QMS
- EDMS
- Electronic Batch Records
- Chromatography Data Systems
- SCADA
- Laboratory systems
- Clinical trial systems
- What is a deviation in CSV?
Answer:
A deviation is a documented departure from an approved procedure, protocol, requirement, or expected result during validation or system operation.
- What should be done when a validation test fails?
Answer:
The failure should be documented as appropriate, investigated, and assessed for impact. The root cause should be identified, corrective actions implemented where necessary, and the test repeated after appropriate resolution and approval.
- What is CAPA?
Answer:
CAPA stands for Corrective and Preventive Action.
- Corrective Action: Addresses the cause of an existing problem.
- Preventive Action: Addresses potential causes to prevent recurrence or occurrence.
- What is change control in CSV?
Answer:
Change control is a formal process used to evaluate, approve, implement, test, and document changes to a validated computerized system while maintaining its validated state.
- What is the impact assessment of a system change?
Answer:
Impact assessment determines how a proposed change could affect the system’s functionality, validated state, regulatory compliance, data integrity, and product quality.
- What is periodic review?
Answer:
Periodic review is a documented assessment performed at defined intervals to confirm that a computerized system remains fit for intended use, compliant, secure, and in a validated state.
- What factors are reviewed during periodic review?
Answer:
Typical areas include:
- System changes
- Deviations
- Incidents
- CAPA
- Access controls
- Audit trails
- Backup and recovery
- Security
- Performance
- Validation status
- Supplier performance
- What is backup and restore testing?
Answer:
Backup and restore testing verifies that important system data can be successfully backed up and recovered when required. It is an important component of data availability and business continuity.
- What is disaster recovery?
Answer:
Disaster recovery is the planned process for restoring computerized systems and data after a major disruption such as hardware failure, cyberattack, natural disaster, or other serious incident.
- What is vendor qualification in CSV?
Answer:
Vendor qualification is the process of evaluating and approving a software or service provider to determine whether the supplier is capable of meeting the organization’s quality, technical, regulatory, and support requirements.
- Can vendor documentation be used during CSV?
Answer:
Yes. Appropriate vendor documentation such as specifications, test evidence, manuals, and qualification records can be leveraged when justified by a risk-based approach. However, the regulated company remains responsible for ensuring the system is fit for its intended use.
- What is the difference between CSV and CSA?
Answer:
CSV traditionally emphasizes documented validation activities and testing throughout the system lifecycle. Computer Software Assurance (CSA) promotes a more risk-based approach that focuses assurance activities on critical functions and intended use rather than applying the same level of testing to every software feature.
- What is the role of a CSV professional in a pharmaceutical company?
Answer:
A CSV professional typically helps with:
- Validation planning
- Requirements review
- Risk assessment
- Protocol preparation
- Test execution
- Requirement traceability
- Deviation management
- Change control
- Periodic review
- Data integrity assessment
- Validation documentation
- What skills are important for a career in CSV?
Answer:
A CSV professional should develop knowledge of:
- GMP and GxP
- GAMP 5
- 21 CFR Part 11
- EU GMP Annex 11
- Data integrity and ALCOA+
- Risk management
- IQ/OQ/PQ
- Validation documentation
- Testing
- Change control
- Deviation and CAPA
- Basic IT concepts
- Communication and documentation skills
For a fresher, the most important starting areas are: GMP → GAMP 5 → 21 CFR Part 11 → Data Integrity → CSV Lifecycle → URS → Risk Assessment → IQ/OQ/PQ → Testing → Change Control.