Risk Assessment in CSV: How to Apply GAMP 5 Risk Principles
8 min readBy Mohammad Awawdeh
Risk assessment is the foundation of modern Computerized System Validation. GAMP 5 Second Edition makes this explicit: validation effort should be proportionate to the system's GxP impact and business risk - not determined by system complexity or the age of the software. This guide explains how to apply risk principles practically in your CSV programme.
Two Levels of Risk Assessment in CSV
GAMP 5 introduces two distinct risk assessment levels:
System-level risk assessment - determines whether the system has GxP impact and what category it falls into. This drives the overall validation approach.
Functional risk assessment - evaluates each function or feature within the system to determine which require testing and to what depth.
Both levels must be documented, reviewed by QA, and used to justify the scope and depth of the validation package.
System-Level Risk Assessment
Step 1: GxP Impact Assessment
The first question is always: is this system subject to GxP requirements? Ask:
Does the system create, modify, maintain, archive, retrieve, or transmit GxP records?
Does the system control or monitor a process that directly affects product quality or patient safety?
Does the system support or produce data used in regulatory submissions?
If any answer is yes, the system requires validation. Document the rationale - both the conclusion and the reasoning.
Step 2: GAMP 5 Category Classification
Classify the system using the GAMP 5 Second Edition categories:
Category 3 - Configured products (LIMS, ERP, EDMS, MES with standard configuration). Standard validation package.
Category 4 - Custom applications (bespoke software, heavily modified products). Full SDLC validation with design documentation.
Note on the old 5-category model: GAMP 5 First Edition had Categories 1–5. The Second Edition consolidates to 3 categories. If your SOPs still reference the old model, update them - inspectors are aware of the change and may question outdated references.
Functional Risk Assessment
For each function or module within the system, score the risk using three dimensions:
Severity (S) - the potential impact on patient safety, product quality, or data integrity if this function fails (typically scored 1–3: low, medium, high)
Probability (P) - the likelihood of failure occurring
Detectability (D) - the likelihood that a failure would be detected before causing harm
The risk score (S × P × D or S × P / D depending on your model) determines the test priority: high-risk functions receive exhaustive testing; low-risk functions may be excluded from formal testing with documented justification.
Translating Risk to Testing
Risk-based testing means your test cases are directly linked to risk scores:
High-risk functions → comprehensive OQ testing with positive and negative test cases
Medium-risk functions → selective testing of critical workflows
Low-risk functions → exclusion from testing with documented rationale (or referencing vendor testing evidence)
The traceability matrix links each risk score to test coverage. This is the document inspectors use to verify that your testing was proportionate and justified.
Documenting Risk Decisions
Risk assessment decisions must be traceable and signed. For each risk decision, document:
The function or system component being assessed
The risk scores and the rationale for each score
The conclusion (validate / do not validate; test / do not test)
Any assumptions made
QA review and approval signature with date
Inspection risk: Risk assessments that are filled in retrospectively - after the validation decision has already been made - are a data integrity concern. Inspectors may check version history and metadata. Conduct and document risk assessments before validation planning decisions are made.
PHARPRO Risk Assessment Support
PHARPRO conducts GxP impact assessments, GAMP 5 category classification, and functional risk assessments for pharmaceutical computerised systems across all GAMP categories. Our risk documentation is audit-ready and aligned with current regulatory expectations from FDA, EU GMP, and PIC/S.
تقييم المخاطر هو أساس التحقق من الأنظمة الحاسوبية الحديثة. توضّح الطبعة الثانية من GAMP 5 ذلك صراحةً: يجب أن يكون جهد التحقق متناسباً مع تأثير GxP للنظام وخطر الأعمال - لا يُحدَّد بتعقيد النظام أو عمر البرنامج. يشرح هذا الدليل كيفية تطبيق مبادئ المخاطر عملياً في برنامج CSV لديك.
مستويان لتقييم المخاطر في CSV
يُقدّم GAMP 5 مستويين متميزين لتقييم المخاطر:
تقييم المخاطر على مستوى النظام - يحدد ما إذا كان للنظام تأثير على GxP وما الفئة التي ينتمي إليها. هذا يدفع نهج التحقق الإجمالي.
تقييم المخاطر الوظيفية - يقيّم كل وظيفة أو ميزة داخل النظام لتحديد أيها يتطلب الاختبار وبأي عمق.
يجب توثيق كلا المستويين ومراجعتهما من قِبل ضمان الجودة واستخدامهما لتبرير نطاق وعمق حزمة التحقق.
