| sop_id | SOP-006 |
|---|---|
| title | Software Validation (QMS Tools) |
| revision | R05 |
| revision_date | 2026-05-04 |
| status | Published |
| owner_role | qa_lead |
| approver_role | management_representative |
| related_issue | #2 |
Define risk-based validation and revalidation of software used in the QMS.
Applies to software tools that create, modify, approve, or retain quality records and compliance evidence.
- Tool purpose and intended QMS use
- Risk assessment (impact to record integrity, product quality, and compliance decisions)
- User requirements and acceptance criteria
- Validation record with scope, tests, results, and approval
- Revalidation record after significant tool changes
| Role | Responsibilities |
|---|---|
| QA Lead | Owns validation planning, evidence completeness, and approval routing. |
| Tool Administrator | Configures tool and executes test protocol steps. |
| Process Owner | Confirms validated behavior supports intended process use. |
| Management Representative | Approves validation for high-criticality tools. |
- Maintain QMS tool inventory in
matrices/qms_tooling_inventory.yml. - Classify each tool criticality (
high,medium,low) based on impact to record integrity, product quality, and compliance decisions.
- Define intended use and user requirements.
- Define validation strategy proportional to risk and complexity.
- Define objective acceptance criteria for each requirement.
- Define traceability from intended use and requirements to planned test coverage and expected evidence.
- Execute test cases and capture evidence (screenshots, logs, exported artifacts).
- Record deviations and assess impact.
- Maintain traceability between defined requirements, executed tests, and captured evidence.
- Resolve critical deviations before tool release for QMS use.
- QA Lead reviews validation completeness.
- Management Representative approval is required for high-criticality tools.
- Tool status in inventory is updated to validated only after approval.
Maintain the validated state throughout tool use by monitoring for internal or vendor changes that could affect intended use, risk, or evidence integrity.
Revalidation is required when:
- Tool vendor introduces major functional/security changes.
- Internal workflows/automation logic changes quality-critical behavior.
- New intended QMS use is introduced.
- Validation plan and protocol
- Test results and deviation log
- Validation summary and approval record
| Standard Clause | Control in this SOP |
|---|---|
| ISO 13485:2016 4.1.6 | Defines validation/revalidation controls for QMS software applications. |
- SOP-001 Document and Record Control
- SOP-005 QMS Governance
| Revision | Revision Date | Change Summary |
|---|---|---|
| R00 | 2026-03-02 | Initial full release. |
| R01 | 2026-03-08 | Updated governance cross-reference after the Quality Manual was split out of SOP-005. |
| R02 | 2026-03-18 | Removed top-table standards clause metadata; normative references remain in the Traceability section. |
| R03 | 2026-03-25 | Generalized the purpose statement, added product-quality criticality language, required requirement-to-test traceability, and defined validated-state maintenance expectations. |
| R04 | 2026-04-27 | Renamed YAML metadata field effective_date to revision_date to align controlled-document metadata with the tag-based publication model. The effective date is derived from the published QMS release tag rather than from the document front matter. |
| R05 | 2026-05-04 | Standardize standards citations to specific versions. |