تقييم المخاطر على مستوى النظام
الخطوة 1: تقييم تأثير GxP
السؤال الأول دائماً: هل هذا النظام خاضع لمتطلبات GxP؟ اسأل:
هل يُنشئ النظام سجلات GxP أو يعدّلها أو يحتفظ بها أو يؤرشفها أو يسترجعها أو ينقلها؟
هل يتحكم النظام في عملية تؤثر مباشرة على جودة المنتج أو سلامة المريض أو يراقبها؟
هل يدعم النظام أو يُنتج بيانات تُستخدم في التقديمات التنظيمية؟
إذا كانت أي إجابة بنعم، يتطلب النظام التحقق. وثّق المبررات - كل من الاستنتاج والمنطق.
الخطوة 2: تصنيف فئة GAMP 5
صنّف النظام باستخدام فئات الطبعة الثانية من GAMP 5:
الفئة 1 - برامج البنية التحتية (أنظمة التشغيل وقواعد البيانات وأدوات الشبكة). مؤهَّلة لا متحقَّق منها رسمياً.
الفئة 4 - التطبيقات المخصصة (البرامج المصمّمة خصيصاً أو المنتجات المعدَّلة بشكل مكثف). تحقق SDLC كامل مع وثائق تصميم.
ملاحظة حول النموذج القديم المكوّن من 5 فئات: كان للطبعة الأولى من GAMP 5 الفئات 1-5. تدمج الطبعة الثانية في 3 فئات. إذا كانت إجراءات التشغيل القياسية لديك لا تزال تستشهد بالنموذج القديم، حدّثها - المفتّشون مدركون للتغيير وقد يتساءلون عن المراجع القديمة.
تقييم المخاطر الوظيفية
لكل وظيفة أو وحدة داخل النظام، قيّم الخطر باستخدام ثلاثة أبعاد:
الخطورة (S) - التأثير المحتمل على سلامة المريض أو جودة المنتج أو سلامة البيانات إذا فشلت هذه الوظيفة (عادةً بمقياس 1-3: منخفض، متوسط، مرتفع)
الاحتمالية (P) - احتمال وقوع الفشل
قابلية الكشف (D) - احتمال كشف الفشل قبل إحداثه ضرراً
درجة الخطر (S × P × D أو S × P / D حسب نموذجك) تحدد أولوية الاختبار: الوظائف عالية الخطورة تتلقى اختباراً شاملاً؛ الوظائف منخفضة الخطورة قد تُستثنى من الاختبار الرسمي مع توثيق المبررات.
ترجمة المخاطر إلى اختبارات
الاختبار المبني على المخاطر يعني أن حالات الاختبار مرتبطة مباشرة بدرجات الخطر:
الوظائف عالية الخطورة ← اختبار OQ شامل بحالات اختبار إيجابية وسلبية
الوظائف متوسطة الخطورة ← اختبار انتقائي لمسارات العمل الحرجة
الوظائف منخفضة الخطورة ← استثناء من الاختبار مع توثيق المبررات (أو الاستشهاد بأدلة اختبار المورد)
تربط مصفوفة التتبع كل درجة خطر بتغطية الاختبار. هذه هي الوثيقة التي يستخدمها المفتّشون للتحقق من أن اختباراتك كانت متناسبة ومبررة.
توثيق قرارات المخاطر
قرارات تقييم المخاطر يجب أن تكون قابلة للتتبع وموقّعة. لكل قرار مخاطر، وثّق:
الوظيفة أو مكوّن النظام الذي يُقيَّم
درجات الخطر والمبررات لكل درجة
الاستنتاج (تحقق / لا تحقق؛ اختبر / لا تختبر)
أي افتراضات صُنعت
توقيع مراجعة وموافقة ضمان الجودة مع التاريخ
خطر التفتيش: تقييمات المخاطر المملوءة بأثر رجعي - بعد اتخاذ قرار التحقق بالفعل - تثير قلقاً تجاه سلامة البيانات. قد يتحقق المفتّشون من سجل الإصدارات والبيانات الوصفية. أجرِ تقييمات المخاطر ووثّقها قبل اتخاذ قرارات تخطيط التحقق.
دعم PHARPRO لتقييم المخاطر
يُجري PHARPRO تقييمات تأثير GxP وتصنيف فئات GAMP 5 وتقييمات المخاطر الوظيفية للأنظمة الحاسوبية الصيدلانية عبر جميع فئات GAMP. توثيق المخاطر لدينا جاهز للتدقيق ومتوافق مع توقعات الجهات التنظيمية الحالية من FDA وGMP الأوروبية وPIC/S.
PHARPRO - Expert Pharma Consulting
PHARPRO provides risk-based CSV services - GAMP 5 risk classification, impact assessments, and proportionate validation strategies for pharmaceutical computerised systems.